PUF-Based Hardware Integrity Verification via Zero Knowledge Proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing sub-component authentication protocols fail to establish a system-wide identity from individual components and lack effective methods for detecting hardware tampering and ensuring the security of private information, leading to potential masquerading by adversaries.

Innovation Solution

The use of physical unclonable functions (PUFs) in conjunction with zero knowledge proof protocols for individual and collaborative verification of subcomponents, enabling the deduction of system integrity through local proofs and a hardware root-of-trust that iteratively extends trust boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing sub-component authentication protocols are used to verify private information possession, then authentication can be performed, but hardware integrity cannot be reliably detected and private information security is compromised

Engineering Contradiction:
Improvehardware integrity detectionVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional cryptographic authentication mechanisms (software-based private key verification) with a physics-based approach using Physical Unclonable Functions. The PUF leverages inherent physical variations in semiconductor manufacturing to create a hardware-rooted authentication mechanism that is inherently tied to the physical device, eliminating the need for stored private keys and providing tamper-evident authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces PUF challenge-response pairs as an intermediary mechanism between the verifier and the hardware. Instead of directly verifying private information possession, the system uses PUF challenges that interact with the physical hardware to generate responses, creating a mediator layer that proves hardware integrity without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private information is stored in subcomponents for authentication, then authentication protocols can function, but security is compromised if private information is compromised

Engineering Contradiction:
Improveauthentication operationVSAvoidprivate information compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and eliminates the need for storing private information in the authenticated device. Instead of storing sensitive cryptographic keys locally, the system uses PUF to generate authentication credentials on-demand from physical characteristics, removing the vulnerable element (stored private information) while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs ephemeral challenge-response pairs that are generated and discarded for each authentication session. Rather than relying on long-term stored secrets, the system uses temporary, single-use authentication credentials derived from PUF, making compromise of individual credentials insignificant to overall system security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Strength

If physical construction is designed to deter tampering, then hardware security is improved, but integrity of physical construction is not inextricably linked to device integrity

Engineering Contradiction:
Improvetamper resistanceVSAvoiddevice integrity linkage
Core Design Contradiction:
StrengthVSReliability

Solution Approach 1:

The patent merges the authentication mechanism directly with the physical hardware structure through PUF. The PUF is implemented as an intrinsic part of the semiconductor device, where the authentication capability is physically embedded in the hardware's manufacturing variations. This creates an inextricable link between device integrity and authentication functionality, as the PUF response changes if the physical structure is tampered with.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9715590B2System and device for verifying the integrity of a system from its subcomponents
Publication Date: 2017.07.25 ANALOG DEVICES INC
  • US9715590B2 patent drawing
  • US9715590B2 patent drawing
  • US9715590B2 patent drawing

AI summary

A system and device for verifying the integrity of a system from its subcomponents, the system comprising a plurality of subcomponents each having a physical state, the system and the device comprising a processor that is connected to each of the subcomponents, the processor configured to verify systemic integrity by performing verification on some or all specified subcomponents. The verification may be individual (1,1) or threshold (n,1), and may be interactive or non-interactive.