Tri-state PUF circuit of FPGA and key generation method of tri-state PUF circuit

By designing a three-state PUF circuit in FPGA, combining multiple modes and using excitation signal obfuscation technology, the problem of insufficient anti-machine learning capabilities of PUF under limited resources is solved, and the stability and security of the circuit are improved.

CN120474707APending Publication Date: 2025-08-12ANHUI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510917591.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The prior art is difficult to improve the anti-machine learning ability of physical non-cloneable functions (PUFs) under limited resources, and is easily cracked.

Method used

A three-state PUF circuit of FPGA is designed, combining APUF, RO PUF and SR PUF modes, and obfuscating the original excitation signal through shuffling algorithms and matrix multiplication to generate a difficult-to-break key.

Benefits of technology

While saving circuit resources, the anti-machine learning ability of PUF is improved, the stability and reliability of the circuit are enhanced, and it is difficult to crack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474707A_ABST
    Figure CN120474707A_ABST
Patent Text Reader

Abstract

The invention discloses a three-state PUF (Physical Unclonable Function) circuit of an FPGA (Field Programmable Gate Array) and a key generation method thereof, the three-state PUF circuit comprises an upper AND gate, a lower AND gate, a first-level module to an nth-level module, the first-level module to the (n-2) th-level module and the nth-level module are all selectors, each level is provided with an upper selector and a lower selector, and the (n-1) th-level module comprises an upper LUT and a lower LUT; the two AND gates are in parallel connection and cross connection with the selector of the first stage, the selector of the current stage is in parallel connection and cross connection with the selector of the next stage, and the output ends of the two selectors of the (n-2) th stage are respectively connected with the input ends of the two LUTs of the (n-1) th stage; the first output ends of the two LUTs of the (n-1) th level are respectively connected in parallel and in cross connection with the selector of the nth level through a NOT gate; the output ends of the two selectors of the nth stage are respectively connected with one input end of each of the two AND gates; the method has the advantages that the machine learning resisting capability of the PUF is improved under limited resources, so that the PUF is difficult to crack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security technology, and in particular to a three-state PUF circuit of an FPGA and a key generation method thereof. Background Art

[0002] In the digital age, with the rapid development of the internet, cybersecurity has become a key concern across all industries. Security keys, as a crucial technology for protecting data security, play a vital role. A security key is a core element in cryptography, a set of critical parameters or information codes used to control encryption and decryption operations. It's like a "key to secret information"; possessing the key is essential for accessing or protecting encrypted data. A security key generates a set of data using an encryption algorithm and is used to ensure the confidentiality and integrity of data transmission during communications. To ensure information security, users often use security keys to encrypt the storage and transmission of sensitive data on their smart devices.

[0003] Early implementations of encryption for smart devices typically used secret keys permanently stored in non-volatile memory (NVM) for direct access from onboard encryption / authentication primitives. However, this design approach is susceptible to probing attacks and other side-channel attacks, making it highly vulnerable. Furthermore, the use of NVM significantly increases the cost, size, and energy consumption of smart devices. Consequently, a growing number of researchers have begun exploring ways to provide more secure encryption for smart devices without the need for additional memory. Physically Unclonable Functions (PUFs) have emerged as an alternative to early non-volatile memory encryption schemes.

[0004] A Physical Unclonable Function (PUF) is a security technology that leverages random process variations (such as transistor threshold voltage and metal layer thickness) during hardware manufacturing to generate a unique identifier. It generates an unclonable response signal based on an input stimulus. Its core relies on microscopic differences in physical structure to achieve a unique mapping between stimulus and response. A set of PUF inputs and outputs is called a Challenge-Response Pair (CRP). The relationship between the stimulus and response is determined solely by certain physical variations in the devices. Due to variations in chip manufacturing, the chip is unclonable, making it anti-counterfeit. This makes PUF technology an essential component of chip security.

