<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A proposal for the secure activation and licensing of FPGA IP cores</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Domenico Amelino</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mario Barbareschi</string-name>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alessandro Cilardo</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CeRICT scrl - Centro Regionale Information Communication Technology</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>DIETI - Department of Electrical Engineering and Information Technologies University of Naples Federico II</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2017</year>
      </pub-date>
      <fpage>29</fpage>
      <lpage>37</lpage>
      <abstract>
        <p>The fabless business model is leading to intellectual property (IP) based design for System-on-chip devices, involving both the field programmable gate array (FPGA) and application specific integrated circuit (ASIC) technology. The main advantage is essentially the decoupling of the system integration phase from the development of the single cores. The use of third-party IPs, however, raises many challenges, especially related to the security of the manufactured devices, as the dynamic installation/activation of new functions makes it more difficult to track the distribution and use of licensed IPs. In that respect, an effective solution involves the online interaction between each end user's device and the IP provider, but this online tracking comes at the price of compromised user's privacy. Bearing in mind this consideration, the work proposes the adoption of a concept borrowed from the trusted computing area, the so-called Direct Anonymous Attestation, to enable remote IP licensing and activation mechanisms while fully preserving the anonymity of the end user, i.e., making it impossible to infer the user's identity from its behaviour as seen by the activation server. The main contribution of this paper is the definition of an ad-hoc protocol, called Remote Anonymous Activation Protocol (RAAP), as well as a proof-of-concept implementation on a commercial target device, which encompasses an FPGA and a general purpose processing system.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        FPGA fabric vendor, etc; Couture et al. propose in [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] an extension of licensing mechanisms
to FPGA components augmenting the system with a secure non-volatile memory (NVM) and
a tamper-resistant unique identifier; the papers [
        <xref ref-type="bibr" rid="ref12 ref13">13, 12</xref>
        ] illustrate a volume licensing scheme for
FPGA bitstreams, extended to the case of multiple cores within one FPGA; Maes et al. in [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]
introduce a pay-per-use licensing scheme protecting individual FPGA IP cores; Cilardo et al.
in [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ] identify the roles involved in the secure IP distribution process for FPGAs and
introduce a cryptographic protocol ensuring the confidentiality and the trustworthiness of partial
bitstreams dynamically downloaded to the user’s device.
      </p>
      <p>
        Conversely, in this work, we are interested in new forms of interactions enabled by Trusted
Computing, not limited to the use cases covered by the above works. In particular, we focus
on remote attestation, a process specified by the Trusted Computing architecture to establish
trusted relationships between devices and third parties, letting the device prove to a remote
verifier that the platform has a valid configuration. While the initial TCG approach relying on
a Privacy Certification Authority (CA) [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] had inherent limitations, because the Privacy CA
turned out to be both a performance and a security bottleneck, the so-called Direct
Anonymous Attestation (DAA) [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] establishes a trusted relation among parties without the online
participation of a trusted party, while preserving the user’s privacy.
      </p>
      <p>
        Based on group signature [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] (which essentially enables users to prove that they are part of
a trusted group), the first proposal for DAA [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] relied on RSA. For efficiency reasons, several
solutions later tweaked the basic protocol to reduce the computational load of DAA
operations [
        <xref ref-type="bibr" rid="ref15 ref16">15, 16</xref>
        ]. In particular, [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] introduced a DAA scheme based on ECC and bilinear maps,
labelled ECC-DAA. Based on this idea, a few contributions tried to limit the computational
load incurred by the fundamental device-side component, e.g. the Trusted Platform Module
(TPM), which embraces all the security-critical operations [
        <xref ref-type="bibr" rid="ref6 ref8">8, 6</xref>
        ]. In fact, the TPM 2.0
specification draft [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] includes multiple ECC-DAA schemes. Several works particularly addressed
the implementation of DAA on security-enabled embedded platforms, such as ARM TrustZone,
providing a secure perimeter within the platform. Reference [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] presents a lightweight
anonymous authentication scheme for embedded devices. Similarly, [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ] proposes a DAA framework
for mobile platforms. The work in [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] describes four ECC-based DAA implementations.
