PUF (Physical Unclonable Function) structure based on delay difference quantization and identity verification method
By extracting and quantifying the delay path difference in the APUF structure and converting it into a nonlinear entropy source, the problem of linear accumulated integral characteristics in the traditional APUF structure is solved, which significantly improves the resistance to model attacks and ensures the security of identity authentication.
Patent Information
- Application Number
- CN202510266176.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-07
AI Technical Summary
The linear accumulated integral feature exists in traditional APUF and its variant structures, which makes it easy to be predicted when facing attacks, threatening the security of the identity authentication protocol.
By extracting and quantifying the delay path difference, the challenge is transformed into a nonlinear entropy source, reducing the linear mapping relationship between the challenge and the response. The specific implementation includes adding multiple configurable delay units on two symmetric paths of APUF, quantizing using a multi-layer differential tap circuit TDC, and outputting the final response through the LFSR obfuscation structure.
It significantly reduces the ability of attackers to predict CRPs, improves the PUF's resistance to model attacks in the identity authentication protocol, and ensures the security and reliability of identity authentication.
Smart Images

Figure CN120223084A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of identity authentication, and more specifically, the present invention relates to a PUF structure and an identity authentication method based on delay difference quantization. Background Art
[0002] At present, the innovation of emerging technologies such as big computing power, 6G communication, and edge computing is driving the world into a new era of the Internet of Everything. The Internet of Things (IoT) is the core technology for realizing the Internet of Everything. Through communication and gateway protocols, sensitive data in various information devices are uploaded to the cloud for information exchange and communication. However, with the rapid development of the Internet of Things, the number of devices on its interconnected and controlled ends has shown an explosive growth trend, and the large amount of sensitive data carried inside it will inevitably face major information security challenges. At the same time, with the rapid innovation of technologies such as AI and large models, many more advanced attack methods have been spawned, breaking through the protection barriers of traditional security protection technologies, making the security of the Internet of Things facing severe tests in many aspects, including: device authentication, authorization, information leakage, data encryption and decryption, etc. Traditionally, conventional cryptographic primitives are generally used to provide security for keys in IoT devices, but traditional encryption strategies often use complex encryption algorithms and bring a lot of hardware resource overhead, such as: Advanced Encryption Standard (AES), Elliptic Curve Cryptography (ECC), Hash-based Message Authentication Code (HMAC), which do not meet the lightweight design requirements of IoT devices. At the same time, the keys that traditional encryption algorithms rely on are stored in digital form in the chip's non-volatile memory (NVM). Attackers can obtain the keys through physical attacks (such as side channel attacks, invasive attacks, semi-invasive attacks, etc.), thereby threatening the security of identity authentication, data encryption and decryption processes in the IoT operating system.
[0003] To solve this problem, the Physical Unclonable Function (PUF), as a new integrated circuit security design method based on hardware security primitives, has gradually become a new paradigm for security protection. It uses the random physical deviations inherent in chip manufacturing processes to form unique digital feature fingerprints, namely Challenge-Response Pairs (CRPs), which are equivalent to the unique keys of device chips, ensuring the trustworthiness, integrity, and authenticity of the system from the hardware bottom layer and providing a lightweight design solution for the security of the Internet of Things. According to the number of CRPs of PUF, PUF can be divided into weak PUF and strong PUF: (1) Weak PUF, typical structures include RO-PUF, SRAM PUF, TERO PUF, etc. Due to its limited number of CRPs, it is generally applied to key generation; (2) Strong PUF, typical structures include APUF, XOR PUF, MPUF, etc. Due to its large number of CRPs, it is generally applied to asymmetric encryption in security authentication protocols. The traditional APUF is composed of a delay model based on linear accumulation of entropy sources, resulting in significant linear correlations among a large number of CRPs of APUF. After an attacker obtains the CRPs of PUF, they can model the internal circuit of PUF through the internal correlations, thereby predicting other CRPs and threatening the security of identity authentication protocols based on APUF and its variant structures.
[0004] To eliminate the characteristics of linear cumulative integration in delay-based strong PUF, the challenge can be converted into this non-linear entropy source by extracting and quantifying the delay path difference, thus greatly reducing the linear mapping relationship between the challenge and the response. For example, a delay difference quantization PUF based on APUF is proposed. By adding multiple configurable delay units on two symmetric paths of APUF, the output responses of APUF under different delay configurations are collected, and it is pointed out that the obtained responses contain the delay difference information of the two symmetric paths of APUF, and the relationship between the quantization information and reliability is discussed. By adopting a tolerance threshold in the authentication protocol, the reliability reaches 99.95% without CRP discard rate, providing a theoretical basis for the application of PUF in the authentication protocol. However, DDQ-APUF quantifies using delay units. Since the delay amount of the delay unit is unknown, the quantified data can only represent the information containing the delay difference and does not achieve true digital code quantization of the delay difference. Summary of the Invention
[0005] The present invention provides a PUF structure and an identity authentication method based on delay difference quantization, aiming to improve the above problems.
[0006] The present invention is implemented as follows. A PUF structure based on delay difference quantization, the PUF structure includes:
[0007] The PUF circuit includes two delay circuits connected in parallel, and the two delay circuits respectively output delay signals;
[0008] A multi-layer differential tap circuit TDC, and a decoder connected to each layer of the differential tap circuit TDC; a delay data quantization unit connected to the multi-layer decoder, and an LFSR scrambling structure connected to the delay data quantization unit;
[0009] The two delay circuits are connected to the differential tap circuit TDC through a signal selection structure. The signal selection structure inputs the delay signals of the first response and the second response in the two delay circuits to the start end and the stop end of each layer of the differential tap circuit TDC respectively. It is required that the delay time of the start end is higher than that of the stop end. The decoder determines the delay time of the two delay circuits at the corresponding delay resolution based on the output signal of the corresponding differential tap circuit TDC. The delay data quantization unit takes the average value of the delay times at different delay resolutions as the final delay data, and outputs the final response R after scrambling the final delay data through the LFSR scrambling structure.
[0010] Furthermore, the delay circuit is formed by connecting multiple stages of delay units in series. Each stage of the delay unit includes: a fourth-order MUX, and a fourth-order DEMUX connected to the output end of the MUX. The two output ends of the DEMUX are connected to the first exclusive-OR gate, and the other two output ends are connected to the second exclusive-OR gate. The first exclusive-OR gate and the second exclusive-OR gate are connected to the third exclusive-OR gate, and the output of the third exclusive-OR gate is connected to the fourth-order MUX of the next stage of each delay unit.
