A Hardware Fingerprint Extraction Method and System Based on SRAM PUF
By grouping and large-number judgment error correction processing of SRAM array bit units, a stable hardware fingerprint is generated, which solves the problem of instability of SRAM PUF response sequence and improves the applicability of hardware security applications.
Patent Information
- Application Number
- CN202110252979.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-02
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2041-03-02
AI Technical Summary
The response sequence quality of existing SRAM PUF outputs is not high and unstable, and is not suitable for hardware security scenarios.
By reading the power-up value of the SRAM array bit cells in the registration stage for grouping, and large-number judgments and error corrections are performed in the reconstruction stage, a stable hardware fingerprint is generated.
Improves the quality and stability of the hardware fingerprint output of SRAM PUF, making it more suitable for hardware security scenarios.
Smart Images

Figure CN114996774B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a hardware fingerprint extraction method and system based on SRAM PUF. Background Art
[0002] With the rapid development of technologies such as the Internet of Things, big data, and artificial intelligence, information security has become a hot issue that cannot be ignored today. The Physically Unclonable Function (PUF) based on integrated circuit technology has been considered a new fundamental technology for ensuring information security since its proposal. The PUF based on integrated circuit technology, also known as silicon PUF, uses uncontrollable physical characteristics in the chip manufacturing process to generate unclonable chip fingerprints, and has broad application prospects in fields such as key generation, authorization, and authentication. In the development and application process of PUF, stability, uniformity, and uniqueness are important indicators for PUF design. Stability refers to the similarity of the output response sequences of the same PUF under the same excitation at different times and environmental conditions, and is commonly measured by the in-chip Hamming distance; uniformity refers to the proportion of 1 in the output response sequences of any PUF under various time and environmental conditions when excited, and is commonly measured by the fractional Hamming weight; uniqueness refers to the difference degree of the output response sequences of different PUFs under the same excitation at various time and environmental conditions, and is commonly measured by the inter-chip Hamming distance.
[0003] The implementation methods of silicon PUF can be divided into PUFs based on inherent delay characteristics, including arbiter PUF, ring oscillator PUF, glitch PUF, etc.; PUFs based on memories, including flip-flop PUF, SRAM PUF, and latch PUF, etc. Currently, SRAM (Static Random Access Memory) PUF is a PUF technology implementation method that has been studied more. The typical SRAM PUF entropy source is implemented based on SRAM logic storage units. The SRAM logic storage unit can be regarded as being composed of two cross-coupled inverters. Due to uncontrollable factors in the manufacturing process, such as the uniformity of doping concentration and the subtle differences in the length-width ratio of transistor channels, the SRAM memory array will randomly generate 0 or 1 responses with innate uniqueness during the power-on process, that is, it has PUF characteristics. However, under various environmental conditions such as temperature and aging, the response sequence output by the SRAM PUF is a noisy hardware fingerprint, with low quality and instability, and is not suitable for hardware security scenarios. Summary of the Invention
[0004] In view of the above analysis, the present invention aims to provide a hardware fingerprint extraction method and system based on SRAM PUF to solve the problem that the response sequence output by the existing SRAM PUF has low quality and instability and is not suitable for hardware security scenarios.
[0005] On the one hand, the present invention provides a hardware fingerprint extraction method based on SRAM PUF, which is characterized by including the following steps:
[0006] Registration stage:
[0007] Power on the SRAM PUF, read the addresses and corresponding power-on values of the bit cells in the SRAM array at the moment of power-on, where the power-on value is 0 or 1;
[0008] Group the bit cells in the SRAM array according to the power-on values of the bit cells and store the grouping;
[0009] Perform majority decision on each group according to the power-on values of the bit cells in the group, and use the decision result sequence as the hardware fingerprint;
[0010] Reconstruction stage:
[0011] Power on the SRAM PUF again, and obtain the power-on values of the bit cells of each group stored in the registration stage according to the power-on values of the bit cells at the same addresses in the SRAM array read at the moment of power-on;
[0012] Perform majority decision on each group to obtain a decision result sequence;
[0013] Correct the decision result sequence, and use the corrected sequence as the hardware fingerprint reconstructed in the reconstruction stage.
