PUFBind: PUF-Enabled Lightweight Program Binary Authentication for FPGA-based Embedded Systems

📅 2025-01-14
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
To address integrity and authenticity risks in FPGA-based embedded systems—where malicious binaries may bypass hardware authentication—this paper proposes a PUF-driven lightweight runtime binary binding and authentication mechanism. The method requires no hardware redesign or binary modification, supports bare-metal execution, and enables platform-agnostic deployment. It leverages the PicoBlaze soft-core processor on Xilinx FPGAs to generate PUF-based signatures and perform real-time integrity verification. Its key contribution is the first zero-dependency, modification-free, full-stack-compatible PUF-software co-authentication scheme. Hardware overhead is significantly lower than existing approaches, while achieving low verification latency and high throughput—fully optimized for resource-constrained bare-metal environments.

Technology Category

Machine Learning: Hardware-aware MLMultiagent Systems: Mechanism DesignReasoning under Uncertainty: Other Foundations of Reasoning under Uncertainty

Application Category

Systems and Infrastructure for Web, Mobile and WoT: Experiences and lessons learnt from Web-based algorithms and system deploymentsSecurity and Privacy: Large-scale security measurementsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systems
📝 Abstract
Field Programmable Gate Array (FPGA)-based embedded systems have become mainstream in the last decade, often in security-sensitive applications. However, even with an authenticated hardware platform, compromised software can severely jeopardize the overall system security, making hardware protection insufficient if the software itself is malicious. In this paper, we propose a novel low-overhead hardware-software co-design solution that utilizes Physical Unclonable Functions (PUFs) to ensure the authenticity of program binaries for microprocessors/microcontrollers mapped on the FPGA. Our technique binds a program binary to a specific target FPGA through a PUF signature, performs runtime authentication for the program binary, and allows execution of the binary only after successful authentication. The proposed scheme is platform-agnostic and capable of operating in a"bare metal'' mode (no system software requirement) for maximum flexibility. Our scheme also does not require any modification of the original hardware design or program binary. We demonstrate a successful prototype implementation using the open-source PicoBlaze microcontroller on AMD/Xilinx FPGA, comparing its hardware resource footprint and performance with other existing solutions of a similar nature.
Problem

Research questions and friction points this paper is trying to address.

FPGA Embedded Systems
Software Integrity
Security Enhancement
Innovation

Methods, ideas, or system contributions that make the work stand out.

PUFBind
Physical Unclonable Functions (PUFs)
FPGA Embedded Systems
🔎 Similar Papers
No similar papers found.
S
Sneha Swaroopa
Dept. of Computer Science and Engineering, Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India – 721302
V
Venkata Sreekanth Balijabudda
Dept. of Computer Science and Engineering, Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India – 721302
R
R. Chakraborty
Dept. of Computer Science and Engineering, Indian Institute of Technology Kharagpur, Kharagpur, West Bengal, India – 721302
Indrajit Chakrabarti
Indrajit Chakrabarti
Professor, Dept. of Electronics and Electrical Communication Engineering, IIT Kharagpur
VLSI Architectures for Video and Image ProcessingError Control Coding and Communication