[0011] Furthermore, the challenge signal C is segmented to obtain the first challenge signal C1 and the second challenge signal C2 of the same length. The 4nth to 4(n + 1)th bits of the first challenge signal C1 are sequentially configured to the two selection ends of the MUX and the DEMUX in the (n + 1)th stage delay unit. The MUX selects one of the four input signals to output based on the two control signals. The DEMUX selects one of the four outputs to output based on the two control signals. The 4nth to (4n + 2)th bits of the second challenge signal C2 are all configured to the two irrelevant bit ends of the first exclusive-OR gate and the second exclusive-OR gate in the (n + 1)th stage delay unit, and the (4n + 2)th to 4(n + 1)th bits are all configured to the two irrelevant bit ends of the third exclusive-OR gate in the (n + 1)th stage delay unit. The first exclusive-OR gate, the second exclusive-OR gate, and the third exclusive-OR gate determine the delay duration applied to the corresponding exclusive-OR gate based on the two control signals.
[0012] Further, the signal selection circuit consists of two buffers and two second-order MUXes. The signals Start and Stop output from the two delay paths are respectively input into the two buffers through the input of the signal selection circuit. The two buffers respectively output the corresponding signals to the input ends of the two second-order MUXes. At the same time, the response signal R is configured to the selection ends of the two second-order MUXes. When the signal Up is output before the signal Down, in response to S = 1, the signal Up is used as the signal Start and the signal Down is used as the signal Stop through the second-order MUX; when the signal Down is output before the signal Up, in response to S = 0, the signal Down is used as the signal Start and the signal Up is used as the signal Stop through the second-order MUX.
[0013] Further, each layer of the differential tap circuit TDC consists of m levels. Each level of the delay element includes two IDELAYE2s with different delay times t1 and t2, and an arbiter connecting the two IDELAYE2s. The signals Start and Stop are respectively input into the IDELAYE2 with the delay time t1 and the IDELAYE2 with the delay time t2 in the first-level delay element. The delay time t1 is greater than the delay time t2.
[0014] Further, the arbiter in the i-level delay element consists of a fourth-order MUX and a second-order MUX. The time delays T i and D i output from the IDELAYE2s with the delay times t1 and t2 in the i-level delay element are input into the two selection ends of the corresponding fourth-order MUX. The fourth-order MUX selects one input for output based on the input signals at the selection ends. The output end is connected to the input end of the second-order MUX. The other input end is connected to the corresponding input end of the fourth-order MUX. The output end outputs the i-th bit of the signal signal. The selection end of the second-order MUX is connected to the enable end.
[0015] Further, the decoder connected to the T of the j-th layer of the differential tap circuit TDC calculates the time delay T j between the two delay paths measured by the j-th layer of the differential tap circuit TDC. The specific calculation formula is as follows:
[0016] T j = N j × (t 1j - t 2j );
[0017] Where, N j is the number of high levels in the output signal signal of the j-th layer of the differential tap circuit TDC, and t 1j , t 2j are the delay times of the delay elements in the j-th layer of the differential tap circuit TDC.
[0018] Further, the reference clock frequency f of each layer of the differential tapped - type circuit TDC is the same, and the reference clock frequencies f between different layers of the differential tapped - type circuit TDC are different. The generated delay signals under the same challenge signal are sent to the differential tapped - type circuit TDC decoding with different delay - line resolutions for quantization of the delay time. The delay data quantization unit takes the average value of all the quantized delay times as the final delay time between the two delay circuits.
[0019] The present invention is implemented as follows. An identity authentication method based on the above - mentioned PUF structure based on delay - difference quantization is as follows:
[0020] (21) The device - side generates a random number N1 for the encryption key, and encrypts the ID i of the device - side i and the random number N1 based on the symmetric key k and sends the encrypted
[0021] to the server - side; When the server receives the i sent by the device - side, it decrypts it using the symmetric key k i to extract the initial information ID and N1 of the device - side, and verifies them through the device information stored on the device - side. If the verification is successful, it extracts the locally - stored challenge C1 and response R i according to the ID i . The server - side generates a random number N2, and encrypts the challenge C1, the response R i and the random number N2 using the random number N2 and the symmetric key k i and sends the encrypted challenge response and the random number to the device - side;
[0022] (23) When the device - side receives the encrypted challenge response and the random number , it calculates and decrypts to extract the random number N2, decrypts using the obtained random number N2 to obtain the challenge C1 and the response R i , verifies whether the challenge C1 is the C1 stored on the device - side. If the verification fails, it takes the previous - round challenge C1 stored locally as the current - round challenge C1. If the verification passes, the device - side uses the built - in PUF structure described above to generate a response R′ i = PUF(C1||C2), and detects whether the Hamming distance between the response R i and the response R′ i is within the Hamming distance threshold Th If it is within the Hamming distance threshold T h inside, the device generates another random number N3 and recalculates the challenge of the front segment of the PUF to reconstruct the response R of the PUF structure i+1 , R i+1 = PUF(C′1||C2). Encrypt the reconstructed response R i+1 using the random number N3, calculate the message authentication code, then encrypt the reconstructed challenge C′1, and send the parameters C′1 * , M, and to the server;
[0023] (24) When the server receives the parameters C′1 * , M, and after that, decrypt the random number N3, the response R i+1 , the challenge C′1 in sequence, and check the integrity of the message by verifying the MAC. If the MAC verification is successful, update and re-store the response R i+1 and the challenge C′1.
[0024] (25) After the authentication is passed, the device updates the previously stored challenge C1 locally to the currently reconstructed challenge C′1, C1←C′1. At the same time, the server updates the previously stored challenge C1 locally to the currently reconstructed challenge C′1, the challenge C1←C′1, and updates the previously stored response R i to the currently reconstructed response R i+1 , the response R i ←R i+1 .
[0025] Furthermore, the determination method of the Hamming distance threshold T h is specifically as follows:
[0026] (1) Build multiple of the PUF structure models and enumerate multiple challenge signals;
[0027] (2) Under normal temperature and pressure, input the m-th challenge into the n-th PUF structure model, and the PUF structure model outputs the corresponding time delay difference B mn , the time delay difference B mn is output as the response R through the LFSR confusion structure mn ;
[0028] (3) Traverse all the challenges and all the PUF structure models;
[0029] (4) Change the environmental temperature and / or the voltage of the PUF structure model for the t-th time, where t ranges from 1 to c. Input the m-th challenge into the n-th PUF structure model, and the PUF structure model outputs the corresponding delay difference B'. mn , the delay difference B' mn is output as the response R' through the LFSR confusion structure mn , calculate the response R' mn and the response R mn Calculate the Hamming distance between them, and save this Hamming distance to the matrix N t ;
[0030] (5) Traverse all challenges and all PUF structure models;
[0031] (6) Take the maximum Hamming distance in the matrix as the Hamming distance threshold, where the matrix Ν = (N1,..., N t ,..., N c ).
