A New PUF Based Lock and Key Solution for Secure In-Field Testing of Cryptographic Chips

A New PUF Based Lock and Key Solution for Secure In-Field Testing of Cryptographic Chips
复制标题

DOI:
10.1109/tetc.2019.2903387
复制
发表时间:
2019-03
影响因子:
5.9
通讯作者:
Aijiao Cui;Chip-Hong Chang;Wei Zhou;Yue Zheng
Aijiao Cui;Chip-Hong Chang;Wei Zhou;Yue Zheng
中科院分区:
计算机科学2区
文献类型:
--
作者:
Aijiao Cui;Chip-Hong Chang;Wei Zhou;Yue Zheng

文献摘要

被引文献

相似文献

基于扫描的旁道攻击已经成为密码芯片的新威胁。现有的对策需要一个秘密的测试密钥来解锁扫描链之前,现场测试是允许的。然而,测试密钥泄露给共享公共测试密钥的多个加密芯片带来了巨大的风险。我们解决这个开放的问题,利用物理不可克隆功能(PUF)的现场测试,使每个芯片的测试密钥唯一的派生。PUF的响应仅被调用一次,并硬化为一次性可编程焊盘。设计者导出每个密码芯片的测试密钥所需的PUF响应只能在锁定扫描链时恢复,而不能直接将其阅读。制造商可以在锁定通过的芯片之前正常地测试芯片,而没有测试时间损失。所提出的解决方案被分析为对所有已知的基于扫描的侧信道攻击是安全的,并且增加的安全性所引起的开销小得可以忽略不计。
Scan-based side-channel attacks have become a new threat to cryptographic chips. Existing countermeasures require a secret test key to unlock the scan chain before in-field testing is allowed. However, test key disclosure poses tremendous risks to multiple crypto chips that share a common test key. We address this open problem of in-field testing by leveraging physical unclonable function (PUF) to make the derived test key unique to each chip. The PUF's response is invoked only once and hardened into a one-time programmable pad. The PUF response required by the designer to derive a test key of each crypto chip can only be recovered at the time of locking the scan chains without directly reading it out. The manufacturer can test the chip normally with no test time penalty before the passed chips are locked. The proposed solution is analyzed to be secure against all known scan-based side-channel attacks and the overhead incurred for the added security is negligibly small.