PUF-Based Key Derivation Without External Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for generating cryptographic keys from Physically Unclonable Functions (PUFs) often require external key derivation functions, key stretching, or storage of pre-programmed keys, which can reduce entropy and increase latency or expose keys to leakage.
Innovation Solution
A method that customizes PUFs to produce keys for specific cryptographic algorithms by generating challenges and responses, applying error correction, and validating potential keys to ensure they meet algorithm criteria, without relying on hash chains or external key derivation functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If external key derivation functions are used to generate cryptographic keys from PUFs, then key generation capability is improved, but entropy is reduced and device complexity increases
Solution Approach 1:
The patent extracts only the necessary PUF responses required for key generation, avoiding unnecessary processing steps. By directly using PUF responses as cryptographic keys after minimal validation, the system eliminates entropy-reducing intermediate steps while maintaining key generation capability for specific algorithms.
Solution Approach 2:
The PUF device generates its own cryptographic keys directly from its physical characteristics without requiring external key derivation functions. The system validates and uses the PUF responses as-is, allowing the device to serve its own key generation needs and preserving maximum entropy.
2Length of moving object
If key stretching is applied to PUF responses, then key length is increased, but entropy is reduced and processing time increases
Solution Approach 1:
The patent applies partial action by using the PUF response directly as the cryptographic key without full key stretching. For algorithms requiring specific key lengths, the system selectively applies minimal processing only when necessary, avoiding the time-consuming full key stretching process while still meeting algorithm requirements.
3Ease of operation
If pre-programmed keys are stored in memory, then key availability is improved, but security is worsened due to potential leakage
Solution Approach 1:
The system performs preliminary validation of PUF responses to ensure they meet cryptographic algorithm requirements before use. By pre-validating the physical characteristics and generating keys on-demand with proper validation, the system ensures key availability while eliminating the security vulnerability of storing pre-programmed keys in memory.
4Reliability
If multiple challenges are generated for PUF key derivation, then key validity is improved, but device complexity and processing time increase
Solution Approach 1:
The patent segments the challenge generation process into distinct phases: initial challenge generation, PUF response validation, and conditional additional challenge generation. This segmentation allows the system to maintain simple base operations while adding complexity only when necessary for key validity, reducing overall device complexity compared to always generating multiple challenges.
Data Source
AI summary
Solutions and methods are disclosed herein for generating a key from outputs of a Physically Unclonable Function (PUF) and using the key for a cryptographic algorithm. In one embodiment, a device generates the key, which comprises (i) receiving a request to generate a key comprising a defined number of bits for a particular cryptography algorithm and (ii) responsive to receiving the request, generating a valid key for the particular cryptography algorithm. The step of generating the valid key further comprises (a) generating one or more first challenges for a PUF, which is one or more of a plurality of challenges in a challenge space of the PUF, (b) generating a first potential key based on one or more first responses by the PUF responsive to the one or more first challenges, and (c) determining whether the first potential key satisfies one or more predefined criteria for the particular cryptography algorithm.


