PUF Circuit Key Masking for Security Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems face challenges in preventing the copying of authentication keys stored in security devices, particularly when using Physically Unclonable Functions (PUFs), as the keys can be vulnerable to exposure and attacks.

Innovation Solution

A security device that employs a PUF circuit to generate random key data and masking data, using post-processing to create a masked key, which is then stored, ensuring that the original key cannot be restored without the masking data, thus enhancing security by making it impossible to expose the key to attackers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a key is stored in a security device using PUF, then the key can be generated dynamically, but the key becomes vulnerable to exposure and attacks

Engineering Contradiction:
Improvekey securityVSAvoidkey exposure vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The PUF circuit is divided into multiple independent PUF cells, each contributing to different aspects of key generation. The key is segmented into multiple shares that are distributed across different PUF cells, so that no single cell contains the complete key information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A masking module is introduced as an intermediary component that combines key shares with masking data generated by additional PUF cells. This masking layer acts as a mediator that protects the original key from direct exposure, requiring both key shares and masking data to reconstruct the key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If masking data is generated from the same PUF cells as key data, then the system is simpler, but the security is reduced due to potential correlations

Engineering Contradiction:
ImprovePUF cell configurationVSAvoidmasking effectiveness
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Different PUF cells are assigned different functional roles: some PUF cells are dedicated to generating key shares while others are dedicated to generating masking data. This local specialization ensures that the output of each PUF cell has specific properties suitable for its intended purpose, improving both security and reliability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11689376B2Security device for generating masking data based on physically unclonable function and operating method thereof
Publication Date: 2023.06.27 SAMSUNG ELECTRONICS CO LTD
  • US11689376B2 patent drawing
  • US11689376B2 patent drawing
  • US11689376B2 patent drawing

AI summary

A security device and an operating method thereof, which generate masking data for masking a key on the basis of a physically unclonable function (PUF), are provided. The security device includes a PUF circuit including a plurality of PUF cells outputting random key data and masking data, a key generator configured to generate a key through post-processing performed on the random key data, and a masking module configured to mask and store the key by using the masking data, wherein the random key data and the masking data are generated by different PUF cells.