PUF-Based ID Generation Device for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PUF technologies fail to guarantee perfect individual identifiability, especially under environmental variations and aging, leading to potential ID value duplication and decreased yield in mass-produced devices.
Innovation Solution
An identification information generation device that separates cryptographic keys and identification information bits from PUF output, connects them with unique device-specific information, and encrypts the result using part of the PUF output as a key to ensure unclonability, response repeatability, and individual identifiability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a PUF circuit is used to generate ID values based on physical characteristics, then unclonability and unpredictability are achieved, but response repeatability and individual identifiability cannot be guaranteed under environmental variations and aging
Solution Approach 1:
The PUF output bits are segmented into two parts: a first part used as cryptographic key material and a second part used as stable identification information. This segmentation allows the system to utilize the unpredictable nature of PUF outputs for security while relying on the stable second part for reliable device identification across environmental variations.
Solution Approach 2:
A hash function is introduced as an intermediary to process the PUF output bits. The hash function converts the raw PUF output into stable identification information that maintains consistency despite environmental variations, thereby mediating between the unstable physical characteristics and the required reliable identification.
2Reliability
If PUF output bits are used directly as ID values, then unclonability is achieved, but individual identifiability may be compromised due to potential duplication under environmental changes
Solution Approach 1:
The system performs preliminary processing of PUF output bits through hashing and segmentation before using them for device identification. This preliminary action ensures that the resulting identification information is stable and unique, preventing ID value duplication even when environmental conditions change during device operation.
Solution Approach 2:
The patent transforms the raw PUF output parameters through cryptographic hashing and selective bit extraction. This parameter transformation converts the physically variable PUF characteristics into stable digital identification parameters that resist environmental influences and ensure unique device identification.
3Reliability
If cryptographic keys are stored in NVRAM or set by blowing fuses, then device authentication is enabled, but security against physical attacks and side channel attacks is compromised
Solution Approach 1:
The PUF circuit automatically generates cryptographic key material through its inherent physical characteristics without requiring external programming or configuration. The circuit serves itself by utilizing manufacturing variations to produce unique, secure keys that are inherently tied to the device's physical structure, eliminating the need for vulnerable storage mechanisms like NVRAM or fuse blowing.
Data Source
AI summary
Provided is an identification information generation device capable of generating identification information with its complete individual identifiability guaranteed. The identification information generation device comprises: an information separation means for separating a cryptographic key of k bits (k is an integer equal to or larger than 1) and second identification information of (r−m) bits (m is an integer equal to or larger than 1) from first identification information of r bits (r is an integer equal to or larger than 2) outputted from an identification information output means which is impossible to physically duplicated and outputs the same response to the same request for response; an information connection means for outputting fourth identification information by connecting the second identification information with third identification information of m bits capable of identifying x devices; and an encryption means for generating fifth identification information of r bits by performing predetermined processing on the fourth identification information by the use of the cryptographic key.


