SRAM PUF key extraction method based on correlation judgment
By adopting two-stage error correction method based on relevant judgments and random cyclic shift coding in SRAM PUF, the problems of SRAM PUF stability and security are solved, and long-term stable and high-security key extraction is achieved.
Patent Information
- Application Number
- CN202510510113.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2045-04-23
AI Technical Summary
How to quickly register and achieve long-term and stable SRAM PUF, reduce information leakage caused by PUF registration or update process, and ensure the security of PUF.
Using the SRAM PUF key extraction method based on relevant judgments, through a two-level error correction structure, the outer layer encoding adopts random cyclic shift to hide information, the inner layer encoding uses linear encoding to correct errors, and dynamically updates auxiliary data to reduce information leakage.
It realizes the stable output of SRAM PUF, reduces the risk of information leakage, and improves the security and long-term reliability of PUF.
Smart Images

Figure CN120050039A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a SRAM PUF key extraction method based on correlation judgment. Background Art
[0002] As IoT devices are widely used in biomedicine, automotive electronics, aerospace, and mobile infrastructure, information security issues have become a focus of attention. Physically Unclonable Function (PUF) uses the physical deviation and unclonability of device manufacturing to perform key generation and security authentication, meeting the security requirements of lightweight cryptographic devices.
[0003] Due to process deviations, the initial data of different individual static random access memories (SRAMs) after power-on are randomly distributed. The initial data of the same individual after multiple power-ons have a certain degree of stability, similar to human fingerprint information, which can be used to implement SRAM PUF. SRAM PUF output (also called response) is often used in information security protection applications such as generating keys or protecting keys.
[0004] The initial data of SRAM after power-on is easily affected by factors such as voltage and temperature, resulting in instability, and drifting due to aging and other reasons. Information security protection applications require that the SRAM PUF output is sufficiently stable, otherwise subsequent related cryptographic function operations cannot be performed, which in turn affects the normal operation of the system. In order to achieve stable output of PUF, an error correction mechanism is required, such as the commonly used SRAM PUF generation structure based on Code-offset or Syndrome. In order to generate error correction data, SRAM PUF needs to be registered before application. Registration needs to be performed in a controlled environment. Based on error correction coding technology, auxiliary data that can be publicly stored is generated according to the SRAM initial data and PUF output. When applied, the auxiliary data is used to correct the noise of the SRAM initial data and restore the PUF output.
[0005] How to quickly register and use less computing resources, an appropriate amount of SRAM and auxiliary data resources to achieve long-term stable SRAM PUF, while reducing information leakage caused by auxiliary data during PUF registration or update process and ensuring the security of PUF is the key to the secure application of PUF lightweight cryptographic devices. Summary of the invention
[0006] The present invention provides a SRAM PUF key extraction method based on correlation decision to solve at least one of the above problems.
[0007] The present invention provides a SRAM PUF key extraction method based on correlation judgment, the method at least includes an initial registration phase and a reconstruction phase, wherein: Initial registration phase: Step 101, SRAM is powered on, PUF variables are configured and initialized, wherein the variables at least include: Configure the data block upper limit I, the number of valid data blocks N, the number of data block bits K and the threshold T; initialize the data block number i to 0, all I-bit auxiliary data HelpDataIndex to 0, and the valid data block temporary sequence number n to 0; Step 102, calculating the XOR of an SRAM data block and its cyclic shifts of different points, and searching for the number of cyclic shift points and the number of negatively correlated bits when the data block has the maximum negative correlation; Step 103, selecting N data blocks whose maximum number of negatively correlated bits is greater than a set threshold, and taking the data blocks as valid data blocks, the number of the valid data blocks is N; Step 104, using N bits to hide random numbers to respectively control whether the N valid data blocks are cyclically shifted according to the number of cyclic shift points when the N valid data blocks have the maximum negative correlation; Step 105, a random number generator generates a PUF output random number, linearly encodes it, and outputs the encoding result; Step 106, the encoding result and the hidden random number are XORed to obtain auxiliary data; Reconstruction phase: Step 201, the SRAM is powered on, variables are initialized, and the auxiliary data is read, and a valid data block is selected according to the auxiliary data; Step 202, using the valid data block and the auxiliary data, restore the approximate random number of the hidden random number; Step 203, XOR the approximate random number with the auxiliary data to obtain a codeword before error correction; Step 204: perform linear coding error correction on the codeword to restore the PUF output random number.
