Integrated Circuit And Encryption Method
Abstract
A provided integrated circuit comprises a secret key module used for generating secret keys. Meanwhile, a provided encryption method comprises the steps of generating the secret keys, using the secret keys to execute an encryption algorithm.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 2 independent, 8 dependent
- 1CLAIMS:1. An integrated circuit, comprising: a key module for generating a key. 1.一种集成电路,包括: 密钥模块,用于生成密钥。
- 6A method of encrypting, comprising:generating a key;and using the key to perform a cryptographic algorithm. 6.—种加密的方法,包括: 生成密钥;以及 使用该密钥执行加密算法。
Independent claims2
188 paragraphs, as filed
Integrated circuit and encryption method
Technical field
[0001] The present invention relates to the field of digital security, and more particularly, to an encryption apparatus and method for managing a key, which can prevent a physical attack in an IC security module such as a smart card.
Technical background
[0002] A smart card is a credit card sized plastic card that contains an integrated circuit (IC) that can process data. Compared with the existing magnetic card, the smart card has many advantages, its own data storage capacity, and with the microprocessor with the co-processor (co-processor) and other processing units.
[0003] Therefore, the encryption algorithm (encryptln) is automatically performed by using an encryption algorithm to acquire personal information and financial settlement information for identifying the identity (Identificat1n).
[0004] In addition, with the development of IT technology, smart cards are widely used, while a variety of security violations for smart cards is also increasing.
In this case, physical attack similar to the reverse engineering technique using the IC chip to read the information of the IC chip has a large problem in security.
[0006] Several physical attacks are known as bus probing, test mode detection, etc., based on the storage characteristics and data storage of the electrically erasable read only memory EEPROM and the read only memory ROM used in the hardware security module (Test-mode probing), read-only memory ROM or erasable EEPROM EEPROM overwriting (overwriting) and other attacks.
Summary of the Invention
[0007] Technical Problem
[0008] An encryption apparatus and method are provided that strongly prevent a physical attack on a smart card.
[0009] In particular, an encryption apparatus and method is provided that does not directly extract a generated or stored key from a memory. In addition, there is provided an encryption apparatus and method that are not leaked through a bus in an IC chip of a smart card.
[0010] Technical Solution
According to one aspect of the present invention, there is provided an encryption apparatus that receives input data to be encrypted and performs an encryption algorithm using a key, the encryption apparatus comprising: an encryption module that includes a key module that provides a key in Internally, using the key provided by the key module to execute the encryption algorithm.
[0012] The encryption modules are contained within a plurality of key modules for providing different keys, respectively. In this case, the encryption module may include a key module selection unit that selects any one of the plurality of key modules, and an encryption unit that uses the key provided by the selected key module Executing the encryption algorithm.
Further, the key module selecting means selects the key modules corresponding to the key modules previously attached to the identification index.
According to an embodiment of the present invention, the encryption module includes a plurality of standard cells configured in an arbitrary position of a plurality of standard cell layouts included in the encryption module. The standard cell may be a normalizing element or function block for embodying the encryption module.
[0015] The integrated circuit as described above, wherein the encryption module executes the encryption algorithm using a key provided by the key module included in the encryption module, and the encryption module The provided key is not leaked to the outside of the encryption module, and other additional keys are not leaked to the encryption module in order to execute the encryption algorithm.
According to an embodiment of the present invention, the key module is a nonvolatile memory module that stores the key generated in advance.
[0017] According to another embodiment of the present invention, the key module is a non-storage module that generates and provides the key.
[0018] In this case, the key module, in violation of a design specification provided in the semiconductor engineering, probabilistically determines whether a short circuit exists between nodes in the key module, and the key module, The key may be generated and provided according to a result of reading whether or not the node is short-circuited.
[0019] Herein, a node in the key module is a conductive layer of a semiconductor, and the design specifies a size of a contact or a path formed between the conductive layer of the semiconductor and the key And a key that is generated by short-circuiting the conductive layer with a contact or a path formed between the conductive layers of the semiconductor.
[0020] Furthermore, the keying module, in violation of the design specifications provided in the semiconductor engineering, causes the junction or via formed between the conductive layers of the semiconductor to cause a probability that the conductive layer is short-circuited with The difference in the probability of non-short-circuiting is maintained within a certain error range and has the dimensions of said contacts or vias.
[0021] According to an embodiment of the invention, the key module has N cell structures that generate I-bit digital values using a pair of conductive layers and a contact or path between them, and pass the N bits, wherein N is a natural number, is generated as a result of the N-bit cell structure.
