A PUF security testing method based on multimodal learning
Through the PUF security testing method based on multimodal learning, the multimodal model is trained on the data set using text-image to evaluate the PUF's anti-modal attack capabilities, and the existing PUF's security risks in the face of machine learning modeling and side channel attacks are solved, and the effective evaluation of PUF's security performance is achieved.
Patent Information
- Application Number
- CN202410531418.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-04-29
AI Technical Summary
When facing machine learning modeling and side channel attacks, existing PUFs lack effective anti-modeling capability evaluation methods, resulting in security risks in practical applications.
Using a PUF security testing method based on multimodal learning, a text-image-pair dataset is composed by input excitation and obtaining the PUF response and power-side channel spectrum images, and a text-image-pair dataset is trained to evaluate the security of PUF.
This method can effectively evaluate the PUF's anti-modeling attack capability, provide a basis to verify the security performance of PUF, and reduce the security risks caused by insufficient PUF security.
Smart Images

Figure CN118316624B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a PUF security testing method based on multimodal learning. Background Art
[0002] With the advent of the era of Internet of Everything and the popularization of artificial intelligence technology, the increasingly complex application scenarios and emerging attack means have made the security protection of information systems more vulnerable. How to ensure the confidentiality, integrity and availability of information systems has become a key concern for researchers, and accordingly, a variety of security solutions have emerged. As a new type of hardware security mechanism, the Physical Unclonable Function (PUF) has characteristics such as anti-tampering, key-free storage, and lightweight, providing a PUF-based hardware security protection solution for applications such as identity authentication, privacy protection, trusted execution, and blockchain. With the continuous increase in research popularity, PUF has gradually become an important branch of research in the field of hardware security and a typical representative of physical cryptography technology.
[0003] PUF is a type of circuit structure that extracts the mismatch parameters introduced by the device manufacturing process. Affected by random variables such as temperature, pressure, and voltage during the manufacturing process, even chips produced under the same conditions inevitably have random differences in circuit physical parameters. These subtle random differences do not affect the function, but can be utilized as the inherent characteristics of the chip in the security field. PUF extracts the inherent parameter differences inside the chip (such as electrical characteristics such as internal wire delay and gate-level voltage in the chip) and presents them in the form of excitation response. The user inputs an excitation to the PUF, and the PUF outputs a response, as Figure 2 shown. Since these differences are random and cannot be eliminated by the manufacturing process, even if the chip manufacturer uses the same process, it is impossible to replicate a chip with the same internal parameters. Therefore, PUF has the characteristic of physical unclonability. PUF relies on the own parameters of the physical entity to provide a unique identity identifier externally, realizing key-free storage and effectively solving the problem of key leakage.
[0004] According to the relationship between the scale of the externally provided Challenge Response Pair (CRP) and the number of basic hardware units, PUFs can be divided into Weak PUFs and Strong PUFs. Weak PUFs can provide a relatively small number of CRPs externally, usually showing a linear relationship with the number of hardware basic components of the PUF, and are generally used as hardware keys. Common Weak PUFs include SRAM PUF, DRAM PUF, Butterfly PUF, Glitch PUF, and Ring Oscillator PUF (RO PUF), etc. Strong PUFs can provide a large number of CRPs based on their high entropy content, and the number of their CRPs shows an exponential relationship with the number of hardware basic components, and is considered to be able to replace traditional security mechanisms. Common Strong PUFs include Arbiter PUF, XOR Arbiter PUF (XOR APUF), Multiplexer-based PUF (MPUF), and Interpose PUF (iPUF), etc.
[0005] Although PUFs were initially positioned as physically unclonable, a large number of subsequent theoretical analyses and experimental studies have shown that Strong PUFs are vulnerable to modeling attacks and pose great security risks. After obtaining a large number of CRPs, the PUF model trained by the attacker using machine learning algorithms can accurately simulate the excitation response behavior of the PUF entity, as Figure 3 shown. Although designers have continuously proposed new Strong PUF designs to counter machine learning modeling attacks, with the application of side-channel analysis in the field of PUF modeling, the severe security situation faced by PUFs has been further exacerbated.
