TroPUF:评估基于延迟的物理不可克隆函数中的硬件木马插入
TroPUF: Evaluating Hardware Trojan Insertion in Delay-Based Physical Unclonable Functions
AI总结:
研究基于延迟的物理不可克隆函数中硬件木马插入问题,提出统一模拟框架并行评估功能指标、硬件开销和建模抗性,揭示当前PUF安全假设差距,强调需将PUF与硬件木马作为耦合安全问题评估。
AI中文摘要:
基于延迟的物理不可克隆函数(PUF)常用于设备认证和密钥生成,因其依赖制造引起的延迟变化。但这些变化使PUF本质上具有不确定性,恶意逻辑可能混入正常电路行为。本文提出一个统一模拟框架,用于评估跨多种基于延迟的PUF架构和木马类型的隐秘硬件木马插入。并行评估功能指标、硬件开销和对机器学习建模的抗性。结果表明,休眠木马保留预期PUF行为、结构特征和建模抗性,可检测的退化仅在激活后出现,这揭示了当前PUF安全假设的差距,强调需将PUF和硬件木马作为耦合安全问题评估。
英文摘要:
Delay-based Physical Unclonable Functions (PUFs) are commonly used for device authentication and key generation due to the fact that they rely on manufacturing induced delay variations. However, these same variations make PUFs inherently non-deterministic, which can allow malicious logic to blend in with normal circuit behavior. As a result, the act of embedding hardware Trojans directly inside the PUF primitive presents a unique security risk that is not yet well understood. This work presents a unified simulation framework for evaluating stealthy hardware Trojan insertion across multiple delay-based PUF architectures and Trojan types. Functional metrics, hardware overhead, and resistance to machine learning modeling are assessed in parallel. Results show that dormant Trojans preserve expected PUF behavior, structural characteristics, and modeling resistance. Detectable degradation appears only after activation, indicating that conventional validation techniques fail to identify embedded Trojans prior to payload execution. These findings expose a gap in current PUF security assumptions, and highlight the need to evaluate PUFs and hardware Trojans as a coupled security problem.