PUF Key Establishment Randomization for Side-Channel Leakage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

PUF-based cryptographic systems leak sensitive information through side-channels, such as power consumption and electromagnetic radiation, making it difficult to maintain the confidentiality of cryptographic keys.

Innovation Solution

A cryptographic system that utilizes a physical system with a partially random configuration, an initial bit-string producer, a normalizer, an error corrector, and a randomizer to establish a reproducible cryptographic key by transforming the initial bit-string into a correctable bit-string within an error correcting code neighborhood, and then using a key derivation algorithm to generate the key, while masking side-channel information through randomization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PUF-based cryptographic system is used to establish secure keys, then key security is improved, but side-channel information leakage occurs that compromises security

Engineering Contradiction:
Improvekey securityVSAvoidside-channel information leakage
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a randomizing component as an intermediary between the PUF and the key derivation process. This randomizer masks the side-channel information by adding randomness to the intermediate representations, while still allowing the legitimate system to recover the original key through de-randomization. The randomizing component acts as a mediator that protects against side-channel attacks while maintaining cryptographic functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter space by introducing randomizing components that transform the deterministic PUF output into a randomized representation. By modifying the parameter space with randomization layers, the system maintains the security benefits of PUFs while eliminating side-channel vulnerabilities through parameter transformation and de-randomization.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If randomization is applied to mask side-channel information, then security against side-channel attacks is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity against side-channel attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary randomization to the PUF output before key derivation, and preliminary de-randomization after key derivation. By performing these randomization operations in advance and in reverse order, the system manages complexity systematically rather than requiring complex real-time protection mechanisms during the critical key derivation process.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If multiple processing steps are added to remove side-channel effects, then information leakage is reduced, but processing time increases

Engineering Contradiction:
Improveside-channel information leakageVSAvoidprocessing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent replaces complex multi-step side-channel protection mechanisms with a more efficient randomization-based approach. Instead of using multiple sequential processing steps to remove side-channel effects, the system uses a single randomization layer that can be applied and removed efficiently, reducing processing time while maintaining protection against information leakage.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20120072737A1System for establishing a cryptographic key depending on a physical system
Publication Date: 2012.03.22 SYNOPSYS INC
  • US20120072737A1 patent drawing
  • US20120072737A1 patent drawing
  • US20120072737A1 patent drawing

AI summary

In systems for establishing a cryptographic key depending on a physical uncloneable function (PUF) it may be a problem that internal information correlated with the cryptographic key is leaked to the outside of the system via a side-channel. To mitigate this problem a cryptographic system for reproducibly establishing a cryptographic key is presented. The system comprises a physical system comprising a physical, at least partially random, configuration of components from which an initial bit-string is derived. An error corrector corrects deviations occurring in the initial bit-string. Through the use of randomization the error corrector operates on a randomized data. Information leaking through a side channel is thereby reduced. After error correction a cryptographic key may be derived from the initial bit-string.