PUF Circuit Key Masking for Security Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems face challenges in preventing the copying of authentication keys stored in security devices, particularly when using Physically Unclonable Functions (PUFs), as the keys can be vulnerable to exposure and attacks.
Innovation Solution
A security device that employs a PUF circuit to generate random key data and masking data, using post-processing to create a masked key, which is then stored, ensuring that the original key cannot be restored without the masking data, thus enhancing security by making it impossible to expose the key to attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a key is stored in a security device using PUF, then the key can be generated dynamically, but the key becomes vulnerable to exposure and attacks
Solution Approach 1:
The PUF circuit is divided into multiple independent PUF cells, each contributing to different aspects of key generation. The key is segmented into multiple shares that are distributed across different PUF cells, so that no single cell contains the complete key information.
Solution Approach 2:
A masking module is introduced as an intermediary component that combines key shares with masking data generated by additional PUF cells. This masking layer acts as a mediator that protects the original key from direct exposure, requiring both key shares and masking data to reconstruct the key.
2Device complexity
If masking data is generated from the same PUF cells as key data, then the system is simpler, but the security is reduced due to potential correlations
Solution Approach 1:
Different PUF cells are assigned different functional roles: some PUF cells are dedicated to generating key shares while others are dedicated to generating masking data. This local specialization ensures that the output of each PUF cell has specific properties suitable for its intended purpose, improving both security and reliability.
Data Source
AI summary
A security device and an operating method thereof, which generate masking data for masking a key on the basis of a physically unclonable function (PUF), are provided. The security device includes a PUF circuit including a plurality of PUF cells outputting random key data and masking data, a key generator configured to generate a key through post-processing performed on the random key data, and a masking module configured to mask and store the key by using the masking data, wherein the random key data and the masking data are generated by different PUF cells.


