PUF-Based Data Protection via Challenge-Response Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods require expensive tamper-resistant storage for encryption keys, and rely on trusted parties for key management, which is insecure and costly.

Innovation Solution

The use of Physically Unclonable Functions (PUFs) as secret keys and keystream generators within an encryption black-box, eliminating the need for external tamper-resistant storage and ensuring only the black-box can decrypt data, with error correction and integrity protection using N-modular redundancy and PUF-based Message Authentication Codes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tamper-resistant storage is used to store encryption keys, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The PUF generates cryptographic keys internally from its unique physical characteristics without requiring external key storage. The key is derived on-demand from the PUF's response to a challenge, eliminating the need for separate tamper-resistant key storage hardware and reducing overall system cost while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The PUF acts as an intermediary that converts physical manufacturing variations into cryptographic keys. Instead of directly storing keys in expensive secure hardware, the system uses the PUF as a mediator that generates keys from its inherent physical properties, achieving secure key management at lower cost

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If sealing keys are entered into the sealing device, then key management is simplified, but trust requirements increase

Engineering Contradiction:
Improvekey managementVSAvoidtrust
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The PUF automatically generates cryptographic keys based on its unique physical characteristics when presented with a challenge. No manual key entry or external key distribution is needed, and no party needs to trust another party with key management since the key is generated locally and never leaves the device in usable form

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secret key is extracted from the PUF's physical characteristics rather than being stored or transmitted. The key exists only as the PUF's response to a specific challenge, and the PUF itself cannot be copied or cloned, removing the need for trusted key distribution channels

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If PUF is used for key generation, then cost is reduced, but fault tolerance requirements increase

Engineering Contradiction:
ImprovecostVSAvoidfault tolerance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system uses N different PUFs, each generating a portion of the cryptographic key. This segmentation allows the system to tolerate failures in individual PUFs, as long as a sufficient number of PUFs remain functional to reconstruct the key, thereby improving fault tolerance while maintaining the cost benefits of using PUFs

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Provides secure, tamper-resistant, and cost-effective data protection without relying on trusted parties, tolerating transient faults and ensuring only the encryption black-box can access the data, thus preventing unauthorized decryption.

Implementation Method 1

A Physically Unclonable Function, PUF, is a physical entity embodied in a physical device which exploits the inherent process variations in the physical device to produce a response which is easy to compute by the PUF, but hard to predict for a PUF-external entity

Methodology Applied
Scientific EffectPhysically Unclonable Function:

Data Source

PatentEP3577642B1Methods and devices for protecting data
Publication Date: 2023.07.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3577642B1 patent drawingFigure 1~3
  • EP3577642B1 patent drawingFigure 4~6
  • EP3577642B1 patent drawingFigure 7

AI summary

A method (20) performed by a device (1) for protecting data is provided. The method (20) comprises inputting (21), to a Physically Unclonable Function, PUF, (3), of the device (1), a challenge; obtaining (22), from the PUF (3), a response; and protecting (23) the data by using the response. A device (1), a method in an encryption unit, computer program and computer program product are also provided.