PUF-Based Cryptographic Device With Server-Side Error Correction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic devices require expensive key programming and non-volatile memory for authentication, which can be vulnerable to attacks and counterfeiting, and there is a need for efficient error correction in physically unclonable functions (PUFs) to ensure secure key generation and storage.
Innovation Solution
An electronic cryptographic device generates PUF data during an enrollment phase, which includes helper data for noise correction, and sends it to a server for later use, allowing the server to recognize and correct PUF outputs, eliminating the need for non-volatile memory and reducing the costly personalization step during manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If keys are programmed into OTP and/or non-volatile memory for device authentication, then secure connections can be established, but the process is expensive and requires costly personalization steps during manufacturing
Solution Approach 1:
The patent extracts the key storage function from non-volatile memory and OTP programming, replacing it with PUF-based key generation. The PUF generates cryptographic keys dynamically without requiring expensive personalization equipment or non-volatile memory, thereby reducing manufacturing costs while maintaining security.
Solution Approach 2:
The patent substitutes the mechanical/electrical key programming process with a physical phenomenon-based PUF approach. Instead of programming keys into memory cells, the system exploits physical variations in manufacturing to create unique cryptographic identifiers, eliminating the need for costly OTP programming equipment.
2Ease of manufacture
If PUFs are used to generate cryptographic keys, then the need for secure memory and costly key programming is eliminated, but manufacturing variations introduce noise and errors in the PUF output
Solution Approach 1:
The patent performs preliminary action by collecting multiple PUF outputs during an enrollment phase before the actual authentication is needed. These preliminary samples are used to generate helper data and establish a reference model, allowing the system to compensate for manufacturing variations and noise in subsequent authentication operations.
Solution Approach 2:
The patent implements feedback mechanisms where the system continuously refines its understanding of the PUF characteristics by comparing multiple outputs and adjusting the helper data accordingly. This feedback loop enables the system to correct for manufacturing variations and maintain high authentication accuracy despite physical process noise.
3Manufacturing precision
If helper data is stored on the device to correct PUF noise, then PUF output accuracy is improved, but the device requires additional non-volatile memory storage
Solution Approach 1:
The patent makes the helper data dynamic by storing it externally (e.g., in a database or cloud system) rather than permanently in the device's non-volatile memory. The helper data is retrieved only when needed for authentication, allowing the system to maintain high PUF output accuracy without permanently occupying additional storage space on the device.
4Reliability
If error correction procedures are applied to PUF outputs, then authentication reliability is improved, but processing time and computational complexity increase
Solution Approach 1:
The patent performs error correction preparation in advance during the enrollment phase, where helper data is pre-computed and stored. During actual authentication, the system only needs to retrieve and apply the pre-computed help data, significantly reducing the processing time and computational complexity compared to performing full error correction procedures in real-time.
Data Source
Figure 1a~1b
Figure 2
Figure 3a~3b
AI summary
An electronic cryptographic device (100) comprising a physically unclonable function (PUF) (110) and an enrollment unit (142) arranged to generate a first PUF data during the enrollment phase, the first PUF data being derived from a first noisy bit string of the PUF, the first PUF data uniquely identifying the physically unclonable function, the first PUF data comprising a first helper data. The first PUF data is transmitted to an electronic server during an enrollment phase. The device comprises a use-phase unit (144) arranged to generate a second PUF data derived from a second noisy bit string during a use phase. The first helper data is received from the server in response to transmitting the second PUF data. An error corrector (160) is arranged to apply the first helper data to the second noisy bit string.