Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A physically unclonable function (PUF) uses tiny manufacturing differences in a chip to produce a device-specific response. An IoT product can use that response to derive an identity or cryptographic key without keeping the long-term secret directly in nonvolatile memory. A PUF is a hardware root-of-trust building block—not a complete security system: it needs enrollment, error correction, conventional cryptography, and lifecycle management.

What is a PUF?

A physically unclonable function exploits microscopic variations introduced when silicon chips are manufactured. Those variations make nominally identical chips behave slightly differently. A PUF measures some of that difference and returns a response associated with the particular chip.

The response is not necessarily stable bit for bit every time the chip is measured. Voltage, temperature, aging, and measurement noise can change some output bits. A design therefore needs a way to reproduce a usable secret despite those variations, while protecting any data used to do so.

How does a PUF secure an IoT device?

The PUF provides a device-bound input for identity or key material. During enrollment, the product records a reference response or related helper data. Later, error correction or a fuzzy-extractor process helps reconstruct a stable value from a fresh, imperfect PUF response. A key-derivation function can turn that value into key material for ordinary cryptographic protocols.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
ELEGOO 3PCS ESP-32 Dev Boards, ESP-WROOM-32, USB-C, WiFi Bluetooth 4.2
  • Dual-Core Performance Up to 240 MHz: Run sensor processing, wireless communication, automation logic and connected-device tasks on a 32-bit dual-core ESP32 platform designed for responsive embedded and IoT projects
  • Built-in Wi-Fi and Bluetooth 4.2: Connect to 2.4 GHz Wi-Fi networks or use Bluetooth Classic and BLE for wireless sensors, smart devices, remote controls, home automation and other connected projects
  • Flexible Power-Saving Modes: ESP32 power-management features support dynamic clock scaling and low-power operating modes, helping developers reduce energy use in compatible sensing, monitoring and connected-device applications, suitable for battery-powered Internet of Things (IoT) devices.
  • USB-C Programming with CP2102: Connect through USB-C for power, sketch uploads and serial monitoring, while GPIO, UART, SPI and I2C interfaces support sensors, displays, motor drivers and other modules (USB-C cable not included)
  • Over-the-Air Update Support: Configure OTA functionality through a compatible ESP-32 software framework to update deployed firmware over Wi-Fi without reconnecting the board by USB for every revision

That derived key can support device authentication, key derivation, secure boot, signed firmware protection, anti-counterfeit checks, or attestation. The PUF itself does not encrypt network traffic, decide who may access a service, or verify software updates; conventional cryptographic protocols and the rest of the product’s security architecture perform those jobs.

Why helper data and enrollment matter

Enrollment establishes the reference needed to reproduce a usable secret. Helper data may assist reconstruction, but it must be designed and protected so it does not undermine the secret’s security. Raw, noisy PUF bits are not ready-made cryptographic keys and should not be used directly as such.

What a PUF can—and cannot—replace

A PUF can reduce reliance on storing a long-term secret directly in nonvolatile memory. It does not remove the need to provision devices, protect cryptographic operations, authenticate peers, handle failures, or revoke and replace compromised identities. Nor does the label “PUF” alone establish that a chip is unclonable against every attack; implementation quality and attack resistance matter.

Rank #2
2 Pack ESP32-DevKitC-32E Development Board for IoT Smart Home/Industrial Control, Dual-Core 240MHz Wi-Fi + Bluetooth 5.0 with USB-C, Original ESP32-WROOM-32E Module (Arduino/Python/IDF) (8M)
  • Certified & Future-Ready: Espressif-certified ESP32-WROOM-32E ensures full hardware compatibility and lifetime firmware support. Upgraded 8MB Flash handles IoT data and OTA updates.
  • Dual-Core Speed: 240MHz dual-core processor runs Wi-Fi/BLE and sensors 2x faster. 38 GPIO pins (10 RTC) support SPI/I2C/UART for LCDs, motors, and industrial sensors.
  • Plug & Play Dev: USB-C driver pre-installed: upload code instantly on Windows/Mac/Linux. Works with Arduino IDE, MicroPython, and Espressif IDF.
  • All-Environment Ready: Run Wi-Fi smart switches (Home Assistant) and BLE tracking on one board. Industrial-grade stability (-40°C~85°C) for outdoor/automated systems.
  • Advantages: The ESP32 development board offers high performance, low power consumption, and rich wireless connectivity, making it suitable for developers of all levels, especially beginners.

