Submitted:
20 July 2024
Posted:
22 July 2024
You are already at the latest version
Abstract
Keywords:
1. Introduction
- The proposal of an optimized RO block structure that takes full advantage of the Configurable Logic Blocks (CLBs) of current Xilinx FPGA and SoC families to significantly increase the hardware efficiency of previous designs.
- The encapsulation of the design as a highly parameterizable IP module, with dual PUF/TRNG functionality, and connectable through a standard interface that facilitates its integration with soft- or hard-core general-purpose processors for the implementation of embedded systems.
- The development of a library of low- and high-level software components that facilitate the interaction of the processor with the hardware and make it possible to carry out online the successive stages of validation, characterization, and exploitation of the design.
- The implementation of two test systems and the collection of a considerable amount of experimental data to perform a complete characterization of the statistical properties of the adopted solution, as well as to obtain the metrics to evaluate the performance of the proposed PUF/TRNG module.
- The availability of an open access repository that includes hardware and software components necessary so that the reader can perform different experiments on their own development board to analyze the effect of different design parameters on the capacity of the PUF/TRNG module to act as an essential element for the obfuscation and recovery of secret information in a key management system.
2. Configurable RO-PUFs
3. Hardware-Efficient Configurable RO-PUF/TRNG Module
3.1. Structure and Main Components of the PUF/TRNG
3.2. PUF/TRNG IP Module Development Process
4. Test System for Statistical Characterization of the CRO-Based PUF/TRNG
4.1. ROs Oscillation Frequencies
4.2. PUF/TRNG_1.0 Bit Selection
4.3. Output Bit Characterization
4.4. Performance Metrics Estimation
5. Test System for Performance Evaluation of the Proposed PUF/TRNG
5.1. PUF/TRNG_2.0 Bit Selection
5.2. PUF Performance Metrics
5.3. TRNG Validation
5.4. Summary and Result Comparison
- The uniqueness of the PUF is excellent regardless of the design parameters and run-time options used, as demonstrated by the fact that the average HDinter values are greater than 49.3 for 12- and 14-bit counter implementations, as well as the circumstance that they remain almost unchanged when the challenge selection mechanism is applied to improve PUF reliability.
- The reliability of the PUF does depend on the run-time options that select the type of counter (binary or Gray code) and the bits chosen to be part of the output (lower or higher). The combinations GL and BH always show the most favorable and unfavorable values of HDintra, respectively, while GH and BL provide intermediate values of this metric.
- Regardless of the used options, the uniformity of the PUF outputs (both of the test system for characterization analyzed in Section 4, and of the test system that uses the proposed PUF) reveal the absence of bias that could compromise the security of a system that uses the latter as a basic primitive. However, the tests carried out to characterize the different combinations of run-time options in the test systems revealed that those combinations that use lower bits of the counters do not provide the necessary entropy to ensure the strength of the PUF against certain types of attacks.
- Depending on the application or task in which it will be used, the user can prioritize the reliability or strength of the PUF. Without forgetting that reliability can also be improved by properly applying the challenge selection mechanism provided by the SDK, the use of GH options can constitute an appropriate trade-off.
