PUF Authentication Server Using Statistical Distribution Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods using Physically Unclonable Functions (PUFs) face challenges in achieving high accuracy with a small number of data samples and are costly to implement, especially in low-cost devices like Field-Programmable Gate Arrays (FPGAs), due to the need for repeated measurements and the complexity of feedback circuits.

Innovation Solution

An authentication system that evaluates the distribution of ID data generated by a PUF circuit, using statistical methods such as random walk tests to authenticate devices with a small number of data samples, thereby reducing the need for extensive repetition and costly feedback circuits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If repeated measurements are performed to improve authentication accuracy, then measurement precision is improved, but loss of time increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-calculating and storing the distribution characteristics (mean and variance) of PUF ID data during device manufacturing or initial setup. When authentication is needed, the system only needs to compare new measurements against these pre-established distributions rather than performing repeated measurements to establish baselines, thus achieving high accuracy with fewer measurements and reduced time loss.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If feedback circuits are added to improve PUF reproductivity, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovePUF reproductivityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical feedback circuit approach with a statistical processing system. Instead of using physical feedback circuits to force PUF outputs to match desired values, the system uses statistical methods (comparing distributions of ID data against pre-stored characteristics) to achieve reliable authentication, thereby reducing device complexity while maintaining or improving reproductivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If a large number of data samples are collected to improve authentication accuracy, then measurement precision is improved, but productivity decreases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidauthentication throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial action by using only the essential statistical parameters (mean and variance of ID data distribution) rather than analyzing complete large datasets. This allows the system to achieve high authentication accuracy with a small number of data samples, thereby maintaining high productivity and authentication throughput while avoiding the need to process extensive data volumes.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10218518B2Authentication server, authentication system, and authentication method
Publication Date: 2019.02.26 KK TOSHIBA
  • US10218518B2 patent drawing
  • US10218518B2 patent drawing
  • US10218518B2 patent drawing

AI summary

An authentication server according to embodiments performs statistical processing on a plurality of pieces of ID data acquired from an electronic device including a PUF circuit generating the pieces of ID data (S1052 to S1071), determines whether the plurality of pieces of ID data are physical random numbers based on a result of the statistical processing (S1072), and when the plurality of pieces of ID data are determined to be physical random numbers, recognizes the result of authentication of the electronic device as a success of authentication (S1073), and when the plurality of pieces of ID data are determined not to be physical random numbers, recognizes a result of authentication of the electronic device as a failure of authentication (S1074).