[0005] PUFs are therefore able to derive secret keys directly from manufacturing process variations without requiring any additional equipment. Due to the random nature of manufacturing process variation, PUFs are expected to generate unique and unpredictable responses, similar to a device's fingerprint. To achieve this, PUFs must be designed to ensure that the stimulus-response pair (CRP) depends solely on the physical characteristics of each device. In addition to being unpredictable and unique, PUFs must also exhibit considerable stability: for a given challenge, they must output the same response even under varying operating conditions and over relatively long periods of time. To mitigate their inherent instability, post-processing techniques are often employed. The most common stabilization method is the use of complex error-correcting codes (ECC). While highly effective, this strategy incurs significant hardware overhead. Majority voting (TMV) is much simpler and widely used, but its stability improvement is relatively low, making it suitable for PUF circuits with limited inherent instability. Dark bit masking techniques, on the other hand, result in a significant loss in CRP. Therefore, it is highly desirable to develop a PUF that achieves highly stable raw responses while requiring only minimal post-processing.

[0006] The paper "Wang Yaodong. Implementation of an Arbiter PUF Based on FPGA [D]. Huazhong University of Science and Technology [2025-06-06]" designs and implements an adaptive and adjustable compensation circuit structure. Using a programmable delay line (PDL) and a multiplexer (MUX) as the main structure of the compensation circuit, the resulting responses are grouped and searched to find the value that guarantees the best randomness. Furthermore, the concept of multi-modal redundancy is introduced to improve the stability of the arbiter PUF. For the same stimulus, after an odd number of measurements, the value that appears the most times is counted as the final response, which is used to reduce the error between each response. This paper thus addresses the inherent instability of the PUF mentioned above. However, its group search method is time-consuming and labor-intensive, and because it promotes a linear relationship between stimulus and response, it actually reduces the final machine learning capability. Summary of the Invention

[0007] The technical problem to be solved by the present invention is how to improve the machine learning capability of PUF under limited resources, making it difficult to be cracked.

[0008] The present invention solves the above technical problems through the following technical means: a three-state PUF circuit of an FPGA, including upper and lower AND gates and first to n-th level modules, the first to n-2 level modules and the n-th level module are all selectors, and each level has upper and lower selectors, and the n-1 level module is an upper and lower LUT; two AND gates are connected in parallel and cross-connected with the selector of the first level, the selector of the current level is connected in parallel and cross-connected with the selector of the next level, the output ends of the two selectors of the n-2 level are respectively connected to the input ends of the two LUTs of the n-1 level; the first output ends of the two LUTs of the n-1 level are respectively connected in parallel and cross-connected with the selector of the n level through a NOT gate, and the second output ends of the two LUTs of the n-1 level are left floating; the output ends of the two selectors of the n level are respectively connected to one input end of the two AND gates, and the other input ends of the two AND gates receive a start-stop control signal; the first to n-level modules receive excitation signals C1 to C2 respectively. n When the excitation of the n-1th level module is 0, the circuit operates in APUF mode. When the excitation of the n-1th level module is 1, if the signal returns from the selector above the n-1th level module to the upper AND gate, the circuit operates in RO PUF mode. If the signal returns from the selector below the n-1th level module to the lower AND gate, the circuit operates in SR PUF mode.

[0009] This invention implements the three-state PUF (APUF, RO PUF, and SR PUF) within a single circuit framework, saving circuit resources and reducing hardware resource consumption. The combination of the APUF, RO PUF, and SR PUF makes it difficult to extract circuit differences based on the circuit's input and output responses, making it difficult to crack the three-state PUF using machine learning, thus improving the PUF's resistance to machine learning.

[0010] Furthermore, when the excitation of the n-1th level module is 0, the first output ends of the two LUTs are not conductive, the second output ends of the two LUTs are conductive, and the second output ends of the two LUTs output the signal of the previous stage as the final response, and the circuit operates in APUF mode.

[0011] Furthermore, when the excitation of the n-1th level module is 1, the first output terminals of the two LUTs are turned on, and the second output terminals of the two LUTs are turned off.

