As the number of devices being interconnected increases, so does also the demand for (lightweight) security. To this end, Physical Unclonable Functions (PUFs) have been proposed as hardware primitives that can act as roots of trust and security. Recently, a new type of PUF based on Carbon NanoTubes (CNTs) has been proposed. At the same time, attacks and testing based on direct electrical probing appear to be moving towards non-invasive techniques. In this context, this work attempts to examine the potential for practical non-invasive probing attacks against the CNT-PUF, a novel PUF based on CNTs. Our results indicate that direct probing might potentially compromise the security of this PUF. Nevertheless, we note that this holds true only in the case that the attacker can directly probe the wire corresponding to the secret value of each CNT-PUF cell. Thus, we can conclude that the examined CNT-PUFs are rather resilient to direct probing attacks, that non-invasive probing methods appear to be promising for testing such PUFs, and that, in order for the attacker to gain the full-length value of the secret, all the relevant channels would need to be probed. Nevertheless, as our work proves, practical non-invasive attacks against the CNT-PUF are feasible and adequate countermeasures need to be employed in order to address this issue.
翻译:随着互联设备数量的增加,对(轻量级)安全的需求也在增长。为此,物理不可克隆函数(PUF)被提出作为能够充当信任根和安全基石的硬件原语。近期,一种基于碳纳米管(CNT)的新型PUF被提出。与此同时,基于直接电学探测的攻击与测试方法正逐步向非侵入式技术演进。在此背景下,本文尝试探讨针对CNT-PUF(一种基于CNT的新型PUF)实施实用非侵入式探测攻击的可能性。研究结果表明,直接探测可能潜在地损害该PUF的安全性。但需注意,这一结论仅在攻击者能够直接探测对应每个CNT-PUF单元秘密值的导线时成立。因此,可得出结论:所研究的CNT-PUF对直接探测攻击具有较强抵抗性,非侵入式探测方法在测试此类PUF时展现出良好前景,且攻击者为获取完整长度的秘密值需要探测所有相关通道。尽管如此,本研究证明针对CNT-PUF的实用非侵入式攻击切实可行,亟需部署充足的对抗措施以解决该问题。