PUF-Based Authentication Key Generation for M2M Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Machine-to-machine (M2M) communication systems face challenges in secure authentication, particularly in autonomously performing knowledge-based authentication and resisting external security attacks, due to the limitations of conventional security methods and the vulnerability of small, portable devices to physical attacks.

Innovation Solution

The implementation of a physical unclonable function (PUF) in M2M communication devices to autonomously generate authentication keys, combined with secret and private key modules and a fuse unit for secure key management, enables robust password authentication and resistance to physical attacks through encryption and decryption processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security authentication methods are applied to M2M communication, then basic authentication can be performed, but devices cannot autonomously generate passwords and are vulnerable to physical attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidautonomous password generation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The PUF circuit enables the device to autonomously generate authentication keys without external assistance. The circuit uses inherent physical variations to self-generate unique cryptographic keys, eliminating the need for manual password configuration or external key distribution systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces conventional software-based password generation with a hardware-based PUF circuit that exploits physical phenomena. The authentication key is generated from intrinsic physical variations in the circuit, substituting mechanical/physical properties for software-based security mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If M2M communication devices are made small and portable, then deployment flexibility is improved, but devices become vulnerable to physical extortion and security attacks

Engineering Contradiction:
Improvedevice portabilityVSAvoidphysical attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the physical variations that make small devices vulnerable into a security asset. The inherent physical differences in circuit manufacturing, which could be exploited by attackers, are instead used to generate unique authentication keys that are impossible to replicate, turning physical vulnerability into cryptographic strength.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent changes the fundamental parameter of security from software-based passwords to hardware-based physical properties. By using physical characteristics of the circuit (resistance, capacitance, timing) as the basis for authentication keys, the system transforms the nature of security protection to be inherent in the device's physical structure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If PUF is used to generate authentication keys, then autonomous authentication and physical attack resistance are achieved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity module complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PUF circuit serves multiple functions simultaneously: it generates authentication keys, provides device identification, and enables secure communication. This single hardware component replaces what would otherwise require multiple separate security modules, reducing overall system complexity despite the advanced functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3206330B1Apparatus and method for authentication between devices based on PUF over machine-to-machine communications
Publication Date: 2018.12.26 ICTK HLDG CO
  • EP3206330B1 patent drawingFigure 1
  • EP3206330B1 patent drawingFigure 2
  • EP3206330B1 patent drawingFigure 3

AI summary

Terminal devices that perform machine-to-machine (M2M) communication may autonomously perform password authentication by autonomously generating a personal identity number (PIN) value, which is not exposed externally, using a physical unclonable function (PUF). A terminal apparatus that performs M2M communication may include a PUF embedded in the terminal apparatus to generate an authentication key for password authentication associated with the terminal apparatus, and an authentication unit to perform the password authentication associated with the terminal apparatus using the authentication key generated by the PUF.