The invention relates generally to physically unclonable functions. More specifically, the invention relates to a neuromorphic network that can be used for creating a physically unclonable function.
The human brain is a powerful computing system that performs information processing quite efficiently via its massively parallel neural mechanism. Analog Neural Networks (ANNs) attempt to mimic this neural mechanism in the human brain in order to overcome some bottlenecks of the traditional von Neumann machines, especially for computationally-intensive applications such as image processing and pattern recognition.
The Cellular Neural Network (CNN) that was first proposed by L. O. Chua and L. Yang in 1988 is a special class of ANNs as it offers only local interconnections among the artificial neurons. Regardless of the number of neurons in the CNN system, each neuron is connected to only the neighboring neurons within a specified radius r and itself. For example, referring to a two-dimensional CNN architecture shown in
Recently, heterogeneous devices and materials have been proposed and implemented as electronic synapses. Of particular interest has been RRAM, which offers non-volatility for such devices. The voltage-controlled resistances that remain the same even when powered off are adjusted to have programmable synaptic weights. Some proposals have also been made for creating neural networks using other types of emerging devices and materials, such as aluminum nitride and magnetics.
Further inspired by the oscillatory nature of some brain sub-systems, others have proposed an Oscillatory Neural Network (ONN) architecture based on coupling phase-locked loops (PLLs) in a network. A single cell of this network is shown conceptually in
Equation 1 is the state space definition of a neuromorphic network. The state of the network is given by xc, the output from each neighbor is given by yd, the weight between the neurons of the system is given by ac,d, and the input to the cell is given by uc. Since it is a dynamical system, the initial condition xc(0) will affect the final settled value of xc(t).
ONNs and CNNs are implementations of the same fundamental state-space equation, given in Equation 1. This state space maps an input vector of length N to an output vector of length N, where N is the number of neurons in the network. The input can be provided by either forcing an initial condition or by providing an input into the summation. The system is then allowed to converge to the closest energy minimum which is defined by the synaptic weights. When using them as an associative memory, these minima are defined by the training the values of the synapses that define the connectivity between neurons.
If, on the other hand, the weights and initial conditions are not explicitly set by the user, the energy landscape would be defined by process variations. Therefore, the system has a set of patterns stored in it upon fabrication, and these patterns are randomly determined by the variability during manufacturing. This variability can be exploited for use as a Physically Unclonable Function (PUF).
PUFs are a method of using intrinsic random physical features of an instance of a chip for the purpose of simple counterfeit detection or as the seed for more complex cryptographic functions. PUFs leverage uncontrollable physical die-to-die variation in integrated circuit (IC) manufacturing to generate unique identifiers, meaning a single mask can be used to generate a large number of chips that can uniquely identify themselves. Unlike a simple ID code, however, a PUF is a function--namely it returns a uniquely identifiable output (or response) in response to an input (or challenge).
However, CMOS-based PUFs suffer from inconsistencies over a range of temperatures and voltages. In addition, some architectures, such as arbiters and ring oscillators, can be vulnerable to attack. In such an attack, a PUF challenge response could be predicted based on a subset of known responses. One key in a strong PUF is that the physical secret should be prohibitively difficult to predict after modeling. An attractive quality of using a neural network as the function to produce an output based on the physical secret is the non-linear nature of the network will obfuscate the initial conditions and random parameters. The number of connections in a large network makes an attempt to learn the system through a modeling attack prohibitive, if not impossible. This is unlike simpler delay-based arbiters or ring oscillator PUF designs. The neural network-based PUF will not need additional circuitry to attempt to obfuscate the secret further.
It would therefore be advantageous to develop an architecture that can be used as a PUF, but that does not suffer from the drawbacks of PUFs created from traditional CMOS-based devices.
According to embodiments of the present disclosure is a neuromorphic network that can function as a PUF. The randomness of the initial state and conditions of the artificial neurons and/or synapses represent a unique identifier for the manufactured IC. If truly random, then no two ICs would have the exact same initial state or conditions for large enough analog neural networks. This variability is the fundamental feature needed to construct a PUF for secure IC applications.
