Encryption device and method for defending a physical attack
Abstract
An integrated circuit is provided, including: a key module for generating a key. An encryption method is also provided, including: generating a key; and using the key to execute an encryption algorithm.

Term
4.4 yearsleft in the term
Expires 28 February 2031.
- Priority
- Filed
- Granted
- Today
- Expires
10 claims: 2 independent, 8 dependent
- 1一种集成电路,包括: 密钥模块,用于生成密钥;以及 加密模块,用于使用该密钥来执行加密算法,所述加密模块包括多个所述密钥模块,所 述多个密钥模块分散设置于多个标准单元布局中的任意位置处,所述多个标准单元被包括 在所述加密模块内。
- 2如权利要求1所述的集成电路,其中所述多个密钥模块与其他标准单元相似地分散 设置。
- 3如权利要求1所述的集成电路,其中该密钥模块包括节点和根据节点之间是否短路 生成密钥。
- 4如权利要求1所述的集成电路,其中,该密钥模块包括多个单元结构,每个单元结构 根据半导体制备工程变化来生成1比特的数字值。
- 5如权利要求1所述的集成电路,其中,该密钥模块包括多个差分放大器, 其中第一差分放大器的两个输入端短路时,根据半导体制备工程变化该第一差分放大 器的两个输出端的逻辑电平互不相同,该密钥模块根据两个输出端的逻辑电平生成对应于 第一差分放大器的1比特的数字值。
- 6一种加密的方法,包括: 将多个密钥模块分散设置于多个标准单元布局中的任意位置处,所述多个标准单元被 包括在所述加密模块内; 生成密钥;以及 使用该密钥执行加密算法。
- 7如权利要求6所述的方法,其中,加密模块使用该密钥执行加密算法,该方法还包括: 防止密钥从加密模块泄露;以及 防止额外的密钥流入加密模块。
- 8如权利要求6所述的方法,其中,根据半导体的导电层之间是否产生短路来生成该密 钥。
- 9如权利要求6所述的方法,其中,生成密钥包括根据半导体制备工程变化由多个单元 结构的每个单元结构生成1比特的数字值。
- 10如权利要求6所述的方法,其中,生成密钥包括根据差分放大器的两个输出端的逻 辑电平生成对应于该差分放大器的1比特的数字值, 其中当差分放大器的两个输入端短路时,根据半导体制备工程变化该差分放大器的两 个输出端的逻辑电平互不相同。
Independent claims10
194 paragraphs, as filed
Technical field of integrated circuits and encryption methods
[0001] The present invention relates to the field of digital security, and in particular, to an encryption device and method for managing keys to prevent physical attacks in IC security modules such as smart cards.
technical background
[0002] As a plastic card the size of a credit card, a smart card includes an integrated circuit (IC) that can process data. Compared with the existing magnetic card, the smart card has many advantages. It has a data storage capacity and has a processing unit such as a co-processor together with a microprocessor.
[0003] Therefore, in order to obtain personal information and financial settlement information for identification (Identification), encryption algorithms are used to automatically perform encryption.
[0004] In addition, with the development of various IT technologies, smart cards are widely used, and at the same time, various security violations of smart cards are increasing.
[0005] In this case, a physical attack similar to using the reverse engineering technology of the IC chip to read the information of the IC chip has a big problem in security.
[0006] According to the storage characteristics and data storage methods of the EEPROM and ROM used in the hardware security module, several known physical attacks are bus probing and test mode detection. Attack methods such as test-mode probing, read-only memory ROM or electronically erasable read-only memory EEPROM (overwriting).
Summary of the invention
[0007] Technical issues
[0008] An encryption device and method are provided, which can strongly prevent physical attacks on smart cards.
[0009] In particular, an encryption device and method are provided that do not directly extract the generated or stored key from the memory. In addition, an encryption device and method that will not be leaked through the bus in the IC chip of the smart card is provided.
[0010] Technical Solution
[0011] According to one aspect of the present invention, there is provided an encryption device that receives input data to be encrypted and executes an encryption algorithm using a key. The encryption device includes: an encryption module, and a key module that provides the key is included in Internally, the encryption algorithm is executed using the key provided by the key module.
[0012] The encryption modules are respectively contained in a plurality of key modules for providing different keys. In this case, the encryption module may include: a key module selection unit to select any one of the plurality of key modules; and an encryption unit to use the key provided by the selected key module to Execute the encryption algorithm.
[0013] In addition, the key module selection unit selects the key module corresponding to the identification index attached in advance among the plurality of key modules.
[0014] According to an embodiment of the present invention, the encryption module includes a plurality of standard units, and the plurality of key modules are configured in any position in the layout of the plurality of standard units included in the encryption module. The standard unit may be a normalized element or functional block used to embody the encryption module.
[0015] The integrated circuit as described above, wherein the encryption module uses the key provided by the key module contained in the encryption module to execute the encryption algorithm, and the key module is The provided key is not leaked to the outside of the encryption module, and in order to execute the encryption algorithm, other additional keys are not leaked to the encryption module.
[0016] According to an embodiment of the present invention, the key module is a non-volatile storage module that stores the key generated in advance.
