The entropy source is the most critical component of a true random number generator (TRNG), which determines the quality of the random numbers. Current TRNGs mainly utilize a specific source of physical randomness as the entropy source, but it is difficult for this method to achieve a balance between low resource overhead and high throughput. This paper explores the self-feedback multiplexer (SFMUX) structure to obtain a novel dynamic hybrid entropy source for TRNGs. Unlike other MUX-based entropy source circuits, our SFMUX cross-connects the outputs of four independent high-frequency ring oscillators (ROs) as the input signals of four MUXs, and the output of each MUX is self-fed back to serve as a selection signal. Thus, the SFMUX can not only output jitter, but also update the selection signal rapidly and randomly, which increases the probability that the SFMUX outputs unstable signals. When using a D-flip-flop (DFF) to sample this signal, the DFF may become metastable. Modeling the entropy source shows that connecting 1-stage ROs and 2-stage ROs to each SFMUX can achieve higher minimum entropy than using ROs with other numbers of stages. The proposed TRNG design is implemented on Xilinx Virtex-6, Artix-7 and Kintex-7 FPGAs. The experimental results demonstrate that our TRNG achieves a maximum throughput of 550 Mbps while using only 6 slices, and it passes the NIST, AIS-31 and Dieharder tests without postprocessing.
With the growing adoption of blockchain technology, security concerns have come to the forefront. Distributed denialof-service (DDoS) attacks targeting blockchain mining pools have become particularly prominent. Such attacks could threaten the stability of blockchain systems and have a significant impact on mining pool revenues. The existing research primarily focuses on preventing DDoS attacks by utilizing machine learning for detection. However, the detection methods do not allow the mining pool to adjust its strategy to maximize the mining benefits. To solve these issues, this paper proposes a dynamic game modeling strategy. We consider the impact of factors such as attack and defense costs on the rewards of the game. Specifically, we construct an evolutionary game model to describe the interactions between the attacking and defending pools. The MATLAB simulation experiment results indicate that under the given parameter conditions, attacking mining pool choose not to attack when network conditions are poor. And attacking mining pool choose to attack when network conditions are favorable. Under better network conditions, when the cost of defense is lower, the attacking mining pool and defending mining pool engage in a cyclical game around a certain point.
True random number generator (TRNG) is the important hardware security primitive for modern internet of things (IoT) devices, while the entropy source (ES) serves as the most crucial component for TRNG. This paper explores the NAND-XOR ring oscillators (NXROs) structure to design a novel ES architecture for TRNG. The basic principle of the ES is to add a self-feedback NAND gate in XOR RO to generate a high-frequency signal, so as to apply the signal to induce a high-frequency change of XOR RO oscillation states and thus to achieve a more significant amplification for random clock jitter. In addition, our NXRO has a higher oscillation frequency and min-entropy than traditional ROs. We implement a TRNG with the new NXRO ES unit on both Xilinx Spartan-6 and Atrix-7 FPGAs. Our experiment results demonstrate that compared with the stateof-the-art TRNGs, the new TRNG achieves a higher throughput and lower hardware overhead in generating true random numbers successfully passing the NIST test and AIS31 test without post-processing.
Recently, true random number generators (TRNGs) have received much attention from academia and industry. In this article, we propose a highly random and resource-efficient entropy source for TRNG. Two new ring oscillator (RO) structures, namely NAND-XOR RO (NXRO) and feedback-XOR RO (FXORRO), are designed as entropy sources for TRNG. The basic principle of the entropy sources is that all RO outputs are cross-XORed to generate random signals and also feedback to the FXORRO enable input, so as to randomly change the FXORRO oscillation state at high speed, thus significantly expanding the jitter and randomness. Moreover, the feedback random enable signals from NXRO outputs are used to initiate the FXORRO oscillation. The experiments on Xilinx Spartan-6 and Artix-7 FPGAs show that our TRNG based on the new entropy sources unit achieves throughputs of 400 Mbps and 600 Mbps while only consuming 12 Slices. The random bit sequence generated by this TRNG successfully passes the NIST SP 800-22, 800-90B, and AIS-31 tests without post-processing and outperforms existing FPGA-based TRNGs.
