A Modeling Attack Resistant Deception Technique for Securing Lightweight-PUF-Based Authentication
A Modeling Attack Resistant Deception Technique for Securing Lightweight-PUF-Based Authentication
复制标题
一种用于保护基于轻量级 PUF 的身份验证的建模抗攻击欺骗技术
DOI:
10.1109/tcad.2020.3036807
复制
发表时间:
2020-10
影响因子:
2.9
通讯作者:
Maire O'Neill
中科院分区:
文献类型:
--
作者:
Chongyan Gu;Chip-Hong Chang;Weiqiang Liu;Shichao Yu;Yale Wang;Maire O'Neill
Silicon physical unclonable function (PUF) has emerged as a promising spoof-proof solution for low-cost device authentication. Due to practical constraints in preventing phishing through a public network or insecure communication channels, simple PUF-based authentication protocol with unrestricted queries and transparent responses is vulnerable to modeling and replay attacks. In this article, we present a modeling attack resistant PUF-based mutual authentication scheme to mitigate the practical limitations in applications where a resource-rich server authenticates a device with no strong restriction imposed on the type of PUF design or any additional protection on the binary channel used for the authentication. Our scheme uses an active deception protocol to prevent machine learning (ML) attacks on a device with a monolithic integration of a genuine strong PUF (SPUF), a fake PUF, a pseudorandom number generator (PRNG), a register, a binary counter, a comparator, and a simple controller. The hardware encapsulation makes the collection of challenge–response pairs (CRPs) easy for model building during enrollment but prohibitively time consuming upon device deployment through the same interface. A genuine server can perform a mutual authentication with the device using a combined fresh challenge contributed by both the server and the device. The message exchanged in clear cannot be manipulated by the adversary to derive unused authentic CRPs. The adversary will have to either wait for an impractically long time to collect enough real CRPs by directly querying the device or the ML model derived from the collected CRPs will be poisoned. The false PUF multiplexing is fortified against the prediction of waiting time by doubling the time penalty for every unsuccessful guess. Our implementation results on field-programmable gate array (FPGA) device and security analysis have corroborated the low hardware overheads and attack resistance of the proposed deception protocol.
登录
查看更多内容
DOI:
10.1109/tmscs.2016.2553027
发表时间:
2016-07-01
期刊:
IEEE TRANSACTIONS ON MULTI-SCALE COMPUTING SYSTEMS
影响因子:
--
作者:
Yu, Meng-Day (Mandel);Hiller, Matthias;Verbauwhede, Ingrid
通讯作者:
Verbauwhede, Ingrid
DOI:
10.1109/iscas.2014.6865362
发表时间:
2014-06
期刊:
2014 IEEE International Symposium on Circuits and Systems (ISCAS)
影响因子:
--
作者:
Chongyan Gu;Julian P. Murphy;Máire O’Neill
通讯作者:
Chongyan Gu;Julian P. Murphy;Máire O’Neill
DOI:
10.1109/spw.2012.30
发表时间:
2012-05
期刊:
2012 IEEE Symposium on Security and Privacy Workshops
影响因子:
--
作者:
Mehrdad Majzoobi;M. Rostami;F. Koushanfar;D. Wallach;S. Devadas
通讯作者:
Mehrdad Majzoobi;M. Rostami;F. Koushanfar;D. Wallach;S. Devadas
影响因子:
16.6
作者:
Delvaux, Jeroen;Peeters, Roel;Verbauwhede, Ingrid
通讯作者:
Verbauwhede, Ingrid
DOI:
10.1007/978-3-319-03491-1_3
发表时间:
2013-12
期刊:
--
影响因子:
--
作者:
Patrick Koeberl;Jiangtao Li;Wei Wu
通讯作者:
Patrick Koeberl;Jiangtao Li;Wei Wu