PUF-Based Password Generation for IoT Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for distributed peripherals rely on centralized databases that store user identifications and passwords, making them vulnerable to hacking and data breaches, leading to significant financial and psychological losses.
Innovation Solution
The method employs an array of physically unclonable functions (PUFs) to generate unique challenge-response pairs, eliminating the need for central databases by storing authentication patterns within secure memories of distributed peripherals, using a hash function to identify locations within the PUF array for password generation and authentication, and leveraging PUFs' inherent uniqueness to prevent cloning.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized databases are used to store user identifications and passwords, then authentication can be performed, but the system becomes vulnerable to hacking and data breaches
Solution Approach 1:
The patent extracts the authentication data (user identifications and passwords) from centralized databases and stores it locally in secure memories of distributed peripherals. This eliminates the single point of failure and reduces hacking vulnerability by distributing authentication credentials across multiple devices rather than storing them centrally.
Solution Approach 2:
The authentication system is segmented into distributed components, with each peripheral device maintaining its own secure memory containing authentication data. This segmentation prevents a single breach from compromising the entire system, as each device operates independently with its own security perimeter.
2Reliability
If PUF arrays are used to generate challenge-response pairs, then security is enhanced, but device complexity increases
Solution Approach 1:
The PUF array is designed to automatically generate challenge-response pairs based on inherent physical variations in the circuitry, without requiring external intervention or complex key management. The physical characteristics of the PUF cells themselves serve as the security mechanism, eliminating the need for manual key distribution and storage.
Solution Approach 2:
The system changes the fundamental parameter used for authentication from stored secret values to physical characteristics of the hardware itself. By measuring electrical properties such as resistance or capacitance variations in PUF cells, the system derives security from manufacturing variations rather than relying on complex cryptographic key management.
3Object-affected harmful factors
If authentication data is distributed across peripherals rather than stored centrally, then data breach risk is reduced, but authentication efficiency may decrease
Solution Approach 1:
Challenge-response pairs are pre-computed and stored in the secure memories of distributed peripherals during manufacturing or initial setup. During authentication, the system simply retrieves and verifies these pre-computed values rather than performing complex computations in real-time, maintaining high authentication speed while distributing security credentials.
Data Source
AI summary
The present invention provides a method for authenticating distributed peripherals on a computer network using an array of physically unclonable functions (PUF). As each PUF is unique, each PUF is able to generate a plurality of challenge response pairs that are unique to that PUF. The integrated circuits of the PUF comprise a plurality of cells, where a parameter (such as a voltage) of each cell may be measured (possibly averaged over many readings). The plurality of cells in the PUF may be arranged in a one, two or more dimensional matrix. A protocol based on an addressable PUF generator (APG) allows the protection of a network having distributed peripherals such as Internet of things (IoT), smart phones, lap top and desk top computers, or ID cards. This protection does not require the storage of a database of passwords, or secret keys, and thereby is immune to traditional database hacking attacks.


