A Unified Approach to Strong PUF and TRNG Using Ring Generator for Cryptography

Tuan-Kiet Dang, Khai-Duy Nguyen, Trong-Thuc Hoang, Cong‐Kha Pham · IEEE Internet of Things Journal · 2025

Physical Unclonable Functions (PUFs) and True Random Number Generators (TRNGs) primitives always come in pairs to provide authenticity and unpredictability for cryptographic applications. Specifically, PUF-based authentication presents huge potential for a lightweight, low-power, and efficient solution to secure communication in the Internet of Things (IoT) networks. In any PUF-based scheme, the exchanging materials comprise PUF’s responses and random nonces to generate shared session keys. PUFs offer authentication properties to a device by generating reproducible and device-specific randomness, whereas TRNGs harvest random entropy from physical phenomena to produce completely unpredictable output. This paper introduces a design approach to a unified circuit of PUF and TRNG targeting lightweight and versatile to meet the constrained requirements of IoT devices. The design employs the XOR-Latch (XL) cell to extract uncontrollable manufacturing variances to yield a stable and unique output. Additionally, with specific excitation, it can operate as an oscillator. Multiple XL cells are connected to a ring generator, which serves as a back-end obfuscation structure, to construct a robust strong PUF. Our final design on Xilinx Artix-7 FPGA features a compact hardware footprint of 102 Look-Up Tables (LUTs) and 32 Flip-Flops (FFs), which can be positioned within 26 SLICEs. Various design strategies were employed to assess the feasibility of ASIC implementation. Experimental analyses of the PUF mode performance have shown that the uniformity, uniqueness, and reliability metrics satisfy the standards, and the design is resistant to state-of-the-art modeling attacks. Furthermore, the TRNG function has undergone rigorous testing, including various health checks and standard random tests recommended by the National Institute of Standards and Technology (NIST) and the German Federal Office for Information Security (BSI).

Read the paper · More papers on PaperTik