WO2014184899A1 - 機器真贋判定システムおよび機器真贋判定方法 - Google Patents
機器真贋判定システムおよび機器真贋判定方法 Download PDFInfo
- Publication number
- WO2014184899A1 WO2014184899A1 PCT/JP2013/063560 JP2013063560W WO2014184899A1 WO 2014184899 A1 WO2014184899 A1 WO 2014184899A1 JP 2013063560 W JP2013063560 W JP 2013063560W WO 2014184899 A1 WO2014184899 A1 WO 2014184899A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- secret information
- semiconductor chip
- authenticity determination
- control terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0861—Generation of secret information including derivation or calculation of cryptographic keys or passwords
- H04L9/0866—Generation of secret information including derivation or calculation of cryptographic keys or passwords involving user or device identifiers, e.g. serial number, physical or biometrical information, DNA, hand-signature or measurable physical characteristics
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3234—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving additional secure or trusted devices, e.g. TPM, smartcard, USB or software token
-
- G—PHYSICS
- G09—EDUCATION; CRYPTOGRAPHY; DISPLAY; ADVERTISING; SEALS
- G09C—CIPHERING OR DECIPHERING APPARATUS FOR CRYPTOGRAPHIC OR OTHER PURPOSES INVOLVING THE NEED FOR SECRECY
- G09C1/00—Apparatus or methods whereby a given sequence of signs, e.g. an intelligible text, is transformed into an unintelligible sequence of signs by transposing the signs or groups of signs or by replacing them by others according to a predetermined system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3271—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
- H04L9/3278—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response using physically unclonable functions [PUF]
Definitions
- the present invention relates to a device authenticity determination system and a device authenticity determination method for detecting counterfeit or falsification of an embedded device on which a semiconductor chip is mounted.
- Such a function is generally realized by an authentication protocol using encryption.
- examples of two authentication protocols having different encryption methods will be described.
- PUF Physical Unclonable Function
- PUF PUF
- Representative examples are “device security based on signal generators” disclosed in Patent Document 1 and “method for generating semiconductor device identifier and semiconductor device” disclosed in Patent Document 2.
- FE Fuzzy Extractor
- Algorithm 1 is a key generation process corresponding to an initial key in FE
- the key reproduction process of algorithm 2 is a process for generating the same bit string as the initial key.
- Encode C and Decode C in algorithm 1 and algorithm 2 represent encoding and correction processing in error correction code C, respectively.
- the coincidence between the generated key and the reproduced key is guaranteed by the following expression (1) for the Hamming distance of the PUF response in Algorithm 1 and Algorithm 2.
- the authentication protocol described above does not essentially confirm the authenticity of the entire embedded device A, but authenticates the LSI incorporated in the embedded device A. For this reason, for example, it is not possible to detect a counterfeit product in which a genuine LSI once discarded or an electronic board on which the LSI is mounted is taken out and other components such as a housing are replaced.
- the present invention has been made to solve the above-described problems.
- An apparatus authenticity determination system is visible from the appearance of an apparatus or a part on which a semiconductor chip including a PUF function and an encryption function is mounted, and generates secret information that is difficult to duplicate using the PUF function.
- a device authenticity determination system using print information including auxiliary data and secret information comprising a control terminal that reads print information that is visible and transmits the print information to the semiconductor chip by electronic access means, The semiconductor chip uses the encryption function and the PUF function to temporarily restore secret information that is difficult to duplicate using auxiliary data included in the print information acquired from the control terminal, and to temporarily store the secret information included in the print information. Tampering with confidential information that is difficult to duplicate and restored, and if a mismatch is detected, tampering is determined In which further comprising a determining function.
- the device authenticity determination method generates secret information that is visible from the appearance of a device or component on which a semiconductor chip including a PUF function and an encryption function is mounted, and is difficult to duplicate using the PUF function.
- the print information affixed to the housing of the embedded device on which the semiconductor chip is mounted matches the print information generated by the currently mounted semiconductor chip based on the read result of the print information. / By determining the mismatch, the consistency of the LSI mounted on the embedded device or the electronic board mounting the LSI and the information printed on the housing that can be visually confirmed by the user of the embedded device is confirmed. An apparatus authenticity determination system and an apparatus authenticity determination method that can be performed can be obtained.
