Return-Path: <paul@nymbus.net>
X-Original-To: t2trg@ietfa.amsl.com
Delivered-To: t2trg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id DBF91130EC1
 for <t2trg@ietfa.amsl.com>; Sun, 17 Feb 2019 21:14:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level: 
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, HTML_MESSAGE=0.001, LOTS_OF_MONEY=0.001,
 RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001]
 autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=nymbus-net.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id VGjVelpxliCi for <t2trg@ietfa.amsl.com>;
 Sun, 17 Feb 2019 21:14:11 -0800 (PST)
Received: from mail-pf1-x441.google.com (mail-pf1-x441.google.com
 [IPv6:2607:f8b0:4864:20::441])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id E852C1200B3
 for <T2TRG@irtf.org>; Sun, 17 Feb 2019 21:14:10 -0800 (PST)
Received: by mail-pf1-x441.google.com with SMTP id h1so7927521pfo.7
 for <T2TRG@irtf.org>; Sun, 17 Feb 2019 21:14:10 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=nymbus-net.20150623.gappssmtp.com; s=20150623;
 h=from:message-id:mime-version:subject:date:in-reply-to:cc:to
 :references; bh=y/zFAhhTKankbPbki4tEjBSqd31uZJa8cUaCOer61xc=;
 b=zUKsg7USOhtCBUYz2VmOZquDYmsb/+7TDi0vuGpcYZ9tFefkTu0EDAB0M4hBPG4rIN
 wP3Gf/CMJYO0PUF/K+8hVEPE3N+QV+b14MlQwjz9sY+rIS6mfWP4JXrAVMrynvjSsXts
 OosuRBE3AHW+QI2uFgv2ALrZUGs5WQhN/hW8OzinubbNwCRwQTzlNzHXs7ukxCK4rYbI
 1jzpv4gZ9yG7NPBIC4w6DicPIaJDNMy1BGLE0Kbi5wGG866irG8NdCHWmyEswllHzIRP
 VGUBAqJ15UcB6Xy86WOKlAkmT/knSpgwXhYNwWpgBxKU0gWz0mjCxJKaEWSPQpo/mwRu
 aAcQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:message-id:mime-version:subject:date
 :in-reply-to:cc:to:references;
 bh=y/zFAhhTKankbPbki4tEjBSqd31uZJa8cUaCOer61xc=;
 b=GQpvt7gtmxUjjsU9kI9HEXIv5sUUrGQgCGiU6FAdPARSjHJJ+ozD6Be3MmyLqUXikk
 K85YLh8joBLXQfLmbsHUCGPmBDa57xs7VCYFhybbtL00PfUcOMHDDjhjxAXnLbwhv0Gn
 CG6/ygUwlhDKQ8HCZpg8OXSnoMBWkpF0FA9owhk6SvMht3UU8tqmU0ETGWUFjPIuqUeD
 CBIj4DCE2wBtgsFfewNw4RoBWjip/T0akW4zLEaY3Ud2WbW412aPi1CQN7NzLIU0yrNg
 TqcTSe/dRE9QnslAUwE2XVCVI3ih4cf9WyVPIrq1jUnMrZQ4AnL+uNzPmaAl66wbzQBe
 3+yw==
X-Gm-Message-State: AHQUAubxJMAuXa6NIFRImPBhtpRP1MrH1LGeN/5W7XyxPXieH8kXCM09
 Z0KMGiGVemx28Tc9S1C45sEwDg==
X-Google-Smtp-Source: AHgI3Ia8uJYIQwihKKboWMIh/exP8gERnIrCA5Pr3e5Q00rfX4GZy8l/ED7ojm4lmumxkawqkk+7/A==
X-Received: by 2002:a63:4346:: with SMTP id q67mr16725345pga.92.1550466850249; 
 Sun, 17 Feb 2019 21:14:10 -0800 (PST)
Received: from [192.168.1.97] (172-125-76-95.lightspeed.sntcca.sbcglobal.net.
 [172.125.76.95])
 by smtp.gmail.com with ESMTPSA id e65sm17089228pfc.184.2019.02.17.21.14.08
 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
 Sun, 17 Feb 2019 21:14:09 -0800 (PST)
From: Paul Lambert <paul@nymbus.net>
Message-Id: <00F86909-D260-4267-AC79-D5D63AD6DBAD@nymbus.net>
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_79A3FFD5-9578-4B4B-A7CC-681160980C15"
Mime-Version: 1.0 (Mac OS X Mail 12.2 \(3445.102.3\))
Date: Sun, 17 Feb 2019 21:14:45 -0800
In-Reply-To: <CAPZZOTgmiDVxJmEYq7J6amgCaWrdcBHDjww=ZjrVd0m-5nbsjg@mail.gmail.com>
Cc: tls@ietf.org,
 T2TRG@irtf.org,
 Russell Housley <housley@vigilsec.com>
To: Sankalp Bagaria <sankalp.nitt@gmail.com>
References: <CAPZZOTgmiDVxJmEYq7J6amgCaWrdcBHDjww=ZjrVd0m-5nbsjg@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.102.3)
Archived-At: <https://mailarchive.ietf.org/arch/msg/t2trg/YlAnVgtL87Ym9-F25rbiX51j0_4>
Subject: Re: [T2TRG] ITDA - IoT Device Authentication
X-BeenThere: t2trg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IRTF Thing-to-Thing Research Group <t2trg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/t2trg>,
 <mailto:t2trg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/t2trg/>
List-Post: <mailto:t2trg@irtf.org>
List-Help: <mailto:t2trg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/t2trg>,
 <mailto:t2trg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Feb 2019 05:14:16 -0000


--Apple-Mail=_79A3FFD5-9578-4B4B-A7CC-681160980C15
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Sankalp,

The schema below is the wrong way to use PUF technology for IoT device =
authentication.=20

PUF is already being used in many fielded IoT systems. You simply use =
the device unique PUF secret to create a public/private key pair. The =
public key is then extracted and used to authentic the device. This =
enables tracking and identification of the device through its full =
life-cycle. Early observation of the device-unique public key mitigates =
a variety of supply chain attacks. The extracted public key may be =
certified by a X.509 CA. The PUF derived identity may then be used =
directly in a TLS protocol exchange.=20

Early assignment of public key certificate to a device enables strong =
protection of the device during manufacturing. The PUF device keys may =
be used as part of the boot process to enable per-device protection of =
sensitive firmware or other cryptographic secrets. =20

PUF may be instantiated as HW or SW. Your scheme mentions " signal path =
can affect the delay in the propagation of a signal=E2=80=9D =E2=80=A6 =
the seems to imply a HW based implementation (perhaps a Butterfly PUF). =
A simpler implementation would be to use SRAM PUF where the entropy in =
uninitialized SRAM is used to generate the device unique secrets. SRAM =
based PUF can be readily integrated into existing MCU devices.

