IP Library Granted Patent US 10,956,557
Granted Patent B2
US 10,956,557 · App. 16/067,757 · Granted Mar 23, 2021

Privacy-preserving, mutual PUF-based authentication protocol

Inventors: James Plusquellic (Albuquerque, NM); Wenjie Che (Albuquerque, NM); Dylan Ismari (Albuquerque, NM)
G06F21/445G06F21/30G06F21/44G06F21/70G06F21/73H04L9/0662H04L9/0866H04L9/3234H04L9/3278G06F7/588H04L2209/08H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,956,557
App. No.
16/067,757
Granted
Mar 23, 2021
Kind
B2
Abstract

An authentication protocol using a Hardware-Embedded Delay PUF (“HELP”), which derives randomness from within-die path delay variations that occur along the paths within a hardware implementation of a cryptographic primitive, for example, the Advanced Encryption Standard (“AES”) algorithm or Secure Hash Algorithm 3 (“SHA-3”). The digitized timing values which represent the path delays are stored in a database on a secure server (verifier) as an alternative to storing PUF response bitstrings thereby enabling the development of an efficient authentication protocol that provides both privacy and mutual authentication.

Claims (22)

1. A Physically Unclonable Function (PUF) method for authenticating a token by a server to prevent cloning and unauthorized use of Integrated Circuits, the method providing both privacy and mutual identification between the server and the token, the method comprising the steps of:

measuring, by the PUF, natural variations that occur in one or more path delays of the PUF;

digitizing the measured one or more path delays;

storing in a database of the server, the digitized measured one or more path delays;

generating a plurality of bitstrings from the digitized measured one or more path delays;

comparing the bitstrings of the plurality to bitstrings of the token; and

authenticating the token when the comparing step results in one or more matches.

2. The method according to claim 1 , wherein the plurality of bitstrings is generated on-the-fly.

3. The method according to claim 1 further comprising the step of generating by the token both a token helper data bitstring and a token bitstring.

4. The method according to claim 3 further comprising the step of generating by the server both a server helper data bitstring and a server bitstring.

5. The method according to claim 4 further comprising the steps:

modifying the token bitstring by eliminating one or more bits from the token bitstring; and

modifying the server bitstring by eliminating one or more bits from the server bitstring.

6. The method according to claim 5 , wherein the modified server bitstring is compared to the modified token bitstring to authenticate the token.

7. The method according to claim 5 , further comprising the step of using the server helper data bitstring to modify the server bitstring and using the token helper data bitstring to modify the token bitstring.

8. The method according to claim 5 further comprising the steps of:

performing an operation to bitwise AND the token helper data bitstring from the token to obtain a AND'ed token helper data bitstring; and

performing an operation to bitwise AND the server helper data bitstring to obtain a AND'ed server helper data bitstring.

9. The method according to claim 8 , wherein the one or more bits eliminated from the token bitstring are bits that correspond to bits in the AND'ed token helper data bitstring that are logic 0 because of the bitwise AND operation, and the one or more bits eliminated from the server bitstring are bits that correspond to bits in the AND'ed server helper data bitstring that are logic 0 because of the bitwise AND operation.

10. The method according to claim 1 , wherein the PUF is provided in a hardware implementation of a cryptographic primitive.

11. The method according to claim 10 , wherein the cryptographic primitive is an Advanced Encryption Standard (“AES”) algorithm.

12. The method according to claim 10 , wherein the cryptographic primitive is a Secure Hash Algorithm 3 (“SHA-3”).

Assignments (1)
CONFIRMATORY LICENSE Recorded Nov 7, 2019
From: UNIVERSITY OF NEW MEXICO
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 050966/0191 →
Continuity (5)
Provisional Application 62277276 · Jan 11, 2016
Provisional Application 62296490 · Feb 17, 2016
Provisional Application 62344754 · Jun 2, 2016
Provisional Application 62417611 · Nov 4, 2016
Related Publication 20190026457A1 · Jan 24, 2019
Cited By (1)
US 12,470,948