PUF Secure Verification Without Exposing Cryptographic Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for provisioning secret keys in electronic devices expose these keys during manufacturing or storage, making them vulnerable to malicious attacks, and direct key verification is hindered by hardware faults and aging, complicating diagnosis of failures.
Innovation Solution
A method for secure verification of a physical unclonable function (PUF) that generates a PUF key from an integrated circuit, computes a digest, and stores a PUF reagent value in non-volatile memory, enabling secure verification without exposing the key, using cryptographic hash algorithms and error-correction codes to ensure accuracy and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If secret keys are programmed to device memory in a manufacturing environment, then key assignment can be completed, but security is compromised because malicious entities can exploit vulnerabilities to access the key
Solution Approach 1:
The patent extracts the secret key from the device memory and replaces it with a PUF (Physical Unclonable Function) that generates the key on-demand. The actual key never resides in memory, eliminating the attack surface for key theft while maintaining the ability to use the key for cryptographic operations.
Solution Approach 2:
The patent introduces a PUF as an intermediary between the need for a secret key and the device memory. The PUF generates keys dynamically based on physical characteristics, acting as a mediator that provides key material without requiring storage of the actual key in vulnerable locations.
2Ease of operation
If secret keys are stored in device memory for use after release, then cryptographic operations can be performed, but security is compromised during key maintenance and usage
Solution Approach 1:
The patent removes the secret key from device memory entirely and replaces it with a PUF that generates the key on-demand. This extraction eliminates the security risks associated with key storage and maintenance while preserving the ability to perform cryptographic operations using the generated key material.
Solution Approach 2:
The PUF generates cryptographic keys autonomously based on its physical characteristics without requiring external key provisioning or storage. The system serves itself by deriving key material from inherent physical properties, eliminating the need for vulnerable key management infrastructure.
3Reliability
If direct key verification is implemented, then operational correctness can be confirmed, but hardware faults and aging complicate diagnosis and reduce reliability
Solution Approach 1:
The patent creates a digital copy or representation of the PUF's physical characteristics that can be verified without accessing the actual key material. This copy enables verification of operational correctness while isolating the verification process from the physical degradation issues that affect the original PUF.
Solution Approach 2:
The patent introduces an intermediary verification mechanism that checks PUF operational correctness without directly examining the key material. This intermediary layer simplifies diagnosis by providing a clear verification interface that is not complicated by hardware faults or aging effects on the key storage system.
Data Source
AI summary
The present disclosure describes apparatuses and methods for implementing secure verification of a physical unclonable function (PUF). In various aspects, a PUF verifier generates a PUF reagent value by obtaining a key from a PUF and a message value useful for PUF verification. The PUF verifier computes a digest value of the PUF key and the message value and selects a portion of the hash digest as a PUF reagent value. The PUF verifier writes the PUF reagent value to a non-volatile memory to enable subsequent verification of the PUF. The PUF verifier may also generate error-correction code information for the PUF reagent value and write this information to the non-volatile memory to enable error correction. Upon device hardware reset, the PUF verifier can securely verify PUF operation by generating a PUF key hash digest and comparing the hash digest with the PUF reagent value without exposing the PUF key.