Reference [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] also introduces a DAA scheme based on TrustZone. A few works [
        <xref ref-type="bibr" rid="ref24 ref9">24, 9</xref>
        ] present a
comparison of different DAA solutions, which may drive the choice of DAA schemes for a given
infrastructure/platform.
      </p>
      <p>Although this work does not deal with the DAA algorithms by themselves, it is useful to
summarize the essential concepts behind the scheme. The DAA requires three players, the
Issuer, granting authentication credentials, the Device, made of a Host and a Trusted Module
(TM), which are enabled to anonymously attest their own platform, and the Verifier, checking
whether the signature generated by a Device belongs to the DAA group and, consequently, it
can be considered trustworthy. The whole process preserves the user privacy since no player can
associate a signature with a user identity, except the Issuer. The scheme also covers the case
that a compromised (i.e. a rogue) TPM attempts to sign a message, by employing a revoking
mechanism. In essence, the DAA protocol is structured in four main phases: Setup, Join, Sign,
and Verify. In the Setup phase, the Issuer generates a DAA public key and the Issuer secret
key. In the Join phase, the Device uses its TM to generate a secret value, then securely stored,
and a public value sent to the Issuer, which in turn generates a credential for the Device. In
the Sign phase, the Device generates a signature to attest its platform trustworthiness to the
Verifier. Each sign operation is masked with a nonce value to avoid replay attacks. In the
Verify phase, the Verifier checks the received signature and, after looking up a revocation list
provided by the infrastructure, it establishes whether the device is trusted or not.</p>
      <p>providing
TTP</p>
      <p>Carnet
Withrawal</p>
      <p>DAA Join</p>
      <p>TM</p>
      <p>IPP: IP Provider
AS: Activation Server
DM: Device Manufacturer
TTP: Trusted Third Party</p>
      <p>TM: Trusted Module
Ticket
Expend</p>
      <p>AS</p>
      <p>Activation</p>
      <p>Key</p>
      <p>IPP</p>
      <p>The work described in this paper borrows a few concepts from the DAA scheme and applies
them to remote IP licensing and activation. It assumes that the end-user devices provide an
environment for run-time download and activation of FPGA-based IP cores, a process mediated
by an Activation Server (AS) in charge of managing the IP cores and related licensing. The
paper relies on an ad-hoc protocol, called Remote Anonymous Activation Protocol (RAAP),
regulating the IP distribution and activation processes. Based on DAA, RAAP preserves the
full anonymity of the end user, i.e. it makes it impossible for an Activation Server to track
the user’s behaviour over the product lifecycle. To confirm the computational feasibility of
RAAP, the paper also presents a demo implementation relying on a medium-size FPGA-based
embedded platform.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Remote Anonymous Attestation Protocol</title>
      <p>In this section we define the underlying infrastructures and main roles involved in the activation
protocol. First, we assume to have a third-trusted party (TTP), which allows trustworthy
communications and attestations among other involved parties. It is the only party getting access
to the full user’s identity. The other players are totally oblivious to the user’s identity, such as
the Device Manufacturer (DM), who integrates the IPs and a Trusted Module (TM) together
in the manufactured device, the IP core Providers (IPPs), which guarantee full compatibility
with the issued IP core design specification and other non-functional requirements, and the
Activation Server, who is responsible for the licensing mechanism.</p>
      <p>From the user-side, the device is made of the host, i.e., the hardware/software environment
within the user’s device, and the TM, which deals with IP core activation tasks. Figure 1 shows
an overview of the players and the interactions among them, described below.</p>
      <p>The main objective of the RAAP protocol is to realize secure remote activation of an IP
Core keeping the user’s identity hidden from all players but the TTP. The mechanism allows
also the monitoring of the number of activations of a specific IP Core. Considering the DAA,
presented in Figure 1, the TTP coincides with the DAA issuer, in that it provides group sign
credentials to the end user’s device. Once the TM of a device gets the DAA credentials, it is
able to contact the AS in an anonymous way. The TTP issues activation tickets used to unblock
an IP for a finite number of activations. The end user can acquire one or more such tickets (a
carnet of tickets) from TTP and spend them at the ASs. Acquisition may be accomplished on
a subscription basis (pay-per-use scheme), or it may correspond to the registration of the user</p>