[0012] Furthermore, the parallel connection and cross connection means that if the upper and lower paths of the current-level module are A and B respectively, and the upper and lower paths of the next-level module are C and D respectively, A is connected to C and D, and B is connected to C and D; among them, the connection between A and C, and B and D is called a parallel connection, and the connection between A and D, and B and C is called a cross connection.

[0013] Furthermore, when the excitation is 0, the output is parallel, and when the excitation is 1, the output is cross-linked.

[0014] Furthermore, when the excitation of the current module is 0, the signal of A is given to C, and the signal of B is given to D; when the excitation of the current module is 1, the signal of A is given to D, and the signal of B is given to C.

[0015] Furthermore, the three-state PUF circuit of the FPGA also includes a post-processing module, and the output end of the n-th level module and the second output ends of the two LUTs of the n-1-th level are both connected to the post-processing module, and the post-processing module processes the signal in the corresponding mode according to different modes.

[0016] The present invention also provides a key generation method for a three-state PUF circuit of an FPGA, comprising:

[0017] Excitation C1 to Excitation C n Composing a character string in sequence, which serves as the original stimulus signal;

[0018] The original stimulus signal is processed by the shuffling algorithm to obtain the obfuscated stimulus;

[0019] Perform matrix multiplication on the confused stimulus and the original stimulus signal to obtain the Boolean stimulus;

[0020] Input the Boolean stimulus into the circuit to obtain a response. When the response is 0, shift the confusion stimulus one bit to the right, thereby removing the first bit of the confusion stimulus, and use the XOR result of the first three bits of the confusion stimulus to fill the first bit of the confusion stimulus to obtain a shifted XOR stimulus. When the response is 1, shift the confusion stimulus one bit to the left, thereby removing the last bit of the confusion stimulus, and use the XOR result of the first three bits of the confusion stimulus to fill the last bit of the confusion stimulus to obtain a shifted XOR stimulus.

[0021] The shifted XOR excitation is multiplied by the original excitation signal matrix and then input into the circuit to obtain the final response.

[0022] Furthermore, the shift of the confusion stimulus to the right by one bit and the shift of the confusion stimulus to the left by one bit are both achieved through a linear shift register.

[0023] Furthermore, the excitation C1 to excitation C n are all 0 or 1, so the original excitation signal, confused excitation, Boolean excitation and shifted XOR excitation are all Boolean matrices.

[0024] The advantages of the present invention are:

[0025] (1) The present invention implements the three-state PUFs (APUF, RO PUF, and SR PUF) within a single circuit framework, thereby conserving circuit resources and reducing hardware resource consumption. The APUF, RO PUF, and SR PUF are combined together, making it difficult to extract circuit differences based on the circuit input and output responses, making it difficult to crack the three-state PUF using machine learning, thereby improving the PUF's ability to withstand machine learning.

[0026] (2) The present invention designs a key generation method based on the above-mentioned three-state PUF circuit, which confuses the original excitation signal through shuffling algorithms, matrix multiplication, etc., and inputs the Boolean excitation obtained through the above-mentioned obfuscation into the circuit to obtain a response. The excitation signal is further shifted and padded according to the different responses, so that the signal is further encrypted. Finally, a matrix multiplication is performed to generate a key that is difficult to crack, thereby improving the key encryption effect based on the multi-modal PUF circuit, making it difficult for attackers to crack the circuit through machine learning and other methods, and improving the stability and reliability of the circuit. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 A schematic diagram of a three-state PUF circuit for an FPGA disclosed in an embodiment of the present invention;

[0028] Figure 2 This is a flow chart of a key generation method for a three-state PUF circuit of an FPGA disclosed in an embodiment of the present invention;

