IP Library › Granted Patent US 12,493,681
Granted Patent B2
US 12,493,681 · App. 17/765,529 · Granted Dec 9, 2025

PUF-rake: a PUF-based robust and lightweight authentication and key establishment protocol

Inventors: Mahmood Azhar Qureshi (Manhattan, KS); Arslan Munir (Manhattan, KS)
Assignee: Kansas State University Research Foundation
G06F21/44G06F21/73H04L9/3093H04L9/3278G06F2221/2103
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,681
App. No.
17/765,529
Granted
Dec 9, 2025
Kind
B2
Abstract

Low-resource overhead computer-implemented methods for enrolling, authenticating and establishing encryption keys for one or more queried devices, each of the queried devices including an electrical circuit configured to output electrical signals indica-five of a physically unclonable function (PUF) of the queried device. Authentication and encryption are implemented in low-resource queried device computational architectures, with embodiments of the present invention utilizing pseudo-random number generators configured based on unique primitive polynomials, masking and unmasking functions, and error correction protocols executed in a querying device.

Claims (63)

1 . A computer-implemented method for authentication enrollment for and authentication of a queried device having a queried memory element, a queried processing element, a queried communication element, and an electrical circuit configured to output electrical signals indicative of a physically unclonable function (PUF) of the queried device, the method comprising:

performing the authentication enrollment, including by—

storing a unique identification value at the queried device;

generating a primitive polynomial unique to the queried device;

generating a configuration file based at least in part on the unique primitive polynomial, the configuration file comprising a first pseudo-random number generator configured based on the unique primitive polynomial;

programming the queried device for authentication based at least in part on the configuration file including by storing the first pseudo-random number generator in non-volatile memory of the queried device;

generating a set of random numbers at the querying device by a first true random number generator;

submitting a challenge corresponding to each of the set of random numbers to the electrical circuit of the queried device to generate a PUF response, the challenges being based at least in part on output generated at the querying device by the first pseudo-random number generator using the set of random numbers as seeds;

storing the PUF response in a queried device database record accessible to a querying device;

performing the authentication of the queried device, including by—

transmitting the unique identification value from the queried device to the querying device;

via the querying device, retrieving the queried device database record;

at the queried device, generating a first random number and transmitting the first random number to the querying device;

at the querying device, generating a second random number and transmitting the second random number to the queried device;

at the queried device, using a masking function on the first random number to generate a masked first random number;

at the querying device, using the masking function on the second random number to generate a masked second random number;

at the querying device, using the masking function, masking the first random number received from the queried device;

at the queried device, using the masking function, masking the second random number received from the querying device;

at the querying device, generating an authentication challenge based at least in part on a retrieved record random number stored in connection with the retrieved queried device database record;

at the querying device, using the masking function, masking the authentication challenge and the retrieved record random number;

transmitting the masked challenge and the masked retrieved record random number from the querying device to the queried device;

at the queried device, using an unmasking function corresponding to the masking function to unmask the masked challenge;

at the queried device, using the unmasking function to unmask the masked retrieved record random number;

at the queried device, using the unmasked challenge and the unmasked random number to verify the querying device;

at the queried device, based on the verification of the querying device, unlocking the electrical circuit of the queried device;

at the queried device, generating a plurality of sub-challenges;

at the queried device, feeding the plurality of sub-challenges to the electrical circuit of the queried device to generate an authentication response;

at the queried device, using the masking function, masking the authentication response;

transmitting the masked response from the queried device to the querying device;

at the querying device, using the unmasking function, unmasking the masked response; and

at the querying device, making a comparison based at least in part on the unmasked response and the PUF response from the retrieved queried device database record to authenticate the queried device to the querying device.

2 . The computer-implemented method of claim 1 —

the queried device and the querying device being in electronic communication via one or more secured communication links,

the unique identification value and the set of random numbers being transmitted from the querying device to the queried device over the one or more secured communication links,

the PUF response being transmitted from the queried device to the querying device over the one or more secured communication links.

