IP Library Granted Patent US 11,258,597
Granted Patent B2
US 11,258,597 · App. 16/629,735 · Granted Feb 22, 2022

Key derivation from PUFs

Inventors: Erik Van Der Sluis (Eindhoven, NL); Roel Maes (Eindhoven, NL)
Assignee: INTRINSIC ID B.V.
H04L9/0866H04L9/0869H04L9/3278H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,258,597
App. No.
16/629,735
Granted
Feb 22, 2022
Kind
B2
Abstract

Some embodiments relate to an electronic cryptographic device ( 100 ) arranged to determine a cryptographic key. The cryptographic device is arranged for an enrollment phase and a later reconstruction phase. The cryptographic device comprising a physically unclonable function (PUF) ( 110 ) and a processor circuit. The circuit being configured to determine during the enrollment phase debiasing data ( 142 ), first noise reduction data ( 131 ) and first noise reduction data. The circuit being configured to during the reconstruction phase compute at least one cryptographic key from first corrected bits and second corrected bits.

Claims (30)

1. An electronic cryptographic device arranged to determine a cryptographic key, the cryptographic device being arranged for an enrollment phase and a later reconstruction phase, the cryptographic device comprising:

a physically unclonable function arranged to produce a first noisy bit string during the enrollment phase and a second noisy bit string during the reconstruction phase, and

a processor circuit configured to

determine, during the enrollment phase, debiasing data from the first noisy bit string, the debiasing data marking a first part of the first noisy bit string as low bias susceptible, and marking a second part of the first noisy bit string as high bias susceptible,

determine during the enrollment phase a first noise reduction data for the first part, and a second noise reduction data for the second part, noise reduction data allowing later correction during the reconstruction phase of differences between the second noisy bit string and the first noisy bit string,

identify during the reconstruction phase a first part and a second part in the second noisy bit string based on the debiasing data,

perform a first correction of differences between the first part of the second noisy bit string and the first part of the first noisy bit string based on the first noise reduction data thus obtaining first corrected bits, and perform a second correction of differences between the second part of the second noisy bit string and the second part of the first noisy bit string based on the second noise reduction data thus obtaining second corrected bits, wherein the first correction and second correction are independent from each other,

compute at least one cryptographic key from the first corrected bits and the second corrected bits.

2. An electronic cryptographic device as in claim 1 , wherein the processor circuit is configured to select, during the enrollment phase, one or more first code words from an error correcting code and one or more second code words from an error correcting code, wherein

determining a bit of the first noise reduction data comprises computing the offset between a corresponding bit in the first part of the first noisy bit string and a corresponding bit in the one or more first code words, and

determining a bit of the second noise reduction data comprises computing the offset between a corresponding bit in the second part of the first noisy bit string and a corresponding bit in the one or more second code words.

3. An electronic cryptographic device as in claim 2 , wherein the one or more first code words are as long or longer as the first noisy bit string, wherein the one or more second code words are as long or longer as the first noisy bit string, each bit in the first noisy bit string corresponding to a bit in the one or more first code words and to a bit in the one or more second code words.

4. An electronic cryptographic device as in claim 2 , wherein the processor circuit is configured to:

determine the offsets between the first noisy bit string and the one or more first code words only for the bits in the first part of the first noisy bit string, and

determine the offsets between the first noisy bit string and the one or more second code words only for the bits in the second part of the first noisy bit string.

5. An electronic cryptographic device as in claim 2 , wherein the processor circuit is arranged to select the one or more first or second code words from the first or second error correcting code by encoding one or more further code words from a further error correcting code.

6. An electronic cryptographic device as in claim 2 , wherein the error correcting code is a concatenated code wherein the inner code is a repetition code.

7. An electronic cryptographic device as in claim 1 , wherein performing a first correction of differences comprises;

obtaining one or more noisy first code words, by applying the first noise reduction data to bits in the first part of the second noisy bit string, and marking as erasures-bits, the bits in the one or more noisy first code words corresponding to bits in the second part of the second noisy bit string,

correcting said one or more noisy first code words using an error correcting algorithm, and/or wherein performing a second correction of differences comprises

obtaining one or more noisy second code words, by applying the second noise reduction data to bits in the second part of the second noisy bit string, and marking as erasures-bits, the bits in the one or more noisy second code words corresponding to bits in the first part of the second noisy bit string, and

correcting said one or more noisy second code words using an error correcting algorithm.

8. An electronic cryptographic device as in claim 1 , wherein the first and second noisy bit string are partitioned in a first and second sequence of bit pairs respectively, the processor circuit being configured to identify bits in unequal bit pairs in the first sequence of bit pairs as low bias susceptible, and to identify bits in equal bit pairs in the first sequence of bit pairs as high bias susceptible.

9. An electronic cryptographic device as in claim 8 , wherein

the debiasing data comprises a single bit for each pair in the first sequence of bit pairs identifying the pair as low or high bias susceptible,

the first noise reduction data comprises a single bit for each pair in the first part of the first noisy bit string, said bit indicating the offset between the pair in the first part of the first noisy bit string and a corresponding pair in one or more first code words, and

the second noise reduction data comprises a single bit for each pair in the second part of the first noisy bit string, said bit indicating the offset between the pair in the second part of the first noisy bit string and a corresponding pair in the one or more second code words.

10. An electronic cryptographic device as in claim 1 , wherein the combined bit size of the debiasing data, first noise reduction data and second noise reduction data equals the bit size of the first noisy bit string.

11. An electronic cryptographic device as in claim 1 , wherein the processor circuit is arranged to compute a single cryptographic key from at least part of the first corrected bits and at least part of the second corrected bits.

12. An electronic cryptographic device as in claim 1 , wherein the processor circuit is arranged to compute a first cryptographic key from at least part of the first corrected bits and a second cryptographic key from at least part of the second corrected bits.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2024
From: INTRINSIC ID B.V.
To: SYNOPSYS, INC.
Reel/Frame 067679/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2020
From: VAN DER SLUIS, ERIK; MAES, ROEL
To: INTRINSIC ID B.V.
Reel/Frame 051466/0589 →
Priority Claims (1)
EP 17180490 · Jul 10, 2017 · regional
Continuity (1)
Related Publication 20210152349A1 · May 20, 2021