US 12,316,787 B2
Device with multiple hardware signatures from a single PUF circuit source and related methods and applications
Wai-Chi Fang, Hsinchu (TW); Nicolas Jean Roger Fahier, Hsinchu (TW); Meng-Ting Wan, Hsinchu (TW); Kai-Yuan Guo, Hsinchu (TW); and Bo-Ting Liu, Hsinchu (TW)
Assigned to Intelligent Information Security Technology Inc., Hsinchu (TW)
Filed by INTELLIGENT INFORMATION SECURITY TECHNOLOGY INC., Hsinchu (TW)
Filed on Dec. 7, 2022, as Appl. No. 18/076,523.
Claims priority of provisional application 63/293,173, filed on Dec. 23, 2021.
Prior Publication US 2023/0208657 A1, Jun. 29, 2023
Int. Cl. H04L 9/32 (2006.01); H04L 9/08 (2006.01)
CPC H04L 9/3278 (2013.01) [H04L 9/0866 (2013.01); H04L 9/0869 (2013.01); H04L 9/3247 (2013.01)] 37 Claims
OG exemplary drawing
 
1. A Multiple digital signature Security Zone system comprising:
an electronic circuit to create a source of PUF entropy dynamically measurable that can be measured anytime during the device operation upon a trigger signal, and which result is used to generate a quasi-static digital device print and true random numbers;
a random numbers generator circuitry using measured results from the source of PUF entropy dynamically measurable;
a quasi-static states voting mechanism creating a quasi-static digital device print pattern using the measured results from the source of PUF entropy dynamically measurable;
a set of digital bitwise shuffle and toggle functions to randomize and shuffle a quasi-static digital device print;
a key derivation function engine taking random numbers, static and quasi-static digital sequences as inputs and generating an entangled digital output;
a set of format preserving encryption and decryption engines which may be duplicated at will in the circuit including both encryption and decryption mechanisms, and providing the ability to create or enroll and recover and load multiple unique PUF-based digital sequences used as unique digital signatures;
a non-volatile memory media to store certain checkpoints data but not limited to, which may be integrated within the device silicon area but not necessarily;
a communication interface adapted to the system target host device to manage inputs and outputs of the disclosed system;
a system controller to execute commands and provide the multiple digital signature security zone system results from the target host device or connected device;
wherein the format preserving encryption and decryption engines take a digital key and a digital input data, encrypted data or plaintext data, sequence as inputs to output an encrypted or plaintext data, and is a symmetrical encryption mechanism.