[0029] Figure 3 The results of modeling attacks on the three-state PUF proposed by the present invention using different machine learning algorithms are shown in Figure 2. Figure 3 (a) is the test result of modeling attack using logistic regression. Figure 3 (b) is the test result of modeling attack using support vector machine. Figure 3 (c) is the test result of modeling attack using covariance matrix adaptive evolution strategy. Figure 3 (d) is the test result of modeling attack using artificial neural network. DETAILED DESCRIPTION

[0030] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0031] like Figure 1As shown, an embodiment of the present invention provides a three-state PUF circuit of an FPGA, including upper and lower AND gates and first to n-th level modules, the first to n-2 level modules and the n-th level modules are all selectors and each level has upper and lower selectors, and the n-1 level module is an upper and lower LUT; two AND gates are connected in parallel and cross-connected with the selector of the first level, the selector of the current level is connected in parallel and cross-connected with the selector of the next level, the output ends of the two selectors of the n-2 level are respectively connected to the input ends of the two LUTs of the n-1 level; the first output ends of the two LUTs of the n-1 level are respectively connected in parallel and cross-connected with the selector of the n level through a NOT gate, and the second output ends of the two LUTs of the n-1 level are left floating; the output ends of the two selectors of the n level are respectively connected to one input end of the two AND gates, and the other input ends of the two AND gates receive a start-stop control signal; the first to n-level modules receive excitation C1 to excitation C1 respectively. n When the excitation of the n-1th level module is 0, the first output ends of the two LUTs are not conducting, and the second output ends of the two LUTs are conducting. The second output ends of the two LUTs output the signal of the previous stage as the final response, and the circuit operates in APUF (arbitrator PUF) mode; when the excitation of the n-1th level module is 1, the first output ends of the two LUTs are conducting, and the second output ends of the two LUTs are not conducting. If the signal returns from the selector above the n-th level module to the upper AND gate, the circuit operates in RO PUF (ring oscillator PUF) mode. If the signal returns from the selector below the n-th level module to the lower AND gate, the circuit operates in SR PUF (butterfly PUF) mode.

[0032] In practical applications, it is also possible to adjust the excitation C1 to C n The number of 1s in the LUT is used to determine the SR PUF mode and the RO PUF mode. The LUT is stimulated by the mode bit, so the data at that position is removed and the data at other positions is counted. When all stimuli have an odd number of "1s", if the stimulus of the mode bit is also "1", the "1" in the mode bit is removed. Then, there is actually an even number of "1s". At this time, the three-state PUF operates in two independent RO PUFs. When there is actually an odd number of "1s", the three-state PUF circuit is used as an SR PUF.

[0033] It should be noted that the parallel connection and cross connection means that if the upper and lower paths of the current level module are A and B respectively, and the upper and lower paths of the next level module are C and D respectively, A is connected to C and D, and B is connected to C and D; among them, the connection between A and C, B and D is called parallel connection, and the connection between A and D, B and C is called cross connection. When the excitation is 0, parallel output is given, and when the excitation is 1, cross output is given. When the excitation of the current level module is 0, the signal of A is given to C, and the signal of B is given to D; when the excitation of the current level module is 1, the signal of A is given to D, and the signal of B is given to C. Figure 1 The two selectors in the first-level module receive stimulus C1. If stimulus C1 is 0, the signal is input from the selector above the current level to the selector above the next level, and the signal is input from the selector below the current level to the selector below the next level. If stimulus C1 is 1, the signal is input from the selector above the current level to the selector below the next level, and the signal is input from the selector below the current level to the selector above the next level. Similarly, if the signal at the AND gate output or the NOT gate output is 0, the signals are output in parallel, that is, output to the selectors at the corresponding positions. If the signal at the AND gate output or the NOT gate output is 1, the signals are output in cross-over, that is, output to the selectors at the cross-over positions.

