PUF-Based Key Generation for Heterogeneous Cloud Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional hardware roots of trust, such as TPM, HSM, and TEE, are costly and not well-suited for low-end hardware, cloud environments with heterogeneous platforms, and container orchestration technologies like Kubernetes, as they are bound to specific hardware devices and cannot securely access data when rescheduled.

Innovation Solution

The use of physical unclonable functions (PUFs) to generate unique hardware outputs, which are then used to create encryption keys for secure data storage and communication, allowing for secure data protection without the need for hardware roots of trust, by utilizing an adaptive library that selects appropriate PUF methods based on hardware type and error tolerance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware roots of trust (TPM, HSM, TEE) are used to ensure data security, then encryption key confidentiality is improved, but deployment cost increases and compatibility with low-end hardware and heterogeneous cloud platforms deteriorates

Engineering Contradiction:
Improveencryption key confidentialityVSAvoidcompatibility with low-end hardware and heterogeneous platforms
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a software-based copy of hardware root of trust functionality using PUF (Physical Unclonable Function) technology. Instead of requiring physical hardware modules like TPM or HSM, the system generates cryptographic keys from unique physical characteristics of any hardware platform through software processing, making security accessible on low-end and heterogeneous hardware without dedicated security modules

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces mechanical/physical hardware security systems (TPM chips, HSM devices, TEE enclaves) with a software-based PUF system that extracts security from inherent physical variations in standard hardware components. This substitution eliminates the need for specialized hardware while maintaining cryptographic security through software processing of physical characteristics

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware roots of trust are bound to specific hardware devices to ensure security, then key confidentiality is improved, but mobility and reusability across different hardware platforms deteriorates

Engineering Contradiction:
Improvekey confidentialityVSAvoidmobility and reusability across hardware platforms
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal PUF-based key generation system that functions across multiple hardware platforms and cloud environments. The software library can extract unique identifiers from various hardware sources (CPU, memory, storage) and generate cryptographic keys that work consistently across heterogeneous platforms, enabling portable security without hardware-specific bindings

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent extracts the essential security function (key generation) from specific hardware roots of trust and relocates it to a software-based PUF system. By taking out the key generation capability from dedicated hardware modules and implementing it through software that processes physical characteristics, the system achieves platform independence while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If container orchestration technology schedules data across different hardware devices to improve resource utilization, then productivity is improved, but access to secret data deteriorates when rescheduled

Engineering Contradiction:
Improveresource utilizationVSAvoidaccess to secret data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic key generation through PUF that adapts to different hardware environments. When containers are rescheduled to different hardware devices, the PUF-based system dynamically generates new cryptographic keys based on the physical characteristics of the target hardware, ensuring continuous security and access without static hardware bindings

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230327864A1Apparatuses, methods, and computer-readable media for generating and utilizing a physical unclonable function key
Publication Date: 2023.10.12 HUAWEI TECH CO LTD
  • US20230327864A1 patent drawing
  • US20230327864A1 patent drawing
  • US20230327864A1 patent drawing

AI summary

There is described methods and devices for generating and utilizing a physical unclonable function (PUF) key. A hardware source is read to obtain a hardware output of a unique identifier of the hardware source. One of a plurality of hardware PUF methods is selected, each of the plurality of hardware PUF methods adapted to a respective hardware source type. The PUF key is generated from the hardware output using the selected hardware PUF method.