In this case, the key module groups the generated N-bit digital values in k units, and compares the first group and the second group among a plurality of groups to be grouped, When the value formed by the k number bits included in the first group is larger than the value of the k number bits included in the second group, a value representing a value of the first group and the second group The digital value is determined as I, and on the contrary, the digital value representing the I-group and the second group is determined to be 0, thereby generating a digital value of N / k bits as the key, where k is Natural number.
[0023] According to another embodiment of the invention, a node within the key module is a conductive layer of a semiconductor, and the design is specified in relation to a gap between the conductive layers of the semiconductor, Wherein the key module generates and supplies the key using a short circuit between the conductive layers of the semiconductor.
[0024] According to still another embodiment of the present invention, the key module includes N unit cells each of which outputs a digital value of I bits, N is a natural number, and the N unit lattices, The digital values of I bits are generated, respectively, based on the semiconductor manufacturing process variation so that the key module generates and provides an N-bit key.
In this case, the I-unit lattice of the N unit cells includes an I-th inverter having an Ith logic threshold, and a 2nd inverter having a second logic threshold value, And an input terminal of the first inverter and an output terminal of the second inverter are connected to an Ith node and an output terminal of the first inverter and an input terminal of the second inverter are connected And the second logic threshold value and the second logic threshold value are different from each other based on the semiconductor manufacturing process variation, and the second logic point is set in accordance with the logic level of the first node and the second node is connected to the second node, To determine an I-bit digital value corresponding to said I-th unit lattice.
According to yet another embodiment of the present invention, the key module comprises: N number of differential amplifiers, N being a natural number, and an N-th differential amplifier of the N differential amplifiers , The logic levels of the two output terminals of the I-th differential amplifier are different from each other when the two inputs of the I-difference amplifier are short-circuited, and the logic levels of the two output terminals of the I- Logic level to determine an I-bit digital value corresponding to the I-differential amplifier, and the key module generates and provides an N-bit key.
[0027] According to another aspect of the present invention, there is provided an encryption method comprising the steps of: receiving data to be encrypted, inputting to a cryptographic module having a key module including a supplied key therein; and using the key Lt; / RTI & gt; module to perform the encryption algorithm, thereby encrypting the data.
According to still another aspect of the present invention, there is provided an IC chip that receives input data to be encrypted and performs an encryption algorithm using a key, the IC chip comprising: an encryption module including therein an encryption key And a key module that executes the encryption algorithm using a key provided by the key module.
In this case, the IC chip is embedded in the smart card, and the encryption algorithm can be executed when the smart card is applied.
[0030] Technical Effect
[0031] Since a key is not generated outside the encryption module to be stored in the memory or transmitted over the bus, it is safe for physical attack such as non-volatile memory attack or bus probing.
[0032] Since the key module is distributed within the module similarly to other standard cells, it is difficult to directly discover that it is safe for attacks that extract memory content by physical attacks.
Since the nonvolatile memory that stores the key is not required, the amount of space and power consumption can be improved.
BRIEF DESCRIPTION OF THE DRAWINGS Fig
[0034] FIG. 1 is a diagram illustrating an encryption apparatus according to an embodiment of the present invention.
[0035] FIG. 2 is a diagram illustrating a cryptographic module according to one embodiment of the present invention.
[0036] FIG. 3 is a block diagram illustrating an exemplary structure of a cryptographic module according to one embodiment of the present invention.
4 is a diagram for explaining the concept of a unit cell of a key module in the form of a physical anti-cloning function PUF (Physical Unclonable Funct 1 ns) in accordance with an embodiment of the present invention using engineering variation to generate a key Circuit diagram.
[0038] FIG. 5 is a reference diagram for understanding the embodiment of FIG.
[0039] FIG. 6 is a block diagram illustrating an exemplary embodiment of a key module according to one embodiment of the present invention.
[0040] FIG. 7 is a diagram illustrating a unit cell of a key module that generates a digital value by engineering variation of a differential amplifier in accordance with one embodiment of the present invention.
[0041] FIG. 8 is an exemplary circuit diagram illustrating a key module embodied in accordance with one embodiment of the present invention.
9 is a conceptual diagram for illustrating the principle of generating a key module in violation of a semiconductor design specification, according to an embodiment of the present invention.
[0043] FIG. 10 is a diagram illustrating a structure of a key module that violates a semiconductor design specification, in accordance with one embodiment of the present invention.
11 is a conceptual diagram for explaining a process of adjusting a gap between conductive layers to generate a key module according to an embodiment of the present invention.
[0045] FIG. 12 is a conceptual diagram illustrating an exemplary structure of a via or contact array formed in a semiconductor layer embodying a key module according to one embodiment of the present invention.