[0006] Regarding the threats of machine learning modeling and side-channel attacks, researchers have continuously designed and introduced complex PUF structures resistant to modeling, and certain effects have been achieved. However, due to the lack of powerful analysis methods and correct evaluation processes for anti-modeling capabilities, the newly proposed complex-structured PUFs have not undergone comprehensive anti-modeling capability analysis and evaluation. Often, designers select some traditional machine learning modeling methods for testing and verification, believing that they have sufficient security. However, they will subsequently be proven by other studies to be unable to withstand machine learning modeling or side-channel attacks. Even more seriously, some PUFs have been proven to lack sufficient security after being mass-produced and put into market use, which may bring huge security risks to enterprises. For example, in 2015, Becker used power analysis combined with the Covariance Matrix Adaptation Evolution Strategy (CMA-ES) to analyze the internal parameters of a PUF on an RFID chip, and simulated the response behavior of the PUF with an accuracy of 98%, cracking the security mechanism of the chip. Summary of the Invention
[0007] The present invention aims to provide a method for testing the security of PUFs based on multimodal learning, so as to provide a basis for whether the security performance of PUFs meets the requirements.
[0008] A method for testing the security of PUFs based on multimodal learning provided by the present invention includes:
[0009] Input a number of stimuli to the PUF to be tested, and obtain a number of stimulus-response pairs composed of the responses of the PUF to be tested under each stimulus;
[0010] Step 2: For each stimulus-response pair, obtain the power consumption side-channel spectrum image during the current operation of the PUF to be tested;
[0011] Step 3: Take each stimulus-response pair of the PUF to be tested as text information, and take the power consumption side-channel spectrum image corresponding to the stimulus-response pair as image information to form a text-image pair dataset;
[0012] Step 4: Use the text-image pair dataset to train a multimodal model to obtain a PUF security test model;
[0013] Step 5: Input the stimulus to be tested of the PUF to be tested into the PUF security test model to obtain the response of the PUF to be tested.
[0014] Furthermore, the multimodal model includes a text encoder and an image encoder; the text encoder is used to generate text feature vectors of the input text information; the image encoder is used to generate image feature vectors of the input image information.
[0015] Furthermore, the multimodal model adopts the CLIP model.
[0016] Advantages of the present invention:
[0017] By testing the security of PUF from the perspective of multimodal data, the present invention can provide a basis for the anti-modeling attack ability of PUF. Description of the drawings
[0018] Figure 1 It is a schematic flowchart of a method for testing the security of PUF based on multimodal learning provided by an embodiment of the present invention;
[0019] Figure 2 It is a schematic concept diagram of PUF;
[0020] Figure 3 It is a schematic diagram of a modeling attack on PUF;
[0021] Figure 4 It is a schematic diagram of a traditional side-channel attack. Specific implementation manners
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0023] The physical security (i.e., achieving security) of PUF is not equivalent to the theoretical security during circuit design. Many theoretically secure PUF designs often introduce side-channel vulnerabilities during implementation. In addition to the normal excitation-response behavior, the specific implementation of PUF may generate information leakage in the form of observable physical characteristics during operation. For example, the current change in the power supply pin of the chip where PUF is located, the electromagnetic radiation around the chip where PUF is located, or even the reliability information obtained by measuring the response to the same excitation multiple times, etc. A large amount of information about PUF parameters and structures is included in these side-channel leaks. Although PUF is considered to be able to resist physical attacks, research shows that most of the claimed secure PUFs do not have side-channel security.
[0024] Side-channel analysis obtains relevant information about the internal parameters and structure of the PUF based on the analysis and processing of the side-channel leakage information of the PUF. In the field of PUF modeling, except for a few methods such as photon emission analysis that can be used alone, most side-channel analysis methods are combined with machine learning algorithms to form a machine learning side-channel hybrid modeling attack. Formally analyzed, the side-channel model of the PUF can only output side-channel information and cannot be directly used to predict responses. Therefore, traditional PUF side-channel modeling attacks all adopt an indirect mode. Through machine learning algorithms, they are trained based on the dataset composed of stimuli and side-channel leakage information, fitting the internal parameters of the PUF and substituting them into the mathematical model of the PUF, and finally the mathematical model predicts the responses. Figure 4 shows the typical process of traditional machine learning modeling attacks.
[0025] Multimodal learning refers to building a model that enables a machine to learn information from multiple modalities and realizes the communication and conversion of information among various modalities. Therefore, when a research problem or dataset contains multiple such modalities, it is described as multimodal. The modalities studied in this invention are: text and image.