The simplest application of PUF in IoT uses a device unique symmetric =
secret key to serve as a key to encrypt sensitive data in unprotected NV =
memory.  This is basically a low-level key vault  that provides =
confidential and non-non-maleable secure device storage. This is a very =
attractive alternative to OTP memory that s more expensive and of =
limited size.=20

PUF is just one way for a device to obtain unique secrets (symmetric or =
asymmetric). It has been standard practice to =E2=80=9Cinject=E2=80=99 =
secrets during manufacturing. Injection requires more trust in the key =
distribution and provisioning process than approaches that generate keys =
on device and never expose these secrets.=20

Long-lived device unique public keys and certificates that provide =
protection through the full manufacturing life-cycle are an interesting =
topic area =E2=80=A6  Challenge/response PUF protocols are not useful or =
interesting for standardization.

Paul





> On Feb 15, 2019, at 9:06 PM, Sankalp Bagaria <sankalp.nitt@gmail.com> =
wrote:
>=20
> Hello,
>=20
> Please take a look at this and advise if it is a good idea and whether =
it should be pursued.
>=20
> Thanks,
>=20
> Sankalp Bagaria.
>=20
>=20
>=20
> ITDA - IoT Device Authentication
>=20
> Abstract: We propose that the server is authenticated using X509 =
certificate in a TLS 1.3 like protocol. The Server sends 32-byte =
Challenge. Client replies by sending 32-byte Response. Thus the client =
is authenticated. In the transfer of the application data, the client =
may send more challenge-response pairs as encrypted data for updating =
database of server. Client doesn=E2=80=99t store challenge/response or =
key or certificate. Both the server and the client can initiate the =
handshake.
>=20
> Background
>=20
> Traditionally, there are two ways to authenticate a device: a =
centralised CA issuing certificates and block-chain. Both require costly =
infrastructure and can=E2=80=99t be used to authenticate IoT devices, =
which are of low cost. While block-chain provides non-repudiation, =
transactions are distributed all over the net. X.509 certificates are =
costlier than many sensors.
>=20
> Another option is Physically Uncloneable Functions (PUF). Because of =
the random variations taking place during the manufacturing process of =
an IC, no two ICs are same. For instance, the impurities present in the =
IC can affect the doping level of an IC and thus cause signal paths to =
change. These slight variations in the signal path can affect the delay =
in the propagation of a signal which can be measured and used to =
identify the chip. This uniqueness of an IC can be used to authenticate =
the device in which the IC has been placed.
>=20
> =20
> PUF: The Concept
>=20
>=20
>=20
>  Figure 1: PUF =E2=80=93 Multiplexer pair=E2=80=99s output delay =
compared by arbiter (latch)
>=20
> When the same input is fed to two adjacent multiplexers, depending on =
the impurities and other manufacturing variations, the delay observed in =
the propagation of the signal to one multiplexer output is different =
from that of the other. This delay can be compared using an arbiter =
(latch) and the final output generated. Several pairs of multiplexers =
can be operated in parallel or a series of inputs can be fed to the same =
pair of multiplexer. Thus, a set of output bits is generated that is =
specific to the chip.
>=20
> The set of input bits is called challenge and the set of output bits =
is called response. A challenge/ response pair is specific to the chip. =
The experimental results [4] show that two identical PUF circuits on two =
different chips have different outputs for the same input with a =
probability of 23% (inter-chip variation). On the other hand, multiple =
measurements on the same chip are different only with 0.7% probability. =
As both the multiplexers on the chip are in the same environment, the =
PUF output is mostly independent of the environmental variations.
>=20
> Limitations of current PUF implementation
>=20
> To prevent the replay attack, a challenge =E2=80=93 response pair can =
be used only once. To enable this, a large set of challenge =E2=80=93 =
response pairs have to be generated at the installation time and =
pre-stored in the server. A server can have many devices connected to =
it. So, it has to have a large database and computational power.
>=20
> Moreover, this setting is inflexible. There is the problem of =
distributing challenge/ response pairs from client to server. When the =
PUF is commissioned, challenge/ response pairs have to be generated at =
the chip and taken to server.  If the server exhausts its supply of =
challenge-response pairs, it cannot be easily renewed.
>=20
> =20
> Our solution
>=20
> Thus in our solution, we combine the best of X.509 certificate and =
PUF. Certificate is well-tested technology and provides flexible way to =
distribute keys. PUF is relatively new but allows a cheap solution to =
IoT authentication problem. Moreover, there is no need to store keys or =
certificates at the client-side.
>=20
> The Protocol Combining TLS 1.3 and Challenge/ Response of PUF
>=20
> The Protocol with Client Starting the Connection
>=20
> Client starts by generating its key_share and sends it to Server for =
normal TLS connection. It also sends acceptable ciphersuites. Server =
generates its own private key and joins with client's keyshare to get =
the shared secret. It takes this share-secret and combines with hash of =
the handshake till that point to generate handshake keys. The connection =
is encrypted from this point on.
>=20
> =20
> The server sends its X.509 certificate, CertificateVerify and =
PUF_Challenge. The client also generates the handshake key from its =
private key and server's public key. It then verifies the certificate, =
generates PUF_Response. It encrypts the PUF_Response and sends to the =
Server. Server verifies it, generates Application Key from Handshake_key =
and hash of the Handshake.
>=20
> =20
> The Client also generates the Application Keys similarly. The =
Application data flows in encrypted form. To start, Server requires only =
one pair of Challenge/ Response. When server's stock is depleting it may =
request more challenge/ response pairs in application data. Client may =
generate more pairs and send them as encrypted data to server which =
stores in its database for future use. Client should delete its copy =
permanently so that an adversary can't recover it by attacking hardware.