[0032] The PUF structure based on delay difference quantization proposed by the present invention has the following beneficial technical effects:
[0033] (1) A PUF circuit based on DEMUX multi-path configuration and dynamic delay difference is proposed to achieve the design goals of low resources and high non-linearity. Use MUX and DEMUX in cascade to form the front end of the PUF unit, and use three XOR gates with don't care bits to form an XOR gate tree to form the back end of the PUF unit. Cascade the front end and the back end to form a delay unit. The multi-path selection configuration in the front section of the delay unit improves the non-linearity degree, and the back section uses the don't care bits of the XOR gate to dynamically adjust the delay amount, thereby dynamically changing the delay difference between the two symmetric paths;
[0034] (2) Adopt a multi-layer differential tap TDC circuit architecture to change the response mechanism of the PUF, and overall improve the anti-model attack ability of the entropy source linear accumulation type APUF and its variant structures. Input the signals of the two symmetric paths of the PUF into the architecture of the multi-layer TDC quantization circuit respectively to realize the quantization of the delay difference digital code. The quantized data directly represents the information of the delay difference between the two symmetric paths of the PUF, so that the response of the PUF to the challenge input contains more unique and dynamic information, and this architecture can be applied to any delay type PUF to improve their anti-model attack ability. Description of the Drawings
[0035] Figure 1 is a schematic structural diagram of the PUF circuit provided by the embodiment of the present invention;
[0036] Figure 2 is a schematic structural diagram of the signal selection structure provided by the embodiment of the present invention;
[0037] Figure 3 It is a schematic structural diagram among the differential tap circuit TDC, decoder and delay data quantization unit provided by an embodiment of the present invention;
[0038] Figure 4 It is a schematic diagram of the LFSR confusion structure provided by an embodiment of the present invention;
[0039] Figure 5 It is a schematic structural diagram of the differential tap circuit TDC provided by an embodiment of the present invention;
[0040] Figure 6 It is a schematic structural diagram of the arbiter provided by an embodiment of the present invention;
[0041] Figure 7 It is a data interaction diagram in the registration stage provided by an embodiment of the present invention;
[0042] Figure 8 It is a data interaction diagram in the identity authentication stage provided by an embodiment of the present invention;
[0043] Figure 9 It is the experimental result of the PUF circuit provided by an embodiment of the present invention to resist different model attacks. Among them, (a) is to resist the CMA-ES model attack; (b) is to resist the LR model attack; (c) is to resist the ANN model attack; (d) is to resist the DNN model attack; (e) is to resist the CNN model attack; (f) is to resist the SVM model attack. Specific embodiments
[0044] Next, with reference to the accompanying drawings, through the description of the embodiments, the specific embodiments of the present invention will be further described in detail to help those skilled in the art have a more complete, accurate and in-depth understanding of the inventive concept and technical solution of the present invention.
[0045] The present invention provides a new PUF response mechanism, which can comprehensively improve the anti-model attack ability of entropy source linear accumulation type APUF and its variants. Since most of the traditional APUF and its variant structures use the arbitration result of the arbiter for the signals on two symmetric paths as the response, but ignore an important entropy source, that is, the delay difference between the symmetric paths. When facing different challenge signal inputs, the delay difference between the two symmetric paths is random and reproducible. The TDC architecture can be used to replace the traditional arbiter to extract and convert the delay difference between the symmetric paths in the APUF and its variant structures and generate a response to improve the non-linearity of the PUF. Therefore, the present invention proposes a DEMUX-based APUF variant structure with low resource overhead and high non-linearity. Then, the multi-layer differential TDC circuit architecture is used to digitally code and quantify the delay difference entropy source, and the quantified data is sent to the LFSR register for scrambled output response, showing excellent anti-model attack ability. The above PUF structure based on delay difference quantization includes:
[0046] A PUF circuit, including two delay circuits connected in parallel, and the two delay circuits respectively output delay signals;
[0047] A multi-layer differential tap circuit TDC, and a decoder connected to each layer of the differential tap circuit TDC; a delay data quantization unit connected to the multi-layer decoder, and an LFSR scrambling structure connected to the delay data quantization unit;
[0048] The two delay circuits are connected to the differential tap circuit TDC through a signal selection structure. The signal selection structure inputs the delay signals of the first response and the second response in the two delay circuits to the start end and the stop end of each layer of the differential tap circuit TDC respectively. It is required that the delay time of the start end is higher than that of the stop end. The decoder determines the delay time of the two delay circuits at the corresponding delay resolution based on the output signal of the corresponding differential tap circuit TDC. The delay data quantization unit takes the average value of the delay times at different delay resolutions as the final delay data, and outputs the final response R after scrambling the final delay data through the LFSR scrambling structure. Among them, the connection relationship between the differential tap circuit TDC, the decoder and the delay data quantization unit is as Figure 3 shown.
