Strong PUF Encrypted Authentication for IoT Sensing Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device authentication methods for IoT sensing devices based on strong PUFs are vulnerable to attacks, leading to resource waste and security risks due to uniform authentication processes and the ability of attackers to steal PUF information, necessitating a method that enhances authentication security and adapts to device environments.

Innovation Solution

A device encrypted authentication method using a strong physical unclonable function (PUF) with a logistic regression machine learning algorithm to construct a mathematic model, combined with random integers and matrixes for encryption, ensuring secure identity verification and reducing resource waste by adapting to device environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional device authentication methods are used with identity labels and keys stored in memory chips, then authentication can be performed, but security is compromised because attackers can intrusively attack the memory chip to steal or alter identity information

Engineering Contradiction:
Improveauthentication securityVSAvoidmemory chip intrusion attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security vulnerability by removing the need to store sensitive authentication data in vulnerable memory chips. Instead, it uses PUF circuits to generate authentication credentials on-the-fly from physical characteristics, eliminating the attack surface associated with stored keys and identity labels while maintaining authentication functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces PUF circuits as an intermediary between the device hardware and authentication protocol. The PUF circuit acts as a mediator that converts physical characteristics into cryptographic credentials, providing a security layer that prevents direct access to sensitive information while enabling authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strong PUF structures are used for device authentication, then authentication security is improved, but attackers can steal PUF information during channel transmission and construct PUF models to launch ML attacks

Engineering Contradiction:
ImprovePUF-based authentication securityVSAvoidPUF information leakage in transmission channel
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary anti-action by pre-processing PUF challenges through cryptographic hashing and encryption before transmission. This prevents attackers from directly observing and modeling the raw PUF response, as the transmitted data is already transformed into a form that cannot be reverse-engineered to reconstruct the PUF model

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent transforms the authentication process by adding cryptographic dimensions to the PUF output. Instead of transmitting raw PUF responses, the system applies multiple layers of cryptographic transformation, changing the dimensionality of the data from direct physical measurements to encrypted cryptographic credentials that resist modeling attacks

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If a unified authentication process is used for all IoT sensing devices, then authentication can be standardized, but resource waste occurs due to the great difference in security requirements across various application scenarios

Engineering Contradiction:
Improveauthentication process standardizationVSAvoidsensing layer resource waste
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The patent implements dynamic authentication by allowing the PUF challenge parameters, cryptographic algorithm selection, and security level to be adjusted based on the specific application scenario and device capabilities. This enables the authentication process to adapt its resource consumption to match the actual security requirements, avoiding unnecessary resource waste while maintaining standardization through a flexible framework

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by allowing different authentication configurations and security levels for different IoT devices and application scenarios. Each device can be configured with appropriate PUF parameters and cryptographic settings matched to its specific security requirements, rather than imposing a uniform high-security configuration on all devices

Inventive Principle:
Principle #3Local quality

4Reliability

If PUF structures are used for IoT node authentication, then device identification security is improved, but once a PUF structure is cracked, other nodes are exposed to great risk

Engineering Contradiction:
Improvedevice identification securityVSAvoidPUF structure vulnerability across nodes
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent segments the authentication system by giving each IoT node its own unique PUF circuit with distinct physical characteristics. This ensures that compromising one node's PUF does not affect other nodes, as each device's authentication credentials are derived from its unique physical fingerprint rather than a shared secret or identical structure

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12395361B2Device encrypted authentication method based on strong physical unclonable function and device encrypted authentication system using the same
Publication Date: 2025.08.19 WENZHOU UNIV
  • US12395361B2 patent drawing
  • US12395361B2 patent drawing
  • US12395361B2 patent drawing

AI summary

A device encrypted authentication method based on a strong physical unclonable function is disclosed, including: generating β matrixes formed by random transformation of a ┌√{square root over (b)}┐-order unit matrix, such that unnecessary device expenditure is reduced; when a sensing device is identified, information to be synchronized between the sensing device and a back-end server is transmitted in the registration phase, such that an attacker cannot obtain confidential information in the encryption phase, and the attacker cannot traverse or completely crack all these possible combinations in a short time; even if the attacker intercepts some CRPs, it is scarcely possible that data sent by the sensing device matches the CRPs collected by the attacker, and with the increase of the number b of bits of challenges and the quick convergence to 0, the accuracy of random guessing is only 50%.