Security authentication method of anti-machine learning PUF (Physical Unclonable Function) circuit based on excitation dynamic confusion

By introducing the excitation dynamic obfuscation module and the response obfuscation module into the PUF circuit and combining them with a lightweight encryption algorithm, the security issue of the PUF circuit under machine learning attacks is solved, and a highly secure and efficient authentication scheme is achieved, which is suitable for the security authentication of IoT devices.

CN120602099APending Publication Date: 2025-09-05CONSTR BRANCH OF STATE GRID JIANGSU ELECTRIC POWER CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510831239.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing PUF circuit security authentication methods have insufficient security when facing machine learning algorithm attacks, and due to limited computing resources, it is difficult to provide a lightweight, highly secure authentication solution.

Method used

By adopting an anti-machine learning PUF circuit based on incentive dynamic obfuscation, constructing incentive obfuscation modules and response obfuscation modules, and combining lightweight encryption algorithms, authentication information interaction and model construction are realized between the device and server sides, thereby enhancing the security and efficiency of authentication.

Benefits of technology

It effectively resists modeling attacks from machine learning algorithms, provides a highly secure authentication solution, reduces unnecessary computational overhead, improves authentication efficiency, and is applicable to various types of PUF circuits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602099A_ABST
    Figure CN120602099A_ABST
Patent Text Reader

Abstract

The invention discloses a security authentication method for an anti-machine learning PUF circuit based on excitation dynamic confusion, and the method comprises the three stages: a preparation stage: deploying the anti-machine learning PUF circuit based on excitation dynamic confusion by Internet of Things terminal equipment; in the registration stage, the server side generates random excitation and an equipment ID number, sends the random excitation and the equipment ID number to the equipment side, receives an excitation response pair generated by the equipment side of the Internet of Things through a PUF circuit, constructs a PUF software model according to the excitation response pair, and stores the PUF software model and a private key and a public key of registration equipment; in the authentication stage, the server initializes the authentication label and initializes an authentication request, the device end and the server perform authentication information interaction, if the authentication information is correct, authentication passes, the device ID and the private key are updated when the authentication is finished, and if one of the server end and the device end detects that the authentication information is wrong in the authentication process, the device ID and the private key are updated. If not, the authentication label is changed to cause authentication failure. The method has the characteristics of modeling attack resistance, low resource overhead, high security and the like, and identity authentication can be provided for the resource-limited Internet of Things terminal equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security and integrated circuit technology, and in particular to a security authentication method for a PUF circuit that is resistant to machine learning and based on excitation dynamic obfuscation. Background Art

[0002] Today, the Internet of Things (IoT) industry has spread globally, and the interconnection of everything (IoE) has become a growing trend. As the core of IoT systems, IoT devices undergo multiple processes during their development, including design, manufacturing, testing, and packaging. However, in the era of globalization, each of these processes can introduce security vulnerabilities. Attackers can exploit these vulnerabilities to steal sensitive data, disrupting or even disrupting the operation of the entire IoT system. While privacy can be protected through the introduction of secure authentication protocols, authentication protocols based on common encryption algorithms such as AES (Advanced Encryption Standard), RSA (Rivest-Shamir-Adleman), and hash algorithms are not fully applicable to IoT devices with limited computing power. As a hardware security primitive, PUF (Physical Unclonable Function) effectively addresses these challenges in IoT systems. It extracts the inevitable process variations during chip manufacturing, thereby endowing each chip with unique characteristics.

[0003] However, with the development of artificial intelligence (AI) technology, the security of PUF circuits themselves is being threatened. For example, machine learning algorithms such as ANNs (Artificial Neural Networks) can learn and predict the stimulus-response pairs generated by PUF circuits, thereby establishing a software model of the PUF. Once the PUF software model is established, the authentication protocols associated with the PUF will no longer be secure.

[0004] Currently, PUF-based authentication methods lack robust security measures, exposing them to modeling attacks and threatening the security of the authentication methods. Furthermore, authentication methods using hash algorithms face computational resource limitations. Therefore, new approaches are urgently needed to address these issues. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a security authentication method for a machine learning-resistant PUF circuit based on excitation dynamic obfuscation, in order to provide a lightweight and highly secure authentication solution for the Internet of Things system.

[0006] In order to solve the above technical problems, the present invention adopts the following technical solutions:

[0007] A security authentication method for a machine learning-resistant PUF circuit based on excitation dynamic obfuscation includes the following steps:

[0008] S1. Construct a machine learning-resistant PUF circuit based on excitation dynamic obfuscation.

[0009] S2. The server generates a random stimulus and device ID number and sends them to the device. The device randomly generates a device private key and uses an anti-machine learning PUF circuit based on stimulus dynamic obfuscation to generate a stimulus-response pair. The response pair and the device private key are sent to the server together to build a PUF model and randomly generate a device public key. The device ID number, private key, PUF model and public key are stored in the database to complete the registration phase.

[0010] S3. The server initializes the authentication tag and initiates an authentication request. The device and the server exchange authentication information. If the authentication information is consistent with the data in the database in step S2, the authentication is successful, and the device ID number and device private key are updated at the end of the authentication. Otherwise, the authentication fails, the authentication is stopped, and the authentication stage is completed.

[0011] Furthermore, in step S1, the anti-machine learning PUF circuit based on excitation dynamic obfuscation includes an excitation obfuscation module, a strong PUF and a response obfuscation module.

[0012] The excitation confusion module includes a first input terminal, a first output terminal and a second output terminal.

[0013] The strong PUF includes a second input terminal and a third output terminal.