- Embodiment 1 of this invention It is a whole block diagram of the apparatus authenticity determination system in Embodiment 1 of this invention. It is a block diagram which shows the structure of the printing information in Embodiment 1 of this invention. It is the flowchart which showed the serial process between the control terminal and master apparatus in Embodiment 1 of this invention. It is the flowchart which showed the series of processes between the server and master apparatus in Embodiment 1 of this invention. It is a block diagram which shows the structure of the printing information employ
- FIG. 1 is an overall configuration diagram of a device authenticity determination system according to Embodiment 1 of the present invention.
- the master device 101 has a SoC (System on Chip) 102 that is a main component of the device, and the SoC 102 has a PUF function and an encryption function.
- the master device 101 has print information 103 in its housing.
- This print information includes a security code which is a point in the present invention, in addition to general product related information I such as a device model number, rating, date of manufacture, serial number.
- the print information is printed in the form of a QR code (registered trademark) or a barcode.
- the slave device 104 has the SoC 105 and the print information 106 and is connected to the master device 101 via the communication path 107.
- the master device 101 is connected to the control terminal 108 via the communication path 109, and the slave device 104 is connected to the control terminal 108 via the communication path 107, the master device 101, and the communication path 109.
- control terminal 108 can make necessary settings for the master device 101 and the slave device 104, respectively.
- a device such as a PC or a tablet is assumed as the control terminal 108.
- the control terminal 108 is connected to the server 110 via the Internet.
- the contents common to both the master device 101 and the slave device 104 will be described simply as “device”.
- FIG. 2 is a block diagram showing a configuration of print information in Embodiment 1 of the present invention.
- the print information 103 and 106 includes product related information I and a security code.
- the security code includes the following three pieces of information.
- Auxiliary data S output by the PUF of the SoC mounted on the device to which the printing information is affixed.
- Data Enc K (MK) obtained by encrypting the master key MK using the secret information K generated by the PUF corresponding to the auxiliary data S.
- An example of keyed hash calculation is HMAC.
- FIG. 3 is a flowchart showing a series of processes between the control terminal and the master device in the first embodiment of the present invention. First, the operation between the control terminal 108 and the master device 101 will be described with reference to FIG.
- the purchaser of the device inputs the print information 103 to the control terminal 108 (step S301).
- print information is transmitted from the control terminal 108 to the master device 101 (step S302).
- the SoC 102 of the master device 101 restores the key MK from the print information according to the following procedure.
- the FE key reproduction function by the PUF in the SoC is operated. That is, using the auxiliary data S that is a part of the print information, K ⁇ Rep (W ′, S) Thus, the secret key K is restored (step S303).
- step S304 keyed hash calculation is performed on the print information using the restored K (step S304). That is, H K (I
- step S305 when the consistency cannot be confirmed, a mismatch notification is transmitted to the control terminal 108 (step S306), and the process is interrupted. On the other hand, if a match is confirmed, the process proceeds to the next step S307.
- Enk K (MK), which is a part of the print information, is decrypted using the secret key K to restore the MK (step S307), and a normal end notification is transmitted to the control terminal 108 (step S308). ) And complete a series of processing.
- the same processing as that of the master device 101 is performed for the slave device 104.
- the slave device 104 performs communication with the control terminal 108 via the master device 101.
- the print information does not correspond to the SoC (102, 105) of the device, the true K cannot be restored due to the nature of the PUF. For this reason, a mismatch with the hash value with the key described as the print information occurs, and it becomes possible to detect an unauthorized product.
- the correct MK can be restored in the SoC.
- MK is information set by the manufacturer, and the server 110 side has the correct MK. Therefore, if the product is a genuine product, the device and the server 110 can share the same key when the operation shown in FIG. 3 is completed.
- FIG. 4 is a flowchart showing a series of processing between the server and the master device in the first embodiment of the present invention.
- the purchaser of the device transmits the product related information I to the server 110 via the network using the control terminal 108, and requests a service (step S401).
- the server 110 transmits the random number R to the master device 101 via the control terminal 108 (step S402).
- the master device 101 encrypts the product related information I and the random number R transmitted in SoC in step S302 with MK, and transmits the encrypted information to the server 110 via the control terminal 108 (step S403). That is, Enc MK (I
- the server 110 decrypts the received Enc MK (I
- the service request from the product related information I is registered in the database as a log (step S406), and service provision is started (step S407).