[0008] Furthermore, the step 102 includes: The addresses are accumulated sequentially to read K bits of SRAM data. The jth bit of the i-th data block is represented by D-SRAM[i][j], where i∈[0,I-1], j∈[0,K-1]; For the i-th data block D-SRAM[i] of K bits of data, in the range of k∈[1,K-1], calculate R[k]=numone(D-SRAM[i] (D-SRAM[i]>>k)); Among them: “>>” means circular right shift, " indicates bit-wise XOR calculation, "numone" indicates the number of bits counted as 1; Calculate MaxR[n]=max(R[1:K-1]), MaxIndex[n]=maxindex(R[1:K-1]); Here, "max" means selecting the maximum value from R[1] to R[K-1], and "maxindex" means the position of the maximum value. If there are multiple positions with the same maximum value, the value with the smallest subscript from R[1] to R[K-1] is selected.
[0009] Furthermore, the step 103 includes: If MaxR[n]≥T in step 102, then HelpDataIndex[i]=1, and the nth K-bit valid data block HelpData0[n]=D-SRAM[i] is set, and n is incremented by 1; If n≥N-1, go to step 104, otherwise, i is incremented by 1, and if i≥I, return registration failure, otherwise go to step 102.
[0010] Furthermore, the step 104 includes: Generate an N-bit hidden random number R0, where each bit is represented by R0[i], i∈[0,N-1]; If R0[i]=1, i∈[0,N-1], then HelpData0[i] is circularly shifted right, that is: HelpData0[i]=HelpData0[i]>>MaxIndex[i], and the auxiliary data HelpData0, a total of N×K bits, and HelpDataIndex, a total of I bits, are stored.
[0011] Furthermore, the steps 105 and 106 include: Step 105: A random number generator generates an M-bit PUF output random number R1, which is linearly encoded. Get an N-bit codeword W; Step 106, W is XORed with R0 and stored as auxiliary data HelpData1, which is N bits in total. At the same time, the upper limit I of the configuration data block, the number of valid data blocks N, the number of data block bits K and the threshold T are stored as auxiliary data.
[0012] Furthermore, the step 201 includes: Step 201, SRAM is powered on, PUF variables are initialized, auxiliary data is read, SRAM data of I data blocks are read according to consecutive addresses, and N K-bit valid data blocks are selected according to HelpDataIndex, which are represented by R-SRAM[i], i∈[0,N-1].
[0013] Furthermore, the step 202 includes: Extract the i-th K-bit data HelpData0[i] of the auxiliary data HelpData0, calculate MaxR[i] and MaxIndex[i] corresponding to HelpData0[i] according to step 102, and further calculate: G0[i]= numone(R-SRAM[i] HelpData0[i]); G1[i]= numone((R-SRAM[i]>>MaxIndex[i]) HelpData0[i]); According to the following decision expression, the approximate random number R0'[i] of the hidden random number R0[i] is restored bit by bit, i∈[0,N-1]: .
[0014] Furthermore, the steps 203 and 204 include: Step 203, XOR HelpData1 with R0' to obtain W'; Step 204, linear encoding , correct W' to get W, and restore the M-bit PUF output random number R1.
[0015] Furthermore, the method further comprises applying process auxiliary data update: Step 301, determine whether to update by a random number to control the update frequency; Step 302, locating the bit with error in the code word W' before error correction by XOR calculation; Step 303: update the auxiliary data corresponding to the error bit in W' according to step 102 and step 104. Before updating, a random number is used to determine whether to update again to control the updating frequency.