13 is a diagram for explaining that the digital value generated in the embodiment of Fig. 12 is not used directly as a key, but for the post-processing of the balance of O and I, according to an embodiment of the present invention Conceptual diagram of the process.
detailed description
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS Hereinafter, a part of embodiments of the present invention will be described in detail with reference to the accompanying drawings. However, the invention is not to be limited or limited by the embodiments, and like reference numerals denote like parts in the various views.
[0048] FIG. 1 is a diagram illustrating an encryption device 100 according to one embodiment of the present invention.
[0049] According to an example, the encryption device 100 may be a structure included in an IC chip of a smart card, an electrically erasable read-only memory (EEPR0M) 120 that stores data, a central processing unit (CPU) 130, and optional synchronization Dynamic random access memory (SDRAM) 140, and communicates externally with the I / O interface 101.
The encryption device 100 includes a cryptographic module 110, which may be, for example, a crypto co-processor for encryption, o & lt; RTI ID = 0.0 & gt;
(EEPROM) 120, a central processing unit (CPU) 130, and a selectable synchronous dynamic random access memory (SDRAM) 130 according to an application example of the encryption device 100 including an IC chip of a smart card or a smart card ) 140 may be omitted and various modifications or applications can be made without departing from the spirit and scope of the present invention and will not be described in detail herein.
The I / O interface 101 is an input / output line for outputting and inputting data to / from the encryption apparatus 100, regardless of the contact type and / or the non-contact type, and is not described in detail herein.
In addition, the encryption module 110 of the encryption device 100 according to one embodiment of the present invention may use a key in the course of executing the encryption algorithm. The key may be a concept such as a public key and a secret key.
[0054] In the prior art, the key used to execute the encryption algorithm is stored in the form of a digital value outside the encryption module 110 so that the encryption module 110 executes the encryption algorithm, encrypts and / or decodes the data through the bus 102 to receive the key.
However, the method is more fragile in a physical attack intended to identify encryption algorithms and / or keys.
[0056] The physical attack can directly attack a keyed area in a memory such as an electrically erasable read-only memory (EEPROM) 120, extracting the key in memory in a manner similar to probing or memory scanning. Further, since the position of the bus 102 in the IC chip can be obtained by performing reverse engineering, a specific command word is executed artificially, and in this case, a bus probing is performed using a micro-probe ) Can extract the key.
[0057] According to one embodiment of the present invention, the key module 111 contained in the encryption module 110 encrypts the directly generated and / or pre-generated keys in the key module 111 for a period of time before the encryption module 110 performs encryption Algorithm to provide the key.
[0058] Thus, according to the above-described embodiment, the encryption module 110 does not store the used key in the form of a digital value outside the encryption module 110 during the execution of the encryption algorithm, and since the key is not passed over the bus 102 Transmission, and therefore, physical attacks on the encryption algorithm of the encryption module 110 can be prevented.
[0059] A key module 111 that generates and / or stores keys to provide when the encryption algorithm of the encryption module 110 is executed, which may be physically included in the encryption module 110, some exemplary implementations of its structure and operation An example will be described with reference to Fig.
[0060] FIG. 2 is a diagram illustrating an encryption module 110 in accordance with one embodiment of the present invention.
As shown in FIG. 1, the encryption module 110 may be connected to the bus 102 by other structures in the encryption apparatus 100. As shown in FIG.
[0062] According to one embodiment of the present invention, the encryption module 110 includes at least one of the key modules 210, 220, 230, 240,
The key modules 210, 220, 230, 240, 250 are each independently or associated with each other to generate and / or store the keys needed to execute the encryption algorithm and provide the encryption module 110 as shown in the example diagram.
In some embodiments, the encryption module 110 may include only one key module, but in other embodiments, as shown in FIG. 2, a plurality of key modules are included.
In addition, when the encryption module 110 includes a plurality of key modules, at least a portion of the plurality of key modules 210, 220, 230, 240, 250 may be dummy that does not actually provide the key.
In embodiments embodying the key modules 210, 220, 230, 240, 250, the key modules 210, 220, 230, 240, 250 may be memory devices and non-memory devices Device) two cases.
Of course, one of the key modules 210, 220, 230, 240 and 250 may be a storage device, and the other part may be a non-storage device, and the present invention is not limited to only a part of the embodiments.
Illustratively, in an embodiment in which the key modules 210, 220, 230, 240, 250 are storage devices, a key in the form of a digital value generated in advance is simply stored in the key module 210, which is a storage device , 220, 230, 240, 250 - After a period of time, the encryption module 110 reads and uses it as needed during the execution of the encryption algorithm.