      <p>TM Host
compute h (ID)
calculate tn 1, . . . , t0 h (ID), t0, n msg := Signupk (h (ID) , t0, n, payment data) msg
store c
c
if msg is not valid</p>
      <p>then abort
add huser, h (ID) , n, t0i to CL</p>
      <p>c := Signbsk (h (ID) , t0, n)
platform to the infrastructure for metering purposes. It must be guaranteed that each ticket
can be spent once and anonymously.</p>
      <p>The AS, that acts as the Verifier of the DAA, owns the activation key k for the IP cores,
used to derive licenses requested by hosts. The AS verifies the tickets authenticity before issuing
a license to the host.</p>
      <p>On the user device side, the activation process has to be managed by the TM, which stores
the tickets since the host is executed on a non-trusted environment. In the proposed scheme,
the tickets coincide with the links of a hash chain. When the user needs to activate a specific
IP Core, the TM generates a chain of elements, sending to the TTP only the last element of
the chain, while the remaining elements are either securely stored or regenerated on-demand.
Depending on the correctness of the information, the TTP releases the required tickets for the
activations. Once the User acquires the tickets, it can spend them to the AS, which generates
and sends the license for the user.</p>
      <p>Below we describe the details of the RAAP phases, namely the ticket withdrawal and ticket
expend.
2.1</p>
      <sec id="sec-2-1">
        <title>Ticket Withdrawal</title>
        <p>The Withdrawal phase, shown in Figure 2, involves the Device and the TTP, where the TM
inside the Device generates a hash chain whose length, specified by the Host, is basically
established as the number of requested activations. Let n, tn−1, and t0 be, respectively, the
number of activations which can be acquired, the first element of the chain, and the last element,
such that hn−1 (tn−1) = t0. The hash function involved in the generation of the chains is
provided by the TM, while tn−1 is a random-salted value derived from the IP core ID.</p>
        <p>Once the hash chain has been completed, the Host gets t0 and a blinded value of the IP
core identifier, i.e. h (ID) from the TM and, through an authenticated communication channel,
forwards such information to the TTP, the amount of required activations n, and the associated
payment data, in case the user has to give a proof of a payment transaction. The TTP verifies
the message and payment data with the user identity. In case of success, the TTP adds a new
entry in the carnet list (CL), a list that contains the association among the user’s identity,
h (ID), t0, and the number of tickets n. The TTP is able to retrieve the ID since either the
IPP or the DM communicate the IDs of every manufactured device. Subsequently, the TTP
creates the carnet of tickets c, by signing the h(ID), t0, and n values with its private key bsk.
Then the TTP forwards the carnet to the Host, which has to be stored within the TM’s secure
perimeter.
2.2</p>
      </sec>
      <sec id="sec-2-2">
        <title>Ticket Expend</title>
        <p>This phase is depicted in Figure 3 the purchased carnet of tickets can be spent by the Host
to activate a specific IP instance n times. Let i be the index of the first available ticket in</p>
        <p>Host
= DAA Sign(c, tj, j)
req lic = (c, , tj, j|| )
req lic
if DAA-Verify( ) fails then abort</p>
        <p>if Verbpk (c) then reject
if j n _ hj (tj) 6= t0 then reject
if ht0, h (ID)i 2/ LCL creates a new entry
cntht0, h(ID)i = j
l = h (tj, k)
activateIP(h (tj, k))</p>
        <p>l
the carnet, i.e. ti, with i 6= 0. Then, let m be the number of tickets that the user wants
to spend in a single interaction with the AS. By means of the ticket expend phase, the user
requests m licenses to the AS. Hence, the host forwards to the AS a message containing the
carnet c, tj , and j, such that j = i + m − 1, where j indicates the counter of the tickets which
have been actually spent at the AS. Indeed, the index of the next available ticket in the carnet
turns out to be j + 1. Exploiting the DAA sign operation, the AS is able to authenticate the
message in an anonymous way. If the verification succeeds, the AS retrieves t0, n, and h(ID)
by authenticating the carnet c using the Issuer (i.e. TTP) public key, bpk.</p>
        <p>Then, the AS has to check if j is greater than the maximum number of purchased activations
n and the correctness of the value tj . The AS also checks if the carnet has already been used in
previous requests by looking up a local carnet list (LCL) and then updating the counter of the
issued licenses. If every check succeeds, it calculates l = h (tj , k), where k is the activation code
for the specific type of IP core involved, shared between AS and IPP. This value is representative
of m licenses useful for carrying out m IP core activations at the TM.