>=20
> Client                                                                 =
                                               Server
>=20
> ClientHello                                      =20
>=20
> + key_share          -------->                    =20
>=20
>                                                                        =
                                            ServerHello
>=20
>                                                                        =
                                           + key_share     =20
>=20
>                                                                        =
                      {Encrypted Extensions}
>=20
>                                                                        =
                                            {Certificate}
>=20
>     {CertificateVerify}
>=20
>                                            <---------                  =
                          {PUF_Challenge}
>=20
> PUF_Response              ---------->                            =20
>=20
>                                                                        =
                                           {Finished}
>=20
>                                          <---------                    =
                             [Application Data]
>=20
> {Finished}                                                             =
   =20
>=20
> [Application Data}         <-------->                                  =
          [Application Data]
>=20
> =20
>=20
> =20
>=20
> The Protocol with Server Starting the Connection
>=20
> The Server may also initiate connection by sending Server Hello. =
Client replies by sending Client Hello with its key_share and list of =
acceptable ciphersuites. When server receives Client_Hello, it proceeds =
just like the above use-case.
>=20
> =20
> Client                                                                 =
                                      Server
>=20
>                                                         <-----------   =
                                    ServerHello
>=20
>                                                                      =20=

> ClientHello                                      =20
>=20
> + key_share                              ---------->                   =
                              =20
>=20
>  key_share               =20
>=20
>                                                                        =
                           {Encrypted Extensions}
>=20
>                                                                        =
                                         {Certificate}
>=20
>                                                                        =
                                  {CertificateVerify}
>=20
>                                                               =
<-----------                          {PUF_Challenge}
>=20
>                                                            =20
> {PUF_Response}                              ----------=C3=A0
>=20
>                                                                        =
                                           {Finished}
>=20
>                                                                   =
<---------                      [Application Data]
>=20
>      {Finished}                                                        =
               =20
>=20
> [Application Data}                              <-------->             =
               [Application Data]
>=20
> =20
> The Client doesn't store the Keys, Challenge/ Response or the =
Certificate. Each session is a unit in itself. Everything is calculated =
on the fly. This may create latency but this minimizes the resource =
requirement. It is required that when the IoT device is commissioned, =
atleast one Challenge/ Response pair is generated and stored in Server =
Database. Whenever the challenge - response pairs are depleting, on =
Server's request, the Client can generate them and send to the Server as =
encrypted data. After sending, the Client deletes its copy of Challenge =
/ Response.
>=20
> Future Work:
>=20
> 1)    Complete the development of protocol described above by =
including use cases like when does the Handshake fails and Challenge/ =
Response has to be re-negotiated; when Resumption happens etc.
> 2)    Adapt other IoT protocols like QUIC, DTLS to work with PUF.
> 3)    Validate the solution with PUF-enabled Evaluation kits.
>=20
> References =E2=80=93
>=20
> [1] RFC 5280 - Internet X.509 Public Key Infrastructure Certificate =
and Certificate Revocation List (CRL) Profile. =
https://tools.ietf.org/html/rfc5280 =
<https://tools.ietf.org/html/rfc5280>
> [2] 50 Billion IoT devices will be connected by 2020 =E2=80=93 Post =
=E2=80=93 The Things Network. =
https://www.thethingsnetwork.org/community/thessaloniki/post/50-billion-io=
t-devices-will-be-connected-by-2020 =
<https://www.thethingsnetwork.org/community/thessaloniki/post/50-billion-i=
ot-devices-will-be-connected-by-2020>
> [3] https://en.wikipedia.org/wiki/Physical_unclonable_function =
<https://en.wikipedia.org/wiki/Physical_unclonable_function>
> [4] G. E. Suh and S. Devadas, =E2=80=9CPhysical unclonable functions =
for device authentication and secret key generation,=E2=80=9D in =
Proceedings of the 44th annual Design Automation Conference, San Diego, =
CA, Jun. 2007, pp.9=E2=80=9314 =
https://people.csail.mit.edu/devadas/pubs/puf-dac07.pdf =
<https://people.csail.mit.edu/devadas/pubs/puf-dac07.pdf>
> [5] =
http://people.csail.mit.edu/rudolph/Teaching/Lectures/Security/Lecture-Sec=
urity-PUFs-2.pdf =
<http://people.csail.mit.edu/rudolph/Teaching/Lectures/Security/Lecture-Se=
curity-PUFs-2.pdf>
> [5] Blaise Gassend, Dwaine Clarke, Marten van Dijk and Srinivas =
Devadas. Silicon Physical Random Functions. Proceedings of the Computer =
and Communications Security Conference, November 2002 =
http://csg.csail..mit.edu/pubs/memos/Memo-456/memo-456.pdf =
<http://csg.csail.mit.edu/pubs/memos/Memo-456/memo-456.pdf>
> [6] C. Herder, L. Ren, M. van Dijk, M-D. Yu, and S. Devadas, "Trapdoor =
Computational Fuzzy Extractors and Cryptographically-Secure Physical =
Unclonable Functions", IEEE Transactions on Dependable and Secure =
Computing, January 2017 =
https://people.csail.mit.edu/devadas/pubs/trapdoor.pdf =
<https://people.csail.mit.edu/devadas/pubs/trapdoor.pdf>
> [7] Helfmeier, Clemens; Nedospasov, Dmitry; Boit, Christian; Seifert, =
Jean-Pierre (2013). Cloning Physically Unclonable Functions =
<http://users.sec.t-labs.tu-berlin.de/~nedos/host2013.pdf> (PDF). IEEE =
Hardware Oriented Security and Trust (IEEE HOST 2013). June 2=E2=80=933, =
2013 Austin, TX, USA
>=20
>  http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6581556 =
<http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6581556>
>  [8] Merchan Jorge Guajardo =
<https://www.google.com/search?tbo=3Dp&tbm=3Dpts&hl=3Den&q=3Dininventor:%2=
2Merchan+Jorge+Guajardo%22>, Shankaran S. Kumar =
<https://www.google.com/search?tbo=3Dp&tbm=3Dpts&hl=3Den&q=3Dininventor:%2=
2Shankaran+S.+Kumar%22>, Pim T. Tuyls =
<https://www.google.com/search?tbo=3Dp&tbm=3Dpts&hl=3Den&q=3Dininventor:%2=
2Pim+T.+Tuyls%22>, Geert J. Schrijen =
<https://www.google.com/search?tbo=3Dp&tbm=3Dpts&hl=3Den&q=3Dininventor:%2=
2Geert+J.+Schrijen%22> Identification of devices using physically =
unclonable functions=20
> WO 2009024913 A2
>=20
> [9] M. Fyrbiak, C. Kison, W. Adi. Construction of Software-Based =
