Digital File Authentication Through PUF Challenge-Response Protocols
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional blockchain-based authentication schemes for digital files are complex, computationally intensive, and vulnerable to interception, especially in distributed networks, and they require secure storage of cryptographic keys which can be stolen.
Innovation Solution
Convert a digital file into a challenge-response-pair (CRP) mechanism using a PUF-based system, where the file is encrypted, concatenated with a nonce, and subjected to one-way functions to generate cryptographic components for authentication, allowing key generation and verification with low computing power.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional blockchain-based authentication schemes are used, then digital file authenticity can be verified, but the process becomes complex and computationally intensive
Solution Approach 1:
The patent extracts the cryptographic key generation function from the file storage system by introducing a separate PUF-based key generation mechanism. The file is stored as ciphertext without embedded keys, and keys are generated on-demand through challenges applied to PUFs, separating the authentication function from the data storage function and reducing overall system complexity.
Solution Approach 2:
The patent introduces PUFs as an intermediary component between the file storage system and authentication mechanism. Instead of directly embedding cryptographic keys in files or using complex blockchain verification, the system uses PUFs as a mediator that generates keys through challenge-response pairs, simplifying the authentication process while maintaining security.
2Reliability
If conventional blockchain-based authentication schemes are used, then digital file authenticity can be verified, but considerable computing resources are required
Solution Approach 1:
The patent employs ephemeral PUF-based keys that are generated on-demand and discarded after use. Instead of using persistent cryptographic keys that require continuous verification, the system generates temporary keys through PUF challenges for each authentication operation, reducing cumulative computational burden while maintaining security through the unclonable nature of PUFs.
3Reliability
If private keys are stored securely, then authentication can be performed, but the keys can still be stolen
Solution Approach 1:
The patent extracts the key storage function from the system by eliminating persistent key storage entirely. Instead of storing private keys that could be stolen, the system stores only the file ciphertext and uses PUF-based key generation that creates keys temporarily during authentication operations, removing the storage vulnerability while maintaining authentication capability.
Solution Approach 2:
The patent performs preliminary key generation through PUF challenges before any authentication operation. The PUFs are pre-configured with unique characteristics, and keys are generated on-demand through challenges applied to these pre-configured PUFs, ensuring that no persistent keys exist that could be stolen, while still providing secure authentication when needed.
4Reliability
If PUF-based key generation is used, then secure key storage is achieved, but physical access to PUF is required
Solution Approach 1:
The patent introduces PUFs as an intermediary component that bridges the gap between secure key generation and operational accessibility. The PUFs are embedded in the device's hardware architecture, allowing key generation through software-based challenges without requiring direct physical access to the PUFs themselves, thus maintaining both security and ease of operation.
Data Source
AI summary
A method and arrangement for converting a digital file into a cryptographic challenge-response-pair mechanism is disclosed. An encrypted digital file is concatenated with a random nonce and subject to one-way cryptographic functions and/or extended output functions such that a result C* is obtained having a known bit length. This result is organized into a series of addressable segments. A random seed is generated and is used to derive a random bit stream that is parsed into segments, each of which is read as an address in C*. These segments are applied as challenges to C*, and the corresponding responses may be used as or to generate or store an encryption key.