[0069] In other embodiments, when the key modules 210, 220, 230, 240, 250 are non-storage devices, at least a portion of the key modules 210, 220, 230, 240, 250 may be protected by a physical anti-clone function 13 (? 1 ^ 8? 31 UnclonableFunct1ns) to achieve.
In embodiments where the key module 210, 220, 230, 240, 250 is comprised of a PUF-like non-storage device, the embodiments embodying the PUF may be implemented in a number of ways, for example, violating design specifications on semiconductor fabrication engineering Or by engineering variation of a semiconductor fabrication process.
This embodiment will be described in more detail with reference to FIG. 4 to FIG. 13.
[0072] FIG. 3 is a block diagram illustrating an exemplary configuration of an encryption module 110 in accordance with one embodiment of the present invention.
When the encrypted data can be input to the data input unit 310 through the bus 102 or the like, the execution of the encryption algorithm is started.
2, the key module 320, which is physically contained in the encryption module 110, may be one or more, as described above. Referring to FIG.
For example, when the key modules 01 321 to the key module N322 are present, the key module selection unit 330 selects a key module for providing a key to be used in the encryption algorithm, where N is a natural number.
[0076] The selection may be index information for identifying the key module (s) actually selected in the index of the key module 320, or the key module 320 and the encryption module 110- and may be configured Process, by wiring (wiring) is set in advance.
[0077] After the key is set by the process, the encryption unit 340 uses the key to execute the encryption algorithm, thereby encrypting the input data and transmitting it via the bus 102 via the data output unit 350 to other structures.
Although only the data encryption process has been described in detail above, the decoding process using the encryption algorithm is similar. Embodiments of the invention are not limited to any one of encryption or decoding.
Thus, the management of the key is automatically formed in the encryption module 110 so that the key is not transmitted to the outside of the encryption module 110 or transmitted from the outside to the encryption module 110 so that the physical attack succeeds The possibility is low. In particular, the probability of a physical attack on the probe bus 102 being successful is very low.
1 to 2, the key module is described as a storage device, and an embodiment in which the key module is embodied by the PUF of the non-storage device will be described with reference to FIGS. 4 to 13. Referring to FIG.
[0081] By way of reference, the PUFs mentioned in the present invention are not capable of performing physical duplication and, after one-time preparation, generate at least theoretically unchangeable keys.
[0082] In the following, various embodiments will be described in which a key module is embodied by a PUF of a non-memory device, and FIGs. 4 to 8 correspond to a secret key generated by engineering variation in a semiconductor process Key module.
9 to 13 correspond to an embodiment in which a key module is generated in violation of design specifications when designing a circuit.
4 is an exemplary circuit diagram for explaining the concept of a unit cell of a key module in the form of a physical anti-clone function PUF in which a key is generated using engineering variation according to an embodiment of the present invention.
In the embodiment shown in Fig. 4, the I-th inverter 410 and the second inverter 420 are shown.
[0086] In semiconductor engineering, engineering variation occurs for a variety of reasons. For example, when preparing a transistor, parameters such as the gate length, the semiconductor dopant density-related index, the oxide thickness-related index, or the threshold voltage may be causes of engineering deterioration.
[0087] In general, it is believed that a smaller semiconductor fabrication process is more excellent in engineering variation, but in terms of physical characteristics, the variation in the variation of the work can be made as small as possible but not completely eliminated.
In the present embodiment, the I inverter 410 may have an Ith logic threshold, and the second inverter 420 may have a second logic threshold. The logic threshold (1gic threshold) is the voltage value at which the input voltage and the output voltage of the inverter have the same value, which will be described below with reference to Fig.
[0089] The logic threshold of the inverter may be detected as a voltage value when the output and the input of the inverter are shorted.
The inverters prepared in the same construction are theoretically designed to have the same logic threshold value, but as described above, since there are engineering variations in the actual preparation work, any two inversions The variator may not have exactly the same logic threshold.
According to one embodiment of the present invention, the first inverter 410 and the second inverter 420 are prepared in the same preparation process, and therefore have a difference in logic threshold due to the engineering variation .
The difference in the logic thresholds may vary from a few millivolts to several tens of millivolts, although it varies according to engineering. Therefore, it is not accurate to detect the logic threshold of the I-th inverter 410 and the logic threshold of the second inverter 420 by using another comparator circuit due to detection errors.
[0093] Therefore, a need exists for a method that can relatively compare the logic thresholds of two inverters (S & lt; 1 & gt; without using another comparator circuit for detection). In some embodiments of the invention, the logic thresholds between the two inverters are relatively (not automatically compared with other comparator circuits) to be compared, so that it is possible to determine which of the logic thresholds is greater.
