Search papers, labs, and topics across Lattice.
This study introduces a simulation framework to evaluate the insertion of stealthy hardware Trojans in delay-based Physical Unclonable Functions (PUFs), which are critical for device authentication and key generation. The research reveals that dormant Trojans can maintain expected PUF behavior and structural integrity, only exhibiting detectable degradation post-activation, thus eluding traditional validation methods. These findings challenge existing security assumptions surrounding PUFs and emphasize the necessity of addressing the interplay between PUFs and hardware Trojans in security assessments.
Dormant hardware Trojans can masquerade as normal behavior in delay-based PUFs, only revealing their presence after activation, which traditional validation methods fail to catch.
Delay-based Physical Unclonable Functions (PUFs) are commonly used for device authentication and key generation due to the fact that they rely on manufacturing induced delay variations. However, these same variations make PUFs inherently non-deterministic, which can allow malicious logic to blend in with normal circuit behavior. As a result, the act of embedding hardware Trojans directly inside the PUF primitive presents a unique security risk that is not yet well understood. This work presents a unified simulation framework for evaluating stealthy hardware Trojan insertion across multiple delay-based PUF architectures and Trojan types. Functional metrics, hardware overhead, and resistance to machine learning modeling are assessed in parallel. Results show that dormant Trojans preserve expected PUF behavior, structural characteristics, and modeling resistance. Detectable degradation appears only after activation, indicating that conventional validation techniques fail to identify embedded Trojans prior to payload execution. These findings expose a gap in current PUF security assumptions, and highlight the need to evaluate PUFs and hardware Trojans as a coupled security problem.