- the service is not provided, and an error notification is sent for the service request (step S408).
- the same processing as that of the master device 101 is performed for the slave device 104.
- the slave device 104 performs communication with the control terminal 108 via the master device 101.
- the services provided by the server 110 include device program and parameter updates, maintenance time notifications, and the like.
- the service information to be provided or a part of the service information is provided in a form encrypted using the secret information MK or a form in which tampering can be detected.
- the device can receive a safe service by performing decryption or tampering detection using the MK held inside.
- the common key MK is used for authentication between the server 110 and the control terminal 108.
- an equivalent function can be achieved even with a public key cryptosystem using a public key pair (SK, PK).
- FIG. 5 is a block diagram showing a configuration of print information employed in the public key cryptosystem according to Embodiment 1 of the present invention.
- Enc K (MK) is Enc K (SK) as the print information
- Enc K (MK)) is defined as H K (I
- the server 110 side determines whether the service can be provided using the public key PK.
- the public key cryptosystem is adopted, information management on the authenticator side is reduced.
- Embodiment 2 a case where the changeability of print information is considered will be described.
- the manufacturer inputs the product related information I and the secret key MK to be printed on the casing to the master device 101, and executes the following key generation process. (K, S) ⁇ Gen (W)
- the master device 101 encrypts the MK with the generated K and outputs S and Enc K (MK) to the outside. At this time, the SoC does not output K.
- the SoC is used as a security code in addition to S and Enc K (MK), and H K (I
- the manufacturer can calculate the keyed hash by receiving S from SoC.
- FIG. 6 is a flowchart showing a series of processes during maintenance in the second embodiment of the present invention.
- maintenance without changing the SoC is assumed.
- the maintenance accompanied by the SoC change that is, the maintenance corresponding to the replacement of the apparatus, is performed in the same flow as that at the time of manufacturing.
- the maintenance person After completing the repair of the device, the maintenance person makes a service request shown in step S406 of FIG. 4 to the server 110 via the control terminal. At this time, it is assumed that the device has transitioned to a state in which the MK is held in the SoC according to the flowchart of FIG.
- the server 110 can separately check the validity of the maintenance staff according to general access control.
- the maintenance staff transmits I and S to the server 110 and makes a print information reissue request (step S601).
- the server 110 adds information such as maintenance execution, maintenance date, and maintenance person to the product related information I as information that can be identified by the server, and changes the product information I to I ′ (step S602). .
