Resilient Device Authentication Using PUF Metadata Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity and authentication management systems across systems, users, and enterprises are complex, disparate, and prone to threats, with high costs and operational burdens associated with hardware biometrics, discouraging their use in managing and authenticating identities.

Innovation Solution

A resilient device authentication system utilizing physical unclonable functions (PUFs) with metadata, featuring verification authorities, provisioning entities, and device management systems to create and manage limited verification sets for secure authentication and key management across diverse applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware biometrics are deployed for secure device identification and authentication, then security and device uniqueness are improved, but manufacturing costs, provisioning burdens, and operational complexity increase significantly

Engineering Contradiction:
Improvedevice authentication securityVSAvoidsystem operational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates cryptographic copies (verification sets) of hardware biometric data that can be distributed and used for authentication without requiring the original hardware device to be present. This allows secure authentication while reducing the complexity of managing physical hardware biometrics across multiple systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces verification authorities as intermediary entities that manage the creation, distribution, and validation of verification sets. These intermediaries handle the complex cryptographic operations and metadata management, shielding end systems from the underlying complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If hardware biometrics are established for each device, then device identification accuracy is improved, but manufacturing and provisioning costs increase

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidmanufacturing and provisioning cost
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent performs preliminary cryptographic processing during manufacturing to create verification sets from hardware biometrics. These verification sets are then distributed to verification authorities, allowing accurate device identification without requiring each device to maintain complex biometric systems, thereby reducing manufacturing costs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the essential authentication capability from the original hardware biometric data by creating verification sets that contain only the necessary cryptographic elements. This extraction allows accurate device identification while removing unnecessary complexity and reducing provisioning burdens.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complete verification sets are stored for all devices, then authentication reliability is improved, but storage requirements and system overhead increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidverification data storage volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the complete verification set into distributed components stored across multiple verification authorities. Each authority holds a portion of the verification data, and authentication requires coordination among multiple authorities, thereby maintaining authentication reliability while reducing the storage burden on any single system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent distributes verification data across multiple dimensions (multiple verification authorities) rather than concentrating it in a single location. This dimensional distribution maintains authentication reliability through redundancy while reducing the storage volume requirement at each individual authority.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9996480B2Resilient device authentication system with metadata binding
Publication Date: 2018.06.12 ANALOG DEVICES INC
  • US9996480B2 patent drawing
  • US9996480B2 patent drawing
  • US9996480B2 patent drawing

AI summary

A resilient device authentication system for use with one or more managed devices each including a physical unclonable function (PUF), comprises: one or more verification authorities (VA) each including a processor and a memory loaded with a complete verification set (CVS) that includes hardware part-specific data associated with the managed devices' PUFs and metadata, the processor configured to create a limited verification set (LVS) through one-way algorithmic transformation of hardware part-specific data together with metadata from the loaded CVS so as to create a LVS representing both metadata and hardware part-specific data adequate to redundantly verify all of the hardware parts associated with the LVS; and one or more provisioning entities (PE) each connectable to a VA and including a processor and a memory loaded with a LVS, and configured to select a subset of the LVS so as to create an application limited verification set (ALVS). The system may also comprise one or more device management systems each connectable to a PE and to managed devices and including a memory configured to store an ALVS. The VA may also be configured to create a replacement LVS.