This description was written by a machine and published without a person checking it. It is what the agent made of this grouping, and not a statement anybody has stood behind.

The secret in the silicon

A subject the papers are about. The loosest grouping, and the one to reach for last.

A key nobody stored: manufacturing variation is measured on demand, so there is no secret at rest to read out.

The founding pair is both from 2002 and the step between them is the whole idea. Pappu's physical one-way functions are optical -- a token, a laser, a speckle pattern. Gassend's silicon physical random functions put the same argument on a die, where the variation is in the fabrication process itself and the measurement is a circuit. Once it is on the chip it can be a key, and everything after assumes that move.

The rest is escalation, and reading them in order shows the primitive being asked to carry steadily more. Chatterjee wires PUFs into OpenSSL, so they authenticate a TLS session. Qureshi builds authentication and key exchange on them. Chanda replaces a stored private key with DRAM variation and calls the result a device-level PKI. Cambou generates post-quantum keys this way, and Nikolopoulos drives the post-processing of quantum key distribution with them. Each record takes the primitive as settled and hands it a larger job; none of them revisits whether it is.

Tajik is the counterweight and the reason the set is not simply an endorsement. Optical contactless probing from a die's backside pulled bitstream encryption keys out of a running 28 nm chip with no preparation or polishing. The premise is that there is no secret at rest -- and that holds -- but a key that is measured on demand exists at the moment it is used, and that is a moment an attacker with backside access can read. 'Nothing stored' and 'nothing readable' are not the same claim.

Tajik is shared with `hardware-security`, where it sits among the attacks rather than against this set. Chanda's DRAM construction is worth reading next to the RowHammer records there: the same refusal of a memory cell to behave like an abstraction, once exploited as a weakness and once as a key.

Note that `nikolopoulos2024quantum` is the record with the open upload question in the queue -- the bytes held may be the preprint rather than the version of record.

6 references

Quantum Key Distribution with Post-Processing Driven by Physical Unclonable Functions
Georgios M. Nikolopoulos and others (2024) · Applied Sciences · MDPI AG
A lightweight device-level Public Key Infrastructure with DRAM based Physical Unclonable Function (PUF) for secure cyber physical systems
Susovan Chanda and others (2022) · Computer Communications
Post quantum cryptographic keys generated with physical unclonable functions
Bertrand Cambou and others (2021) · Applied Sciences
PUF-RAKE: A PUF-based robust and lightweight authentication and key establishment protocol
Mahmood Azhar Qureshi and others (2021) · IEEE Transactions on Dependable and Secure Computing
PUFSSL: An OpenSSL Extension for PUF based Authentication
Urbi Chatterjee and others (2018) · 2018 IEEE 23rd International Conference on Digital Signal Processing (DSP) · IEEE
On the Power of Optical Contactless Probing: Attacking Bitstream Encryption of FPGAs
Shahin Tajik and others (2017) · Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS '17) · Association for Computing Machinery