Gold nanoparticles create an unclonable security feature

This QR code has a secret: embedded in the half-millimeter-square symbol are thousands of gold nanoparticles, which form an unclonable security feature. Purdue University researchers use a combination of nanomanufacturing and machine learning to create digital fingerprints that are impossible to forge.
Purdue University researchers have created the ultimate two-factor authentication using gold nanoparticles (right) embedded onto a thin film. These nanoparticles create an unclonable visual pattern, allowing for secure identification of any physical object.

Hardware security in the 21st century has become a digital arms race. Even the most secure digital passwords or tokens can be stolen or forged. As such, many security experts are seeking to perfect physical unclonable functions (PUFs): attributes of natural randomness that can definitively identify an object.

“Instead of storing a secret key in memory, we use the random physical structure of the material itself as the key,” said Jingang Li, assistant professor of mechanical engineering and materials engineering. “That makes the system very difficult to duplicate or to attack.”

As with many discoveries, Li’s breakthrough came by accident. “I was making thin films for an unrelated project,” he said, “and when I looked at the surface through a microscope, I saw that gold nanoparticles had separated into a visually distinct pattern of islands. I wondered whether these could function as a PUF.”

He tasked two members of his lab — Ph.D. student Junyuan Lu and undergraduate researcher Ruhaan Batta — to tackle this two-fold problem: manufacturing the gold nanoparticles, and developing a visual verification system that could positively identify the patterns. They built a machine-learning algorithm that achieves an identification accuracy of 99.9%, even under less-than-ideal lighting conditions.

Their research has been published in Nano Letters.

Junyuan Lu and Ruhaan Batta examine a half-millimeter-square QR code under a microscope. This one graphic can contain thousands of unclonable nanoparticle security tags.

“These gold nanoparticles are very small,” said Lu. “Each test section is about one-fifth the width of a human hair, so we can only visually resolve individual particles under a microscope. That’s both a good thing and a bad thing — it’s small enough that it is very difficult to counterfeit, but it also makes identification difficult when the image is slightly shifted, noisy, or color-changed.”

They turned to deep learning to solve this challenge. Lu developed a PUF autoencoder based on deep contrastive learning strategies and a light-weight image-recognition architecture. Rather than comparing images pixel by pixel, the model learns to convert each optical image into a mathematical embedding. In the embedding space, images from the same physical key are mapped close together, while images from different keys are pushed far apart.

This method also makes identification robust under challenging conditions, such as when the image is slightly blurry or off-center. The deep learning method maintained reliable identification under all tested conditions; whereas traditional black-and-white image recognition algorithms failed at most of them.

In the real world, this method could be used to create unique identifiers for manufactured items like semiconductors. Rather than printing each piece of hardware with a number (which could be easily forged), one of these test sections could be embedded, making each piece uniquely identifiable and unclonable using this machine-learning process. The same could be done for bank notes, or pharmaceuticals, or other high-security items.

“That’s why we use gold nanoparticles,” Lu said. “We know that gold is resistant to moisture or physical abrasion, which means these visual patterns will not change under challenging physical conditions. And we’re only using trace amounts of it, which means it’s not really that expensive.”

As a demonstration, they used the nanomanufacturing facilities at Birck Nanotechnology Center to create a half-millimeter-square QR code with this thin-film process. The code itself is visually readable by human-scale QR code readers, but embedded within the code are thousands of nanoparticle test keys — each one unique and unclonable, verifiable only under a microscope.

“This shows that we can create different levels of security,” Lu said. “Even one of these keys is 99.9% verifiable under challenging lighting conditions. Combine thousands of them, and we can make an item statistically impossible to forge. We can trade capacity for accuracy, depending on the application.”

Li’s team are already working on the next generation of this technology, experimenting with materials other than gold, and processes that enable this visual verification at different scales, and even in three dimensions.

“This project started with an accident,” Li said. “But it has resulted in some pretty memorable ‘wow’ moments. I love being able to use combinations of nanomaterials, optics, and machine learning to achieve something amazing.”


Source: Jingang Li, jingang@purdue.edu

Writer: Jared Pike, jaredpike@purdue.edu, 765-496-0374


Noise-Resilient Plasmonic Physical Unclonable Functions via Deep Contrastive Learning
Junyuan Lu, Ruhaan Batta, Jingang Li
https://doi.org/10.1021/acs.nanolett.6c02614
ABSTRACT: Physical unclonable functions (PUFs) based on the stochastic optical responses of nanomaterials have emerged as promising hardware security primitives. Their enormous encoding space and inherent randomness produce high-entropy challenge–response characteristics that resist model-based attacks. However, the readout reliability of optical PUFs is susceptible to imaging inconsistencies, including mechanical vibrations and illumination variations. Here, we present a plasmonic PUF system based on spatially disordered gold nanoislands formed by polymer-mediated dewetting. A ConvNeXt-based encoder is trained with combined supervised contrastive, circle, and uniformity losses to achieve an identification accuracy of 99.9%. The resulting embeddings maintain robust discrimination under color perturbations and region-of-interest shifts up to 20%, outperforming traditional direct binarization methods. We further demonstrate the on-chip integration of plasmonic PUFs with both one-time and reusable authentication, highlighting a scalable route toward practical hardware security systems.