PUF-Based Device Authentication with Error Correction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device authentication systems face challenges in securely authenticating hardware devices due to limitations in traditional public key infrastructure (PKI) constructions, particularly in resisting tampering and substitution attacks, and require more robust and efficient methods for error correction and key management.

Innovation Solution

A device authentication system utilizing physically unclonable functions (PUFs) to generate and verify device-specific tokens, incorporating error correction mechanisms and reduced modular multiplications to enhance security and efficiency on resource-constrained devices, with a tiered authentication structure to minimize re-enrollment costs and adapt to environmental variations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional public key infrastructure (PKI) constructions are used for device authentication, then key management and authentication can be implemented, but the system is vulnerable to tampering and substitution attacks and requires more computational resources

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional PKI cryptographic mechanisms with physically unclonable functions (PUFs) that leverage inherent physical variations in hardware circuits. The PUF generates unique device identifiers based on physical characteristics such as wire delays and resistance variations, eliminating the need for complex key management infrastructure while providing tamper-resistant authentication. This substitution of mechanical/cryptographic systems with physical property-based systems directly addresses the vulnerability to tampering and substitution attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If PUFs are used for authentication, then tamper detection and security against substitution attacks are improved, but error correction mechanisms are required to handle noisy responses

Engineering Contradiction:
Improvetamper detection capabilityVSAvoiderror correction complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements error correction codes (ECC) during the enrollment phase to pre-process and protect the PUF responses. By generating and storing corrected error patterns in advance, the system can efficiently handle noisy PUF responses during authentication without requiring complex real-time error correction. This preliminary preparation reduces the computational burden during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If full verification sets are distributed to all child servers, then authentication accuracy is maximized, but re-enrollment costs increase when devices are compromised

Engineering Contradiction:
Improveauthentication accuracyVSAvoidre-enrollment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent divides the complete verification set into multiple subsets and distributes different subsets to different child servers. This segmentation allows the system to maintain authentication accuracy by having multiple verification options while reducing re-enrollment costs - when a device is compromised, only the specific subset held by the compromised server needs to be updated rather than redistributing the entire verification set to all servers. This segmented approach directly addresses the trade-off between authentication accuracy and re-enrollment efficiency.

Inventive Principle:
Principle #1Segmentation

4Reliability

If PUF-based authentication is implemented, then security against modeling attacks is improved, but the number of modular multiplications required increases computational overhead

Engineering Contradiction:
Improveresistance to modeling attacksVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and utilizes only the essential PUF response bits required for authentication, avoiding unnecessary computational operations. By focusing on the core PUF challenge-response mechanism and eliminating redundant modular multiplications, the system maintains strong resistance to modeling attacks while significantly reducing computational energy consumption. This extraction of essential elements from the authentication process directly addresses the computational overhead issue.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3069249B1Authenticatable device
Publication Date: 2020.09.02 ANALOG DEVICES INC
  • EP3069249B1 patent drawingFigure 1
  • EP3069249B1 patent drawingFigure 2~3
  • EP3069249B1 patent drawingFigure 4~5

AI summary

An authenticatable device comprising a physically-unclonable function ('PUF') device having a PUF input and a PUF output and constructed to, in response to a challenge C, generate a characteristic output O; a processor, having an input connected to the PUF output, configured to: (1) in response to receipt of output O, generate a commitment value dependent upon a private value r, and (2) in response to contemporaneous receipt of output O and of an authentication query including a nonce, return a zero knowledge proof authentication value that corresponds to the commitment value and to a token that includes a blinded value dependent upon private value r and a random value, the processor being configured to decrypt the random value. An authentication system used with the device preferably has a working verification set including challenge C and commitment value, and a limited verification set including challenge C and a corresponding token.