[0016] Furthermore, the application process auxiliary data update specifically includes: Step 301, generate a temporary random number and convert it into a probability value AdjIndex0 between [0,1), and compare it with the update probability threshold AdjP0 set in the initial registration stage. If AdjIndex0≥AdjP0, exit, otherwise execute step 302; Step 302, reconstruction phase After step 204, determine whether the random number R1 output by the M-bit PUF is accurate. If it is wrong, exit. If it is correct, XOR W and W' to obtain ER0'; Step 303, the loop is executed until i∈[0,N-1] is traversed. If ER0'[i]=0, it means that there is no error in the R0'[i] data, and the next loop is executed. Otherwise, a temporary random number is generated and converted into a probability value AdjIndex1 between [0,1), and compared with the update probability threshold AdjP1 set in the initial registration stage. If AdjIndex1≥AdjP1, the next loop is executed. Otherwise, the R-SRAM[i] data block is processed according to steps 102 and 104. If the corresponding MaxR[i]≥T, the HelpData0[i] data is updated.
[0017] Compared with the prior art, the advantages of the present invention are: The present invention designs a SRAM PUF key extraction method based on correlation judgment, which is based on two-level error correction. The outer layer encoding uses random cyclic shift to "hide" information and uses correlation judgment to restore information, thereby ensuring the security of SRAM PUF.
[0018] The present invention "hides" the random number R0 by random cyclic shift, and will not cause a significant decrease in PUF information security due to the increase of outer layer data. Therefore, when implemented, the error correction performance can be improved by appropriately increasing the length of the outer layer error correction data.
[0019] The present invention can dynamically and partially update the auxiliary data HelpData0 during long-term use, and can effectively control the information leakage caused by the update, greatly reducing the maintenance and guarantee requirements and improving the long-term reliability.
[0020] It can be seen that compared with the prior art, the present invention has outstanding substantive features and significant progress, and the beneficial effects of its implementation are also obvious. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 A schematic diagram of dynamic screening and hiding control of SRAM-PUF negatively correlated data blocks in the registration phase of an SRAM PUF key extraction method based on correlation judgment of the present invention; Figure 2 A schematic diagram of linear encoding and auxiliary data generation in the registration phase of an SRAM PUF key extraction method based on correlation judgment of the present invention; Figure 3 A schematic diagram of the reconstruction phase of a SRAM PUF key extraction method based on correlation judgment of the present invention; Figure 4 The present invention is a flow chart of auxiliary data update in the application process of an SRAM PUF key extraction method based on correlation judgment. DETAILED DESCRIPTION
[0022] In order to make the technical solution and advantages of the present invention more clear, the technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings.
[0023] The basic idea of the present invention is: based on a two-level error correction structure, the inner error correction can use commonly used linear error correction coding, and the outer error correction uses random cyclic shift of block data to "hide" information and restore information through relevant judgment. The outer error correction first divides the continuous address SRAM data into data blocks, and then generates a random number to be "hidden" with the same number of bits as the number of SRAM data blocks. Each random number bit corresponds to a data block. Whether to cyclically shift the data block is determined according to the random number bit value. In order to improve the error correction performance, the number of cyclic shift points selects the position with the maximum negative correlation between the data block and the cyclic shift data block, and the "hidden" random number is output to the inner error correction to protect the PUF output random number. The inner error correction first linearly encodes the PUF output random number. The length of the encoded data is the same as the length of the "hidden" random number. The two are XORed and stored as auxiliary data.
[0024] Figure 1 The present invention is a schematic diagram of dynamic screening and hiding control of SRAM-PUF negative correlation data blocks in the registration phase of an SRAM PUF key extraction method based on correlation judgment.
[0025] Figure 2 The present invention is a schematic diagram of linear encoding and auxiliary data generation in the registration phase of an SRAM PUF key extraction method based on correlation judgment.
