Puf-based password generation scheme
Abstract
The present invention provides a method for authenticating distributed peripherals on a computer network using an array of physically unclonable functions (PUF). As each PUF is unique, each PUF is able to generate a plurality of challenge response pairs that are unique to that PUF. The integrated circuits of the PUF comprise a plurality of cells, where a parameter (such as a voltage) of each cell may be measured (possibly averaged over many readings). The plurality of cells in the PUF may be arranged in a one, two or more dimensional matrix. A protocol based on an addressable PUF generator (APG) allows the protection of a network having distributed peripherals such as Internet of things (IoT), smart phones, lap top and desk top computers, or ID cards. This protection does not require the storage of a database of passwords, or secret keys, and thereby is immune to traditional database hacking attacks.
Claims
exact text as granted — not AI-modifiedThe invention claimed is:
1 . A method for generating a password from an array of physically unclonable functions (PUFs), comprising the steps of:
transmitting, by a host, a user identification, a random number and an instruction to an addressable PUF generator (APG) interface manager, wherein the host is configured to authenticate a plurality of distributed peripherals; generating an input to a hash function using the user identification and the random number; generating, by the hash function, a hash digest based on the input to the hash function, wherein the hash digest identifies a location within the array of PUFs; generating, by a PUF controller, a challenge from the location within the array of PUFs using the instruction; creating a password using the instruction, the random number and the challenge, wherein the password is configured to be converted back into the instruction, the random number and the challenge; and transmitting, by the host, the password to a distributed peripheral in the plurality of distributed peripherals, wherein the distributed peripheral is not physically connected to the array of PUFs and after transmitting the password to the distributed peripheral, the host does not store the password.
2 . The method of claim 1 , wherein the user identification and/or the password are permanently stored only on the distributed peripheral and not permanently stored anywhere else.
3 . The method of claim 1 , wherein the array of PUFs is a memory array configured to generate a plurality of challenge response pairs that are unique to each PUF due to manufacturing variations in the array of PUFs as compared to other arrays of PUFs.
4 . The method of claim 1 , wherein the step of generating the input to the hash function comprises the step of adding the random number to the user identification.
5 . The method of claim 1 , wherein the distributed peripheral is a terminal, a lap top, a phone, a computer or a connected device in an Internet of Things.
6 . The method of claim 1 , wherein the user identification and the password are stored in a secure memory (SM) of the distributed peripheral.
7 . The method of claim 1 , wherein the location comprises a horizontal location, a vertical location and an angle.
8 . A method for authenticating a distributed peripheral, comprising the steps of:
receiving, by a host, a user identification and a password from the distributed peripheral, wherein the host is configured to authenticate a plurality of distributed peripherals; converting, by the host, the password into an instruction, a random number and a challenge; generating an input to a hash function using the user identification and the random number; generating, by the hash function, a hash digest based on the input to the hash function, wherein the hash digest identifies a location within an array of PUFs; generating, by a PUF controller, a response from the location within the array of PUFs using the instruction; comparing the response to the challenge; and upon determining the response matches the challenge within a predetermined statistical limit, authenticating the distributed peripheral in the plurality of distributed peripherals, wherein the distributed peripheral is not physically connected to the array of PUFs.
9 . The method of claim 8 , wherein the user identification and/or the password are not stored in a database with other user identifications and/or other passwords.
10 . The method of claim 8 , wherein the array of PUFs is a memory array configured to generate a plurality of challenge response pairs that are unique to each PUF due to manufacturing variations within the array of PUFs as compared to other arrays of PUFs.
11 . The method of claim 8 , wherein the step of generating the input to the hash function comprises the step of adding the random number to the user identification.
12 . The method of claim 8 , wherein the distributed peripheral is a terminal, a lap top, a phone, a computer or a connected device in an Internet of Things.
13 . The method of claim 8 , wherein the user identification and the password are stored in a secure memory (SM) of the distributed peripheral.
14 . The method of claim 8 , wherein the location comprises a horizontal location, a vertical location and an angle or a direction.
15 . A method for a host to authenticate a distributed peripheral, in a plurality of distributed peripherals, comprising the steps of:
generating, by the host, a plurality of passwords using a physically unclonable function (PUF), wherein the host comprises the PUF and the plurality of passwords are unique to the PUF due to manufacturing variations in the PUF as compared to other PUFs; transmitting, by the host, each password, in the plurality of passwords, to each distributed peripheral, in the plurality of distributed peripherals, wherein each distributed peripheral is not physically connected to the host or the PUF and after transmitting, by the host, each password to each distributed peripheral, the host does not store each password in the plurality of passwords; receiving, by the host, a user identification and a password, in the plurality of passwords, from the distributed peripheral, in the plurality of distributed peripherals; and authenticating, by the host, the distributed peripheral using the user identification and the password from the distributed peripheral and the PUF of the host.
16 . The method of claim 15 , wherein the password is permanently stored only on the distributed peripheral and is not permanently stored on the host or anywhere else.
17 . The method of claim 15 , wherein the distributed peripheral is a terminal, a lap top, a phone, a computer or a connected device in an Internet of Things.
18 . The method of claim 15 , wherein the password is stored in a secure memory (SM) of the distributed peripheral.
19 . The method of claim 15 , wherein the password is not stored in a database with other passwords.
20 . The method of claim 15 , further comprising the steps of:
receiving, by the host, other user identifications and other passwords, in the plurality of passwords, from other distributed peripherals, in the plurality of distributed peripherals; and authenticating, by the host, the other distributed peripherals using the other user identifications and the other passwords from the other distributed peripherals and the PUF of the host.Join the waitlist — get patent alerts
Track US2019238348A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.