Reverse Computational Fuzzy Extractor for PUF Entropy Preservation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional fuzzy extractors fail to preserve the full entropy of physical unclonable functions (PUFs), resulting in insufficient key lengths for secure device authentication, particularly in lightweight devices with limited processing capability and memory.
Innovation Solution
The method employs a reverse computational fuzzy extractor using Learning with Errors (LWE) to derive longer cryptographic keys by encoding a helper bit string with a uniformly distributed random matrix and vector, masking statistical bias in the PUF response, and transmitting this helper bit string for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional information-theoretic fuzzy extractors are used to remove noise from PUF response, then authentication reliability is improved, but the full entropy of the PUF cannot be preserved resulting in shorter key lengths
Solution Approach 1:
The patent inverts the traditional fuzzy extractor approach by using a computational model based on Learning With Errors (LWE) problem. Instead of using error-correcting codes that lose entropy, the system generates helper data that allows recovery of the secret without requiring redundancy that reduces key length. The inversion lies in shifting from information-theoretic security with entropy loss to computational security with full entropy preservation.
Solution Approach 2:
The patent changes the security model parameters from information-theoretic security to computational security based on the hardness of the LWE problem. This parameter change allows the system to achieve both reliability (through computational security) and full entropy preservation (by avoiding traditional error-correcting code redundancy). The helper data structure and recovery process are redesigned to work with computational rather than information-theoretic assumptions.
2Reliability
If longer cryptographic keys are derived from PUF to enhance security, then security strength is improved, but the processing and memory requirements increase which is problematic for lightweight devices
Solution Approach 1:
The patent enables lightweight devices to generate their own cryptographic keys using their inherent physical characteristics through the PUF. The device uses its own noisy physical response, combined with publicly available helper data and a shared secret, to derive long cryptographic keys without requiring external key generation infrastructure. This self-service approach allows resource-constrained devices to achieve strong security independently.
Solution Approach 2:
The patent introduces a mathematical intermediary based on the Learning With Errors problem that bridges the gap between the noisy PUF response and the desired long cryptographic key. The helper data acts as an intermediary that, when combined with the PUF response and shared secret through LWE-based computations, enables derivation of long keys without requiring the device to store or process large amounts of data, thus reducing memory and processing requirements.
3Measurement precision
If traditional fuzzy extractors are used with error correcting codes, then noise removal is achieved, but redundancy information in helper data reduces the usable key length
Solution Approach 1:
The patent substitutes the mechanical/error-correcting-code-based noise removal system with a computational system based on the Learning With Errors problem. Instead of using traditional error-correcting codes that require redundancy and reduce key length, the system uses LWE-based computational hardness to achieve noise tolerance while preserving full entropy. The mathematical structure of LWE provides inherent noise resistance without the need for redundant helper data that would reduce key length.
Data Source
AI summary
A method and system for authenticating a first device is disclosed. The method includes the steps of: measuring a first response bit string of a physical unclonable function of the first device with respect to a challenge bit string, the physical unclonable function being provided by one of the processor of the first device and a further physical component of the first device; deriving a shared secret bit string from a uniformly distributed random vector; encoding a helper bit string by multiplying a uniformly distributed random matrix with the uniformly distributed random vector and adding the first response bit string to a result of the multiplication; and transmitting the helper bit string to a second device that is remote from the first device.