[0014] Further, the step of grouping the bit cells in the SRAM array is as follows:
[0015] Select m bit cells corresponding to m power-on values that meet the fractional Hamming weight requirement in the SRAM array as the reference group, and the remaining n - m bit cells as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit cells in the SRAM array;
[0016] According to each bit cell in the reference group, at most k - 1 bit cells in the ballot box group that have the same power-on value as the corresponding bit cell in the reference group and have not been grouped are grouped with the corresponding bit cell in the reference group to obtain m groups; the remaining bit cells in the ballot box group that have different power-on values and have not been grouped are grouped into groups with less than k bit cells, or the remaining ungrouped bit cells in the ballot box group are not grouped into groups, and the grouping is completed; where k is the maximum number of bit cells in each group.
[0017] Further, the maximum value k of the number of bit units in each group is an odd number.
[0018] Optionally, a parallel grouping method that preferentially traverses the reference group is used for grouping. The steps are as follows: For the group where the m bit units of the reference group are located, the j-th in-group bit unit of each group is found in sequence:
[0019] For the j-th in-group bit unit of each group, traverse the bit units of the reference group: For the i-th bit unit of the reference group, if a bit unit with the same power-on value and not yet grouped is found in the ticket warehouse group, then divide this bit unit into the group where the i-th bit unit of the reference group is located as the j-th in-group bit unit of this group; otherwise, use the first ungrouped bit unit in the ticket warehouse group as the j-th bit unit of the group where the i-th bit unit of the reference group is located;
[0020] where j ∈ [2, k] and i ∈ [1, m].
[0021] Optionally, a serial grouping method that preferentially traverses the reference group is used for grouping. The steps are as follows:
[0022] Traverse the bit units of the reference group in sequence:
[0023] For the i-th bit unit in the reference group, if k - 1 bit units with the same power-on value and not yet grouped are found in sequence in the ticket warehouse group, then divide these k - 1 bit units into the group where the i-th bit unit of the reference group is located; otherwise, end the traversal of the reference group, and use the i-th to m-th bit units in the reference group as the only in-group bit units respectively to complete the grouping, obtaining m groups; where i ∈ [1, m].
[0024] Optionally, a method that preferentially traverses the ticket warehouse group is also used for grouping. The steps are as follows:
[0025] Traverse the bit units in the ticket warehouse group in sequence:
[0026] For the g-th ungrouped bit unit in the ticket warehouse group with a power-on value of b g if a bit unit with a power-on value of b g and the number of in-group bit units less than k is found in the reference group, then divide the g-th bit unit in the ticket warehouse group into the group where the bit unit in the reference group is located; otherwise, end the traversal of the ticket warehouse group, and sequentially divide the g-th to n - m-th ungrouped bit units in the ticket warehouse group into the groups in the reference group where the number of in-group bit units is less than k, obtaining m groups; where g ∈ [1, n - m], and the value of b g is 0 or 1.
[0027] Further, in the registration stage or the reconstruction stage, the steps of performing majority decision on each group are as follows:
[0028] Perform a decision on each group. If the number of bit units in the group is k, when at least (k + 1) / 2 bit units have a powered-on value of 1, the decision result is 1; otherwise, it is 0. If the number of bit units in the group is 1, then use the powered-on value of this bit unit as the decision result.
[0029] Perform majority decision on each group separately to obtain a decision result sequence of m bit units.
[0030] On the other hand, the present invention provides a hardware fingerprint extraction system based on SRAM PUF, including an SRAM array, a grouper, and a majority decision maker;
[0031] The SRAM array includes a plurality of bit units, and is used to obtain the powered-on values of each bit unit through power-on in the registration stage and the reconstruction stage;
[0032] The grouper is used to power on the SRAM PUF in the registration stage, read the addresses and corresponding powered-on values of the bit units in the SRAM array at the moment of power-on; and group the bit units of the SRAM array according to the powered-on values of the bit units in the SRAM array;
[0033] The majority decision maker is used to perform majority decision on each group according to the powered-on values of each bit unit in the group in the registration stage, and use the decision result sequence as the hardware fingerprint; in the reconstruction stage, power on the SRAM PUF again, obtain the powered-on values of each bit unit of the stored group in the registration stage according to the powered-on values of the bit units at the same addresses in the SRAM array read at the moment of power-on, perform majority decision on each group to obtain a decision result sequence, and then correct the decision result sequence, and use the corrected sequence as the hardware fingerprint reconstructed in the reconstruction stage.
