From Weak to Strong: Shielding IoT with RRAM and SHA-256
Extending 1kb RRAM array from weak PUF to strong PUF by employment of SHA module
This paper presents a hybrid Strong Physical Unclonable Function (PUF) design that extends a limited 1 kb RRAM array's challenge-response pair (CRP) space using a Secure Hash Algorithm (SHA-256) module. By splitting challenge bits and mixing RRAM entropy with external inputs, the system achieves massive scalability and high security.
TL;DR
Researchers from Arizona State University and Tsinghua University have developed a way to turn a standard 1 kb RRAM array into a high-security "Strong PUF" by embedding it within an SHA-256 module. This architecture not only explodes the available challenge-response pairs (CRPs) but also provides a mathematical shield against Machine Learning (ML) attacks, achieving near-perfect uniqueness (~50%) and 10-year reliability.
Background: The Identity Crisis in IoT
In the IoT era, every device needs a unique digital fingerprint. Physical Unclonable Functions (PUFs) provide this by exploiting microscopic manufacturing variations. However, we face a trade-off: Weak PUFs (memory-based) are reliable but have too few "passwords," while Strong PUFs (delay-based) have many passwords but are easily "learned" and predicted by AI. This paper bridges that gap.
Motivation: Why RRAM Needs SHA
RRAM (Resistive RAM) is an ideal entropy source due to the stochastic nature of oxygen vacancy filament formation. However, a 1 kb array usually only offers 1024 unique response bits. If an attacker reads the memory, the PUF is compromised.
The authors realized that by using RRAM as a "seed" for a Secure Hash Algorithm (SHA), they could create a Strong PUF where the physical randomness is cryptographically multiplied.
Methodology: The Challenge-Splitting Architecture
The core innovation lies in how the challenge (input) is handled.
- Challenge Splitting: An -bit challenge is split. The first segment selects a row in the RRAM array.
- Entropy Extraction: The RRAM row is read, yielding bits of physical randomness.
- Cryptographic Mixing: These bits are mixed with the rest of the challenge bits and fed into the SHA-256 module.
This ensures that even a small RRAM array can support challenges.
Figure 1: The proposed circuit macro showing the construction (red) and operation (green) phases.
Solving the Reliability Bottleneck
Hash functions are notoriously sensitive—a single flipped bit in the input completely changes the output. To fix RRAM's inherent resistance drift, the authors used cell grouping. By wiring 8 RRAM cells together to represent 1 bit, the statistical "average" of the group remains stable even if individual cells drift.
Figure 2: Using 8 cells/bit ensures a clear memory window and long-term reliability compared to the 1 cell/bit baseline.
Experimental Results & Security Analysis
The team fabricated 1 kb arrays to validate their model.
- Uniqueness: The Inter-Hamming Distance (Inter-HD) reached 49.95%, meaning two different chips are almost guaranteed to produce different signatures.
- ML Resilience: This is the "killer feature." The authors tried to "break" the PUF using a 3-layer Multi-Layer Perceptron (MLP). Even with 100,000 training samples, the AI could not predict responses better than a random guess (50% accuracy).
Figure 3: Prediction rate remains flat at ~50% regardless of training set size, proving immunity to MLP modeling.
Depth Insight: The Trade-off
The primary cost of this approach is the Area Overhead. While the RRAM array is tiny (~600 ), the SHA-256 logic is relatively large (~27,000 ). However, for high-security applications, this is a small price to pay for hardware-level immunity to modeling attacks and massive CRP scalability.
Conclusion
By marrying the physical unpredictability of RRAM with the mathematical "one-way" nature of SHA-256, Liu et al. have created a blueprint for highly secure, ML-resistant hardware signatures. Future work could focus on replacing SHA-256 with "lightweight" primitives (like ASCON or PHOTON) to bring this technology to the smallest, power-constrained IoT sensors.
