PUF Key Reconstruction Using Helper Data for Noise Reliability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physical unclonable functions (PUFs) produce unpredictable and device-unique responses but are susceptible to measurement noise and environmental influences, which can compromise the reliability and security of cryptographic keys, necessitating post-processing to correct for noise and ensure key consistency.

Innovation Solution

The use of fuzzy extractors, which include an enrollment stage to derive and store helper data from PUF responses, and a reconstruction stage to reevaluate and correct these responses, ensuring identical key derivation while maintaining helper data as public and non-sensitive, thereby reducing information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PUF responses are used directly to generate cryptographic keys, then device uniqueness and unpredictability are achieved, but measurement noise and environmental influences compromise reliability and key consistency

Engineering Contradiction:
Improvekey consistencyVSAvoidmeasurement noise
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces helper data as an intermediary between the noisy PUF response and the cryptographic key. The helper data contains correction information that mediates the transformation from noisy PUF output to reliable, consistent cryptographic keys across multiple uses while maintaining security properties

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary processing of PUF responses during an enrollment phase, where helper data is generated and stored before actual key usage. This preliminary action prepares the system to correct noise in future operations, ensuring reliability without requiring real-time complex processing

Inventive Principle:
Principle #10Preliminary action

2Reliability

If post-processing is applied to correct PUF noise, then key reliability improves, but additional handling may introduce security risks and information leakage

Engineering Contradiction:
Improvekey consistencyVSAvoidsecurity risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potentially harmful helper data into a beneficial element by designing it to contain only public, non-sensitive information that aids in noise correction without revealing cryptographic secrets. The helper data structure itself becomes a security feature by separating public correction information from private key material

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent applies different quality requirements to different parts of the system: the helper data is designed to be public and non-sensitive (lower security requirement), while the cryptographic key remains private and highly sensitive (higher security requirement). This local differentiation of security properties allows noise correction without compromising key security

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11218306B2Cryptographic device having physical unclonable function
Publication Date: 2022.01.04 SYNOPSYS INC
  • US11218306B2 patent drawing
  • US11218306B2 patent drawing
  • US11218306B2 patent drawing

AI summary

Some embodiments are directed to an electronic cryptographic device arranged to determine a cryptographic key. The cryptographic device can include a physically unclonable function (PUF) arranged to produce a first noisy bit string during the enrollment phase and a second noisy bit string during the reconstruction phase, and a statistical unit arranged to execute a statistical test for verifying correct functioning of the physical unclonable function. The statistical test computes a statistical parameter for the physical unclonable function using helper data. The statistical test determines correct functioning if the statistical parameter satisfies a criterion of the statistical test.