Digital Physical Clone Resistant Functions. 2013 Fourth International =
Conference on Emerging Security Technologies =
http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6680199 =
<http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6680199>
>       =
[10]https://www.esat.kuleuven.be/cosic/thesis/2011/mai/CloningTheUnclonabl=
e_en.pdf =
<https://www.esat.kuleuven.be/cosic/thesis/2011/mai/CloningTheUnclonable_e=
n.pdf>
> [11] Srinivas Devadas, Edward Suh, Sid Paral, Richard Sowell, Tom =
Ziola, Vivek Khandelwal . Design and Implementation of PUF-Based =
=E2=80=9CUnclonable=E2=80=9D RFID ICs for Anti-Counterfeiting and =
Security Applications.  =
http://verayo.com/pdf/2008_Verayo_IEEE_RFID_Paper.pdf =
<http://verayo.com/pdf/2008_Verayo_IEEE_RFID_Paper.pdf>
> [12] Rishab Nithyanand, John Solis. A Theoretical Analysis: Physical =
Unclonable Functions and The Software Protection Problem. SANDIA REPORT =
SAND2011-6673. Printed in 2011. =
http://prod.sandia.gov/techlib/access-control.cgi/2011/116673.pdf =
<http://prod.sandia..gov/techlib/access-control.cgi/2011/116673.pdf>
> [13] Shahriar B. Shokouhi. Cooperative Artificial Immune System And =
Recurrent Neural Network Error Correction Scheme For Generating Robust =
Hardware Key. International Journal Of Electrical, Electronics And Data =
Communication. ISSN: 2320-2084. Volume-4, Issue-5,May 2016 =
http://www.iraj.in/journal/journal_file/journal_pdf/1-254-146502604154-59.=
.pdf =
<http://www.iraj.in/journal/journal_file/journal_pdf/1-254-146502604154-59=
.pdf>
> [15] D. Lim. Extracting secret keys from integrated circuits. =
Master=E2=80=99s thesis, Massachusetts Institute of Technology, May =
2004. http://csg.csail.mit.edu/pubs/memos/Memo-476/DaihyunLimThesis.pdf =
<http://csg.csail.mit.edu/pubs/memos/Memo-476/DaihyunLimThesis.pdf>
> [16] Ulrich Ruhrmair. On the Formal Foundations of PUFs and Related =
Primitives. October 19, 2016.  =
https://depositonce.tu-berlin.de/bitstream/11303/5994/4/ruehrmair_ulrich.p=
df =
<https://depositonce.tu-berlin.de/bitstream/11303/5994/4/ruehrmair_ulrich.=
pdf>
> [17] =
https://patents.google.com/patent/US20090083833A1/en?q=3DPUF&q=3Dphysicall=
y+unclonable+function&oq=3DPUF+physically+unclonable+function =
<https://patents.google.com/patent/US20090083833A1/en?q=3DPUF&q=3Dphysical=
ly+unclonable+function&oq=3DPUF+physically+unclonable+function>
> [18]      =
https://patents.google.com/patent/US8290150B2/en?q=3Dauthentication&q=3DPU=
F&q=3Dphysically+unclonable+function&oq=3Dauthentication+PUF+physically+un=
clonable+function =
<https://patents.google.com/patent/US8290150B2/en?q=3Dauthentication&q=3DP=
UF&q=3Dphysically+unclonable+function&oq=3Dauthentication+PUF+physically+u=
nclonable+function>
> [19] =
https://patents.google.com/patent/US20140279532A1/en?q=3Dauthentication&q=3D=
PUF&q=3Dphysically+unclonable+function&oq=3Dauthentication+PUF+physically+=
unclonable+function =
<https://patents.google.com/patent/US20140279532A1/en?q=3Dauthentication&q=
=3DPUF&q=3Dphysically+unclonable+function&oq=3Dauthentication+PUF+physical=
ly+unclonable+function>
> [20] RFC 8446 =E2=80=93 The Transport Layer Security (TLS) Protocol =
Version 1.3 https://datatracker.ietf.org/doc/rfc8446/ =
<https://datatracker.ietf.org/doc/rfc8446/>
> [21] The New Illustrated TLS Connection https://tls13.ulfheim.net/ =
<https://tls13.ulfheim.net/>
>       [22] Internet-draft: State-of-the-Art and Challenges for the =
Internet of      Things Security draft-irtf-t2trg-iot-seccons-16
>=20
> [23] Internet-draft: TLS 1.3 Extension for Certificate-based =
Authentication with  an External Pre-Shared Key. =
draft-housley-tls-tls13-cert-with-extern-psk-03
>=20
> _______________________________________________
> T2TRG mailing list
> T2TRG@irtf.org
> https://www.irtf.org/mailman/listinfo/t2trg


--Apple-Mail=_79A3FFD5-9578-4B4B-A7CC-681160980C15
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; line-break: after-white-space;" =
class=3D"">Sankalp,<div class=3D""><br class=3D""></div><div =
class=3D"">The schema below is the wrong way to use PUF technology for =
IoT device authentication.&nbsp;<div class=3D""><br class=3D""></div><div =
class=3D"">PUF is already being used in many fielded IoT systems. You =
simply use the device unique PUF secret to create a public/private key =
pair. The public key is then extracted and used to authentic the device. =
This enables tracking and identification of the device through its full =
life-cycle. Early observation of the device-unique public key mitigates =
a variety of supply chain attacks. The extracted public key may be =
certified by a X.509 CA. The PUF derived identity may then be used =
directly in a TLS protocol exchange.&nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">Early assignment of public key =
certificate to a device enables strong protection of the device during =
manufacturing. The PUF device keys may be used as part of the boot =
process to enable per-device protection of sensitive firmware or other =
cryptographic secrets. &nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">PUF may be instantiated as HW or SW. =
Your scheme mentions " signal path can affect the delay in the =
propagation of a signal=E2=80=9D =E2=80=A6 the seems to imply a HW based =
implementation (perhaps a Butterfly PUF). A simpler implementation would =
be to use SRAM PUF where the entropy in uninitialized SRAM is used to =
generate the device unique secrets. SRAM based PUF can be readily =
integrated into existing MCU devices.</div><div class=3D""><br =
class=3D""></div><div class=3D"">The simplest application of PUF in IoT =
uses a device unique symmetric secret key to serve as a key to encrypt =
sensitive data in unprotected NV memory. &nbsp;This is basically a =
low-level key vault &nbsp;that provides confidential and =
non-non-maleable secure device storage. This is a very attractive =
alternative to OTP memory that s more expensive and of limited =
size.&nbsp;</div><div class=3D""><br class=3D""></div><div class=3D"">PUF =
is just one way for a device to obtain unique secrets (symmetric or =
asymmetric). It has been standard practice to =E2=80=9Cinject=E2=80=99 =
secrets during manufacturing. Injection requires more trust in the key =
distribution and provisioning process than approaches that generate keys =
on device and never expose these secrets.&nbsp;</div><div class=3D""><br =
class=3D""></div><div class=3D"">Long-lived device unique public keys =
and certificates that provide protection through the full manufacturing =
life-cycle are an interesting topic area =E2=80=A6 =
&nbsp;Challenge/response PUF protocols are not useful or interesting for =
standardization.</div><div class=3D""><br class=3D""></div><div =
class=3D"">Paul</div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""></div><div class=3D""><br class=3D""></div><div =
class=3D""><br class=3D""><div><br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D"">On Feb 15, 2019, at 9:06 PM, Sankalp Bagaria =
&lt;<a href=3D"mailto:sankalp.nitt@gmail.com" =
class=3D"">sankalp.nitt@gmail.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><div dir=3D"ltr" =
class=3D""><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-family:Calibri,sans-serif"><span =
style=3D"font-size:18.6667px" class=3D""><b =
class=3D"">Hello,</b></span></p><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-family:Calibri,sans-serif"><span =
style=3D"font-size:18.6667px" class=3D""><b class=3D"">Please take a =
