PUF-LPN Threshold Key Verification Without Broadcast Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing non-interactive key generation protocols over unencrypted channels are vulnerable to quantum attacks and require encrypted communication or broadcast communication, making them unsuitable for the quantum era and impractical for cold storage settings.

Innovation Solution

The use of hardware-based physically unclonable functions (PUFs) to generate correlated randomness for learning parity with noise (LPN) instances, allowing key generation and verification over unencrypted channels without broadcast communication, using regression models to estimate combined errors and recover encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing non-interactive key generation protocols are used over unencrypted channels, then key generation can be performed without encrypted communication, but the protocols are vulnerable to quantum attacks

Engineering Contradiction:
Improvekey generation over unencrypted channelsVSAvoidsecurity against quantum attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the cryptographic parameters from classical to post-quantum by using LPN instances with specific error distributions (Bernoulli errors) and parameters (q, n, m dimensions) that are secure against quantum attacks. The error rate parameter epsilon is carefully selected to balance security and correctness.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional cryptographic mechanisms (encrypted communication, broadcast channels, zero-knowledge proofs) with a new mechanism based on physically unclonable functions (PUFs) and LPN instances that can operate over unencrypted channels while providing post-quantum security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encrypted communication channels with dedicated cryptographic commitment are used, then security is improved, but device complexity and communication overhead increase

Engineering Contradiction:
Improvecryptographic securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security function from complex cryptographic protocols and implements it through a simplified mechanism using PUFs and LPN instances. Only the necessary components are retained: challenge-response pairs from PUFs, LPN instance generation, and threshold combining, eliminating unnecessary encrypted channels and zero-knowledge proofs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the key generation process into independent steps: each device independently generates LPN instances using its own PUF, the combiner collects and combines these instances, and verification is performed locally. This segmentation eliminates the need for complex coordinated communication protocols.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If broadcast communication with zero knowledge proofs is used, then verification capability is improved, but communication overhead and time requirements increase

Engineering Contradiction:
Improvekey correctness verificationVSAvoidcommunication time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-generating and distributing public matrices to all devices before the actual key generation. This allows the time-consuming matrix operations to be done in advance, making the actual key generation process faster and eliminating the need for time-consuming broadcast verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each device performs self-verification by locally computing whether its contributed LPN instance is consistent with the final key using its own PUF and stored public matrix. This eliminates the need for centralized verification and broadcast communication, making verification instantaneous and distributed.

Inventive Principle:
Principle #25Self-service

4Measurement precision

If complete reliance on back and forth zero-knowledge proofs is used, then verification of key consistency is improved, but communication complexity and trust requirements increase

Engineering Contradiction:
Improvekey consistency verificationVSAvoidtrust model complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces physically unclonable functions (PUFs) as an intermediary that provides inherent trust and verification without requiring complex zero-knowledge proofs. The PUFs act as a mediator that guarantees key consistency through their physical properties, eliminating the need for elaborate trust models and interactive verification protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250365143A1Broadcast-free threshold post-quantum key generation and verification over unencrypted channels from hardware-based correlated randomness
Publication Date: 2025.11.27 CIRCLE INTERNET GRP INC
  • US20250365143A1 patent drawing
  • US20250365143A1 patent drawing
  • US20250365143A1 patent drawing

AI summary

Methods, systems, and apparatus for generating an encryption key. In one aspect, a method includes the generating and sending, by a first device, a stream of random challenges to other devices. Each other device processes, by a physically unclonable function (PUF) included in the device, the stream of random challenges twice to obtain pairs of responses and computes a first Bernoulli matrix vector. Each other device generates a first LPN instance using a pre-stored public matrix, a partial encryption key, and the first Bernoulli error matrix, and sends the first LPN instance to the first device. The first device computes a threshold number of the first LPN instances and an estimated combined error of PUFs included in the other devices. The first device generates an encryption key by recovering a summation of each partial encryption key encoded in the threshold number of first LPN instances.