3 . The computer-implemented method of claim 1 , further comprising—

at the querying device, generating helper data based at least in part on the PUF response of the queried device,

wherein the database record includes, for each of the set of random numbers, the random number, the corresponding PUF response, the unique primitive polynomial, the unique identification value, and the helper data.

4 . The computer-implemented method of claim 1 —

the queried device and the querying device being in electronic communication via one or more unsecured communication links,

the second random number, the masked challenge and the masked retrieved record random number being transmitted from the querying device to the queried device over the one or more unsecured communication links,

the unique identification value, the first random number and the masked response being transmitted from the queried device to the querying device over the one or more unsecured communication links.

5 . The computer-implemented method of claim 1 , the retrieved record being encrypted upon retrieval, further comprising—

retrieving a random challenge from non-volatile memory of the querying device,

submitting the random challenge to a weak physically unclonable function of the querying device to generate a response comprising an encryption key,

decrypting the retrieved record using the encryption key.

6 . The computer-implemented method of claim 1 —

the querying device having the first pseudo-random number generator stored on non-volatile memory,

execution of the masking and unmasking functions relying on output from the first pseudo-random number generator.

7 . The computer-implemented method of claim 6 , further comprising—

following receipt of the unique identification value and retrieval of the queried device database record, retrieving the unique primitive polynomial from the queried device database record,

using the unique primitive polynomial to configure the first pseudo-random number generator at the querying device.

8 . The computer-implemented method of claim 6 —

the first pseudo-random number generator being based on a linear feedback shift register.

9 . The computer-implemented method of claim 6 —

the plurality of sub-challenges being generated at the queried device by a second pseudo-random number generator using the authentication challenge as a seed.

10 . The computer-implemented method of claim 1 —

the unmasked response comprising a noisy response,

the comparison to authenticate the queried device to the querying device including retrieving helper data from the retrieved queried device database record, generating a corrected response, and comparing the corrected response to the PUF response from the retrieved queried device database record.

11 . The computer-implemented method of claim 1 , wherein—

generating the masked response includes taking the masked second random number as input to XOR the authentication response.

12 . The computer-implemented method of claim 1 , wherein—

generating the first and second random numbers includes calculating the Hamming weight of a true random number generator output, comparing the Hamming weight against at least one threshold, and, if the threshold is not met, replacing the output with an additional true random number generator output.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2022
From: QURESHI, MAHMOOD AZHAR; MUNIR, ARSLAN
To: KANSAS STATE UNIVERSITY RESEARCH FOUNDATION
Reel/Frame 059541/0009 →
Continuity (3)
Provisional Application 63073527 · Sep 2, 2020
Provisional Application 62909085 · Oct 1, 2019
Related Publication 20220358203A1 · Nov 10, 2022
References Cited (12)
US 20100127822A1 · Devadas · 2010 [cited by applicant]
US 20110274193A1 · Yoon · 2011 [cited by examiner]
US 20140140513A1 · BrightSky et al. · 2014 [cited by applicant]
US 20140189890A1 · Koeberl et al. · 2014 [cited by applicant]
US 20150171870A1 · Parker · 2015 [cited by examiner]
US 20180006830A1 · Cambou · 2018 [cited by applicant]
US 20190349208A1 · Merchan · 2019 [cited by examiner]
US 20200412556A1 · Yoon · 2020 [cited by examiner]
International Search Report and Written Opinion in corresponding PCT/US2020/053467, dated Mar. 12, 2021. [cited by applicant]
Braeken, “PUF Based Authentication Protocol for IoT”, Symmetry, 2018, 10, 352, 15 pages. [cited by applicant]
Halak, et al., “Overview of PUF-based hardware security solutions for the Internet of Things”, IEEE 59th International Midwest Symposium on Circuits and Systems, 2016, 4 pages. [cited by applicant]
Suh, et al., “Physical Unclonable Functions for Device Authentication and Secret Key Generation”, DAC, 2007, 6 pages. [cited by applicant]