Which kinds of PUF are used in IoT?

SRAM PUFs

An SRAM PUF reads the power-up pattern of uninitialized SRAM. Manufacturing variation influences which cells tend toward one state or the other when power is applied. The resulting pattern can serve as the basis for a device-specific response, subject to stabilization and error correction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Delay and ring-oscillator PUFs

Delay PUFs measure differences in signal timing through chip paths. Ring-oscillator PUFs compare the frequencies of oscillators whose timing is affected by manufacturing variation. Both derive responses from physical differences rather than relying solely on a secret stored in memory.

These approaches differ in how they produce a response, but neither is automatically reliable or secure by virtue of its type. The product must be characterized under its intended operating conditions and threat model.

What evidence is available for SRAM PUFs?

A 2024 version of the RIOT/PUF for the Commons work reports experiments on commercial off-the-shelf devices with 64 kB of SRAM. Across about 250 evaluated platforms, the researchers reported secure random seeds of 256 bits and device-unique keys with more than 128 bits of security. Those figures describe the cited experiment; they are not universal guarantees for SRAM PUFs or any particular IoT product.

The reported result should not be read as evidence that every device with SRAM can reliably generate keys of those strengths. A product’s entropy, reconstruction error, helper-data design, implementation, and environmental behavior must be evaluated for that product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Are PUFs reliable over temperature and aging?

Reliability is an engineering requirement, not an assumed property. A PUF response can vary with voltage, temperature, process variation, measurement conditions, and aging. Error correction can help recover a stable value, but a design must show that its correction scheme works across the product’s operating range without weakening the resulting key.

Rank #4
ESP-WROOM-32 ESP32 ESP-32S Development Board 2.4GHz Dual-Mode WiFi + Bluetooth Dual Cores Microcontroller Processor Integrated with Antenna RF AMP Filter AP STA Compatible with Arduino IDE (3PCS)
  • 2.4GHz Dual Mode WiFi + Bluetooth Development Board
  • Support LWIP protocol, Freertos
  • SupportThree Modes: AP, STA, and AP+STA
  • Ultra-Low power consumption, Compatible with Arduino IDE
  • ESP32 is a safe, reliable, and scalable to a variety of applications

A 2025 paper in Computers & Security identifies aging effects, production cost, and maintenance complexity among practical concerns for PUF-based security. These concerns affect both initial qualification and long-term support: a device that cannot reproduce its identity may fail authentication or require a recovery path.

What to test before deployment

  • Characterize responses across the intended voltage and temperature ranges, process corners, and expected aging conditions.
  • Measure reconstruction failures and confirm that error correction can handle the observed variation.
  • Review whether helper data could reveal information about the underlying response or derived secret.
  • Test provisioning throughput, device replacement, recovery, and re-enrollment procedures at production scale.
  • Assess exposure to modeling attacks and other attacks relevant to the specific PUF implementation.

Can an SRAM PUF replace a secure element or TPM?

Not as a blanket substitution. A PUF is a way to derive device-specific material from physical variation; a secure element or TPM-style root of trust is a hardware security component or architecture whose capabilities depend on the particular product. A PUF may be used within a root-of-trust design, but it does not automatically supply every cryptographic interface, isolation feature, certification, or operational function an alternative might provide.

