{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T07:59:08Z","timestamp":1782374348614,"version":"3.54.5"},"reference-count":40,"publisher":"Engineering and Technology Publishing","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["jcm"],"published-print":{"date-parts":[[2020]]},"abstract":"<jats:p>Security is critically important for Internet-of-Things, but existing cryptographic protocols are not lightweight enough for resource-constrained IoT devices. Implementable with simplistic circuits and operable with shallow power, physical unclonable functions (PUFs) leverage small but unavoidable physical variations of the circuit to produce unique responses for individual PUF instances, rendering themselves good candidates as security primitives for IoT devices. Component-differentially-challenged XOR PUFs (CDC XPUFs) are among the PUFs which were shown to be highly secure to machine learning modeling attacks. However, no study of implementation and experimentation has been carried out. In this paper, we report our implementations of CDC XPUFs on FPGAs and experimental studies of the essential properties of CDC XPUFs.<\/jats:p>","DOI":"10.12720\/jcm.15.10.714-721","type":"journal-article","created":{"date-parts":[[2020,12,29]],"date-time":"2020-12-29T06:43:57Z","timestamp":1609224237000},"page":"714-721","source":"Crossref","is-referenced-by-count":5,"title":["Experimental Study of Component-Differentially-Challenged XOR PUFs as Security Primitives for Internet-of-Things"],"prefix":"10.12720","author":[{"name":"Department of Computer Science, Texas Tech University, Lubbock, Texas, USA","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Khalid T.","family":"Mursi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Zhuang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"4977","published-online":{"date-parts":[[2020]]},"reference":[{"key":"ref0","doi-asserted-by":"publisher","unstructured":"[1] M. D. Yu, M. Hiller, J. Delvaux, R. Sowell, S. Devadas, and I. Verbauwhede, \"A lockdown technique to prevent machine learning on PUFs for lightweight authentication,\" IEEE Transactions on Multi-Scale Computing Systems, vol. 2, pp. 146-159, 2016.","DOI":"10.1109\/TMSCS.2016.2553027"},{"key":"ref1","doi-asserted-by":"publisher","unstructured":"[2] C. Herder, M. D. Yu, F. Koushanfar, and S. Devadas, \"Physical unclonable functions and applications: A tutorial,\" Proceedings of the IEEE, vol. 102, pp. 1126-1141, 2014.","DOI":"10.1109\/JPROC.2014.2320516"},{"key":"ref2","doi-asserted-by":"publisher","unstructured":"[3] D. Gruss, C. Maurice, K. Wagner, and S. Mangard, \"Flush+ Flush: a fast and stealthy cache attack,\" in Proc. International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, 2016.","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"ref3","unstructured":"[4] O. K\u00f6mmerling and M. G. Kuhn, \"Design principles for tamper-resistant smartcard processors,\" Smartcard, vol. 99, pp. 9-20, 1999."},{"key":"ref4","doi-asserted-by":"publisher","unstructured":"[5] D. A. Osvik, A. Shamir, and E. Tromer, \"Cache attacks and countermeasures: The case of AES,\" in Proc. Cryptographers' Track at the RSA Conference, 2006.","DOI":"10.1007\/11605805_1"},{"key":"ref5","doi-asserted-by":"publisher","unstructured":"[6] U. R\u00fchrmair and D. E. Holcomb, \"PUFs at a glance,\" in Proc. Design, Automation & Test in Europe Conference & Exhibition (DATE), 2014.","DOI":"10.7873\/DATE.2014.360"},{"key":"ref6","unstructured":"[7] S. P. Skorobogatov, \"Semi-invasive attacks: A new approach to hardware security analysis,\" 2005."