网络与信息安全学报 ›› 2021, Vol. 7 ›› Issue (3): 115-122.doi: 10.11959/j.issn.2096-109x.2021019

• 学术论文 • 上一篇    

基于对抗学习的强PUF安全结构研究

李艳, 刘威, 孙远路   

  1. 信息工程大学,河南 郑州 450001
  • 修回日期:2020-07-02 出版日期:2021-06-01 发布日期:2021-06-01
  • 作者简介:李艳(1988- )女,河南郑州人,信息工程大学讲师,主要研究方向为网络空间安全
    刘威(1982- )男,湖北随州人,信息工程大学讲师,主要研究方向为硬件安全
    孙远路(1974- )男,河南商丘人,信息工程大学副教授,主要研究方向为管理科学与工程
  • 基金资助:
    国家自然科学基金(61871405);国家自然科学基金(61802431)

Research on security architecture of strong PUF by adversarial learning

Yan LI, Wei LIU, Yuanlu SUN   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2020-07-02 Online:2021-06-01 Published:2021-06-01
  • Supported by:
    The National Natural Science Foundation of China(61871405);The National Natural Science Foundation of China(61802431)

摘要:

针对强物理不可复制函数(PUF,physical unclonable function)面临的机器学习建模威胁,基于对抗学习理论建立了强PUF的对抗机器学习模型,在模型框架下,通过对梯度下降算法训练过程的分析,明确了延迟向量权重与模型预测准确率之间的潜在联系,设计了一种基于延迟向量权重的对抗样本生成策略。该策略与传统的组合策略相比,将逻辑回归等算法的预测准确率降低了5.4%~9.5%,低至51.4%。结合资源占用量要求,设计了新策略对应的电路结构,并利用对称设计和复杂策略等方法对其进行安全加固,形成了ALPUF(adversarial learning PUF)安全结构。ALPUF不仅将机器学习建模的预测准确率降低至随机预测水平,而且能够抵御混合攻击和暴力破解。与其他 PUF结构的对比表明,ALPUF在资源占用量和安全性上均具有明显优势。

关键词: 物理不可复制函数, 对抗样本, 延迟向量, 对抗学习PUF

Abstract:

To overcome the vulnerability of strong physical unclonable function, the adversarial learning model of strong PUF was presented based on the adversarial learning theory, then the training process of gradient descent algorithm was analyzed under the framework of the model, the potential relationship between the delay vector weight and the prediction accuracy was clarified, and an adversarial sample generation strategy was designed based on the delay vector weight.Compared with traditional strategies, the prediction accuracy of logistic regression under new strategy was reduced by 5.4% ~ 9.5%, down to 51.4%.The physical structure with low overhead was designed corresponding to the new strategy, which then strengthened by symmetrical design and complex strategy to form a new PUF architecture called ALPUF.ALPUF not only decrease the prediction accuracy of machine learning to the level of random prediction, but also resist hybrid attack and brute force attack.Compared with other PUF security structures, ALPUF has advantages in overhead and security.

Key words: strong physical unclonable function, adversarial sample, delay vector, adversarial learning PUF

中图分类号: 

No Suggested Reading articles found!