6. Using the PUF/TRNG IP for Secure Key Management
7. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
Abbreviations
| AXI | Advanced Extensible Interface |
| BR PUF | Bistable Ring Physical Unclonable Function |
| BRAM | Block Random-Access Memory |
| CLB | Configurable Logic Block |
| CRO | Configurable Ring Oscillator |
| DRAM | Dynamic Random-Access Memory |
| ECC | Error-Correcting Code |
| FPGA | Field-Programmable Gate Array |
| GUI | Graphical User Interface |
| HDA | Helper Data Algorithm |
| IC | Integrated Circuit |
| ID | Identifier |
| IID | Independent and Identically Distributed |
| IoT | Internet of Things |
| IP | Intellectual Property |
| LFSR | Linear Feedback Shift Register |
| LSB | Least Significant Bit |
| LSR | Longest Repeated Substring |
| LUT | Look-Up Table |
| MSB | Most Significant Bit |
| NIST | National Institute of Standards and Technology |
| PDL | Programmable Delay Line |
| PL | Programmable Logic |
| PS | Processor System |
| PUF | Physical Unclonable Function |
| PYNQ | Python Productivity for Zynq |
| RO | Ring Oscillator |
| RoT | Root of Trust |
| SoC | System on Chip |
| SDK | Software Development Kit |
| SRAM | Static Random-Access Memory |
| TMV | Temporal Majority Voting |
| TRNG | True-Random Number Generators |
References
- Abouzakhar, N. Critical infrastructure cybersecurity: a review of recent threats and violations. In Proceedings of the European Conference on Information Warfare and Security, Jyväskylä, Finland, 11–12 July 2013; pp. 1–10. [Google Scholar]
- Alyas, T.; Tabassum, N.; Abbas, S.; Ather, A. Data Breaches Security Issues for Cloud Based Internet of Things. Int. J. Elect. Crime Investigation 2018, 2, 35–41. [Google Scholar] [CrossRef]
- Chernyshev, M.; Zeadally, S.; Baig, Z. Healthcare data breaches: Implications for digital forensic readiness. J. Med. Syst. 2019, 43, 1–12. [Google Scholar] [CrossRef]
- Resul, D.; Gündüz, M.Z. Analysis of cyber-attacks in IoT-based critical infrastructures. Int. J. Inf. Secur. Sci. 2020, 8, 122–133. [Google Scholar]
- Meneghello, F.; Calore, M.; Zucchetto, D.; Polese, M.; Zanella, A. IoT: Internet of Threats? A Survey of Practical Security Vulnerabilities in Real IoT Devices. IEEE Internet Things J. 2019, 6, 8182–8201. [Google Scholar] [CrossRef]
- Amaraweera, S.P.; Halgamuge, M.N. Internet of Things in the Healthcare Sector: Overview of Security and Privacy Issues. In Security, Privacy and Trust in the IoT Environment; Mahmood, Z., Ed.; Springer International Publishing: Cham, 2019; pp. 153–179. [CrossRef]
- Frustaci, M.; Pace, P.; Aloi, G.; Fortino, G. Evaluating Critical Security Issues of the IoT World: Present and Future Challenges. IEEE Internet Things J. 2018, 5, 2483–2495. [Google Scholar] [CrossRef]
- Tawalbeh, L.; Muheidat, F.; Tawalbeh, M.; Quwaider, M. IoT Privacy and Security: Challenges and Solutions. Applied Sciences 2020, 10. [Google Scholar] [CrossRef]
- Suh, G.E.; Devadas, S. Physical Unclonable Functions for Device Authentication and Secret Key Generation. In Proceedings of the 2007 44th ACM/IEEE Design Automation Conference, San Diego, CA, USA, 4–8 June 2007; pp. 9–14. [Google Scholar] [CrossRef]
- Lee, J.; Lim, D.; Gassend, B.; Suh, G.; van Dijk, M.; Devadas, S. A technique to build a secret key in integrated circuits for identification and authentication applications. In Proceedings of the 2004 Symposium on VLSI Circuits. Digest of Technical Papers (IEEE Cat. No.04CH37525), Honolulu, HI, USA, 7–19 June 2004; pp. 176–179. [Google Scholar] [CrossRef]
