PUF Key Establishment Randomization for Side-Channel Leakage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
PUF-based cryptographic systems leak sensitive information through side-channels, such as power consumption and electromagnetic radiation, making it difficult to maintain the confidentiality of cryptographic keys.
Innovation Solution
A cryptographic system that utilizes a physical system with a partially random configuration, an initial bit-string producer, a normalizer, an error corrector, and a randomizer to establish a reproducible cryptographic key by transforming the initial bit-string into a correctable bit-string within an error correcting code neighborhood, and then using a key derivation algorithm to generate the key, while masking side-channel information through randomization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a PUF-based cryptographic system is used to establish secure keys, then key security is improved, but side-channel information leakage occurs that compromises security
Solution Approach 1:
The patent introduces a randomizing component as an intermediary between the PUF and the key derivation process. This randomizer masks the side-channel information by adding randomness to the intermediate representations, while still allowing the legitimate system to recover the original key through de-randomization. The randomizing component acts as a mediator that protects against side-channel attacks while maintaining cryptographic functionality.
Solution Approach 2:
The patent changes the parameter space by introducing randomizing components that transform the deterministic PUF output into a randomized representation. By modifying the parameter space with randomization layers, the system maintains the security benefits of PUFs while eliminating side-channel vulnerabilities through parameter transformation and de-randomization.
2Reliability
If randomization is applied to mask side-channel information, then security against side-channel attacks is improved, but system complexity increases
Solution Approach 1:
The patent applies preliminary randomization to the PUF output before key derivation, and preliminary de-randomization after key derivation. By performing these randomization operations in advance and in reverse order, the system manages complexity systematically rather than requiring complex real-time protection mechanisms during the critical key derivation process.
3Loss of information
If multiple processing steps are added to remove side-channel effects, then information leakage is reduced, but processing time increases
Solution Approach 1:
The patent replaces complex multi-step side-channel protection mechanisms with a more efficient randomization-based approach. Instead of using multiple sequential processing steps to remove side-channel effects, the system uses a single randomization layer that can be applied and removed efficiently, reducing processing time while maintaining protection against information leakage.
Data Source
AI summary
In systems for establishing a cryptographic key depending on a physical uncloneable function (PUF) it may be a problem that internal information correlated with the cryptographic key is leaked to the outside of the system via a side-channel. To mitigate this problem a cryptographic system for reproducibly establishing a cryptographic key is presented. The system comprises a physical system comprising a physical, at least partially random, configuration of components from which an initial bit-string is derived. An error corrector corrects deviations occurring in the initial bit-string. Through the use of randomization the error corrector operates on a randomized data. Information leaking through a side channel is thereby reduced. After error correction a cryptographic key may be derived from the initial bit-string.