},{"key":"ref7","unstructured":"[8] Y. Yarom and K. Falkner, \"FLUSH+ RELOAD: A high resolution, low noise, L3 cache side-channel attack,\" in Proc. 23rd {USENIX} Security Symposium ({USENIX} Security 14), 2014."},{"key":"ref8","doi-asserted-by":"publisher","unstructured":"[9] B. Gassend, D. Clarke, M. V. Dijk, and S. Devadas, \"Silicon physical random functions,\" in Proc. 9th ACM Conference on Computer and Communications Security, 2002.","DOI":"10.1145\/586110.586132"},{"key":"ref9","doi-asserted-by":"publisher","unstructured":"[10] B. Gassend, D. Clarke, M. V. Dijk, and S. Devadas, \"Controlled physical random functions,\" in Proc. 18th Annual Computer Security Applications Conference, 2002.","DOI":"10.1145\/586110.586132"},{"key":"ref10","doi-asserted-by":"publisher","unstructured":"[11] G. E. Suh and S. Devadas, \"Physical unclonable functions for device authentication and secret key generation,\" in Proc. 44th ACM\/IEEE Design Automation Conference, 2007.","DOI":"10.1109\/DAC.2007.375043"},{"key":"ref11","doi-asserted-by":"publisher","unstructured":"[12] M. Majzoobi, M. Rostami, F. Koushanfar, D. S. Wallach, and S. Devadas, \"Slender PUF protocol: A lightweight, robust, and secure authentication by substring matching,\" in Proc. IEEE Symposium on Security and Privacy Workshops, 2012.","DOI":"10.1109\/SPW.2012.30"},{"key":"ref12","unstructured":"[13] D. Lim, \"Extracting secret keys from integrated circuits in Master thesis,\" Massachusetts Institute of Technology, 2004."},{"key":"ref13","doi-asserted-by":"publisher","unstructured":"[14] D. Lim, J. W. Lee, B. Gassend, G. E. Suh, M. V. Dijk, and S. Devadas, \"Extracting secret keys from integrated circuits,\" IEEE Transactions on Very Large Scale Integration (VLSI) Systems, vol. 13, pp. 1200-1205, 2005.","DOI":"10.1109\/TVLSI.2005.859470"},{"key":"ref14","doi-asserted-by":"publisher","unstructured":"[15] M. Majzoobi, F. Koushanfar and M. Potkonjak, \"Testing techniques for hardware security,\" in Proc. IEEE International Test Conference, 2008.","DOI":"10.1109\/TEST.2008.4700636"},{"key":"ref15","doi-asserted-by":"publisher","unstructured":"[16] J. Tobisch and G. T. Becker, \"On the scaling of machine learning attacks on PUFs with application to noise bifurcation,\" in Proc. International Workshop on Radio Frequency Identification: Security and Privacy Issues, 2015.","DOI":"10.1007\/978-3-319-24837-0_2"},{"key":"ref16","unstructured":"[17] J. W. Lee, D. Lim, B. Gassend, G. E. Suh, M. Van Dijk and S. Devadas, \"A technique to build a secret key in integrated circuits for identification and authentication applications,\" in Proc. Symposium on VLSI Circuits. Digest of Technical Papers (IEEE Cat. No. 04CH37525), 2004."},{"key":"ref17","doi-asserted-by":"publisher","unstructured":"[18] N. Wisiol, G. T. Becker, M. Margraf, T. A. A. Soroceanu, J. Tobisch, and B. Zengin, \"Breaking the lightweight secure PUF: Understanding the relation of input transformations and machine learning resistance,\" in Proc. International Conference on Smart Card Research and Advanced Applications, 2019.","DOI":"10.1007\/978-3-030-42068-0_3"},{"key":"ref18","doi-asserted-by":"publisher","unstructured":"[19] B. Gassend, D. Lim, D. Clarke, M. V. Dijk, and S. Devadas, \"Identification and authentication of integrated circuits,\" Concurrency and Computation: Practice and Experience, vol. 16, pp. 1077-1098, 