PUF-Based Authentication in IoT Against Strong Physical Adversary Using Zero-Knowledge Proofs

Lukas Petzi, Alexandra Dmitrienko, Ivan Visconti · 2024

This work focuses on utilising Physically Unclonable Functions (PUFs) for device authentication, exploiting a device's unique manufacturing-induced hardware variations. Traditional PUF-based authentication methods often rely on trusted third parties for validation or necessitate that Verifiers maintain large databases. Existing approaches that aim to reduce storage demands by reutilizing information typically address only networklevel threats, leading to doubts about the necessity of PUFs, or they focus exclusively on adversaries aiming at non-volatile memory. This paper introduces a classification guideline that delineates the scenarios in which PUFs are necessary or advantageous. Additionally, we present a novel PUF-based authentication scheme that incorporates challenge concealment to safeguard against comprehensive invasive physical attacks. This method offers perfect hiding, an enhanced level of security compared to previous models that permitted the reusing of PUF challenges. Through this approach, we aim to provide a more secure yet efficient framework for PUF-based authentication, addressing the limitations of current methodologies and extending the protection against a broader spectrum of adversaries.

Read the paper · More papers on PaperTik