Software-only identities avoid dedicated PUF circuitry but depend on how secrets are generated, stored, and protected by the device. No option is universally preferable: the decision depends on the threat model, silicon and energy budgets, provisioning process, cryptographic interfaces, maintenance plan, certification needs, and total bill of materials. Product-specific evidence is necessary for a performance or security comparison; the cited sources do not establish universal rankings or costs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Type-C D1 Mini NodeMCU ESP32 WLAN WiFi Bluetooth IoT Development Board 5V Compatible for Arduino (3pcs Type-C)
  • D1 Mini NodeMCU Type-C ESP32 WLAN WiFi Bluetooth IoT Development Board 5V Compatible for Arduino
  • Designed with ultra-low power technology, it offers the full range of performance and features of the ESP32 chip. The pin arrangement provides compatibility with the modules developed for the D1 Mini ESP8266 while also offering fast WLAN, enhanced GPIO, Bluetooth functionality, and with its higher performance, a wider range of applications.
  • 100% compatible with Arudino IDE, Lua and Micropython, it shows robustness, versatility, and reliability in a wide variety of applications and power scenarios.
  • All I/O pins have interrupt, PWM, I2C and one-wire capability, except the pin DO.
  • Designed with ultra-low power technology, it offers the full range of performance and features of the ESP32 chip. The pin arrangement provides compatibility with the modules developed for the D1 Mini ESP8266 while also offering fast WLAN, enhanced GPIO, Bluetooth functionality, and with its higher performance, a wider range of applications.
Evaluation area Questions for a PUF design Questions for a secure element, TPM-style root, or software identity
Cloning and invasive attacks What attacks were tested against this implementation, and what evidence supports its resistance? What protections and attack evaluations apply to the specific component or software design?
Reliability over time How does response reconstruction perform across environment, process variation, and aging? How does the alternative protect and retain its keys over the device’s service life?
Modeling and secret exposure Can an attacker predict responses or exploit helper data? Where are secrets held, and how are they protected from extraction or misuse?
Integration costs What silicon area, energy, enrollment capacity, and helper-data storage does the design require? What component, integration, energy, and provisioning requirements apply?
Lifecycle operations How are failed reconstruction, recovery, re-enrollment, replacement, and decommissioning handled? How are keys provisioned, rotated or revoked, recovered, replaced, and decommissioned?
Cryptographic and compliance fit Which cryptographic interfaces and standards requirements are met by the complete implementation? Which interfaces, certifications, and standards requirements are met by the selected product?

The table is a procurement and design checklist, not a benchmark: the evidence cited here does not provide comparable measurements for these alternatives.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should a product team build PUF security into an IoT lifecycle?

  1. Characterize the implementation. Test the PUF across voltage, temperature, process corners, and expected aging before relying on it for identity or key derivation.
  2. Enroll and protect reconstruction data. Record the reference response or helper data through a controlled enrollment process. Do not treat raw PUF bits as a cryptographic key.
  3. Derive keys and use established cryptography. Apply a key-derivation function, then use conventional authenticated cryptography for device-to-gateway or device-to-cloud communication.
  4. Bind identity to product controls. Connect the derived identity to secure boot, signed software updates, access control, and attestation. A PUF does not supply those controls on its own.
  5. Verify before onboarding. Establish device identity and verify the device and network before issuing network credentials. NIST SP 1800-36, published in November 2025, describes this trusted network-layer onboarding approach and the need to maintain security posture through the device lifecycle.
  6. Plan for failure and retirement. Define recovery, re-enrollment, device replacement, decommissioning, and compromise response. Device uniqueness does not eliminate operational key management.

Which standards and guidance cover PUF-based IoT security?

ISO/IEC 20897-1

ISO/IEC 20897-1:2020 specifies requirements for PUF output properties, tamper resistance, and unclonability, and describes typical use cases. Random-number generation is outside the scope of that standard. A 2026 working draft, identified as ISO/IEC WD 20897-1, is intended to replace the 2020 edition. Procurement and design requirements should therefore identify the exact edition they reference rather than saying only “ISO/IEC 20897-1.”

NIST IoT capabilities and onboarding

NIST’s IoT capability catalog identifies baseline technical capabilities including device identification, configuration, data protection, logical access, software update, cybersecurity state awareness, and device security. These capabilities clarify why a PUF alone is insufficient: it may contribute to device identity or a root of trust, but the product still needs the broader controls.

NIST SP 1800-36 (November 2025) addresses trusted network-layer onboarding: attest and verify the device and network before credentials are delivered, then maintain security posture throughout the lifecycle. A PUF can contribute to the device’s identity in such a process, but it does not replace the onboarding workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.