Secure Content Protection Schemes for Industrial IoT with SRAM PUF-Based One-Time Use Cryptographic Keys
摘要
This paper outlines our primary objectives, which revolved around devising a robust and lightweight solution for safeguarding industrial Internet of Things (IoT) device’s content. Our study delves into the critical issue of potential vulnerabilities in cryptographic keys within insecure communication networks, vulnerable to side-channel attacks and data leaks. Additionally, it introduces practical flexibility in real-world applications by enabling the generation of keys with the required length while upholding a high level of security. To counteract the risk of losing cryptographic keys in insecure environments, our proposed solution integrates Physical Unclonable Functions (PUFs) and available Error Correction Code (ECC). This integration produces a flexible-length, one-time-use key tailored to specific software requirements. Our protocol employs commercially available Static Random Access Memory (SRAM) devices, one-way hashing functions, incorporates various error-correcting schemes, and utilizes standardized cryptographic algorithms like AES128 and AES256 to enhance security. Rigorous characterization of SRAMs, achieved through multiple readings under diverse conditions and temperatures, optimizes randomness while minimizing bit error rates. Validation of the protocol encompasses demonstrating low bit error rates at low latency, understanding the random cell selection for key generation, and analyzing and comparing three different ECCs like Reed Solomon (RS), Bose-Chaudhuri-Hocquenghem (BCH), and Response-Based Cryptography (RBC). Furthermore, ECCs are refined to reduce latencies while maintaining negligible failure rates in cryptographic key recovery and ensuring that helper data remains secure. This comprehensive approach aims to significantly enhance the security and efficiency of data transfers in IoT devices, particularly in the face of potential threats in insecure communication networks.