look at this and advise if it is a good idea and whether it should be =
pursued.</b></span></p><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-family:Calibri,sans-serif"><span =
style=3D"font-size:18.6667px" class=3D""><b =
class=3D"">Thanks,</b></span></p><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-family:Calibri,sans-serif"><span =
style=3D"font-size:18.6667px" class=3D""><b class=3D"">Sankalp =
Bagaria.</b></span></p><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span =
style=3D"font-size:14pt;line-height:115%;background-image:initial;backgrou=
nd-position:initial;background-size:initial;background-repeat:initial;back=
ground-origin:initial;background-clip:initial" class=3D""><br =
class=3D""></span></b></p><p class=3D"MsoNormal" align=3D"center" =
style=3D"text-align:center;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span =
style=3D"font-size:14pt;line-height:115%;background-image:initial;backgrou=
nd-position:initial;background-size:initial;background-repeat:initial;back=
ground-origin:initial;background-clip:initial" class=3D"">ITDA - IoT =
Device Authentication</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><i =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">Abstract: </span></i><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">We propose that the =
server is authenticated using X509
certificate in a TLS 1.3 like protocol. The Server sends 32-byte =
Challenge. Client
replies by sending 32-byte Response. Thus the client is authenticated. =
In the
transfer of the application data, the client may send more =
challenge-response
pairs as encrypted data for updating database of server. Client =
doesn=E2=80=99t store
challenge/response or key or certificate. Both the server and the client =
can initiate
the handshake.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">Background</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">Traditionally, =
there are two ways to authenticate a device: a
centralised CA issuing certificates and block-chain. Both require costly
infrastructure and can=E2=80=99t be used to authenticate IoT devices, =
which are of low
cost. While block-chain provides non-repudiation, transactions are =
distributed
all over the net. X.509 certificates are costlier than many =
sensors.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">Another option is =
Physically Uncloneable Functions (PUF). Because
of the random variations taking place during the manufacturing process =
of an
IC, no two ICs are same. For instance, the impurities present in the IC =
can
affect the doping level of an IC and thus cause signal paths to change. =
These
slight variations in the signal path can affect the delay in the =
propagation of
a signal which can be measured and used to identify the chip. This =
uniqueness
of an IC can be used to authenticate the device in which the IC has been
placed.</span></p><div style=3D"text-align: justify; margin: 0cm 0cm =
10pt; line-height: 115%; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span><br class=3D"webkit-block-placeholder"></div><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D"">PUF:=
 The Concept</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D""><img=
 width=3D"576" height=3D"307" alt=3D"P02.JPG" class=3D""></span></b><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D""></span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">&nbsp;Figure 1: =
PUF =E2=80=93
Multiplexer pair=E2=80=99s output delay compared by arbiter =
(latch)</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">When the same =
input is fed to two adjacent multiplexers,
depending on the impurities and other manufacturing variations, the =
delay
observed in the propagation of the signal to one multiplexer output is
different from that of the other. This delay can be compared using an =
arbiter
(latch) and the final output generated. Several pairs of multiplexers =
can be
operated in parallel or a series of inputs can be fed to the same pair =
of
multiplexer. Thus, a set of output bits is generated that is specific to =
the
chip. </span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">The set of input =
bits is called challenge and the set of
output bits is called response. A challenge/ response pair is specific =
to the
chip. The experimental results [4] show that two identical PUF circuits =
on two
different chips have different outputs for the same input with a =
probability of
23% (inter-chip variation). On the other hand, multiple measurements on =
the
same chip are different only with 0.7% probability. As both the =
multiplexers on
the chip are in the same environment, the PUF output is mostly =
independent of
the environmental variations. </span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">Limitations of current PUF implementation</span></b></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">To prevent the =
replay attack, a challenge =E2=80=93 response pair can
be used only once. To enable this, a large set of challenge =E2=80=93 =
response pairs
have to be generated at the installation time and pre-stored in the =
server. A
server can have many devices connected to it. So, it has to have a large
database and computational power.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">Moreover, this =
setting is inflexible. There is the problem of
distributing challenge/ response pairs from client to server. When the =
PUF is
commissioned, challenge/ response pairs have to be generated at the chip =
and
taken to server.&nbsp; If the server exhausts
its supply of challenge-response pairs, it cannot be easily renewed. =
</span></p><div style=3D"text-align: justify; margin: 0cm 0cm 10pt; =
line-height: 115%; font-size: 11pt; font-family: Calibri, sans-serif;" =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span><br class=3D"webkit-block-placeholder"></div><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D"">Our =
solution</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">Thus in our =
solution, we combine the best of X.509
certificate and PUF. Certificate is well-tested technology and provides
flexible way to distribute keys. PUF is relatively new but allows a =
cheap
solution to IoT authentication problem. Moreover, there is no need to =
store
keys or certificates at the client-side.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D"">The =
Protocol Combining TLS 1.3 and Challenge/ Response of =
PUF</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D"">The =
Protocol with Client Starting the Connection</span></b></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">Client starts by =
generating its key_share and sends it to
Server for normal TLS connection. It also sends acceptable ciphersuites. =
Server
generates its own private key and joins with client's keyshare to get =
the
shared secret. It takes this share-secret and combines with hash of the
handshake till that point to generate handshake keys. The connection is
encrypted from this point on.</span></p><div style=3D"text-align: =
justify; margin: 0cm 0cm 10pt; line-height: 115%; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">&nbsp;</span><br =
class=3D"webkit-block-placeholder"></div><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">The server sends =
its X.509 certificate, CertificateVerify and
PUF_Challenge. The client also generates the handshake key from its =
private key
and server's public key. It then verifies the certificate, generates =
PUF_Response.
