US20190114115A1

Puf based boot-loading for data recovery on secure flash devices

Claim Score by NHIP

Read claim 19, the broadest

Abstract

In high security devices, like smart cards, the on-board software may be embedded in ROM (read only memory). But, based on flexibility arguments, non-volatile flash memory based software storage can be more preferred. This invention describes a method to recover from a situation of data loss on flash devices by combining the on-device available secure boot-loading with embedded physical unclonable functions (PUF), where the PUF provides the cryptographic key for starting the data recovery procedure.

US20190114115A1, drawing sheet 1
Sheet 1 of 7

Term

11.2 yearsto projected expiry

Projected expiry 8 December 2037, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    A method for recovering corrupted data on a device using a PUF (physical unclonable function) located on the device, the method comprising:transmitting, by the device, to a server a request for data recovery and a unique device identifier that is unalterably stored in the device;receiving, by the device, a PUF challenge transmitted by the server in response to the request for data recovery and the unique device identifier, wherein the PUF challenge is used to determine a restore key;transmitting, by the device, to the server the unique device identifier encrypted by the restore key in response to the PUF challenge;receiving, by the device, a device restore data encrypted by the restore key, wherein the device restore data is transmitted by the server in response to the server authenticating the unique device identifier with the restore key stored on the server together with the PUF challenge after a first device initialization at a protected production site.
  2. 13
    A device configured for recovering corrupted data on the device, the device comprising:a non-volatile memory;a PUF (physical unclonable function);a processor, wherein the processor is configured to perform the following steps: in response to corruption of data in the non-volatile memory, transmitting to a server a request for data recovery and a unique device identifier that is unalterably stored in the device,receiving a PUF challenge associated with the PUF of the device transmitted by the server in response to the request for data recovery and the unique device identifier, wherein the PUF challenge is used to determine a restore key,in response to the PUF challenge, transmitting to the server the unique device identifier encrypted by the restore key,receiving a device restore data encrypted by the restore key, wherein the device restore data is transmitted by the server in response to the server authenticating the unique device identifier with the restore key stored on the server together with the PUF challenge after a first device initialization at a protected production site.
  3. 19
    Broadest claimClaim Score 56, average(NHIP)A server configured for providing recovery data to a device that has corrupted data and a PUF (physical unclonable function), wherein the server is configured to perform the following steps:receiving, from the device, a request for data recovery and a unique device identifier,transmitting, to the device, a PUF challenge associated with the PUF of the device in response to the request for data recovery and the unique device identifier, wherein the PUF challenge is used to determine a restore key associated with the PUF challenge, wherein the restore key is stored on the server together with the PUF challenge after a first device initialization at a protected production site,receiving, from the device, the unique device identifier encrypted by the restore key associated with the PUF challenge,authenticating the device using the encrypted unique identifier together with the restore key,in response to authenticating the restore key to be valid, transmitting a device restore data encrypted by the restore key to the device.