节点文献

基于信号延迟的芯片指纹提取技术及其安全应用

Signal Latency Based Chip Signature Extraction Techniques with Its Secure Application

【作者】 高雪峰

【导师】 谷大武;

【作者基本信息】 上海交通大学 , 计算机系统结构, 2008, 硕士

【摘要】 所有计算机系统的安全性,几乎都取决于对密钥等核心秘密的可靠保护。但多数系统对密钥保护的安全程度很低,尤其在面临物理攻击时,往往会造成密钥的泄漏而丧失系统的安全性。芯片指纹扩展了芯片在制造过程中由环境变化所引起的线路和晶体管的静态时延差异,是芯片物理特征的反映,能够用来建立不可复制的密钥,从物理上保证了系统的安全。本文主要研究基于信号延迟的芯片指纹提取技术及其安全应用,在分析Daihyun方案的基础上,提出了两个芯片指纹提取改进方案,并给出了基于FPGA的实现。测试结果表明改进方案提取的芯片指纹随机性优于Daihyun方案,能够用来建立不可复制的密钥,保证系统的物理安全性。本文还扩展了芯片指纹在身份认证方面的安全应用。在分析Das等人的方案漏洞的基础上,引入芯片指纹,提出了一种改进的身份认证方案。此方案从物理上保证了智能卡片内密钥的安全。基于这一独特的安全属性,该方案能够抵御伪装攻击、芯片复制攻击、拒绝服务攻击、重传攻击、口令猜测攻击等,从而可靠地实现了服务器对用户的身份认证。在对系统安全度要求较高的环境中有着良好的应用前景。

【Abstract】 Nearly all the security issues of a computer system are due to the protection of the confidential information such as keys. But most of the current systems are weak in terms of protecting the keys; especially when facing the physical attack, the keys will easily get leaked so that the security of the computer system is damaged. Chip signature extends the differences of chips, which are caused by the impact of environment changes on the circuits and transistors during the manufacturing, is the unique identity of chip feature, so that can be used to construct a non-reproducible key to protect the security of the computer system.The chip signature extraction technique based on signal latency, as well as the application of this new technique, is discussed. Based on Daihyun’s approach, two improved schemes are proposed and implemented on FPGA.The experiment results showed that improved scheme could produce more random signatures, and thus could be used to construct a non-reproducible key to protect the physical security of the system;The application of the chip signature in identity authentication was also introduced. Based on the analysis of Das’solution, an improved identity authentication protocol was introduced by using chip signature. The new protocol could protect the key in the chip from the physical nature. Based on the unique security feature, the new protocol could protect against impersonation attack, chip replication attack, DoS attack, replay attack, password-guess attack, etc. The new protocol could be widely used in those scenarios that required a high security environment.

  • 【分类号】TP309
  • 【被引频次】1
  • 【下载频次】113
节点文献中: 

本文链接的文献网络图示:

本文的引文网络