PUF Root Key Entanglement with User Inputs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PUF systems face limitations in integrating user-defined and application-specific inputs with root keys, requiring lengthy helper data storage and external verification, which restricts their application in secure access and authentication mechanisms.
Innovation Solution
A system that entangles multiple root keys with arbitrary user-defined inputs using a Physically Unclonable Function (PUF) and a digital algorithmic system, enabling the creation and recovery of multiple true random root keys independent of power cycles, with a root key extractor comprising a key extractor controller, true random number generator, fuzzy extractor, message authentication code unit, and format preserving encryption unit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PUF systems store lengthy helper data to ensure root key retrieval, then root key reliability is improved, but device complexity and storage requirements increase
Solution Approach 1:
The patent extracts the core entropy from the PUF system and separates it from the lengthy helper data. By using a fuzzy extractor to extract a compact secret string from the PUF output, the system maintains root key retrieval reliability while eliminating the need to store extensive helper data within the device.
Solution Approach 2:
The patent introduces a fuzzy extractor as an intermediary component that processes the PUF output and generates a compact secret string. This intermediary enables reliable root key derivation without requiring the PUF system to directly store or manage lengthy helper data, thus reducing device complexity.
2Speed
If PUF systems integrate helper data storage to avoid external verification, then authentication speed is improved, but security boundaries are compromised
Solution Approach 1:
The patent extracts only the essential secret string from the PUF output using a fuzzy extractor, removing the need to store lengthy helper data within the secure boundary. This extraction approach maintains authentication speed while preserving security boundaries, as the compact secret can be verified externally without compromising the PUF's security model.
Solution Approach 2:
Instead of storing helper data inside the secure boundary to speed up authentication, the patent inverts the approach by using a fuzzy extractor to generate a compact secret that can be verified externally. This reversal maintains authentication efficiency while actually strengthening security boundaries by minimizing internal storage requirements.
3Ease of operation
If PUF systems use fixed root keys for device lifecycle, then key management simplicity is improved, but adaptability to different applications decreases
Solution Approach 1:
The patent introduces dynamic key derivation by combining the PUF-based secret with application-specific inputs through a key derivation function. This allows the system to generate different root keys for different applications while maintaining a single PUF source, thus achieving both operational simplicity and application adaptability.
Solution Approach 2:
The patent creates a universal PUF-based secret that can serve multiple applications through key derivation. The single PUF instance generates a secret that can be transformed into different root keys for various cryptographic purposes, achieving multi-functionality without requiring multiple PUF instances or complex key management.
4Reliability
If PUF systems require external secure modules for password verification, then authentication security is improved, but system complexity increases
Solution Approach 1:
The patent merges the PUF-based secret extraction with the password verification function in a single integrated process. The fuzzy extractor directly processes the PUF output combined with user input to generate authentication credentials, eliminating the need for separate external secure modules while maintaining authentication security.
Solution Approach 2:
The patent enables the PUF system to self-serve authentication functions by directly generating verifiable credentials from its output through the fuzzy extractor. The system performs its own password verification and key generation without requiring external secure modules, reducing system complexity while maintaining security.
Data Source
AI summary
The present invention discloses a system for entangling multiple root keys with multiple arbitrary user-defined and self-generated input data using a Physically Unclonable Function (PUF) and a proposed digital algorithmic system. The key innovation lies in the combination of a PUF-based dynamically measurable entropy source and the proposed invention, enabling the generation of multiple true random keys. These keys serve as a secure foundation for establishing cryptographic channels, allowing the creation of isolated secure channels for different stakeholders and applications. The ability to create isolated secure channels with multiple root keys enables the establishment of multiple roots of trust, enhancing the integrity and security of cryptographic operations. The invention finds applications in various domains, such as FIDO authentications, point-to-point encryptions, crypto wallets, and encryption key management systems.


