IP Library Granted Patent US 12,671,597
Granted Patent B2
US 12,671,597 · App. 17/634,536 · Granted Jun 30, 2026

Secure identity card using unclonable functions

Inventor: Martin Kaufmann (Graz, AT)
Assignee: ASSA ABLOY AB
H04L9/3278
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,671,597
App. No.
17/634,536
Filed
Feb 10, 2022
Granted
Jun 30, 2026
Kind
B2
Art Unit
2499
USPC
713/168
Abstract

Various systems and methods for securely sharing private information are described herein. A user device includes a memory device; and a processor subsystem, which when configured by instructions stored on the memory device, is operable to perform the operations comprising: receiving, at a verifier device, an indication of supported unclonable functions and a challenge value; identifying an unclonable function from the supported unclonable functions, to obtain a selected unclonable function; executing the selected unclonable function based on the challenge value, to obtain a result; and transmitting the indication of supported unclonable functions, the selected unclonable function, and the result to the verifier device to authenticate the user device.

Claims (42)

1 . A machine-readable medium including instructions for securing data on a user device having a manufactured physically unclonable function (PUF) provided to the user device in the form of a credential or identity card by an issuer, which when executed by the user device during a transaction when a user with the user device is asked to present the user device to a verifier device, cause the user device to perform operations comprising:

receiving, from the verifier device, a challenge message including a list of identifiers of supported unclonable functions and a challenge value, wherein the verifier device selects a challenge from known challenge/response pairs and transmits it to the user device as part of the challenge message, wherein the known challenge/response pairs are stored in a secure storage;

identifying an unclonable function from the list of identifiers of supported unclonable functions, to obtain an identifier of a selected unclonable function and selecting, by the user device the identifier of the selected unclonable function to provide an indication to the verifier device of which unclonable function will be used;

executing the selected unclonable function based on the challenge value, to obtain a result; and

transmitting, a reply message in response to the challenge message, the reply message including the list of identifiers of supported unclonable functions, the identifier of the selected unclonable function, and the result to the verifier device to authenticate the user device, wherein the verifier device is then able to check and ensure that the response is correct by comparing the result of the challenge/response pair corresponding with the challenge sent in the challenge message with that provided by the user device to authenticate the credential or the identity card.

2 . The machine-readable medium of claim 1 , wherein the list of identifiers of supported unclonable functions is included in a field of a message structure.

3 . The machine-readable medium of claim 1 , wherein the challenge value is a random value.

4 . The machine-readable medium of claim 1 , wherein the selected unclonable function is a physically unclonable function (PUF).

5 . The machine-readable medium of claim 4 , wherein executing the unclonable function based on the challenge value comprises:

executing the PUF with the challenge value as an input bit value for the PUF.

6 . The machine-readable medium of claim 1 , wherein the selected unclonable function is a software-based unclonable function.

7 . The machine-readable medium of claim 6 , wherein executing the unclonable function based on the challenge value comprises:

executing the software-based unclonable function with the challenge value as an input value to the software-based unclonable function.

8 . The machine-readable medium of claim 1 , wherein a credential is stored in a memory device of the user device and the selected unclonable function is used to secure the credential.

9 . The machine-readable medium of claim 8 , wherein the instructions cause the user device to perform operations comprising:

receiving the challenge message from the verifier device to access the credential, the challenge message including the list of identifiers of supported unclonable functions and the challenge value, and the challenge message having a corresponding response message format defined by a protocol; and

transmitting the list of identifiers of supported unclonable functions, the identifier of the selected unclonable function, and the result to the verifier device to authenticate the user device using the corresponding response message format.

10 . A verifier device comprising:

a memory device; and

a processor subsystem, which when configured by instructions stored on the memory device, is operable to perform the operations comprising:

transmitting, to a user device during a transaction when a user with the user device is asked to present the user device to the verifier device, a message including a list of identifiers of supported unclonable functions and a challenge value, the user device having a manufactured physically unclonable function (PUF) provided to the user device in the form of a credential or identity card by an issuer, wherein the verifier device selects a challenge from known challenge/response pairs and transmits it to the user device as part of the message, wherein the known challenge/response pairs are stored in a secure storage of the verifier device;

receiving, from the user device, a response message including the list of identifiers of supported unclonable functions, an identifier of a selected unclonable function, and a result, the identifier of the selected unclonable function selected from the list of identifiers of supported unclonable functions and the identifier of the selected unclonable function is selected by the user device to provide an indication to the verifier device of which unclonable function will be used, and the result being derived from an output of the selected unclonable function with the challenge value used as input to the selected unclonable function, wherein the verifier device is then able to check and ensure that the response is correct by comparing the result of the challenge/response pair corresponding with the challenge sent in the message with the result provided by the user device to authenticate the credential or the identity card;

obtaining an expected result of the selected unclonable function with the challenge value as input; and

authenticating the user device based on a comparison between the expected result and the result received from the user device.