- Kumar, S.S.; Guajardo, J.; Maes, R.; Schrijen, G.J.; Tuyls, P. Extended abstract: The butterfly PUF protecting IP on every FPGA. In Proceedings of the 2008 IEEE International Workshop on Hardware-Oriented Security and TRUST (HOST), Anaheim, CA, USA, 9 June 2008; pp. 67–70. [Google Scholar] [CrossRef]
- Saraza-Canflanca, P.; Carrasco-Lopez, H.; Santana-Andreo, A.; Brox, P.; Castro-Lopez, R.; Roca, E.; Fernandez, F. Improving the reliability of SRAM-based PUFs under varying operation conditions and aging degradation. Microelectronics Reliab. 2021, 118, 114049. [Google Scholar] [CrossRef]
- Tehranipoor, F.; Karimian, N.; Xiao, K.; Chandy, J. DRAM Based Intrinsic Physical Unclonable Functions for System Level Security. In Proceedings of the 25th Edition on Great Lakes Symposium on VLSI (GLSVLSI’15), Pittsburgh, PA, USA, 20–22 May 2015; pp. 15–20. [Google Scholar] [CrossRef]
- Sutar, S.; Raha, A.; Raghunathan, V. D-PUF: An intrinsically reconfigurable DRAM PUF for device authentication in embedded systems. In Proceedings of the 2016 International Conference on Compliers, Architectures, and Sythesis of Embedded Systems (CASES), Pittsburgh, PA, USA, 1–7 Oct. 2016; pp. 1–10. [Google Scholar] [CrossRef]
- Hori, Y.; Yoshida, T.; Katashita, T.; Satoh, A. Quantitative and Statistical Performance Evaluation of Arbiter Physical Unclonable Functions on FPGAs. In Proceedings of the 2010 International Conference on Reconfigurable Computing and FPGAs, Cancun, Mexico, 13-15 Dec. 2010; pp. 298–303. [Google Scholar] [CrossRef]
- Maiti, A.; Gunreddy, V.; Schaumont, P. , V.; Schaumont, P., A Systematic Method to Evaluate and Compare the Performance of Physical Unclonable Functions. In Embedded Systems Design with FPGAs; Athanas, P., Pnevmatikatos, D., Sklavos, N., Eds.; Springer New York: New York, NY, 2013; pp. 245–267. [Google Scholar] [CrossRef]
- Hazari, N.A.; Alsulami, F.; Oun, A.; Niamat, M. Performance Analysis of XOR-Inverter based Ring Oscillator PUF for Hardware Security. In Proceedings of the 2019 IEEE National Aerospace and Electronics Conference (NAECON), Dayton, OH, USA, 15–19 July 2019; pp. 253–256. [Google Scholar] [CrossRef]
- ISO/IEC 20897-1:2020, Information security, cybersecurity and privacy protection — Physically unclonable functions — Security requirements. https://www.iso.org/standard/76353.html.
- ISO/IEC 20897-2:2022, Information security, cybersecurity and privacy protection — Physically unclonable functions — Test and evaluation methods. https://www.iso.org/standard/76354.html.
- Mansour, S.; Lauf, A. Hardware Root Of Trust for IoT Security In Smart Home Systems. In Proceedings of the 2020 IEEE 17th Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 10–13 Jan. 2020; pp. 1–2. [Google Scholar] [CrossRef]
- Martínez-Rodríguez, M.C.; Rojas-Muñoz, L.F.; Camacho-Ruiz, E.; Sánchez-Solano, S.; Brox, P. Efficient RO-PUF for Generation of Identifiers and Keys in Resource-Constrained Embedded Systems. Cryptography 2022, 6. [Google Scholar] [CrossRef]
- Rojas-Muñoz, L.F.; Sánchez-Solano, S.; Martínez-Rodríguez, M.C.; Brox, P. On-Line Evaluation and Monitoring of Security Features of an RO-Based PUF/TRNG for IoT Devices. Sensors 2023, 23. [Google Scholar] [CrossRef]
- Merli, D.; Stumpf, F.; Eckert, C. Improving the Quality of Ring Oscillator PUFs on FPGAs. In Proceedings of the 5th Workshop on Embedded Systems Security (WESS’10), Scottsdale, AZ, USA, 24 Oct. 2010. [Google Scholar] [CrossRef]
