DexterLab

🔥 New release: Parser AXI-Full Edition v1.0.0 now available🔥 Roadmap updated: AXI-Lite & AHB-Full/Lite in development📘 Unified command architecture — new documentation planned📘 Timing diagrams and bus models coming in next updates📘 Theory ↔ Design Library integration continues

PUF‑based Key Derivation

Overview

A Physical Unclonable Function (PUF) is a hardware primitive that extracts device‑unique secrets from microscopic manufacturing variations. Unlike stored keys, PUF‑derived keys:

  • do not exist in non‑volatile memory
  • cannot be cloned or copied
  • are regenerated on demand
  • disappear when power is removed
  • are resistant to invasive attacks

PUFs are used to derive:

  • Device Root Keys (DRK)
  • Key Encryption Keys (KEK)
  • HSM internal secrets
  • MACsec/IPsec long‑term keys
  • Secure Boot keys
  • Attestation keys

This page focuses on the hardware architecture of PUF‑based key derivation and its integration with the HSM.

PUF Fundamentals

A PUF exploits physical randomness introduced during silicon manufacturing. Common PUF types include:

1. SRAM PUF

  • uses power‑up state of SRAM cells
  • high entropy
  • widely used in SoCs and secure elements

2. Ring Oscillator PUF

  • compares frequencies of nominally identical oscillators
  • stable after calibration

3. Arbiter PUF

  • measures delay differences in symmetric paths
  • requires careful layout

4. Butterfly PUF

  • latch‑based
  • used in FPGA implementations

5. Composite PUF

  • combines multiple PUF types
  • improves robustness

PUF Response Characteristics

PUF responses are:

  • unique per device
  • noisy (not perfectly reproducible)
  • not directly usable as keys
  • sensitive to temperature, voltage, aging

Therefore, raw PUF bits must be processed through:

  • error correction
  • helper data
  • key derivation functions

PUF Key Reconstruction Pipeline

A typical PUF‑based key derivation pipeline looks like this:


1. Error Correction (ECC)

Corrects bit flips due to noise:

  • BCH codes
  • Reed‑Solomon
  • LDPC
  • repetition codes

2. Helper Data

Public, non‑secret metadata that helps reconstruct the key. Must not leak information about the PUF response.

3. Fuzzy Extractor

Transforms noisy PUF output into a stable, uniform secret.

4. Key Derivation Function (KDF)

Derives cryptographic keys from the stable secret:

  • HKDF
  • SP800‑108
  • AES‑CMAC KDF

PUF Enrollment and Reconstruction

PUF‑based systems operate in two phases:

Enrollment (Manufacturing / Provisioning)

During enrollment:

  • the PUF is sampled
  • helper data is generated
  • no key is stored
  • helper data is written to NVM or OTP

Reconstruction (Runtime)

At runtime:

  • the PUF is sampled again
  • helper data corrects noise
  • the same key is reconstructed
  • the key is injected into secure hardware

Integration with the HSM

The HSM is the orchestrator of PUF‑based key derivation.

HSM responsibilities:

  • control PUF sampling
  • manage helper data
  • run ECC and fuzzy extraction
  • run KDF
  • wrap derived keys
  • inject keys into crypto engines
  • enforce key usage policies

PUF‑to‑HSM flow

Keys never leave the HSM in plaintext.

PUF‑Derived Keys in the System

PUF‑derived keys are used for:

1. Device Root Key (DRK)

The root of all key hierarchies.

2. Key Encryption Keys (KEK)

Used to wrap:

  • MACsec SAK
  • IPsec Child SA keys
  • Secure Boot keys
  • Firmware update keys

3. Attestation Keys

Used to prove device identity.

4. Secure Boot Keys

Used to verify firmware signatures.

5. HSM Internal Secrets

Used for:

  • DRBG seeding
  • entropy mixing
  • internal authentication

Security Properties

PUF‑based keys provide:

Unclonability

No two chips produce the same PUF response.

No Key Storage

Keys are never stored in NVM.

Tamper Resistance

Invasive attacks disturb the physical structure → PUF changes → key cannot be reconstructed.

Side‑Channel Resistance

PUF responses are not repeatedly used like stored keys.

Forward Secrecy

Destroying helper data or PUF state prevents future reconstruction.

Threats and Mitigations

ThreatDescriptionMitigation
Modeling attacksTrying to predict PUF behaviorComposite PUFs, fuzzy extractors
Helper data leakageInferring PUF bitsSecure helper data construction
Environmental manipulationTemperature/voltage attacksSensors + compensation
AgingDrift over timeECC + periodic recalibration
Invasive probingReading PUF circuitsTamper mesh + active shields

PUF vs TRNG

FeaturePUFTRNG
PurposeDevice‑unique keysRandomness
StabilityDeterministic (after ECC)Non‑deterministic
StorageNot storedNot stored
Attack surfacePhysicalPhysical + statistical
OutputSecretEntropy

PUF = identity TRNG = randomness

Entrambi sono necessari.

Related Pages