IP Library Granted Patent US 9,946,858
Granted Patent B2
US 9,946,858 · App. 14/746,054 · Granted Apr 17, 2018

Authentication system and device including physical unclonable function and threshold cryptography

Inventor: John Ross Wallrabenstein (West Lafayette, IN)
Assignee: Analog Devices, Inc.
G06F21/31G09C1/00H04L9/3278G06F2221/2129H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,946,858
App. No.
14/746,054
Granted
Apr 17, 2018
Kind
B2
Abstract

An authentication system and device including physical unclonable function (PUF) and threshold cryptography comprising: a PUF device having a PUF input and a PUF output and constructed to generate, in response to the input of a challenge, an output value characteristic to the PUF and the challenge; and a processor having a processor input that is connected to the PUF output, and having a processor output connected to the PUF input, the processor configured to: control the issuance of challenges to the PUF input via the processor output, receive output from the PUF output, combine multiple received PUF output values each corresponding to a share of a private key or secret, and perform threshold cryptographic operations. The system and device may be configured so that shares are refreshable, and may be configured to perform staggered share refreshing.

Claims (47)

1. An authenticatable device for use with an authentication system for processing arbitrary cryptographic operations on auxiliary data communicated to the device, comprising:

one or more physical unclonable function (‘PUF’) devices internal to the authenticatable device; and

at least one processor internal to the authenticable device and operatively connected to the one or more PUF devices, wherein the at least one processor is configured to:

issue a first challenge to a first PUF device of the one or more PUF devices and receive a first output value from the first PUF device in response to issuing the first challenge;

recover, internal to the authenticatable device, a first share of a private key or secret encoded with the one or more PUFs, wherein the first share is mapped to the first output value;

perform a first threshold cryptographic operation with the first share and the auxiliary data;

issue a second challenge to the first PUF device or a second PUF device of the one or more PUF devices having a mapping to a second share and receive a second output value mapped to the second share in response to issuing the second challenge;

recover, internal to the authenticatable device, a second share of the private key or secret, encoded with the one or more PUFs, the second share different from the first share and mapped to the second output value;

perform a second threshold cryptographic operation with the second share and the auxiliary data; and

enable processing of the arbitrary cryptographic operation with a combined output of at least the first and second threshold cryptographic operations.

2. The authenticatable device of claim 1 , wherein the authenticatable device comprises more than one PUF device internal to the authenticatable device.

3. The authenticatable device of claim 2 , wherein the at least one processor comprises more than one logical core.

4. The authenticatable device of claim 1 , wherein the at least one processor is further configured to perform a share refresh procedure to refresh shares of the private key or secret.

5. The authenticatable device of claim 4 , wherein the at least one processor is further configured to divide the share refresh procedure into a preparation phase and an application phase.

6. The authenticatable device of claim 5 , wherein the at least one processor is further configured to perform a preparation phase that comprises generating share update information, and to perform an application phase that comprises applying the share update information to one or more shares.

7. The authenticatable device of claim 6 , wherein the at least one processor is further configured to perform the preparation and application phases such that only one share refresh procedure is performed at once.

8. The authenticatable device of claim 7 , wherein the authenticatable device includes a reconfigurable PUF device.

9. The authenticatable device of claim 1 , wherein the at least one processor is further configured to combine multiple internal cryptographic operations to yield a cryptographic output.

10. The authenticatable device of claim 1 , wherein the at least one processor is further configured to perform a zero knowledge proof authentication protocol.

11. The authenticatable device of claim 1 , wherein the at least one processor is further configured to perform distributed key generation.

12. The authenticatable device of claim 1 , wherein the at least one processor comprises more than one logical core, and the at least one processor is configured so that a first one of the more than one logical core can issue a challenge, recover a share, and perform a cryptographic operation in parallel with a second one of the more than one logical core.

13. The authenticatable device of claim 1 , wherein the at least one processor is further configured to combine cryptographic operations on the first and the second shares without generating the private key or secret in memory.

14. The authenticatable device of claim 1 , wherein the first share recovered is associated with the output received from the first PUF device based on at least a respective helper value.

15. The authenticatable device of claim 14 , wherein the helper value is stored on the authenticatable device.

16. The authenticatable device of claim 1 , wherein the at least one processor is configured to issue a different challenge for each challenge.

