PUF-Based Symmetric Key Distribution via Printer Control Settings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic methods face challenges in securely generating and distributing symmetric encryption keys, especially over insecure channels, due to the need for significant computational effort and the risk of key interception and alteration.

Innovation Solution

A computer-implemented method for distributing symmetric encryption keys using a communication system with nodes that generate encryption keys based on changing printer control settings and jobs, leveraging the principles of physical unclonable functions (PUFs) to create unique and unpredictable encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric encryption keys are distributed over insecure channels using traditional cryptographic methods, then data security can be maintained through encryption, but the keys are vulnerable to interception and alteration by unauthorized parties

Engineering Contradiction:
Improvedata securityVSAvoidkey interception and alteration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional cryptographic key distribution mechanisms with a physical unclonable function (PUF) based system. Instead of relying on mathematical encryption algorithms and secure channel assumptions, the system uses physical characteristics of hardware components (such as variations in semiconductor manufacturing) to generate unique, unclonable keys that are inherently resistant to interception and alteration. The PUF-based key generation substitutes the mechanical/cryptographic system with a physics-based system that derives security from physical law rather than computational complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional key generating algorithms are used to produce secure encryption keys, then satisfactory data security can be achieved, but significant computational effort and time are required

Engineering Contradiction:
Improvedata securityVSAvoidkey generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning each node with a unique physical unclonable function characteristic during manufacturing. The PUF key material is embedded in the hardware itself before deployment, eliminating the need for computationally intensive key generation at runtime. When keys are needed, the system simply reads or activates the pre-existing physical characteristics rather than performing complex cryptographic operations, thus dramatically reducing key generation time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If quantum computing becomes available, then brute-force decryption of traditional encryption becomes feasible, but this threatens the security of existing cryptographic systems

Engineering Contradiction:
Improveencryption securityVSAvoidquantum computing threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent substitutes cryptographic security based on mathematical problems (which are vulnerable to quantum algorithms like Shor's algorithm) with security based on physical laws. The PUF system relies on physical characteristics such as quantum mechanical effects, material properties, or manufacturing variations that are fundamentally unclonable and cannot be broken by quantum computing. This physics-based approach replaces the mathematical/crypto system with a physical system that is inherently resistant to both classical and quantum computational attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4256452B1Key distribution for a physical unclonable encryption system
Publication Date: 2025.02.12 BASF SE
  • EP4256452B1 patent drawingFigure 1
  • EP4256452B1 patent drawingFigure 2
  • EP4256452B1 patent drawingFigure 3

AI summary

A computer-implemented method for distributing symmetric encryption keys in a communication system (110) comprising a plurality of nodes (112) is disclosed. Each of the nodes (112) comprises a printing device (114) configured for generating at least one encryption key for encrypting data based on changing printer control setting (116) and printer job (118). Each node (112) comprises information about possible printer control settings (116) and possible printer jobs (118). The method comprising the following steps a) providing an initial session key information via at least one secure channel to each node (112), wherein the initial session key information comprises an initial printer control setting (116) and an initial printer job setting (118), wherein the initial session key information is different for each node (112); b) providing as one-time pad an initial session key package to each of the nodes (112) encrypted with the respective node's (112) initial session key information, wherein the initial session key package (128) comprises a plurality of items of first session key information for communication of the respective receiving node (112) with the other nodes (112) of the communication system (110), wherein any two nodes (112) have a common item of first session key information; c) generating at each node (112) second session key information for each of the other nodes (112), wherein the second session key information comprises a second printer control setting (116) and a second printer job setting (118), wherein the second session key information generated by the respective node (112) for the respective other nodes (112) is different for each of the other nodes (112); and d) sending a message from one of the nodes (112) to another one of the nodes (112), wherein the message is encrypted with the first session key information for communication between said node (112) and said another one of the nodes (112), wherein the message comprises the second session key information generated by the node (112) sending the message for the node (112) receiving the message such that the node (112) sending the message and the node (112) receiving the message are able for encrypted communication with each other.