TY - GEN
T1 - Improving Usability of the SRAM PUF with a Compact Token Design
AU - Garrard, Jack
AU - Jain, Saloni
AU - Burke, Ian
AU - Alam, Mahafujul
AU - Cambou, Bertrand
N1 - Publisher Copyright:
© The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2025
Y1 - 2025
N2 - With the importance of cybersecurity and cryptography in the modern era, two-factor authentication has become critical to user authentication. Devices like phones, YubiKeys, and smart cards are foundational technologies in this field. However, these devices have been found to give predictable responses if internal secrets are discovered. By using measured intrinsic properties of devices rather than stored secrets, a Physically Unclonable Function (PUF) can provide more cryptographic information with great resilience to side-channel attacks. This cryptographic information can be measured using Challenge-Response Pairs (CRPs) and the resulting response can be used for key generation. The Static Random Access Memory (SRAM) PUF is one viable option for creating such a cryptographic primitive. Current implementations of the SRAM PUF are still not feasible for replacement of a portable two-factor authentication mechanism due to size and error rates. In this paper, we improve upon previous SRAM PUF designs allowing them to be a publicly accessible source for two-factor authentication through tokenization of the PUF. Our design shown has a similar size to the YubiKey while being backed by PUF-based technologies allowing for accessible security primitives capable of key generation.
AB - With the importance of cybersecurity and cryptography in the modern era, two-factor authentication has become critical to user authentication. Devices like phones, YubiKeys, and smart cards are foundational technologies in this field. However, these devices have been found to give predictable responses if internal secrets are discovered. By using measured intrinsic properties of devices rather than stored secrets, a Physically Unclonable Function (PUF) can provide more cryptographic information with great resilience to side-channel attacks. This cryptographic information can be measured using Challenge-Response Pairs (CRPs) and the resulting response can be used for key generation. The Static Random Access Memory (SRAM) PUF is one viable option for creating such a cryptographic primitive. Current implementations of the SRAM PUF are still not feasible for replacement of a portable two-factor authentication mechanism due to size and error rates. In this paper, we improve upon previous SRAM PUF designs allowing them to be a publicly accessible source for two-factor authentication through tokenization of the PUF. Our design shown has a similar size to the YubiKey while being backed by PUF-based technologies allowing for accessible security primitives capable of key generation.
KW - Challenge-Response Pairs (CRPs)
KW - Cryptography
KW - Cybersecurity, Tokenization
KW - Key generation
KW - Physical Unclonable Function (PUF)
KW - Static random access memory
UR - https://www.scopus.com/pages/publications/105013621132
UR - https://www.scopus.com/inward/citedby.url?scp=105013621132&partnerID=8YFLogxK
U2 - 10.1007/978-3-031-92611-2_18
DO - 10.1007/978-3-031-92611-2_18
M3 - Conference contribution
AN - SCOPUS:105013621132
SN - 9783031926105
T3 - Lecture Notes in Networks and Systems
SP - 257
EP - 268
BT - Intelligent Computing - Proceedings of the 2025 Computing Conference
A2 - Arai, Kohei
PB - Springer Science and Business Media Deutschland GmbH
T2 - Computing Conference, CompCom 2025
Y2 - 19 June 2025 through 20 June 2025
ER -