[0014] The response obfuscation module includes a third input terminal, a fourth input terminal, and a fourth output terminal.

[0015] The first output terminal is connected to the second input terminal, the second output terminal is connected to the third input terminal, and the third output terminal is connected to the fourth input terminal.

[0016] The first input end serves as an input end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation, and the fourth output end serves as an output end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0017] Furthermore, the excitation obfuscation module includes a sub-PUF, two linear feedback shift registers, an obfuscation logic circuit, and a feedback path.

[0018] The sub-PUF includes a fifth input terminal and fifth to seventh output terminals.

[0019] The first linear feedback shift register includes a first clock input terminal CLK, a first data input terminal and a first data output terminal.

[0020] The second linear feedback shift register includes a second clock input terminal CLK, a second data input terminal and a second data output terminal.

[0021] The garbled logic circuit includes an XOR gate and a data selector; the XOR gate includes XOR first to third input terminals and an XOR output terminal; the data selector includes a third data input terminal, a fourth data input terminal, a data selection terminal and a third data output terminal; the XOR third input terminal is connected to the third data output terminal, and the fourth data input terminal is fixed to 0.

[0022] The fifth output terminal is connected to the first data input terminal, the sixth output terminal is connected to the second data input terminal, the seventh output terminal is respectively connected to the second output terminal and the XOR first input terminal, the first data output terminal is connected to the XOR second input terminal, the second data output terminal is connected to the third data input terminal, the fifth input terminal and the data selection terminal serve as the first input terminal of the excitation confusion module, and the XOR output terminal serves as the first output terminal of the excitation confusion module.

[0023] The feedback path includes a buffer, the input end of the buffer is connected to the first output end, and the signal output from the output end of the buffer can be iteratively input to the first input end.

[0024] Furthermore, in step S2, the output response of the sub-PUF includes the following:

[0025] Step 1: Input the excitation signal C into the anti-machine learning PUF circuit based on excitation dynamic obfuscation. After the excitation obfuscation module, the excitation signal is evenly divided into k groups to obtain k groups of sub-excitation signals, where k = m / n, where m represents the length of the excitation signal and n represents the length of the input signal at the fifth input terminal.

[0026] Step 2: Sub-stimulation signals C k1 ~C kk are input into the sub-PUF through the fifth input terminal, and k output responses R are obtained. k1 ~R kk Among them, C k1 Indicates the first group of sub-excitation signals, C kk represents the kth group of sub-excitation signals, R k1 represents the output response corresponding to the first group of sub-stimulus signals, R kk represents the output response corresponding to the kth group of sub-stimulus signals.

[0027] Step 3: k output responses R k1 ~R kk Arrange in the order of the three combinations to get three bit strings R Sα 、R Sβ and R Sγ, and is output from the fifth to seventh output terminals in sequence as the output response of the sub-PUF.

[0028] Furthermore, in step S2, the final output signal of the excitation obfuscation module includes the following:

[0029] Step 1: The first output response R of the sub-PUF Sα After being processed by the first linear feedback shift register, the output signal S of the first data output terminal is obtained. L .

[0030] Step 2: Set S L The number of 1s is N1, let T=N1, where T represents the total number of confusions.

[0031] Step 3: The second output response R of the sub-PUF Sβ After being processed by the second linear feedback shift register, the output signal O of the second data output terminal is obtained. L .

[0032] Step 4: Excitation signal C, third output response R of sub-PUF Sγ 、S L and O L After being processed by the obfuscation logic circuit, the first output signal C of the excitation obfuscation module is obtained. t0 .

[0033] Step 5: Use the primary clock signal input from the second clock input terminal CLK to L Perform a shift, and the shifted data is used as the output signal O' of the new second data output terminal L .

[0034] Step 6: Let C temp =C t1 , C temp represents the incentive variable; C temp 、R Sγ 、S L and O′ L After being processed by the obfuscation logic circuit, the second output signal C of the excitation obfuscation module is obtained. t1 .

[0035] Step 7: Repeat steps 5 to 6 until the number of confusions reaches T, and then get the output signal C. tT , as the final output signal C of the excitation confusion module O .

[0036] Furthermore, in step S2, the final output response of the anti-machine learning PUF circuit based on excitation dynamic obfuscation includes the following:

[0037] Step 1: The final output signal C of the excitation confusion module O The output response R of the third output terminal of the strong PUF is obtained by inputting it into the strong PUF through the second input terminal. S .

[0038] Step 2: The third output response R of the sub-PUF Sγ The third input terminal is input into the response confusion module, and R S The output response R is input into the response obfuscation module through the fourth input terminal to obtain the output response R of the fourth output terminal, which serves as the final output result of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0039] Furthermore, in step S2, the registration phase includes the following:

[0040] Step 1: Deploy a random number generator on the server side and use it to generate a string of IDs of the pth device to be registered with a bit length of l. p ; Use this random number generator to generate N c The j-th bit stimulus C of the p-th device to be registered with a bit length of l pj .

[0041] Step 2: Based on the ID number of the pth device to be registered p , generate the private key K of the pth device to be registered DSp , sent to the server.

[0042] Step 3: N c C pj Input into the strong PUF and get N c The output response R of the j-th bit stimulus of the p-th device to be registered pj , and R pj , the circuit characteristics of the stimulus obfuscation module and the response obfuscation module are sent to the server, and the anti-fuse technology is used to cut off the external response of the device to the strong PUF, and obtain the circuit parameters of the stimulus obfuscation module and the response obfuscation module.

[0043] Step 4: Based on N c C pj 、N c R pj As well as the circuit characteristics of the stimulus obfuscation module and the response obfuscation module, the server uses a machine learning algorithm to build a PUF model.