3</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>Case Studies</title>
      <p>In this section, we provide a prototype implementation of the RAAP scheme on a hybrid target
user device featuring an FPGA-accelerated SoC. Indeed, the choice of the hardware components
has a central role for the support of performance and security critical aspects. Our main aim
in this paper is to demonstrate the feasibility of the RAAP scheme particularly addressing
the portion of the protocol running on the user device. We firstly describe the hardware and
software test setting, based on a customizable and efficient hardware library ported to the
target platform. Then, we present the overheads incurred by our scheme detailing the
timeand memory-critical part of the process. We also propose the integration of custom hardware
accelerators to improve the system performance on low/medium-complexity target devices,
where pure software implementations might pose a limitation.
3.1</p>
      <sec id="sec-3-1">
        <title>Implementation Details</title>
        <p>As detailed in the previous sections, we consider three main entities: the TTP, the AS, and the
End User. In our experiments, we simulate TTP and AS by means of a desktop PC: in a real
scenario they are remote high-end servers. For the end-user device, we use a Zedboard
Zynq7000 Development Board. This device features an ARM-A9 MPCore processing system (PS)
together with a reconfigurable part based on an FPGA fabric, possibly hosting IP hardware
cores managed through a license-based activation mechanism. For the experimental tests, we
connected the ZedBoard via a USB cable to the PC, which in turn plays the role of the TTP
and the AS.</p>
        <p>
          We adopt the MIRACL software library [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ] for implementing the RAAP scheme on the
bare metal ARM processor and on the PC for simulating the TTP and the AS. This library
provides optimized implementations of cryptographic primitives, particularly Elliptic Curve
Cryptography operations and supports a wide range of platforms such as x86-x64 Intel and
ARM. The following evaluations do not consider a separation between host and TM: our
experiments mainly aim at demonstrating the computational feasibility of the remote attestation
and licensing mechanism of the RAAP scheme.
3.2
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>Experimental Results: Software Implementation</title>
        <p>As explained in the previous sections, RAAP is composed of two main steps: Ticket Withdrawal
and Ticket Expend. We evaluate the time overhead of the execution on ZedBoard development
board and each average experimental result is taken over 20 test-runs.</p>
        <p>Based on the interactions required by RAAP, we relied on the following combined use
of different cryptographic building blocks. Each player of the protocol uses 1024-bit RSA
cryptography for authentication and message exchange. Furthermore, since RAAP partially
relies on an anonymous group signature scheme, as required by the DAA anonymous attestation
technique, we need to support ECC. In particular, we adopt a 128-bit BN curve DAA ECC
scheme for allowing users to acquire a trustworthy group signature from the TTP. Last, the
hash chain is generated by means of a SHA-256 cryptographic hash function.</p>
        <p>As discussed in Section 1 the DAA-Join phase allows a device to acquire group credentials
from a trusted party used to attest End User Device trustworthiness to other parties. It is
important to notice that this operation is sporadically executed and it is not of interest for our
scopes.</p>
        <p>The following results regard only the software-based implementation. Further details about
the introduction of hardware acceleration are given in Section 3.3.</p>
        <p>As described before, the Ticket Withdrawal executes a blind signature, a hash chain
generation, a request signature, and a carnet verification. This phase is executed each time the user
needs to acquire licenses for activating IP Cores. For hash chain generation, we consider a hash
chain size of 1000 elements. The blind signature, complying with NIST specification, is
characterized by an execution time of 29.7 ms. The overall Ticket Withdrawal average execution time
is 2653 ms. As regards the generation of the hash chain, the overhead becomes significantly high
only when the chain size reaches 10,000 elements: below this value, the SHA-256 introduces a
limited time overhead, around 500 ms. The above time overheads can be considered negligible
since the corresponding operations occur infrequently compared to the application lifecycle.</p>
        <p>The Ticket Expend phase is dominated by the DAA-Sign. The DAA-Sign implemented on
the ZedBoard platform is characterized by an average elapsed time of about 833 ms for each
license acquisition offering a reasonable security level (128-bit) and a reasonable time overhead
for an embedded device. It is worth noting that the presented results do not take into account
the time overhead caused by network communications as well as the time required for I/O
operations.
