IP Library Patent Application 14103599
Patent Application
App. No. 14/103,599

Authentication System

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/103,599
Abstract

A device authentication system for use with an authenticatable device having a physically-unclonable function and constructed to, in response to input of challenge C, internally generate an output O characteristic to the PUF and the challenge C, and configured to: i) upon receiving challenge C, generate a corresponding commitment value that depends upon a private value r, and ii) upon receiving an authentication query that includes the challenge C and a nonce, return a zero knowledge proof authentication value that corresponds to the commitment value. The system comprises an enrollment server having a working verification set that includes challenge C and corresponding commitment value, wherein: a) the enrollment server is configured to generate an authentication token that corresponds to the authentication value and includes a blinded value depending upon the private value r and a random value decryptable by the authenticatable device; and/or b) the system is configured to pre-process and convey data to the authenticatable device as part of an extended Boyko-Peinado-Venkatesan generation.

Claims (45)

1 - 33 . (canceled)

34 . An authentication system for use with an authenticatable device constructed so as to, in response to the input of a specific challenge C, internally generate an output O that is characteristic to the device and the specific challenge C, and configured to: i) upon receiving the specific challenge C, generate a corresponding commitment value that depends upon the output O and a private value r, and ii) upon receiving an authentication query that includes the specific challenge C and a nonce, return a zero knowledge proof authentication value that corresponds to the commitment value; the authentication system comprising an enrollment server that:

a) has a working verification set that includes the specific challenge C and the authenticatable device's corresponding commitment value; and

b) is configured to generate an authentication token that:

i) includes a blinded value that depends upon the private value r and a random value that can be decrypted by the authenticatable device; and

ii) corresponds to the zero knowledge proof authentication value.

35 . The authentication system of claim 34 , wherein the enrollment server is configured to generate the random value.

36 . The authentication system of claim 34 , wherein the enrollment server is configured to encrypt the random value with a key that is shared with the authenticatable device.

37 . The authentication system of claim 34 , wherein the commitment value is an exponential function of the private value r.

38 . The authentication system of claim 34 , wherein the blinded value depends exponentially upon the private value r multiplied by the random value.

39 . The authentication system of claim 34 , wherein the commitment value is an exponential function of the private value r and wherein the blinded value depends exponentially upon the private value r multiplied by the random value.

40 . The authentication system of claim 34 , wherein the random value is an element of a group of prime order.

41 . The authentication system of claim 34 , wherein the enrollment server is configured to generate a limited verification set that includes the specific challenge C and authentication token.

42 . The authentication system of claim 41 , wherein the limited verification set further includes an error-correction helper string, and the dependency of the commitment value upon the output O consists of a dependency upon the error-correction helper string.

43 . The authentication system of claim 41 , further comprising an authentication server having the limited verification set.

44 . The authentication system of claim 41 , further comprising a plurality of authentication servers each having a different limited verification set, wherein each limited verification set includes the specific challenge C and a corresponding token that is specific to the particular authentication server.

45 . The authentication system of claim 34 , wherein the enrollment server has a complete verification set that includes multiple different specific challenge values and the authenticatable device's corresponding commitment values.

46 . The authentication system of claim 34 , wherein the enrollment server possesses challenge values and corresponding commitment values for multiple authenticatable devices.

47 . The authentication system of claim 34 , wherein the output O of the authenticatable device which the system is for use with is generated by a physically-unclonable function (‘PUF’) in the authenticatable device.

48 . The authentication system of claim 47 , wherein the PUF of the authenticatable device which the system is for use with is a strong PUF.

49 . The authentication system of claim 47 , wherein the PUF of the authenticatable device which the system is for use with resides in a field-programmable gate array.

50 . The authentication system of claim 34 , further comprising an authenticatable device having a physically-unclonable function (‘PUF’) capable of generating the output O.

51 . The authentication system of claim 50 , wherein the PUF resides in a field-programmable gate array.

52 . The authentication system of claim 34 , wherein the system is further configured to perform operations as part of an extended Boyko-Peinado-Venkatesan generation.