It encrypts the PUF_Response and sends to the Server. Server verifies =
it,
generates Application Key from Handshake_key and hash of the =
Handshake.</span></p><div style=3D"text-align: justify; margin: 0cm 0cm =
10pt; line-height: 115%; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span><br class=3D"webkit-block-placeholder"></div><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">The Client also =
generates the Application Keys similarly. The
Application data flows in encrypted form. To start, Server requires only =
one
pair of Challenge/ Response. When server's stock is depleting it may =
request
more challenge/ response pairs in application data. Client may generate =
more
pairs and send them as encrypted data to server which stores in its =
database
for future use. Client should delete its copy permanently so that an =
adversary can't
recover it by attacking hardware.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">Client&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Server</sp=
an></p><p class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">ClientHello&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">+ =
key_share&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
--------&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
 =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ServerHello</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;+
key_share&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;{Encrypted
Extensions}</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;
=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;{Certificate}</span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
324pt;text-align:justify;line-height:115%;font-size:11pt;font-family:Calib=
ri,sans-serif"><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;
{CertificateVerify}</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&lt;---------&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; {PUF_Challenge}</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">PUF_Response&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;----------&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></p><p class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm =
0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{Finished}</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;---------&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[Appli=
cation
Data]</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">{Finished}&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</=
span></p><p class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm =
0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">[Application Data} =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;--------&gt;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[Application
Data]</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span></b></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" class=3D"">The =
Protocol with Server Starting the Connection</span></b></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">The Server may =
also initiate connection by sending Server
Hello. Client replies by sending Client Hello with its key_share and =
list of
acceptable ciphersuites. When server receives Client_Hello, it proceeds =
just like
the above use-case.</span></p><div style=3D"text-align: justify; margin: =
0cm 0cm 10pt; line-height: 115%; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;</span><br class=3D"webkit-block-placeholder"></div><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">Client&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;Server</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&lt;-----------&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
ServerHello</span></p><div style=3D"text-align: justify; margin: 0cm 0cm =
10pt; line-height: 115%; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;</span><br class=3D"webkit-block-placeholder"></div><p=
 class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">ClientHello&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">+ =
key_share&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;----------&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp; &nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
</span></p><p class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
324pt;text-align:justify;text-indent:36pt;line-height:115%;font-size:11pt;=
font-family:Calibri,sans-serif"><span =
style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;key_share&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{Encrypt=
ed Extensions}</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;{Certificate}</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;{CertificateVerify}</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;-----------&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;{PUF_Challenge}</span></p><div style=3D"text-align: justify; =
margin: 0cm 0cm 10pt; line-height: 115%; font-size: 11pt; font-family: =
Calibri, sans-serif;" class=3D""><span =
style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span><br class=3D"webkit-block-placeholder"></div><p class=3D"MsoNormal"=
 style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">{PUF_Response}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;----------</span=
><span style=3D"font-size:14pt;line-height:115%;font-family:Wingdings" =
class=3D"">=C3=A0</span><span style=3D"font-size:14pt;line-height:115%" =
class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{Finished}</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&lt;---------&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;[Application =
Data]</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">&nbsp;&nbsp;&nbsp; =
&nbsp;{Finished}&nbsp;
=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</=
span></p><p class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm =
0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">[Application =
Data}&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&lt;--------&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; =
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;[Application Data]</span></p><div =
style=3D"text-align: justify; margin: 0cm 0cm 10pt; line-height: 115%; =
font-size: 11pt; font-family: Calibri, sans-serif;" class=3D""><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">&nbsp;</span><br =
class=3D"webkit-block-placeholder"></div><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">The Client doesn't =
store the Keys, Challenge/ Response or the
Certificate. Each session is a unit in itself. Everything is calculated =
on the
fly. This may create latency but this minimizes the resource =
requirement. It is
required that when the IoT device is commissioned, atleast one =
Challenge/
Response pair is generated and stored in Server Database. Whenever the
challenge - response pairs are depleting, on Server's request, the =
Client can