[0049] Figure 1The following is a schematic structural diagram of the PUF circuit provided by the embodiment of the present invention. For the convenience of description, only the parts related to the embodiment of the present invention are shown. The circuit of this PUF circuit includes two delay circuits connected in parallel. The input ends of the two delay circuits are both connected to the input end of the EN signal. The two delay circuits are of a symmetric structure and are both composed of multiple-order delay units connected in series. Each order of delay unit includes: a fourth-order MUX, and a fourth-order DEMUX connected to the output end of the MUX. The two output ends of the DEMUX are connected to the first exclusive-OR gate, and the other two output ends are connected to the second exclusive-OR gate. The first exclusive-OR gate and the second exclusive-OR gate are connected to the third exclusive-OR gate. The output of the third exclusive-OR gate is connected to the fourth-order MUX of the next order of each delay unit;
[0050] The challenge signal C is segmented to obtain the first challenge signal C1 and the second challenge signal C2 of the same length. The 4nth to 4(n + 1)th bits of the first challenge signal C1 are sequentially configured to the two selection ends of the MUX and the DEMUX in the (n + 1)th order delay unit. The MUX selects one of the four input signals to output based on the two-bit control signal, and the DEMUX selects one of the four outputs to output based on the two-bit control signal; the 4nth to (4n + 2)th bits of the second challenge signal C2 are all configured to the two irrelevant bit ends of the first exclusive-OR gate and the second exclusive-OR gate in the (n + 1)th order delay unit, and the (4n + 2)th to 4(n + 1)th bits are all configured to the two irrelevant bit ends of the third exclusive-OR gate in the (n + 1)th order delay unit. The first exclusive-OR gate and the third exclusive-OR gate determine the delay time length applied to the corresponding exclusive-OR gate based on the two-bit control signal; the length of the challenge signal C is generally 64 bits or 128 bits. When the length of the challenge signal C is 64 bits, the two delay circuits are both composed of eight-order delay units. When the length of the challenge signal C is 128 bits, the two delay circuits are both composed of sixteen-order delay units. The first 32 bits of the 64-bit challenge signal C[63:0] are used as the first challenge signal C1[31:0], and the last 32 bits are used as the second challenge signal C1[63:32].
[0051] By introducing the two uncertain factors of different non-linear paths and non-linear delay times into the two symmetric delay paths through the first challenge signal C1 and the second challenge signal C2, signals Up and Down with uncertain delays are obtained at the outputs of the two delay paths.
[0052] In the embodiment of the present invention, the differential tapped circuit TDC requires that the input signals Start and Stop should satisfy that the signal Start enters the differential tapped circuit TDC before the signal Stop; due to the influence of the delay path configuration and process manufacturing factors of the PUF circuit, the order of the signals Up and Down output by the above two delay paths is random, and a signal selection circuit needs to be proposed for reconfiguration to meet the requirements of the tapped circuit TDC, so as to ensure that the tapped circuit TDC can work properly. AsFigure 2 As shown, the signal selection circuit consists of two buffers and two second-order MUXs. The signals Start and Stop output from the two delay paths are respectively input into the two buffers through the input of the signal selection circuit. The two buffers respectively output the corresponding signals to the input ends of the two second-order MUXs. At the same time, the response signal R is configured to the selection ends of the two second-order MUXs. When the signal Up is output before the signal Down, in response to S = 1, in order to meet the requirements of the input end of the differential tapped circuit TDC, the signal Up is used as the signal Start and the signal Down is used as the signal Stop through the second-order MUX; when the signal Down is output before the signal Up and in response to S = 0, to meet the requirements of the input end of the differential tapped circuit TDC, therefore, the signal Down is used as the signal Start and the signal Up is used as the signal Stop through the second-order MUX.
[0053] If the signal Up and the signal Down arrive at the second-order MUX before the response signal R, it can be observed from the post-layout timing post-simulation that the original nanosecond-level delay difference will be directly reduced to more than a dozen picoseconds, almost 0, seriously affecting the experimental results. Therefore, to ensure the accuracy of the delay difference quantified by the subsequent differential tapped circuit TDC, a buffer with high delay is connected between the input ends of the two second-order MUXs to ensure that the signals Up and Down arrive at the second-order MUX later than the response signal R. Among them, the buffer with high delay is configured by a 6-input LUT, where A1 is the input end, and (A2, A3, A4, A5, A6) = 11111, that is, the delay path of the input signal inside the LUT is the highest, achieving the design goal of low resource and high delay.
[0054] Figure 5 It is a schematic structural diagram of the differential tapped circuit TDC provided by the embodiment of the present invention. For the convenience of description, only the parts related to the embodiment of the present invention are shown. This multi-layer differential tapped circuit TDC is a three-layer differential tapped circuit TDC. Each layer of the differential tapped circuit TDC consists of m levels (m ≤ 25). Each level of the delay element includes two IDELAYE2s with different delay times t1 and t2 (delay times t1 and t2), and an arbiter connecting the two IDELAYE2s. The signals Start and Stop are respectively input into the IDELAYE2 with a delay time of t1 and the IDELAYE2 with a delay time of t2 in the first-level delay element. The delay time t1 is greater than the delay time t2;
[0055] The arbiter in the i-th level (the value of i ranges from 1 to m) of the delay element consists of a fourth-order MUX and a second-order MUX, and the time delays T i and time delays D iInput the two selection terminals of the corresponding fourth-order MUX. The fourth-order MUX selects one input for output based on the selection signal input at the selection terminals. The output terminal is connected to the terminal of the second-order MUX, and the other input terminal is connected to the corresponding input terminal of the fourth-order MUX. The output terminal outputs the i-th bit of the signal signal. The selection terminal of the second-order MUX is connected to the enable terminal, as Figure 6 shown.
