[论文解读] Towards Implementation of Robust and Low-Cost Security Primitives for Resource-Constrained IoT Devices
本文提出了一种低成本、基于硬件的硬件安全原原子——具体为基于DRAM的PUF和多种TRNG设计——利用现有DRAM和电源组件中的固有物理变异。该方法无需额外电路,实现高熵和符合NIST标准的随机性,并在资源受限的物联网设备中证明了可行性,平均互芯片汉明距离为0.4937,且具有强统计随机性。
In recent years, due to the trend in globalization, system integrators have had to deal with integrated circuit (IC)/intellectual property (IP) counterfeiting more than ever. These counterfeit hardware issues counterfeit hardware that have driven the need for more secure chip authentication. High entropy random numbers from physical sources are a critical component in authentication and encryption processes within secure systems [6]. Secure encryption is dependent on sources of truly random numbers for generating keys, and there is a need for an on chip random number generator to achieve adequate security. Furthermore, the Internet of Things (IoT) adopts a large number of these hardware-based security and prevention solutions in order to securely exchange data in resource efficient manner. In this work, we have developed several methodologies of hardware-based random functions in order to address the issues and enhance the security and trust of ICs: a novel DRAM-based intrinsic Physical Unclonable Function (PUF) [13] for system level security and authentication along with analysis of the impact of various environmental conditions, particularly silicon aging; a DRAM remanence based True Random Number Generation (TRNG) to produce random sequences with a very low overhead; a DRAM TRNG model using its startup value behavior for creating random bit streams; an efficient power supply noise based TRNG model for generating an infinite number of random bits which has been evaluated as a cost effective technique; architectures and hardware security solutions for the Internet of Things (IoT) environment. Since IoT devices are heavily resource constrained, our proposed designs can alleviate the concerns of establishing trustworthy and security in an efficient and low-cost manner.
研究动机与目标
- 应对全球化电子供应链中日益严峻的集成电路与IP仿制威胁。
- 克服传统加密方法在资源受限的物联网设备中的局限性,这些方法速度慢、成本高,且易受侧信道攻击。
- 开发低成本、高效且鲁棒的硬件安全原原子——特别是PUF与TRNG——专为面积和功耗开销极小的嵌入式系统设计。
- 利用现有组件中的固有物理随机性,实现物联网与信息物理系统(CPS)中的可信认证与密钥生成。
- 通过最小化硬件修改与成本,确保安全原原子在真实物联网环境中的实际部署。
提出的方法
- 提出一种基于DRAM的固有PUF,利用DRAM电容在上电时的随机初始化值,无需定制模数转换电路。
- 开发一种基于DRAM残留保持特性的TRNG,利用断电后残留数据保持特性,从现有DRAM组件生成不可预测的比特流。
- 提出一种基于启动值的DRAM TRNG模型,从DRAM上电过程中的随机行为中提取随机比特序列。
- 设计一种基于电源噪声的TRNG,利用电源中固有的电压波动,并通过动态电压反馈调谐(DVFT)提升稳定性与自校准能力。
- 采用NIST统计测试套件验证所有提出的TRNG设计的随机性与不可预测性。
- 应用注册算法以提升不同DRAM芯片在不同环境条件下PUF响应的可靠性和唯一性。
实验结果
研究问题
- RQ1是否可以可靠地利用DRAM在上电时的固有物理随机性,在无需额外电路的情况下生成硬件PUF?
- RQ2DRAM残留保持特性在多大程度上能够以低成本方式生成密码学强度的、不可预测的随机比特流?
- RQ3能否将电源噪声作为嵌入式系统中的真正随机源?其非平稳行为如何稳定以实现一致输出?
- RQ4温度和硅老化等环境因素如何影响基于DRAM的PUF与TRNG的可靠性与唯一性?
- RQ5这些硬件原原子是否能以极小的面积与功耗开销实现,以满足真实物联网与CPS设备的约束条件?
主要发现
- 所提出的DRAM PUF实现了0.4937的高平均互芯片汉明距离,表明在不同芯片间具有强唯一性与不可克隆性。
- 基于DRAM残留保持特性的TRNG生成了符合NIST标准的随机比特流,具有强统计不可预测性与不可重复性,验证了其密码学适用性。
- 经动态电压反馈调谐(DVFT)增强的电源噪声基TRNG模型展现出鲁棒性与实时部署的可行性,且硬件成本极低。
- 所有提出的TRNG均通过NIST统计测试套件,证实其具有高熵与无偏输出质量。
- 注册算法显著提升了不同工作条件下PUF的可靠性,实现了在真实DRAM硬件中稳定且可重复的识别。
- 整个安全原原子套件可使用物联网设备中现有组件实现,无需额外电路,从而实现低成本、轻量化且高效的硬件安全。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。