[0026] Figure 3 The figure is a schematic diagram of the reconstruction phase of a SRAM PUF key extraction method based on correlation decision of the present invention.
[0027] like Figure 1-3 As shown, the method of the present invention at least includes an initial registration phase and a reconstruction phase, wherein: Initial registration phase: Step 101, SRAM is powered on, PUF variables are configured and initialized, wherein the variables at least include: Configure the data block upper limit I, the number of valid data blocks N, the number of data block bits K and the threshold T; initialize the data block number i to 0, all I-bit auxiliary data HelpDataIndex to 0, and the valid data block temporary sequence number n to 0.
[0028] It should be noted that HelpDataIndex[i] represents the i-th bit, and its value indicates whether the i-th data block is available, i∈[0,I-1].
[0029] K represents the number of bits in a data block. For convenience, an integer multiple of 8 is generally selected, and a suitable threshold T is set according to K.
[0030] Step 102, calculate the exclusive OR of an SRAM data block and its cyclic shifts of different points, and search to obtain the number of cyclic shift points and the number of negatively correlated bits when the data block has the maximum negative correlation.
[0031] The step 102 includes: The addresses are accumulated sequentially to read K bits of SRAM data. The jth bit of the i-th data block is represented by D-SRAM[i][j], where i∈[0,I-1], j∈[0,K-1]; For the i-th data block D-SRAM[i] of K bits of data, in the range of k∈[1,K-1], calculate R[k]=numone(D-SRAM[i] (D-SRAM[i]>>k)); Among them: “>>” means circular right shift, " indicates bit-wise XOR calculation, "numone" indicates the number of bits counted as 1; Calculate MaxR[n]=max(R[1:K-1]), MaxIndex[n]=maxindex(R[1:K-1]); "max" indicates the maximum value among R[1]~R[K-1], and "maxindex" indicates the position of the maximum value. If there are multiple positions with the same maximum value, the value with the smallest index among R[1]~R[K-1] is selected. For example, if R[1] and R[3] have the same maximum value, R[1] is selected.
[0032] Step 103: select N data blocks whose maximum number of negatively correlated bits is greater than a set threshold, and use the data blocks as valid data blocks. The number of the valid data blocks is N.
[0033] The step 103 comprises: If MaxR[n]≥T in step 102, then HelpDataIndex[i]=1, and the nth valid data block HelpData0[n]=D-SRAM[i] is set, and n is incremented by 1; If n≥N-1, go to step 104, otherwise, i is incremented by 1, and if i≥I, return registration failure, otherwise go to step 102.
[0034] Step 104: Use N bits to hide random numbers to control whether the N valid data blocks are cyclically shifted according to the number of cyclic shift points when the N valid data blocks have the maximum negative correlation.
[0035] The step 104 comprises: Generate an N-bit masked random number R0, which is an intermediate variable and is not stored.
[0036] Each bit is represented by R0[i], i∈[0,N-1]; If R0[i]=1, i∈[0,N-1], then HelpData0[i] is circularly shifted right, that is: HelpData0[i]=HelpData0[i]>>MaxIndex[i], and the auxiliary data HelpData0, a total of N×K bits, and HelpDataIndex, a total of I bits, are stored.
[0037] Step 105: A random number generator generates a PUF output random number, linearly encodes it, and outputs the encoding result.
[0038] The step 105 comprises: Step 105: A random number generator generates an M-bit PUF output random number R1, which is linearly encoded. Get the N-bit codeword W.
[0039] Step 106: XOR the linear encoding result with the hidden random number to obtain auxiliary data.
[0040] The step 106 comprises: Step 106, W is XORed with R0 and stored as auxiliary data HelpData1, which has N bits in total.
[0041] Reconstruction phase: Step 201, the SRAM PUF is powered on, variables are initialized, and the auxiliary data is read, and a valid data block is selected according to the auxiliary data.
