PUF-Based Hardware Integrity Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing component authentication protocols fail to establish a system-wide identity from individual components, lack effective hardware integrity verification, and are vulnerable to tampering and private information compromise, especially in systems where components are untrusted.

Innovation Solution

Employing physical unclonable functions (PUFs) for detecting hardware tampering and zero knowledge proof protocols for authentication, allowing individual or collaborative verification of components to establish system integrity, and using a hardware root-of-trust to iteratively extend trust boundaries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing component authentication protocols are used, then component verification is achieved, but system-wide identity construction is not possible and hardware integrity verification is insufficient

Engineering Contradiction:
Improvesystem integrity verificationVSAvoidauthentication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides authentication into component-level verification (individual PUF verification) and system-level verification (collective PUF verification), allowing separate handling of component integrity and system integrity through distinct protocol modes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A verifier acts as an intermediary that coordinates both individual and collective authentication protocols, managing the interaction between multiple untrusted components and establishing system-wide identity through the intermediary's aggregation of component proofs

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If physical unclonable functions are used for hardware integrity verification, then tampering detection is improved, but the complexity of implementing system-wide identity increases

Engineering Contradiction:
Improvehardware integrity verificationVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PUF mechanism serves multiple functions: individual component authentication, system-wide identity construction, and tampering detection, eliminating the need for separate mechanisms for each function and reducing overall implementation complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines individual PUF verifications and collective PUF verifications into a unified authentication framework where both modes operate together to establish component-level and system-level trust simultaneously

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If zero knowledge proof protocols are employed, then authentication security is improved, but the computational overhead and verification time increase

Engineering Contradiction:
Improveauthentication securityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system allows selective execution of individual verification (partial action) when only component-level trust is needed, versus full collective verification (excessive action) when system-wide identity is required, optimizing verification time based on security requirements

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9292692B2System and device for verifying the integrity of a system from its subcomponents
Publication Date: 2016.03.22 ANALOG DEVICES INC
  • US9292692B2 patent drawing
  • US9292692B2 patent drawing
  • US9292692B2 patent drawing

AI summary

A system and device for verifying the integrity of a system from its components, the system comprising a plurality of components each having a physical state, the system and the device comprising a processor that is connected to each of the components, the processor configured to verify systemic integrity by performing verification on some or all specified components. The verification may be individual (1, 1) or threshold (n, 1), and may be interactive or non-interactive.