PUF Modeling Attacks on Simulated and Silicon Data

PUF Modeling Attacks on Simulated and Silicon Data
复制标题

DOI:
10.1109/tifs.2013.2279798
复制
发表时间:
2013-11-01
影响因子:
6.8
通讯作者:
Devadas, Srinivas
Devadas, Srinivas
中科院分区:
计算机科学1区
文献类型:
--
作者:
Ruehrmair, Ulrich;Soelter, Jan;Devadas, Srinivas

文献摘要

被引文献

相似文献

我们讨论了几个建议的强物理不可克隆功能(PUF)的数值建模攻击。给定一组强PUF的挑战-响应对(CRP),我们攻击的目标是构建一个计算机算法,该算法在几乎所有CRP上的行为都与原始PUF不可分割。如果成功,该算法随后可以模拟强PUF,并且可以任意克隆和分发。它打破了任何依赖于Strong PUF的不可预测性和物理不可克隆性的应用程序的安全性。我们的方法与其他PUF类型(如弱PUF)的相关性较低。我们可以成功攻击的强PUF包括基本上任意大小的标准Arbiter PUF,以及XOR Arbiter PUF,轻量级安全PUF和前馈Arbiter PUF(达到特定大小和复杂度)。我们还研究了在典型的强PUF应用中某些环形振荡器PUF架构的硬度。我们的攻击基于各种机器学习技术,包括一种专门定制的逻辑回归和进化策略变体。我们的研究结果主要是从数值模拟中获得的CRP,使用各自的PUF建立的数字模型。对于所考虑的PUF的子集-即标准仲裁器PUF和XOR仲裁器PUF-我们还对FPGA和ASIC的硅数据进行了概念验证。在这个过程中使用了超过400万个硅CRP。硅CRPs的性能非常接近模拟CRPs,证实了这项工作的早期版本的猜想。我们的研究结果为安全的电气强PUF提出了新的设计要求,对PUF设计者和攻击者都很有用。
We discuss numerical modeling attacks on several proposed strong physical unclonable functions (PUFs). Given a set of challenge-response pairs (CRPs) of a Strong PUF, the goal of our attacks is to construct a computer algorithm which behaves indistinguishably from the original PUF on almost all CRPs. If successful, this algorithm can subsequently impersonate the Strong PUF, and can be cloned and distributed arbitrarily. It breaks the security of any applications that rest on the Strong PUF's unpredictability and physical unclonability. Our method is less relevant for other PUF types such as Weak PUFs. The Strong PUFs that we could attack successfully include standard Arbiter PUFs of essentially arbitrary sizes, and XOR Arbiter PUFs, Lightweight Secure PUFs, and Feed-Forward Arbiter PUFs up to certain sizes and complexities. We also investigate the hardness of certain Ring Oscillator PUF architectures in typical Strong PUF applications. Our attacks are based upon various machine learning techniques, including a specially tailored variant of logistic regression and evolution strategies. Our results are mostly obtained on CRPs from numerical simulations that use established digital models of the respective PUFs. For a subset of the considered PUFs-namely standard Arbiter PUFs and XOR Arbiter PUFs-we also lead proofs of concept on silicon data from both FPGAs and ASICs. Over four million silicon CRPs are used in this process. The performance on silicon CRPs is very close to simulated CRPs, confirming a conjecture from earlier versions of this work. Our findings lead to new design requirements for secure electrical Strong PUFs, and will be useful to PUF designers and attackers alike.