PUF-Based Authentication Using Intermediary Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods face challenges in securely storing and processing bio-information and user passwords, particularly in ensuring high-level security and user convenience, as physically unclonable functions (PUFs) generate unpredictable keys but may be difficult for users to remember, and user input passwords require high-level protection.

Innovation Solution

An information processing apparatus incorporating a PUF to generate unique keys through process variations in semiconductor manufacturing, combined with an encryption unit that encrypts user input passwords or bio-information using these keys, employing AES or T-DES encryption standards to create a secure identification key, which is stored and used for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PUF-generated unique keys are used for authentication, then security level is improved, but user convenience deteriorates due to difficulty in remembering the identification key

Engineering Contradiction:
Improvesecurity levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an encryption unit that acts as an intermediary between the PUF-generated unique key and the authentication process. User-friendly passwords or bio-information are encrypted using the unique key to generate identification keys, allowing users to interact with familiar authentication methods while the PUF provides strong cryptographic security in the background

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user input passwords and bio-information are stored for authentication, then ease of operation is improved, but security level deteriorates due to vulnerability during storage

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary encryption action by encrypting user passwords and bio-information using the PUF-generated unique key before storing them in the terminal. This preliminary protective measure ensures that even if stored data is compromised, the actual authentication credentials remain secure as they are transformed into encrypted identification keys

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unique key generated by the PUF serves as an intermediary cryptographic element that protects user credentials during storage. The encryption unit uses this intermediary key to transform vulnerable plaintext passwords and bio-information into secure encrypted forms, maintaining both user convenience and high-level security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If interlayer contact size is reduced below design rule to generate PUF keys, then uniqueness of PUF keys is improved, but manufacturing precision deteriorates due to process variation

Engineering Contradiction:
Improveuniqueness of PUF keysVSAvoidcontact formation precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent converts the harmful effect of process variation and manufacturing imprecision into a beneficial feature for PUF key generation. By intentionally designing interlayer contacts smaller than the design rule, the patent ensures that process variations create random short-circuit patterns that generate unique cryptographic keys. The manufacturing imprecision, which would normally be detrimental, becomes the source of cryptographic entropy and device uniqueness

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11729005B2Apparatus and method for processing authentication information
Publication Date: 2023.08.15 ICTK HLDG CO
  • US11729005B2 patent drawing
  • US11729005B2 patent drawing
  • US11729005B2 patent drawing

AI summary

Provided is an information processing apparatus including a physical unclonable function (PUF) to generate a unique key using a process variation in a semiconductor manufacturing process, and an encryption unit to encrypt a password and/or bio-information received from a user using the unique key.