3.3</p>
      </sec>
      <sec id="sec-3-3">
        <title>Custom hardware accelerator</title>
        <p>As highlighted by the results above, the cryptographic operations behind the RAAP scheme
involve a significant computational load due to large operands and complex mathematical
operations.</p>
        <p>For this reason, we profiled the most performance-critical operations, shown in Table 1.
The table illustrates the impact of the main MIRACL primitives on performance, specifying
the cumulative time spent by each function during the DAA-Join and DAA-Sign phases. We
identify the Montgomery Reduction, called red c function in the code, as the main performance
hotspot of the implementation. In particular, the red c contributes to DAA-Join and
DAASign execution time respectively by 49.4% and 36.5%. The operation computes the product
Y = X · R−1 mod N and can be profitably migrated to hardware.</p>
        <p>In order to improve the system performance, we evaluate the integration of hardware
acceleration for the Montogomery Reduction in place of the software red c. We designed a hardware
component as an AXI4 slave peripheral which wraps a dedicated data path for the red c. The
datapath handles input binary strings up to 576 bits. The input and output protocols, as well
as the synchronization mechanism, are arbitrated by a software driver available as a bare metal
function, seamlessly integrated within the MIRACL library in place of the software red c. The
implementation of the hardware red c yields a resource occupation of 714 Look-up Tables, 16
DSP − 48 blocks, 893 Flip-Flops, 4 Block-RAMs, and 560 Data Memory RAMs. Arithmetic
operators (multiplication and addition) are pipelined and customized for the accelerated
operation, leading to a clock speed of 142.33 MHz. Figure 4 shows a comparison between DAA-Join
and DAA-Sign execution times adopting software and hardware implementation of the red c
function. Hardware acceleration for Montgomery reduction gains a considerable speed-up of
37% and 27% respectively for DAA-Join and DAA-Sign. In particular, the DAA-Sign is the
core operation of RAAP Ticket Expend, showing a considerable improvement in the target
system performance. The measurements with the hardware core also consider the elapsed time
required to exchange data between the processing system and the core itself.
4</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>Conclusions</title>
      <p>In this paper, we have shown an anonymous activation protocol based on the concept of Direct
Anonymous Attestation. The solution introduces a licensing/activation protection mechanism
for IP core-based Systems-on-Chip. Our proposal also allows implementing hardware metering
to monitor core activations and uses. We have provided a thorough description of the protocol
and a prototype implementation highlighting its suitability for lightweight user devices. The
results confirm the feasibility of the proposed protocol, even considering user’s devices with
limited compute resources, like the one adopted for our experimental evaluation.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <article-title>[1] TPM main part 1 design principles specification version 1</article-title>
          .2,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <article-title>[2] Trusted computing platform alliance (TCPA) main specification, version 1.1a republished as trusted computing group (TCG) main specifcation</article-title>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <article-title>[3] Trusted platform module library part 1: Architecture 2</article-title>
          .0,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>Ernie</given-names>
            <surname>Brickell</surname>
          </string-name>
          , Jan Camenisch, and
          <string-name>
            <given-names>Liqun</given-names>
            <surname>Chen</surname>
          </string-name>
          .
          <article-title>Direct anonymous attestation</article-title>
          .
