PUF Arrays for Session Key Generation via Hashing Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Central organizations face challenges in securing networks due to the asymmetry between user identity verification and unverified server authenticity, leading to cyberattacks, especially when servers are mobile or exposed to insiders, and conventional password management systems are vulnerable to password guessing techniques despite using one-way cryptographic functions.

Innovation Solution

A system utilizing physical unclonable function (PUF) devices generates session keys by iteratively hashing passwords and using the difference in hashing cycles as a challenge to authenticate servers and clients, ensuring secure communication without storing the hashed passwords, and employing pseudo-homomorphic methods to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password management systems use one-way cryptographic functions to store hashed passwords, then security is improved, but the systems remain vulnerable to password guessing techniques

Engineering Contradiction:
ImprovesecurityVSAvoidpassword guessing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces PUF devices as an intermediary between the password storage system and the authentication process. Instead of directly storing or verifying passwords through traditional cryptographic methods, the system uses PUFs to generate unique challenge-response pairs that mediate the authentication process, making password guessing ineffective while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical/cryptographic password verification system with a physics-based PUF system. The PUF devices utilize physical characteristics (such as manufacturing variations in electronic circuits) to generate responses, substituting conventional cryptographic mechanisms with physical phenomena that are inherently resistant to guessing attacks

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If servers are made mobile or distributed to improve adaptability, then system flexibility is enhanced, but the risk of insider attacks and unauthorized access increases

Engineering Contradiction:
Improveserver mobilityVSAvoidinsider attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service authentication where PUF devices on both client and server sides independently generate and verify challenge-response pairs without relying on centralized password databases. This self-verified authentication mechanism allows mobile and distributed servers to authenticate themselves and clients without exposing centralized credentials that insiders could compromise

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication actions through PUF challenge-response verification before any sensitive operations occur. By establishing mutual authentication in advance through physics-based verification, the system prevents insider attacks even when servers are mobile or distributed, as each server must prove its identity through unique PUF characteristics before accessing any resources

Inventive Principle:
Principle #10Preliminary action

3Reliability

If users are required to frequently change passwords and use multi-factor authentication, then security is strengthened, but user convenience and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The PUF-based system enables self-service authentication where the physical characteristics of the user's device automatically generate authentication credentials. Instead of requiring users to manually change passwords or remember multiple factors, the system leverages the inherent physical properties of the device to continuously provide authentication, eliminating the burden of frequent password changes while maintaining strong security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a cryptographic copy of the PUF's physical characteristics through challenge-response pairs. This copy can be used for authentication without requiring the user to physically present the device or remember secrets, enabling convenient remote authentication while maintaining security equivalent to or stronger than multi-factor authentication

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12184797B2Associative PUF arrays to generate session keys with pseudo-homomorphic methods
Publication Date: 2024.12.31 THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
  • US12184797B2 patent drawing
  • US12184797B2 patent drawing
  • US12184797B2 patent drawing

AI summary

Systems and methods for the generation and use of session keys supporting secure communications between a client and server device are disclosed. The client hashes each of a series of passwords a first number of times. The hashed passwords are sent to a server. The server applies the hashed password to an array of PUF devices, and receives an initial response bitstream which is stored. The client later hashes each of the series of passwords a second number of times, which is less than the first number, and these are sent to the server. The server continues to hash the second message digest, generate PUF responses, and compare the result to the initially stored responses. For each password, the number of hashes necessary to achieve a match is a partial session key. Latency is improved by an array of separately addressable PUFs, each producing a partial session key.