11 . The verifier device of claim 10 , wherein the challenge value is a random value.

12 . The verifier device of claim 10 , wherein the selected unclonable function is a physically unclonable function (PUF).

13 . The verifier device of claim 10 , wherein the selected unclonable function is a software-based unclonable function.

14 . The verifier device of claim 10 , wherein obtaining the expected result of the selected unclonable function with the challenge value as input comprises:

accessing a secure storage device having challenge/response pairs for the supported unclonable functions for the user device; and

obtaining the expected result by performing a lookup on the challenge/response pairs using the challenge value and the selected unclonable function.

15 . A machine-readable medium including instructions for authenticating a user device at a verifier device, which when executed by the verifier device, cause the verifier device to perform operations comprising:

transmitting, to the user device during a transaction when a user with the user device is asked to present the user device to the verifier device, a message including a list of identifiers of supported unclonable functions and a challenge value, the user device having a manufactured physically unclonable function (PUF) provided to the user device in the form of a credential or identity card by an issuer, wherein the verifier device selects a challenge from known challenge/response pairs and transmits it to the user device as part of the message, wherein the known challenge/response pairs are stored in a secure storage of the verifier device;

receiving, from the user device, a response message including the list of identifiers of supported unclonable functions, an identifier of a selected unclonable function, and a result, the identifier of the selected unclonable function selected from the list of identifiers of supported unclonable functions and the identifier of the selected unclonable function is selected by the user device to provide an indication to the verifier device of which unclonable function will be used, and the result being derived from an output of the selected unclonable function with the challenge value used as input to the selected unclonable function, wherein the verifier device is then able to check and ensure that the response is correct by comparing the result of the challenge/response pair corresponding with the challenge sent in the message with the result provided by the user device to authenticate the credential or the identity card;

obtaining an expected result of the selected unclonable function with the challenge value as input; and

authenticating the user device based on a comparison between the expected result and the result received from the user device.

16 . The machine-readable medium of claim 15 , wherein the list of identifiers of supported unclonable functions is included in a field of a message structure.

17 . The machine-readable medium of claim 15 , wherein the challenge value is a random value.

18 . The machine-readable medium of claim 15 , wherein the selected unclonable function is a physically unclonable function (PUF).

19 . The machine-readable medium of claim 15 , wherein the selected unclonable function is a software-based unclonable function.

20 . The machine-readable medium of claim 15 , wherein obtaining the expected result of the selected unclonable function with the challenge value as input comprises:

accessing a secure storage device having challenge/response pairs for the supported unclonable functions for the user device; and