generate them and send to the Server as encrypted data. After sending, =
the
Client deletes its copy of Challenge / Response.</span></p><p =
class=3D"MsoNormal" style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><b =
class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">Future Work:</span></b></p><div style=3D"text-align: justify; =
margin: 0cm 0cm 0.0001pt 36pt; line-height: 115%; font-size: 11pt; =
font-family: Calibri, sans-serif;" class=3D""><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">1)<span =
style=3D"font-variant-numeric:normal;font-variant-east-asian:normal;font-s=
tretch:normal;font-size:7pt;line-height:normal;font-family:&quot;Times =
New Roman&quot;" class=3D"">&nbsp;&nbsp;&nbsp; </span></span><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">Complete the =
development of protocol
described above by including use cases like when does the Handshake =
fails and
Challenge/ Response has to be re-negotiated; when Resumption happens =
etc.</span></div><div style=3D"text-align: justify; margin: 0cm 0cm =
0.0001pt 36pt; line-height: 115%; font-size: 11pt; font-family: Calibri, =
sans-serif;" class=3D""><span style=3D"font-size:14pt;line-height:115%" =
class=3D"">2)<span =
style=3D"font-variant-numeric:normal;font-variant-east-asian:normal;font-s=
tretch:normal;font-size:7pt;line-height:normal;font-family:&quot;Times =
New Roman&quot;" class=3D"">&nbsp;&nbsp;&nbsp; </span></span><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">Adapt other IoT =
protocols like QUIC,
DTLS to work with PUF.</span></div><p =
class=3D"gmail-MsoListParagraphCxSpLast" =
style=3D"text-align:justify;margin:0cm 0cm 10pt =
36pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">3)<span =
style=3D"font-variant-numeric:normal;font-variant-east-asian:normal;font-s=
tretch:normal;font-size:7pt;line-height:normal;font-family:&quot;Times =
New Roman&quot;" class=3D"">&nbsp;&nbsp;&nbsp; </span></span><span =
style=3D"font-size:14pt;line-height:115%" class=3D"">Validate the =
solution with
PUF-enabled Evaluation kits.</span></p><p class=3D"MsoNormal" =
style=3D"text-align:justify;margin:0cm 0cm =
10pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size:14pt;line-height:115%" class=3D"">References =
=E2=80=93</span></p><p class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[1] RFC 5280 - Internet X.509 =
Public Key Infrastructure
Certificate and Certificate Revocation List (CRL) Profile. </span><a =
href=3D"https://tools.ietf.org/html/rfc5280" class=3D""><span =
style=3D"font-size: 14pt;" =
class=3D"">https://tools.ietf.org/html/rfc5280</span></a><span =
style=3D"font-size: 14pt;" class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[2] 50 Billion IoT devices will =
be connected by 2020 =E2=80=93
Post =E2=80=93 The Things Network. </span><a =
href=3D"https://www.thethingsnetwork.org/community/thessaloniki/post/50-bi=
llion-iot-devices-will-be-connected-by-2020" class=3D""><span =
style=3D"font-size: 14pt;" =
class=3D"">https://www.thethingsnetwork.org/community/thessaloniki/post/50=
-billion-iot-devices-will-be-connected-by-2020</span></a><span =
style=3D"font-size: 14pt;" class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[3] </span><a =
href=3D"https://en.wikipedia.org/wiki/Physical_unclonable_function" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">https://en.wikipedia.org/wiki/Physical_unclonable_function</spa=
n></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[4] G. E. Suh and S. Devadas, =
=E2=80=9CPhysical unclonable
functions for device authentication and secret key generation,=E2=80=9D =
in Proceedings
of the 44th annual Design Automation Conference, San Diego, CA, Jun. =
2007,
pp.9=E2=80=9314 </span><a =
href=3D"https://people.csail.mit.edu/devadas/pubs/puf-dac07.pdf" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">https://people.csail.mit.edu/devadas/pubs/puf-dac07.pdf</span><=
/a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[5] </span><a =
href=3D"http://people.csail.mit.edu/rudolph/Teaching/Lectures/Security/Lec=
ture-Security-PUFs-2.pdf" class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://people.csail.mit.edu/rudolph/Teaching/Lectures/Security/=
Lecture-Security-PUFs-2.pdf</span></a><span style=3D"font-size: 14pt;" =
class=3D""></span></p><p class=3D"MsoNormal" style=3D"margin:0cm 0cm =
10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[5] Blaise Gassend, Dwaine =
Clarke, Marten van Dijk and
Srinivas Devadas. Silicon Physical Random Functions. Proceedings of the
Computer and Communications Security Conference, November 2002 </span><a =
href=3D"http://csg.csail.mit.edu/pubs/memos/Memo-456/memo-456.pdf" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://csg.csail..mit.edu/pubs/memos/Memo-456/memo-456.pdf</spa=
n></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[6] C. Herder, L. Ren, M. van =
Dijk, M-D. Yu, and S.
Devadas, "Trapdoor Computational Fuzzy Extractors and
Cryptographically-Secure Physical Unclonable Functions", IEEE =
Transactions
on Dependable and Secure Computing, January 2017 </span><a =
href=3D"https://people.csail.mit.edu/devadas/pubs/trapdoor.pdf" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">https://people.csail.mit.edu/devadas/pubs/trapdoor.pdf</span></=
a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[7] Helfmeier, Clemens; =
Nedospasov, Dmitry; Boit,
Christian; Seifert, Jean-Pierre (2013). </span><a =
href=3D"http://users.sec.t-labs.tu-berlin.de/~nedos/host2013.pdf" =
class=3D""><span style=3D"font-size: 14pt;" class=3D"">Cloning
Physically Unclonable Functions</span></a><span style=3D"font-size: =
14pt;" class=3D""> (PDF). IEEE Hardware Oriented Security and Trust =
(IEEE HOST 2013). June
2=E2=80=933, 2013 Austin, TX, USA</span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">&nbsp;</span><a =
href=3D"http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6581556" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6581556</=
span></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">&nbsp;[8] </span><a =
href=3D"https://www.google.com/search?tbo=3Dp&amp;tbm=3Dpts&amp;hl=3Den&am=
p;q=3Dininventor:%22Merchan+Jorge+Guajardo%22" class=3D""><span =
style=3D"font-size: 14pt;" class=3D"">Merchan Jorge
Guajardo</span></a><span style=3D"font-size: 14pt;" class=3D"">, =
</span><a =
href=3D"https://www.google.com/search?tbo=3Dp&amp;tbm=3Dpts&amp;hl=3Den&am=
p;q=3Dininventor:%22Shankaran+S.+Kumar%22" class=3D""><span =
style=3D"font-size: 14pt;" class=3D"">Shankaran S.
Kumar</span></a><span style=3D"font-size: 14pt;" class=3D"">, </span><a =
href=3D"https://www.google.com/search?tbo=3Dp&amp;tbm=3Dpts&amp;hl=3Den&am=
p;q=3Dininventor:%22Pim+T.+Tuyls%22" class=3D""><span style=3D"font-size: =
14pt;" class=3D"">Pim T. Tuyls</span></a><span style=3D"font-size: =
14pt;" class=3D"">, </span><a =
href=3D"https://www.google.com/search?tbo=3Dp&amp;tbm=3Dpts&amp;hl=3Den&am=
p;q=3Dininventor:%22Geert+J.+Schrijen%22" class=3D""><span =
style=3D"font-size: 14pt;" class=3D"">Geert J.