2004.","DOI":"10.1002\/cpe.805"},{"key":"ref19","doi-asserted-by":"publisher","unstructured":"[20] U. R\u00fchrmair, F. Sehnke, J. S\u00f6lter, G. Dror, S. Devadas and J. Schmidhuber, \"Modeling attacks on physical unclonable functions,\" in Proc. 17th ACM conference on Computer and Communications Security, 2010.","DOI":"10.1145\/1866307.1866335"},{"key":"ref20","doi-asserted-by":"publisher","unstructured":"[21] U. R\u00fchrmair, J. S\u00f6lter, F. Sehnke, X. Xu, A. Mahmoud, V. Stoyanova, G. Dror, J. Schmidhuber, W. Burleson, and S. Devadas, \"PUF modeling attacks on simulated and silicon data,\" IEEE Transactions on Information Forensics and Security, vol. 8, pp. 1876-1891, 2013.","DOI":"10.1109\/TIFS.2013.2279798"},{"key":"ref21","doi-asserted-by":"publisher","unstructured":"[22] A. O. Aseeri, Y. Zhuang, and M. S. Alkatheiri, \"A machine learning-based security vulnerability study on XOR PUFs for resource-constraint internet of things,\" in Proc. IEEE International Congress on Internet of Things (ICIOT 2018), 2018.","DOI":"10.1109\/ICIOT.2018.00014"},{"key":"ref22","doi-asserted-by":"publisher","unstructured":"[23] N. Wisiol, C. Graebnitz, M. Margraf, M. Oswald, T. Soroceanu, and B. Zengin, \"Why attackers lose: Design and security analysis of arbitrarily large XOR arbiter PUFs,\" Journal of Cryptographic Engineering, 2019.","DOI":"10.1007\/s13389-019-00204-8"},{"key":"ref23","doi-asserted-by":"publisher","unstructured":"[24] G. Hospodar, R. Maes, and I. Verbauwhede, \"Machine learning attacks on 65nm Arbiter PUFs: Accurate modeling poses strict bounds on usability,\" in WIFS, 2012.","DOI":"10.1109\/WIFS.2012.6412622"},{"key":"ref24","doi-asserted-by":"publisher","unstructured":"[25] C. Zhou, K. K. Parhi, and C. H. Kim, \"Secure and reliable XOR arbiter PUF design: An experimental study based on 1 trillion challenge response pair measurements,\" in Proceedings 54th Annual Design Automation Conference 2017, 2017.","DOI":"10.1145\/3061639.3062315"},{"key":"ref25","doi-asserted-by":"publisher","unstructured":"[26] R. Want, \"The magic of RFID,\" Queue, vol. 2, pp. 40-48, 2004.","DOI":"10.1145\/1035594.1035619"},{"key":"ref26","doi-asserted-by":"publisher","unstructured":"[27] A. O. Aseeri, Y. Zhuang, and M. S. Alkatheiri, \"A subspace pre-learning approach to fast high-accuracy machine learning of large XOR PUFs with component-differential challenges,\" in Proc. IEEE International Conference on Big Data (Big Data), 2018.","DOI":"10.1109\/BigData.2018.8621890"},{"key":"ref27","doi-asserted-by":"publisher","unstructured":"[28] K. T. Mursi, Y. Zhuang, M. S. Alkatheiri, and A. O. Aseeri, \"Extensive examination of XOR arbiter PUFs as security primitives for resource-constrained IoT devices,\" in Proc. 17th International Conference on Privacy, Security and Trust (PST), 2019.","DOI":"10.1109\/PST47121.2019.8949070"},{"key":"ref28","doi-asserted-by":"publisher","unstructured":"[29] Y. Hori, H. Kang, T. Katashita, A. Satoh, S. Kawamura, and K. Kobara, \"Evaluation of physical unclonable functions for 28-nm process field-programmable gate arrays,\" Journal of Information Processing, vol. 22, pp. 344-356, 2014.","DOI":"10.2197\/ipsjjip.22.344"},{"key":"ref29","doi-asserted-by":"publisher","unstructured":"[30] M. S. Alkatheiri, Y. Zhuang, M. Korobkov, and A. R. Sangi, \"An experimental study of the state-of-the-art PUFs implemented on FPGAs,\" in Proc. IEEE Conference on Dependable and Secure Computing, 