{"id":{"repo_id":"calgary","oai_identifier":"oai:ucalgary.scholaris.ca:1880/121319"},"canonical_url":"https://search.dev.ndltd.org/etd/calgary/oai:ucalgary.scholaris.ca:1880/121319","repository":{"repo_id":"calgary","name":"University of Calgary","base_url":"https://ucalgary.scholaris.ca/server/oai/request"},"display":{"title":"Entropy Estimation for Arbiter PUF and Applications to Authenticated Key Exchange","abstract":"Physically Unclonable Functions (PUF) are hardware-based security primitives whose unique challenge and response behavior serves as a &quot;fingerprint&quot; for device authentication, key generation, and anti-counterfeiting. Modeling and estimating the entropy of PUF responses to random challenges is the first step in formalizing the security of PUF-based cryptographic protocols. In this thesis, we consider the Arbiter PUF (APUF), a widely used and studied PUF construction. We propose a novel approach to modeling and estimating APUF entropy as a special type of randomness source, known as the (α,k) source. These sources had been previously used to model low-entropy rate biometric data, such as iris codes. We show that APUFs can be modeled as an (α,k) source by developing a framework to estimate extractable, inter-PUF, and intra-PUF entropies of a large number of simulated APUFs. We use the (α,k) source model of APUF to design a novel mutually Authenticated Key Exchange (mAKE) protocol that uses a single (large) multi-bit APUF response. Our mAKE has proved post-quantum cryptographic security in the random oracle model. The main building block of our construction is a new hash-based robust and reusable Fuzzy Extractor (rrFE) that is obtained by extending the reusable FE in Canetti et al. We implement our protocol and show its performance results.","abstract_html":"Physically Unclonable Functions (PUF) are hardware-based security primitives whose unique challenge and response behavior serves as a &amp;quot;fingerprint&amp;quot; for device authentication, key generation, and anti-counterfeiting. Modeling and estimating the entropy of PUF responses to random challenges is the first step in formalizing the security of PUF-based cryptographic protocols. In this thesis, we consider the Arbiter PUF (APUF), a widely used and studied PUF construction. We propose a novel approach to modeling and estimating APUF entropy as a special type of randomness source, known as the (α,k) source. These sources had been previously used to model low-entropy rate biometric data, such as iris codes. We show that APUFs can be modeled as an (α,k) source by developing a framework to estimate extractable, inter-PUF, and intra-PUF entropies of a large number of simulated APUFs. We use the (α,k) source model of APUF to design a novel mutually Authenticated Key Exchange (mAKE) protocol that uses a single (large) multi-bit APUF response. Our mAKE has proved post-quantum cryptographic security in the random oracle model. The main building block of our construction is a new hash-based robust and reusable Fuzzy Extractor (rrFE) that is obtained by extending the reusable FE in Canetti et al. We implement our protocol and show its performance results.","abstract_has_math":false,"creators":["Tripathi, Nikita"],"institution":"Graduate Studies","degree_name":"Master of Science (MSc)","degree_level":null,"degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Safavi-Naeini, Rei"],"committee_chairs":[],"committee_members":["Fong, Philip Wai Leung","Ghaderi, Majid"],"year":2025,"date_issued":"2025-04-30","date_published":"2025-04-30","updated_at":"2026-07-24T01:30:20Z","subjects":["Information Security","IoT","Authentication","Key Exchange","PQC","post-quantum","Information Theory","Entropy","Biometrics","AKE"],"languages":["en"],"rights":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://dx.doi.org/10.11575/PRISM/48909"],"render_values":[{"text":"https://dx.doi.org/10.11575/PRISM/48909","href":"https://dx.doi.org/10.11575/PRISM/48909","code":true}]}]},"links":{"outbound_url":"https://hdl.handle.net/1880/121319","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Safavi-Naeini, Rei"]},{"key":"dc:contributor.committeemember","label":"Committee Member","values":["Fong, Philip Wai Leung","Ghaderi, Majid"]},{"key":"dc:creator","label":"Author","values":["Tripathi, Nikita"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2025-06"]},{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2025-05-05T14:49:55Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2025-05-05T14:49:55Z"]},{"key":"dc:date.issued","label":"Date","values":["2025-04-30"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Calgary"]},{"key":"dc:type","label":"Dc Type","values":["master thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MSc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Calgary"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Information Security","IoT","Authentication","Key Exchange","PQC","post-quantum","Information Theory","Entropy","Biometrics","AKE"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.doi","label":"DOI","values":["https://dx.doi.org/10.11575/PRISM/48909"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1880/121319"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Physically Unclonable Functions (PUF) are hardware-based security primitives whose unique challenge and response behavior serves as a &quot;fingerprint&quot; for device authentication, key generation, and anti-counterfeiting. Modeling and estimating the entropy of PUF responses to random challenges is the first step in formalizing the security of PUF-based cryptographic protocols. In this thesis, we consider the Arbiter PUF (APUF), a widely used and studied PUF construction. We propose a novel approach to modeling and estimating APUF entropy as a special type of randomness source, known as the (α,k) source. These sources had been previously used to model low-entropy rate biometric data, such as iris codes. We show that APUFs can be modeled as an (α,k) source by developing a framework to estimate extractable, inter-PUF, and intra-PUF entropies of a large number of simulated APUFs. We use the (α,k) source model of APUF to design a novel mutually Authenticated Key Exchange (mAKE) protocol that uses a single (large) multi-bit APUF response. Our mAKE has proved post-quantum cryptographic security in the random oracle model. The main building block of our construction is a new hash-based robust and reusable Fuzzy Extractor (rrFE) that is obtained by extending the reusable FE in Canetti et al. We implement our protocol and show its performance results."]},{"key":"dc:title","label":"Title","values":["Entropy Estimation for Arbiter PUF and Applications to Authenticated Key Exchange"]}]}],"canonical_facts":{"dc:contributor.advisor":["Safavi-Naeini, Rei"],"dc:contributor.committeemember":["Fong, Philip Wai Leung","Ghaderi, Majid"],"dc:creator":["Tripathi, Nikita"],"dc:date":["2025-06"],"dc:date.accessioned":["2025-05-05T14:49:55Z"],"dc:date.available":["2025-05-05T14:49:55Z"],"dc:date.issued":["2025-04-30"],"dc:description.abstract":["Physically Unclonable Functions (PUF) are hardware-based security primitives whose unique challenge and response behavior serves as a &quot;fingerprint&quot; for device authentication, key generation, and anti-counterfeiting. Modeling and estimating the entropy of PUF responses to random challenges is the first step in formalizing the security of PUF-based cryptographic protocols. In this thesis, we consider the Arbiter PUF (APUF), a widely used and studied PUF construction. We propose a novel approach to modeling and estimating APUF entropy as a special type of randomness source, known as the (α,k) source. These sources had been previously used to model low-entropy rate biometric data, such as iris codes. We show that APUFs can be modeled as an (α,k) source by developing a framework to estimate extractable, inter-PUF, and intra-PUF entropies of a large number of simulated APUFs. We use the (α,k) source model of APUF to design a novel mutually Authenticated Key Exchange (mAKE) protocol that uses a single (large) multi-bit APUF response. Our mAKE has proved post-quantum cryptographic security in the random oracle model. The main building block of our construction is a new hash-based robust and reusable Fuzzy Extractor (rrFE) that is obtained by extending the reusable FE in Canetti et al. We implement our protocol and show its performance results."],"dc:identifier.doi":["https://dx.doi.org/10.11575/PRISM/48909"],"dc:identifier.uri":["https://hdl.handle.net/1880/121319"],"dc:language.iso":["en"],"dc:publisher.institution":["University of Calgary"],"dc:rights":["University of Calgary graduate students retain copyright ownership and moral rights for their thesis. You may use this material in any way that is permitted by the Copyright Act or through licensing that has been assigned to the document. For uses that are not allowable under copyright legislation or licensing, you are required to seek permission."],"dc:subject":["Information Security","IoT","Authentication","Key Exchange","PQC","post-quantum","Information Theory","Entropy","Biometrics","AKE"],"dc:title":["Entropy Estimation for Arbiter PUF and Applications to Authenticated Key Exchange"],"dc:type":["master thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_name":["Master of Science (MSc)"],"thesis:institution_name":["University of Calgary"]},"updated_at":"2026-07-24T01:30:20Z"}