As a low-cost hardware security primitive, physically unclonable function (PDF) has been widely utilized in secure key generation and identity authentication of physical devices due to the advantages of high reliability and randomness. However, hackers can model a PDF circuit by collecting a small number of challenge- response pairs (CRPs), making it potentially vulnerable to machine learning (ML) attacks. To effectively resist this risk, various ML-resistance methods have been proposed. However, most of them mainly enhance the anti-attack ability of PDFs by structure nonlinear and CRP obfuscation, reducing stability and reliability. Therefore, we present a logic encryption-enhanced PDF (LEE PDF) architecture to resist ML-based attacks without affecting PDF performance. A logic encryption unit is applied to protect the function of original PDF circuits, thus concealing the valid CRPs in a large number of useless ones. Since hackers can only obtain a sparse number of useful CRPs without knowing the correct key, making it impossible to model PDF using ML methods. We have implemented the proposed LEE PDF on FPGA micro-boards. The experimental results demonstrate that the LEE PDF with only 2-bit key can effectively resist various ML- based attacks, average prediction rate is close to 50 %. In addition, the PDF performance remains almost constant.
Strong physical unclonable function (PUF) is a low-cost hardware security primitive to protect Internet-of-Things (IoT) devices. However, it may be attacked by machine learning (ML). Various PUF models designed in complex structures, such as nonlinearity or challenge-response pair (CRP) obfuscation, have been presented to combat these risks. However, these methods mainly increase area overhead, and the prediction rate is still very high. Therefore, this paper proposes a structure obfuscated PUF named SO-PUF. Our proposal derives from the configurable ring oscillator (CRO) PUF. The CRO can be transformed into two different structures depending on the challenges by randomly deleting one of the two NOT gates in each stage. Thus, half of the CRPs generated by SO-PUF are invalid, which will confuse the attackers. We have implemented and verified the performance of SO-PUF on the Xilinx-6XC6SLX25 microboard. Experimental results show that compared with the dual-mode PUF, the SO-PUF improves uniqueness by 0.71 %, temperature reliability by 38.4 %, and voltage reliability by 1.92 %. In addition, the SO-PUF also reduces the prediction rates of LR, SVM, and ANN modeling attacks by 0.26 %, 0.38 %, and 5.62 %, respectively. The results prove that SO-PUF has better resistance to ML attacks than dual-mode PUF.
Physically unclonable function (PUF) can be applied as a lightweight way to improve the security of Internet of Thing (IoT) devices. In the existing PUF studies, reconfigurable Pico-PUF (RPPUF) is an effective solution with good uniqueness and reliability. However, it still has a limited key space and requires extra hardware resources to generate more challenge-response pairs (CRPs). Therefore, this paper improves the RPPUF and proposes a lightweight XOR-based Pico-PUF, namely XORPPUF. By replacing each NOT gate in the configurable logic with an XOR gate, the key space is effectively expanded while preserving the PUF performance. We have implemented and verified the proposed XORPPUF on Xilinx Spartan-6 XC6SLX25 microboards. The experimental results show that XORPPUF achieves 40.06% uniqueness and 99.49% temperature reliability. Compared with the RPPUF, our work improves temperature reliability by 0.26%, expands key space by 2 n , and reduces hardware resources overhead by 11.3% when generating a 128-bit PUF response. In addition, the prediction rate of our XORPPUF against Decision Tree (DT) and Random Forest (RF)-based modeling attacks is 34.17% and 39.40% lower than RPPUF, respectively. This means XORPPUF performs better resistant than RPPUF in Machine Learning (ML) attack. Thus, it is more suitable for securing the IoT devices with limited resources.