          <source>In Proceedings of the 11th ACM conference on Computer and communications security</source>
          , pages
          <fpage>132</fpage>
          -
          <lpage>145</lpage>
          . ACM,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Ernie</given-names>
            <surname>Brickell</surname>
          </string-name>
          , Liqun Chen, and
          <string-name>
            <given-names>Jiangtao</given-names>
            <surname>Li</surname>
          </string-name>
          .
          <article-title>A new direct anonymous attestation scheme from bilinear maps</article-title>
          .
          <source>In Trusted Computing-Challenges and Applications</source>
          , pages
          <fpage>166</fpage>
          -
          <lpage>178</lpage>
          . Springer,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Ernie</given-names>
            <surname>Brickell</surname>
          </string-name>
          and
          <string-name>
            <given-names>Jiangtao</given-names>
            <surname>Li</surname>
          </string-name>
          .
          <article-title>A pairing-based DAA scheme further reducing TPM resources</article-title>
          .
          <source>In Trust and Trustworthy Computing</source>
          , pages
          <fpage>181</fpage>
          -
          <lpage>195</lpage>
          . Springer,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>David</given-names>
            <surname>Chaum</surname>
          </string-name>
          and Eug`ene Van Heyst.
          <article-title>Group signatures</article-title>
          .
          <source>In Advances in CryptologyEUROCRYPT91</source>
          , pages
          <fpage>257</fpage>
          -
          <lpage>265</lpage>
          . Springer,
          <year>1991</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Liqun</given-names>
            <surname>Chen</surname>
          </string-name>
          .
          <article-title>A DAA scheme requiring less TPM resources</article-title>
          .
          <source>In Information Security and Cryptology</source>
          , pages
          <fpage>350</fpage>
          -
          <lpage>365</lpage>
          . Springer,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Liqun</given-names>
            <surname>Chen</surname>
          </string-name>
          , Dan Page, and Nigel P Smart.
          <article-title>On the design and implementation of an efficient DAA scheme</article-title>
          .
          <source>In Smart Card Research and Advanced Application</source>
          , pages
          <fpage>223</fpage>
          -
          <lpage>237</lpage>
          . Springer,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Alessandro</surname>
            <given-names>Cilardo</given-names>
          </string-name>
          , Mario Barbareschi, and
          <string-name>
            <given-names>Antonino</given-names>
            <surname>Mazzeo</surname>
          </string-name>
          .
          <article-title>Secure distribution infrastructure for hardware digital contents</article-title>
          .
          <source>Computers &amp; Digital Techniques, IET</source>
          ,
          <volume>8</volume>
          (
          <issue>6</issue>
          ):
          <fpage>300</fpage>
          -
          <lpage>310</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Nathaniel</given-names>
            <surname>Couture and Kenneth B Kent</surname>
          </string-name>
          .
          <article-title>Periodic licensing of FPGA based intellectual property</article-title>
          .
          <source>In Field Programmable Technology</source>
          ,
          <year>2006</year>
          .
          <article-title>FPT 2006</article-title>
          . IEEE International Conference on, pages
          <fpage>357</fpage>
          -
          <lpage>360</lpage>
          . IEEE,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Saar</surname>
            <given-names>Drimer</given-names>
          </string-name>
          , Tim Gu¨neysu, Markus G Kuhn,
          <article-title>and Christof Paar. Protecting multiple cores in a single FPGA design</article-title>
          . Draft available at http://www.cl.cam.ac.uk/sd410/, written May,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Tim</surname>
            <given-names>Guneysu</given-names>
          </string-name>
          , Bodo Mo¨ller, and Christof Paar.
          <article-title>Dynamic intellectual property protection for reconfigurable devices</article-title>
          .
          <source>In Field-Programmable Technology</source>
          ,
          <year>2007</year>
          . ICFPT 2007. International Conference on, pages
          <fpage>169</fpage>
          -
          <lpage>176</lpage>
          . IEEE,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Krzysztof</surname>
            <given-names>Kepa</given-names>
          </string-name>
          , Fearghal Morgan, Krzysztof Kosciuszkiewicz, and
          <string-name>
            <given-names>Tomasz</given-names>
            <surname>Surmacz</surname>
          </string-name>
          .
