Reconfigurable PUF Mapping Against Heterogeneous System Modeling Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security methods for heterogeneous systems, particularly in IoT devices, are vulnerable to unauthorized attacks due to the modeling of physical unclonable function (PUF) circuits based on challenge-response pairs, leading to poor security.
Innovation Solution
A security protection method that includes detecting abnormal inputs in a heterogeneous system, acquiring a new configuration file, and reconstructing the mapping of the PUF circuit on a processor to a different layout, using a TAF-DPS-PUF circuit to generate unique responses, thereby thwarting attackers' modeling attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the PUF circuit uses a fixed configuration file for challenge-response pair generation, then the system operation is simple and stable, but the security is poor due to vulnerability to modeling attacks
Solution Approach 1:
The patent implements dynamic reconfiguration of the PUF circuit by loading different configuration files based on detected attack patterns. The system transitions from a static configuration to a dynamic one where the circuit topology can change in response to security threats, making modeling attacks ineffective while maintaining operational simplicity through automated detection and reconfiguration.
Solution Approach 2:
The system changes physical and logical parameters of the PUF circuit by loading different configuration files that modify circuit connections, delay paths, and challenge-response pair generation logic. This parameter variation prevents attackers from creating accurate models of the PUF behavior while keeping the underlying hardware structure relatively simple.
2Reliability
If the system detects abnormal inputs and reconstructs the PUF mapping, then the security is enhanced, but the processing time and energy consumption increase
Solution Approach 1:
The system performs preliminary actions by pre-loading multiple configuration files and maintaining a detection mechanism that can quickly identify attack patterns. When normal operation is detected, the system uses pre-prepared responses, and when attacks are detected, the reconfiguration process is already primed to execute rapidly, minimizing the time loss while enhancing security.
Solution Approach 2:
The system takes preliminary anti-action by detecting attack patterns before they can successfully compromise security and by having pre-prepared alternative configurations ready to deploy. This proactive approach prevents successful modeling attacks while keeping the response time minimal since the countermeasures are prepared in advance.
3Reliability
If the PUF circuit is reconstructed with a different configuration file, then attackers cannot model the circuit, but the system requires multiple configuration files increasing storage requirements
Solution Approach 1:
The patent extracts the essential security function from the physical PUF circuit hardware and implements it through configurable logic that can be loaded from storage. By separating the security-critical mapping function from the fixed hardware and making it reconfigurable, the system achieves high security with minimal storage requirements, as only configuration data rather than multiple physical circuits need to be stored.
Data Source
AI summary
Provided is a security protection method for a heterogeneous system, wherein the heterogeneous system includes a processor. The processor includes a first region, wherein the first region includes a physical unclonable function circuit. The method includes: detecting whether an input of the heterogeneous system is abnormal; acquiring a configuration file in response to the input of the heterogeneous system being detected as abnormal, wherein the acquired configuration file is different from a configuration file of the physical unclonable function circuit that has run; and reconstructing, on the processor, a mapping of the physical unclonable function circuit based on the acquired configuration file.


