PUF Authentication System with Dynamic Key Refresh

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

PUF-based authentication systems face challenges due to hardware aging, which leads to increased errors in responses over time, and are vulnerable to side-channel attacks that exploit static PUF output values.

Innovation Solution

The implementation of a PUF-enabled authentication system that internalizes challenge-response behavior to maintain shares of a private key, allowing for arbitrary threshold cryptographic operations without generating, reconstructing, or storing the private key, and periodically refreshes sensitive values to mitigate aging and side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If PUF-based authentication systems use static PUF output values, then the system structure is simple, but the system becomes vulnerable to side-channel attacks

Engineering Contradiction:
Improvesystem structureVSAvoidside-channel attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transitioning from static PUF output values to dynamic, time-varying challenge-response pairs. The system periodically refreshes the challenge-helper pairs and uses timestamped responses that change over time, making the PUF output non-static and resistant to side-channel attacks that exploit fixed values.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements periodic action through the mechanism of refreshing challenge-helper pairs at regular intervals. The system periodically updates the authentication data, creating a time-varying authentication state that prevents attackers from capturing and analyzing static PUF outputs, thereby mitigating side-channel attacks.

Inventive Principle:
Principle #19Periodic action

2Ease of operation

If PUF-based authentication systems do not periodically refresh values, then the system operation is simple, but hardware aging causes increased errors over time

Engineering Contradiction:
Improvesystem operationVSAvoiderror rate
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies periodic action by implementing regular refresh cycles of challenge-helper pairs. This periodic updating counteracts the cumulative effect of hardware aging by resetting the authentication state, thereby maintaining reliable operation despite gradual degradation of PUF characteristics over time.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements feedback through the challenge-response mechanism where the system continuously monitors authentication success and can detect degradation in PUF performance. When errors increase due to aging, the system can adjust refresh rates or parameters to maintain acceptable error levels, creating a feedback loop that adapts to hardware degradation.

Inventive Principle:
Principle #23Feedback

3Device complexity

If external entities issue challenges and store helper data, then the authentication protocol is simple, but the system requires additional external infrastructure

Engineering Contradiction:
Improveprotocol structureVSAvoidsystem independence
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies self-service by enabling the PUF-enabled device to generate and manage its own challenge-response pairs locally. The device internally maintains the authentication state without requiring external entities to issue challenges or store helper data, making the system self-sufficient and independent of external infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the challenge-response functionality from external entities and relocates it within the PUF-enabled device. By internalizing the authentication mechanism, the system eliminates dependency on external challengers and storages, achieving greater autonomy and reducing the need for external infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If the system stores private keys for authentication, then the authentication process is simple, but the system becomes vulnerable to key compromise

Engineering Contradiction:
Improveauthentication processVSAvoidkey compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies segmentation by dividing the private key into multiple shares that are distributed across different PUFs. Instead of storing a single private key, the system segments the authentication credential into parts that can be independently managed and refreshed, reducing the impact of any single key compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamics by making the private key shares time-varying through periodic refreshing. The key shares are not static but are continuously updated based on current challenge-response pairs, ensuring that even if one share is compromised, the dynamic nature of the shares prevents complete key compromise and maintains authentication security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10931467B2Authentication system and device including physical unclonable function and threshold cryptography
Publication Date: 2021.02.23 ANALOG DEVICES INC
  • US10931467B2 patent drawing
  • US10931467B2 patent drawing
  • US10931467B2 patent drawing

AI summary

A device comprising: a physical unclonable function (PUF) device configured to generate an output value based on hardware characteristics of the PUF device; and a processor connected to the PUF device, the processor configured to: execute a cryptographic operation in a sequence of ordered stages including a first stage and a second stage, the executing comprising: in the first stage: recovering a first secret value based on a first output value obtained from the PUF device; executing a first sub-operation using the first secret value; and removing unobscured values from memory prior to execution of a subsequent stage; in the second stage: recovering a second secret value based on a second output value obtained from the PUF device; and executing a second sub-operation using the second secret value to enable execution of a cryptographic operation encoded with at least the first secret value and the second secret value.