PUF Circuit Unique Identifier Generation for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-cost integrated circuits, such as those used in IoT devices, face challenges in providing cryptographic capabilities without increasing complexity and cost, as they often lack necessary circuitry, which can impair functionality.
Innovation Solution
A hardware/software-based system that extracts entropy from manufacturing variability in silicon devices to generate a unique identifier or private key using Physically Unclonable Function (PUF) circuitry, eliminating the need for non-volatile storage and allowing for dynamic generation and regeneration of random numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic capabilities are added to low-cost integrated circuits, then security is improved, but device complexity and cost increase
Solution Approach 1:
The PUF circuit utilizes inherent manufacturing variations in the silicon device itself to generate cryptographic keys, eliminating the need for separate key generation and storage hardware. The device serves its own cryptographic needs through its natural physical characteristics, avoiding additional complexity while maintaining security
Solution Approach 2:
The PUF circuit serves multiple functions: it generates unique device identifiers, provides cryptographic keys, and enables security protocols all through a single hardware component that leverages manufacturing variations, reducing overall system complexity compared to dedicated cryptographic modules
2Device complexity
If non-volatile storage is removed from integrated circuits, then device complexity and cost are reduced, but the ability to store unique identifiers and cryptographic keys is impaired
Solution Approach 1:
Instead of storing cryptographic keys statically in non-volatile memory, the PUF circuit dynamically generates keys based on current manufacturing variations. The cryptographic capability becomes a dynamic process rather than a static stored value, eliminating storage requirements while maintaining security functionality
Solution Approach 2:
The PUF circuit acts as an intermediary between the physical manufacturing variations and the cryptographic system. It translates inherent silicon variations into usable cryptographic keys without requiring storage, serving as a bridge that converts physical characteristics into functional security credentials
3Ease of manufacture
If design simplification is implemented in integrated circuits, then manufacturing cost and time to market are reduced, but cryptographic functionality is impaired
Solution Approach 1:
The patent converts the harmful effect of manufacturing variations (which create inconsistency) into a beneficial cryptographic key generation mechanism. The very variations that complicate manufacturing become the source of secure, unique cryptographic identifiers, eliminating the need for additional security circuitry
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach simplifies chip design, reduces complexity, and provides flexible, secure cryptographic capabilities without the need for non-volatile storage, enabling faster time to market and lower costs while maintaining security and functionality.
Implementation Method 1
extracts entropy from manufacturing variability in silicon devices to generate a unique identifier or private key using Physically Unclonable Function (PUF) circuitry
Data Source
AI summary
In one embodiment, an apparatus includes: a device having a physically unclonable function (PUF) circuit including a plurality of PUF cells to generate a PUF sample responsive to at least one control signal; a controller coupled to the device, the controller to send the at least one control signal to the PUF circuit and to receive a plurality of PUF samples from the PUF circuit; a buffer having a plurality of entries each to store at least one of the plurality of PUF samples; and a filter to filter the plurality of PUF samples to output a filtered value, wherein the controller is to generate a unique identifier for the device based at least in part on the filtered value. Other embodiments are described and claimed.