[0017] According to another embodiment of the present invention, the key module is a non-storage module that generates and provides the key.
[0018] In this case, the key module, in violation of the design regulations provided in the semiconductor engineering, probabilistically determines whether there is a short circuit between the nodes in the key module, and the key module, The key can be generated and provided according to the result of reading whether there is a short circuit between the nodes.
[0019] Here, the node in the key module is a conductive layer of a semiconductor, and the design stipulation is related to the size of the contact or path formed between the conductive layer of the semiconductor, and the key The module uses the contacts or paths formed between the conductive layers of the semiconductor to cause the conductive layer to short-circuit or not to generate the key.
[0020] In addition, the key module, in violation of the design regulations provided in the semiconductor engineering, causes the contact or via formed between the conductive layers of the semiconductor to cause the conductive layer to be short-circuited. The difference in the probability of no short circuit is kept within a certain error range, and has the size of the contact or via.
[0021] According to an embodiment of the present invention, the key module has N unit structures that generate a 1-bit digital value by using a pair of conductive layers and a contact or path connected between them, and pass all The N-bit digital value generated by the N unit structure is generated as the key, where N is a natural number.
[0022] In this case, the key module groups the generated N-bit digital value in k units, and compares the first group and the second group among the grouped groups, When the value formed by the k digital bits contained in the first group is greater than the value formed by the k digital bits contained in the second group, it will represent the values of the first group and the second group. When the digital value is determined to be 1, and on the contrary, the digital value representing the first group and the second group is determined to be 0, so that a digital value of N/k bits is generated as the key, where k is Natural number.
[0023] According to another embodiment of the present invention, the node in the key module is a conductive layer of a semiconductor, and the design specification is related to the gap between the conductive layers of the semiconductor, and The key module utilizes the short circuit between the conductive layers of the semiconductor to generate and provide the key.
[0024] According to yet another embodiment of the present invention, the key module includes: N unit lattices, each outputting a 1-bit digital value, N is a natural number, and the N unit lattices, The 1-bit digital value is generated based on the semiconductor manufacturing process variation (Process variation) respectively, so that the key module generates and provides an N-bit key.
[0025] In this case, the first unit cell of the N unit cells includes: a first inverter with a first logic threshold; and a second inverter with a second logic threshold, And the input terminal of the first inverter and the output terminal of the second inverter are connected to the first node, and the output terminal of the first inverter and the input terminal of the second inverter It is connected to the second node to form a feedback structure, and the first logic threshold and the second logic threshold are different from each other based on the semiconductor manufacturing process variation, according to the logic level of the first node and the second node To determine the 1-bit digital value corresponding to the first unit cell.
[0026] In addition, according to yet another embodiment of the present invention, the key module includes: N differential amplifiers, N is a natural number, and the first differential amplifier in the N differential amplifiers is When the two input terminals of the first differential amplifier are short-circuited, the logic levels of the two output terminals of the first differential amplifier are different from each other based on the variation of the semiconductor manufacturing process
At the same time, the 1-bit digital value corresponding to the first differential amplifier is determined according to the logic levels of the two output terminals, and the key module generates and provides an N-bit key.
[0027] According to another aspect of the present invention, an encryption method is provided, including the steps of: receiving data to be encrypted, and inputting it into an encryption module containing a key module that provides a key; and using the key The key provided by the module is used to execute the encryption algorithm to encrypt the data.
[0028] According to yet another aspect of the present invention, there is provided an IC chip that receives input data to be encrypted and executes an encryption algorithm using a key. The IC chip includes: an encryption module that contains a key The key module uses the key provided by the key module to execute the encryption algorithm.
[0029] In this case, the IC chip is embedded in a smart card, and the encryption algorithm can be executed when the smart card is applied.
[0030] Technical Effect
[0031] Since the key is not generated outside the encryption module to be stored in the memory or transmitted through the bus, it is safe to attack non-volatile memory or physical attacks such as bus probing.
[0032] Since the key module is distributed within the module similarly to other standard cells, it is difficult to directly find that it is safe to extract the memory content through a physical attack.
[0033] Since there is no need for a non-volatile memory to store the key, the usage of space and power can be improved.
Description of the drawings
[0034] FIG. 1 is a diagram showing an encryption device according to an embodiment of the present invention.
[0035] FIG. 2 is a diagram illustrating an encryption module according to an embodiment of the present invention.
[0036] FIG. 3 is a block diagram showing an exemplary structure of an encryption module according to an embodiment of the present invention.
[0037] FIG. 4 is an exemplary illustration for explaining the concept of a unit lattice of a key module in the form of a physical unclonable function PUF (Physical Unclonable Functions) that uses engineering variation to generate a key according to an embodiment of the present invention Circuit diagram.
[0038] FIG. 5 is a reference chart for understanding the embodiment of FIG. 4.
[0039] FIG. 6 is a block diagram showing an exemplary embodiment of a key module according to an embodiment of the present invention.
[0040] FIG. 7 is a diagram illustrating a unit lattice of a key module that uses engineering variation of a differential amplifier to generate a digital value according to an embodiment of the present invention.
[0041] FIG. 8 is an exemplary circuit diagram in which a key module is embodied according to an embodiment of the present invention.