[0042] The step 201 includes: Step 201, the SRAM is powered on, the PUF variables are initialized, and the auxiliary data is read. The SRAM data of I data blocks are read according to the continuous address, and N K-bit valid data blocks are selected according to HelpDataIndex, which are represented by R-SRAM[i], i∈[0,N-1].
[0043] Step 202: Use the valid data block and the auxiliary data to restore the approximate random number of the hidden random number.
[0044] The step 202 includes: Extract the i-th K-bit data HelpData0[i] of the auxiliary data HelpData0, calculate MaxR[i] and MaxIndex[i] corresponding to HelpData0[i] according to step 102, and further calculate: G0[i]= numone(R-SRAM[i] HelpData0[i]); G1[i]= numone((R-SRAM[i]>>MaxIndex[i]) HelpData0[i]); Restore the approximate random number R0'[i] of the hidden random number R0[i] bit by bit, i∈[0,N-1], and restore R0'[i] according to the following decision expression:
[0045] Step 203, XOR the approximate random number with the auxiliary data to obtain a codeword before error correction.
[0046] The step 203 includes: Step 203, XOR HelpData1 with R0' to obtain W'; Step 204: perform linear coding error correction on the codeword to restore the PUF output random number.
[0047] The step 204 includes: Step 204, linear encoding , correct W' to get W, and restore the M-bit PUF output random number R1.
[0048] It should be noted that the outer error correction of the method proposed in the present invention is essentially a repetition code, but the effective repetition code length of each data block is MaxR[i], which is an even number between [T, K]. In step 104, if R0[i]=1, the data block HelpData0[i] is cyclically shifted to the right; if R0[i]=0, the data block remains unchanged. For example, if the data block HelpData0[i]=2'b10111001 is input from step 102, then MaxIndex[i]=2, MaxR[i]=6, if R0[i]=0, the output of step 104 is: 2'b10111001; if R0[i]=1, the output of step 104 is: 2'b01101110. In the reconstruction step 202, let the corresponding R-SRAM[i] be expressed as 2'b vvzvzvvv, the number of "v" is MaxR[i]=6, and the corresponding bit is the effective repeated coded data of the data block. When the reconstruction step 202 is related to the calculation, the bit corresponding to "z" in R-SRAM[i] changes the values of G0[i] and G1[i] synchronously regardless of whether there is a bit error, and has no effect on the judgment result. Only the bit corresponding to "v" in R-SRAM[i] has an effect on the judgment result. When HelpData0 and R-SRAM are cyclically shifted and matched, the bit corresponding to "v" is positively correlated, otherwise it is negatively correlated. Therefore, the error correction capability of each data block depends not only on the stability of the SRAM data, but also on the MaxR[i] value of each data block. In order to ensure the error correction capability of each data block, step 102 screens the SRAM data blocks and selects the data blocks with MaxR[i]≥T. The screening rate can be analyzed according to the asymptotic uniformity theory under the assumption that each bit of the SRAM data is independently and identically distributed. In practical applications, the effective data block ratio N / I can be selected in the range of 80~90%. For example, when K=32 bits, T=12 can be selected.
[0049] The method of step 102 of the present invention can be applied alone to the SRAM data screening of common SRAMPUF generation structures such as Code-offset or Syndrome, and the screened data is close to uniform distribution, which can ensure the information security of PUF when used for PUF output. In step 102, DataIndex[i]=D-SRAM[i] is calculated. (D-SRAM[i]>>MaxIndex[i]), and select D-SRAM[i][j] corresponding to DataIndex[i][j]=1 according to the K-bit value of DataIndex[i] for generating PUF. For example, D-SRAM[i]=2'b10111001, the data after cyclic right shift of 2 bits is 2'b01101110, at this time DataIndex[i]=2'b 11010111, and the D-SRAM[i] data is discarded, that is, the bits at the positions of the two x in 2'b10x1x001, and the two 1s are discarded. The remaining data is: 101001, and the 0 and 1 bits are strictly equal. Compared with the common selection method based on "01" or "10", the number of original data points and entropy value are retained to the maximum extent. Under the condition that the original data is independent and identically distributed, the information security of SRAM PUF can be ensured. When resources permit, each data block can randomly select a number from [1, K-1] to replace MaxIndex[i] to filter data. Although this will reduce the effective data rate, it can better guarantee the entropy value of the remaining data.