Assuming that the second inverter 420 is not present and the input and output terminals of the first inverter 410 are short-circuited, the output voltage of the I-th inverter 410 is the same as the logic threshold of the I-th inverter 410 the same.
When the first inverter 420 is not present and the input and output terminals of the second inverter 420 are short-circuited, the output voltage of the second inverter 420 is the same as the output voltage of the second inverter 420 The logic thresholds are the same.
4, when the input terminal of the I inverter 410 and the output terminal of the second inverter 420 are short-circuited and connected through the I-th node, and the output of the I-th inverter 410 is output as shown in Fig. And the input terminal of the second inverter 420 are short-circuited, and when they are connected through the second node, there is a difference from the above.
When the first node and the second node are short-circuited by the switch 430, the voltage value of the two nodes short-circuited is the logical threshold value of the first inverter 410 and the second threshold value of the second inverter (Possibly below the average) of the logic thresholds of the variable 420. [
[0098] Regardless of which of the logical thresholds of the two inverters is high, the value of the output voltage is the median of the logic thresholds of the two inverters during the time the switch 430 is closed.
When the switch 430 is turned on and the I-node and the second node are made to be open, the logical voltage of the voltage value of any one of the I-th node and the second node is turned on Logical level is "O", and the logical level of the other is "I".
For example, it is assumed that the switch 430 is turned off when the logic threshold value of the I-th inverter 410 is lower than the logic threshold value of the second inverter 420, and the first node (the opposite node of the output Out) The voltage of the I-th node during the short-circuit period is higher than the logic threshold value of the I-th inverter 410. In this case,
After the switch 430 is reopened and the first node and the second node are opened, the I inverter 410 recognizes the voltage at the (Ith) node of the (own input terminal) as high (High) The voltage of the second node at the output terminal of the I-th inverter 210 is a low logic level.
In this case, the voltage of the second node (input terminal) of the second inverter 420 is recognized as a low logic level, so that the voltage of the first node of the output terminal of the second inverter 420 For high logic levels.
As a result, the voltage at the second node of the output terminal ("Out") of Fig. 4 is high (Logical).
On the other hand, when the logic threshold value of the I-th inverter 410 is higher than the logic threshold value of the second inverter 420, the switch 430 is closed and the I-node and the second node are short-circuited, Is lower than the logic threshold of the I-th inverter 410. [
When the switch 430 is turned on again and the first node and the second node are opened, the I-inverter 410 recognizes the voltage of the (I-th input) I-node as a low logic level , The voltage of the second node at the output terminal of the I-th inverter 410 is a high logic level.
In this case, the voltage of the second node (input terminal) of the second inverter 420 is recognized as a high logic level, and therefore the voltage of the first node of the output terminal of the second inverter 420 a low logic level.
As a result, the voltage at the second node of the output terminal ("Out") of Fig. 4 is a low logic level.
As described above, the short-open ("Out") output of the switch 430 is determined based on which of the logic thresholds of the I-th inverter 410 and the logic threshold of the second inverter 420 is high. Is high (or "I") or low (or "O").
However, the logic thresholds of the first inverter 410 and the second inverter 420, which are prepared in the same production process, are higher in randomness, The probability that one of the logic thresholds of the inverter is higher than the other logic threshold is about 50%.
In addition, after preparation, it is difficult to change which one of the higher logical threshold values is.
4, it is possible to generate digital values of I bits ("I" or "O", although the probability is the same, but it is difficult to change once the decision is made.) As shown in Fig.
The above process will be more clearly understood with reference to Fig.
Fig. 5 is a reference diagram for understanding the embodiment of Fig. 4. Fig.
In the present exemplary embodiment, a voltage characteristic is obtained when the logic threshold value of the I-th inverter 410 of FIG. 4 is lower than the logic threshold value of the second inverter 420. As shown in FIG.
Curve 510 is a voltage characteristic curve of the I-th inverter 410, and a curve 520 is a voltage characteristic curve of the second inverter 420. [ According to one embodiment of the present invention, when the first inverter 410 and the second inverter 420 are prepared in the same preparation process, the curve 510 and the curve 520 are substantially identical, but because of the engineering deterioration, difference.
The logic threshold Vl of the I-th inverter 410 may be determined when finding the intersection of the curve 510 and the slanting I-line 530. [00116] In addition, when the intersection of the curve 520 and the line 530 is found, the logic threshold V2 of the second inverter 420 can be determined.
When the first node and the second node are short-circuited (also referred to as "reset"), the first node and the second node are connected to the first node and the second node of the second node. In this embodiment, The voltage (VReset) is any value between Vl and V2.