- the server 110 calculates H MK (I ′
- FIG. 7 is a block diagram showing the configuration of the print information after the change in the second embodiment of the present invention.
- the maintenance person generates print information in the format shown in FIG. 7, and performs reprinting on the housing by changing the seal (step S604).
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
Description
(1)あらかじめ、スレイブAに搭載されたLSIには、秘密鍵MKが格納される。また、マスタBにも、Aの秘密鍵MKを登録しておく。
(2)認証時、Bは、乱数rを生成し、秘密鍵MKを用いて乱数rを暗号化したcを生成し、Aへ送る。これを、c=EMK(r)と表記する。
(3)Aは、MKを用いて、cを復号した、r’をBに送る。これをr’=DMK(c)と表記する。
(4)Bは、r=r’であるならば真正品であることを通知する。r≠r’であれば模倣品である可能性を通知する。
例2:公開鍵暗号方式による認証プロトコル
(1)あらかじめ、スレイブAに搭載されたLSIには、秘密鍵SKが格納される。また、マスタBには、Aの秘密鍵SKに対応する公開鍵PKを登録しておく。
(2)認証時、Bは、乱数rを生成し、公開鍵PKを用いて乱数rを暗号化したcを生成し、Aへ送る。これを、c=EPK(r)と表記する。
(3)Aは、SKを用いて、cを復号した、r’をBに送る。これをr’=DSK(c)と表記する。
(4)Bは、r=r’であるならば真正品であることを通知する。r≠r’であれば模倣品である可能性を通知する。
前述の認証プロトコルは、本質的に組み込み機器A全体の真正性を確認しているのではなく、組み込み機器Aに内蔵されるLSIに対して認証を行なっている。このため、例えば、一度廃棄された真正品のLSIあるいは当該LSIを搭載する電子基板を取り出し、筐体などその他の構成品を入れ替えた模倣品の検出はできない。
図1は、本発明の実施の形態1における機器真贋判定システムの全体構成図である。マスタ機器101は、機器の主要構成要素であるSoC(System on Chip)102を持ち、SoC102は、PUF機能および暗号化機能を持つ。また、マスタ機器101は、その筐体に印字情報103を持つ。この印字情報としては、機器の型番、定格、製造年月日、シリアル番号など一般的な製品関連情報Iに加え、本発明でのポイントとなるセキュリティコードが含まれる。印字情報は、QRコード(登録商標)やバーコードなどの形態で印字される。
・印字情報が貼付される機器に搭載されたSoCが持つPUFが出力する補助データS。
・補助データSに対応してPUFが生成する秘密情報Kを用いてマスタ鍵MKを暗号化
したデータEncK(MK)。
・I、S、EncK(MK)の連結データ列に対してKを鍵とする鍵付きハッシュ値HK(I||S||EncK(MK))。なお、鍵付きハッシュ計算の例としては、HMACなどが挙げられる。ここで||はビット連結を意味する。
K←Rep(W’、S)
により秘密鍵Kを復元する(ステップS303)。
本実施の形態2では、印字情報の変更容易性を考慮する場合について説明する。製造者は、マスタ機器101に対して、筐体へ印字予定の製品関連情報Iおよび秘密鍵MKを入力し、以下の鍵生成処理を実行させる。
(K、S)←Gen(W)
Claims (9)
- PUF機能および暗号化機能を含む半導体チップが搭載された機器または部品の外観から視認可能であり、前記PUF機能を用いた複製困難な秘密情報を生成するための補助データおよび前記秘密情報を含む印字情報を用いた機器真贋判定システムであって、
視認可能な前記印字情報を読み取るとともに、前記半導体チップに対して電子的なアクセス手段により前記印字情報を送信する制御端末を備え、
前記半導体チップは、前記暗号化機能および前記PUF機能により、前記制御端末から取得した前記印字情報に含まれる前記補助データを用いて前記複製困難な秘密情報を一時的に復元するとともに、前記印字情報に含まれる秘密情報と一時的に復元された前記複製困難な秘密情報とを比較処理し、不一致を検出した場合には改ざんが発生したと判定する改ざん判定機能をさらに含む
機器真贋判定システム。 - 請求項1に記載の機器真贋判定システムにおいて、
前記印字情報は、前記機器または前記部品の製造者が設定した第2の秘密情報を複製困難な秘密情報により保護した情報をさらに含み、
前記半導体チップは、前記暗号化機能および前記PUFにより、前記複製困難な秘密情報の復元後に前記第2の秘密情報を復元するとともに、前記改ざん判定機能により、前記製造者が設定した前記第2の秘密情報と復元された第2の秘密情報とを比較処理し、不一致を検出した場合には改ざんが発生したと判定する
機器真贋判定システム。 - 請求項1または2に記載の機器真贋判定システムにおいて、
前記半導体チップは、前記改ざん判定機能における前記比較処理を、前記秘密情報を鍵情報としてハッシュ計算の比較により実行する
機器真贋判定システム。 - 請求項1に記載の機器真贋判定システムにおいて、
前記半導体チップは、復元した前記複製困難な秘密情報の適否を可否ハッシュ計算により確認する
機器真贋判定システム。 - 請求項2に記載の機器真贋判定システムにおいて、
前記半導体チップは、復元した前記第2の秘密情報の適否を可否ハッシュ計算により確認する
機器真贋判定システム。 - 請求項2に記載の機器真贋判定システムにおいて、
前記制御端末とネットワークを介して接続されたサーバ
をさらに備え、
前記半導体チップは、復元された前記第2の秘密情報を、前記制御端末を介して前記ネットワーク経由で前記サーバに送信し、
前記サーバは、前記半導体チップにより復元された前記第2の秘密情報と、自身が保有する第2の秘密情報とを比較することで、前記半導体チップが搭載された前記機器または前記部品の正当性を確認し、比較結果が一致することで前記正当性が確認できた後に、前記機器または前記部品に対してサービス情報を提供する
機器真贋判定システム。 - 請求項6に記載の機器真贋判定システムにおいて、
前記サーバは、前記サービス情報を前記第2の秘密情報を用いて暗号化して送信し、
復元された前記第2の秘密情報の送信元である前記半導体チップは、前記第2の秘密情報で暗号化されたサービス情報を取得し、自身が復元した第2の秘密情報を用いて前記サービス情報を復号することで、前記サーバから前記サービス情報を取得する
機器真贋判定システム。 - 請求項6または7に記載の機器真贋判定システムにおいて、
