On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices

The proliferation of devices for the Internet of Things (IoT) and their implication in many activities of our lives have led to a considerable increase in concern about the security of these devices, posing a double challenge for designers and developers of products. On the one hand, the design of n...

ver descrição completa

Detalhes bibliográficos
Autores: Rojas Muñoz, Luis F., Sánchez Solano, Santiago, Martínez Rodríguez, Macarena Cristina, Brox Jiménez, Piedad
Tipo de documento: artigo
Estado:Versão publicada
Data de publicação:2023
País:España
Recursos:Universidad de Sevilla (US)
Repositório:idUS. Depósito de Investigación de la Universidad de Sevilla
OAI Identifier:oai:idus.us.es:11441/147519
Acesso em linha:https://hdl.handle.net/11441/147519
https://doi.org/10.3390/s23084070
Access Level:Acceso aberto
Palavra-chave:Embedded systems
Hardware security
Key generation
Physical unclonable functions
Reconfigurable devices
True-random number generator
id ES_c3ce50e0964c8442eded21c5e8bcb215
oai_identifier_str oai:idus.us.es:11441/147519
network_acronym_str ES
network_name_str España
repository_id_str
spelling On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT DevicesRojas Muñoz, Luis F.Sánchez Solano, SantiagoMartínez Rodríguez, Macarena CristinaBrox Jiménez, PiedadEmbedded systemsHardware securityKey generationPhysical unclonable functionsReconfigurable devicesTrue-random number generatorThe proliferation of devices for the Internet of Things (IoT) and their implication in many activities of our lives have led to a considerable increase in concern about the security of these devices, posing a double challenge for designers and developers of products. On the one hand, the design of new security primitives, suitable for resource-limited devices, can facilitate the inclusion of mechanisms and protocols to ensure the integrity and privacy of the data exchanged over the Internet. On the other hand, the development of techniques and tools to evaluate the quality of the proposed solutions as a step prior to their deployment, as well as to monitor their behavior once in operation against possible changes in operating conditions arising naturally or as a consequence of a stress situation forced by an attacker. To address these challenges, this paper first describes the design of a security primitive that plays an important role as a component of a hardware-based root of trust, as it can act as a source of entropy for True Random Number Generation (TRNG) or as a Physical Unclonable Function (PUF) to facilitate the generation of identifiers linked to the device on which it is implemented. The work also illustrates different software components that allow carrying out a self-assessment strategy to characterize and validate the performance of this primitive in its dual functionality, as well as to monitor possible changes in security levels that may occur during operation as a result of device aging and variations in power supply or operating temperature. The designed PUF/TRNG is provided as a configurable IP module, which takes advantage of the internal architecture of the Xilinx Series-7 and Zynq-7000 programmable devices and incorporates an AXI4-based standard interface to facilitate its interaction with soft- and hard-core processing systems. Several test systems that contain different instances of the IP have been implemented and subjected to an exhaustive set of on-line tests to obtain the metrics that determine its quality in terms of uniqueness, reliability, and entropy characteristics. The results obtained prove that the proposed module is a suitable candidate for various security applications. As an example, an implementation that uses less than 5% of the resources of a low-cost programmable device is capable of obfuscating and recovering 512-bit cryptographic keys with virtually zero error rate.European Union 952622Ministerio de Ciencia e Innovación PID2020-116664RB100Multidisciplinary Digital Publishing Institute (MDPI)Electrónica y ElectromagnetismoEuropean Union (UE)Ministerio de Ciencia e Innovación (MICIN). España2023info:eu-repo/semantics/articleinfo:eu-repo/semantics/publishedVersionapplication/pdfapplication/pdfhttps://hdl.handle.net/11441/147519https://doi.org/10.3390/s23084070reponame:idUS. Depósito de Investigación de la Universidad de Sevillainstname:Universidad de Sevilla (US)InglésSensors, 23 (8), 4070.952622PID2020-116664RB100https://doi.org/10.3390/s23084070info:eu-repo/semantics/openAccessoai:idus.us.es:11441/1475192026-06-17T12:51:07Z
dc.title.none.fl_str_mv On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
title On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
spellingShingle On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
Rojas Muñoz, Luis F.
Embedded systems
Hardware security
Key generation
Physical unclonable functions
Reconfigurable devices