[0056] In the three-layer differential tapped circuit TDC, the reference clock frequency f of each layer of the differential tapped circuit TDC is the same, and the reference clock frequencies f between different layers of the differential tapped circuit TDC are different. The delay times t1 and t2 in each layer of the differential tapped circuit TDC are obtained by adjusting the tap. The core of the multi-layer differential tapped circuit TDC is a configurable delay element, and the delay configuration is mainly achieved through IDELAYE2. The delay time t of the delay element is set by adjusting the reference clock frequency and the number of taps of IDELAYE2:
[0057]
[0058] Among them, f is the reference clock frequency (REFCLK_FREQUENCY), generally 200MHZ, 300MHZ, 400MHZ; tap is the number of taps (IDELAY_VALUE), generally 0 to 31; 600ps is the inherent delay of IDELAYE2 itself. Therefore, for a delay element at the above three different reference frequencies, the minimum delay times are 678ps, 652ps, and 639ps respectively. Due to the inherent delay of IDELAYE2 itself and the delay introduced by layout and wiring, the resolution of the differential tapped circuit TDC is low, and the quantization delay difference error is large, making it difficult to characterize good uniqueness and anti-model attack capabilities. Therefore, the present invention adopts a differential tapped TDC circuit, a differential tapped circuit TDC, to cancel the inherent delay of IDELAYE2 itself and improve the quantization resolution. At this time, the delay difference T of the delay path can be expressed as:
[0059] T = N × (t1 - t2) (2)
[0060] Among them, t1 and t1 are the delay times of the delay elements in the corresponding differential tapped circuit TDC. In addition, since the delay difference is in the nanosecond level, multiple delay units are required to improve the resolution. Therefore, multiple D flip-flops will be required in the differential tapped circuit TDC to arbitrate the delayed signals. However, D flip-flops are greatly affected by the environment and temperature, resulting in unstable quantization data of the TDC, thereby affecting the reliability of the response. Therefore, the present invention proposes an improved arbitration unit based on a look-up table, as Figure 6The arbiter in it is configured as a four-to-two multiplexer through a 6-input lookup table. According to the timing waveform under the EN enable signal, the time delay T after the delay element i and the time delay D i are used as the selection terminals of the fourth-order MUX. Their delay difference will output a high-level pulse signal. Subsequently, the number of pulse signals is recorded by triggering with a high level in the decoder. Then, according to the resolution t1 - t2 of the delay element, the delay difference entropy source is quantified
[0061] In the embodiment of the present invention, the three-layer differential tapped circuit TDC corresponds to three decoders. Each decoder calculates the corresponding time delay based on the output signal signal of the corresponding layer differential tapped circuit TDC. The time delay T j of the j-th layer (j = 1, 2, 3) differential tapped circuit TDC is specifically calculated as follows
[0062] T j = N j ×(t 1j - t 2j ) (3)
[0063] where N j is the number of high levels in the output signal signal of the j-th layer differential tapped circuit TDC, and t 1j , t 2j are the delay times of the delay elements in the j-th layer differential tapped circuit TDC
[0064] In addition, in order to avoid the phenomenon that the quantified data fluctuates due to environmental influence when quantifying data at a certain reference frequency, and at the same time to increase the non-linearity degree of the quantified data. According to the basic principle of IDELAYE2, the present invention sets up a three-layer differential tapped circuit TDC. The reference clock frequencies of each layer of the TDC differential tapped circuit TDC are 200MHZ, 300MHZ, and 400MHZ respectively, and each layer has 25 delay elements. The delay signals generated under the same challenge signal are respectively input into the differential tapped circuit TDCs with different delay element resolutions of the three layers for data quantization, and 3 m-bit Signal[m - 1:0] are output. The decoder encodes according to the resolution set for each layer of the differential tapped circuit TDC to obtain the decimal sequence OUT j = T j , and the delay data quantization unit will process the 3 OUT jAdd them up and divide by 3 to obtain the final quantized data. Although the operation of taking the average of the added delays quantized by the three-layer differential tap TDC is a linear operation, it realizes the true high-precision quantization of the symmetric path delay difference of the PUF, enabling the non-linear subtle delay difference fluctuations caused by the external challenge vector configuration and internal process effects of the entropy source to be captured by the differential tap TDCs with different precisions, thereby affecting the final output and improving the anti-attack ability and the extraction rate of the delay difference entropy source.
[0065] In the embodiment of the present invention, the LFSR scrambling structure is an 8th-order Fibonacci-type LFSR. The final quantized data OUT is divided into two parts. If OUT is 14 bits, the lowest 6 bits are decoded as the shift count of the LFSR, and the highest 8 bits are used as the initial seed of the LFSR, as Figure 4 shown. By associating the two variables, the initial seed and the shift count, that affect the LFSR output with the quantized data, and since the quantized data is derived from the symmetric path delay difference of the PUF, the non-linear entropy source in the original PUF presents a highly non-linear relationship between the challenge and the response under the unpredictable state transitions of the LFSR, improving the anti-model attack ability of the final response.
[0066] The PUF structure based on delay difference quantization proposed by the present invention has the following beneficial technical effects:
[0067] (1) A PUF circuit based on DEMUX multi-path configuration and dynamic delay difference is proposed to achieve the design goals of low resources and high non-linearity. The front end of the PUF unit is formed by cascading MUX and DEMUX, and the back end of the PUF unit is composed of an XOR gate tree formed by three XOR gates with don't care bits. The front end and the back end are cascaded to form a delay unit. The multi-path selection configuration in the front section of the delay unit improves the non-linearity degree, and the don't care bits of the XOR gate in the back section are used to dynamically adjust the delay amount, thereby dynamically changing the delay difference between the two symmetric paths;
[0068] (2) The multi-layer differential tap TDC circuit architecture is adopted to change the response mechanism of the PUF and overall improve the anti-model attack ability of the entropy source linear accumulation type APUF and its variant structures. The signals of the two symmetric paths of the PUF are respectively input into the architecture of the multi-layer TDC quantization circuit to realize the quantization of the delay difference digital code. The quantized data directly represents the information of the delay difference between the two symmetric paths of the PUF, enabling the response of the PUF to contain more unique and dynamic information when facing challenge inputs, and this architecture can be applied to any delay-based PUF to improve their anti-model attack ability.
[0069] The core problem faced by most PUF-based identity authentication methods is that under the same challenge, in the face of different device environments, the bit error rate of the response will affect the judgment of identity authentication, resulting in an increase in the false judgment rate of the identity authentication protocol. Currently, most technical solutions will use two methods to solve this problem: (1) Using a Fuzzy Extractor, which is actually a post-processing method. Its error correction ability can be designed according to the reliability test results of the PUF device, but it will increase the computational / communication overhead and complexity of the protocol. At the same time, the auxiliary data generated by the Fuzzy Extractor is at risk of leakage; (2) Using the method of setting thresholds, by collecting the bit error rates between responses in different environments, generating the required thresholds, and storing the thresholds in the protocol for use, meeting the design concepts of lightweight and security of the protocol.
[0070] Therefore, in order to reduce the false judgment rate of responses in the mutual authentication protocol, the present invention proposes a Hamming distance threshold generation algorithm, constructs the above PUF structure model, and calculates the delay difference between two paths through the PUF structure model. After quantifying and confusing the absolute values of the delay differences under all challenge configurations, the generated responses are stored, and the Hamming distance threshold T is determined by obtaining the responses under the same challenge configuration under different temperature and voltage conditions. h . When in the identity authentication protocol, by comparing the Hamming distance between two responses, it is determined whether the response is stable and secure. If the Hamming distance is within the generated threshold T h , the other party can be considered to have a legitimate identity, and thus the identity authentication is passed.