[0044] Step 5: The server uses a random number generator to generate a public key K S , the PUF model, K DSp and K S Store in the database, K SSent to the pth device to be registered; when relevant data is needed, it is directly retrieved from the database.

[0045] Step 6. ID p , K DSp and K S Stored in the non-volatile memory of the pth device to be registered.

[0046] Furthermore, in step S3, the authentication phase includes the following:

[0047] Step 1: Set (TT*5%, T+T*5%) as the valid range of the current timestamp, and initialize S tag =D tag =0; where T represents the current timestamp, S tag Indicates the first authentication label, D tag Indicates the second authentication tag.

[0048] Step 2: S tag Assigned to the server, D tag Assigned to the qth device to be authenticated.

[0049] Step 3: The server generates a random number N1 using a random number generator, records the first timestamp T1, and sends N1 and T1 to the qth device to be authenticated. If T1 is within the valid range of the current timestamp, the server performs the following operations:

[0050]

[0051] R=PUF(C)

[0052] Among them, ID q Indicates the ID number of the qth device to be authenticated, represents an XOR operation, and PUF represents an anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0053] If T1 is not in the valid range of the current timestamp, perform the following operations:

[0054] Let D tag =1, the server uses a random number generator to generate a random number N2 and sets R=N2.

[0055] The timestamp after the operation is performed is recorded as the second timestamp T2, and T2 and R are sent to the server.

[0056] Step 4: Initialize the server with one registered device. If T2 is within the valid range of the current timestamp, perform the following operations:

[0057]

[0058] Rw =PUF model (C w )

[0059] Among them, C w Indicates the stimulus signal of the wth registered device, ID w Indicates the wth registered device ID number, R w represents the final output response of the w-th registered device’s PUF circuit based on excitation dynamic obfuscation and anti-machine learning. model Indicates the PUF model.

[0060] If T2 is not in the valid range of the current timestamp, perform the following operations:

[0061] Let S tag =1, the server uses a random number generator to generate random numbers N4, N5 and N6, and sets A=N4, B=N5, and Tag1=N6; where A, B and Tag1 all represent authentication information.

[0062] Step 5: If R is equal to R w , the ID w and the private key K of the wth registered device DSw Remove it and do the following:

[0063] The server uses a random number generator to generate a random number N3, Among them, ASCON() represents a lightweight encryption algorithm.

[0064] If R is not equal to R w , then select the w+1th registered device and repeat step 4 until the selected registered device is the last registered device.

[0065] The timestamp after the operation is performed is recorded as the third timestamp T3, and T3, A, B and Tag1 are sent to the qth device to be authenticated.

[0066] Step 6: If D tag If it is equal to 0, and T3 is within the valid range of the current timestamp, the following operations are performed:

[0067]

[0068]

[0069] N3', B' and Tag1' all represent intermediate data restored by the device using authentication information.

[0070] When B' equals B and Tag1' equals Tag1, the server is deemed legitimate and the following operations are performed:

[0071] Use a random number generator to generate a random number N7, let

[0072] Among them, E, F and Tag2 all represent the authentication information in the authentication process, K DSq Indicates the private key of the qth device to be authenticated, ID q Indicates the ID number of the qth device to be authenticated.

[0073] If D tag If it is not equal to 0, T3 is not in the valid range of the current timestamp, B′ is not equal to B, or Tag1' is not equal to Tag1, then the following operations are performed:

[0074] The server is deemed illegal; let D tag =1, the server uses the random number generator to generate random numbers N8, N9 and N 10 , and let E=N8,F=N9,Tag2=N 10 .

[0075] The timestamp after the operation is performed is recorded as the fourth timestamp T4, and T4, E, F and Tag2 are sent to the server.

[0076] Step 7: If S tag If it is equal to 0, and T4 is within the valid range of the current timestamp, the following operations are performed:

[0077]

[0078] Among them, N7', F' and Tag2' all represent the intermediate data restored by the server using the authentication information, K DSw Represents the private key of the wth registered device.

[0079] When F' equals F and Tag2' equals Tag2, the qth device to be authenticated is deemed legitimate and the following operations are performed:

[0080]

[0081] in, Indicates the wth registered device ID number in the next authentication process, K DSw new Indicates the private key of the wth registered device in the next authentication process.

[0082] Will and K DSw new Update to the database and send an update request to the qth device to be authenticated.

[0083] If Stag If it is not equal to 0, T4 is not in the valid range of the current timestamp, F' is not equal to F, or Tag2' is not equal to Tag2, the following operations are performed:

[0084] Let S tag =1, the qth device to be authenticated is deemed illegal, the server does not perform any other operations, the authentication fails, and the authentication is stopped.

[0085] Step 8: After receiving the update request, the qth device to be authenticated performs the following operations:

[0086]

[0087] in, Indicates the ID number of the qth device to be authenticated in the next authentication process, K DSq new Indicates the private key of the qth device to be authenticated in the next authentication process.

[0088] Will and K DSq new Update to non-volatile memory.

[0089] At this point, the authentication is successful.

[0090] Furthermore, the present invention also proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and runnable on the processor. When the processor executes the computer program, the steps of the security authentication method of the anti-machine learning PUF circuit based on excitation dynamic obfuscation are implemented.

[0091] Furthermore, the present invention also proposes a computer-readable storage medium, which stores a computer program. When the computer program is run by a processor, it executes the security authentication method of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0092] Compared with the prior art, the present invention adopts the above technical solution and has the following technical effects:

[0093] 1. The anti-machine learning PUF circuit based on excitation dynamic obfuscation described in the present invention has high security and can resist modeling attacks of machine learning algorithms such as ANN, providing a secure root of trust for the authentication method.

