[saag] Re: IETF Use of PUF

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <[email protected]>
PUF == physically-unclonable function
    {Sometimes as simple/trivial as observing the biases in uninitialized ram.}

Hesham ElBakoury <[email protected]> wrote:
    > I appreciate your opinion on using PUF for device authentication
    > compared to other methods such as IEEE 802.1AR?

1. They are not mutually exclusive.
That is, a major use for the PUF is to act as a seed to generate a private
key.  The factory also knows the PUF, and generates the same key, and gets
the public part signed to turn it into an 802.1AR certificate.


2. PUF is fundamentally a shared secret.  So anyone who can authenticate the
   PUF can also impersonate the device.


3. There are many many different kinds of PUFs, and many people are skeptical
about a number of the methods.  Often too many NDAs around it, so they do
not, in my opinion, get investigated as much by researchers.

Please read/review: draft-irtf-t2trg-taxonomy-manufacturer-anchors-09
section 4 (4.1.1.3 specifically)


--
Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
           Sandelman Software Works Inc, Ottawa and Worldwide

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE-----

iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmhmqYEWHG1jcitpZXRm
QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZailB/9roYezbdq+CwUEOnbSGbbVxhz7
b07WhVIQ5qGhQ0PsSUcrQlVAp+zkpswSAHA4PF9HaDR+Lfk6s8MUHChzYm9Fmq33
JdB4qTjcPDFhs7T1KgxJfUhe+i7fzv/qBnn0HaqnnJjZKkh2+KsWBK7g2cC9LGtP
CSQsMDyVP7oLGTnro/8G/Mqn9wA7y6/AEUpcALxSiaWlb48uxaZgRvT/XVvEqalX
DARj5djM2lJxOpYNsK3WBSBVG0IohlE4TlL6MM20uylIIfQ491wIYFfG5tDBw4j+
h7nQ2BeEYwZgndA5NyO2UsI5etR3QKENq3PzcoFiJ2lgd8dz1WyVImZ33i1A
=QQyp
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.