前記制御端末は、保守員の操作に基づいて前記補助データを含む印字情報再発行依頼を前記サーバに送信し、
前記サーバは、前記制御端末から前記印字情報再発行依頼を受けた場合には、前記第2の秘密情報を用いて保守情報を付加した新たな印字情報を生成し、生成した前記新たな印字情報を、前記印字情報再発行依頼を送信してきた前記制御端末に対して返送し、
前記制御端末は、受信した前記新たな印字情報により視認可能な印字情報を更新させるために、前記新たな印字情報を再印字する
機器真贋判定システム。 - PUF機能および暗号化機能を含む半導体チップが搭載された機器または部品の外観から視認可能であり、前記PUF機能を用いた複製困難な秘密情報を生成するための補助データおよび前記秘密情報を含む印字情報を用いた機器真贋判定システムに用いられる機器真贋判定方法であって、
前記制御端末において、
視認可能な前記印字情報を読み取るとともに、前記半導体チップに対して電子的なアクセス手段により前記印字情報を送信するステップと、
前記半導体チップにおいて、
前記制御端末から取得した前記印字情報に含まれる前記補助データを用いて前記複製困難な秘密情報を一時的に復元するステップと、
前記印字情報に含まれる秘密情報と一時的に復元された前記複製困難な秘密情報とを比較処理し、不一致を検出した場合には改ざんが発生したと判定するステップと
を備える機器真贋判定方法。
Priority Applications (7)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2013/063560 WO2014184899A1 (ja) | 2013-05-15 | 2013-05-15 | 機器真贋判定システムおよび機器真贋判定方法 |
| JP2015516815A JP5885178B2 (ja) | 2013-05-15 | 2013-05-15 | 機器真贋判定システム、機器真贋判定方法、および半導体チップが搭載された組み込み機器 |
| US14/785,805 US20160080153A1 (en) | 2013-05-15 | 2013-05-15 | Device authenticity determination system and device authenticity determination method |
| EP13884745.4A EP2999156B1 (en) | 2013-05-15 | 2013-05-15 | Device authenticity determination system and device authenticity determination method |
| KR1020157035359A KR101752083B1 (ko) | 2013-05-15 | 2013-05-15 | 기기 진위 판정 시스템 및 기기 진위 판정 방법 |
| CN201380076598.6A CN105229965B (zh) | 2013-05-15 | 2013-05-15 | 设备真伪判定系统以及设备真伪判定方法 |
| TW102134235A TWI518548B (zh) | 2013-05-15 | 2013-09-24 | Machine authenticity judgment system and machine authenticity judgment method |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2013/063560 WO2014184899A1 (ja) | 2013-05-15 | 2013-05-15 | 機器真贋判定システムおよび機器真贋判定方法 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014184899A1 true WO2014184899A1 (ja) | 2014-11-20 |
Family
ID=51897914
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2013/063560 Ceased WO2014184899A1 (ja) | 2013-05-15 | 2013-05-15 | 機器真贋判定システムおよび機器真贋判定方法 |
Country Status (7)
| Country | Link |
|---|---|
| US (1) | US20160080153A1 (ja) |
| EP (1) | EP2999156B1 (ja) |
| JP (1) | JP5885178B2 (ja) |
| KR (1) | KR101752083B1 (ja) |
| CN (1) | CN105229965B (ja) |
| TW (1) | TWI518548B (ja) |
| WO (1) | WO2014184899A1 (ja) |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2016207944A1 (ja) * | 2015-06-22 | 2016-12-29 | 三菱電機株式会社 | 真贋判定装置、及び真贋判定方法 |
| JP2017503289A (ja) * | 2014-10-31 | 2017-01-26 | 小米科技有限責任公司Xiaomi Inc. | 端末検証方法、装置、プログラム、及び記録媒体 |
| JP2018507658A (ja) * | 2015-03-05 | 2018-03-15 | アナログ ディヴァイスィズ インク | 物理的複製不可能関数および閾値暗号化を含む認証システムならびにデバイス |
| US10019604B2 (en) | 2014-10-31 | 2018-07-10 | Xiaomi Inc. | Method and apparatus of verifying terminal and medium |
| US10771267B2 (en) | 2014-05-05 | 2020-09-08 | Analog Devices, Inc. | Authentication system and device including physical unclonable function and threshold cryptography |
| US10958452B2 (en) | 2017-06-06 | 2021-03-23 | Analog Devices, Inc. | System and device including reconfigurable physical unclonable functions and threshold cryptography |
Families Citing this family (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2015057116A1 (en) * | 2013-10-15 | 2015-04-23 | Telefonaktiebolaget L M Ericsson (Publ) | Establishing a secure connection between a master device and a slave device |