[0094] 2. The anti-machine learning PUF circuit based on excitation dynamic obfuscation described in the present invention does not require changing the strong PUF circuit structure. It only needs to add an excitation obfuscation module and a response obfuscation module, so it can provide protection for various types of PUF circuits.

[0095] 3. The security authentication method described in the present invention utilizes the authentication tag to quickly identify the accuracy of the authentication information. After detecting that the authentication information is incorrect, the authentication information is replaced with a random number, which reduces unnecessary computing overhead and improves authentication efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0096] Figure 1 It is an overall implementation flow chart of the present invention.

[0097] Figure 2 This is a circuit structure diagram of the anti-machine learning PUF based on excitation dynamic obfuscation of the present invention.

[0098] Figure 3 It is a circuit structure diagram of the excitation confusion module of the present invention.

[0099] Figure 4 This is a diagram showing the arrangement order of the three output responses of the present invention.

[0100] Figure 5 It is a signal transmission structure diagram in the obfuscated logic circuit of the present invention.

[0101] Figure 6 It is a signal transmission structure diagram in the response obfuscation module of the present invention.

[0102] Figure 7 It is a flow chart of the registration phase in the security authentication protocol of the present invention.

[0103] Figure 8 It is a flow chart of the authentication phase in the security authentication protocol of the present invention. DETAILED DESCRIPTION

[0104] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and are not intended to limit the scope of protection of the present invention.

[0105] To achieve the above objectives, the present invention proposes a security authentication method for a machine learning PUF circuit based on excitation dynamic obfuscation, such as Figure 1 The specific steps are as follows:

[0106] S1. Construct an anti-machine learning PUF circuit based on excitation dynamic obfuscation, such as Figure 2 As shown, specifically:

[0107] The anti-machine learning PUF circuit based on excitation dynamic obfuscation includes an excitation obfuscation module, a 64-order traditional arbiter PUF and a response obfuscation module.

[0108] The stimulus obfuscation module includes a first input terminal as the original stimulus, a first output terminal as the obfuscated stimulus, and a second output terminal as the auxiliary response.

[0109] The 64-order conventional arbiter PUF includes a second input terminal and a third output terminal.

[0110] The response obfuscation module includes a third input terminal, a fourth input terminal, and a fourth output terminal.

[0111] The first output terminal is connected to the second input terminal, the second output terminal is connected to the third input terminal, and the third output terminal is connected to the fourth input terminal.

[0112] The first input end serves as an input end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation, and the fourth output end serves as an output end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0113] Among them, such as Figure 3 As shown, the excitation obfuscation module includes a 16-order traditional arbiter PUF, two LFSRs (Linear Feedback Shift Registers), an obfuscation logic circuit and a feedback path.

[0114] The 16-order conventional arbiter PUF includes a fifth input terminal and fifth to seventh output terminals, wherein the seventh output terminal is a multiplexing port.

[0115] The first linear feedback shift register LFSR1 includes a first clock input terminal CLK, a first data input terminal and a first data output terminal.

[0116] The second linear feedback shift register LFSR2 includes a second clock input terminal CLK, a second data input terminal and a second data output terminal.

[0117] The clock input and feedback paths are omitted in the figure.

[0118] The garbled logic circuit includes an XOR gate and a data selector; the XOR gate includes XOR first to third input terminals and an XOR output terminal; the data selector includes a third data input terminal, a fourth data input terminal, a data selection terminal and a third data output terminal; the XOR third input terminal is connected to the third data output terminal, and the fourth data input terminal is fixed to 0.

[0119] The fifth output terminal is connected to the first data input terminal, the sixth output terminal is connected to the second data input terminal, the seventh output terminal is respectively connected to the second output terminal and the XOR first input terminal, the first data output terminal is connected to the XOR second input terminal, the second data output terminal is connected to the third data input terminal, the fifth input terminal and the data selection terminal serve as the first input terminal of the excitation confusion module, and the XOR output terminal serves as the first output terminal of the excitation confusion module.

[0120] The feedback path includes a buffer, the input end of the buffer is connected to the first output end, and the signal output from the output end of the buffer can be iteratively input to the first input end.

[0121] S2. The server generates a random stimulus and device ID number and sends them to the device. The device randomly generates a device private key, uses a machine learning-resistant PUF circuit based on dynamic obfuscation of the stimulus to generate a stimulus-response pair, and sends the response pair and the device private key to the server. The PUF model is then constructed and the device public key is randomly generated. The device ID number, private key, PUF model, and public key are stored in the database, completing the registration phase. Specifically:

[0122] The output response of the 16-order traditional arbiter PUF includes the following:

[0123] Step 1: Input a 64-bit excitation signal C into the anti-machine learning PUF circuit based on excitation dynamic obfuscation. The length of the input signal at the fifth input end is 16 bits. After passing through the excitation obfuscation module, the excitation signal is evenly divided into 4 groups to obtain 4 groups of sub-excitation signals.

[0124] Step 2: Sub-stimulation signals C 41 ~C 44 They are input into the 16-order traditional arbiter PUF through the fifth input terminal and four output responses R are obtained. 41 ~R 44 Among them, C 41 Indicates the first group of sub-excitation signals, C 44 Indicates the fourth group of sub-excitation signals, R 41 represents the output response corresponding to the first group of sub-stimulus signals, R 44 It represents the output response corresponding to the fourth group of sub-stimulus signals.