[0071] In the embodiment of the present invention, the method for obtaining the Hamming distance threshold T h is specifically as follows:
[0072] (1) Build multiple above PUF structure models and enumerate multiple challenge signals;
[0073] (2) Under normal temperature and pressure, input the mth challenge into the nth PUF structure model, and the PUF structure model outputs the corresponding time delay difference B mn , and the time delay difference B mn is output as the response R through the LFSR confusion structure mn ;
[0074] (3) Traverse all challenges and all PUF structure models;
[0075] (4) The tth time change the environmental temperature and / or the voltage of the PUF structure model, where t ranges from 1 to c. Input the mth challenge into the nth PUF structure model, and the PUF structure model outputs the corresponding time delay difference B' mn , and the time delay difference B' mnOutput the response R′ through the LFSR confusion structure mn , calculate the response R′ mn and the response R mn to calculate the Hamming distance, and save the Hamming distance to the matrix N t ;
[0076] (5) Traverse all challenges and all PUF structure models;
[0077] (6) Take the maximum Hamming distance in the matrix as the Hamming distance threshold, where the matrix Ν = (N1,..., N t 、...、N c ).
[0078] Before the protocol implementation, use this algorithm to statistically obtain the Hamming distance threshold T of the on-chip Hamming distance of the proposed PUF under different environmental conditions h to reduce the misjudgment rate in the protocol authentication process, thereby ensuring the reliability of response generation.
[0079] The identity authentication method proposed by the present invention includes three stages: a registration stage, an identity verification and a key update stage. The registration stage is carried out in a secure channel before the device leaves the factory. The identity verification and key update stages are carried out in an actual non-secure channel full of threats. Among them, the change of the delay difference in the PUF structure mainly depends on the challenge configurations of the front and rear sections of the delay unit. The four-order MUX and the four-order DEMUX connected to the output end of the MUX constitute the front section of the delay unit. The four-order DEMUX, the first exclusive-OR gate, the second exclusive-OR gate and the third exclusive-OR gate constitute the rear section of the delay unit; Therefore, the present invention proposes a method for reconstructing the response key of the PUF. While completing the mutual authentication between the device side and the server side, the challenge signal is segmented into C1 and C2. Among them, C1 is used to reconstruct the response of the PUF; C2 is used to verify the identity and is always located at the device side and does not appear in the channel. It should be noted that the responses used in the registration, authentication and update stages are all the responses output by the LFSR confusion structure.
[0080] (1) The registration process in the registration stage is as Figure 7 shown as follows:
[0081] The server sends a sufficient number of challenges and the corresponding symmetric key k of the device side i to the device side. After receiving the challenges and the corresponding keys, the device side divides the challenges into the first challenge signal C1 and the second challenge signal C2, and locally stores {C1, C2, k i}, and generates a response R i through the built-in PUF structure based on delay difference quantization i , and the response R iSent to the server, which locally stores {C1, ID i , R i , k i}.
[0082] (2) The authentication process in the authentication stage is as follows Figure 8 shown below:
[0083] (21) The device first generates a random number N1 through the TRNG for the encryption key. Based on the symmetric key k i encrypts the device's ID i and the random number N1, and sends the encrypted to the server side, indicating that the device requests the next identity authentication process.
[0084] (22) When the server receives the data sent by the device it decrypts using the symmetric key k i extracts the device's initial information ID i , N1, and verifies through the device information stored on the device . If the verification fails, it cannot enter the identity authentication stage; if the verification is successful, it extracts the previously stored challenge C1 and response R i based on the ID i . The server then generates a random number N2 and encrypts the challenge C1, response R i and the random number N2 using the random number N2 and the symmetric key k i , and sends the encrypted challenge response and the random number to the device. Among them, the random number N2 is to ensure the freshness of the information in each round of identity authentication process.
[0085] (23) When receiving the encrypted challenge response and the random number , the device calculates and decrypts to extract the random number N2 , decrypts using the obtained random number N2 to obtain the challenge C1 and response R i , verifies whether the challenge C1 is the C1 stored on the device. If the verification fails, it means that an attacker may be conducting a DOS attack. At this time, the previous round's challenge C1 stored on the device this time is used as the current round's challenge C1 to ensure the synchronization between the device and the server side; if the verification passes, the device uses the built-in PUF structure above to generate R′ i = PUF(C1||C2), and detects the response Ri and the response R' i Is the Hamming distance between them within the Hamming distance threshold T h If not within the Hamming distance threshold T h It indicates that the authentication fails and the process is terminated immediately; if within the Hamming distance threshold T h It indicates that the authentication is successful. The device side reconstructs the challenge and obtains a new response R based on the reconstructed challenge C'1 i+1 . The device side generates another random number N3, recalculates the challenge of the front segment of the PUF and stores it for the next round of authentication. Reconstruct the response R of the PUF structure i+1 , R i+1 = PUF(C'1||C2). The device side encrypts the reconstructed response R based on the random number N3 i+1 Perform encryption Calculate the message authentication code M = MAC(N2||R i+1 ||N3||k i ). M is used to confirm the integrity of the exchanged information, and then encrypt C'1 The parameter C'1 * , M, and are sent to the server
[0086] (24) When the server side receives the parameters C'1 * , M, and , decrypt the random number N3, the response R i+1 , and the challenge C'1 in sequence Check the integrity of the message by verifying the MAC. If the MAC verification is successful, update and re-store the response R i+1 and the challenge C'1
[0087] (25) After the authentication is passed, the device side updates the previously stored challenge C1 locally to the currently reconstructed challenge C'1, C1 ← C'1, and stores {C1, C2, k i}. At the same time, the server updates the previously stored challenge C1 locally to the currently reconstructed challenge C'1, the challenge C1 ← C'1, updates the previously stored response R i locally to the currently reconstructed response R i+1 , the response R i ← R i+1 , and stores {C1, ID i , R i , k i}, the parameters stored by both parties before the next round of identity authentication are consistent. Through this parameter update method, it is ensured that during each round of identity authentication, both the symmetric key and the asymmetric key are updated, so that even if an attacker obtains the old parameters, it will not affect the next round of identity authentication, improving the security of the protocol.
[0088] The identity authentication method based on the PUF structure with delay difference quantization proposed by the present invention has the following beneficial technical effects:
[0089] (1) A mutual authentication method based on the reconstructed PUF is proposed, which further improves the anti-model attack ability and anti-physical attack ability of the authentication protocol. The proposed protocol includes a device side and a server side. To protect the CRPs information, the protocol makes full use of the characteristics of the front and rear delay units based on DEMUX, divides the challenge signal into C1 and C2, and C2 is always stored on the device side and does not appear on the communication link. And after each round of mutual authentication ends, the challenge signal of the reconstructed PUF obtains a new reconstructed response key to improve the security of the protocol;
[0090] (2) Under environmental fluctuations, there will be slight fluctuations in the delay difference of the response, which will cause changes in the response. To reduce the false judgment rate of the protocol, a threshold generation algorithm is proposed based on the Hamming distance of the response, and the response within this threshold can pass the identity authentication.