[0034] Further, the steps of grouping the bit units in the SRAM array are as follows:
[0035] Select m bit units corresponding to m powered-on values that meet the fractional Hamming weight requirement in the SRAM array as the reference group, and the remaining n - m bit units as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit units in the SRAM array;
[0036] For each bit cell in the reference group, at most k-1 bit cells in the ballot box group that have the same power-on value as the corresponding bit cell in the reference group and have not been grouped are grouped with the corresponding bit cell in the reference group to obtain m groups; the remaining bit cells in the ballot box group that have different power-on values and have not been grouped are grouped into groups with less than k bit cells, or the remaining ungrouped bit cells in the ballot box group are not grouped into groups, and the grouping is completed; where k is the maximum number of bit cells in each group.
[0037] Further, the maximum value k of the number of bit cells in each group is an odd number.
[0038] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0039] In this application, during the registration phase, the bit cells of the SRAM array are grouped according to the power-on values of the SRAM array, and majority voting is performed on each group to obtain the hardware fingerprint; and during the reconstruction phase, according to the power-on values of the SRAM array read again, majority voting is performed on each group, and the reconstructed hardware fingerprint in the reconstruction phase is obtained after correcting the judgment results, so that even if the power-on values of some bit cells in the SRAM array change due to environmental noise, etc., an accurate hardware fingerprint can still be output. By this method, each time the SRAM PUF is reconstructed, it is ensured that the output hardware fingerprint is more stable, realizing the conversion of the noisy hardware fingerprint output by the SRAM PUF into a stable hardware fingerprint, greatly improving the quality and stability of the extracted hardware fingerprint, being more suitable for hardware security scenarios, and enabling stable PUF chip fingerprints to be accurately generated in most integrated circuit processes.
[0040] In the present invention, the above technical solutions can also be combined with each other to achieve more preferred combination schemes. Other features and advantages of the present invention will be described in the subsequent specification, and some advantages can be made obvious from the specification, or understood by implementing the present invention. The objectives and other advantages of the present invention can be realized and obtained from the content specifically pointed out in the specification and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The drawings are only for the purpose of showing specific embodiments and are not considered to be a limitation of the present invention. Throughout the drawings, the same reference numerals represent the same components.
[0042] Figure 1 It is a schematic diagram of the registration phase process in the hardware fingerprint extraction method based on SRAM PUF provided in Embodiment 1 of the present invention;
[0043] Figure 2 It is a schematic diagram of the reconstruction phase process in the hardware fingerprint extraction method based on SRAM PUF provided in Embodiment 1 of the present invention;
[0044] Figure 3 It is a schematic structural diagram of the hardware fingerprint extraction system based on SRAM PUF provided in Embodiment 2 of the present invention;
[0045] Figure 4 It is a schematic diagram of the parallel grouping method for preferentially traversing the reference group in the implementation process of the hardware fingerprint extraction method based on SRAM PUF provided in Embodiment 3 of the present invention. Detailed implementation manners
[0046] The following will specifically describe the preferred embodiments of the present invention in conjunction with the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.
[0047] Embodiment 1
[0048] A specific embodiment of the present invention discloses a hardware fingerprint extraction method based on SRAM PUF, as Figure 1 and Figure 2 shown, including the following steps:
[0049] Registration stage:
[0050] The SRAM PUF is powered on, and the addresses and corresponding power-on values of the bit cells in the SRAM array at the moment of power-on are read; wherein, the power-on value is 0 or 1.
[0051] The bit cells in the SRAM array are grouped according to the power-on values of the bit cells, and the groups are stored; it should be noted that when storing the groups, the groups are stored in a non-volatile memory for use in the reconstruction stage.
[0052] According to the power-on values of the bit cells in each group, a majority decision is made on each group, and the decision result sequence is used as the hardware fingerprint.
[0053] Reconstruction stage:
[0054] The SRAM PUF is powered on again, and according to the power-on values of the bit cells at the same addresses in the SRAM array at the moment of power-on read, the power-on values of the bit cells of the groups stored in the registration stage are obtained.
[0055] A majority decision is made on each group to obtain a decision result sequence.