[0042] FIG. 9 is a conceptual diagram for explaining the principle of generating a key module in violation of semiconductor design regulations according to an embodiment of the present invention.
[0043] FIG. 10 is a diagram illustrating the structure of a key module that violates semiconductor design regulations according to an embodiment of the present invention.
[0044] FIG. 11 is a conceptual diagram for explaining a process of adjusting the interval between conductive layers to generate a key module according to an embodiment of the present invention.
[0045] FIG. 12 is a conceptual diagram showing an exemplary structure for embodying a via or a contact array formed in a semiconductor layer of a key module according to an embodiment of the present invention.
[0046] FIG. 13 is an embodiment of the present invention for explaining that the digital value generated in the embodiment of FIG. 12 is not directly used as a key, but is post-processed for the balance of 0 and 1. Conceptual diagram of the process.
Detailed ways
[0047] Hereinafter, some embodiments of the present invention will be described in detail with reference to the drawings. However, the present invention is not limited or limited by the embodiments, and the same symbols shown in the drawings represent the same components.
[0048] FIG. 1 is a diagram showing an encryption device 100 according to an embodiment of the present invention.
[0049] According to an example, the encryption device 100 may be a structure included in an IC chip of a smart card, having an electrically erasable read-only memory (EEPROM) 120 for storing data, a central processing unit (CPU) 130, and optional synchronization A dynamic random access memory (SDRAM) 140 can communicate with the outside through the I/O interface 101.
[0050] The encryption device 100 includes an encryption module 110, for example, the encryption module 110 may be a co-processor (Crypto co-processor) for encryption.
[0051] In the following, according to an application example of the encryption device 100 including a smart card or an IC chip of a smart card, an electrically erasable read-only memory (EEPROM) 120, a central processing unit (CPU) 130, and an optional synchronous dynamic random access memory (SDRAM) At least a part of) 140 can be omitted, and various changes or applications can be made without departing from the scope of the present invention, which will not be described in detail here.
[0052] In addition, regardless of the contact type and/or non-contact type, the I/O interface 101 is an input and output line for data output and input of the encryption device 100, which will not be described in detail here.
[0053] In addition, the encryption module 110 of the encryption device 100 according to an embodiment of the present invention may use a key in the process of executing an encryption algorithm. The key can be a concept such as a public key and a secret key.
[0054] In the prior art, the key used to execute the encryption algorithm is stored outside the encryption module 110 in the form of a digital value, so that the encryption module 110 executes the encryption algorithm and passes through the bus in the process of encrypting and/or decoding data. 102 to receive the key.
[0055] However, this method is relatively vulnerable in physical attacks intended to identify encryption algorithms and/or keys.
[0056] The physical attack can directly attack an area with a key in a memory such as an electronically erasable read-only memory (EEPROM) 120, and extract the key in the memory by a method similar to probing or memory scanning. In addition, since reverse engineering can be performed to obtain the position of the bus 102 in the IC chip, the specific command language is artificially executed, and in this case, bus probing using micro-probes is executed. ), then the key can be extracted.
[0057] According to an embodiment of the present invention, the key module 111 included in the encryption module 110 stores the directly generated and/or pre-generated key in the key module 111 for a period of time, and then performs the encryption in the encryption module 110. The key is provided when the algorithm is used.
[0058] Therefore, according to the above-mentioned embodiment, the encryption module 110 does not store the used key in the form of a digital value outside the encryption module 110 in the process of executing the encryption algorithm, and the key will not be transferred through the bus 102. Therefore, physical attacks on the encryption algorithm of the encryption module 110 can be prevented.
[0059] The key module 111 that generates and/or stores a key so as to be provided when the encryption algorithm of the encryption module 110 is executed, which can be physically included in the encryption module 110, and some exemplary implementations of its structure and operation Examples will be described with reference to FIG. 2.
[0060] FIG. 2 is a diagram illustrating an encryption module 110 according to an embodiment of the present invention.
[0061] As shown in FIG. 1, the encryption module 110 in the encryption device 100 may be connected to the bus 102 through other structures.
[0062] According to an embodiment of the present invention, the encryption module 110 includes at least one key module 210, 220,
230、240、250。
[0063] As shown in the diagram of the example, the key modules 210, 220, 230, 240, and 250 are independent of each other or related to each other, generate and/or store the keys required to execute the encryption algorithm, and provide them to the encryption module 110 .
[0064] In some embodiments, the encryption module 110 may include only one key module, but in other embodiments, as shown in FIG. 2, it includes multiple key modules.
[0065] In addition, when the encryption module 110 includes multiple key modules, the multiple key modules 210, 220, 230, 240,
At least a part of 250 may be a dummy that does not actually provide a key.
[0066] In the embodiment embodying the key modules 210, 220, 230, 240, 250, the key modules 210, 220, 230, 240,
250 can be a memory device and a non-memory device.
[0067] Of course, a part of the key modules 210, 220, 230, 240, 250 may also be a storage device, and the other part may be a non-storage device, and the present invention is not limited to this part of the embodiments.
