IP Library Granted Patent US 12,627,513
Granted Patent B2
US 12,627,513 · App. 17/556,979 · Granted May 12, 2026

Methods and apparatus to derive and verify virtual physical unclonable keys

Inventors: Tat Kin Tan (Penang, MY); Siew Chin Lim (Penang, MY); Boon Khai Ng (Penang, MY)
Assignee: Altera Corporation
H04L9/3278H04L9/0825H04L9/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,513
App. No.
17/556,979
Granted
May 12, 2026
Kind
B2
Abstract

Methods, apparatus, systems, and articles of manufacture are disclosed. An example apparatus includes: instructions; and processor circuitry to execute the instructions to: retrieve a random number and a physical unclonable function (PUF) from a trusted environment; generate a virtual PUF (vPUF) based on a trusted operation including the random number and the PUF; and store the vPUF and the random number in a persistent storage.

Claims (41)

1 . An apparatus comprising:

physical unclonable function (PUF) circuitry to provide a PUF;

number generation circuitry;

instructions; and

at least one programmable circuit to be programmed based on the instructions to:

generate a first virtual PUF (vPUF) based on a first message from a first client device, the first vPUF based on a trusted operation performed with a first number from the number generation circuitry and the PUF;

generate a second vPUF based on a second message from a second client device, the second vPUF based on the trusted operation performed with a second number from the number generation circuitry and the PUF;

cause transmission of the first vPUF to the first client device and cause transmission of the second vPUF to the second client device;

cause storage of the first vPUF, the first number, the second vPUF and the second number in a persistent storage; and

in response to a verification request from a third client device, the verification request including a third vPUF, use the third vPUF to look up a third number in the persistent storage, generate a fourth vPUF based on the trusted operation performed with the third number and the PUF, compare the fourth vPUF to the third vPUF to determine a verification result, and provide the verification result to the third client device.

2 . The apparatus of claim 1 , wherein the first number is a random number.

3 . The apparatus of claim 1 , wherein one or more of the at least one programmable circuit is to generate a third vPUF based on a third message from a third client device, the third vPUF based on the PUF and a third number from the number generation circuitry.

4 . The apparatus of claim 1 , wherein the first vPUF is associated with a microservice.

5 . The apparatus of claim 1 , wherein the trusted operation includes an involutory function.

6 . The apparatus of claim 5 , wherein the involutory function is an XOR operation.

7 . The apparatus of claim 1 , wherein one or more of the at least one programmable circuit is to:

determine the third vPUF is valid based on the third vPUF matching the fourth vPUF; and

determine the third vPUF is invalid based on the third vPUF not matching the fourth vPUF.

8 . The apparatus of claim 1 , wherein the first message is a request from the first client device for a session key to access a microservice, and one or more of the at least one programmable circuit is to cause the transmission of the first vPUF to the first client device to occur as a response to the request.

9 . A non-transitory computer readable medium comprising instructions to cause at least one programmable circuit to at least:

retrieve a physical unclonable function (PUF) from PUF circuitry:

generate a first virtual PUF (vPUF) based on a first message from a first client device, the first vPUF based on a trusted operation performed with a first number from number generation circuitry and the PUF;

generate a second vPUF based on a second message from a second client device, the second vPUF based on the trusted operation performed with a second number from the number generation circuitry and the PUF;

cause transmission of the first vPUF to the first client device and cause transmission of the second vPUF to the second client device;

cause storage of the first vPUF, the first number, the second vPUF and the second number in a persistent storage; and

in response to a verification request from a third client device, the verification request including a third vPUF, use the third vPUF to look up a third number in the persistent storage, generate a fourth vPUF based on the trusted operation performed with the third number and the PUF, compare the fourth vPUF to the third vPUF to determine a verification result, and provide the verification result to the third client device.

10 . The non-transitory computer readable medium of claim 9 , wherein the instructions are to cause one or more of the at least one programmable circuit to generate a third vPUF based on a third message from a third client device, the third vPUF based on the PUF and a third number from the number generation circuitry.