In one embodiment of the present invention, the circuitry of the neuromorphic network is similar to that used in an ONN or CNN to perform the PUF function. More specifically, in one embodiment the neuromorphic network consists of a plurality of interconnected nodes, or artificial neurons, where the weighted outputs of several nodes in a first layer are summed and used as the input of a second layer node. An input to the network will represent a “challenge” that will receive a “response” based on the random initial state and conditions of the network. To function as a PUF, the system relies on the initial state being truly random from die-to-die to distinguish one IC from another, while being consistent for repeated queries on a single die. This unclonable random initial state must remain consistent for all product aging and environmental conditions. Most importantly, the design of the neural network can be structured to accommodate some small perturbations with aging. For example, consider one embodiment in which an ONN based on oscillators is used for neurons and programmable resistances are used for synapses, whereby the stored information is the total phase shifts among the oscillators upon startup. Since the response to any challenge is an aggregate response due to the phase relationships among all of the artificial neurons, small shifts in the initial phase states relative to neighboring neuron phases will have only a limited impact on the overall response. This is due to the inherent nature of neural networks that perform their computation based on imprecise data.
Embodiments of the present invention and its advantages are best understood by referring to the figures.
A schematic showing a single cell, or neuron 102, of the network 106 according to the preferred embodiment is shown in
The state of the network 106 is stored as the relative phase between the oscillators 301, and therefore the input vector will be a waveform of phase 0 or 180 degrees. The output vector is generated by measuring the phase of each neuron 102 relative to a reference neuron 102, and thresholding them to be either 0 or 180 degrees. Thresholding is used in the preferred embodiment because the phase settles quickly to a value near 0 or 180, but complete settling takes a longer period of time. For example, if the phase of a neuron 102 settles to 2, then the thresholding step would cause the phase to be indicated as 0, since the phase is more likely to completely settle to 0 than 180.
The physical randomness needed for the PUF comes from the randomization of the initial condition of the network 106, which is based on the initial phase of the individual oscillators 301 comprising the network 106. For example,
As previously indicated, the oscillators 301 used in the preferred embodiment are based on devices exhibiting S-NDR behavior. This behavior is seen in transition metal oxides and chalcogenide-based phase change materials (also known as threshold switches). It has been widely known that disordered glasses (including polycrystalline films with defects) like chalcogenides and some transition metal oxides show a characteristic bistability in their resistance states. As an example of one such device, Ta2O5−x devices exhibit transient and reversible localization of current; thus, this material can be used as an S-type NDR device.
The negative differential resistance observed in a transition metal oxide material can be utilized as an oscillatory element. The oscillatory element comprises a dielectric material 402 placed between two electrodes 403, which is shown in the inset of
To prevent current runaway and permanent changes in the device 401, a series resistance is added in the circuit path. Depending on the over-voltage (differential voltage beyond the threshold voltage) applied to the device 401, the device 401 may settle down to various low resistance states, or ON states. The ON state is completely volatile (corresponding to volatile filament) and the device would revert back to the OFF state (filament dissolved) once the field is removed. The voltage and current associated with this reversal is termed as holding voltage and current.
Once the device 401 switches to ON state (i.e. temporary filament formed and temporary low resistance state), the resistance of the device 401 experiences a rapid decrease. Due to the voltage division enforced by the resistance in series, the voltage across the device 401 drops. This drives the device 401 to an I-V point in the ON state that is lower than the holding voltages and current. Thus the electronic filament is unstable and dissolves, driving the device 401 back to the OFF state. Once in high resistance state, the voltage across the device 401 starts increasing, eventually beyond the threshold voltage which causes the device 401 to go back to the ON state. This process repeats itself resulting in self-sustained oscillations, as shown in
Despite the device 401 being stressed with a certain applied voltage beyond the threshold voltage, it takes a well-defined incubation time before the oscillations start. This sets an initial phase offset that propagates through the oscillations and thus sets the initial conditions for the PUF. In other words, any two devices 401 with different incubation times (delay) will result in those two oscillators having two dissimilar phases. It must be noted that a range of voltages can be used to initiate oscillations and the incubation time associated with these voltages can be tuned, as shown in