[0050] The basic principle of using the method of step 102 of the present invention alone for data screening is based on the correlation between the original sequence and the cyclic sequence. In applications where security requirements are high, SRAM data screening based on random scrambling can be used according to the idea of the above method. The specific method is: for the i-th data block D-SRAM[i] of K bits, a method similar to Fisher-Yates Shuffle is used to scramble D-SRAM[i] bit by bit, represented by F-SRAM[i], and DataIndex[i]=D-SRAM[i] is calculated. F-SRAM[i], and select D-SRAM[i][j] corresponding to DataIndex[i][j]=1 according to the K-bit value of DataIndex[i]. The scrambled data block has better randomness. The selected data is equivalent to a random sampling of the original data block D-SRAM[i]. For example: D-SRAM[i]=2'b10111001, of which 5 bits are 1 and 3 bits are 0. Assume that after random scrambling, a sequence F-SRAM[i]= 2'b01011101 with 5 bits of 1 and 3 bits of 0 is obtained. At this time, DataIndex[i]= 2'b11100100, and the D-SRAM[i] data is discarded, that is, the bits at the positions of the 4 xs in 2'b101xx0xx. The remaining data is: 2'b1010. Compared with the cyclic shift and related judgment methods, the remaining data after discarding is relatively small, but the entropy value of the remaining data can be better guaranteed.
[0051] During the random cyclic shift in the registration phase, step 104 does not use the random sequence R0, but directly uses the PUF output random number R1 output after inner encoding W. At this time, HelpData1 does not need to be stored, and the auxiliary data storage requirements are reduced, but the information security is also reduced.
[0052] When storage resources allow, the MaxIndex data calculated in step 102 may be stored as auxiliary data to reduce the computational complexity of the reconstruction process.
[0053] For high information security and high reliability application scenarios, the SRAM data can be screened first to remove unstable bits after power-on. According to literature data, about 80% of SRAM data has a very stable initial value after power-on. Stable data units can be screened out through multiple power-ons. Given the randomness of the unstable bit distribution, the discarding process is similar to random sampling of the original SRAM data, which can effectively reduce the correlation of SRAM data. Therefore, it can effectively improve information security and reliability at the same time. The cost is the need to add an additional set of auxiliary data similar to HelpIndex to indicate whether a certain bit is used.
[0054] Figure 4 The present invention is a flow chart of auxiliary data update in the application process of an SRAM PUF key extraction method based on correlation judgment.
[0055] like Figure 4 As shown, the application process assists data update: Step 301, determining whether to update by using the random number to control the update frequency.
[0056] The step 301 specifically includes: Step 301, generate a temporary random number, and convert it into a probability value AdjIndex0 between [0,1), and compare it with the update probability threshold AdjP0 set in the initial registration stage (AdjP0=1 means no auxiliary data update, AdjP0=0 means update every time), if AdjIndex0≥AdjP0, exit, otherwise execute step 302; Step 302: locate the bit with error in the code word W' before error correction by XOR calculation.
[0057] The step 302 specifically includes: Step 302, reconstruction phase After step 204, determine whether the random number R1 output by the M-bit PUF is accurate. If it is wrong, exit. If it is correct, XOR W and W' to obtain ER0'.
[0058] Step 303: update the auxiliary data corresponding to the error bit in W' according to step 102 and step 104. Before updating, a random number is used to determine whether to update again to control the updating frequency.