After the switch 430 is reopened and the first node and the second node are opened, the first inverter 410 recognizes the voltage (VReset) of the first node as a high logic level. Therefore, And the voltage of the second node at the output terminal of the first inverter 410 is a low logic level.
In this case, the second inverter 420 recognizes the voltage (VReset) of the second node as a low logic level, so that the voltage at the output node I node of the second inverter 420 is high logic Level.
Therefore, the voltage at the second node of the output terminal ("Out") of Fig. 4 is a high logic level.
As shown in Fig. 4, when the unit lattice is a digital value of I bits, when the unit lattice is integrated with N, a digital value of N bits generates a key.
[00122] According to some embodiments of the present invention, the key module 320 may be embodied in this manner.
The key module may be embodied as shown in FIG. 6 below, and a key in the form of a digital value may be generated by using the logic threshold difference of the inverter device of the semiconductor engineering variation.
6 is a block diagram illustrating an exemplary embodiment of a key module 600 in accordance with one embodiment of the present invention.
In the present embodiment, the key module 600 includes five inverters of the inverter 611 to the inverter 615, a selection unit 620, and a comparison unit 630. [
[0126] The selection unit 620 may select any two of the five inverters shown in FIG. 6, for example, the inverter 612 and the inverter 613 may be selected.
In this case, the comparison unit 630 compares the logic threshold of the inverter 612 with the logic threshold of the inverter 613, and provides an output voltage to the output terminal according to the comparison result. In addition, a digital value of I bits can be generated based on the logic level of the output voltage at the output (Out) terminal.
In addition, when the selection unit 620 selects another two inverters, the comparison unit 630 may regenerate the I-bit digital value.
As described above, the selection unit 620 may select two of the five inverters (611 to 615), and when the comparison unit 630 compares the logic thresholds of the selected two inverters to generate a digital value , Up to 1-bit digital values can be obtained.
In the present embodiment, although five inverters are included, the present invention is not limited to the number of bits of the digital value generated by the OFF, the area of the circuit, and the like, and various changes can be made.
In addition, in the present embodiment, the plurality of inverters and the one comparing unit 630 are connected to each other by selecting the cells (611 to 615) when the area of the comparing unit 630 integrated in the semiconductor chip is larger than the area of the inverters 620 are connected. However, in other application embodiments, each two inverters may form pairs with a comparison unit to generate N-bit digital values.
In addition, a key module that generates a key in the form of a digital value by using the logic threshold difference of the inverter device of the semiconductor engineering variation can also be embodied by the structure shown in Fig. 7.
7 is a diagram illustrating a unit cell 700 of a key module that generates a digital value using engineering variation of a differential amplifier in accordance with one embodiment of the present invention.
[0134] The unit cell 700 is a differential amplifier circuit. A difference amplifier circuit unit lattice 700 composed of at least one of a transistor and a resistor that amplifies a voltage difference between the I-input terminal 711 and the second input terminal 712 as an I-output terminal 721 and a second output terminal 722 To provide a voltage difference.
Therefore, when the I-input terminal 711 and the second input terminal 712 are short-circuited, the voltage difference between the output voltage value Ith output terminal 721 and the second output terminal 722 should be O in theory.
However, since the semiconductor engineering deteriorates, there is a difference in electrical characteristics between the devices. Therefore, the voltage of the first output terminal 721 and the voltage of the second output terminal 722 can not be completely the same.
Therefore, in the embodiment of FIG. 6, by comparing the logic thresholds of the inverters in a similar manner, a digital value of I bits can be generated when the voltage of which of the two output terminals is higher.
When the voltage value of the I-output terminal 721 is higher than the voltage value of the second output terminal 722 when the I-input terminal 711 and the second input terminal 712 are short-circuited, for example, the digital value "I "And, in the opposite case, can be identified as the digital value" O "
Thus, when the differential amplifier unit crystal 700 is integrated with N, a key may be provided in the form of an N-bit digital value so that a key module according to some embodiments of the present invention can be embodied. This is illustrated in Figure 8.
8 is an exemplary circuit diagram illustrating a key module 800 embodied in accordance with one embodiment of the present invention.
In the illustrated embodiment, the key module 800 includes six differential amplifiers (811 to 816), a selection unit 820 for selecting any one of the six differential amplifiers, and a comparator 830 to compare the two output voltages of the differential amplifier selected by the selection unit 820 to generate a digital value of I bits.
In this case, the entire input terminals of the six differential amplifiers (811 to 816) are short-circuited with the same voltage.
[0143] In accordance with an embodiment of the present invention, the selection unit 820 may be a 6: 1 multiplexer (6: 1 MUX). However, it is merely an embodiment for embodying the present invention, and the present invention is not limited to this particular embodiment.