[0056] Error correction is performed on the decision result sequence, and the corrected sequence is used as the hardware fingerprint reconstructed in the reconstruction stage.
[0057] In specific implementation, the error correction process for the judgment sequence can be carried out according to existing error correction methods, such as repetition codes, binary Gray codes, cyclic codes, and concatenated codes. According to different error correction methods, corresponding assistance data for the error correction codes can be generated in the registration stage, and the error correction process can be carried out in the reconstruction stage. This embodiment does not make specific limitations, and only the error correction function needs to be realized. In addition, in this embodiment, the method of grouping and performing majority judgment on the groups has processed the error data once, so an error correction method with lower complexity can be selected to further reduce the bit error rate.
[0058] Compared with the prior art, in this application, in the registration stage, the bit cells of the SRAM array are grouped and saved according to the power-on values of the SRAM array, and majority judgment is performed on each group to obtain the hardware fingerprint. In the reconstruction stage, according to the power-on values of the SRAM array read again, majority judgment is performed on each group, and after error correction post-processing with lower complexity on the judgment results, the hardware fingerprint of the SRAM PUF can be reconstructed, which can greatly improve the quality and stability of extracting the hardware fingerprint and is more suitable for the hardware security scenario.
[0059] Specifically, the SRAM array is a static random access memory array. According to its design principle, each bit cell in it has a fixed storage address, and the address of the bit cell can be directly read. The power-on value refers to the value measured for each bit cell after the SRAM PUF is powered on. According to the design principle of the SRAM PUF, the power-on value of each bit cell, which is 0 or 1, can be measured when powered on. Therefore, when the SRAM PUF is powered on, the addresses of each bit cell can be read, and the power-on values of each bit cell can be read.
[0060] It should be noted that in the registration stage, the power-on values of the bit cells in the SRAM array can be read once or multiple times. Multiple readings are more beneficial to obtaining stable power-on values of the bit cells in the SRAM array, which is more beneficial to accurate grouping and further beneficial to reducing the bit error rate. This embodiment does not make limitations on this. The groups obtained in the registration stage are the groups of the bit cells in the SRAM array and are stored fixedly. The power-on values during each reconstruction will be slightly different from those in the registration stage. Therefore, in the reconstruction stage, majority judgment is performed according to the groups of SRAM cells with fixed addresses and the new power-on values read during reconstruction. In addition, in the reconstruction stage, multiple reconstructions can be performed according to the usage situation of the SRAM PUF, and the hardware fingerprint is not stored and is only generated when needed.
[0061] During implementation, the steps of grouping the bit cells in the SRAM array are as follows:
[0062] Select m bit cells where the m powered-on values in the SRAM array meet the fractional Hamming weight requirement as the reference group, that is, as the reference for subsequent grouping. The remaining n - m bit cells are used as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit cells in the SRAM array. That is to say, according to the number of bits m of the hardware fingerprint to be extracted, the n bit cells of the SRAM array are divided into m groups. Specifically, when selecting the reference group, the first m bit cells in the SRAM array can be preferentially selected. When the powered-on values of the first m bit cells do not meet the fractional Hamming weight requirement in the PUF application index, then select other m bit cells that meet the requirements from the n bit cells of the SRAM array. It should be noted that the fractional Hamming weight is the Hamming weight divided by the bit length, that is, the ratio between the sum of the powered-on values of the m bit cells and m. The m powered-on values that meet the fractional Hamming weight requirement refer to that the ratio between the sum of the powered-on values of the m bit cells and m meets the specific threshold requirement of the fractional Hamming weight in the PUF application index. For example, the threshold requirement is [0.45, 0.55], which can be determined according to the specific requirements of the PUF application index in practice.
[0063] According to each bit cell in the reference group, at most k - 1 bit cells in the ballot box group that have the same powered-on value as the corresponding bit cell in the reference group and have not been grouped are grouped with the corresponding bit cell in the reference group to obtain m groups; the remaining bit cells in the ballot box group that have different powered-on values and have not been grouped are grouped into the groups with the number of bit cells less than k, or the remaining ungrouped bit cells in the ballot box group are not grouped into the groups, and the grouping is completed; where k is the maximum value of the number of bit cells in each group. It should be noted that in this step, by dividing the SRAM array into m non-overlapping groups, that is, the bit cells in each group are all different, and trying to group the bit cells with the same powered-on value into one group, so that after the powered-on values of some bit cells change during the reconstruction stage, the output sequence can still be guaranteed to be accurate with a probability close to 1 through majority decision, that is, the stability of the reconstructed hardware fingerprint is enhanced, and it is ensured that the hardware fingerprint can be extracted with lower complexity error correction post-processing.
