Optimal Machine-Learning Attacks on Hybrid PUFs
摘要
Physical Unclonable Functions (PUFs) are a promising, low-cost entropy source and security primitive for Internet-of-Things (IoT) applications, widely used in authentication, key generation and management. As PUFs have been investigated further, they have often been found to be vulnerable to machine-learning attacks (MLA). Despite numerous attempts to fortify PUFs against such vulnerabilities by innovating with different structures and compositions - among which hybrid PUFs were considered a promising approach - the security of these designs against MLA largely remained untested. Specifically, this paper targets the recently introduced hybrid PUFs, namely the heterogeneous Feed-Forward PUFs [1] and OAX PUFs [28], which were claimed to be secure against MLAs. Contrary to these claims, to the best of our knowledge, we are the first to report that even these advanced PUF structures are not immune to MLA. Furthermore, the paper delivers a comprehensive evaluation of the MLA resistance of hybrid PUF structures and proposes the Transition Theorem, which provides a novel insight for performing Hybrid PUF modelling. We successfully apply this theory to three classic attack models, Ruhrmair2010 [18], Mursi2020 [16] and Wisiol2022 [27], and enable them to successfully attack the earlier PUFs modelling failures. This theory contributes to the effectiveness of current strategies and lays the groundwork for future advancements in PUF security.