The number of input / output ports of the MUX device can be changed, and furthermore, the selecting unit 820 may be other devices than the MUX devices, and the 6: 1 MUX device converts the six differentials inputted through the twelve input terminals The output voltage of the amplifier is output to both output terminals. In addition, the two outputs are connected to the two inputs of the comparator 830. [
In the described embodiment, the key module 800 may generate a 6-bit digital value key.
An embodiment in which the key module is embodied by the engineering variation of the semiconductor engineering will be described with reference to FIGS. 4 to 8.
9 to 13, an embodiment in which the key module is embodied in violation of the semiconductor design specification will be described. Fig.
9 is a conceptual diagram for explaining the principle of generating a key module in violation of a semiconductor design specification according to an embodiment of the present invention.
In general, contacts or vias are designed to connect between conductive layers, and generally determine the size of the contacts or vias to short circuit the conductive layer. In addition, in conventional design rules (rule), a minimum number of contacts or vias are specified to ensure a short circuit between the conductive layers.
However, in the embodiment of the key module according to an embodiment of the present invention, the size of the contacts or vias is made smaller than specified in the design specification, so that a part of the contacts or paths short-circuit the conductive layers, and The other part of the contacts or vias do not short-circuit the conductive layers, which are probabilistically determined.
In the conventional semiconductor engineering, when a contact or a path can not short-circuit between the conductive layers, it is an engineering failure, but it can be used to generate a key having a random number.
9, it is shown that a path between the metal I layer 902 and the metal 2 layer 901 is formed during a semiconductor fabrication process.
In the group 910 having a large passage size in accordance with the design requirements, all the paths short-circuit the metal I layer 902 and the metal 2 layer 901, and the short circuit is represented by a digital value.
Further, in the group 930 having a small passage size, all of the vias do not short-circuit the metal I layer 902 and the metal 2 layer 901. [ Therefore, if the short circuit is represented by a digital value, it is I.
In the group 920 having the path size between the group 910 and the group 930, a part of the paths short-circuits the metal I layer 902 and the metal 2 layer 901, and the other part of the paths does not cause the metal I layer 902 and the metal 2 layer 901 is short-circuited.
According to one embodiment of the present invention, to realize the key module, as shown in the group 920, a part of the paths short-circuits the metal I-layer 902 and the metal-2 layer 901, and the other part of the paths is set in the path size, The metal I layer 902 and the metal 2 layer 901 are not short-circuited.
[0157] The design specifications for the vias are different depending on the semiconductor fabrication process. For example, in the embodiment of a key module according to one embodiment of the present invention, in the case of a Complementary Metal Oxide Semiconductor (CMOS) of 0.18 micrometers (um), when the design of the via is defined as 0.25 micrometers, Provides that the path size is set to 0.19 microns, so that the probability of short-circuit between the metal layer distribution.
Preferably, the probability distribution of the short circuit has a short circuit probability of 50%. In the embodiment of the key module according to an embodiment of the present invention, the probability distribution is set to a maximum of nearly 50% size. In this path size setting, the path size can be determined by engineering tests.
10 is a diagram for illustrating the structure of a key module that violates a semiconductor design specification, according to an embodiment of the present invention.
In the graph, the larger the path size, the short circuit probability between the metal layers may be close to I. According to the design of the channel size Sd, is to ensure that the metal layer between the short-circuit value.
In addition, Sm is a path size in which the short circuit probability of the metal layer is theoretically 0.5. As described above, the maximum similarity value can be obtained by experiment, but it is difficult to obtain accurate Sm.
Therefore, in the embodiment of the key module according to an embodiment of the present invention, the short circuit between the metal layers can be set within the range of Sxl and Sx2 with a certain allowable error in 0.5 according to the concrete test Although Sx1 and Sx2 are not shown in the drawings, the regions Sx1 and Sx2 may have a certain edge in the neighborhood of Sx.
In Figs. 9 to 10, although embodiments of the key module are described in violation of the design specifications for the size of the vias, other embodiments of the present invention may also be implemented by means other than the related conductive layer (Gap) between the design specifications to embody the key module.
11 is a conceptual diagram for explaining a process of adjusting a gap between conductive layers to generate a key module according to one embodiment of the present invention.
As described above, according to embodiments of the present invention, the spacing between the metal lines is adjusted so that the short circuit between the metal lines is probabilistically determined.
In the group 1110 which sufficiently shortens the short-circuiting between the metal lines and the metal line interval is small, the metal lines are short-circuited in all cases.