True-random number generator
title_short On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
title_full On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
title_fullStr On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
title_full_unstemmed On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
title_sort On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices
dc.creator.none.fl_str_mv Rojas Muñoz, Luis F.
Sánchez Solano, Santiago
Martínez Rodríguez, Macarena Cristina
Brox Jiménez, Piedad
author Rojas Muñoz, Luis F.
author_facet Rojas Muñoz, Luis F.
Sánchez Solano, Santiago
Martínez Rodríguez, Macarena Cristina
Brox Jiménez, Piedad
author_role author
author2 Sánchez Solano, Santiago
Martínez Rodríguez, Macarena Cristina
Brox Jiménez, Piedad
author2_role author
author
author
dc.contributor.none.fl_str_mv Electrónica y Electromagnetismo
European Union (UE)
Ministerio de Ciencia e Innovación (MICIN). España
dc.subject.none.fl_str_mv Embedded systems
Hardware security
Key generation
Physical unclonable functions
Reconfigurable devices
True-random number generator
topic Embedded systems
Hardware security
Key generation
Physical unclonable functions
Reconfigurable devices
True-random number generator
description The proliferation of devices for the Internet of Things (IoT) and their implication in many activities of our lives have led to a considerable increase in concern about the security of these devices, posing a double challenge for designers and developers of products. On the one hand, the design of new security primitives, suitable for resource-limited devices, can facilitate the inclusion of mechanisms and protocols to ensure the integrity and privacy of the data exchanged over the Internet. On the other hand, the development of techniques and tools to evaluate the quality of the proposed solutions as a step prior to their deployment, as well as to monitor their behavior once in operation against possible changes in operating conditions arising naturally or as a consequence of a stress situation forced by an attacker. To address these challenges, this paper first describes the design of a security primitive that plays an important role as a component of a hardware-based root of trust, as it can act as a source of entropy for True Random Number Generation (TRNG) or as a Physical Unclonable Function (PUF) to facilitate the generation of identifiers linked to the device on which it is implemented. The work also illustrates different software components that allow carrying out a self-assessment strategy to characterize and validate the performance of this primitive in its dual functionality, as well as to monitor possible changes in security levels that may occur during operation as a result of device aging and variations in power supply or operating temperature. The designed PUF/TRNG is provided as a configurable IP module, which takes advantage of the internal architecture of the Xilinx Series-7 and Zynq-7000 programmable devices and incorporates an AXI4-based standard interface to facilitate its interaction with soft- and hard-core processing systems. Several test systems that contain different instances of the IP have been implemented and subjected to an exhaustive set of on-line tests to obtain the metrics that determine its quality in terms of uniqueness, reliability, and entropy characteristics. The results obtained prove that the proposed module is a suitable candidate for various security applications. As an example, an implementation that uses less than 5% of the resources of a low-cost programmable device is capable of obfuscating and recovering 512-bit cryptographic keys with virtually zero error rate.
publishDate 2023
dc.date.none.fl_str_mv 2023
dc.type.none.fl_str_mv info:eu-repo/semantics/article
info:eu-repo/semantics/publishedVersion
format article
status_str publishedVersion
dc.identifier.none.fl_str_mv https://hdl.handle.net/11441/147519
https://doi.org/10.3390/s23084070
url https://hdl.handle.net/11441/147519
https://doi.org/10.3390/s23084070
dc.language.none.fl_str_mv Inglés
language_invalid_str_mv Inglés
dc.relation.none.fl_str_mv Sensors, 23 (8), 4070.
952622
PID2020-116664RB100
https://doi.org/10.3390/s23084070
dc.rights.none.fl_str_mv info:eu-repo/semantics/openAccess
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
application/pdf
dc.publisher.none.fl_str_mv Multidisciplinary Digital Publishing Institute (MDPI)
publisher.none.fl_str_mv Multidisciplinary Digital Publishing Institute (MDPI)
dc.source.none.fl_str_mv reponame:idUS. Depósito de Investigación de la Universidad de Sevilla
instname:Universidad de Sevilla (US)
instname_str Universidad de Sevilla (US)
reponame_str idUS. Depósito de Investigación de la Universidad de Sevilla
collection idUS. Depósito de Investigación de la Universidad de Sevilla
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869418827514642432
score 15,301603