[0091] Due to the characteristics of strong PUFs having exponential CRPs, machine learning-based modeling algorithms can train by collecting a large number of CRPs, simulate the circuit structure of strong PUFs, obtain an approximate linear relationship between challenges and responses, and thus predict the responses of strong PUFs, which seriously affects the application of strong PUFs in identity authentication protocols. Therefore, the anti-model attack ability of strong PUFs is an important security indicator. In the evaluation of this ability, the present invention uses six currently mainstream machine learning algorithms to test the anti-model attack ability of the PUF circuit proposed by the present invention. The six machine learning algorithms include: Covariance Matrix Adaptation Evolution Strategy (CMA-ES), Logistic Regression (LR), Artificial Neural Networks (ANN), Deep Neural Network (DNN), Convolutional Neural Network (CNN), Support Vector Machines (SVM). Ideally, the prediction accuracy of the model attack algorithm for PUFs at 50% is the ideal value, indicating that the PUF has excellent anti-model attack ability. During the evaluation process, APUF, APUF-TDC, DEMUX PUF, DEMUX-TDC PUF, and 3PXOR DDQ-APUF are used as test objects, and CRPs of 10k - 100k (step size of 10k) are respectively collected as test data. Among them, 70% is used as the training set for the model attack algorithm to train the machine learning model, and 30% is used as the test set to verify the anti-model attack ability of the PUF.
[0092] From Figure 9 It can be intuitively seen that for the traditional APUF structure, the prediction accuracy of the six machine learning algorithms for APUF reaches 97% - 99%, indicating that the traditional APUF is completely broken by the model attack. However, the responses generated by the present invention through digital code quantization and confusion processing of the delay difference between the two delay paths of APUF by the differential tap type circuit TDC have improved anti-model attack ability. For CMA-ES and LR, the average prediction rates of the APUF-TDC circuit are 58.01% and 54.19% respectively. Compared with the traditional APUF, the anti-model attack ability has increased by 41% and 45% respectively; for ANN, DNN, CNN, and SVM, the average prediction rate of the APUF-TDC circuit is basically at ~80%, and the anti-model attack ability has increased by 27%. For the proposed DEMUX PUF structure, by adding a non-linear vector for path selection in the front section of the PUF unit and dynamically changing the non-linear delay time in the rear section, the linear characteristics between challenges and responses are reduced. From Figure 9It can be observed that the prediction rates of CMA-ES, LR, CNN, and DNN for the DEMUX PUF are around 60%, and the prediction rates of ANN and SVM for the DEMUX PUF are around 53%, effectively improving the anti-model attack ability. In addition, for the DEMUX-TDC PUF circuit formed by combining the DEMUX PUF with the TDC quantization circuit, the prediction rates of the six model attacks for this structure do not show an upward trend with the increase in the size of the training set and always remain around 50%, increasing the anti-model attack ability by about 10%. At the same time, the DEMUX-TDC PUF also has a certain improvement in the anti-model attack ability compared to the 3PXOR DDQ-APUF and can successfully resist two model attacks of CNN and DNN.
[0093] In summary, the present invention highlights that the PUF circuit has excellent resistance against the above six model attacks. In addition, the proposed response generation mechanism of the TDC quantization strong PUF delay difference entropy source can further improve the anti-model attack ability of the delay-type strong PUF and significantly increase the non-linearity between the challenge and the response.
[0094] The present invention has been described by way of example. Obviously, the specific implementation of the present invention is not limited by the above methods. As long as various non-substantive improvements are made by adopting the method concept and technical solution of the present invention, or the concept and technical solution of the present invention are directly applied to other occasions without improvement, they are all within the protection scope of the present invention.
Claims
1. A PUF structure based on delay difference quantization, characterized in that: The PUF structure comprises: The PUF circuit includes two time delay circuits connected in parallel, and the two time delay circuits respectively output time delay signals; A multi-layer differential tap circuit TDC, and a decoder connected to each layer of the differential tap circuit TDC; a delay data quantization unit connected to the multi-layer decoder, and a LFSR confusion structure connected to the delay data quantization unit; The two delay circuits are connected to the differential tap circuit TDC through a signal selection structure. The signal selection structure inputs the delay signals of the first response and the last response in the two delay circuits into the start end and the stop end of each layer of the differential tap circuit TDC respectively. The delay time of the start end is higher than that of the stop end. The decoder determines the delay time of the two delay circuits at the corresponding delay resolution based on the output signal of the corresponding differential tap circuit TDC. The delay data quantization unit takes the average of the delay time at different delay resolutions as the final delay data. The final delay data is mixed by the LFSR mixing structure and the final response R is output.
2. The PUF structure based on delay difference quantization as claimed in claim 1, characterized in that: The delay circuit is composed of multiple delay units connected in series, and each delay unit includes: a four-order MUX and a four-order DEMUX connected to the output end of the MUX, two output ends of the DEMUX are connected to the first XOR gate, and the other two output ends are connected to the second XOR gate. The first XOR gate and the second XOR gate are connected to the third XOR gate, and the output of the third XOR gate is connected to the four-order MUX of each delay unit of the next order.
3. The PUF structure based on delay difference quantization as claimed in claim 2, characterized in that: The challenge signal C is processed in segments to obtain a first challenge signal C1 and a second challenge signal C2 of the same length. The 4nth to 4(n+1) bits of the first challenge signal C1 are sequentially configured to two selection ends of MUX and DEMUX in the n+1th order delay unit. The MUX selects one of the four input signals for output based on a two-bit control signal, and the DEMUX selects one of the four output signals for output based on a two-bit control signal. The 4nth to (4n+2)th bits of the second challenge signal C2 are all configured to two irrelevant bit ends of the first XOR gate and the second XOR gate in the n+1th order delay unit, and the (4n+2)th to 4(n+1)th bits are all configured to two irrelevant bit ends of the third XOR gate in the n+1th order delay unit. The first XOR gate, the second XOR gate, and the third XOR gate determine the delay length applied to the corresponding XOR gate based on the two-bit control signal.
