Software PUF on RISC-V Processor for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IoT security systems face high implementation and maintenance costs, and traditional hardware PUFs are ineffective in extremely resource-limited IoT environments, where hardware changes are not feasible.
Innovation Solution
A software PUF based on a 32-bit RISC-V processor that uses temperature and voltage sensors to generate output responses by comparing normal and abnormal operating states, avoiding exclusive hardware overheads and enhancing security and stability through dynamic frequency compensation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware PUF is used to generate secure output responses, then security is improved, but device complexity and hardware overhead increase
Solution Approach 1:
The patent replaces the hardware circuit-based PUF system with a software-based PUF system that runs on general-purpose processors. Instead of using physical hardware structures like arbiter circuits or ring oscillators, the invention uses software programs that exploit timing violations and abnormal information generation during processor execution to generate PUF responses, thereby eliminating the need for dedicated hardware PUF components.
Solution Approach 2:
The software PUF can be deployed on existing general-purpose processors without requiring specialized hardware. The same processor can execute both normal applications and PUF generation functions, making the system universally applicable across different platforms without adding dedicated hardware overhead.
2Reliability
If hardware PUF is implemented in IoT devices, then security is improved, but implementation cost and design time increase
Solution Approach 1:
The patent uses software code as a copyable, configurable representation of PUF functionality. Instead of manufacturing dedicated hardware circuits for each device, the same software PUF implementation can be copied and deployed across multiple IoT devices, significantly reducing manufacturing costs and design time while maintaining security functionality.
Solution Approach 2:
The software PUF approach uses inexpensive software implementations rather than expensive hardware circuits. The software can be updated, modified, or replaced without hardware changes, making it a cost-effective solution for resource-constrained IoT devices where hardware modifications are prohibitively expensive.
3Adaptability or versatility
If hardware changes are made to adapt to hardware PUF, then PUF functionality is achieved, but product design cost and time increase
Solution Approach 1:
Instead of modifying hardware to achieve PUF functionality, the patent inverts the approach by keeping hardware unchanged and implementing PUF functionality through software. The software exploits the inherent timing characteristics and abnormal information generation of the existing processor architecture, eliminating the need for hardware modifications entirely.
Solution Approach 2:
The patent replaces hardware-based PUF implementation with software-based implementation, substituting physical circuit modifications with programmable software solutions that achieve the same PUF functionality without requiring any hardware changes to the processor or surrounding circuitry.
4Device complexity
If software PUF is used to avoid hardware overhead, then device complexity is reduced, but security and stability may be compromised
Solution Approach 1:
The patent converts the harmful effect of timing violations and abnormal information generation (which normally indicate processor errors or failures) into a beneficial security feature. By deliberately inducing timing violations through frequency adjustments and using the resulting abnormal information as PUF responses, the system transforms potential security vulnerabilities into a robust security mechanism that is resistant to modeling attacks.
Data Source
AI summary
Disclosed is a software PUF based on an RISC-V processor for IoT security. A 32-bit RISC-V processor is used to generate abnormal information results in an abnormal operating state under a low voltage, and the abnormal information results are used to represent the features of the 32-bit RISC-V processor; 5-bit binary data obtained by comparing the abnormal information results with normal information results has high randomness and uniqueness and it is extremely difficult to directly extract internal abnormal information result from a hardware circuit of the 32-bit RISC-V processor, so modeling attacks based on the 5-bit binary data calculated according to the abnormal information results of the 32-bit RISC-V processor are almost impossible; in addition, when the 32-bit RISC-V processor is in an abnormal operating state, the operating frequency of the 32-bit RISC-V processor is dynamically adjusted through a frequency compensation method.


