PUFSec: Device fingerprint-based security architecture for Internet of Things

PUFSec: Device fingerprint-based security architecture for Internet of Things
复制标题

DOI:
10.1109/infocom.2017.8057146
复制
发表时间:
2017-05
期刊:
IEEE INFOCOM 2017 - IEEE Conference on Computer Communications
影响因子:
--
通讯作者:
So-Yeon Park;S. Lim;Dahee Jeong;Jungjin Lee;Joon-Sung Yang;Hyungjune Lee
So-Yeon Park;S. Lim;Dahee Jeong;Jungjin Lee;Joon-Sung Yang;Hyungjune Lee
中科院分区:
其他
文献类型:
--
作者:
So-Yeon Park;S. Lim;Dahee Jeong;Jungjin Lee;Joon-Sung Yang;Hyungjune Lee

文献摘要

被引文献

相似文献

物联网(IoT)的低端嵌入式平台经常遭受安全增强和计算开销之间的关键权衡困境。我们提出了PUFSec,这是一种新的基于设备指纹的物联网设备安全架构。通过利用固有的硬件特性,我们的目标是设计一个计算轻量级的安全软件系统架构,使复杂的密码计算可以显着禁止。我们利用公共物理不可克隆函数(PPUFs)的创新思想,从根本上保护攻击者从公共门延迟信息恢复密钥。我们实现其硬件逻辑在一个现实世界的FPGA板。在PPUF指纹硬件之上,我们提出了一种自适应安全控制机制,由自适应密钥生成和密钥交换协议组成,根据系统负载动态调整安全强度。我们证明,我们的PPUF FPGA实现嵌入独特的可变性,足以区分两个不同的PPUF高保真度。我们通过在真实世界的物联网平台上实现必要的算法和协议来验证我们的PUFSec架构,并在计算和内存使用方面进行实证评估,证明其实际可行性。
A low-end embedded platform for Internet of Things (IoT) often suffers from a critical trade-off dilemma between security enhancement and computation overhead. We propose PUFSec, a new device fingerprint-based security architecture for IoT devices. By leveraging intrinsic hardware characteristics, we aim to design a computationally lightweight security software system architecture so that complex cryptography computation can dramatically be prohibited. We exploit the innovative idea of Public Physical Unclonable Functions (PPUFs) that fundamentally protects attackers from recovering the secret key from public gate delay information. We implement its hardware logic in a real-world FPGA board. On top of the PPUF fingerprint hardware, we present an adaptive security control mechanism consisting of adaptive key generation and key exchange protocol, which adjusts security strength depending on system load dynamics. We demonstrate that our PPUF FPGA implementation embeds distinctive variability enough to distinguish between two different PPUFs with high fidelity. We validate our PUFSec architecture by implementing necessary algorithms and protocols in a real-world IoT platform, and performing empirical evaluation in terms of computation and memory usages, proving its practical feasibility.