PUF-Based Multi-Factor Authentication for Hardware Spoofing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems are vulnerable to spoofing attacks due to the lack of integration of 'something you have' and 'something you are' into a single cryptographic challenge, allowing adversaries to subvert devices by replacing them with counterfeit components that can mimic the authentication process without requiring the ancillary authentication data.

Innovation Solution

The integration of Physical Unclonable Function (PUF) technology into hardware devices to create a unique multi-factor authentication value that combines 'something you know,' 'something you have,' and 'something you are' into a single cryptographic challenge, using PUFs derived from the device's physical characteristics to enhance security and detect spoofing attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If multiple authentication factors are checked in serial fashion separately, then the authentication process is simpler to implement, but the system becomes vulnerable to spoofing attacks where adversaries can subvert devices by replacing them with counterfeit components

Engineering Contradiction:
Improveauthentication process structureVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (something you know, something you have, and something you are) into a single integrated cryptographic challenge. The PUF circuit generates a challenge that incorporates all three factors simultaneously, so that the authentication response validates all factors in one operation rather than in separate serial checks. This merging eliminates the vulnerability to spoofing while maintaining implementation feasibility.

Inventive Principle:
Principle #5Merging (Combining)

2Device complexity

If ancillary authentication data are stored separately in the device, then the device structure is simpler, but adversaries can more easily spoof authentication by extracting or deducing the single secret and completing a simple cryptographic challenge

Engineering Contradiction:
Improvedata storage structureVSAvoidspoofing vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the storage and processing of multiple authentication factors into a unified cryptographic challenge structure. Rather than storing secrets separately and checking them in sequence, the system incorporates all factors into a single PUF-based challenge that must be solved together, making it computationally infeasible for adversaries to extract or deduce individual factors.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The PUF circuit acts as an intermediary that binds multiple authentication factors together in a cryptographic challenge. The PUF's physical unclonability ensures that the challenge incorporates device-specific characteristics, while the structured challenge/response mechanism ensures that all authentication factors must be satisfied simultaneously, preventing adversaries from bypassing any single factor.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If trusted foundry processing is used with rigorous procedures, then component authenticity is protected during fabrication, but enormous investments are required and trust is only maintained during the fabrication phase, not during deployment

Engineering Contradiction:
Improvecomponent authenticityVSAvoidauthentication system requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent incorporates PUF circuits into the hardware device during the fabrication phase, establishing a unique cryptographic identity for each device before deployment. This preliminary action creates a binding between the physical device and its authentication credentials, enabling continuous verification of authenticity throughout the device's operational life without requiring ongoing trusted foundry oversight or expensive physical protection schemes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8868923B1Multi-factor authentication
Publication Date: 2014.10.21 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US8868923B1 patent drawing
  • US8868923B1 patent drawing
  • US8868923B1 patent drawing

AI summary

Detection and deterrence of spoofing of user authentication may be achieved by including a cryptographic fingerprint unit within a hardware device for authenticating a user of the hardware device. The cryptographic fingerprint unit includes an internal physically unclonable function (“PUF”) circuit disposed in or on the hardware device, which generates a PUF value. Combining logic is coupled to receive the PUF value, combines the PUF value with one or more other authentication factors to generate a multi-factor authentication value. A key generator is coupled to generate a private key and a public key based on the multi-factor authentication value while a decryptor is coupled to receive an authentication challenge posed to the hardware device and encrypted with the public key and coupled to output a response to the authentication challenge decrypted with the private key.