          <article-title>Serecon: A secure dynamic partial reconfiguration controller</article-title>
          .
          <source>In Symposium on VLSI</source>
          ,
          <year>2008</year>
          . ISVLSI'08. IEEE Computer Society Annual, pages
          <fpage>292</fpage>
          -
          <lpage>297</lpage>
          . IEEE,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Jiqiang</surname>
            <given-names>Liu</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Jia</given-names>
            <surname>Zhao</surname>
          </string-name>
          , and Zhen Han.
          <article-title>A remote anonymous attestation protocol in trusted computing</article-title>
          .
          <source>In Parallel and Distributed Processing</source>
          ,
          <year>2008</year>
          .
          <article-title>IPDPS 2008</article-title>
          . IEEE International Symposium on, pages
          <fpage>1</fpage>
          -
          <lpage>6</lpage>
          . IEEE,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Li</surname>
            <given-names>Lixin</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Li</given-names>
            <surname>Chaoling</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Zhou</given-names>
            <surname>Yanzhou</surname>
          </string-name>
          .
          <article-title>A remote anonymous attestation scheme with improved privacy CA</article-title>
          .
          <source>In 2009 International Conference on Multimedia Information Networking and Security</source>
          , volume
          <volume>1</volume>
          , pages
          <fpage>153</fpage>
          -
          <lpage>157</lpage>
          . IEEE,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Roel</surname>
            <given-names>Maes</given-names>
          </string-name>
          , Dries Schellekens, and
          <string-name>
            <given-names>Ingrid</given-names>
            <surname>Verbauwhede</surname>
          </string-name>
          .
          <article-title>A pay-per-use licensing scheme for hardware IP cores in recent SRAM-based FPGAs</article-title>
          .
          <source>Information Forensics and Security</source>
          , IEEE Transactions on,
          <volume>7</volume>
          (
          <issue>1</issue>
          ):
          <fpage>98</fpage>
          -
          <lpage>108</lpage>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Ravikanth</surname>
            <given-names>Pappu</given-names>
          </string-name>
          , Ben Recht, Jason Taylor, and Neil Gershenfeld.
          <article-title>Physical one-way functions</article-title>
          .
          <source>Science</source>
          ,
          <volume>297</volume>
          (
          <issue>5589</issue>
          ):
          <fpage>2026</fpage>
          -
          <lpage>2030</lpage>
          ,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Luis</surname>
            <given-names>Parrilla</given-names>
          </string-name>
          ,
          <source>Encarnacio´n Castillo</source>
          , Diego P Morales, and Antonio Garc´ıa.
          <article-title>Hardware activation by means of PUFs and elliptic curve cryptography in field-programmable devices</article-title>
          .
          <source>Electronics</source>
          ,
          <volume>5</volume>
          (
          <issue>1</issue>
          ):
          <fpage>5</fpage>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Jerome</surname>
            <given-names>Rampon</given-names>
          </string-name>
          , Renaud Perillat, Lionel Torres, Pascal Benoit, Giorgio Di Natale, and
          <string-name>
            <given-names>Mario</given-names>
            <surname>Barbareschi</surname>
          </string-name>
          .
          <article-title>Digital right management for IP protection</article-title>
          .
          <source>In VLSI (ISVLSI)</source>
          ,
          <source>2015 IEEE Computer Society Annual Symposium on</source>
          , pages
          <fpage>200</fpage>
          -
          <lpage>203</lpage>
          . IEEE,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>Micheal</given-names>
            <surname>Scott</surname>
          </string-name>
          .
          <article-title>Multiprecision integer and rational arithmetic cryptographic library (MIRACL</article-title>
          ),
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>Eric</given-names>
            <surname>Simpson</surname>
          </string-name>
          and
          <string-name>
            <given-names>Patrick</given-names>
            <surname>Schaumont</surname>
          </string-name>
          .
          <article-title>Offline hardware/software authentication for reconfigurable platforms</article-title>
          .