4. The PUF structure based on delay difference quantization as claimed in claim 1, characterized in that: The signal selection circuit is composed of two buffers and two second-order MUXs. The Start signal and the Stop signal output by the two delay paths are input into the two buffers through the input of the signal selection circuit. The two buffers output the corresponding signals to the input ends of the two second-order MUXs respectively. At the same time, the response signal R is configured to the selection ends of the two second-order MUXs. When the Up signal is output before the Down signal, the response S=1, and the Up signal is used as the Start signal and the Down signal is used as the Stop signal through the second-order MUX; when the Down signal is output before the Up signal, the response S=0, and the Down signal is used as the Start signal and the Up signal is used as the Stop signal through the second-order MUX.
5. The PUF structure based on delay difference quantization as claimed in claim 1, characterized in that: Each layer of the differential tap circuit TDC is composed of m stages. Each stage of the delay device includes two IDELAYE2s with different delay times t1 and t2 and an arbitrator connecting the two IDELAYE2s. The Start signal and the Stop signal are respectively input to the IDELAYE2 with a delay time of t1 and the IDELAYE2 with a delay time of t2 in the first stage of the delay device. The delay time t1 is greater than the delay time t2.
6. The PUF structure based on delay difference quantization as claimed in claim 5, characterized in that: The arbiter in the i-stage delay device consists of a fourth-order MUX and a second-order MUX. The delay T output by IDELAYE2 with delay times t1 and t2 in the i-stage delay device is i , delay D i The input corresponds to the two selection terminals of the fourth-order MUX. The fourth-order MUX selects one input for output based on the selection signal input to the selection terminal. The output terminal is connected to the terminal of the second-order MUX, and the other input terminal is connected to the corresponding input terminal of the fourth-order MUX. The output terminal outputs the i-th bit of the signal signal, and the selection terminal of the second-order MUX is connected to the enable terminal.
7. The PUF structure based on delay difference quantization as claimed in claim 4, characterized in that: The decoder connected to T, the j-th layer differential tap circuit TDC calculates the delay time T between the two delay paths tested by the j-th layer differential tap circuit TDC j , the calculation formula is as follows: T j =N j ×(t 1j -t 2j ); Among them, N j is the number of high levels in the output signal signal of the j-th layer differential tap circuit TDC, t 1j ,t 2j is the delay time of the delay device in the j-th layer differential tap circuit TDC.
8. The PUF structure based on delay difference quantization as claimed in claim 1, characterized in that: The reference clock frequency f of each layer of differential tap circuit TDC is the same, and the reference clock frequency f between different layers of differential tap circuit TDC is different. The delayed signal generated under the same challenge signal is sent to the differential tap circuit TDC decoding with different resolutions of each layer of delay device to quantize the delay time. The delay data quantization unit takes the average of all quantized delay times as the final delay time between the two delay circuits.
9. An identity authentication method based on the PUF structure based on delay difference quantization according to any one of claims 1 to 8, characterized in that: The method is specifically as follows: (21) The device generates a random number N1 for encryption key based on the symmetric key k i ID of the device i , random number N1 is used for encryption, and the encrypted Send to the server; (22) When the server receives the Using symmetric key k i Decrypt and extract the initial information ID of the device i , N1, through the device information stored on the device side Verify, if successful, then according to ID i Extract the locally stored challenge C1 and response R i The server generates a random number N2 and uses the random number N2 and the symmetric key k i To challenge C1, response R i and the random number N2, and the encrypted challenge response And random numbers Send to the device; (23) When the device receives the encrypted challenge response And random numbers After that, the random number N2 is extracted by calculation and decryption, and the obtained random number N2 is used for decryption to obtain the challenge C1 and the response R i , verify whether the challenge C1 is the C1 stored on the device. If the verification fails, the challenge C1 of the previous round stored locally is used as the challenge C1 of the current round. If the verification passes, the device uses the built-in PUF structure described above to generate a response R i ′=PUF(C1||C2), and detect the response R i and the response R i ′ is within the Hamming distance threshold T h If it is within the Hamming distance threshold T h If the device generates a random number N3, the challenge of the PUF front end is recalculated. Reconstruct the response R of the PUF structure i+1 , R i+1 =PUF(C'1||C2), response R to reconstruction based on random number N3 i+1 Encrypt, calculate and use the message authentication code, and then encrypt the reconstructed challenge C1', and use the parameter M. and Send to the server; (24) When the server receives the parameter M. and After that, the random number N3 and the response R are decrypted in turn. i+1 , challenge C'1, check the integrity of the message by verifying the MAC, and if the MAC verification succeeds, update and re-store the response R i+1 and Challenge C'1. (25) After the authentication is passed, the device updates the challenge C1 stored in the previous round stored locally to the challenge C1' reconstructed in the current round, C1←C1'. At the same time, the server updates the challenge C1 stored in the previous round stored locally to the challenge C1' reconstructed in the current round, challenge C1←C1', and updates the response R stored in the previous round stored locally i Updated to the current round of refactoring responsive R i+1 , response R i ←R i+1 .
10. The identity authentication method based on the PUF structure of delay difference quantization as claimed in claim 9, characterized in that: Hamming distance threshold T h The specific method for determining is as follows: (1) Building multiple PUF structure models and enumerating multiple challenge signals; (2) At normal temperature and pressure, the mth challenge is input into the nth PUF structure model, and the PUF structure model outputs the corresponding delay difference B mn , delay difference B mn The LFSR confusion structure outputs the response R mn ; (3) Traverse all challenges and all PUF structure models; (4) Change the ambient temperature and / or PUF structure model voltage for the tth time, where t ranges from 1 to c. Input the mth challenge into the nth PUF structure model, and the PUF structure model outputs the corresponding delay difference B′ mn , delay difference B′ mn The LFSR confusion structure outputs the response R′ mn , calculate the response R′ mn With response R mn The Hamming distance between them is stored in the matrix N. t ; (5) Traverse all challenges and all PUF structure models; (6) The maximum Hamming distance in the matrix is used as the Hamming distance threshold, where N matrix N = (N1, ..., N t ,...,N c ).
Citation Information
Patent Citations
Memristor-based multifunctional PUF (Physical Unclonable Function) circuit and use method thereof
CN115766029A
Arbiter PUF (Physical Unclonable Function) structure and encryption device with same
CN117650892A
Systems and methods for leveraging path delay variations in a circuit and generating error-tolerant bitstrings
US20160204781A1
Isa accessible physical unclonable function
US20220209967A1
System and methods for PUF-based authentication
US20230216838A1
Cited By
Configurable delay transient effect ring oscillator PUF
CN122020738A
A configurable delay transient effect ring oscillator puf
CN122020738B
Strong PUF (Physical Unclonable Function) machine learning attack resisting method and system
CN122490602A