PUF-Based ID Generation Device for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PUF technologies fail to guarantee perfect individual identifiability, especially under environmental variations and aging, leading to potential ID value duplication and decreased yield in mass-produced devices.

Innovation Solution

An identification information generation device that separates cryptographic keys and identification information bits from PUF output, connects them with unique device-specific information, and encrypts the result using part of the PUF output as a key to ensure unclonability, response repeatability, and individual identifiability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PUF circuit is used to generate ID values based on physical characteristics, then unclonability and unpredictability are achieved, but response repeatability and individual identifiability cannot be guaranteed under environmental variations and aging

Engineering Contradiction:
Improveresponse repeatabilityVSAvoidenvironmental variation resistance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The PUF output bits are segmented into two parts: a first part used as cryptographic key material and a second part used as stable identification information. This segmentation allows the system to utilize the unpredictable nature of PUF outputs for security while relying on the stable second part for reliable device identification across environmental variations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hash function is introduced as an intermediary to process the PUF output bits. The hash function converts the raw PUF output into stable identification information that maintains consistency despite environmental variations, thereby mediating between the unstable physical characteristics and the required reliable identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PUF output bits are used directly as ID values, then unclonability is achieved, but individual identifiability may be compromised due to potential duplication under environmental changes

Engineering Contradiction:
Improveindividual identifiabilityVSAvoidID value duplication risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary processing of PUF output bits through hashing and segmentation before using them for device identification. This preliminary action ensures that the resulting identification information is stable and unique, preventing ID value duplication even when environmental conditions change during device operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms the raw PUF output parameters through cryptographic hashing and selective bit extraction. This parameter transformation converts the physically variable PUF characteristics into stable digital identification parameters that resist environmental influences and ensure unique device identification.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cryptographic keys are stored in NVRAM or set by blowing fuses, then device authentication is enabled, but security against physical attacks and side channel attacks is compromised

Engineering Contradiction:
Improvesecurity against physical attacksVSAvoidID setting complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The PUF circuit automatically generates cryptographic key material through its inherent physical characteristics without requiring external programming or configuration. The circuit serves itself by utilizing manufacturing variations to produce unique, secure keys that are inherently tied to the device's physical structure, eliminating the need for vulnerable storage mechanisms like NVRAM or fuse blowing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9590804B2Identification information generation device and identification information generation method
Publication Date: 2017.03.07 NEC CORP
  • US9590804B2 patent drawing
  • US9590804B2 patent drawing
  • US9590804B2 patent drawing

AI summary

Provided is an identification information generation device capable of generating identification information with its complete individual identifiability guaranteed. The identification information generation device comprises: an information separation means for separating a cryptographic key of k bits (k is an integer equal to or larger than 1) and second identification information of (r−m) bits (m is an integer equal to or larger than 1) from first identification information of r bits (r is an integer equal to or larger than 2) outputted from an identification information output means which is impossible to physically duplicated and outputs the same response to the same request for response; an information connection means for outputting fourth identification information by connecting the second identification information with third identification information of m bits capable of identifying x devices; and an encryption means for generating fifth identification information of r bits by performing predetermined processing on the fourth identification information by the use of the cryptographic key.