PUF Authentication Without Error Correction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional physical unclonable function (PUF) authentication systems are sensitive to aging and noise, requiring error correction codes that are costly and impractical, especially for devices with limited resources, and are vulnerable to security threats due to storage of PUF values.
Innovation Solution
The system uses high-resolution analog PUF values, compares them using a distance calculation without error correction, and employs cryptographic techniques like garbled circuits to authenticate devices securely without revealing new PUF values, while adjusting for aging and noise by tracking and compensating for drift in PUF values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If error correction codes are applied to PUF values to handle aging and noise, then authentication reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts only the essential authentication function from the PUF system, comparing raw PUF output values directly against stored reference values without applying error correction codes. This removes the complexity of error correction while maintaining authentication reliability through direct threshold-based comparison of the PUF characteristics.
Solution Approach 2:
The patent uses simple, inexpensive comparison logic instead of complex error correction codes. The authentication mechanism relies on basic threshold comparison that can be implemented with minimal hardware resources, making it suitable for resource-constrained devices while maintaining adequate reliability for authentication purposes.
2Ease of operation
If PUF values are stored for authentication comparison, then authentication functionality is enabled, but security is worsened due to vulnerability to data theft
Solution Approach 1:
The patent introduces secure storage mechanisms and controlled access protocols as intermediaries between the PUF values and the authentication comparison process. Reference values are stored in secure memory with restricted access, and the comparison process is mediated through controlled authentication routines that prevent unauthorized extraction or modification of the stored PUF values.
Solution Approach 2:
The patent implements preventive security measures by storing PUF reference values in protected memory regions with access controls before any authentication operations occur. The system preemptively safeguards against data theft through secure boot processes and encrypted storage, preventing attackers from extracting PUF values even if they gain physical access to the device.
3Measurement precision
If high-resolution analog PUF values are used instead of quantized values, then measurement precision is improved, but quantization errors occur when converting to digital format
Solution Approach 1:
The patent uses high-resolution analog-to-digital conversion with more bits than strictly necessary for basic authentication. By oversampling and using higher precision digital representation of the PUF values, the system captures more information than the minimum required, then applies threshold-based comparison that is tolerant of the inevitable quantization errors, effectively discarding the excessive precision where it becomes noise.
Solution Approach 2:
The patent changes the parameter of PUF value representation from binary quantized values to high-resolution multi-bit digital values. This parameter change allows the system to maintain better precision through the conversion process and use statistical or threshold-based comparison methods that are robust to the quantization errors introduced during analog-to-digital conversion.
Data Source
AI summary
This application describes systems and methods for using a physical unclonable function (PUF) to authenticate a device, which may include circuitry for generating PUF values that may uniquely identify the device. According to one aspect, the device may provide enrollment PUF values to an authentication device. The device may later be authenticated if PUF values generated by the device are within a threshold distance of the enrollment PUF values. Since the PUF values are compared using a distance, it may not necessary to apply an error correcting code to the PUF values. The enrollment values and/or the calculated distance may be adjusted to compensate for time variations in the PUF values due to circuit aging. Systems and methods are also described herein for authenticating the device without revealing new PUF values to any second party, for example using a cryptographic technique known as a garbled circuit.


