Reliable, Secure, and Efficient Hardware Implementation of Password Manager System Using SRAM PUF

Reliable, Secure, and Efficient Hardware Implementation of Password Manager System Using SRAM PUF
复制标题

DOI:
10.1109/access.2021.3129499
复制
发表时间:
2021-01-01
期刊:
影响因子:
3.9
通讯作者:
Burke, Ian
Burke, Ian
中科院分区:
计算机科学3区
文献类型:
--
作者:
Mohammadinodoushan, Mohammad;Cambou, Bertrand;Burke, Ian

文献摘要

被引文献

相似文献

最近有人提出在服务器端使用物理不可克隆功能(puf)来解决密码(PW)身份验证机制的安全漏洞,包括对用户凭证数据库(DB)的攻击。使用可用的内存技术和受限的硬件模块来实践这个想法可以提供额外的硬件安全层。因此,寻找pw需要攻击者访问包含PUF的硬件和存储在DB中的信息。在以往的研究中,puf已与其他加密算法一起使用,以进一步提高系统的安全性。然而,这些研究忽略了在受限硬件设备下实现这些算法的挑战。因此,在实现的安全性和期望的效率之间进行权衡仍然是一个挑战。所提出的基于puf的硬件-软件解决方案可以在服务器端硬件中实现更快的计算。此外,客户端协议可以应对基本应用程序(包括受限物联网)中存在的资源限制。此外,该方案处理了静态随机存取存储器(SRAM) PUF的不稳定性和位别名。本文的可靠、低成本和高效的原型展示了依赖于硬件的协议的功能,该协议可以抵抗内部人员、PW猜测和中间人攻击。所提供的硬件软件可以很容易地与服务器端集成。对嵌入式SRAM的统计测试表明,该协议改善了存储在数据库中的PUF熵响应。此外,本工作的实验结果表明,在不使用任何额外硬件开销的情况下,可以获得具有非常低的puf内变化的SRAM。
Using Physical Unclonable Functions (PUFs) within the server-side has been recently proposed to address security vulnerabilities of the password (PW) authentication mechanism, including attacks on the database (DB) of user credentials. Practicing this idea using available memory technologies and constrained hardware modules may offer an additional hardware security layer. Thus, finding the PWs would require the attacker to access both the hardware containing the PUF and the information stored in the DB. PUFs have been used with other cryptographic algorithms in previous studies to improve the system's security further. However, these studies have overlooked the challenges of implementing these algorithms with constrained hardware devices. Therefore, the trade-off between the achieved security and desired efficiency is still a challenge. The presented hardware-software PUF-based solutions lead to faster computation in the server-side hardware. Also, the client-side protocol can cope with the resource limitations existing in essential applications, including constrained IoTs. Moreover, the scheme handles the instability and bit alias of the Static Random-Access Memory (SRAM) PUF. This paper's reliable, low-cost, and efficient prototype shows the functionality of a hardware-dependent protocol that is resistant to insider, PW guessing, and man-in-the-middle attacks. The presented hardware-software can be easily integrated with the server-side. Statistical tests on the embedded SRAM show that this paper protocol improves PUF entropy responses stored in the DB. Besides, the experimental results of this work show the possibility of obtaining an SRAM with very low intra-PUF variation without using any extra hardware overhead.