PUF-Based Lightweight Identity Authentication for IoT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing lightweight identity authentication methods for resource-limited devices in IoT systems face challenges of low efficiency, insufficient security, and poor engineering implementability, particularly in M2M communication systems where traditional encryption algorithms are not feasible due to limited resources.

Innovation Solution

A lightweight identity authentication method based on a physical unclonable function (PUF) that involves device registration and bidirectional authentication processes using challenge-response pairs, where an authentication server generates random challenge strings and temporary identity identifiers, and the device generates unique response strings using its PUF, ensuring secure authentication while optimizing computational and storage costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption algorithms are used for identity authentication, then security is improved, but device complexity and resource consumption increase making them unsuitable for resource-limited IoT devices

Engineering Contradiction:
Improveauthentication securityVSAvoidalgorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional cryptographic algorithms (symmetric and asymmetric encryption) with a challenge-response authentication mechanism based on Physical Unclonable Functions (PUF). This substitution eliminates the need for complex key management and large computational operations, making authentication feasible for resource-constrained IoT devices while maintaining security through the inherent physical uniqueness of each device's PUF characteristics

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the authentication approach from computing-intensive cryptographic operations to physics-based PUF operations. By utilizing the physical characteristics of the device (such as variations in manufacturing processes that create unique electrical pathways), the system transforms authentication from a computational problem to a physical measurement problem, significantly reducing resource requirements

Inventive Principle:
Principle #35Parameter changes

2Productivity

If challenge-response pairs are used for PUF-based authentication, then authentication efficiency is improved, but security risks increase due to potential exposure of challenge-response messages

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidmessage confidentiality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary actions by establishing secure key agreement protocols before actual authentication occurs. The system pre-establishes binding relationships between challenge-response pairs and device identities through secure key derivation, ensuring that even if challenge-response messages are intercepted, they cannot be reused or transferred to other devices without the corresponding secret keys

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication server as an intermediary that manages challenge-response pairs and coordinates the authentication process. The server acts as a trusted mediator that verifies device identities through PUF-based challenges while maintaining security through controlled message exchange, preventing direct exposure of sensitive authentication data between devices

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If lightweight authentication methods are implemented for resource-limited devices, then resource consumption is reduced, but security strength may be compromised

Engineering Contradiction:
Improveenergy consumptionVSAvoidsecurity strength
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The patent enables devices to perform self-authentication using their inherent PUF characteristics without requiring external authentication credentials or complex cryptographic computations. Each device automatically generates unique authentication responses based on its physical characteristics, eliminating the need for pre-shared keys or certificates while maintaining strong security through the unclonability of physical features

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs ephemeral challenge-response pairs that are used once and then discarded, replacing the need for long-term cryptographic keys. Each authentication session generates fresh challenges and responses that are immediately invalidated after use, providing forward security while minimizing storage requirements and computational overhead on resource-limited devices

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12149642B2Lightweight identity authentication method based on physical unclonable function
Publication Date: 2024.11.19 ZHEJIANG LAB
  • US12149642B2 patent drawing
  • US12149642B2 patent drawing

AI summary

The present disclosure belongs to an identity authentication technology in network security field, and relates to a lightweight identity authentication method. The method utilizes lightweight operations of the physical unclonable function, Hash operation, XOR operation, etc. for bidirectional authentication between an authentication server and an Internet of Things resource-limited device, and particularly utilizes uniqueness of an integrated circuit (IC) physical microstructure created by the physical unclonable function in the resource-limited device in a manufacturing process to design an engineering-implementable information desynchronization recovery mechanism of two authentication parties by optimizing an interaction mode of input challenge and output response of the physical unclonable function, thereby solving the problem that the same lightweight identity authentication type solution cannot ensure forward security and resist desynchronization attack, further reducing resource cost for an identity authentication process, and effectively improving security and operation efficiency of identity authentication of the Internet of Things resource-limited device.