[0125] Step 3: Figure 4 As shown, the 4 output responses R 41 ~R 44 Arrange in the order of the three combinations to get three bit strings R Sα 、R Sβ and R Sγ , and is output from the fifth to seventh output terminals in sequence as the output response of the 16-order traditional arbiter PUF.

[0126] like Figure 5 As shown, the final output signal of the excitation confusion module includes the following:

[0127] Step 1: The first output response R of the 16-order traditional arbiter PUF Sα After being processed by the first linear feedback shift register, the output signal S of the first data output terminal is obtained. L .

[0128] Step 2: Set S LThe number of 1s is N1, let T=N1, where T represents the total number of confusions.

[0129] Step 3: The second output response R of the 16-order traditional arbiter PUF Sβ After being processed by the second linear feedback shift register, the output signal O of the second data output terminal is obtained. L .

[0130] Step 4: Excitation signal C, third output response R of 16-order traditional arbiter PUF Sγ 、S L and O L After being processed by the obfuscation logic circuit, the first output signal C of the excitation obfuscation module is obtained. t0 .

[0131] Step 5: Use the primary clock signal input from the second clock input terminal CLK to L Perform a shift, and the shifted data is used as the output signal O' of the new second data output terminal L .

[0132] Step 6: Let C temp =C t1 , C temp represents the incentive variable; C temp 、R Sγ 、S L and O′ L After being processed by the obfuscation logic circuit, the second output signal C of the excitation obfuscation module is obtained. t1 .

[0133] Step 7: Repeat steps 5 to 6 until the number of confusions reaches T, and then get the output signal C. tT , as the final output signal C of the excitation confusion module O .

[0134] like Figure 6 As shown, the final output response of the anti-machine learning PUF circuit based on excitation dynamic obfuscation includes the following:

[0135] Step 1: The final output signal C of the excitation confusion module O The output response R of the third output terminal of the 64-order traditional arbiter PUF is obtained. S .

[0136] Step 2: The third output response R of the 16-order traditional arbiter PUF Sγ The third input terminal is input into the response confusion module, and R SThe output response R is input into the response obfuscation module through the fourth input terminal to obtain the output response R of the fourth output terminal, which serves as the final output result of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0137] like Figure 7 As shown, the registration phase includes the following:

[0138] Step 1: Deploy a random number generator on the server side and use it to generate a 64-bit ID number for the device to be registered. p ; Use this random number generator to generate N c The j-th bit stimulus C of the p-th device to be registered is 64 bits long. pj .

[0139] Step 2: Based on the ID number of the pth device to be registered p , generate the private key K of the pth device to be registered DSp , sent to the server.

[0140] Step 3: N c C pj Input into the 64-order traditional arbiter PUF and get N c The output response R of the j-th bit stimulus of the p-th device to be registered pj , and R pj , the circuit characteristics of the stimulus obfuscation module and the response obfuscation module are sent to the server, and the anti-fuse technology is used to cut off the external response of the device to the 64-order traditional arbiter PUF, and obtain the circuit parameters of the stimulus obfuscation module and the response obfuscation module.

[0141] Step 4: Based on N c C pj 、N c R pj As well as the circuit characteristics of the stimulus obfuscation module and the response obfuscation module, the server uses a machine learning algorithm to build a PUF model.

[0142] Step 5: The server uses a random number generator to generate a public key K S , the PUF model, K DSp and K S Store in the database, K S Sent to the pth device to be registered; when relevant data is needed, it is directly retrieved from the database.

[0143] Step 6. ID p , K DSp and K S Stored in the non-volatile memory of the pth device to be registered.

[0144] S3, the server initializes the authentication tag and initiates an authentication request. The device and the server exchange authentication information. If the authentication information is consistent with the data in the database in step S2, the authentication is successful, and the device ID and device private key are updated at the end of the authentication. Otherwise, the authentication fails, the authentication is stopped, and the authentication stage is completed. Figure 8 As shown, specifically:

[0145] Step 1: Set (TT*5%, T+T*5%) as the valid range of the current timestamp, and initialize S tag =D tag =0; where T represents the current timestamp, S tag Indicates the first authentication label, D tag Indicates the second authentication tag.

[0146] Step 2: S tag Assigned to the server, D tag Assigned to the qth device to be authenticated.

[0147] Step 3: The server generates a random number N1 using a random number generator, records the first timestamp T1, and sends N1 and T1 to the qth device to be authenticated. If T1 is within the valid range of the current timestamp, the server performs the following operations:

[0148]

[0149] R=PUF(C)

[0150] Among them, ID q Indicates the ID number of the qth device to be authenticated, represents an XOR operation, and PUF represents an anti-machine learning PUF circuit based on excitation dynamic obfuscation.

[0151] If T1 is not in the valid range of the current timestamp, perform the following operations:

[0152] Let D tag =1, the server uses a random number generator to generate a random number N2 and sets R=N2.

[0153] The timestamp after the operation is performed is recorded as the second timestamp T2, and T2 and R are sent to the server.

[0154] Step 4: Initialize the server with one registered device. If T2 is within the valid range of the current timestamp, perform the following operations:

[0155]

[0156] R w =PUF model (C w )

[0157] Among them, C w Indicates the stimulus signal of the wth registered device, ID w Indicates the wth registered device ID number, R w represents the final output response of the w-th registered device’s PUF circuit based on excitation dynamic obfuscation and anti-machine learning. model Indicates the PUF model.

[0158] If T2 is not in the valid range of the current timestamp, perform the following operations:

[0159] Let S tag =1, the server uses a random number generator to generate random numbers N4, N5 and N6, and sets A=N4, B=N5, and Tag1=N6; where A, B and Tag1 all represent authentication information.