17. A computer implemented method of authenticating an authenticatable device for processing arbitrary cryptographic operations on auxiliary data communicated to the authenticatable device, the method comprising:

issuing, by at least one processor internal to the authenticatable device, a first challenge to a first PUF device operatively connected with the at least one processor;

receiving, by the at least one processor, a first output value from the first PUF device in response to issuing the first challenge;

recovering, internal to the authenticatable device by the at least one processor, a first share of a private key or secret encoded with the one or more PUFs, wherein the first share is mapped to the first output value;

performing a first threshold cryptographic operation with the first share;

issuing, by the at least one processor, a second challenge to the first PUF device or a second PUF device of the at least one PUF device having a mapping to a second share;

receiving, by the at least one processor, a second output value in response to issuing the second challenge;

recovering, internal to the authenticable device by the at least one processor, the second share of the private key or secret, encoded with the one or more PUFs, the second share different from the first share, and mapped to the second output value;

performing a second threshold cryptographic operation with the second share; and

enabling processing of the arbitrary cryptographic operation with a combined output of at least the first and second threshold cryptographic operations.

18. The method according to claim 17 , further comprising an act of enabling arbitrary operations to be performed without generating the private key or the secret in memory, wherein the act of enabling includes combining threshold cryptographic operations on the first and second shares.

19. The method according to claim 17 , further comprising an act of refreshing, by the at least one processor, shares of the private key or secret.

20. At least one non-transitory computer-readable storage medium containing processor-executable instructions that, when executed, perform a method for processing arbitrary cryptographic operations on auxiliary data communicated to an authenticatable device comprising:

issuing a first challenge to a first PUF device operatively connected to at least one processor internal to the authenticatable device;

receiving a first output value from the first PUF device in response to issuing the first challenge;

recovering, internal to the authenticatable device, a first share of a private key or secret encoded with the one or more PUFs, wherein the first share is mapped to the first output value;

performing a first threshold cryptographic operation with the first share;

issuing a second challenge to the first PUF device or a second PUF device of the at least one PUF device having a mapping to a second share;

receiving a second output value in response to issuing the second challenge;

recovering, internal to the authenticatable device, a second share of the private key or secret, different from the first share, mapped to the second output value;

performing a second threshold cryptographic operation with the second share; and

enabling processing of the arbitrary cryptographic operation with a combined output of at least the first and second threshold cryptographic operations.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2017
From: SYPRIS ELECTRONICS, LLC
To: ANALOG DEVICES, INC.
Reel/Frame 041079/0878 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: GREAT ROCK CAPITAL PARTNERS MANAGEMENT, LLC
To: SYPRIS SOLUTIONS, INC.; SYPRIS DATA SYSTEMS, INC.; SYPRIS ELECTRONICS, LLC; SYPRIS TECHNOLOGIES, INC.; SYPRIS TECHNOLOGIES INTERNATIONAL, INC.; SYPRIS TECHNOLOGIES KENTON, INC.; SYPRIS TECHNOLOGIES MARION, LLC; SYPRIS TECHNOLOGIES MEXICAN HOLDINGS, LLC; SYPRIS TECHNOLOGIES NORTHERN, INC.; SYPRIS TECHNOLOGIES SOUTHERN, INC.
Reel/Frame 039759/0328 →
RELEASE OF SECURITY INTEREST Recorded Sep 15, 2016
From: SIENA LENDING GROUP, LLC
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 039759/0348 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2016
From: WALLRABENSTEIN, JOHN ROSS
To: SYPRIS ELECTRONICS, LLC
Reel/Frame 038430/0677 →
SECURITY AGREEMENT Recorded Nov 5, 2015
From: SYPRIS SOLUTIONS, INC.; SYPRIS DATA SYSTEMS, INC.; SYPRIS ELECTRONICS, LLC; SYPRIS TECHNOLOGIES, INC.; SYPRIS TECHNOLOGIES INTERNATIONAL, INC.; SYPRIS TECHNOLOGIES KENTON, INC.; SYPRIS TECHNOLOGIES MARION, LLC; SYPRIS TECHNOLOGIES MEXICAN HOLDINGS, LLC; SYPRIS TECHNOLOGIES NORTHERN, INC.; SYPRIS TECHNOLOGIES SOUTHERN, INC.
To: GREAT ROCK CAPITAL PARTNERS MANAGEMENT, LLC
Reel/Frame 037055/0796 →
Continuity (5)
Continuation In Part 14704914 · May 5, 2015
Provisional Application 62150586 · Apr 21, 2015
Provisional Application 61988848 · May 5, 2014
Provisional Application 62128920 · Mar 5, 2015
Related Publication 20160269186A1 · Sep 15, 2016