11 . The non-transitory computer readable medium of claim 9 , wherein the first vPUF is associated with a microservice.

12 . The non-transitory computer readable medium of claim 9 , wherein the trusted operation includes an involutory function.

13 . The non-transitory computer readable medium of claim 12 , wherein the involutory function is an XOR operation.

14 . A method comprising:

retrieving a physical unclonable function (PUF) from PUF circuitry:

generating a first virtual PUF (vPUF) based on a first message from a first client device, the first vPUF based on a trusted operation performed with a first number from number generation circuitry and the PUF;

generating a second vPUF based on a second message from a second client device, the second vPUF based on the trusted operation performed with a second number from the number generation circuitry and the PUF;

transmitting the first vPUF to the first client device and transmitting the second vPUF to the second client device;

storing the first vPUF, the first number, the second vPUF and the second number in a persistent storage; and

in response to a verification request from a third client device, the verification request including a third vPUF, using the third vPUF to look up a third number in the persistent storage, generating a fourth vPUF based on the trusted operation performed with the third number and the PUF, comparing the fourth vPUF to the third vPUF to determine a verification result, and providing the verification result to the third client device.

15 . The method of claim 14 , including generating a third vPUF based on a third message from a third client device, the third vPUF based on the PUF and a third number from the number generation circuitry.

16 . The method of claim 14 , wherein the first vPUF is associated with a microservice.

17 . The method of claim 16 , wherein the trusted operation includes an involutory function.

18 . The method of claim 17 , wherein the involutory function is an XOR operation.

Assignments (3)
SECURITY INTEREST Recorded Sep 12, 2025
From: ALTERA CORPORATION
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 073431/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: INTEL CORPORATION
To: ALTERA CORPORATION
Reel/Frame 066353/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2022
From: TAN, TAT KIN; LIM, SIEW CHIN; NG, BOON KHAI
To: INTEL CORPORATION
Reel/Frame 058858/0991 →
Continuity (1)
Related Publication 20220116234A1 · Apr 14, 2022
References Cited (16)
US 11340978B2 · Tan et al. · 2022 [cited by applicant]
US 11985236B2 · Hunacek · 2024 [cited by examiner]
US 20060101454A1 · Whitehead · 2006 [cited by examiner]
US 20170177302A1 · Tan · 2017 [cited by examiner]
US 20170288869A1 · Li · 2017 [cited by examiner]
US 20190250969A1 · Tan et al. · 2019 [cited by applicant]
US 20220012106A1 · Tan et al. · 2022 [cited by applicant]
US 20220129252A1 · Abdul Rashid et al. · 2022 [cited by applicant]
US 20220171659A1 · Tan et al. · 2022 [cited by applicant]
US 20220376920A1 · Aune · 2022 [cited by examiner]
European Patent Office, “Extended European Search Report,” issued in connection with European Patent Application No. 22206990, dated May 16, 2023, 9 pages. [cited by applicant]
Fyrbiak et al., “Combined HW-SW adaptive clone-resistant functions as physical security anchors,” 2013 NASA/ESA Conference on Adaptive Hardware and Systems (AHS-2013), IEEE, dated Jun. 24, 2013, 8 pages. [cited by applicant]
Mulhem et al., “Mini-Block-Based Cipher Class for Physically Clone-Resistant Devices,” 2019 Eighth International Conference on Emerging Security Technologies (EST), IEEE, Jul. 22, 2019, 6 pages. [cited by applicant]
Sampangi et al., “HiveSec: security in resource-constrained wireless networks inspired by beehives and bee swarms,” International Journal of Information Security, dated Jul. 6, 2016, 17 pages. [cited by applicant]
Mulhem et al., “Security and Complexity Bounds of SUC-Based Physical Identity,” 2018 NASA/ESA Conference on Adaptive Hardware and Systems (AHS), IEEE, dated Aug. 6, 2018, 6 pages. [cited by applicant]
Mulhem et al., “Chaining trusted links by deploying secured physical identities,” 2017 Seventh International Conference on Emerging Security Technologies (EST), IEEE, dated Sep. 6, 2017, 6 pages. [cited by applicant]