Interactive Authentication Using PUF Keys Without Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in securely managing identity authentication and data encryption for a large number of devices, particularly in machine-to-machine communications, where device identities are vulnerable to theft and network management becomes complex.
Innovation Solution
An interactive authentication method using biased time-average-frequency direct period synthesis (TAF-DPS) and physical unclonable function (PUF) to generate unique device identities and encryption keys, ensuring secure communication through challenge-response pairs without storing keys, integrating authentication and encryption into a single hardware-based process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional identity authentication and data encryption methods are used, then device identities can be managed, but the system becomes complex and vulnerable to attacks as the number of devices increases
Solution Approach 1:
The patent combines identity authentication and data encryption into a single integrated system. The TAF-DPS circuit simultaneously generates both the authentication key and the encryption key from a single challenge, eliminating the need for separate key management systems and reducing overall system complexity while maintaining high security
Solution Approach 2:
The system uses physical unclonable functions (PUF) and time-average-frequency direct period synthesis to generate unique, non-reproducible keys for each device based on its inherent hardware characteristics. This self-service approach eliminates the need for centralized key distribution and storage, reducing network management complexity
2Reliability
If device identities are stored for authentication, then authentication can be performed, but the identities become vulnerable to theft and manipulation
Solution Approach 1:
The system performs preliminary key generation using the device's unique hardware characteristics (PUF) and time-average-frequency properties before any communication occurs. The key is derived from the challenge-response pair generated by the TAF-DPS circuit, ensuring that even if identities are intercepted, they cannot be reused or stolen since the key generation process is stateless and hardware-dependent
Solution Approach 2:
The patent changes the fundamental parameter of key generation from stored static identifiers to dynamically generated keys based on time-average-frequency characteristics. Each key is unique to the specific challenge instance and device hardware state, making them impossible to store, copy, or steal in the traditional sense
3Reliability
If multiple encryption keys are managed for each device, then secure communication can be achieved, but the management overhead increases significantly
Solution Approach 1:
The TAF-DPS circuit serves multiple functions simultaneously: it generates the authentication key, generates the encryption key, and provides the challenge-response mechanism. This universal approach eliminates the need for separate key management systems, reducing overhead while maintaining secure communication
Solution Approach 2:
The challenge-response pair acts as an intermediary that bridges authentication and encryption. The challenge from the transmitter and the corresponding response containing the authentication key and encryption key create a secure linkage without requiring direct key exchange or storage, simplifying management
Data Source
AI summary
Provided is an interactive authentication method, applicable to a transmitter. The transmitter is communicatively connected to a receiver. The authentication method includes: generating a first challenge and transmitting the first challenge to the receiver; receiving a response from the receiver, wherein the response comprises first identity authentication information and a second challenge, the first identity authentication information and the second challenge being encrypted using a first identity authentication key; generating, based on the first challenge, a second identity authentication key and second identity authentication information; and decrypting the first identity authentication information using the second identity authentication key, and performing identity authentication by matching the decrypted first identity authentication information with the second identity authentication information.