Previously, nucleation theory has been looked at as a tool to analyze this incubation time in phase change materials. Nucleation theory defines a critical radius that any phase should reach before it is stabilized. When the field is applied to the device, the material may have small crystallites in an amorphous matrix corresponding to a conducting phase. However, the radius of these crystallites is very small compared to the critical radius needed for sustained stabilization of the conductive phase. Upon exposing the device to a field for a certain incubation time, the nucleus grows in a manner that creates a cylindrical conductive phase that shunts the field through the device. This incubation time is followed by a rapid decrease in resistance known as threshold switching and subsequently oscillations. During this rapid decrease in the resistance of the device 401, the filament is formed through the device thickness. The nucleation theory predicts that the incubation time should be a function of field and temperature and should be governed by the following equation:
Here, τ is the incubation time, τ0 to is the pre-exponential factor (often defined as the inverse of attempt frequency), W0 is the activation energy, k is the Boltzmann's constant, T is the temperature in K, V˜ is the voltage acceleration pre-factor and V is the applied voltage to initiate oscillations. Thus, the incubation time is a strong function of the field dependent activation energy and the attempt frequency. Variability in τ0 to represents how many growth attempts it takes at different sub-critical nuclear sites before one of those sub-critical nuclei start growing to form the filament. These sub-critical nuclei are usually the defects in a certain device 401 that are a result of process conditions that a particular device experienced. Thus the defect distribution for a single device 401 is preset while it is impossible for two devices 401 to have the same defect distribution. Thus, different devices 401 have a different attempt frequency and thus a different incubation time. The second source of variability is from the activation energy which has an intrinsic distribution that depends not only on the number of defect sites, but also the orientation of the defect sites through the thickness. Similarly, due to localized conduction through this stochastically grown filament experiences different temperatures depending on the defect orientation (straight versus oblique or irregular filament). Thus, the thermal environment is nearly unique to a single device 401 (reducing cycle to cycle variation) but different devices 401 can have different preferred path shapes and resistances. Moreover, these factors affect the incubation time exponentially and thus there is usually a magnified effect of device 401 to device 401 variability due to variation in defect shape, size, orientation and concentration. Also, the incubation time (initial phase for the PUF) is relatively independent of temperature.
The main advantages of this oscillator 301 of this type are: (1) Compact size due to the filamentary nature of the oscillations. (2) Large dynamic change in the voltage during oscillations that can drive other loads, as opposed to other nano-oscillators like spin torque oscillators. (3) Low temperature coefficient of resistance due to the physical mechanism involving a very high-temperature process. (4) Frequency tunability over four orders of magnitude with a ballast device as shown in
The method of performing a physically unclonable function using a neural network 106, according to one embodiment, is depicted in the flowchart as shown in
As previously discussed, the user inputs a configuration of weight patterns as the challenge. This could be done through a digital interface, and will depend precisely on how the weights are implemented. To reduce the possible input space (infinite in the case of analog weights), constraints can be set on the number of weight choices that are possible. The system would then be evaluated, and due to the dynamics of neural networks will settle to each neuron either being a “1” or a “0” based on the weights and the secret initial condition.
The secret stored in the neural network-based PUF could be in either randomized weights between the neurons 102 of the network 106 or in randomized initial conditions. The randomized weights could be achieved through the stochastic nature of switching RRAM. A simulated example of this method of PUF generation is given in
This is a small example PUF. Given a much larger neural network 106, it becomes infeasible to attempt to divine the resistance values based only on the input pattern and final settled state due to the complexity of the system. To further increase the randomness of the system, the initial conditions of the neurons 102 are randomized due to process variation as described above. This system defends against modeling attacks by not providing the raw waveforms at the output, but rather whether the final settled phases are in or out of phase with the reference neuron 102. Physical attacks are prevented by the scaling of the RRAM devices 401 to a size where they cannot be probed. Even if physical probing were possible, doing so would introduce defects into the devices (as discussed above), which would change their initial phase, making the system tamper proof.
While the disclosure has been described in detail and with reference to specific embodiments thereof, it will be apparent to one skilled in the art that various changes and modification can be made therein without departing from the spirit and scope of the embodiments. Thus, it is intended that the present disclosure cover the modifications and variations of this disclosure provided they come within the scope of the appended claims and their equivalents.
This application claims the benefit under 35 U.S.C. §119 of Provisional Ser. No. 62/122,964, filed Nov. 3, 2014, which is incorporated herein by reference.
This invention was made with government funds under Agreement No. HR0011-13-3-0002 awarded by DARPA. The U.S. Government has rights in this invention.
Number | Date | Country | |
---|---|---|---|
62122964 | Nov 2014 | US |