Physical Unclonable Function Storage in Non-Host Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Non-volatile memory devices face challenges in securely storing and managing physical unclonable function (PUF) values, which are essential for device identification and authentication, as storing PUF values in memory devices makes them vulnerable to attacks and failure scenarios.
Innovation Solution
The memory device is configured to access a PUF protection key stored in a non-host-addressable memory region, encrypt the PUF value using this key, and store the encrypted PUF value in scattered memory locations, ensuring secure storage while allowing for data access even in case of PUF failure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PUF values are stored in memory devices for device identification and authentication, then device security and identification capability are improved, but the memory devices become vulnerable to attacks and failure scenarios
Solution Approach 1:
The patent extracts the PUF value from the memory device's addressable storage and stores it in a non-host-addressable memory region. This separation removes the PUF value from the host's direct access scope, preventing extraction attacks while maintaining the authentication function. The PUF value is effectively taken out of the vulnerable storage space and placed in a protected zone.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism using a PUF protection key. Instead of storing the PUF value in plain form, it encrypts the PUF value with a protection key before storing it in the non-host-addressable region. This intermediary encryption layer acts as a mediator that prevents direct access to the PUF value while allowing authenticated access through proper decryption procedures.
2Object-affected harmful factors
If PUF values are encrypted and stored in non-host-addressable memory regions, then security against attacks is improved, but access complexity increases
Solution Approach 1:
The patent implements a self-service mechanism where the host device automatically performs the decryption of the PUF value using the PUF protection key when authentication is required. The complex decryption operation is executed by the host itself rather than requiring external intervention or complex hardware support, thereby managing the complexity within the existing system capabilities.
Solution Approach 2:
The patent performs preliminary encryption of the PUF value with the PUF protection key before storage in the non-host-addressable memory region. This preliminary action ensures that the PUF value is already protected when stored, eliminating the need for complex runtime security measures and simplifying the access protocol to a straightforward decrypt-and-use process.
3Object-affected harmful factors
If PUF values are stored securely in non-host-addressable memory regions, then unauthorized access is prevented, but data access in case of PUF failure may be compromised
Solution Approach 1:
The patent changes the storage parameter of the PUF value from volatile to non-volatile memory. By storing the encrypted PUF value in a non-volatile memory region, the system ensures that the authentication data persists across power cycles and remains accessible even in failure scenarios. This parameter change from volatile to non-volatile storage enhances both security and reliability simultaneously.
Solution Approach 2:
The patent implements beforehand cushioning by storing the encrypted PUF value in a protected non-host-addressable memory region that remains accessible even when the host system experiences failures. This prior preparation ensures that the authentication credential is preserved and accessible for recovery operations, cushioning against the impact of potential PUF failures or host system crashes.
Data Source
AI summary
In some implementations, a memory device may generate a physical unclonable function (PUF) value. The memory device may access a PUF protection key stored in a non-host-addressable memory region. The memory device may encrypt the PUF value, using the PUF protection key, to generate an encrypted PUF value. The memory device may store the encrypted PUF value in scattered memory locations in the non-host-addressable memory region.