2017.","DOI":"10.1109\/DESEC.2017.8073844"},{"key":"ref30","doi-asserted-by":"publisher","unstructured":"[31] D. E. Holcomb, W. P. Burleson, and K. Fu, \"Power-up SRAM state as an identifying fingerprint and source of true random numbers,\" IEEE Transactions on Computers, vol. 58, pp. 1198-1210, 2008.","DOI":"10.1109\/TC.2008.212"},{"key":"ref31","doi-asserted-by":"publisher","unstructured":"[32] Y. Hori, T. Yoshida, T. Katashita, and A. Satoh, \"Quantitative and statistical performance evaluation of arbiter physical unclonable functions on FPGAs,\" in Proc. International Conference on Reconfigurable Computing and FPGAs (ReConFig), 2010.","DOI":"10.1109\/ReConFig.2010.24"},{"key":"ref32","doi-asserted-by":"publisher","unstructured":"[33] A. Maiti, J. Casarona, L. McHale, and P. Schaumont, \"A large scale characterization of RO-PUF,\" in Proc. IEEE International Symposium on Hardware-Oriented Security and Trust (HOST), 2010.","DOI":"10.1109\/HST.2010.5513108"},{"key":"ref33","doi-asserted-by":"publisher","unstructured":"[34] A. Maiti, V. Gunreddy, and P. Schaumont, \"A systematic method to evaluate and compare the performance of physical unclonable functions,\" in Embedded Systems Design with FPGAs, Springer, 2013, pp. 245-267.","DOI":"10.1007\/978-1-4614-1362-2_11"},{"key":"ref34","doi-asserted-by":"publisher","unstructured":"[35] G. T. Becker, \"The gap between promise and reality: On the insecurity of XOR arbiter PUFs,\" in Proc. International Workshop on Cryptographic Hardware and Embedded Systems, 2015.","DOI":"10.1007\/978-3-662-48324-4_27"},{"key":"ref35","doi-asserted-by":"publisher","unstructured":"[36] G. T. Becker, \"On the pitfalls of using arbiter-PUFs as building blocks,\" IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 34, pp. 1295-1307, 2015.","DOI":"10.1109\/TCAD.2015.2427259"},{"key":"ref36","doi-asserted-by":"publisher","unstructured":"[37] M. S. Alkatheiri and Y. Zhuang, \"Towards fast and accurate machine learning attacks of feed-forward arbiter PUFs,\" in Proc. IEEE Conference on Dependable and Secure Computing, 2017.","DOI":"10.1109\/DESEC.2017.8073845"},{"key":"ref37","doi-asserted-by":"publisher","unstructured":"[38] H. M. Allam and A. A. Chaudhri, \"Internet of things: Extracting latest challenges and solutions,\" Journal of Communications, vol. 12, no. 9, 2017.","DOI":"10.12720\/jcm.12.9.538-542."},{"key":"ref38","doi-asserted-by":"publisher","unstructured":"[39] W. Abbass, et al., \"Assessing the internet of things security risks,\" Journal of Communications, vol. 14, no. 10, 2019.","DOI":"10.12720\/jcm.14.10.958-964"},{"key":"ref39","doi-asserted-by":"publisher","unstructured":"[40] K. T. Mursi and Y. Zhuang, \"Experimental examination of component-differentially-challenged XOR PUF circuits,\" in Proc. 4th International Conference on Circuits, Systems and Devices (ICCSD), 2020 (forthcoming).","DOI":"10.1088\/1742-6596\/1729\/1\/012006"}],"container-title":["Journal of Communications"],"original-title":[],"link":[{"URL":"http:\/\/www.jocm.us\/uploadfile\/2020\/0911\/20200911051927831.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,11,24]],"date-time":"2021-11-24T07:26:59Z","timestamp":1637738819000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.jocm.us\/show-245-1595-1.html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":40,"URL":"https:\/\/doi.org\/10.12720\/jcm.15.10.714-721","relation":{},"ISSN":["1796-2021"],"issn-type":[{"value":"1796-2021","type":"print"}],"subject":[],"published":{"date-parts":[[2020]]}}}