[0068] Illustratively, in an embodiment where the key modules 210, 220, 230, 240, and 250 are storage devices, the pre-generated key in the form of a digital value is simply stored in the key module 210 as the storage device. , 220, 230, 240, 250 after a period of time, the encryption module 110 performs the encryption algorithm when needed to read (read) and use.
[0069] In other embodiments, when the key modules 210, 220, 230, 240, and 250 are non-storage devices, at least a part of the key modules 210, 220, 230, 240, and 250 can pass the physical anti-cloning function PUF (Physical Unclonable Functions).
[0070] In the embodiments in which the key modules 210, 220, 230, 240, and 250 are composed of non-storage devices similar to PUF, the embodiments embodying the PUF have many ways, for example, it may violate the design regulations on semiconductor manufacturing engineering Or use the engineering variation of semiconductor manufacturing engineering to realize it.
[0071] This embodiment will be described in more detail with reference to FIGS. 4 to 13.
[0072] FIG. 3 is a block diagram showing an exemplary structure of an encryption module 110 according to an embodiment of the present invention.
[0073] When the encrypted data can be input to the data input unit 310 through the bus 102 or the like, the encryption algorithm starts to be executed.
[0074] Referring to FIG. 2, as described above, the key module 320 physically contained in the encryption module 110 may be one or more.
[0075] For example, when the key module 01 321 to the key module N322 exist, the key module selection unit 330 selects the key module for providing the key to be used in the encryption algorithm, where N is a natural number.
[0076] The selection may be the index information used to identify the key module actually selected in the index of the key module 320, or the key module 320 and the encryption module 110 are designed together and can be prepared in In the process, it is preset through wiring.
[0077] After the key is set through this process, the encryption unit 340 uses the key to execute an encryption algorithm, thereby encrypting the input data, and transmits it to other structures through the bus 102 via the data output unit 350.
[0078] Although only the data encryption process has been described in detail above, the decoding process using the encryption algorithm is similar to this. The embodiments of the present invention are not limited to either encryption or decoding.
[0079] Therefore, the key management is automatically formed in the encryption module 110, therefore, the key will not be transmitted to the outside of the encryption module 110, or from the outside to the encryption module 110, so that the physical attack is successful. The possibility is low. In particular, the probability of a successful physical attack on the detection bus 102 is very low.
[0080] The above description of the case where the key module is a storage device is described with reference to FIGS. 1 to 2. Hereinafter, with reference to FIGS. 4 to 13, an embodiment in which the key module is embodied by a PUF of a non-storage device will be described.
[0081] For reference, the PUF mentioned in the present invention cannot perform physical copying. After a one-time preparation, a key that does not change at least theoretically is generated.
[0082] Hereinafter, various embodiments in which the key module is embodied by the PUF of a non-storage device will be described. FIGS. 4 to 8 correspond to the use of engineering variation in the semiconductor process to generate a key. An example of a key module.
[0083] In addition, FIGS. 9 to 13 correspond to an embodiment in which a key module is generated in violation of design regulations when designing a circuit.
[0084] FIG. 4 is an exemplary circuit diagram for explaining the concept of a unit lattice of a key module in the form of a physical anti-cloning function PUF that uses engineering variation to generate a key according to an embodiment of the present invention.
[0085] In the embodiment of FIG. 4, a first inverter 410 and a second inverter 420 are shown.
[0086] In semiconductor engineering, engineering deterioration occurs for many reasons. For example, when manufacturing transistors, parameters such as effective gate length, semiconductor dopant density-related index, oxide layer thickness-related index, or threshold voltage may all become the cause of engineering deterioration.
[0087] In general, it is considered that the engineering deterioration of a smaller semiconductor manufacturing process is better. However, in terms of physical characteristics, the engineering deterioration can be minimized as much as possible, but it is impossible to completely eliminate it.
[0088] In this embodiment, the first inverter 410 may have a first logic threshold, and the second inverter 420 may have a second logic threshold. The logic threshold is the voltage value when the input voltage and the output voltage of the inverter have the same value, which will be described below with reference to FIG. 5.
[0089] The logic threshold of the inverter can be detected as a voltage value when the output terminal and the input terminal of the inverter in operation are shorted.
[0090] Inverters prepared in the same project are theoretically designed to have the same logical threshold. However, as described above, due to the engineering deterioration in the actual manufacturing project, any two inverse It is impossible for the transformers to have exactly the same logic threshold.
[0091] According to an embodiment of the present invention, the first inverter 410 and the second inverter 420 are prepared in the same manufacturing process, and therefore have a difference in logic thresholds due to engineering deterioration. .
[0092] Although the difference in the logic threshold value varies according to engineering projects, it may differ by a few millivolts to tens of millivolts. Therefore, due to detection errors, it is not accurate to use another comparator circuit to detect the logic threshold of the first inverter 410 and the logic threshold of the second inverter 420.
[0093] Therefore, there is a need for a method that can relatively compare the logic thresholds of two inverters (that is, without using another comparator circuit for detection). In some embodiments of the present invention, the logical thresholds between the two inverters are compared relatively (without using another comparator circuit but automatically), so that it can be judged which one has a larger logical threshold.
