IoT Device Security Using PUF-Based Tags: A Lightweight Protocol for Preventing Hardware Substitution
摘要
The swift expansion of the Internet of Things (IoT) has intensified concerns regarding device security, particularly in the areas of authentication and identification. In response, silicon Physically Unclonable Functions (PUFs) have been adopted, categorized into “strong” and “weak” types. Strong PUFs, capable of generating numerous Challenge-Response Pairs (CRPs), are used for robust device authentication. In contrast, weak PUFs, such as SRAM-based types, generate fewer CRPs and are more suited for tasks like device identification. This paper improves a recent novel IoT device security framework that leverages both PUF types to address these challenges. The framework utilizes a monostatic-based strong PUF connected via a hardwired interface to an electronic device (e.g., a sensor), serving as an authentication tag (ID tag). Concurrently, the device’s SRAM serves as a weak PUF, aiding in the identification and preventing hardware substitution attacks-where an alternate device might be connected to the same ID tag. A key contribution of this paper is the presentation of a novel lightweight identification protocol that significantly improves the efficiency of verifying the original device’s identity. This improvement involves replacing the traditional approach of reading the entire SRAM with just a small portion of it, thereby streamlining the identification process and enhancing security within the IoT ecosystem.