PUF-Based Hardware OTP for Secure 2-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OTP providing devices are vulnerable to security attacks such as debugging port and internal memory attacks, software hacking, and are at risk of certificate authentication replication and personal information leakage, which can lead to financial losses in electronic payment and mobile banking systems.

Innovation Solution

A hardware-based one-time password (OTP) providing apparatus that incorporates a physically unclonable function (PUF) to generate OTP values directly through hardware, eliminating the need for software processing and making it impossible to replicate, thereby enhancing security against physical and software-based attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based OTP providing apparatus is used, then ease of operation is improved, but reliability deteriorates due to vulnerability to security attacks

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based OTP generation with hardware-based PUF (Physically Unclonable Function) implementation. The PUF utilizes physical characteristics of semiconductor structures (such as variations in transistor thresholds or inter-layer contact positions) to generate OTP values, substituting the software processing system with a hardware system that is inherently resistant to software hacking and debugging attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent combines multiple security layers: a secure element (SE) for certificate authentication and a PUF-based hardware OTP generator for additional security. This composite approach integrates two different authentication mechanisms (certificate-based and PUF-based) to create a multi-factor authentication system that addresses the weaknesses of each individual approach.

Inventive Principle:
Principle #40Composite materials

2Reliability

If hardware-based PUF OTP providing apparatus is used, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the PUF-based OTP generation functionality with the existing secure element (SE) structure. By integrating the PUF function within the SE or alongside it in a unified hardware module, the patent reduces the need for separate independent hardware components, thereby managing device complexity while maintaining enhanced security and reliability.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If common secure element is used for authentication, then ease of operation is improved, but object-affected harmful factors increase due to replication risk

Engineering Contradiction:
Improveease of operationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the file-based certificate authentication system in common SE with a hardware-based PUF authentication mechanism. The PUF utilizes physical characteristics of semiconductor structures (such as variations in transistor thresholds or inter-layer contact positions) to generate authentication values that cannot be replicated or extracted through software attacks, thereby substituting the vulnerable software-based authentication with a physically secure hardware mechanism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3598696B1Apparatus for providing PUF-based hardware OTP and method for authenticating 2-factor using same
Publication Date: 2025.03.05 ICTK HLDG CO
  • EP3598696B1 patent drawingFigure 1~2
  • EP3598696B1 patent drawingFigure 3~4
  • EP3598696B1 patent drawingFigure 5~6

AI summary

Provided is an apparatus for generating a hardware-based OTP which is impossible to duplicate. The apparatus for generating the OTP can comprise a PUF for generating a unique PIN. In addition, provided is a method which is used for 2-Factor authentication with the apparatus for generating the OTP and existing secure elements.