[0064] Specifically, the maximum value k of the number of bit cells in each group is an odd number. It should be noted that k is an odd number less than or equal to the floor of n / m, which is more convenient for the implementation of majority decision in the reconstruction stage in practical applications.
[0065] An optional implementation method is to use the parallel grouping method of preferentially traversing the reference group for grouping. The steps are as follows:
[0066] For the groups where the m bit cells in the reference group are located, sequentially find the jth in-group bit cell of each group:
[0067] For the j-th intra-group bit unit of each group, traverse the bit units of the reference group: For the i-th bit unit of the reference group, if a bit unit with the same power-on value and not yet grouped is found in the ticket warehouse group, then classify this bit unit into the group where the i-th bit unit of the reference group is located, as the j-th intra-group bit unit of this group; otherwise, classify the first ungrouped bit unit in the ticket warehouse group as the j-th bit unit of the group where the i-th bit unit of the reference group is located. That is to say, at this time, the ungrouped bit units in the ticket warehouse group only have power-on values of 0 or 1, so the power-on values are no longer compared, but the ungrouped bit units in the ticket warehouse group are directly classified into the groups with less than k intra-group bit units in turn. Where j ∈ [2, k] and i ∈ [1, m].
[0068] It should be noted that when looking for a bit unit in the ticket warehouse group that has the same power-on value as the bit unit of the reference group and is not yet grouped, it is searched sequentially from the front to the back in the ticket warehouse group; each bit unit of the reference group is the first intra-group bit unit of each group, so the intra-group bit units searched in the ticket warehouse group start from the second bit unit of each group.
[0069] An optional implementation method is to perform grouping using a serial grouping method that preferentially traverses the reference group. The steps are as follows:
[0070] Traverse the bit units of the reference group in turn:
[0071] For the i-th bit unit in the reference group, if k - 1 bit units with the same power-on value and not yet grouped are found in the ticket warehouse group in turn, then classify these k - 1 bit units into the group where the i-th bit unit of the reference group is located; otherwise, end the traversal of the reference group, and classify the i-th to m-th bit units in the reference group as the only intra-group bit units respectively to complete the grouping, obtaining m groups. That is to say, if the number of ungrouped bit units in the ticket warehouse group that have the same power-on value as the bit units of the reference group is less than k - 1, then the remaining ungrouped bit units in the ticket warehouse group are not classified into the groups and are all discarded, and only the i-th to m-th bit units in the reference group are classified as the only intra-group bit units respectively to complete the grouping; where i ∈ [1, m].
[0072] In an optional implementation method, grouping can also be performed using a method that preferentially traverses the ticket warehouse group. The steps are as follows:
[0073] Traverse the bit units in the ticket warehouse group in turn:
[0074] For the g-th ungrouped bit unit in the ticket warehouse group with a power-on value of b g If a group in the reference group is found where the number of intra-group bit units is less than k and the power-on value is b gFor the g-th bit cell of the ballot box group, if it is classified into the group where the bit cells of the reference group are located; otherwise, end the traversal of the ballot box group, and sequentially classify the g-th to the (n - m)-th unclassified bit cells of the ballot box group into the groups in the reference group where the number of bit cells in the group is less than k, obtaining m groups. That is to say, the power-on values of the bit cells of the reference group corresponding to the groups with less than k bit cells in the group are all 1 - b g , at this time, directly put the unclassified bit cells in the ballot box group into the groups with less than k bit cells in the group in sequence, where g ∈ [1, n - m], b g The value of is 0 or 1.
[0075] It should be noted that if the bit cells of the reference group are the first m cells of the SRAM array, then the bit cells of the ballot box group are the last n - m cells. Relative to the n bit cells of the SRAM array, the first bit cell of the ballot box group is the (m + 1)-th bit cell of the SRAM array, and the last bit cell of the ballot box group is the n-th bit cell of the SRAM array.