[0094] Assuming that the second inverter 420 does not exist, when the input terminal and the output terminal of the first inverter 410 are short-circuited, the output voltage of the first inverter 410 is equal to the logic threshold of the first inverter 410 the same.
[0095] In addition, assuming that the first inverter 410 does not exist, when the input terminal and the output terminal of the second inverter 420 are short-circuited, the output voltage of the second inverter 420 is the same as that of the second inverter 420. The logic threshold is the same.
[0096] However, as shown in FIG. 4, when the input terminal of the first inverter 410 and the output terminal of the second inverter 420 are short-circuited and are connected through the first node, the output of the first inverter 410 When the terminal and the input terminal of the second inverter 420 are short-circuited and connected via the second node, the result is different from the above.
[0097] When the first node and the second node are short-circuited by the switch 430, the voltage values of the two short-circuited nodes are the logical threshold value of the first inverter 410 and the second inverse The intermediate value (may be flat) of the logic threshold of the converter 420
Below average).
[0098] Regardless of which of the logic thresholds of the two inverters has a higher value, during the period when the switch 430 is off, the value of the output voltage is the middle value of the logic thresholds of the two inverters.
[0099] In addition, after the switch 430 is opened, when the first node and the second node are opened (open), the logic voltage of the voltage value of any one of the first node and the second node is The logical level is "0", and the logic level of the other is "1".
[0100] For example, suppose that when the logic threshold of the first inverter 410 is lower than the logic threshold of the second inverter 420, the switch 430 is closed, and the first node (the opposite node of output Out) and the second The voltage of the first node during the period when the second node (output Out node) is short-circuited is higher than the logic threshold of the first inverter 410.
[0101] Therefore, the switch 430 is reopened, and after the first node and the second node are opened, the first inverter 410 recognizes (its own input terminal) the voltage of the first node as high (High). ) Logic level. Therefore, the voltage of the second node at the output end of the first inverter 210 is a Low logic level.
[0102] In this case, the second inverter 420 recognizes the voltage of the second node (its input terminal) as a low logic level. Therefore, the voltage of the first node of the output terminal of the second inverter 420 It is a high logic level.
[0103] As a result, the voltage at the second node of the output terminal (Out) of FIG. 4 is a high logic level.
[0104] Conversely, assuming that the logic threshold of the first inverter 410 is higher than the logic threshold of the second inverter 420, the switch 430 is closed, and the first node and the second node are short-circuited. The voltage of is lower than the logic threshold of the first inverter 410.
[0105] Therefore, the switch 430 is reopened, and after the first node and the second node are opened, the first inverter 410 recognizes (its own input terminal) the voltage of the first node as a low logic voltage. Therefore, the voltage of the second node at the output end of the first inverter 410 is at a high logic level.
[0106] In this case, the second inverter 420 recognizes the voltage of the second node (its own input terminal) as a high logic level. Therefore, the voltage of the first node of the output terminal of the second inverter 420 It is a low logic level.
[0107] As a result, the voltage at the second node of the output terminal (Out) in FIG. 4 is a low logic level.
[0108] As described above, according to which of the logic threshold of the first inverter 410 and the logic threshold of the second inverter 420 is higher, the logic of the output terminal (Out) after the short-circuit of the switch 430 is determined Is the level high (or "1") or low (or "0").
[0109] However, in the first inverter 410 and the second inverter 420 prepared in the same manufacturing process, which one has the higher logic threshold is random, and probabilistically two The probability that the logic threshold of one of the inverters is higher than the logic threshold of the other is about 50%.
[0110] In addition, after preparation, it is more difficult to change which side the higher logical threshold is.
[0111] As a result, through the embodiment of FIG. 4, a 1-bit digital value can be generated (although the probability of being "1" or "0" is the same, it is difficult to change once it is determined).
[0112] When referring to FIG. 5, the above process will be more clearly understood.
[0113] FIG. 5 is a reference chart for understanding the embodiment of FIG. 4.
[0114] In this exemplary reference graph, the voltage characteristic when the logic threshold of the first inverter 410 of FIG. 4 is lower than the logic threshold of the second inverter 420 is shown.
[0115] The curve 510 is the voltage characteristic curve of the first inverter 410, and the curve 520 is the voltage characteristic curve of the second inverter 420. According to an embodiment of the present invention, when the first inverter 410 and the second inverter 420 are in the same manufacturing process
When being prepared, although the curve 510 and the curve 520 are basically the same, there is a little difference due to engineering deterioration.
[0116] When the intersection of the curve 510 and the inclined straight line 530 is found, the logical threshold V1 of the first inverter 410 can be determined. In addition, when the intersection of the curve 520 and the straight line 530 is found, the logical threshold V2 of the second inverter 420 can be determined.
[0117] In this embodiment, V1 is lower than V2. Therefore, the switch 430 in FIG. 4 is closed. When the first node and the second node are short-circuited (also called "Reset"), the first node and the second node The voltage (VReset) is any value between V1 and V2.
[0118] In addition, the switch 430 is reopened, and after the first node and the second node are opened, the first inverter 410 recognizes the voltage of the first node (VReset) as a high logic level, so , The voltage of the second node at the output end of the first inverter 410 is a low logic level.
