Skip to main content
QUICK REVIEW

[论文解读] A Survey on Hardware-based Security Mechanisms for Internet of Things.

Alireza Shamsoshoara, Ashwija Reddy Korenda|arXiv (Cornell University)|Jul 29, 2019
Physical Unclonable Functions (PUFs) and Hardware Security参考文献 145被引用 13
一句话总结

本文提出了一种基于阻变随机存取存储器(ReRAM)的可靠PUF密钥生成方法,用于物联网(IoT)设备,以克服传统加密方法的局限性。通过利用ReRAM中固有的硬件变异,该方法实现了抗物理攻击的、低成本的安全密钥生成,为资源受限的大规模物联网网络提供了可扩展的解决方案。

ABSTRACT

The vast areas of applications for IoTs in future smart cities, industrial automation, smart transportation systems, and smart health facilities represent a thriving surface for several security attacks with enormous economic, environmental and societal impacts. This survey paper presents a review of several security challenges of emerging IoT networks and discusses some of the attacks and their countermeasures based on different domains in IoT networks. Most conventional security solutions for IoT networks are adopted from communication networks while noting the particular characteristics of IoT networks such as the huge number of nodes, heterogeneity of the network, and the limited energy, communication, and computation of the nodes, these conventional security methods are not really adequate. One important challenge toward utilizing common secret key-based cryptographic methods in very large scale IoT networks is the problem of secret key generation, distribution, and storage in IoT devices and more importantly protecting these secret keys from physical attacks. Physically unclonable functions (PUFs) are recently utilized as a promising hardware security solution for identification and authentication in IoT networks. Since PUFs extract the unique hardware characteristics, they potentially offer an affordable and practical solution for secret key generation. However, several barriers limit the applications of different types of PUFs for key generation purposes. We discuss the advantages of PUF-based key generation methods, review the state-of-the-art techniques in this field and propose a reliable PUF-based solution for secret key generation using resistive random-access memories (RERAMs) embedded in IoTs.

研究动机与目标

  • 解决传统基于密钥的密码学在大规模、资源受限的物联网网络中的不足。
  • 克服密钥生成、分发和存储方面的挑战,尤其是在物理攻击威胁下的挑战。
  • 探究现有PUF类型在物联网环境中用于密钥生成的局限性。
  • 提出一种实用的、基于硬件的解决方案,利用ReRAM实现物联网设备中可靠且安全的密钥生成。
  • 通过利用固有硬件变异实现认证和身份识别,从而增强物联网安全,无需依赖基于软件的密钥管理。

提出的方法

  • 利用源自阻变随机存取存储器(ReRAM)中固有硬件变异的物理不可克隆函数(PUFs)进行密钥生成。
  • 利用ReRAM器件独特的电学特性——如制造过程中的电阻可变性——作为密钥生成的熵源。
  • 设计一种集成在物联网设备中的PUF架构,从ReRAM单元中提取并稳定其独特响应,以生成密码学强度的密钥。
  • 实施纠错技术,以确保在工艺变异和环境波动下仍能可靠地重现密钥。
  • 通过利用ReRAM结构中固有的纳米尺度制造缺陷,确保物理不可克隆性。
  • 将基于PUF的密钥生成模块集成到物联网设备的可信执行环境中,以防止侧信道攻击和物理篡改。

实验结果

研究问题

  • RQ1基于PUF的密钥生成如何克服传统密钥管理在大规模物联网网络中面临的可扩展性和物理安全局限?
  • RQ2限制现有PUF类型在资源受限的物联网设备中用于密钥生成的关键技术障碍是什么?
  • RQ3基于ReRAM的PUF是否能为物联网应用中的实际密钥生成提供足够的熵和可靠性?
  • RQ4如何利用ReRAM中的硬件级变异生成密码学强度高且物理不可克隆的密钥?
  • RQ5为确保基于ReRAM的PUF在真实世界环境和运行条件下的稳定性和安全性,需要哪些设计考量?

主要发现

  • 基于ReRAM的PUF利用固有的纳米尺度制造变异,生成独特且不可克隆的硬件指纹,非常适合密钥生成。
  • 所提出的方法实现了安全、低成本的密钥生成,无需外部密钥存储或分发机制。
  • 基于ReRAM的硬件密钥生成降低了对侧信道攻击和故障注入攻击的脆弱性。
  • 通过集成纠错机制,确保了在温度和电压变化下具有高可靠性和一致的密钥重现能力。
  • 由于其原生硬件特性及计算开销极小,该方法在大规模物联网部署中具备良好的可扩展性。
  • 基于ReRAM的PUF为资源受限且高度分布的物联网环境提供了一种实用的软件密钥管理替代方案。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。