[0076] During implementation, in the registration stage or the reconstruction stage, the steps for performing majority decision on each group are as follows:
[0077] Perform a decision on each group. If the number of bit cells in the group is k, when at least (k + 1) / 2 bit cells have a power-on value of 1, the decision result is 1; otherwise, it is 0; if the number of bit cells in the group is 1, then use the power-on value of this bit cell as the decision result.
[0078] Perform decisions on each group separately to obtain a decision result sequence of m bit cells. Specifically, the decision result sequence obtained in the registration stage is the hardware fingerprint to be extracted. The decision result sequence obtained in the reconstruction stage needs further error correction and post-processing to extract the same hardware fingerprint as in the registration stage.
[0079] It should be noted that in this implementation, by performing majority decision on each group to obtain the decision result sequence, the stability of the obtained sequence can be enhanced when the power-on values of some bit cells change.
[0080] Embodiment 2
[0081] Another specific embodiment of the present invention discloses a hardware fingerprint extraction system based on SRAM PUF, as Figure 3 shown, including an SRAM array, a grouper, and a majority decision maker.
[0082] The SRAM array includes multiple bit cells and is used to obtain the power-on values of each bit cell through power-on in the registration stage and the reconstruction stage.
[0083] A grouper, which is used to power on through the SRAM PUF during the registration phase, read the addresses of the bit cells in the SRAM array at the moment of power-on and the corresponding power-on values; and group the bit cells of the SRAM array according to the power-on values of the bit cells in the SRAM array.
[0084] A majority decider is used to perform majority decision on each group according to the power-on values of the bit cells in the group during the registration phase, and use the decision result sequence as the hardware fingerprint; during the reconstruction phase, it powers on through the SRAM PUF again, and according to the power-on values of the bit cells at the same addresses in the SRAM array read at the moment of power-on as those in the registration phase, obtains the power-on values of the bit cells storing each group during the registration phase, performs majority decision on each group to obtain a decision result sequence, and then corrects the decision result sequence, and uses the corrected sequence as the hardware fingerprint reconstructed during the reconstruction phase.
[0085] When implemented, the steps of grouping the bit cells in the SRAM array are as follows:
[0086] Select m bit cells corresponding to m power-on values that meet the fractional Hamming weight requirement in the SRAM array as the reference group, and the remaining n - m bit cells as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit cells in the SRAM array.
[0087] According to each bit cell in the reference group, at most k - 1 bit cells in the ballot box group that have the same power-on value as the corresponding bit cell in the reference group and have not been grouped are grouped with the corresponding bit cell in the reference group to obtain m groups; the remaining bit cells in the ballot box group that have different power-on values and have not been grouped are grouped into the groups with the number of bit cells less than k, or the remaining ungrouped bit cells in the ballot box group are not grouped into the groups, and the grouping is completed; where k is the maximum number of bit cells in each group.
[0088] When implemented, the maximum value k of the number of bit cells in each group is an odd number.
[0089] It should be noted that the relevant parts of this embodiment and Embodiment 1 can be borrowed from each other, and this is a repeated description here. For example, for the specific grouping method of the grouper in this Embodiment 2, any optional implementation method in Embodiment 1 can be selected; for the decision method of the majority decider in this Embodiment 2, the specific decision method in Embodiment 1 is selected.
[0090] Embodiment 3
[0091] Taking the specific Embodiment 3 of the present invention as an example of screening out a 160-bit stable PUF response sequence from an 1120-bit SRAM memory array as the hardware fingerprint, the specific implementation processes of the methods and systems in Embodiment 1 and Embodiment 2 are described:
[0092] As Figure 3 shown, the device of this embodiment includes an SRAM array, a grouper ( Figure 3 Marker 1 in Figure 3 ) and a majority decision maker ( Figure 4 Marker 2 in
[0093] . As
[0094] shown, in this embodiment, a parallel grouping method that preferentially traverses the reference group is adopted. The parallel grouping method is more convenient for hardware implementation. Preferably, in this embodiment, the first 1 to m bit cells in the SRAM array are used as the bit cells of the reference group, so that one less bit cell can be stored for each group. Compared with directly storing m groups, the number of stored bit cells is reduced from nlogn to (n - m)logm. Figure 4 During implementation, the grouper is used to group the bit cells in the 1120-bit SRAM memory array. For each bit cell from 1 to 160 bits that meets the PUF application characteristics, as much as possible, 6 bit cells with the same power-on value and not grouped among the remaining 161 to 1120 bits are used to form a group. The 1120 bit cells are divided into 160 groups, and each group contains 7 bit cells.