- Kodýtek, F.; Lórencz, R. A Design of Ring Oscillator Based PUF on FPGA. In Proceedings of the 2015 IEEE 18th International Symposium on Design and Diagnostics of Electronic Circuits Systems, Belgrade, Serbia, 22–24 Apr. 2015; pp. 37–42. [Google Scholar] [CrossRef]
- Kodýtek, F.; Lórencz, R.; Buek, J. Improved Ring Oscillator PUF on FPGA and Its Properties. Microprocess. Microsyst. 2016, 47, 55–63. [Google Scholar] [CrossRef]
- Maiti, A.; Schaumont, P. Improving the quality of a Physical Unclonable Function using configurable Ring Oscillators. In Proceedings of the 2009 International Conference on Field Programmable Logic and Applications, Prague, Czech Republic, 31 Aug. – 2 Sept. 2009; pp. 703–707. [Google Scholar] [CrossRef]
- Maiti, A.; Schaumont, P. Improved Ring Oscillator PUF: An FPGA-friendly Secure Primitive. J. Cryptology 2011, 24, 375–397. [Google Scholar] [CrossRef]
- Xin, X.; Kaps, J.P.; Gaj, K. A Configurable Ring-Oscillator-Based PUF for Xilinx FPGAs. In Proceedings of the 2011 14th Euromicro Conference on Digital System Design, Oulu, Finland, 31 Aug. – 2 Sep. 2011; pp. 651–657. [Google Scholar] [CrossRef]
- Gao, M.; Lai, K.; Qu, G. A highly flexible ring oscillator PUF. In Proceedings of the 2014 51st ACM/EDAC/IEEE Design Automation Conference (DAC), San Francisco, CA, USA, 1–5 June 2014; pp. 1–6. [Google Scholar] [CrossRef]
- Pei, S.; Zhang, J.; Wang, R. A low-overhead RO PUF design for Xilinx FPGAs. IEICE Electron. Express 2018, 15, 20180093–20180093. [Google Scholar] [CrossRef]
- Habib, B.; Gaj, K.; Kaps, J.P. FPGA PUF Based on Programmable LUT Delays. In Proceedings of the 2013 Euromicro Conference on Digital System Design, Los Alamitos, CA, USA, 4–6 Sep. 2013; pp. 697–704. [Google Scholar] [CrossRef]
- Zhang, Q.; Liu, Z.; Ma, C.; Li, C.; Zhang, L., FROPUF: How to Extract More Entropy from Two Ring Oscillators in FPGA-Based PUFs. In Security and Privacy in Communication Networks; Deng, R.; Weng, J.; Ren, K.; Yegneswaran, V., Eds.; Springer International Publishing: Cham, 2017; pp. 675–693. [CrossRef]
- Anandakumar, N.N.; Hashmi, M.S.; Sanadhya, S.K. Compact Implementations of FPGA-based PUFs with Enhanced Performance. In Proceedings of the 30th International Conference on VLSI Design and 16th International Conference on Embedded Systems (VLSID), Hyderabad, India, 7–11 Jan. 2017; pp. 161–166. [Google Scholar] [CrossRef]
- Zhou, K.; Liang, H.; Jiang, Y.; Huang, Z.; Jiang, C.; Lu, Y. FPGA-based RO PUF with low overhead and high stability. Electron. Lett. 2019, 55, 510–513. [Google Scholar] [CrossRef]
- Li, J.; Li, L.; Yang, J.; He, Y.; Zhou, W.; Yuan, S. An efficient and stable composed entropy extraction method for FPGA-based RO PUF. IEICE Electron. Express 2020, 17, 1–6. [Google Scholar] [CrossRef]
- Anandakumar, N.N.; Hashmi, M.S.; Sanadhya, S.K. Design and Analysis of FPGA Based PUFs with Enhanced Performance for Hardware-Oriented Security. ACM J. Emerg. Technol. Comput. Syst.. (JETC) 2022, 18, 1–26. [Google Scholar] [CrossRef]
- Diez-Senorans, G.; Garcia-Bosque, M.; Sánchez-Azqueta, C.; Celma, S. Programmable delay lines on different LUT implementations for CRO-PUF. In Proceedings of the 17th Conference on Ph.D Research in Microelectronics and Electronics (PRIME), Villasimius, SU, Italy, 12–15 June 2022; pp. 357–360. [Google Scholar] [CrossRef]
