PUF Data Generator Security via Verification Feedback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data generating devices using physically unclonable functions (PUFs) face security risks due to the potential for attacks when second data is obtained from outside the device, as it can lead to inference of device-specific first data or generated third data, such as cryptographic keys, especially when falsified second data is repeatedly input.
Innovation Solution
A data generating device is configured with a first generator for producing device-specific first data, an obtainer for obtaining second data from outside, a second generator for producing third data based on first and second data, and a verifier to ensure correctness, with an operation selector that regenerates first data, re-obtains second data, or disables the device if incorrect third data is detected, following predetermined selection rules to mitigate attack risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If second data is obtained from outside the device to reduce memory area and manufacturing cost, then device complexity and cost are reduced, but security reliability deteriorates due to risk of attacks using falsified second data
Solution Approach 1:
The patent implements a feedback mechanism where the verifier continuously monitors the third data generated from second data. When verification fails, the system detects abnormal behavior and triggers countermeasures such as disabling the device or alerting the user. This feedback loop enables the system to respond to attack patterns, transforming a static security system into a dynamic one that adapts to threat conditions.
Solution Approach 2:
The patent performs preliminary verification of second data before using it to generate third data. The verifier is activated in advance to check the validity of incoming second data, preventing potentially malicious data from entering the data generation process. This preliminary action stops attacks before they can compromise the system.
2Reliability
If verification of third data is performed to ensure security, then security reliability is improved, but device complexity increases due to additional verification mechanisms
Solution Approach 1:
The verifier component is designed with multi-functionality, serving multiple purposes: verifying the correctness of third data, detecting attack patterns, triggering security countermeasures, and providing system monitoring. By making the verification mechanism universal, the patent reduces the need for separate dedicated components for each function, thereby limiting the increase in device complexity.
3Reliability
If the device disables itself upon verification failure to prevent attacks, then security reliability is improved, but productivity decreases due to operational interruptions
Solution Approach 1:
The patent implements dynamic security responses rather than static disabling. The system adjusts its behavior based on the severity and pattern of verification failures, offering graduated responses such as warnings, temporary restrictions, or selective disabling. This dynamic approach allows the system to maintain productivity during minor issues while preserving security against serious attacks.
Data Source
AI summary
According to an embodiment, a data generating device includes a first generator, an obtainer, a second generator, a verifier, and an operation selector. The first generator generates device-specific first data. The obtainer obtains second data from outside of the data generating device. The second generator generates third data based on the first data and the second data. The verifier verifies correctness of the third data. When the third data is determined to be incorrect, the operation selector selects at least one of regenerating the first data, re-obtaining the second data, and disabling the data generating device according to a predetermined selection rule.