[0160] Step 5: If R is equal to R w , the ID w and the private key K of the wth registered device DSw Remove it and do the following:

[0161] The server uses a random number generator to generate a random number N3, Among them, ASCON() represents a lightweight encryption algorithm.

[0162] If R is not equal to R w , then select the w+1th registered device and repeat step 4 until the selected registered device is the last registered device.

[0163] The timestamp after the operation is performed is recorded as the third timestamp T3, and T3, A, B and Tag1 are sent to the qth device to be authenticated.

[0164] Step 6: If D tag If it is equal to 0, and T3 is within the valid range of the current timestamp, the following operations are performed:

[0165]

[0166] N3', B' and Tag1' all represent intermediate data restored by the device using authentication information.

[0167] When B′ is equal to B and Tag1′ is equal to Tag1, the server is considered legal and the following operations are performed:

[0168] Use a random number generator to generate a random number N7, let

[0169] Among them, E, F and Tag2 all represent the authentication information in the authentication process, K DSq Indicates the private key of the qth device to be authenticated, ID q Indicates the ID number of the qth device to be authenticated.

[0170] If D tag If it is not equal to 0, T3 is not in the valid range of the current timestamp, B′ is not equal to B, or Tag1' is not equal to Tag1, then the following operations are performed:

[0171] The server is deemed illegal; let D tag =1, the server uses the random number generator to generate random numbers N8, N9 and N 10 , and let E=N8,F=N9,Tag2=N 10 .

[0172] The timestamp after the operation is performed is recorded as the fourth timestamp T4, and T4, E, F and Tag2 are sent to the server.

[0173] Step 7: If S tag If it is equal to 0, and T4 is within the valid range of the current timestamp, the following operations are performed:

[0174]

[0175] Among them, N7', F' and Tag2' all represent the intermediate data restored by the server using the authentication information, K DSw Represents the private key of the wth registered device.

[0176] When F' equals F and Tag2' equals Tag2, the qth device to be authenticated is deemed legitimate and the following operations are performed:

[0177]

[0178] in, Indicates the wth registered device ID number in the next authentication process, K DSw new Indicates the private key of the wth registered device in the next authentication process.

[0179] Will and K DSw new Update to the database and send an update request to the qth device to be authenticated.

[0180] If S tag If it is not equal to 0, T4 is not in the valid range of the current timestamp, F' is not equal to F, or Tag2' is not equal to Tag2, the following operations are performed:

[0181] Let Stag =1, the qth device to be authenticated is deemed illegal, the server does not perform any other operations, the authentication fails, and the authentication is stopped.

[0182] Step 8: After receiving the update request, the qth device to be authenticated performs the following operations:

[0183]

[0184] in, Indicates the ID number of the qth device to be authenticated in the next authentication process, K DSq new Indicates the private key of the qth device to be authenticated in the next authentication process.

[0185] Will and K DSq new Update to non-volatile memory.

[0186] At this point, the authentication is successful.

[0187] To further demonstrate the positive effects of the present invention's solution, the proposed machine learning-resistant PUF circuit was designed and implemented using a Xilinx Artix-7 series FPGA. The circuit's input stimulus and output response were collected. Using the resulting stimulus-response pairs as a dataset, four machine learning algorithms, ANN, LR, SVM, and CMA-ES, were used to attempt to model the PUF. The resulting modeling accuracy was approximately 50%, demonstrating that the proposed machine learning-resistant PUF circuit exhibits excellent resistance to modeling attacks. Furthermore, an analysis of the proposed security authentication method revealed its high security, capable of resisting replay attacks, physical attacks, and eavesdropping attacks.

[0188] An embodiment of the present invention further provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable by the processor. It should be noted that when the processor executes the computer program, it corresponds to the specific steps of the method provided in the embodiment of the present invention and has the corresponding functional modules and beneficial effects of the method. For technical details not fully described in this embodiment, please refer to the method provided in the embodiment of the present invention.

[0189] The present invention also provides a computer-readable storage medium storing a computer program. It should be noted that when executed by a processor, the computer program corresponds to the specific steps of the method provided in the present invention and has the corresponding functional modules and beneficial effects. For technical details not fully described in this embodiment, please refer to the method provided in the present invention.

[0190] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A security authentication method for a machine learning-resistant PUF circuit based on excitation dynamic obfuscation, characterized in that: include: S1. Constructing a machine learning-resistant PUF circuit based on excitation dynamic obfuscation; S2. The server generates a random stimulus and device ID and sends them to the device. The device randomly generates a device private key and uses a machine learning-resistant PUF circuit based on dynamic obfuscation of the stimulus to generate a stimulus-response pair. This response pair and the device private key are sent to the server, which then constructs the PUF model and randomly generates the device's public key. The device ID, private key, PUF model, and public key are stored in the database, completing the registration phase. S3. The server initializes the authentication tag and initiates an authentication request. The device and the server exchange authentication information. If the authentication information is consistent with the data in the database in step S2, the authentication is successful, and the device ID number and device private key are updated at the end of the authentication. Otherwise, the authentication fails, the authentication is stopped, and the authentication stage is completed.

