IP Library Granted Patent US 12665774
Granted Patent B2
US 12665774 · App. 18/287,936 · Granted Jun 23, 2026

Systems and methods of physically unclonable function (PUF)-based key derivation function

Inventors: Niklas Lindskog (Lund, SE); Håkan Englund (Lund, SE)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L9/3278H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665774
App. No.
18/287,936
Granted
Jun 23, 2026
Kind
B2
Abstract

Solutions and methods are disclosed herein for generating a key from outputs of a Physically Unclonable Function (PUF) and using the key for a cryptographic algorithm. In one embodiment, a device generates the key, which comprises (i) receiving a request to generate a key comprising a defined number of bits for a particular cryptography algorithm and (ii) responsive to receiving the request, generating a valid key for the particular cryptography algorithm. The step of generating the valid key further comprises (a) generating one or more first challenges for a PUF, which is one or more of a plurality of challenges in a challenge space of the PUF, (b) generating a first potential key based on one or more first responses by the PUF responsive to the one or more first challenges, and (c) determining whether the first potential key satisfies one or more predefined criteria for the particular cryptography algorithm.

Claims (41)

1 . A method for providing a cryptographic key to a client, the method comprising:

receiving from the client a request to generate a key comprising a defined number, N, of bits for a particular cryptography algorithm; and

responsive to receiving the request, providing a valid key for the particular cryptography algorithm to the client, wherein providing the valid key for the particular cryptography algorithm comprises:

generating a set of challenges for a Physically Unclonable Function, PUF, wherein the set of challenges comprises one or more challenges from a plurality of challenges in a challenge space of the PUF;

generating at least one potential key based on a set of two or more responses by the PUF responsive to the set of challenges, wherein generating the at least one potential key comprises combining at least two responses included in the set of responses;

for each potential key of the at least one potential key:

determining whether the potential key satisfies one or more predefined criteria for the particular cryptography algorithm; and

in response to determining that the potential key satisfies the one or more predefined criteria for the particular cryptography algorithm, providing the potential key to the client as the valid key.

2 . The method of claim 1 wherein a first challenge in the set of challenges corresponds to selection of at least one element in the PUF and at least one response in the set of responses is a result of the selection.

3 . The method of claim 1 wherein a first challenge in the set of challenges corresponds to configuration of at least one element in the PUF and at least one response in the set of responses is a result of the configuration.

4 . The method of claim 1 wherein generating the at least one potential key comprises applying error correction based on helper data to the set of responses.

5 . The method of claim 1 wherein:

the set of challenges consists of a single challenge,

the set of responses consists of a single response by the PUF responsive to the single challenge,

the at least one potential key is a single potential key, and

the single potential key is based on at least a part of the single response.

6 . The method of claim 5 wherein generating the at least one potential key comprises generating helper data responsive to the single response by the PUF.

7 . The method of claim 1 wherein the set of challenges consists of two or more challenges.

8 . The method of claim 1 , wherein combining the at least two responses comprises combining at least a first part of a first response and a second part of a second response.

9 . The method of claim 8 wherein the at least one potential key consists of two or more potential keys, and wherein each of the two or more potential keys are formed by at least one function taking at least one part of each of the two or more responses as input.

10 . The method of claim 1 , wherein generating the at least one potential key comprises applying error correction using helper data to at least one of the two or more responses.

11 . The method of claim 1 , further comprising providing the set of challenges used to generate the valid key to the client.

12 . The method of claim 11 wherein:

generating the potential key comprises generating the potential key based on the set of responses by the PUF responsive to the set of challenges and associated helper data; and

the method further comprising at least one of providing the associated helper data used to generate the valid key to the client or saving the associated helper data locally in the client.

13 . The method of claim 1 , wherein:

generating the set of challenges for the PUF comprises generating the set of challenges for the PUF based on a state of a state module; and

the method further comprising at least one of providing to the client the state used to generate the set of challenges used to generate the valid key or saving the state locally in the client.

14 . The method of claim 1 further comprising storing information that indicates the set of challenges used to generate the valid key in association with a tag or an identifier, and providing the tag or the identifier to the client.

15 . The method of claim 1 , wherein receiving the request to generate a key further comprises receiving a unique token, and generating the set of challenges for the PUF comprises generating the set of challenges for the PUF based on the unique token.

16 . The method of claim 15 wherein the unique token is one or more of a password, a Personal Identification Number, PIN, and biometric input.

17 . A device for generating a key for a cryptography algorithm, comprising:

one or more processing circuitries;

a memory storing instructions which, when executed by the one or more processing circuitries, cause the device to:

receive from a client a request to generate a key comprising a defined number, N, of bits for a particular cryptography algorithm;

responsive to receiving the request, provide a valid key for the particular cryptography algorithm to the client, wherein providing the valid key to the client comprises:

generating a set of challenges for a Physically Unclonable Function, PUF, wherein the set of challenges comprises one or more challenges from a plurality of challenges in a challenge space of the PUF;

generating at least one potential key based on a set of two or more responses by the PUF responsive to the set of challenges, wherein generating the at least one potential key comprises combining at least two responses included in the set of responses;

for each potential key of the at least one potential key:

determining whether the potential key satisfies one or more predefined criteria for the particular cryptography algorithm; and

in response to determining that the potential key satisfies the one or more predefined criteria for the particular cryptography algorithm, providing the potential key to the client as the valid key.