          <source>In CHES</source>
          , volume
          <volume>4249</volume>
          , pages
          <fpage>311</fpage>
          -
          <lpage>323</lpage>
          . Springer,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Christian</surname>
            <given-names>Wachsmann</given-names>
          </string-name>
          , Liqun Chen, Kurt Dietrich, Hans Lo¨hr,
          <string-name>
            <surname>Ahmad-Reza Sadeghi</surname>
            , and
            <given-names>Johannes</given-names>
          </string-name>
          <string-name>
            <surname>Winter</surname>
          </string-name>
          .
          <article-title>Lightweight anonymous authentication with TLS and DAA for embedded mobile devices</article-title>
          .
          <source>In Information Security</source>
          , pages
          <fpage>84</fpage>
          -
          <lpage>98</lpage>
          . Springer,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <surname>Li</surname>
            <given-names>Xi</given-names>
          </string-name>
          , Dengguo Feng, Yu Qin, Feng Wei, Jianxiong Shao, and
          <string-name>
            <given-names>Bo</given-names>
            <surname>Yang</surname>
          </string-name>
          .
          <article-title>Direct anonymous attestation in practice: Implementation and efficient revocation</article-title>
          .
          <source>In Privacy, Security and Trust (PST)</source>
          ,
          <year>2014</year>
          Twelfth Annual International Conference on, pages
          <fpage>67</fpage>
          -
          <lpage>74</lpage>
          . IEEE,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>Bo</surname>
            <given-names>Yang</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Dengguo</given-names>
            <surname>Feng</surname>
          </string-name>
          , and
          <string-name>
            <given-names>Yu</given-names>
            <surname>Qin</surname>
          </string-name>
          .
          <article-title>A lightweight anonymous mobile shopping scheme based on DAA for trusted mobile platform</article-title>
          .
          <source>In Trust, Security and Privacy in Computing and Communications (TrustCom)</source>
          ,
          <year>2014</year>
          IEEE 13th International Conference on, pages
          <fpage>9</fpage>
          -
          <lpage>17</lpage>
          . IEEE,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Bo</surname>
            <given-names>Yang</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kang</surname>
            <given-names>Yang</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yu</surname>
            <given-names>Qin</given-names>
          </string-name>
          , Zhenfeng Zhang, and Dengguo Feng.
          <article-title>DAA-TZ: An efficient DAA scheme for mobile devices using ARM trustzone</article-title>
          .
          <source>In Trust and Trustworthy Computing</source>
          , pages
          <fpage>209</fpage>
          -
          <lpage>227</lpage>
          . Springer,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <surname>Jiliang</surname>
            <given-names>Zhang</given-names>
          </string-name>
          , Yaping Lin, Yongqiang
          <string-name>
            <surname>Lyu</surname>
            , and
            <given-names>Gang</given-names>
          </string-name>
          <string-name>
            <surname>Qu</surname>
          </string-name>
          .
          <article-title>A PUF-FSM binding scheme for FPGA IP protection and pay-per-device licensing</article-title>
          .
          <source>Information Forensics and Security</source>
          , IEEE Transactions on,
          <volume>10</volume>
          (
          <issue>6</issue>
          ):
          <fpage>1137</fpage>
          -
          <lpage>1150</lpage>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>Qianying</surname>
            <given-names>Zhang</given-names>
          </string-name>
          , Shijun
          <string-name>
            <surname>Zhao</surname>
            ,
            <given-names>Li</given-names>
          </string-name>
          <string-name>
            <surname>Xi</surname>
            ,
            <given-names>Wei</given-names>
          </string-name>
          <string-name>
            <surname>Feng</surname>
            , and
            <given-names>Dengguo</given-names>
          </string-name>
          <string-name>
            <surname>Feng</surname>
          </string-name>
          .
          <article-title>Mdaak: A flexible and efficient framework for direct anonymous attestation on mobile devices</article-title>
          .
          <source>In Information and Communications Security</source>
          , pages
          <fpage>31</fpage>
          -
          <lpage>48</lpage>
          . Springer,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>