[0059] The step 303 specifically includes: Step 303, the loop is executed until i∈[0,N-1] is traversed. If ER0'[i]=0, it means that there is no error in the R0'[i] data, and the next loop is executed. Otherwise, a temporary random number is generated and converted into a probability value AdjIndex1 between [0,1), and compared with the update probability threshold AdjP1 set in the initial registration stage. If AdjIndex1≥AdjP1, the next loop is executed. Otherwise, the R-SRAM[i] data block is processed according to steps 102 and 104. If the corresponding MaxR[i]≥T, the HelpData0[i] data is updated.
[0060] In the method of the present invention, all auxiliary data can be publicly stored, including: HelpIndex, HelpData0, HelpData1, AdjP0, AdjP1, MaxIndex, T, etc. When applied, if the adversary can easily tamper with the auxiliary data, for example: the auxiliary data is independently stored in the Flash chip, the adversary can directly read and write, for the security of PUF application, part of the R0 data can be selected and hashed together with all the auxiliary data, and the hash value is also stored as the auxiliary data. During reconstruction, the hash value is used to determine whether it has been tampered with. If it has been tampered with, the reconstruction process is stopped.
[0061] The same and similar parts between the various embodiments in this specification can be referenced to each other.
[0062] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A SRAM PUF key extraction method based on correlation judgment, characterized in that: The method comprises at least an initial registration phase and a reconstruction phase, wherein: Initial registration phase: Step 101, SRAM is powered on, PUF variables are configured and initialized, wherein the variables at least include: Configure the data block upper limit I, the number of valid data blocks N, the number of data block bits K and the threshold T; initialize the data block number i to 0, all I-bit auxiliary data HelpDataIndex to 0, and the valid data block temporary sequence number n to 0; Step 102, calculating the XOR of an SRAM data block and its cyclic shifts of different points, and searching for the number of cyclic shift points and the number of negatively correlated bits when the data block has the maximum negative correlation; Step 103, selecting N data blocks whose maximum number of negatively correlated bits is greater than a set threshold, and taking the data blocks as valid data blocks, the number of the valid data blocks is N; Step 104, using N bits to hide random numbers to respectively control whether the N valid data blocks are cyclically shifted according to the number of cyclic shift points when the N valid data blocks have the maximum negative correlation; Step 105, a random number generator generates a PUF output random number, linearly encodes it, and outputs the encoding result; Step 106, the encoding result and the hidden random number are XORed to obtain auxiliary data; Reconstruction phase: Step 201, the SRAM is powered on, variables are initialized, and the auxiliary data is read, and a valid data block is selected according to the auxiliary data; Step 202, using the valid data block and the auxiliary data, restore the approximate random number of the hidden random number; Step 203, XOR the approximate random number with the auxiliary data to obtain a codeword before error correction; Step 204: perform linear coding error correction on the codeword to restore the PUF output random number.
2. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The step 102 includes: The addresses are accumulated sequentially to read K bits of SRAM data. The jth bit of the i-th data block is represented by D-SRAM[i][j], where i∈[0,I-1], j∈[0,K-1]; For the i-th data block D-SRAM[i] of K bits of data, in the range of k∈[1,K-1], calculate R[k]=numone(D-SRAM[i] (D-SRAM[i] >> k)); Among them: ">>" means circular right shift, " "" means to calculate XOR by bit, "numone" means the number of bits counted as 1; Calculate MaxR[n]=max(R[1:K-1]), MaxIndex[n]=maxindex(R[1:K-1]); "max" means selecting the maximum value from R[1] to R[K-1], and "maxindex" means the position of the maximum value. If there are multiple positions with the same maximum value, the value with the smallest subscript from R[1] to R[K-1] is selected.
3. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The step 103 comprises: If MaxR[n]≥T in step 102, then HelpDataIndex[i]=1, and the nth K-bit valid data block HelpData0[n]=D-SRAM[i] is set, and n is incremented by 1; If n≥N-1, go to step 104, otherwise, i is incremented by 1, and if i≥I, return registration failure, otherwise go to step 102.
4. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The step 104 includes: Generate an N-bit hidden random number R0, where each bit is represented by R0[i], i∈[0,N-1]; If R0[i]=1, i∈[0,N-1], then HelpData0[i] is circularly shifted right, that is: HelpData0[i]= HelpData0[i] >> MaxIndex[i], and the auxiliary data HelpData0, a total of N×K bits, and HelpDataIndex, a total of I bits, are stored.
5. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The steps 105 and 106 include: Step 105: A random number generator generates an M-bit PUF output random number R1, which is linearly encoded. Get an N-bit codeword W; Step 106, W is XORed with R0 and stored as auxiliary data HelpData1, which is N bits in total. At the same time, the upper limit I of the configuration data block, the number of valid data blocks N, the number of data block bits K and the threshold T are stored as auxiliary data.
6. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The step 201 includes: Step 201, SRAM is powered on, PUF variables are initialized, auxiliary data is read, SRAM data of I data blocks are read according to consecutive addresses, and N K-bit valid data blocks are selected according to HelpDataIndex, which are represented by R-SRAM[i], i∈[0,N-1].
7. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The step 202 includes: Extract the i-th K-bit data HelpData0[i] of the auxiliary data HelpData0, calculate MaxR[i] and MaxIndex[i] corresponding to HelpData0[i] according to step 102, and further calculate: G0[i]= numone(R-SRAM[i] HelpData0[i]); G1[i]= numone((R-SRAM[i] >> MaxIndex[i]) HelpData0[i]); According to the following decision expression, the approximate random number R0'[i] of the hidden random number R0[i] is restored bit by bit, i∈[0,N-1]: 。 8. The SRAM PUF key extraction method based on correlation decision according to claim 1, characterized in that: The steps 203 and 204 include: Step 203, XOR HelpData1 with R0' to obtain W'; Step 204, linear encoding , correct W' to get W, and restore the M-bit PUF output random number R1.
9. The SRAM PUF key extraction method based on correlation decision according to claim 8, characterized in that: The method further comprises applying process auxiliary data updates: Step 301, determine whether to update by a random number to control the update frequency; Step 302, locating the bit with error in the code word W' before error correction by XOR calculation; Step 303: update the auxiliary data corresponding to the error bit in W' according to step 102 and step 104. Before updating, a random number is used to determine whether to update again to control the updating frequency.
10. The SRAM PUF key extraction method based on correlation decision according to claim 9, characterized in that: The application process auxiliary data update specifically includes: Step 301, generate a temporary random number and convert it into a probability value AdjIndex0 between [0,1), and compare it with the update probability threshold AdjP0 set in the initial registration stage. If AdjIndex0≥AdjP0, exit, otherwise execute step 302; Step 302, reconstruction phase After step 204, determine whether the random number R1 output by the M-bit PUF is accurate. If it is wrong, exit. If it is correct, XOR W and W' to obtain ER0'; Step 303, the loop is executed until i∈[0,N-1] is traversed. If ER0'[i]=0, it means that there is no error in the R0'[i] data, and the next loop is executed. Otherwise, a temporary random number is generated and converted into a probability value AdjIndex1 between [0,1), and compared with the update probability threshold AdjP1 set in the initial registration stage. If AdjIndex1≥AdjP1, the next loop is executed. Otherwise, the R-SRAM[i] data block is processed according to steps 102 and 104. If the corresponding MaxR[i]≥T, the HelpData0[i] data is updated.
Citation Information
Patent Citations
Key extraction method based on SRAM-PUF (Spatial Random Access Memory-Physical Unclonable Function)
CN110730068A
Mixed physical unclonable function structure and SBOX masking method
CN113489582A
One-time pad encryption method based on PUF (Physical Unclonable Function) and fuzzy extraction algorithm
CN114205079A
SRAM (static random access memory) physical unclonable function circuit and equipment
CN118378312A
Physically unclonable function (PUF) with improved error correction
WO2013083415A2