[0119] In this case, the second inverter 420 recognizes the voltage of the second node (VReset) as a low logic level. Therefore, the voltage of the first node at the output end of the second inverter 420 is a high logic level. Level.
[0120] Therefore, the voltage at the second node of the output terminal (Out) of FIG. 4 is a high logic level.
[0121] As shown in FIG. 4, when the unit lattice is a 1-bit digital value, when the unit lattice is integrated into N units, the N-bit digital value can generate a key.
[0122] According to some embodiments of the present invention, the key module 320 may be embodied in this manner.
[0123] The key module can be embodied as the structure shown in FIG. 6 below, and generates a key in the form of a digital value by using the difference in the logic threshold of the inverter device whose semiconductor engineering has deteriorated.
[0124] FIG. 6 is a block diagram showing an exemplary embodiment of a key module 600 according to an embodiment of the present invention.
[0125] In this embodiment, the key module 600 includes: five inverters from the inverter 611 to the inverter 615, a selection unit 620, and a comparison unit 630.
[0126] The selection unit 620 may select any two of the five inverters shown in FIG. 6, for example, the inverter 612 and the inverter 613 may be selected.
[0127] In this case, the comparison unit 630 compares the logic threshold of the inverter 612 and the logic threshold of the inverter 613, and provides an output voltage to the output (Out) terminal according to the comparison result. In addition, a 1-bit digital value can be generated according to the logic level of the output voltage of the output (Out) terminal.
[0128] In addition, when the selection unit 620 selects another two inverters, the comparison unit 630 may regenerate a 1-bit digital value.
[0129] As described above, the selection unit 620 can select two of the five inverters (611 to 615), and when the comparison unit 630 compares the logic thresholds of the two selected inverters to generate a digital value , Can get up to 10 bits of digital value.
[0130] In this embodiment, although five inverters are included, the present invention is not limited to the number of bits of the digital value generated by the gate, the area of the circuit, etc., can be changed in various ways.
[0131] In addition, when the area of the comparison unit 630 that can be integrated in the semiconductor chip is larger than the area of the inverters (611 to 615), in this embodiment, a plurality of inverters and one comparison unit 630 pass through the selection unit 620 is connected. However, in other application embodiments, every two inverters can form a pair with one comparison unit to generate an N-bit digital value.
[0132] In addition, a key module that generates a key in the form of a digital value by using a difference in the logic threshold of an inverter device whose semiconductor engineering has deteriorated may also be embodied by the structure shown in FIG. 7.
[0133] FIG. 7 is a diagram illustrating a unit lattice 700 of a key module that uses engineering variation of a differential amplifier to generate a digital value according to an embodiment of the present invention.
[0134] The unit cell 700 is a differential amplifier circuit. A differential amplifier circuit unit cell 700 composed of at least one of a transistor and a resistor expands the voltage difference between the first input terminal 711 and the second input terminal 712 as the first output
The voltage difference between the terminal 721 and the second output terminal 722 is provided.
[0135] Therefore, when the first input terminal 711 and the second input terminal 712 are short-circuited, theoretically, the output voltage value of the voltage difference between the first output terminal 721 and the second output terminal 722 should be zero.
[0136] However, due to the deterioration of semiconductor engineering and the differences in electrical characteristics between devices, the voltage of the first output terminal 721 and the voltage of the second output terminal 722 may not be exactly the same.
[0137] Therefore, in the embodiment of FIG. 6, a 1-bit digital value can be generated when comparing which of the two output terminals has a higher voltage through a method similar to comparing the logic thresholds of the inverters.
[0138] For example, in the case of short-circuiting the first input terminal 711 and the second input terminal 712, when the voltage value of the first output terminal 721 is higher than the voltage value of the second output terminal 722, it is recognized as a digital value "1". ", and in the opposite case, it can be recognized as a digital value "0"
[0139] Therefore, when the differential amplifier unit crystal 700 is integrated with N pieces, the key can be provided in the form of a digital value of N bits, so that the key module according to some embodiments of the present invention can be embodied. This embodiment is shown in FIG. 8.
[0140] FIG. 8 is an exemplary circuit diagram in which the key module 800 is embodied according to an embodiment of the present invention.
[0141] In the illustrated embodiment, the key module 800 includes: 6 differential amplifiers (811 to 816); a selection unit 820 for selecting any one of the 6 differential amplifiers; and a comparator 830, The two output voltages of the differential amplifier selected by the selection unit 820 are compared to generate a 1-bit digital value.
[0142] In this case, the entire input terminals of the six differential amplifiers (811 to 816) are short-circuited and have the same voltage.
[0143] According to an embodiment of the present invention, the selection unit 820 may be a 6:1 multiplexer (6:1 MUX). However, it is only an embodiment for embodying the present invention, and the present invention is not limited to this specific embodiment.
[0144] Therefore, the number of input/output ports of the MUX device can be changed. Further, the selection unit 820 may be another device instead of the MUX device, and the 6:1 MUX device will input 6 differential amplifiers through 12 input terminals. The output voltage is output to two output terminals. In addition, the two output terminals are connected to the two input terminals of the comparator 830.
[0145] In the described embodiment, the key module 800 can generate a 6-bit digital value key.
