PUF-Based Key Covering Structure Against Probe Tampering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing tamper-proof chips are not foolproof, allowing malicious users to access secret cryptographic keys, posing a security risk in scenarios where the signature-computing hardware device is not stored in a safe environment.

Innovation Solution

A security device with a covering device that provides a random output signal varying with its microstructure, a key generation component, and a digital signature component, surrounded by a protective layer to prevent unauthorized access and alteration, ensuring the secrecy of the secret key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secret key is stored in a tamper-proof chip surrounded by an outer layer, then the key is protected from casual access, but a malicious user can still insert a probe and read the key without destroying it

Engineering Contradiction:
Improvesecret key protectionVSAvoidprobe access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-configuring the chip with self-destruct mechanisms that activate upon detecting tampering attempts. The outer layer includes fuse elements and anti-probe structures that are designed to fail safely before an attacker can access the secret key, preventing the harmful effect of probe reading by making the key unreadable before access is gained.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent converts the harmful effect of physical probing into a beneficial security feature. When a probe is inserted, the mechanical stress or electrical contact triggers the self-destruct mechanism, which deliberately corrupts the secret key. The harm of probe insertion is thus transformed into the benefit of key destruction, ensuring that even if probing succeeds physically, it fails cryptographically.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Strength

If the outer protective layer is made stronger to prevent probing, then physical access is more difficult, but the cost and complexity of the chip increases

Engineering Contradiction:
Improveprotective layer strengthVSAvoidchip structure
Core Design Contradiction:
StrengthVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by modifying the physical and electrical properties of the outer layer materials to achieve high strength and tamper sensitivity without proportionally increasing complexity. The protective layer uses specialized materials with specific mechanical properties (such as piezoelectric or piezoresistive characteristics) that enable both strength and self-destruct functionality through inherent material behavior rather than complex structural designs.

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Prevents unauthorized determination of secret keys by altering the microstructure upon attempted access, maintaining key secrecy even under physical attacks.

Implementation Method 1

US 10 523 443 B1 discloses use of a physically unclonable function (PUF) to produce a unique, unobservable, unclonable, and permanent output value that is used as a private key by a public-key cryptography logic. PUFs exploit variations inherent in the manufacture of semiconductor ICs to produce a statistically random output value that is different in every IC manufactured.

Methodology Applied
Scientific EffectPhysically unclonable function (PUF):

Data Source

PatentEP4281955B1Securing cryptographic keys
Publication Date: 2026.03.04 MICALI SILVIO
  • EP4281955B1 patent drawingFigure 1
  • EP4281955B1 patent drawingFigure 2
  • EP4281955B1 patent drawingFigure 3A

AI summary

A security device includes a covering device that, in response to an input signal, consistently provides a same random output signal that varies according to the microstructure of the covering device, where altering the microstructure of the covering device alters the random output signal, a key generation component that generates a secret key based on the random output signal, and a digital signature component that produces a digital signature of a message received by the security device using the secret key. The covering device surrounds at least a portion of the key generation component and the digital signature component to prevent access thereto and where accessing any of the components alters the microstructure of the covering device to alter the random output signal. The security device may be attached to an object and detaching the security device from the object may alter the microstructure of the covering device.