53 . An authentication system for use with an authenticatable device constructed so as to, in response to the input of a specific challenge C, internally generate an output O that is characteristic to the device and the specific challenge C, and configured to: i) upon receiving the specific challenge C, generate a corresponding commitment value that depends upon the output O and a private value r, and ii) upon receiving an authentication query that includes the specific challenge C and a nonce, return a zero knowledge proof authentication value that corresponds to the commitment value; wherein the authentication system:

a) includes an enrollment server that has a working verification set including the specific challenge C and the authenticatable device's corresponding commitment value; and

b) is configured to pre-process and convey data to the authenticatable device as part of an extended Boyko-Peinado-Venkatesan generation.

54 . The authentication system of claim 53 , wherein the data includes exponents for a prime group.

55 . The authentication system of claim 54 , wherein the data includes a group generator.

56 . The authentication system of claim 53 , wherein the data includes an error-correction helper string, and wherein the dependency of the commitment value upon the output O consists of a dependency upon the error-correction helper string.

57 . The authentication system of claim 53 , further comprising an authentication server.

58 . The authentication system of claim 53 , wherein the enrollment server is configured to pre-process and convey data to the authenticatable device as part of an extended Boyko-Peinado-Venkatesan generation.

59 . The authentication system of claim 58 , wherein the data includes exponents for a prime group, and a group generator.

60 . The authentication system of claim 53 , wherein the output O of the authenticatable device which the system is for use with is generated by a physically-unclonable function (‘PUF’) in the authenticatable device.

61 . An authenticatable device for use with an authentication system, comprising:

a) an internal input and an internal output constructed so as to, in response to the internal input of a specific challenge C, generate an internal output O that is characteristic to the device and the specific challenge C;

b) a processor having a processor input that is connected to the internal output, the processor configured to:

i) in response to the receipt of an output O from the internal output, generate a commitment value that depends upon the output O and a private value r; and

ii) in response to the contemporaneous receipt of an authentication query that includes a nonce and of an output O from the internal output, return a zero knowledge proof authentication value that corresponds to the commitment value;

wherein the zero knowledge proof authentication value further corresponds to an authentication token that includes a blinded value that depends upon the private value r and a random value, and wherein the processor is configured to decrypt the random value.

62 . The authenticatable device of claim 61 , further comprising a physically-unclonable function (‘PUF’) having a PUF input and a PUF output, wherein the PUF input is the internal input and the PUF output is the internal output, and wherein the output O is characteristic to the PUF.

63 . The authenticatable device of claim 62 , wherein the dependency of the commitment value upon the output O consists of a dependency upon an error-correction helper string.

64 . The authenticatable device of claim 61 , wherein the PUF is a strong PUF.

65 . The authenticatable device of claim 61 , further comprising a field-programmable gate array (‘FPGA’), wherein the PUF resides in the FPGA.

66 . The authenticatable device of claim 65 , wherein the FPGA is part of a Spartan®-6 FPGA SP605 development board.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2017
From: SYPRIS ELECTRONICS, LLC
To: ANALOG DEVICES, INC.
Reel/Frame 041079/0878 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: GILL FAMILY CAPITAL MANAGEMENT INC.
To: SYPRIS ELECTRONICS, LLC
Reel/Frame 039759/0201 →
RELEASE OF SECURITY INTEREST Recorded Nov 9, 2015
From: MERITOR HEAVY VEHICLE SYSTEMS, LLC
To: SYPRIS TECHNOLOGIES, INC.; SYPRIS ELECTRONICS, LLC
Reel/Frame 036988/0886 →
ASSIGNMENT OF GRANT OF SECURITY INTEREST IN TRADEMARKS AND PATENTS Recorded Nov 5, 2015
From: PNC BANK, NATIONAL ASSOCIATION
To: SIENA LENDING GROUP, LLC
Reel/Frame 037055/0258 →
SECURITY INTEREST Recorded Sep 10, 2015
From: SYPRIS TECHNOLOGIES, INC.; SYPRIS ELECTRONICS, LLC
To: GILL FAMILY CAPITAL MANAGEMENT, INC.
Reel/Frame 036529/0261 →
SECURITY INTEREST Recorded Jul 20, 2015
From: SYPRIS ELECTRONICS, LLC
To: MERITOR HEAVY VEHICLE SYSTEMS, LLC
Reel/Frame 036134/0194 →
SECURITY INTEREST Recorded Feb 12, 2015
From: SYPRIS TECHNOLOGIES, INC.; SYPRIS ELECTRONICS, LLC
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 034945/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2014
From: WALLRABENSTEIN, JOHN ROSS
To: SYPRIS ELECTRONICS, LLC
Reel/Frame 032463/0681 →