- Choudhury, M.; Pundir, N.; Niamat, M.; Mustapa, M. Analysis of a novel stage configurable ROPUF design. In Proceedings of the 2017 IEEE 60th International Midwest Symposium on Circuits and Systems (MWSCAS), Boston, MA, USA, 6–9 Aug. 2017; pp. 942–945. [Google Scholar] [CrossRef]
- Zhang, L.; Wang, C.; Liu, W.; O’Neill, M.; Lombardi, F. XOR gate based low-cost configurable RO PUF. In Proceedings of the 2017 IEEE International Symposium on Circuits and Systems (ISCAS), Baltimore, MD, USA, 28-31 May 2017; pp. 1–4. [Google Scholar] [CrossRef]
- Liu, W.; Zhang, L.; Zhang, Z.; Gu, C.; Wang, C.; O’neill, M.; Lombardi, F. XOR-Based Low-Cost Reconfigurable PUFs for IoT Security. ACM Trans. Embed. Comput. Syst. 2019, 18. [Google Scholar] [CrossRef]
- Deng, D.; Hou, S.; Wang, Z.; Guo, Y. Configurable Ring Oscillator PUF Using Hybrid Logic Gates. IEEE Access 2020, 8, 161427–161437. [Google Scholar] [CrossRef]
- Wei, Z.; Cui, Y.; Chen, Y.; Wang, C.; Gu, C.; Liu, W. Transformer PUF : A Highly Flexible Configurable RO PUF Based on FPGA. In Proceedings of the 2020 IEEE Workshop on Signal Processing Systems (SiPS), Coimbra, Portugal, 20–22 Oct. 2020; pp. 1–6. [Google Scholar] [CrossRef]
- Yao, L.; Liang, H.; Huang, Z.; Jiang, C.; Yi, M.; Lu, Y. A Lightweight Configurable XOR RO-PUF Design Based on Xilinx FPGA. In Proceedings of the 2021 IEEE 4th International Conference on Electronics Technology (ICET), Chengdu, China, 7-10 May 2021; pp. 83–88. [Google Scholar] [CrossRef]
- Cherif, Z.; Danger, J.L.; Guilley, S.; Bossuet, L. An Easy-to-Design PUF Based on a Single Oscillator: The Loop PUF. In Proceedings of the 15th Euromicro Conference on Digital System Design, Cesme, Turkey, 5–8 Sep. 2012; pp. 156–162. [Google Scholar] [CrossRef]
- Cui, Y.; Wang, C.; Liu, W.; Yu, Y.; O’Neill, M.; Lombardi, F. Low-cost configurable ring oscillator PUF with improved uniqueness. In Proceedings of the 2016 IEEE International Symposium on Circuits and Systems (ISCAS), Montreal, QC, Canada, 22-25 May 2016; pp. 558–561. [Google Scholar] [CrossRef]
- Gan, J.; Zhou, J.; Wang, N. A FPGA-based RO PUF with LUT-Based Self-Compare Structure and Adaptive Counter Time Period Tuning. In Proceedings of the 2018 IEEE International Symposium on Circuits and Systems (ISCAS), Florence, Italy, 27-30 May 2018; pp. 1–5. [Google Scholar] [CrossRef]
- Hu, Y.; Jiang, Y.; Wang, W. Compact PUF Design With Systematic Biases Mitigation on Xilinx FPGAs. IEEE Access 2022, 10, 22288–22300. [Google Scholar] [CrossRef]
- Martínez-Rodríguez, M.C.; Camacho-Ruiz, E.; Brox, P.; Sánchez-Solano, S. A Configurable RO-PUF for Securing Embedded Systems Implemented on Programmable Devices. Electronics 2021, 10. [Google Scholar] [CrossRef]
- 7 Series FPGAs Configurable Logic Block: UG474 (v1.8). Available online http://docs.xilinx.com/v/u/en-US/ug474_7Series_CLB, accessed on 16.07.2022.
- Pynq-Z2 development board. Available online http://www.tulembedded.com/FPGA/ProductsPYNQ-Z2.html/, accessed on 16.07.2024.
- Majzoobi, M.; Koushanfar, F.; Devadas, S. FPGA PUF using programmable delay lines. In Proceedings of the 2010 IEEE International Workshop on Information Forensics and Security, Seattle, WA, USA, 12-15 Dec. 2010; pp. 1–6. [Google Scholar] [CrossRef]
- AMBA AXI4 Interface Protocol. Available online https://www.xilinx.com/products/intellectual-property/axi.html, accessed on 16.07.2024.
- PYNQ—Python Productivity for Zynq. Available online http://www.pynq.io/, accessed on 16.075.2024.