[0034] After the above processing, the mode of the circuit can be determined, and after the mode is determined, signal processing in the corresponding mode is required. The above three different modes of PUF and the corresponding signal processing methods of each PUF are all based on existing technical principles. Therefore, the present application sets up a post-processing module, and the output end of the n-th level module and the second output ends of the two LUTs of the n-1th level are connected to the post-processing module. The post-processing module processes the signal in the corresponding mode according to different modes. For example, for the APUF mode, after receiving the signal from the corresponding port of the three-state PUF circuit, the post-processing module determines that it belongs to the APUF mode, and thus selects the arbitrator to start working and process the output signal. For the RO PUF mode, the frequency oscillator in the post-processing module starts working, and the two links generate a one-bit response based on the frequency difference between the ROs. For the SR PUF mode, the circuit generates transient oscillations. The timer in the post-processing module starts working and ends the timing before the step signal jumps, and selects the output of the selector under the stabilized n-th level module as the response. Some SR PUFs may not stabilize. In this case, a flag can be added to mark them as unstable and removed later. The more time given to stabilize, the more likely the response will stabilize. The technical principles of the three PUFs and the subsequent signal processing are not part of the technical improvements of this invention and are not detailed here.

[0035] like Figure 2 As shown, based on the above-mentioned three-state PUF circuit, the present invention also provides a key generation method for the three-state PUF circuit of FPGA, including:

[0036] Excitation C1 to Excitation C nA character string is formed in sequence, and the character string is used as the original excitation signal C. The original excitation signal C is processed by the shuffling algorithm to obtain a confusion excitation. The confusion excitation is matrix multiplied with the original excitation signal C to obtain a Boolean excitation. The Boolean excitation is input into the circuit to obtain a response. When the response is 0, the confusion excitation is shifted one bit to the right using a linear shift register, thereby removing the first bit of the confusion excitation, and the first bit of the confusion excitation is filled with the XOR result of the first three bits of the confusion excitation to obtain a shifted XOR excitation; when the response is 1, the confusion excitation is shifted one bit to the left using a linear shift register, thereby removing the last bit of the confusion excitation, and the last bit of the confusion excitation is filled with the XOR result of the first three bits of the confusion excitation to obtain a shifted XOR excitation; the shifted XOR excitation is matrix multiplied with the original excitation signal C and input into the circuit to obtain the final response.

[0037] The excitation C1 to excitation C n All are 0 or 1, so the original excitation signal C, the aliased excitation, the Boolean excitation, and the shifted XOR excitation are all Boolean matrices. Matrix multiplication is a well-known technique. The "AND" operation is calculated for each corresponding element in the i-th row of matrix E and the j-th column of matrix F. All the results of the "AND" operation are then "ORed" to obtain the matrix multiplication result, resulting in a new matrix.

[0038] The above design employs a two-round masking scheme to conceal the true stimulus. First, the original stimulus signal C is generated in the FPGA. This signal is then shuffled using the Fisher-Yates-Shuffle algorithm to produce a linearly obfuscated stimulus. The original stimulus signal C and the Boolean stimulus are then input into a matrix encryption module, performing matrix multiplication to produce the Boolean stimulus. The matrix encryption module performs encryption by multiplying two matrices. This encryption is possible because one of the matrices is randomly generated. In this invention, the original stimulus signal C and the obfuscated stimulus cannot be multiplied if they are not square matrices, so stimulus bit counts of 16, 36, or 64 bits are selected. Furthermore, because both matrices are binary, Boolean matrix multiplication is employed. The resulting Boolean response is non-reproducible, accounting for process variations. If the response value is 0, the linearly obfuscated stimulus passes through a linear shift register (Lfsr), shifting all data to the left. If the response value is 1, the obfuscated stimulus data passing through the Lfsr is shifted to the right. A second round of responses then occurs. This process not only further obfuscates the stimulus-response pair but also completely severs the correspondence between the response and stimulus. Attackers cannot obtain intermediate responses because they are not output to the I / O port and are only temporarily stored in the intermediate register. Therefore, attackers can only use stimulus-response pairs with two rounds of responses to train the model. Without intermediate responses, the direct correspondence between stimulus and response cannot be obtained, which directly affects the attacker's PUF modeling, thereby improving security.