[0146] Above, with reference to FIG. 4 to FIG. 8, an embodiment in which the key module is embodied by the engineering variation of the semiconductor engineering is described.
[0147] Hereinafter, with reference to FIGS. 9-13, in violation of the design requirements of the semiconductor body so as to now a key module according to embodiments will be described.
[0148] FIG. 9 is a conceptual diagram for explaining the principle of generating a key module in violation of semiconductor design regulations according to an embodiment of the present invention.
[0149] Generally, contacts or vias are designed to connect between conductive layers. Generally, the size of the contacts or vias is determined to short-circuit the conductive layers. In addition, in a conventional design rule, a minimum contact or via size is specified to ensure a short circuit between the conductive layers.
[0150] However, in the embodiment of the key module according to an embodiment of the present invention, the size of the contact or the path is made smaller than specified in the design regulations, so that a part of the contact or the path short-circuits between the conductive layers, and The other part of the contacts or paths will not short-circuit between the conductive layers, and the conductivity is determined probabilistically.
[0151] In the existing semiconductor engineering, when the contacts or vias cannot short-circuit the conductive layers, it is an engineering failure, but it can be used to generate a key with a random number.
[0152] Referring to FIG. 9, it is shown that in the semiconductor manufacturing process, a via is formed between the metal 1 layer 902 and the metal 2 layer 901.
[0153] In the group 910 in which the via size is made larger according to the design regulations, all vias short-circuit the metal 1 layer 902 and the metal 2 layer 901, and when the short circuit is expressed as a digital value, it is all 0.
[0154] In addition, in the group 930 with a smaller via size, all vias did not short-circuit the metal 1 layer 902 and the metal 2 layer 901. Therefore, when the short-circuit or not is expressed as a digital value, it is all 1.
[0155] In addition, in the group 920 whose via size is between the group 910 and the group 930, a part of the vias short-circuit the metal 1 layer 902 and the metal 2 layer 901, and the other part of the vias do not short the metal 1 layer 902 and the metal 2 layer. 901 short circuit.
[0156] According to an embodiment of the present invention, in order to realize the key module, as shown in group 920, a part of the via short-circuits the metal 1 layer 902 and the metal 2 layer 901, and the other part of the via is formed by setting the size of the via, thereby The metal 1 layer 902 and the metal 2 layer 901 will not be short-circuited.
[0157] The design regulations on the size of the vias vary according to the semiconductor manufacturing process. For example, in a 0.18 micron (um) complementary metal oxide semiconductor CMOS (Complementary metal oxide semiconductor), when the design of the via is specified as 0.25 micron, in the embodiment of the key module according to an embodiment of the present invention, the design is violated It is stipulated that the size of the via is set to 0.19 microns, so that the short circuit between the metal layers is probabilistically distributed.
[0158] Preferably, the probability distribution of the short-circuit or not has a short-circuit probability of 50%. In the embodiment of the key module according to an embodiment of the present invention, the probability distribution is set as close to 50% as possible to form a path. size. In this channel size setting, the channel size can be determined through engineering tests.
[0159] FIG. 10 is a diagram illustrating the structure of a key module that violates semiconductor design regulations according to an embodiment of the present invention.
[0160] In the graph, the larger the via size, the probability of a short circuit between the metal layers can be close to 1. The via size Sd specified by the design is a value sufficient to ensure a short circuit between the metal layers.
[0161] In addition, Sm is theoretically a via size with a short-circuit probability of 0.5 for the metal layer. As described above, depending on the engineering, when the value is different, the maximum similar value can be obtained through experiments, but it is difficult to obtain an accurate Sm.
[0162] Therefore, in the embodiment of the key module according to an embodiment of the present invention, according to specific experiments, whether the short circuit between the metal layers can be set within the range of Sx1 and Sx2 with a certain allowable error in 0.5 (Although the Sx 1 and Sx 2 are not shown separately, they may be regions with a certain edge near Sx as shown).
[0163] In FIGS. 9 to 10, although the embodiment in which the key module is embodied in violation of the design regulations related to the path size is described, according to some other embodiments of the present invention, it can also be implemented by violating the related conductive layer. The gap is designed to reflect the key module.
[0164] FIG. 11 is a conceptual diagram for explaining a process of adjusting the interval between conductive layers to generate a key module according to an embodiment of the present invention.
[0165] As described above, according to the embodiment of the present invention, the interval between the metal lines is adjusted so as to probabilistically determine whether there is a short circuit between the metal lines.
[0166] In order to sufficiently ensure a short circuit between the metal lines, in the group 1110 in which the metal line interval is small, the metal lines are short-circuited in all cases.
[0167] In addition, in the group 1130 with a large metal line interval, the metal lines were not short-circuited in all cases.
[0168] In this embodiment, in order to realize the key module, as shown in group 1120, a metal line interval for probabilistically forming a short circuit is set, so that a part of the metal line is short-circuited and a part is not short-circuited.
[0169] FIG. 12 is a conceptual diagram illustrating an exemplary structure for embodying a via or a contact array formed in the semiconductor layer of the key module 1200 according to an embodiment of the present invention.
