论文标题

PUF-RLA:一种基于PUF的可靠且轻巧的身份验证协议,采用二进制字符串改组

PUF-RLA: A PUF-based Reliable and Lightweight Authentication Protocol employing Binary String Shuffling

论文作者

Qureshi, Mahmood Azhar, Munir, Arslan

论文摘要

物理上无统治的功能(PUF)可用于设备识别,身份验证,秘密密钥存储和其他安全任务。但是,如果许多PUF的挑战 - 响应对(CRP)暴露于对手,则PUF容易对攻击进行建模。此外,许多需要身份验证的嵌入式设备具有严格的资源约束,因此需要轻巧的身份验证机制。我们提出了PUF-RLA,这是一种采用二进制弦乐调整的基于PUF的轻巧,高度可靠的身份验证方案。提出的方案提高了PUF的可靠性,并通过在不损害安全性的情况下在服务器中使用误差校正而不是设备来减轻资源约束。拟议的PUF-RLA对蛮力,重播和建模攻击非常强大。在PUF-RLA中,我们在设备内部引入了廉价但安全的流身份验证方案,该方案在可以调用基础PUF之前对服务器进行身份验证。这样可以防止对手蛮力迫使设备的PUF从未经授权的模型生成中锁定设备基本上锁定了CRP。此外,我们还引入了涉及XOR和洗牌操作的轻质CRP混淆机制。结果和安全分析验证了PUF-RLA是否可以防止蛮力,重播和建模攻击,并提供约99%的可靠身份验证。此外,与最近提出的方法相比,在FPGA中,PUF-RLA分别为查找表(LUTS)和寄存器计数分别减少了63%和74%,同时提供了其他身份验证优势。

Physically unclonable functions (PUFs) can be employed for device identification, authentication, secret key storage, and other security tasks. However, PUFs are susceptible to modeling attacks if a number of PUFs' challenge-response pairs (CRPs) are exposed to the adversary. Furthermore, many of the embedded devices requiring authentication have stringent resource constraints and thus require a lightweight authentication mechanism. We propose PUF-RLA, a PUF-based lightweight, highly reliable authentication scheme employing binary string shuffling. The proposed scheme enhances the reliability of PUF as well as alleviates the resource constraints by employing error correction in the server instead of the device without compromising the security. The proposed PUF-RLA is robust against brute force, replay, and modeling attacks. In PUF-RLA, we introduce an inexpensive yet secure stream authentication scheme inside the device which authenticates the server before the underlying PUF can be invoked. This prevents an adversary from brute forcing the device's PUF to acquire CRPs essentially locking out the device from unauthorized model generation. Additionally, we also introduce a lightweight CRP obfuscation mechanism involving XOR and shuffle operations. Results and security analysis verify that the PUF-RLA is secure against brute force, replay, and modeling attacks, and provides ~99% reliable authentication. In addition, PUF-RLA provides a reduction of 63% and 74% for look-up tables (LUTs) and register count, respectively, in FPGA compared to a recently proposed approach while providing additional authentication advantages.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源