[0039] In order to verify the effect of the present invention, this embodiment conducted relevant experiments and analyzed the experimental results. The analysis process is as follows:

[0040] (1) Anti-machine learning capabilities:

[0041] To evaluate the security of the proposed three-state PUF circuit architecture, this example employs four well-known machine learning algorithms for modeling attack testing: logistic regression (LR), support vector machine (SVM), covariance matrix adaptive evolutionary strategy (CMA-ES), and artificial neural network (ANN). During the attack evaluation, the dataset was randomly partitioned into a training set (80%) and a test set (20%). The machine learning model was trained using the training set, and its prediction accuracy was verified on an independent test set. Figure 3 The results of modeling attacks using different machine learning algorithms are given, among which, Figure 3 (a) is the test result of modeling attack using logistic regression. Figure 3 (b) is the test result of modeling attack using support vector machine. Figure 3 (c) is the test result of modeling attack using covariance matrix adaptive evolution strategy. Figure 3 (d) is the test result of modeling attack using artificial neural network. The test results of each model are analyzed below.

[0042] 1) Logistic regression: It predicts the probability that a sample belongs to a certain category by linearly combining features and then mapping the results to the (0,1) interval using a Sigmoid function. It can be seen that at 500 CRPs, both the 36-bit APUF and the 64-bit APUF have been cracked, while the prediction rate of the TPO-PUF-36 of the present invention is around 0.55, which is also unbreakable. Even when the number of CRPs (stimulus-response pairs) increases to 6000, there is still a slight fluctuation, and the prediction success rate has not improved. From the results summarized above, it can be concluded that the TPO-PUF of the present invention can resist logistic regression learning attacks. Here, TPO-PUF refers to the three-state PUF proposed in the present invention, 36 refers to 36 bits, that is, it has a 36-bit stimulus input, and n is 36.

[0043] 2) Support Vector Machine (SVM): This machine distinguishes data points of different categories by finding an optimal hyperplane in the feature space. It can be seen that the prediction success rate of all PUFs increases with the increase in CRP. When the CRP reaches 10,000, the prediction success rate of the TP-PUF64 of the present invention is only 0.65, which is close to random guessing.

[0044] 3) Covariance Matrix Adaptive Evolution Strategy: CMA-ES is a gradient-free optimization algorithm that solves optimization problems by adjusting the covariance matrix of a normal distribution. This algorithm demonstrates strong capabilities in handling complex, multimodal, and nonlinear optimization problems. It can be seen that the APUF was cracked with a prediction success rate of 0.95%, and the TP-PUF36 also had a prediction success rate close to 0.9, also nearly cracked. However, the TPO-PUF, after two rounds of obfuscation, achieved a maximum prediction rate of only 0.67 at 10,000 CRP. This shows that the Covariance Matrix Adaptive Evolution Strategy is ineffective for the TPO-PUF of the present invention.

[0045] 4) Artificial neural network: A mathematical or computational model that mimics the structure and function of biological neural networks and is used to estimate or approximate functions. It consists of a large number of nodes (or neurons) that interact with each other through specific connections. Each node represents a specific output function, called the activation function. The present invention uses a dual-hidden layer structure with ReLU activation, which effectively models the complex nonlinear characteristics of PUFs. However, none of these methods were able to effectively break the TPO-PUF of the present invention.

[0046] The following section evaluates PUF performance, including consistency, reliability, uniqueness, and hardware overhead. Uniformity evaluates the randomness of the PUF response. Reliability assesses the stability of the PUF response. Uniqueness tests whether the PUF response is a unique identifier.

[0047] (2) Uniformity

[0048] Uniformity reflects the distribution balance of 0 and 1 in the response generated by a single PUF instance. Ideally, the uniformity should be close to 50%, that is, the probability of 0 and 1 appearing is equal. The formula for calculating uniformity is as follows

[0049]

[0050] in, The average uniformity obtained from the experiment of the present invention is 43.28%.

