Skip to content

Drift Key

Fuzzy extractor · code-offset sketch · Dodis–Reyzin–Smith 2004

Same device, different bits, same key — then watch a weak source give that key away without a single check failing.

SIMULATED SOURCE

No physical device here: the cell readings come from a labelled model whose parameters are on screen. Not production crypto — a teaching demo.

What is real, and what is modelled

Modelled: the cells. A browser has no physical unclonable function and cannot acquire one, so each cell leans toward a value with a probability you set, and each later reading flips cells at a rate you set. Real SRAM does not separate those two — a strongly biased cell is also a stable one — so a real deployment measures per-cell error rates across temperature, voltage and age.

Real: everything downstream of the readings. The BCH encoder and decoder are implemented here and verified over the whole space of the smallest code; the helper data is the code-offset construction of Juels–Wattenberg and Dodis–Reyzin–Smith; the key derivation is HKDF-SHA-256 from WebCrypto, pinned to the RFC 5869 test vectors.