- Bassham III, L.E.; Rukhin, A.L.; Soto, J.; Nechvatal, J.R.; Smid, M.E.; Barker, E.B.; Leigh, S.D.; Levenson, M.; Vangel, M.; Banks, D.L.; et al. SP 800-22 rev. 1a. A statistical test suite for random and pseudorandom number generators for cryptographic applications; National Institute of Standards & Technology, 2010. [CrossRef]
- Turan, M.S.; Barker, E.; Kelsey, J.; McKay, K.A.; Baish, M.L.; Boyle, M.; et al. SP800-90B: Recommendation for the entropy sources used for random bit generation; National Institute of Standards & Technology, 2018; p. 102. [CrossRef]
- NIST SP 800-22: Download Documentation and Software. Available online https://csrc.nist.gov/Projects/random-bit-generation/Documentation-and-Software, accessed on 16.076.2024.
- Shiozaki, M.; Hori, Y.; Fujino, T. Entropy Estimation of Physically Unclonable Functions with Offset Error. Cryptology ePrint Archive, Paper 2020/1284, 2020. https://eprint.iacr.org/2020/1284.
- NIST. NIST SP800-90B EntropyAssessment. Available online https://github.com/usnistgov/SP800-90B_EntropyAssessment, accessed on 10.06.2024.
- Delvaux, J.; Gu, D.; Schellekens, D.; Verbauwhede, I. Helper Data Algorithms for PUF-Based Key Generation: Overview and Analysis. IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst. 2015, 34, 889–902. [Google Scholar] [CrossRef]
- Hiller, M.; Kürzinger, L.; Sigl, G. Review of error correction for PUFs and evaluation on state-of-the-art FPGAs. J. Cryptogr. Eng. 2020, 10, 229–247. [Google Scholar] [CrossRef]



















| Function | Description |
|---|---|
| Create memory-mapped IO window for PUF/TRNG registers | |
| Generate PUF reference output and challenge selection mask | |
| Write challenge selection mask | |
| Reset, configure and start PUF/TRNG operation | |
| Read PUF/TRNG results from output memory | |
| Application | Description |
| Select counter bits that form the PUF output (characterization mode) | |
| Capture data for off-line evaluation of PUF performance (operation mode) | |
| Calculate parameters to estimate the unpredictability of PUF outputs | |
| , | Obtain metrics related to PUF reliability and uniqueness |
| , | Evaluates reliability and uniqueness of the PUF when used for ID generation |
| Combine some of the above functions to illustrate PUF operation | |
| * | Demonstrate PUF ability to obfuscate and recover cryptographic keys |
| Collects data for randomness analysis and entropy estimation as TRNG | |
| Run health test of the entropy source provided by the IP acting as TRNG |
| Test / Options | GH | GL | BH | BL |
|---|---|---|---|---|
| Most Common Value | 0.99527 | 0.99461 | 0.98815 | 0.97661 |
| Collision Test | 0.92264 | 0.92292 | 0.91741 | 0.93008 |
| Markov Test | 0.99722 | 0.99622 | 0.98987 | 0.98123 |
| Compression Test | 0.87331 | 0.85969 | 0.83169 | 0.85284 |
| T-Tuple Test | 0.93558 | 0.93134 | 0.93134 | 0.91799 |
| LRS Test | 0.86169 | 0.40777 | 0.98442 | 0.62947 |
| MultiMCW Prediction Test | 0.99150 | 0.99305 | 0.99511 | 0.98333 |
| Lag Prediction Test | 0.97968 | 0.98100 | 0.98050 | 0.98005 |
| MultiMMC Prediction Test | 0.99489 | 0.99113 | 0.98890 | 0.97663 |
| LZ78Y Prediction Test | 0.99572 | 0.99497 | 0.98830 | 0.97662 |
| H_original | 0.86169 | 0.40777 | 0.83169 | 0.62947 |
| Run-time Option | HDinter | HDintra | HDintra | Reduction |
|---|---|---|---|---|
| (BG - LH) | (mean) | (all cmps) | (% cmps) | ( % ) |
| Gray/Higher | 48.62 | 0.95 | 0.20 | 79.12 |
| Gray/Lower | 48.62 | 0.48 | 0.07 | 86.27 |
| Binary/Higher | 48.64 | 1.88 | 0.69 | 63.30 |
| Binary/Lower | 48.61 | 0.93 | 0.14 | 84.63 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2024 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).