[0051] (3) Uniqueness

[0052] Uniqueness is defined as the difference between the responses of different PUF instances to the same challenge, reflecting the uniqueness of the PUF. Ideally, the responses of different PUFs should differ by approximately 50%. This can be expressed as the Hamming distance. The uniqueness formula is as follows:

[0053]

[0054] Where k represents the number of PUF instances tested, Ra, R b represents the responses generated by the xth and yth instances under the same test conditions, respectively. HD represents the Hamming distance. n represents the total number of responses for a PUF instance. In this example, 15,000 randomly generated challenges were input into three chips, each with one TPO-PUF instance. The measured average uniqueness was 44.89%.

[0055] (4) Reliability

[0056] Reliability is defined as the average difference between responses to the same challenge generated multiple times by the same PUF under the same environment (temperature, voltage, etc.). Ideally, the difference should be close to 0%, indicating a highly stable response. Because the butterfly PUF pattern passes through too many LUTs, it has more responses that can stabilize over the longest possible time. However, the present invention requires a quick response, so some responses cannot stabilize in a short period of time and have to be screened out and discarded. Those that stabilize have large process deviations and are more stable. The stability calculation formula is as follows

[0057]

[0058] Where S is the public stable bit set S = R1∩R2∩…R i , for each bit i∈S, check whether its response is consistent in all tests: if R1=R2=…=R i , then the bit is consistent; otherwise it is inconsistent.

[0059] Define the indicator function:

[0060]

[0061] In the experiment of this embodiment, the average value of the reliability test results of 10 times is 93.67%.

[0062] (5) Hardware consumption

[0063] Table 1 Comparison of resource consumption of 64-bit PUF

[0064]

[0065]

[0066] As shown in Table 1, Dual-mode PUF and CT-PUF are both PUFs with switchable modes. Dual-mode PUF switches between RO PUF and BR PUF, while CT-PUF can switch between RO PUF, APUF, and BR PUF. 2-XOR-PUF is an XOR operation performed on two APUFs. LUTS represents a lookup table, and FFS represents a trigger. The values in the table represent the number of lookup tables or triggers used to generate the corresponding PUF circuit, thereby intuitively showing the hardware resource consumption. The TP-PUF of the present invention can switch between three modes and can adjust the mode control bit to select the amount of CRP space in the APUF. Compared with similar PUFs, it uses fewer resources. After integrating the obfuscation mechanism, it has greater flexibility and can better defend against attackers' modeling of the PUF. Even if the internal structure is cracked through reverse engineering, the TPO-PUF will linearly amplify the basic noise of machine learning, making it more difficult for attackers to successfully crack it.

[0067] In summary, the present invention excels in anti-machine learning capability, uniformity, uniqueness, reliability, and hardware consumption, and the three-state PUF of the present invention has excellent performance.

[0068] Through the above technical solutions, this invention expands SR PUF and RO PUF into strong PUFs, leveraging the path delay of the APUF to significantly reduce hardware resource consumption. It also adds a flag bit that can be used to filter unstable bits. This is the first time that the APUF, ROPUF, and SR PUF have been formally combined. Rather than using a single pattern for obfuscation, which can only extract responses where the stimulus is all zeros or 1s, the invention fully extracts circuit differences and combines them for comparison. The responses of the three patterns are evenly mixed in the stimulus-response pairs, making modeling attacks difficult.

