arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.21643cs.CR

信任的跨层根源:整合生物特征、PUF与硬件混淆

Cross-Layer Roots of Trust: Integrating Biometrics, PUFs, and Hardware Obfuscation

Nima Karimian

首次发表
浏览论文内容

中文总结 AI 辅助

本综述整合生物特征、PUF与硬件混淆三类信任原语,构建人类-设备-功能统一信任视角,分析其安全问题并提出组合架构与研究议程,为跨层信任研究提供框架。

中文摘要 AI 辅助

现代网络物理系统、物联网(IoT)、可穿戴设备及边缘系统日益需要对三类不同实体建立信任:请求访问的人、执行计算的物理设备、被允许运行的硬件功能。这些需求通常被不同领域分别研究。生物特征可建立人类身份,但易受呈现攻击、用户内变异、模板泄露及可撤销性有限等问题影响;物理不可克隆函数(PUF)能提供设备特定物理身份与按需密钥派生,但需应对环境不稳定性、辅助数据暴露、侧信道及建模攻击;硬件混淆与逻辑锁定使电路正确行为依赖激活密钥,但面临基于预言机的、近似的、结构的、移除的及物理攻击。本综述构建了人类-设备-功能的统一信任视角:首先将每个原语分解为完整处理链,识别对应安全假设、实现机制与评估指标;随后形式化生物特征-PUF、PUF-硬件混淆、生物特征-硬件混淆的成对组合,以及将正确功能绑定到授权用户与真实设备的三方架构。重点关注生物特征密钥重构、PUF稳定与抗建模、逻辑锁定攻击评估、跨层错误传播、注册信任、密钥生命周期及接口泄露。综述最后给出可撤销人类-设备凭证、组合安全、感知泄露的整合、可重配置激活及标准化端到端评估的分类与研究议程。

英文摘要

Modern cyber--physical, Internet-of-Things (IoT), wearable, and edge systems increasingly require trust in three distinct entities: the human requesting access, the physical device executing the computation, and the hardware function that is permitted to operate. These requirements are usually studied in separate communities. Biometrics establish human identity but remain vulnerable to presentation attacks, intra-user variability, template leakage, and limited revocability. Physical unclonable functions (PUFs) provide device-specific physical identity and on-demand secret derivation, yet must address environmental instability, helper-data exposure, side channels, and modeling attacks. Hardware obfuscation and logic locking condition correct circuit behavior on an activation secret, but face oracle-guided, approximate, structural, removal, and physical attacks. This survey develops a unified human--device--function view of trust. We first decompose each primitive into its complete processing chain and identify the corresponding security assumptions, implementation mechanisms, and evaluation metrics. We then formalize pairwise compositions---biometric--PUF, PUF--obfuscation, and biometric--obfuscation---and a three-way architecture in which correct functionality is bound jointly to an authorized user and a genuine device. Particular attention is given to biometric key reconstruction, PUF stabilization and modeling resistance, logic-locking attack evaluation, cross-layer error propagation, enrollment trust, key lifecycle, and interface leakage. The survey concludes with a taxonomy and research agenda for revocable human--device credentials, compositional security, leakage-aware integration, reconfigurable activation, and standardized end-to-end evaluation.

↑