| ES2794406T3 (es) * | 2016-12-21 | 2020-11-18 | Merck Patent Gmbh | Marca de seguridad compuesta basada en puf para antifalsificación |
| ES2764128T3 (es) * | 2016-12-21 | 2020-06-02 | Merck Patent Gmbh | Dispositivo de lectura para leer una marca compuesta que comprende una función física no clonable para la lucha contra la falsificación |
| IL256108B (en) | 2017-12-04 | 2021-02-28 | Elbit Systems Ltd | A system and method for identifying the state of use and originality of a product |
| EP3564846A1 (en) * | 2018-04-30 | 2019-11-06 | Merck Patent GmbH | Methods and systems for automatic object recognition and authentication |
| EP3565179B1 (en) * | 2018-04-30 | 2022-10-19 | Merck Patent GmbH | Composite security marking and methods and apparatuses for providing and reading same |
| US11151290B2 (en) | 2018-09-17 | 2021-10-19 | Analog Devices, Inc. | Tamper-resistant component networks |
| CN115244893A (zh) * | 2020-01-23 | 2022-10-25 | 学校法人东京理科大学 | 注册装置、验证装置、识别装置以及个体识别系统 |
| KR102340585B1 (ko) * | 2020-04-24 | 2021-12-20 | (주)메티스 | Puf가 적용된 cc-link 기반 슬레이브 모듈 |
| KR102334005B1 (ko) * | 2020-04-24 | 2021-12-02 | (주)메티스 | Puf가 적용된 cc-link 기반 게이트웨이 모듈 |
| US11917088B2 (en) * | 2020-09-21 | 2024-02-27 | International Business Machines Corporation | Integrating device identity into a permissioning framework of a blockchain |
| DE102021105402A1 (de) * | 2021-03-05 | 2022-09-08 | Infineon Technologies Ag | Datenverarbeitungsvorrichtung und verfahren zum übermitteln von daten über einen bus |
| CN113872769B (zh) * | 2021-09-29 | 2024-02-20 | 天翼物联科技有限公司 | 基于puf的设备认证方法、装置、计算机设备及存储介质 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2006040190A (ja) * | 2004-07-30 | 2006-02-09 | Omron Corp | 通信システム、通信装置および方法、加工装置および方法、記録媒体、並びにプログラム |
| JP2006102364A (ja) * | 2004-10-08 | 2006-04-20 | Le Tekku:Kk | 遊技機制御用半導体デバイス並びにそのための検査装置及び検査方法 |
| JP2009508430A (ja) * | 2005-09-14 | 2009-02-26 | コーニンクレッカ フィリップス エレクトロニクス エヌ ヴィ | 品目の真正性を判定するデバイス、システム及び方法 |
| JP2009524998A (ja) | 2006-01-24 | 2009-07-02 | ヴェラヨ インク | 信号発生器をベースとした装置セキュリティ |
| JP2009533741A (ja) | 2006-04-13 | 2009-09-17 | エヌエックスピー ビー ヴィ | 半導体デバイス識別子の生成方法および半導体デバイス |
| JP2011198317A (ja) * | 2010-03-24 | 2011-10-06 | National Institute Of Advanced Industrial Science & Technology | 認証処理方法及び装置 |
Family Cites Families (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5960086A (en) * | 1995-11-02 | 1999-09-28 | Tri-Strata Security, Inc. | Unified end-to-end security methods and systems for operating on insecure networks |
| JPH09284272A (ja) * | 1996-04-19 | 1997-10-31 | Canon Inc | エンティティの属性情報に基づく暗号化方式、署名方式、鍵共有方式、身元確認方式およびこれらの方式用装置 |
| US20030145208A1 (en) * | 2002-01-25 | 2003-07-31 | Willins Bruce A. | System and method for improving integrity and authenticity of an article utilizing secure overlays |
| US7840803B2 (en) * | 2002-04-16 | 2010-11-23 | Massachusetts Institute Of Technology | Authentication of integrated circuits |
| JP2004072214A (ja) * | 2002-08-02 | 2004-03-04 | Sharp Corp | 電子印鑑、icカード、本人認証システムおよび携帯機器 |