[0095] The majority voter is used to perform majority voting on 160 groups respectively according to the read power-on values during the registration stage or the reconstruction stage, obtaining a 160-bit decision result sequence. That is, for the i-th group where i ∈ [1, 160], there are 7 cells marked with i (including the i-th cell in the first 160-bit cell, i.e., the reference group). If the power-on values of more than or equal to 4 of these 7 cells are 1, then the i-th bit is decided as 1; otherwise, it is decided as 0. After performing the decision on 160 groups, a decision result sequence of 160-bit cells is obtained. During the registration stage, a 160-bit stable hardware fingerprint is obtained. During the reconstruction stage, the hardware fingerprint can be reconstructed by using error correction post-processing with lower complexity.
[0096] Compared with the prior art, the hardware fingerprint extraction method provided in this embodiment divides the bit cells with the same power-on value in the SRAM array into one group as much as possible, obtaining m groups. During the reconstruction stage, by performing majority voting on each group according to the re-read power-on values, the hardware fingerprint can be reconstructed, avoiding the problem that the output hardware fingerprint contains ineliminable noise due to the unstable power-on values of some bit cells in the SRAM array under various environmental conditions such as temperature and aging during the reconstruction stage, that is, when using the hardware fingerprint, and greatly improving the efficiency of hardware fingerprint extraction.
[0097] Those skilled in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium. Among them, the computer-readable storage medium is a magnetic disk, an optical disc, a read-only memory, or a random access memory, etc.
[0098] The above is only a preferred specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.
Claims
1. A hardware fingerprint extraction method based on SRAM PUF, characterized in that, It includes the following steps: Registration stage: The SRAM PUF is powered on, and the addresses and corresponding power-on values of the bit cells in the SRAM array at the moment of power-on are read, where the power-on value is 0 or 1; The bit cells in the SRAM array are grouped according to the power-on values of the bit cells in the SRAM array and the grouped results are stored; the steps of grouping the bit cells in the SRAM array are as follows: Select m bit cells corresponding to m power-on values that meet the fractional Hamming weight requirement in the SRAM array as the reference group, and the remaining n - m bit cells as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit cells in the SRAM array; According to each bit cell in the reference group, at most k - 1 bit cells in the ballot box group that have the same power-on value as the corresponding bit cell in the reference group and have not been grouped are grouped with the corresponding bit cell in the reference group to obtain m groups; the remaining bit cells in the ballot box group with different power-on values and not grouped are grouped into the groups with less than k bit cells, or the remaining ungrouped bit cells in the ballot box group are not grouped into the groups, and the grouping is completed; where k is the maximum number of bit cells in each group; According to the power-on values of the bit cells in each group, a majority decision is made on each group, and the decision result sequence is used as the hardware fingerprint; Reconstruction stage: The SRAM PUF is powered on again, and according to the power-on values of the bit cells at the same addresses in the SRAM array at the moment of power-on read, the power-on values of the bit cells storing the grouped results in the registration stage are obtained; A majority decision is made on each group to obtain a decision result sequence; Error correction is performed on the decision result sequence, and the corrected sequence is used as the hardware fingerprint reconstructed in the reconstruction stage.
2. The hardware fingerprint extraction method based on SRAM PUF according to claim 1, wherein, The maximum value k of the number of bit cells in each group is an odd number.
3. The hardware fingerprint extraction method based on SRAM PUF according to claim 1, characterized in that The parallel grouping method that preferentially traverses the reference group is used for grouping, and the steps are as follows: For the groups where the m bit cells in the reference group are located, the jth in-group bit cell of each group is found in turn: For the jth in-group bit cell of each group, traverse the bit cells in the reference group: for the ith bit cell in the reference group, if a bit cell with the same power-on value and not grouped is found in the ballot box group, then the bit cell is grouped into the group where the ith bit cell in the reference group is located as the jth in-group bit cell of the group; otherwise, the first ungrouped bit cell in the ballot box group is grouped into the group where the ith bit cell in the reference group is located as the jth bit cell of the group; where j ∈ [2, k], i ∈ [1, m].
