Breaching the Gap: Modelling SRAM-PUFs via Side-Channel Signatures

Kuheli Pratihar, Soumi Chatterjee, Rajat Subhra Chakraborty, Debdeep Mukhopadhyay · 2024

Cryptographic systems employing SRAM-based Physically Unclonable Functions (SRAM-PUFs) rely on the assumption that modelling the internal PUF state is practically infeasible. This work investigates the modelling prowess of an adversary with access to side-channel information collected from similar, albeit not identical, devices to develop templates for leakages. To the best of our knowledge, this is the first work to show the modelling vulnerability of SRAM-PUFs to side-channel leakages by utilizing the correlation between power, electromagnetic signatures obtained from similar devices with identical patterns in their PUF responses. To evaluate the effectiveness of our attack, we perform extensive experiments on ATmega328P and demonstrate a maximum accuracy of 98.45% in the Hamming Weight ( Math 2 ) prediction of the PUF responses and Math 3 for the exact PUF response over 50 target devices. Our attack’s feasibility also extends to newer technology nodes, as validated on the 32-bit ARM Cortex M0+. Additionally, we augment the well-known helper data induced min-entropy loss to factor in the effect of side-channels and show that the residual entropy per byte of SRAM-PUF reduces significantly due to Math 4 leakage. Lastly, we propose an in-situ masking countermeasure using SRAM metastable cells, that effectively randomizes the side-channel signatures and reduces the Math 5 prediction accuracy to Math 6 .

Read the paper · More papers on PaperTik