obtaining the expected result by performing a lookup on the challenge/response pairs using the challenge value and the selected unclonable function.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2022
From: KAUFMANN, MARTIN
To: ASSA ABLOY AB
Reel/Frame 058985/0580 →
Continuity (2)
Provisional Application 62886686 · Aug 14, 2019
Related Publication 20220337435A1 · Oct 20, 2022
References Cited (59)
US 8762723B2 · Yu · 2014 [cited by examiner]
US 10256983B1 · Bauer · 2019 [cited by examiner]
US 10320573B2 · Cambou · 2019 [cited by examiner]
US 11152313B1 · Wong · 2021 [cited by examiner]
US 11700246B2 · Tremlet · 2023 [cited by examiner]
US 20050097363A1 · Bajko · 2005 [cited by examiner]
US 20050198490A1 · Jaganathan · 2005 [cited by examiner]
US 20100293612A1 · Potkonjak · 2010 [cited by examiner]
US 20120131340A1 · Teuwen · 2012 [cited by examiner]
US 20140189890A1 · Koeberl · 2014 [cited by examiner]
US 20150195088A1 · Rostami · 2015 [cited by examiner]
US 20170005811A1 · Tremlet · 2017 [cited by examiner]
US 20170141930A1 · Rajski · 2017 [cited by examiner]
US 20170255503A1 · Hori · 2017 [cited by examiner]
US 20180129801A1 · Cambou · 2018 [cited by applicant]
US 20180183613A1 · Dafali · 2018 [cited by examiner]
US 20190165957A1 · Abbott · 2019 [cited by examiner]
US 20190165958A1 · Guajardo Merchan · 2019 [cited by examiner]
US 20190199525A1 · Mondello et al. · 2019 [cited by applicant]
US 20190305973A1 · Dewan · 2019 [cited by examiner]
US 20200186350A1 · Wentz · 2020 [cited by examiner]
US 20210091952A1 · Wentz · 2021 [cited by examiner]
US 20210099314A1 · Schat · 2021 [cited by examiner]
US 20210234710A1 · Facon · 2021 [cited by examiner]
US 20220116233A1 · Hoffman · 2022 [cited by examiner]
US 20220166638A1 · Razi · 2022 [cited by examiner]
US 20220318437A1 · Pomerance · 2022 [cited by examiner]
US 20220337435A1 · Kaufmann · 2022 [cited by examiner]
CN 1610441 · 2010 [cited by applicant]
CN 103778374 · 2014 [cited by applicant]
CN 107133533 · 2017 [cited by applicant]
CN 108173662 · 2018 [cited by applicant]
CN 108768660 · 2018 [cited by applicant]
CN 109522753 · 2019 [cited by applicant]
CN 110100412 · 2019 [cited by applicant]
CN 114365134 · 2022 [cited by applicant]
EP 4040720 · 2024 [cited by applicant]
WO 2017040124 · 2017 [cited by applicant]
WO WO2018183915A1 · 2018 [cited by applicant]
WO WO2018183926A1 · 2018 [cited by applicant]
WO 2020109512 · 2020 [cited by applicant]
WO WO2021028574A1 · 2021 [cited by applicant]
“International Application Serial No. PCT/EP2020/072877, International Search Report mailed Nov. 6, 2020”, 5 pgs. [cited by applicant]
“International Application Serial No. PCT/EP2020/072877, Written Opinion mailed Nov. 6, 2020”, 6 pgs. [cited by applicant]
“International Application Serial No. PCT/EP2020/072877, International Preliminary Report on Patentability mailed Feb. 24, 2022”, 8 pgs. [cited by applicant]
“European Application Serial No. 20757318.9, Response Filed Jun. 13, 2022 to Communication Pursuant to Rules 161 and 162 mailed May 18, 2022”, 16 pgs. [cited by applicant]
“European Application Serial No. 22165419.7, Extended European Search Report mailed Jul. 11, 2022”, 5 pgs. [cited by applicant]
“European Application Serial No. 22165419.7, Response Filed Jan. 12, 2023 to Extended European Search Report mailed Jul. 11, 2022”, 4 pages. [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Office Action mailed Apr. 30, 2024”, with English translation, 24 pages. [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Response filed Oct. 12, 2024 to Office Action mailed Apr. 30, 2024”, with English claims, 19 pages. [cited by applicant]
Liu, Ya-Nan, “PUF based Lightweight Device Authentication and Its Implementation”, Journal of Jinling Institute of Technology, No. 3 with machine English translation, (Sep. 30, 2018), 14 pages. [cited by applicant]
Xu, Rui, “Identification System for Enterprise Users Based on National Cryptographic Algorithms and PUF”, Computer and Modernization, No. 03 with machine English translation, (Mar. 15, 2018), 17 pages. [cited by applicant]
Yuan, Bian-Qing, “Analysis and Design of RFID Security Protocol”, Scientific and Technical Documentation Press with machine English translation, (Sep. 30, 2018), 6 pages. [cited by applicant]
Zhu, Feng, “A Lightweight RFID Mutual Authentication Protocol with PUF”, Sensors, vol. 19, No. 13, (Jul. 1, 2017), 22 pages. [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Office Action mailed Nov. 12, 2024”, with English translation, 21 pages. [cited by applicant]
“Annual Report of China Academy of Engineering Physics Edition 2016”, Annual Report of China Academy of Engineering Physics Editorial Department, China Atomic Energy Press with manual English translation, (Dec. 2016), 1… [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Response Filed Jan. 13, 2025 to Office Action mailed Nov. 12, 2024”, with English claims, 18 pages. [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Decision of Rejection mailed Feb. 26, 2025”, W/English Translation, 18 pgs. [cited by applicant]
“Chinese Application Serial No. 202080060625.0, Response Filed May 26, 2025 to Decision of Rejection mailed Feb. 26, 2025”, W/ English Claims, 19 pgs. [cited by applicant]