Hans Kieninger, Paul Jimenez, Fabio Pavanello, David Navarro, Thach Nguyen, Arnan Mitchell, Cédric Marchand
Physically unclonable functions (PUFs) have emerged as a promising hardware security primitive, and recent years have seen growing interest in realizing PUFs on photonic integrated circuits (PICs). We classify existing PIC-based PUFs into electrically configured and optically encoded designs. Notably, security properties remain insufficiently analyzed, with mathematical unclonability often assumed without supporting argument. To illustrate this issue, we introduce a modeling attack against the subclass of optically encoded PUFs that operate in a linear optical regime. We show that, for a representative simulated PUF construction, observing as few as 200 challenge-response pairs allows learning the challenge-response mapping. Under canonical modeling assumptions, linear optically encoded PUFs are therefore mathematically clonable, calling for a careful assessment of their suitability for authentication protocols that rely on mathematical unclonability.