In addition, in the group 1130 where the metal line spacing is large, the metal lines are not short-circuited in all cases.
In the present embodiment, in order to realize the key module, as shown in the group 1120, a wire interval for forming a short circuit in a probability is set so that a part of the wire is short-circuited and a part is not short-circuited.
12 is a conceptual diagram illustrating an exemplary structure of a path or contact array formed in the semiconductor layer for embodying the key module 1200, according to one embodiment of the present invention.
(M and N are natural numbers) are formed between the metal layers to be laminated in the substrate [0? 7O], and a total of M * N paths are formed between the metal layers laminated on the semiconductor substrate.
The key module 1200 generates an M * N bit based on whether each of the M * N paths short-circuits (a digital value of 0) or does not short-circuit (a digital value of I) between the metal layers Key.
13 is a diagram for explaining a concept of a process for not using a numerical value generated in the embodiment of Fig. 12 as a key directly, for post-processing of the balance of O and I according to an embodiment of the present invention Fig.
In accordance with one embodiment of the present invention, the digital values of the M * N bits generated in the key module 1200 are aggregated into a predetermined number of k units, and k is a natural number.
Of course, the agglomeration shown in FIG. 13 is an illustrative drawing that is convenient to explain. In a practical embodiment, a method of aggregating transistors or flip-flops in the key module 1200 can be used.
Thus, the process of performing the balance of O and I by a method of clustering digital values may be performed by a person of ordinary skill in the art by various modifications and applications without departing from the scope of the present invention.
In the embodiment of FIG. 13, four numerical values are aggregated into one group.
The key module 1200 compares the sizes of the 4-bit digital values generated by the group 1310 and the group 1320, respectively. In addition, when the 4-bit numerical value of the group 1310 is greater than the 4-bit numeric value of the group 1320, the digital values representative of the group 1310 and the group 1320 are I.
In contrast, when the 4-bit numerical value of the group 1310 is smaller than the 4-bit numeric value of the group 1320, the digital values representing the group 1310 and the group 1320 are O. [
In other embodiments, the numerical values of the representative groups may be selected by comparing the number of numerical values I between the groups.
A method according to an embodiment of the present invention may be recorded in a computer-readable medium in the form of executable program commands by a variety of computer means. The computer-readable medium may include separate or combined program instructions, data files, data structures, and the like. The program instructions for the media recording may be specifically designed and created for the purposes of the present invention or may be applied to those skilled in the art of computer software. Examples of computer-readable media include magnet ic media such as hard disks, floppy disks and magnetic tape; optical media such as CD R0M, DVD; magneto-optical media such as optical disks Disk); and hardware devices that are specifically configured to store and execute program instructions, such as read only memory (R0M), random access memory (RAM), and the like. Examples of program instructions include both machine code, such as those produced by the compiler, and files containing higher-level code that can be executed by the computer using an interpreter. The hardware devices may be configured to operate as one or more software modules to perform the operations of the invention described above, and vice versa.
As described above, the present invention has been described with reference to a limited number of embodiments and drawings, but the present invention is not limited to the described embodiments, and any person having ordinary knowledge in the field of the present invention may, Various modifications and variations are made.
Accordingly, the scope of the present invention is not to be limited by the embodiments described or defined, but is defined by the appended claims and the scope of equivalents of the claims.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN101089998A | Cites | China | Search report |
| CN1777097A | Cites | China | Search report |
| US2006131575A1 | Cites | United States of America | Search report |
| US2008044010A1 | Cites | United States of America | Search report |
| US2009080647A1 | Cites | United States of America | Search report |
| US2010031065A1 | Cites | United States of America | Search report |
| JP2011010218A | Cites | Japan | Search report |
| US5559889A | Cites | United States of America | Search report |
| JPH10116326A | Cites | Japan | Search report |
7 priority claims, no other members on record
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020110013269 | Republic of Korea | – | |
| 20110013269 | Republic of Korea | A | |
| 201180070008 | China | A | |
| 1020110013269 | – | – | – |
| 201180070008X | – | – | – |
| CN2011870008 | – | – | – |
| KR20110013269 | – | – | – |
Numbers
- Publication
- 106295408
- Publication, DOCDB
- 106295408
- Publication, EPODOC
- CN106295408
- Application
- 2016106216935
- Application, DOCDB
- 201610621693
- Application, EPODOC
- CN201610621693
Titles2
- Chinese
- 集成电路及加密方法
- English
- Integrated circuit and encryption method
Classification
- CPC, 6
- G06F21/72
- H04L9/0816
- H04L9/002
- H04L2209/12
- H04L9/14
- H04L2209/24
- IPC, 2
- G06F21 72
- H04L9 00