4. The hardware fingerprint extraction method based on SRAM PUF according to claim 1, wherein The serial grouping method that preferentially traverses the reference group is used for grouping, and the steps are as follows: Traverse the bit cells in the reference group in turn: For the ith bit cell in the reference group, if k - 1 bit cells with the same power-on value and not grouped as it are found in the ballot box group in turn, then the k - 1 bit cells are grouped into the group where the ith bit cell in the reference group is located; Otherwise, the traversal of the reference group ends, and the ith to mth bit cells in the reference group are used as the only in-group bit cells respectively to complete the grouping, and m groups are obtained; where i ∈ [1, m].
5. The hardware fingerprint extraction method based on SRAM PUF according to claim 1, characterized in that The method of preferentially traversing the ballot box group is also used for grouping, and the steps are as follows: Traverse the bit units in the ballot box group in sequence: For the g-th ungrouped bit cell in the ticket bin group with a power-on value of b g If a bit cell with a power-on value of b g is found in the reference group and the number of bit cells within the group is less than k, then the g-th bit cell in the ticket bin group is grouped into the group where the bit cell in the reference group is located; otherwise, the traversal of the ticket bin group ends, and the g-th to the (n - m)-th ungrouped bit cells in the ticket bin group are sequentially grouped into the groups in the reference group where the number of bit cells within the group is less than k to obtain m groups; where g ∈ [1, n - m], and the value of b g is 0 or 1.
6. The hardware fingerprint extraction method based on SRAM PUF according to claim 1, characterized in that In the registration stage or the reconstruction stage, the steps for performing majority decision on each group are as follows: Perform a decision on each group. If the number of bit units in the group is k, when at least (k + 1) / 2 bit units have a powered-on value of 1, the decision result is 1; otherwise, it is 0. If the number of bit units in the group is 1, the powered-on value of the bit unit is used as the decision result; Perform majority decision on each group separately to obtain a decision result sequence of m bit units.
7. A hardware fingerprint extraction system based on SRAM PUF, characterized in that, It includes a SRAM array, a grouper, and a majority decision maker; The SRAM array includes a plurality of bit units, and is used to obtain the powered-on values of each bit unit through power-on in the registration stage and the reconstruction stage; The grouper is used to power on through the SRAM PUF in the registration stage, and read the addresses and corresponding powered-on values of the bit units in the SRAM array at the moment of power-on; And group the bit units of the SRAM array according to the powered-on values of the bit units in the SRAM array. Among them, the steps of grouping the bit units in the SRAM array are as follows: Select m bit units corresponding to m powered-on values that meet the fractional Hamming weight requirement in the SRAM array as the reference group, and the remaining n - m bit units as the ballot box group; where m is the number of bits of the hardware fingerprint to be extracted, and n is the total number of bit units in the SRAM array; According to each bit unit in the reference group, at most k - 1 bit units in the ballot box group that have the same powered-on value as the corresponding bit unit in the reference group and have not been grouped are grouped with the corresponding bit unit in the reference group to obtain m groups; the remaining bit units in the ballot box group that have different powered-on values and have not been grouped are grouped into groups with less than k bit units, or the remaining ungrouped bit units in the ballot box group are not grouped into groups to complete the grouping; where k is the maximum number of bit units in each group; The majority decision maker is used to perform majority decision on each group according to the powered-on values of the bit units in the group in the registration stage, and use the decision result sequence as the hardware fingerprint; in the reconstruction stage, it powers on again through the SRAM PUF, obtains the powered-on values of the bit units of the stored groups in the registration stage according to the powered-on values of the bit units at the same addresses in the SRAM array read at the moment of power-on, performs majority decision on each group to obtain a decision result sequence, and then corrects the decision result sequence, and uses the corrected sequence as the hardware fingerprint reconstructed in the reconstruction stage.
8. The hardware fingerprint extraction system based on SRAM PUF according to claim 7, wherein The maximum value k of the number of bit units in each group is an odd number.
Citation Information
Patent Citations
SRAM-PUF-based fuzzy safe box authentication method
CN106941400A