2. The security authentication method for the machine learning resistant PUF circuit based on excitation dynamic obfuscation according to claim 1 is characterized in that: In step S1, the anti-machine learning PUF circuit based on excitation dynamic obfuscation includes an excitation obfuscation module, a strong PUF and a response obfuscation module; The stimulus confusion module includes a first input terminal, a first output terminal, and a second output terminal; The strong PUF includes a second input terminal and a third output terminal; The response obfuscation module includes a third input terminal, a fourth input terminal, and a fourth output terminal; The first output terminal is connected to the second input terminal, the second output terminal is connected to the third input terminal, and the third output terminal is connected to the fourth input terminal; The first input end serves as an input end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation, and the fourth output end serves as an output end of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

3. The security authentication method for the machine learning-resistant PUF circuit based on excitation dynamic obfuscation according to claim 2, characterized in that: The incentive obfuscation module includes a sub-PUF, two linear feedback shift registers, an obfuscation logic circuit, and a feedback path; The sub-PUF includes a fifth input terminal and fifth to seventh output terminals; The first linear feedback shift register includes a first clock input terminal CLK, a first data input terminal and a first data output terminal; The second linear feedback shift register includes a second clock input terminal CLK, a second data input terminal and a second data output terminal; Confusion logic circuits include XOR gates and data selectors; The XOR gate includes XOR first to third input terminals and an XOR output terminal, the data selector includes a third data input terminal, a fourth data input terminal, a data selection terminal and a third data output terminal, the XOR third input terminal is connected to the third data output terminal, and the fourth data input terminal is fixed to 0; The fifth output terminal is connected to the first data input terminal, the sixth output terminal is connected to the second data input terminal, the seventh output terminal is respectively connected to the second output terminal and the first XOR input terminal, the first data output terminal is connected to the second XOR input terminal, the second data output terminal is connected to the third data input terminal, the fifth input terminal and the data selection terminal serve as the first input terminal of the excitation obfuscation module, and the XOR output terminal serves as the first output terminal of the excitation obfuscation module; The feedback path includes a buffer, the input end of the buffer is connected to the first output end, and the signal output from the output end of the buffer can be iteratively input to the first input end.

4. The security authentication method for the machine learning resistant PUF circuit based on excitation dynamic obfuscation according to claim 3 is characterized in that: In step S2, the output response of the sub-PUF includes the following: Step 1: Input the excitation signal C into the anti-machine learning PUF circuit based on excitation dynamic obfuscation. After the excitation obfuscation module, the excitation signal is evenly divided into k groups to obtain k groups of sub-excitation signals, where k = m / n, where m represents the length of the excitation signal and n represents the length of the input signal at the fifth input terminal. Step 2: Sub-stimulation signals C k1 ~C kk are input into the sub-PUF through the fifth input terminal, and k output responses R are obtained. k1 ~R kk ; Among them, C k1 Indicates the first group of sub-excitation signals, C kk represents the kth group of sub-excitation signals, R k1 represents the output response corresponding to the first group of sub-stimulus signals, R kk represents the output response corresponding to the kth group of sub-stimulus signals; Step 3: k output responses R k1 ~R kk Arrange in the order of the three combinations to get three bit strings R Sα 、R Sβ and R Sγ , and is output from the fifth to seventh output terminals in sequence as the output response of the sub-PUF.

5. The security authentication method for the machine learning resistant PUF circuit based on excitation dynamic obfuscation according to claim 4 is characterized in that: In step S2, the final output signal of the excitation confusion module includes the following: Step 1: The first output response R of the sub-PUF Sα After being processed by the first linear feedback shift register, the output signal S of the first data output terminal is obtained. L ; Step 2: Set S L The number of 1s in is N1, let T = N1, T represents the total number of confusions; Step 3: The second output response R of the sub-PUF Sβ After being processed by the second linear feedback shift register, the output signal O of the second data output terminal is obtained. L ; Step 4: Excitation signal C, third output response R of sub-PUF Sγ 、S L and O L After being processed by the obfuscation logic circuit, the first output signal C of the excitation obfuscation module is obtained. t0 ; Step 5: Use the primary clock signal input from the second clock input terminal CLK to L Perform a shift, and the shifted data is used as the output signal O' of the new second data output terminal L ; Step 6: Let C temp =C t1 , C temp represents the incentive variable; C temp 、R Sγ 、S L and O′ L After being processed by the obfuscation logic circuit, the second output signal C of the excitation obfuscation module is obtained. t1 ; Step 7: Repeat steps 5 to 6 until the number of confusions reaches T, and then get the output signal C. tT , as the final output signal C of the excitation confusion module O .

6. The security authentication method for the machine learning-resistant PUF circuit based on excitation dynamic obfuscation according to claim 5, characterized in that: In step S2, the final output response of the machine learning-resistant PUF circuit based on excitation dynamic obfuscation includes the following: Step 1: The final output signal C of the excitation confusion module O The output response R of the third output terminal of the strong PUF is obtained by inputting it into the strong PUF through the second input terminal. S ; Step 2: The third output response R of the sub-PUF Sγ The third input terminal is input into the response confusion module, and R S The output response R is input into the response obfuscation module through the fourth input terminal to obtain the output response R of the fourth output terminal, which serves as the final output result of the anti-machine learning PUF circuit based on excitation dynamic obfuscation.

7. The security authentication method for the machine learning resistant PUF circuit based on excitation dynamic obfuscation according to claim 6 is characterized in that: In step S2, the registration phase includes the following: Step 1: Deploy a random number generator on the server side and use it to generate a string of IDs of the pth device to be registered with a bit length of l. p ; Use this random number generator to generate N c The j-th bit stimulus C of the p-th device to be registered with a bit length of l pj ; Step 2: Based on the ID number of the pth device to be registered p , generate the private key K of the pth device to be registered DSp , sent to the server; Step 3: N c C pj Input into the strong PUF and get N c The output response R of the j-th bit stimulus of the p-th device to be registered pj , and R pj , the circuit characteristics of the stimulus obfuscation module and the response obfuscation module are sent to the server, and the anti-fuse technology is used to cut off the external response of the device to the strong PUF, and obtain the circuit parameters of the stimulus obfuscation module and the response obfuscation module; Step 4: Based on N c C pj 、N c R pj As well as the circuit characteristics of the stimulus obfuscation module and the response obfuscation module, the server uses a machine learning algorithm to build a PUF model; Step 5: The server uses a random number generator to generate a public key K S , the PUF model, K DSp and K S Store in the database, K S Send to the pth device to be registered; when relevant data is needed, directly retrieve it from the database; Step 6. ID p , K DSp and K S Stored in the non-volatile memory of the pth device to be registered.

