Skip to main navigation Skip to search Skip to main content

Robust authentication using physically unclonable functions

  • Miami University
  • Purdue University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

90 Scopus citations

Abstract

In this work we utilize a physically unclonable function (PUF) to improve resilience of authentication protocols to various types of compromise. As an example application, we consider users who authenticate at an ATM using their bank-issued PUF and a password. We present a scheme that is provably secure and achieves strong security properties. In particular, we ensure that (i) the user is unable to authenticate without her device; (ii) the device cannot be used by someone else to successfully authenticate as the user; (iii) the device cannot be duplicated (e.g., by a bank employee); (iv) an adversary with full access to the bank's personal and authentication records is unable to impersonate the user even if he obtains access to the device before and/or after the setup; (v) the device does not need to store any information. We also give an extension that endows the solution with emergency capabilities: if a user is coerced into opening her secrets and giving the coercer full access to the device, she gives the coercer alternative secrets whose use notifies the bank of the coercion in such a way that the coercer is unable to distinguish between emergency and normal operation of the protocol.

Original languageEnglish
Title of host publicationInformation Security - 12th International Conference, ISC 2009, Proceedings
PublisherSpringer Verlag
Pages262-277
Number of pages16
ISBN (Print)3642044735, 9783642044731
DOIs
StatePublished - 2009
Event12th Information Security Conference, ISC 2009 - Pisa, Italy
Duration: Sep 7 2009Sep 9 2009

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume5735 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference12th Information Security Conference, ISC 2009
Country/TerritoryItaly
CityPisa
Period09/7/0909/9/09

Fingerprint

Dive into the research topics of 'Robust authentication using physically unclonable functions'. Together they form a unique fingerprint.

Cite this