PUF Integrated Circuit for Dynamic Multi-Key Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuits with physically unclonable functions (PUFs) are vulnerable to external hacking due to their structure, which repeatedly generates the same security key, making them inefficient for changing keys in response to exposure or compromise.
Innovation Solution
The integrated circuit includes a PUF block, a controller, and a key generator that performs error correction and length extension operations on PUF data to generate multiple final security keys, enabling flexible key management and enhanced security by adaptively providing different keys to security devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the integrated circuit repeatedly generates the same security key using helper data stored in non-volatile memory, then the security key generation is simple and reliable, but the system becomes vulnerable to external hacking and cannot efficiently change keys when exposed or compromised
Solution Approach 1:
The patent applies dynamics by transitioning from a static key generation model to a dynamic one. The controller can now flexibly generate different final keys from the same intermediate key based on dynamic selection criteria, allowing the system to adapt to compromise scenarios and change keys without re-executing the entire enrollment phase, thus resolving the contradiction between reliability and adaptability.
Solution Approach 2:
The patent segments the key generation process into distinct stages: PUF data generation, error correction to produce intermediate key, and final key generation from multiple candidates. This segmentation allows the system to maintain reliability in the first two stages while providing flexibility in the final key selection, enabling key changes without re-executing the entire process.
2Adaptability or versatility
If the integrated circuit performs error correction and length extension operations to generate multiple final keys, then the security and adaptability are enhanced, but the device complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing multiple final keys derived from the intermediate key during the enrollment phase. This allows the controller to simply select from pre-generated keys during operation, reducing the complexity of real-time key generation while maintaining high flexibility and security.
Solution Approach 2:
The controller is designed with multi-functionality to handle both error correction, length extension, and final key selection operations. By integrating these functions into a single controller that operates on the PUF block output, the patent reduces overall device complexity while maintaining the ability to generate multiple secure keys.
3Reliability
If the integrated circuit generates multiple final keys from an intermediate key, then the security against external hacking is improved, but the manufacturing process complexity increases
Solution Approach 1:
The patent applies preliminary action by performing error correction and length extension operations during the manufacturing/enrollment phase to pre-generate multiple final keys. This shifts the computational complexity to the manufacturing phase rather than the operation phase, simplifying the ease of manufacture during deployment while maintaining high security against hacking.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to integrated circuits including an integrated circuit supporting a physically unclonable function (PUF). An example integrated circuit includes a PUF block including a PUF cell array, and a controller configured to generate a security key based on PUF data that is generated based on the PUF block. The controller is configured to perform an error correction operation on the PUF data to generate an initial key, perform a length extension operation on the initial key to generate an intermediate key, and generate at least one of a plurality of final keys as the security key from the intermediate key.