Schrijen</span></a><span style=3D"font-size: 14pt;" class=3D""> =
Identification of devices using physically
unclonable functions <br class=3D"">
WO 2009024913 A2</span></p><p class=3D"MsoNormal" style=3D"margin:0cm =
0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[9] M. Fyrbiak, C. Kison, W. Adi. =
Construction of
Software-Based Digital Physical Clone Resistant Functions. 2013 Fourth
International Conference on Emerging Security Technologies </span><a =
href=3D"http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6680199" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=3D6680199</=
span></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
[10]<a =
href=3D"https://www.esat.kuleuven.be/cosic/thesis/2011/mai/CloningTheUnclo=
nable_en.pdf" class=3D""><span style=3D"" =
class=3D"">https://www.esat.kuleuven.be/cosic/thesis/2011/mai/CloningTheUn=
clonable_en.pdf</span></a></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[11] Srinivas Devadas, Edward =
Suh, Sid Paral, Richard
Sowell, Tom Ziola, Vivek Khandelwal . Design and Implementation of =
PUF-Based
=E2=80=9CUnclonable=E2=80=9D RFID ICs for Anti-Counterfeiting and =
Security Applications.&nbsp; </span><a =
href=3D"http://verayo.com/pdf/2008_Verayo_IEEE_RFID_Paper.pdf" =
class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://verayo.com/pdf/2008_Verayo_IEEE_RFID_Paper.pdf</span></a=
><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[12] Rishab Nithyanand, John =
Solis. A Theoretical Analysis:
Physical Unclonable Functions and The Software Protection Problem. =
SANDIA
REPORT SAND2011-6673. Printed in 2011. </span><a =
href=3D"http://prod.sandia..gov/techlib/access-control.cgi/2011/116673.pdf=
" class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://prod.sandia.gov/techlib/access-control.cgi/2011/116673.p=
df</span></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[13] Shahriar B. Shokouhi. =
Cooperative Artificial Immune
System And Recurrent Neural Network Error Correction Scheme For =
Generating
Robust Hardware Key. International Journal Of Electrical, Electronics =
And Data
Communication. ISSN: 2320-2084. Volume-4, Issue-5,May 2016 </span><a =
href=3D"http://www.iraj.in/journal/journal_file/journal_pdf/1-254-14650260=
4154-59.pdf" class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://www.iraj.in/journal/journal_file/journal_pdf/1-254-14650=
2604154-59..pdf</span></a><span style=3D"font-size: 14pt;" =
class=3D""></span></p><p class=3D"MsoNormal" style=3D"margin:0cm 0cm =
10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[15] D. Lim. Extracting secret =
keys from integrated
circuits. Master=E2=80=99s thesis, Massachusetts Institute of =
Technology, May 2004. </span><a =
href=3D"http://csg.csail.mit.edu/pubs/memos/Memo-476/DaihyunLimThesis.pdf"=
 class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">http://csg.csail.mit.edu/pubs/memos/Memo-476/DaihyunLimThesis.p=
df</span></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p =
class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[16] Ulrich Ruhrmair. On the =
Formal Foundations of PUFs
and Related Primitives. October 19, 2016. &nbsp;</span><a =
href=3D"https://depositonce.tu-berlin.de/bitstream/11303/5994/4/ruehrmair_=
ulrich.pdf" class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">https://depositonce.tu-berlin.de/bitstream/11303/5994/4/ruehrma=
ir_ulrich.pdf</span></a><span style=3D"font-size: 14pt;" =
class=3D""></span></p><p class=3D"MsoNormal" style=3D"margin:0cm 0cm =
10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[17] </span><a =
href=3D"https://patents.google.com/patent/US20090083833A1/en?q=3DPUF&amp;q=
=3Dphysically+unclonable+function&amp;oq=3DPUF+physically+unclonable+funct=
ion" class=3D""><span style=3D"font-size: 14pt;" =
class=3D"">https://patents.google.com/patent/US20090083833A1/en?q=3DPUF&am=
p;q=3Dphysically+unclonable+function&amp;oq=3DPUF+physically+unclonable+fu=
nction</span></a><span style=3D"font-size: 14pt;" class=3D""></span></p><p=
 class=3D"MsoNormal" style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[18]&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span><a =
href=3D"https://patents.google.com/patent/US8290150B2/en?q=3Dauthenticatio=
n&amp;q=3DPUF&amp;q=3Dphysically+unclonable+function&amp;oq=3Dauthenticati=
on+PUF+physically+unclonable+function" class=3D""><span =
style=3D"font-size: 14pt;" =
class=3D"">https://patents.google.com/patent/US8290150B2/en?q=3Dauthentica=
tion&amp;q=3DPUF&amp;q=3Dphysically+unclonable+function&amp;oq=3Dauthentic=
ation+PUF+physically+unclonable+function</span></a><span =
style=3D"font-size: 14pt;" class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[19] </span><a =
href=3D"https://patents.google.com/patent/US20140279532A1/en?q=3Dauthentic=
ation&amp;q=3DPUF&amp;q=3Dphysically+unclonable+function&amp;oq=3Dauthenti=
cation+PUF+physically+unclonable+function" class=3D""><span =
style=3D"font-size: 14pt;" =
class=3D"">https://patents.google.com/patent/US20140279532A1/en?q=3Dauthen=
tication&amp;q=3DPUF&amp;q=3Dphysically+unclonable+function&amp;oq=3Dauthe=
ntication+PUF+physically+unclonable+function</span></a><span =
style=3D"font-size: 14pt;" class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[20] RFC 8446 =E2=80=93 The =
Transport Layer Security (TLS)
Protocol Version 1.3 </span><a =
href=3D"https://datatracker.ietf.org/doc/rfc8446/" class=3D""><span =
style=3D"font-size: 14pt;" =
class=3D"">https://datatracker.ietf.org/doc/rfc8446/</span></a><span =
style=3D"font-size: 14pt;" class=3D""></span></p><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[21] The New Illustrated TLS =
Connection
<a href=3D"https://tls13.ulfheim.net/" =
class=3D"">https://tls13.ulfheim.net/</a></span></p>

<h1 =
style=3D"margin-right:0cm;margin-left:0cm;font-size:24pt;font-family:&quot=
;Times New Roman&quot;,serif" class=3D""><span style=3D"font-size: 14pt; =
font-family: Calibri, sans-serif; font-weight: normal;" =
class=3D"">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
[22] Internet-draft: State-of-the-Art and Challenges for the Internet
of&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Things Security
draft-irtf-t2trg-iot-seccons-16</span></h1><p class=3D"MsoNormal" =
style=3D"margin:0cm 0cm 10pt =
18pt;line-height:115%;font-size:11pt;font-family:Calibri,sans-serif"><span=
 style=3D"font-size: 14pt;" class=3D"">[23]
Internet-draft: TLS 1.3 Extension for Certificate-based Authentication
with&nbsp; an External Pre-Shared Key. =
draft-housley-tls-tls13-cert-with-extern-psk-03</span></p></div>
_______________________________________________<br class=3D"">T2TRG =
mailing list<br class=3D""><a href=3D"mailto:T2TRG@irtf.org" =
class=3D"">T2TRG@irtf.org</a><br =
class=3D"">https://www.irtf.org/mailman/listinfo/t2trg<br =
class=3D""></div></blockquote></div><br =
class=3D""></div></div></body></html>=

--Apple-Mail=_79A3FFD5-9578-4B4B-A7CC-681160980C15--

