PUF Key Derivation via Debiasing Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PUF-based cryptographic key generation systems face issues with entropy loss due to high bias, leading to insecure key production and resource inefficiency, particularly in low-resource systems, and are vulnerable to repeated enrollment attacks.
Innovation Solution
A cryptographic device that employs a debiasing unit to separate noisy bit strings into low and high bias susceptible parts, generating independent noise reduction data for each part, allowing for independent corrections during the reconstruction phase to produce cryptographic keys with reduced entropy loss and enhanced security against repeated enrollments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PUF-based key generation is used, then cryptographic keys can be generated from physical variations, but entropy loss occurs due to high bias leading to insecure key production
Solution Approach 1:
The patent divides the noisy bit string into multiple parts (first part and second part) based on bias characteristics. The debiasing unit segments the bit string such that the first part has lower bias susceptibility while the second part has higher bias susceptibility, allowing independent processing and correction of each segment to minimize overall entropy loss.
Solution Approach 2:
The patent applies different noise reduction strategies to different parts of the bit string based on their local bias characteristics. The first noise reduction data is generated for the low-bias portion while the second noise reduction data is generated for the high-bias portion, allowing each segment to be corrected optimally for its specific bias conditions.
2Reliability
If PUF resources are increased to reduce bias impact, then key security improves, but resource efficiency decreases especially in low-resource systems
Solution Approach 1:
The patent segments the PUF response into parts with different bias characteristics, allowing the system to process and correct each segment independently. This segmentation enables effective bias mitigation without requiring additional PUF resources, as the same physical PUF is processed differently based on segment characteristics.
Solution Approach 2:
The patent changes the processing parameters applied to different parts of the bit string based on their bias susceptibility. By adjusting the noise reduction approach according to the local bias parameters of each segment, the system achieves secure key generation without increasing the physical PUF resource quantity.
3Manufacturing precision
If noise reduction data is generated for the entire PUF response, then correction completeness improves, but vulnerability to repeated enrollment attacks increases
Solution Approach 1:
The patent segments the noise reduction process into independent parts corresponding to different bias susceptibility regions. The first noise reduction data and second noise reduction data are generated independently for their respective parts, which prevents an attacker from exploiting correlations across the entire response that would enable repeated enrollment attacks.
Solution Approach 2:
The patent applies localized noise reduction strategies to specific segments of the PUF response based on their individual bias characteristics. This localized approach ensures that each segment is corrected optimally while maintaining security, as the independent processing of segments prevents information leakage that could be exploited in repeated enrollment scenarios.
Data Source
AI summary
Some embodiments relate to an electronic cryptographic device (100) arranged to determine a cryptographic key. The cryptographic device is arranged for an enrollment phase and a later reconstruction phase. The cryptographic device comprising a physically unclonable function (PUF) (110) and a processor circuit. The circuit being configured to determine during the enrollment phase debiasing data (142), first noise reduction data (131) and first noise reduction data. The circuit being configured to during the reconstruction phase compute at least one cryptographic key from first corrected bits and second corrected bits.


