PUF Cryptographic Key Configuration via Altered Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Physical Unclonable Functions (PUFs) require access to a special characterization mode for helper data generation, increasing test time and silicon costs, and existing cryptographic key management is not always stable.
Innovation Solution
A method where an initial configuration message is generated using a PUF, transmitted to a client access server, and altered to obtain a cryptographic key without needing the special characterization mode, reducing test time and production costs, and enhancing security through a secure link and cryptographic key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If helper data generation is performed in a controlled environment using special characterization mode, then cryptographic key stability is improved, but test time increases and silicon costs increase
Solution Approach 1:
The patent performs helper data generation during wafer-level testing before the chips are packaged and shipped. This preliminary action allows the cryptographic keys to be established early in the manufacturing process, eliminating the need for post-production characterization modes and reducing both test time and silicon costs while maintaining key stability.
Solution Approach 2:
The patent introduces a secure element or trusted platform as an intermediary that stores the helper data generated during wafer testing. This intermediary enables the PUF to generate stable cryptographic keys in production environments without requiring access to the special characterization mode, thus resolving the contradiction between key stability and test time requirements.
2Reliability
If helper data generation is performed in a controlled environment using special characterization mode, then cryptographic key stability is improved, but silicon costs increase
Solution Approach 1:
The patent performs helper data generation during wafer-level testing before the chips are packaged and shipped. This preliminary action allows the cryptographic keys to be established early in the manufacturing process, eliminating the need for post-production characterization modes and reducing both test time and silicon costs while maintaining key stability.
Solution Approach 2:
The patent introduces a secure element or trusted platform as an intermediary that stores the helper data generated during wafer testing. This intermediary enables the PUF to generate stable cryptographic keys in production environments without requiring access to the special characterization mode, thus resolving the contradiction between key stability and test time requirements.
3Ease of manufacture
If PUF is used to generate cryptographic keys without one-time programmable memory, then cost efficiency is improved, but PUF algorithm stability deteriorates
Solution Approach 1:
The patent introduces a secure element or trusted platform as an intermediary that stores the helper data generated during wafer testing. This intermediary enables the PUF to generate stable cryptographic keys in production environments without requiring access to the special characterization mode, thus resolving the contradiction between key stability and test time requirements.
Solution Approach 2:
The patent changes the operational parameters of the PUF by providing it with helper data from secure storage during key generation. This parameter change allows the PUF to operate stably in production environments without requiring expensive one-time programmable memory, thus resolving the contradiction between cost efficiency and algorithm stability.
Data Source
AI summary
The disclosure relates to a method of obtaining a cryptographic key in a chipset (1). An initial configuration message may be generated using a physical unclonable function (hereinafter: PUF) (22) of the chipset (1). Said PUF (22) may generate a predetermined value when using the initial configuration message as input to the PUF (22). The initial configuration message may be transmitted to a client access server (31). An altered configuration message may be received from the client access server (31), wherein the altered configuration message is generated by the client access server (31) based on the initial configuration message. The cryptographic key may be obtained from the PUF (22) using the altered configuration message as input to the PUF (22).