[0026] Since it is difficult for machine learning modeling attacks to model PUFs with complex structures, side-channel analysis methods in cryptography are introduced into the field of PUF modeling. Among side-channel analysis methods, power consumption analysis is relatively easy to implement. Therefore, the power consumption side-channel attack has become the most concerned PUF side-channel modeling attack method. However, when performing mathematical modeling on the power consumption side-channel and discretizing the voltage for machine learning or neural network modeling training, a large amount of information will be lost. Therefore, this invention proposes a modeling attack method based on multimodal learning.
[0027] As Figure 1 shown, a PUF security testing method based on multimodal learning provided by an embodiment of this invention specifically includes the following steps:
[0028] S101: Input several stimuli to the PUF to be tested, and obtain the responses of the PUF to be tested under each stimulus to form several stimulus-response pairs;
[0029] Specifically, in this embodiment, by continuously inputting stimuli to the PUF to be tested, a large number of stimulus-response pairs can be collected. In order to better learn the parameters of the PUF to be tested, the number of stimulus-response pairs in this embodiment is set in the order of millions.
[0030] S102: For each stimulus-response pair, obtain the power consumption side-channel spectrum image during the current operation of the PUF to be tested;
[0031] Specifically, during normal operation or an attack, the bit positions of the internal structure of the PUF will change, such as flipping, according to different excitations, thereby generating voltage pulse spikes, which in turn lead to the leakage of voltage and power consumption side-channel information. During the operation of the PUF, the power consumption side-channel information of the PUF is collected in the form of a spectrum.
[0032] S103: Use each excitation response pair of the PUF under test as text information, and use the power consumption side-channel spectrum image corresponding to the excitation response pair as image information to form a text-image pair dataset.
[0033] Specifically, the multi-modal learning technology is used to model and attack the PUF. The excitation response pair (CRP) of the PUF is a binary value, which is a text modality, and the spectrum of the power consumption side-channel is an image modality.
[0034] By continuously inputting excitations to the PUF and collecting the power consumption side-channel spectrum image during the process of collecting responses, a large number of text-image pairs can be obtained.
[0035] S104: Use the text-image pair dataset to train the multi-modal model to obtain a PUF security test model.
[0036] Specifically, the core idea of multi-modal learning is to map images and text to the same feature space. The multi-modal model consists of a text encoder and an image encoder. The text encoder is used to map text to the text feature space, and the image encoder is used to map images to the image feature space. The text-image pairs with given response labels are used to train the multi-modal model. After training the multi-modal model, the model's effect realizes the ability to map similar images and text to the same feature space. At this time, the PUF security test model can reflect the internal attribute parameters of the PUF under test.
[0037] In this embodiment, the multi-modal model uses the CLIP model.
[0038] S105: Input the excitation to be tested of the PUF under test into the PUF security test model to obtain the response of the PUF under test.
[0039] Specifically, during the training phase, the power consumption side-channel spectrum image is used for the multi-modal model to better learn the internal attribute parameters of the PUF under test. During the test phase, only the excitation to be tested needs to be input to obtain the predicted response. When predicting the PUF response, the PUF security test model maps the excitation of the PUF into a feature vector and predicts the PUF response and the corresponding prediction accuracy rate according to the feature vector to achieve the effect of modeling and attacking the PUF.
[0040] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A PUF security testing method based on multimodal learning, characterized in that: include: Step 1: Input several stimuli to the PUF to be tested, and obtain the response of the PUF to be tested under each stimulus to form several stimulus-response pairs; Step 2: For each stimulus-response pair, obtain the power consumption side channel spectrum image during the current operation of the PUF under test; Step 3: Take each stimulus response pair of the PUF to be tested as text information, and take the power consumption side channel spectrum image corresponding to the stimulus response pair as image information to form a text-image pair data set; Step 4: Use the text-image pair dataset to train the multimodal model to obtain the PUF security test model; Step 5: Input the stimulus to be tested of the PUF to be tested into the PUF security test model to obtain the response of the PUF to be tested.
2. According to claim 1, a PUF security testing method based on multimodal learning is characterized in that: The multimodal model includes a text encoder and an image encoder; the text encoder is used to generate a text feature vector of input text information; the image encoder is used to generate an image feature vector of input image information.
3. A PUF security testing method based on multimodal learning according to claim 2, characterized in that: The multimodal model adopts the CLIP model.
Citation Information
Patent Citations
Multi-mode reconfigurable physical unclonable function circuit and method thereof
CN113515783A
Identification authentication method and system based on physical unclonable hardware
CN115694905A