| GB0503972D0 (en) * | 2005-02-25 | 2005-04-06 | Firstondemand Ltd | Identification systems |
| US8224018B2 (en) * | 2006-01-23 | 2012-07-17 | Digimarc Corporation | Sensing data from physical objects |
| US8334757B2 (en) * | 2006-12-06 | 2012-12-18 | Koninklijke Philips Electronics N.V. | Controlling data access to and from an RFID device |
| ATE492854T1 (de) * | 2007-06-14 | 2011-01-15 | Intrinsic Id Bv | Vorrichtung und verfahren zur bereitstellung von authentifizierungsdaten |
| US8549298B2 (en) * | 2008-02-29 | 2013-10-01 | Microsoft Corporation | Secure online service provider communication |
| WO2009156904A1 (en) * | 2008-06-27 | 2009-12-30 | Koninklijke Philips Electronics N.V. | Device, system and method for verifying the authenticity integrity and/or physical condition of an item |
| JP2010108054A (ja) * | 2008-10-28 | 2010-05-13 | Mitsubishi Electric Corp | 認証システム、認証方法、認証プログラム、認証装置及び依頼装置 |
| WO2012164721A1 (ja) * | 2011-06-02 | 2012-12-06 | 三菱電機株式会社 | 鍵情報生成装置及び鍵情報生成方法 |
| US20130087609A1 (en) * | 2011-06-17 | 2013-04-11 | The University of Washington through its Center for Commercialization, a public Institution of Hig | Medical Device Tracking System and Method |
-
2013
- 2013-05-15 WO PCT/JP2013/063560 patent/WO2014184899A1/ja not_active Ceased
- 2013-05-15 US US14/785,805 patent/US20160080153A1/en not_active Abandoned
- 2013-05-15 KR KR1020157035359A patent/KR101752083B1/ko not_active Expired - Fee Related
- 2013-05-15 JP JP2015516815A patent/JP5885178B2/ja not_active Expired - Fee Related
- 2013-05-15 EP EP13884745.4A patent/EP2999156B1/en active Active
- 2013-05-15 CN CN201380076598.6A patent/CN105229965B/zh active Active
- 2013-09-24 TW TW102134235A patent/TWI518548B/zh not_active IP Right Cessation
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2006040190A (ja) * | 2004-07-30 | 2006-02-09 | Omron Corp | 通信システム、通信装置および方法、加工装置および方法、記録媒体、並びにプログラム |
| JP2006102364A (ja) * | 2004-10-08 | 2006-04-20 | Le Tekku:Kk | 遊技機制御用半導体デバイス並びにそのための検査装置及び検査方法 |
| JP2009508430A (ja) * | 2005-09-14 | 2009-02-26 | コーニンクレッカ フィリップス エレクトロニクス エヌ ヴィ | 品目の真正性を判定するデバイス、システム及び方法 |
| JP2009524998A (ja) | 2006-01-24 | 2009-07-02 | ヴェラヨ インク | 信号発生器をベースとした装置セキュリティ |
| JP2009533741A (ja) | 2006-04-13 | 2009-09-17 | エヌエックスピー ビー ヴィ | 半導体デバイス識別子の生成方法および半導体デバイス |
| JP2011198317A (ja) * | 2010-03-24 | 2011-10-06 | National Institute Of Advanced Industrial Science & Technology | 認証処理方法及び装置 |
Cited By (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US10771267B2 (en) | 2014-05-05 | 2020-09-08 | Analog Devices, Inc. | Authentication system and device including physical unclonable function and threshold cryptography |
| US10931467B2 (en) | 2014-05-05 | 2021-02-23 | Analog Devices, Inc. | Authentication system and device including physical unclonable function and threshold cryptography |
| JP2017503289A (ja) * | 2014-10-31 | 2017-01-26 | 小米科技有限責任公司Xiaomi Inc. | 端末検証方法、装置、プログラム、及び記録媒体 |
| US10019604B2 (en) | 2014-10-31 | 2018-07-10 | Xiaomi Inc. | Method and apparatus of verifying terminal and medium |