8. The security authentication method for the machine learning resistant PUF circuit based on excitation dynamic obfuscation according to claim 7 is characterized in that: In step S3, the authentication phase includes the following: Step 1: Set (TT*5%, T+T*5%) as the valid range of the current timestamp, and initialize S tag =D tag =0; where T represents the current timestamp, S tag Indicates the first authentication label, D tag Indicates the second authentication label; Step 2: S tag Assigned to the server, D tag Assigned to the qth device to be authenticated; Step 3: The server generates a random number N1 using a random number generator, records the first timestamp T1, and sends N1 and T1 to the qth device to be authenticated. If T1 is within the valid range of the current timestamp, the server performs the following operations: R=PUF(C) Among them, C represents the excitation signal, ID q Indicates the ID number of the qth device to be authenticated, represents an XOR operation, and PUF represents an anti-machine learning PUF circuit based on incentive dynamic obfuscation; If T1 is not in the valid range of the current timestamp, perform the following operations: Let D tag =1, the server uses a random number generator to generate a random number N2 and sets R = N2; Record the timestamp after the operation is completed as the second timestamp T2, and send T2 and R to the server; Step 4: Initialize the server with one registered device. If T2 is within the valid range of the current timestamp, perform the following operations: R w =PUF model (C w ) Among them, C w Indicates the stimulus signal of the wth registered device, ID w Indicates the wth registered device ID number, R w represents the final output response of the w-th registered device’s PUF circuit based on excitation dynamic obfuscation and anti-machine learning. model Represents the PUF model; If T2 is not in the valid range of the current timestamp, perform the following operations: Let S tag =1, the server uses a random number generator to generate random numbers N4, N5, and N6, and sets A = N4, B = N5, and Tag1 = N6; where A, B, and Tag1 all represent authentication information; Step 5: If R is equal to R w , the ID w and the private key K of the wth registered device DSw Remove it and do the following: The server uses a random number generator to generate a random number N3, Among them, ASCON() represents a lightweight encryption algorithm, K S Represents the public key; If R is not equal to R w , then select the w+1th registered device and repeat step 4 until the selected registered device is the last registered device; Record the timestamp after the operation is completed as the third timestamp T3, and send T3, A, B and Tag1 to the qth device to be authenticated; Step 6: If D tag If it is equal to 0, and T3 is within the valid range of the current timestamp, the following operations are performed: Among them, N3', B' and Tag1' all represent the intermediate data recovered by the device using the authentication information; When B′ is equal to B and Tag1′ is equal to Tag1, the server is considered legal and the following operations are performed: Use a random number generator to generate a random number N7, let Among them, E, F and Tag2 all represent the authentication information in the authentication process, K DSq Indicates the private key of the qth device to be authenticated, ID q Indicates the ID number of the qth device to be authenticated; If D tag If it is not equal to 0, T3 is not in the valid range of the current timestamp, B′ is not equal to B, or Tag1' is not equal to Tag1, then the following operations are performed: The server is deemed illegal; let D tag =1, the server uses the random number generator to generate random numbers N8, N9 and N 10 , and let E=N8,F=N9,Tag2=N 10 ; Record the timestamp after the operation is completed as the fourth timestamp T4, and send T4, E, F and Tag2 to the server; Step 7: If S tag If T4 is equal to 0 and is within the valid range of the current timestamp, the following operations are performed: Among them, N7', F' and Tag2' all represent the intermediate data restored by the server using the authentication information, K DSw represents the private key of the wth registered device; When F' equals F and Tag2' equals Tag2, the qth device to be authenticated is deemed legitimate and the following operations are performed: in, Indicates the wth registered device ID number in the next authentication process, K DSw new Indicates the private key of the wth registered device in the next authentication process; Will and K DSw new Update to the database and send an update request to the qth device to be authenticated; If S tag If it is not equal to 0, T4 is not in the valid range of the current timestamp, F' is not equal to F, or Tag2' is not equal to Tag2, the following operations are performed: Let S tag =1, the qth device to be authenticated is deemed illegal, the server will not perform any other operations, the authentication fails, and the authentication is stopped; Step 8: After receiving the update request, the qth device to be authenticated performs the following operations: in, Indicates the ID number of the qth device to be authenticated in the next authentication process, K DSq new Indicates the private key of the qth device to be authenticated in the next authentication process; Will and K DSq new Update to non-volatile memory; At this point, the authentication is successful.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the security authentication method of the anti-machine learning PUF circuit based on excitation dynamic obfuscation according to any one of claims 1 to 8 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the security authentication method for the machine learning-resistant PUF circuit based on excitation dynamic obfuscation according to any one of claims 1 to 8 is executed.

Citation Information

Patent Citations

  • Machine learning CRP confusion resisting method facing strong PUF

    CN116522296A

  • Lightweight dynamic security authentication method and system implemented based on PUF (Physical Unclonable Function)

    CN119402205A

  • System with physical non-replicable function

    CN119652504A