PUF Hardware Fingerprinting for Device Subversion Deterrence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information processing systems are vulnerable to subversive attacks through the substitution of components with 'look-alike' devices that can disrupt operations, as existing physical system protection schemes are technically difficult and expensive to implement, and trusted foundry processing only imparts trust during the fabrication phase, lacking rigorous authentication during the deployment phase.

Innovation Solution

The implementation of a unique 'device fingerprint' and cryptographic challenge/response protocol using Physical Unclonable Function (PUF) technology, which leverages random physical characteristics of hardware devices to authenticate and deter subversion by substitution, ensuring authenticity throughout the component's life cycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical system protection schemes are used to prevent subversive attacks, then security against component substitution is improved, but implementation complexity and cost increase significantly

Engineering Contradiction:
Improvesecurity against component substitutionVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses the device's own inherent physical characteristics (manufacturing variations, material properties) to generate its authentication fingerprint, eliminating the need for external protection schemes. The device authenticates itself through its unique physical identity rather than requiring complex external verification infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces complex physical protection schemes (mechanical security measures, physical security infrastructure) with a cryptographic authentication system based on physical unclonable functions. This substitutes physical/mechanical protection with an information-theoretic security approach that is simpler to implement and more scalable.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If trusted foundry processing is used during fabrication, then trust is established during manufacturing, but authentication during deployment phase is lacking

Engineering Contradiction:
Improvetrust during fabrication phaseVSAvoidauthentication coverage time
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The authentication mechanism is built into the device during fabrication through the trusted foundry process, where the physical unclonable function characteristics are established and registered. This preliminary authentication capability is then carried forward through deployment, allowing continuous verification without requiring re-establishment of trust at each phase transition.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates the authentication function from the functional components of the device. The PUF-based authentication subsystem operates independently from the main device functionality, allowing trust verification to be performed separately and continuously throughout the device lifecycle without interfering with normal operations.

Inventive Principle:
Principle #1Segmentation

3Object-generated harmful factors

If component substitution with look-alike devices occurs, then undetected subversion is possible, but detection capability is insufficient

Engineering Contradiction:
Improvesubversion capabilityVSAvoiddetection capability
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The system changes the 'identity signature' or cryptographic fingerprint of each device based on its unique physical characteristics. Just as color changes can reveal hidden objects, the unique PUF-based fingerprint makes each device distinctly identifiable, causing substituted look-alike devices to reveal their false identity through mismatched authentication credentials.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces a cryptographic challenge-response protocol as an intermediary verification mechanism between the device and the system it serves. This intermediary process actively tests the device's physical characteristics and authentication credentials, making it difficult for substituted devices to pass undetected while maintaining seamless operation for legitimate devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enhances the trustworthiness of deployed information processing systems by providing a robust authentication mechanism that prevents subversion and counterfeiting, allowing for the detection of tampering and attribution of subversions, thereby protecting against sophisticated adversaries.

Implementation Method 1

Physical Unclonable Function (PUF) technology may be leveraged to deter adversaries from attempting subversion by insertion of subversive functionality and also by instantiation of counterfeit components (subversion via substitution). PUFs are derived from the inherently random, physical characteristics of the material, component, or system from which they are sourced, which makes the output of a PUF physically or computationally very difficult to predict.

Methodology Applied
Scientific EffectPhysical Unclonable Function:

Data Source

PatentUS8848905B1Deterrence of device counterfeiting, cloning, and subversion by substitution using hardware fingerprinting
Publication Date: 2014.09.30 UT BATTELLE LLC
  • US8848905B1 patent drawing
  • US8848905B1 patent drawing
  • US8848905B1 patent drawing

AI summary

Deterrence of device subversion by substitution may be achieved by including a cryptographic fingerprint unit within a computing device for authenticating a hardware platform of the computing device. The cryptographic fingerprint unit includes a physically unclonable function (“PUF”) circuit disposed in or on the hardware platform. The PUF circuit is used to generate a PUF value. A key generator is coupled to generate a private key and a public key based on the PUF value while a decryptor is coupled to receive an authentication challenge posed to the computing device and encrypted with the public key and coupled to output a response to the authentication challenge decrypted with the private key.