[0069] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A three-state PUF circuit for FPGA, characterized in that: It includes upper and lower AND gates and first to n-level modules. The first to n-2-level modules and n-level modules are all selectors and each level has upper and lower selectors. The n-1-level module is an upper and lower LUT. The two AND gates are connected in parallel and cross-connected with the selector of the first level. The selector of the current level is connected in parallel and cross-connected with the selector of the next level. The output ends of the two selectors of the n-2 level are respectively connected to the input ends of the two LUTs of the n-1 level. The first output ends of the two LUTs of the n-1 level are respectively connected in parallel and cross-connected with the selector of the n level through a NOT gate, and the second output ends of the two LUTs of the n-1 level are left floating. The output ends of the two selectors of the n level are respectively connected to one input end of the two AND gates, and the other input end of the two AND gates receives the start-stop control signal. The first to n-level modules receive the excitation C1 to the excitation C1 respectively. n When the excitation of the n-1th level module is 0, the circuit operates in APUF mode. When the excitation of the n-1th level module is 1, if the signal returns from the selector above the n-1th level module to the upper AND gate, the circuit operates in ROPUF mode. If the signal returns from the selector below the n-1th level module to the lower AND gate, the circuit operates in SR PUF mode.

2. The three-state PUF circuit of an FPGA according to claim 1, characterized in that: When the excitation of the n-1th level module is 0, the first output ends of the two LUTs are not conductive, and the second output ends of the two LUTs are conductive. The second output ends of the two LUTs output the signal of the previous stage as the final response, and the circuit operates in APUF mode.

3. The three-state PUF circuit of an FPGA according to claim 1, characterized in that: When the excitation of the n-1th level module is 1, the first output ends of the two LUTs are turned on, and the second output ends of the two LUTs are not turned on.

4. The three-state PUF circuit of an FPGA according to claim 1, characterized in that: The parallel connection and cross connection means that if the upper and lower paths of the current level module are A and B respectively, and the upper and lower paths of the next level module are C and D respectively, A is connected with C and D, and B is connected with C and D; among them, the connection between A and C, B and D is called parallel connection, and the connection between A and D, B and C is called cross connection.

5. The three-state PUF circuit of an FPGA according to claim 4, characterized in that: When the excitation is 0, the output is parallel, and when the excitation is 1, the output is cross-linked.

6. The three-state PUF circuit of an FPGA according to claim 5, characterized in that: When the excitation of the current module is 0, the signal of A is given to C and the signal of B is given to D; when the excitation of the current module is 1, the signal of A is given to D and the signal of B is given to C.

7. The three-state PUF circuit of an FPGA according to claim 1, characterized in that: It also includes a post-processing module, the output end of the n-th level module and the second output ends of the two LUTs of the n-1th level are connected to the post-processing module, and the post-processing module processes the signal in the corresponding mode according to different modes.

8. The key generation method of a three-state PUF circuit of an FPGA according to any one of claims 1 to 7, characterized in that: include: Excitation C1 to Excitation C n Composing a character string in sequence, which serves as the original stimulus signal; The original stimulus signal is processed by the shuffling algorithm to obtain the obfuscated stimulus; Perform matrix multiplication on the confused stimulus and the original stimulus signal to obtain the Boolean stimulus; Input the Boolean stimulus into the circuit to obtain a response. When the response is 0, shift the confusion stimulus one bit to the right, thereby removing the first bit of the confusion stimulus, and use the XOR result of the first three bits of the confusion stimulus to fill the first bit of the confusion stimulus to obtain a shifted XOR stimulus. When the response is 1, shift the confusion stimulus one bit to the left, thereby removing the last bit of the confusion stimulus, and use the XOR result of the first three bits of the confusion stimulus to fill the last bit of the confusion stimulus to obtain a shifted XOR stimulus. The shifted XOR excitation is matrix-multiplied with the original excitation signal and then input into the circuit to obtain the final response.

9. The key generation method of a three-state PUF circuit of an FPGA according to claim 8, characterized in that: The shift of the aliased excitation to the right by one bit and the shift of the aliased excitation to the left by one bit are both achieved by a linear shift register.

10. The key generation method of a three-state PUF circuit of an FPGA according to claim 8, characterized in that: The excitation C1 to excitation C n are all 0 or 1, so the original excitation signal, confused excitation, Boolean excitation and shifted XOR excitation are all Boolean matrices.