With the importance of cybersecurity and cryptography in the modern era, two-factor authentication has become critical to user authentication. Devices like phones, YubiKeys, and smart cards are foundational technologies in this field. However, these devices have been found to give predictable responses if internal secrets are discovered. By using measured intrinsic properties of devices rather than stored secrets, a Physically Unclonable Function (PUF) can provide more cryptographic information with great resilience to side-channel attacks. This cryptographic information can be measured using Challenge-Response Pairs (CRPs) and the resulting response can be used for key generation. The Static Random Access Memory (SRAM) PUF is one viable option for creating such a cryptographic primitive. Current implementations of the SRAM PUF are still not feasible for replacement of a portable two-factor authentication mechanism due to size and error rates. In this paper, we improve upon previous SRAM PUF designs allowing them to be a publicly accessible source for two-factor authentication through tokenization of the PUF. Our design shown has a similar size to the YubiKey while being backed by PUF-based technologies allowing for accessible security primitives capable of key generation.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Improving Usability of the SRAM PUF with a Compact Token Design

  • Jack Garrard,
  • Saloni Jain,
  • Ian Burke,
  • Mahafujul Alam,
  • Bertrand Cambou

摘要

With the importance of cybersecurity and cryptography in the modern era, two-factor authentication has become critical to user authentication. Devices like phones, YubiKeys, and smart cards are foundational technologies in this field. However, these devices have been found to give predictable responses if internal secrets are discovered. By using measured intrinsic properties of devices rather than stored secrets, a Physically Unclonable Function (PUF) can provide more cryptographic information with great resilience to side-channel attacks. This cryptographic information can be measured using Challenge-Response Pairs (CRPs) and the resulting response can be used for key generation. The Static Random Access Memory (SRAM) PUF is one viable option for creating such a cryptographic primitive. Current implementations of the SRAM PUF are still not feasible for replacement of a portable two-factor authentication mechanism due to size and error rates. In this paper, we improve upon previous SRAM PUF designs allowing them to be a publicly accessible source for two-factor authentication through tokenization of the PUF. Our design shown has a similar size to the YubiKey while being backed by PUF-based technologies allowing for accessible security primitives capable of key generation.