[0170] In the semiconductor substrate (substrate), M in the horizontal direction and N in the vertical direction are formed between the laminated metal layers (but M and N are natural numbers), a total of M*N vias.
[0171] The key module 1200 generates M*N bits according to whether the M*N paths each short-circuit between the metal layers (digital value 0) or not short-circuit (digital value 1). Key.
[0172] FIG. 13 is an embodiment of the present invention for explaining the concept of a process of post-processing for the balance of 0 and 1 without directly using the digital value generated in the embodiment of FIG. 12 as a key. Figure.
[0173] According to an embodiment of the present invention, the digital values of M*N bits generated in the key module 1200 are aggregated into predetermined k units, and k is a natural number.
[0174] Of course, the cluster shown in FIG. 13 is an exemplary drawing for ease of description. In an actual embodiment, a method of clustering transistors or flip-flops in the key module 1200 may be used.
[0175] Therefore, the process of performing the balance of 0 and 1 through methods such as aggregating digital values can be performed by a person of ordinary skill in the art through various modifications and applications, and does not go beyond the scope of the present invention.
[0176] In the embodiment of FIG. 13, 4 digital values are gathered into one group.
[0177] The key module 1200 compares the size of the 4-bit digital value generated by each of the group 1310 and the group 1320. In addition, when the 4-bit digital value of the group 1310 is greater than the 4-bit digital value of the group 1320, the digital value representing the group 1310 and the group 1320 is 1.
[0178] On the contrary, when the 4-bit digital value of the group 1310 is smaller than the 4-bit digital value of the group 1320, it represents that the digital value of the group 1310 and the group 1320 is 0.
[0179] In other embodiments, the number of digital values 1 between groups can be compared to select a digital value representing the group.
[0180] The method according to the embodiment of the present invention may be recorded in a computer-readable medium in the form of executable program commands by a variety of computer means. The computer-readable medium may include independent or combined program instructions, data files, data structures, and the like. The program instructions recorded on the media may be specially designed and created for the purpose of the present invention, or may be well known and applied by computer software technicians. Examples of computer-readable media include: magnetic media, such as hard disks, floppy disks, and tapes; optical media, such as CD ROM, DVD, and magneto-optical media, such as floptical disks. ); and hardware devices specifically configured to store and execute program instructions, such as read-only memory (ROM), random access memory (RAM), etc. Examples of program instructions include both machine code, such as generated by a compiler, and files containing higher-level codes that can be executed by a computer using an interpreter. The hardware device may be configured to operate as more than one software module to perform the operations of the present invention described above, and vice versa.
[0181] As shown above, although the present invention has been described with reference to limited embodiments and drawings, the present invention is not limited to the described embodiments. Anyone with ordinary knowledge in the field to which the present invention pertains can be described here. Make various modifications and transformations.
[0182] Therefore, the scope of the present invention is not limited or defined by the illustrated embodiments, but is defined by the appended claims and their equivalents.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US20080044010A1 | Cites | United States of America | X | Search report | 1-2,6-7 |
| US20060131575A1 | Cites | United States of America | Y | Search report | 3-5,8-10 |
| US5559889A | Cites | United States of America | A | Search report | 1-10 |
| JP特开平10116326A | Cites | Japan | A | Search report | 1-10 |
| JP特开201110218A | Cites | Japan | A | Search report | 1-10 |
| CN1777097A | Cites | China | A | Search report | 1-10 |
| US20090080647A1 | Cites | United States of America | A | Search report | 1-10 |
| US20100031065A1 | Cites | United States of America | A | Search report | 1-10 |
16 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 1020110013269 | Republic of Korea | – | |
| 20110013269 | Republic of Korea | A | |
| 201180070008 | China | A |
Members16
| Document | Office | Kind | |
|---|---|---|---|
| KR101118826B1 | Republic of Korea | B1 | |
| WO2012111872A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2013322624A1 | United States of America | A1 | |
| EP2677452A1 | European Patent Office (EPO) | A1 | |
| CN103621006A | China | A | |
| JP2014506095A | Japan | A | |
| EP2677452A4 | European Patent Office (EPO) | A4 | |
| US9014371B2 | United States of America | B2 | |
| US2015195085A1 | United States of America | A1 | |
| JP2016021772A | Japan | A | |
| US9397826B2 | United States of America | B2 | |
| CN103621006B | China | B | |
| US2016301528A1 | United States of America | A1 | |
| CN106295408A | China | A | |
| EP2677452B1 | European Patent Office (EPO) | B1 | |
| CN106295408BThis record | China | B |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent grantGrantedGR01 | GR01 | |
| Transfer of patent application rightTA01 | TA01 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 106295408
- Publication, DOCDB
- 106295408
- Publication, EPODOC
- CN106295408B
- Application
- 2016106216935
- Application, DOCDB
- 201610621693
- Application, EPODOC
- CN201610621693
Titles2
- Chinese
- 集成电路及加密方法
- English
- Integrated circuit and encryption method
Classification
- CPC, 8
- G06F21/72
- G06F21/78
- H04L9/0816
- H04L9/002
- H04L2209/12
- G06F12/14
- H04L9/14
- H04L2209/24
- IPC, 2
- G06F21 72
- H04L9 00