Machine Learning-based Vulnerability Study of Interpose PUFs as Security Primitives for IoT Networks

Machine Learning-based Vulnerability Study of Interpose PUFs as Security Primitives for IoT Networks
复制标题

基于机器学习的插入 PUF 作为物联网网络安全原语的漏洞研究

DOI:
10.1109/nas51552.2021.9605405
复制
发表时间:
2021
期刊:
Architecture and Storage (NAS
影响因子:
--
通讯作者:
Zhuang, Yu
Zhuang, Yu
中科院分区:
--
文献类型:
--
作者:
Thapaliya, Bipana;Mursi, Khalid T.;Zhuang, Yu

文献摘要

被引文献

相似文献

安全对于通信网络非常重要,许多网络节点(例如传感器和物联网设备)都受到资源限制。物理不可克隆功能 (PUF) 利用集成电路的物理变化来产生单个电路特有的响应,并具有为低成本网络提供安全性的潜力。但在 PUF 应用于安全应用之前,必须发现所有安全漏洞。最近,提出了一种称为Interpose PUF(IPUF)的新PUF,经过测试,当被攻击的IPUF尺寸较小时,它可以抵御基于可靠性的建模攻击和机器学习攻击。最近的一项研究表明,IPUF 屈服于分而治之的攻击,并且该攻击方法需要攻击者知道插入位的位置,通过使用随机插入位置可以轻松混淆这一条件。因此,如果攻击者不知道插入位置,大型 IPUF 仍然可以安全地抵御所有已知的建模攻击。在本文中,我们提出了一种使用多层神经网络的 IPUF 建模攻击新方法,该攻击方法不需要知道插入位置。我们的攻击在模拟 IPUF 和 FPGA 上实现的硅 IPUF 上进行了测试,结果表明,许多对现有攻击具有弹性的 IPUF 无法承受我们的新攻击方法,通过重新定义 IPUF 参数空间中安全区域和不安全区域之间的边界,揭示了 IPUF 的新漏洞。
Security is of importance for communication networks, and many network nodes, like sensors and IoT devices, are resource-constrained. Physical Unclonable Functions (PUFs) leverage physical variations of the integrated circuits to produce responses unique to individual circuits and have the potential for delivering security for low-cost networks. But before a PUF can be adopted for security applications, all security vulnerabilities must be discovered. Recently, a new PUF known as Interpose PUF (IPUF) was proposed, which was tested to be secure against reliability-based modeling attacks and machine learning attacks when the attacked IPUF is of small size. A recent study showed IPUFs succumbed to a divide-and-conquer attack, and the attack method requires the position of the interpose bit known to the attacker, a condition that can be easily obfuscated by using a random interpose position. Thus, large IPUFs may still remain secure against all known modeling attacks if the interpose position is unknown to attackers. In this paper, we present a new modeling attack method of IPUFs using multilayer neural networks, and the attack method requires no knowledge of the interpose position. Our attack was tested on simulated IPUFs and silicon IPUFs implemented on FPGAs, and the results showed that many IPUFs which were resilient against existing attacks cannot withstand our new attack method, revealing a new vulnerability of IPUFs by re-defining the boundary between secure and insecure regions in the IPUF parameter space.