Digital identity enables the identification of devices to provide security in the cyberspace. Such identity comprises a set of attributes that allow the authentication of devices by means of a trusted verification process. Authenticating devices is essential for controlling access to networks and ensuring privacy in communications, while also preventing counterfeit and detecting manipulation. However, with an increasing reliance of society in the cyberspace and an upscaling number of cyberattacks, uniquely and univocally identifying digital devices is becoming more challenging. This is particularly problematic considering the advent of quantum computers, with the potential of solving complex problems in just a fraction of the time it takes to the most powerful supercomputers today. With conventional public key infrastructure (PKI) cryptography at risk, we face the task of securing our digital systems with the development of new cryptographic primitives for the post-quantum era.
To reinforce security in the cyberspace, hardware-based security techniques are being developed to generate strong digital identifiers. In this case, the set of identification attributes are based on physical features that can uniquely represent a specific entity. For example, manufacturing variability inherent to microelectronic circuits can be exploited to derive a digital footprint. Silicon Physical unclonable functions (PUFs) are circuits responsible for generating a digital identity for the device. In essence, a PUF is the hardware implementation of a mathematical one-way function, i.e. a numerical function where the mapping from input to output is nonlinear (this is also known as challenge-response pair, CRP). The nonlinear mapping is realised by the physical uncertainties, which are intrinsically unique for each entity. Moreover, this allows an easy probing of the PUF while the non-invertibility of the one-way function prevents the prediction of the output, which makes the digital identity strong. In electronics, common cost-effective implementations of PUFs exploit the random power-up bias of memory cells or the statistical delay variations of identical circuits. However, these electronic PUFs have been classified as weak, since the underlying physical scrambling mechanism of the one-way function is rather simplistic, which makes them vulnerable to modelling attacks. In addition, with the expecting capabilities of future quantum computing, stronger solutions are required.
Optical implementations are a viable alternative for realising strong PUFs for the post-quantum era. Current implementations propose exploiting complex physical mechanisms with high entropy, such as multiple scattering or multimode interference inside disordered three-dimensional microstructures. The outputs are typically optical intensity maps or transmission spectra that are later converted through a digital process into an identity, i.e. a bit string used in authorisation protocols. These physical mechanisms are computationally difficult to simulate and thus these PUFs are more robust against modelling attacks. However, the systems employed to derive the digital identity from those PUFs are typically complex, bulky and prone to error. Most works propose methods for probing the PUFs which require the physical displacement of the laser beam, rotation of the PUF, or costly equipment such as tunable lasers and spectrometers.
This project aimed to make a contribution in the development of optical cryptographic primitives that remain safe in the post-quantum era. In particular, the project addressed three of the main challenges ahead for making optical PUFs a reality: improving reliability, enhancing robustness and enabling miniaturisation.