PUF-Based Hardware OTP for Secure 2-Factor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing OTP providing devices are vulnerable to security attacks such as debugging port and internal memory attacks, software hacking, and are at risk of certificate authentication replication and personal information leakage, which can lead to financial losses in electronic payment and mobile banking systems.
Innovation Solution
A hardware-based one-time password (OTP) providing apparatus that incorporates a physically unclonable function (PUF) to generate OTP values directly through hardware, eliminating the need for software processing and making it impossible to replicate, thereby enhancing security against physical and software-based attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based OTP providing apparatus is used, then ease of operation is improved, but reliability deteriorates due to vulnerability to security attacks
Solution Approach 1:
The patent replaces software-based OTP generation with hardware-based PUF (Physically Unclonable Function) implementation. The PUF utilizes physical characteristics of semiconductor structures (such as variations in transistor thresholds or inter-layer contact positions) to generate OTP values, substituting the software processing system with a hardware system that is inherently resistant to software hacking and debugging attacks.
Solution Approach 2:
The patent combines multiple security layers: a secure element (SE) for certificate authentication and a PUF-based hardware OTP generator for additional security. This composite approach integrates two different authentication mechanisms (certificate-based and PUF-based) to create a multi-factor authentication system that addresses the weaknesses of each individual approach.
2Reliability
If hardware-based PUF OTP providing apparatus is used, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent merges the PUF-based OTP generation functionality with the existing secure element (SE) structure. By integrating the PUF function within the SE or alongside it in a unified hardware module, the patent reduces the need for separate independent hardware components, thereby managing device complexity while maintaining enhanced security and reliability.
3Ease of operation
If common secure element is used for authentication, then ease of operation is improved, but object-affected harmful factors increase due to replication risk
Solution Approach 1:
The patent replaces the file-based certificate authentication system in common SE with a hardware-based PUF authentication mechanism. The PUF utilizes physical characteristics of semiconductor structures (such as variations in transistor thresholds or inter-layer contact positions) to generate authentication values that cannot be replicated or extracted through software attacks, thereby substituting the vulnerable software-based authentication with a physically secure hardware mechanism.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
Provided is an apparatus for generating a hardware-based OTP which is impossible to duplicate. The apparatus for generating the OTP can comprise a PUF for generating a unique PIN. In addition, provided is a method which is used for 2-Factor authentication with the apparatus for generating the OTP and existing secure elements.