| JP2018507658A (ja) * | 2015-03-05 | 2018-03-15 | アナログ ディヴァイスィズ インク | 物理的複製不可能関数および閾値暗号化を含む認証システムならびにデバイス |
| WO2016207944A1 (ja) * | 2015-06-22 | 2016-12-29 | 三菱電機株式会社 | 真贋判定装置、及び真贋判定方法 |
| JPWO2016207944A1 (ja) * | 2015-06-22 | 2017-09-14 | 三菱電機株式会社 | 真贋判定装置、及び真贋判定方法 |
| US10958452B2 (en) | 2017-06-06 | 2021-03-23 | Analog Devices, Inc. | System and device including reconfigurable physical unclonable functions and threshold cryptography |
Also Published As
| Publication number | Publication date |
|---|---|
| EP2999156A1 (en) | 2016-03-23 |
| CN105229965B (zh) | 2018-10-09 |
| JP5885178B2 (ja) | 2016-03-15 |
| KR20160010521A (ko) | 2016-01-27 |
| EP2999156B1 (en) | 2019-07-31 |
| JPWO2014184899A1 (ja) | 2017-02-23 |
| CN105229965A (zh) | 2016-01-06 |
| TWI518548B (zh) | 2016-01-21 |
| TW201443689A (zh) | 2014-11-16 |
| US20160080153A1 (en) | 2016-03-17 |
| EP2999156A4 (en) | 2017-01-11 |
| KR101752083B1 (ko) | 2017-06-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP5885178B2 (ja) | 機器真贋判定システム、機器真贋判定方法、および半導体チップが搭載された組み込み機器 | |
| US11811912B1 (en) | Cryptographic algorithm status transition | |
| CN108667608B (zh) | 数据密钥的保护方法、装置和系统 | |
| KR102177848B1 (ko) | 액세스 요청을 검증하기 위한 방법 및 시스템 | |
| CN112260826B (zh) | 用于安全凭证供应的方法 | |
| CN106664206B (zh) | 用于已认证的通信的高效方法 | |
| JP5815525B2 (ja) | 情報処理装置、コントローラ、鍵発行局、無効化リスト有効性判定方法および鍵発行方法 | |
| JP5216932B1 (ja) | ワンタイムパスワード装置、システム及びプログラム | |
| WO2017042400A1 (en) | Access method to an on line service by means of access tokens and secure elements restricting the use of these access tokens to their legitimate owner | |
| US9531540B2 (en) | Secure token-based signature schemes using look-up tables | |
| CN110188551B (zh) | 一种保单加密传输方法及系统 | |
| US8806206B2 (en) | Cooperation method and system of hardware secure units, and application device | |
| WO2009028794A2 (en) | Method for providing anonymous public key infrastructure and method for providing service using the same | |
| CN101627390A (zh) | 用于程序状态数据在电子设备中的安全存储的方法 | |
| CN116582266B (zh) | 电子签章方法、电子签章系统以及可读存储介质 | |
| KR20120091618A (ko) | 연쇄 해시에 의한 전자서명 시스템 및 방법 | |
| WO2024216127A1 (en) | Apparatus and method for managing credentials | |
| CN104735064B (zh) | 一种标识密码系统中标识安全撤销并更新的方法 | |
| JP5159752B2 (ja) | 通信データの検証装置及びそのコンピュータプログラム | |
| CN113393241A (zh) | 一种区块链账本数据的编辑方法及装置 | |
| KR20140071775A (ko) | 암호키 관리 시스템 및 방법 | |
| WO2017109058A1 (en) | Security management system for securing a communication between a remote server and an electronic device | |
| JP2005278065A (ja) | 認証用鍵の更新システム、認証用鍵の更新方法および認証用鍵の更新プログラム | |
| TW201701610A (zh) | 真品贋品判別裝置以及真品贋品判別方法 | |
| JP2026503927A (ja) | ユーザ機器に秘密を利用させるための方法及びシステム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 201380076598.6 Country of ref document: CN |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 13884745 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2015516815 Country of ref document: JP Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 14785805 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2013884745 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 20157035359 Country of ref document: KR Kind code of ref document: A |
