PUF-Based Password Generation for IoT Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for distributed peripherals rely on centralized databases that store user identifications and passwords, making them vulnerable to hacking and data breaches, leading to significant financial and psychological losses.

Innovation Solution

The method employs an array of physically unclonable functions (PUFs) to generate unique challenge-response pairs, eliminating the need for central databases by storing authentication patterns within secure memories of distributed peripherals, using a hash function to identify locations within the PUF array for password generation and authentication, and leveraging PUFs' inherent uniqueness to prevent cloning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized databases are used to store user identifications and passwords, then authentication can be performed, but the system becomes vulnerable to hacking and data breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidhacking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication data (user identifications and passwords) from centralized databases and stores it locally in secure memories of distributed peripherals. This eliminates the single point of failure and reduces hacking vulnerability by distributing authentication credentials across multiple devices rather than storing them centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system is segmented into distributed components, with each peripheral device maintaining its own secure memory containing authentication data. This segmentation prevents a single breach from compromising the entire system, as each device operates independently with its own security perimeter.

Inventive Principle:
Principle #1Segmentation

2Reliability

If PUF arrays are used to generate challenge-response pairs, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidPUF array implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PUF array is designed to automatically generate challenge-response pairs based on inherent physical variations in the circuitry, without requiring external intervention or complex key management. The physical characteristics of the PUF cells themselves serve as the security mechanism, eliminating the need for manual key distribution and storage.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the fundamental parameter used for authentication from stored secret values to physical characteristics of the hardware itself. By measuring electrical properties such as resistance or capacitance variations in PUF cells, the system derives security from manufacturing variations rather than relying on complex cryptographic key management.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If authentication data is distributed across peripherals rather than stored centrally, then data breach risk is reduced, but authentication efficiency may decrease

Engineering Contradiction:
Improvedata breach riskVSAvoidauthentication speed
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Challenge-response pairs are pre-computed and stored in the secure memories of distributed peripherals during manufacturing or initial setup. During authentication, the system simply retrieves and verifies these pre-computed values rather than performing complex computations in real-time, maintaining high authentication speed while distributing security credentials.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10320573B2PUF-based password generation scheme
Publication Date: 2019.06.11 ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV
  • US10320573B2 patent drawing
  • US10320573B2 patent drawing
  • US10320573B2 patent drawing

AI summary

The present invention provides a method for authenticating distributed peripherals on a computer network using an array of physically unclonable functions (PUF). As each PUF is unique, each PUF is able to generate a plurality of challenge response pairs that are unique to that PUF. The integrated circuits of the PUF comprise a plurality of cells, where a parameter (such as a voltage) of each cell may be measured (possibly averaged over many readings). The plurality of cells in the PUF may be arranged in a one, two or more dimensional matrix. A protocol based on an addressable PUF generator (APG) allows the protection of a network having distributed peripherals such as Internet of things (IoT), smart phones, lap top and desk top computers, or ID cards. This protection does not require the storage of a database of passwords, or secret keys, and thereby is immune to traditional database hacking attacks.