Security device and method
Patent Information
- Application Number
- KR1020230118261
- Authority / Receiving Office
- KR · KR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-06
- Publication Date
- 2026-09-04
- Estimated Expiration
- Not applicable · inactive patent
Smart Images

Figure 112023098464910-PAT00001_ABST
Abstract
Description
Technology Field
[0001] The embodiments relate to a security device and a security method. Background Technology
[0002] With the advent of the information society, the protection of information using cryptographic algorithms and protocols is becoming increasingly important. In particular, among the cryptographic algorithms used to protect information, open-key cryptographic algorithms used in the RSA (Rivest Shamir Adleman) cryptosystem and Elliptic Curve Cryptography (ECC) are rapidly being applied in various fields such as the internet and financial networks, as they solve the disadvantages of secret-key cryptographic algorithms, such as the key distribution problem and the digital signature problem.
[0003] Furthermore, regarding these quantum technologies, quantum computers have the ability to solve problems at a much faster speed than conventional computers, and in particular, due to quantum algorithms such as Shor's algorithm and Grover's algorithm, there is a significant possibility that existing symmetric-key encryption and public-key encryption algorithms could be decrypted by quantum computers within 24 hours.
[0004] If quantum computers are developed to have a sufficient number of qubits, currently used symmetric and public-key algorithms such as RSA and ECC can be easily decrypted by attacks using quantum computers. In this situation, quantum-resistant cryptography (PQC) is being researched to prepare for such problems.
[0005] As such, Post-Quantum Cryptography (PQC) is an encryption technology being developed to address security threats arising from the advancement of quantum computers. This PQC consists of algorithms that make it impossible to decrypt encrypted data using quantum computers. Currently, PQC is undergoing research and standardization processes, with various algorithms and protocols being developed. These algorithms are expected to provide robust encryption technology capable of countering quantum computing attacks.
[0006] In this regard, issues regarding the implementation and miniaturization of quantum-resistant cryptography composed of various algorithms are emerging. The problem to be solved
[0007] The embodiment provides a security device and a security method that accelerate cryptographic operations through some common hardware and provide flexibility for various cryptographic resistance algorithms.
[0008] In addition, by moving parts with high complexity and requiring acceleration to a common hardware device or module, and implementing the remaining algorithms in software, it is possible to provide a security device and method that comply with various standards and enable chip miniaturization.
[0009] The problems intended to be solved in the embodiments are not limited thereto, and may also include objectives or effects that can be identified from the means of solving the problems or the forms of implementation described below. means of solving the problem
[0010] A security device according to an embodiment comprises: a random number generator that generates a random number; a control unit that encrypts a key using the random number and an encryption algorithm; and a communication unit that transmits the encrypted key; wherein the operation applied to the random number or the encryption algorithm is performed based on a Physically Unclonable Function (PUF), the random number generator generates the random number based on a digital value generated by the Physically Unclonable Function (PUF), and the encryption algorithm is a quantum-resistant cryptography (PQC) algorithm.
[0011] The above control unit can generate a public key-based key pair by applying the above random number to a quantum-resistant cryptography (PQC) algorithm.
[0012] The digital value of the above PUF may be the initial value of the input that generates the random number in the above random number generation unit.
[0013] The above digital value may be a VIA PUF generated according to process deviations occurring in the semiconductor manufacturing process.
[0014] The above encryption algorithm may include at least one of lattice-based algorithms, code-based algorithms, multivariate algorithms, hash-based algorithms, and isogeny algorithms.
[0015] The above control unit may include a logic operation device that encrypts multiple keys by applying multiple encryption algorithms.
[0016] The above logic operation device may include a multiplier.
[0017] The multiplier of the above logic operation device can be implemented in hardware.
[0018] The above logic operation device may include a Physically Unclonable Function (PUF) in hardware.
[0019] The above logic operation device can be operated with a security key generated based on PUF.
[0020] When multiple algorithms are applied, the above control unit can generate the random number in units of the PUF area corresponding to the bits used.
[0021] Hardware acceleration can be applied to the above encryption algorithm.
[0022] The above control unit can schedule operations when multiple algorithms are applied.
[0023] The above control unit can schedule operations preferentially to the algorithm with the highest priority when multiple algorithms are applied.
[0024] The above control unit can schedule multiple algorithms to be used alternately.
[0025] The above control unit can schedule based on the available resources of a plurality of algorithms.
[0026] The above control unit can schedule the multiple algorithms by dividing them according to the priority of available resources.
[0027] The random number generator may include a true random number generator (TRNG).
[0028] A security device according to an embodiment comprises: a random number generator that generates a random number; a control unit that encrypts a key using the random number and an encryption algorithm; and a communication unit that transmits the encrypted key; wherein the random number is generated based on a Physically Unclonable Function (PUF), and the control unit utilizes a multiplier implemented in hardware in the encryption algorithm.
[0029] A security method according to an embodiment comprises: a step of generating a random number; a step of encrypting a public key using the random number and an encryption algorithm; and a step of transmitting the encrypted public key; wherein the operation applied to the random number or the encryption algorithm is performed based on a Physically Unclonable Function (PUF), and in the step of generating the random number, the random number is generated based on a digital value generated by the Physically Unclonable Function (PUF), and the encryption algorithm is a quantum-resistant cryptographic algorithm. Effects of the invention
[0030] According to an embodiment, a security device and a security method are implemented that accelerate cryptographic operations through some common hardware and provide flexibility for various cryptographic resistance algorithms.
[0031] In addition, by moving parts with high complexity and requiring acceleration to a common hardware device or module, and implementing the remaining algorithms in software, it is possible to implement security devices and methods that comply with various standards and enable chip miniaturization.
[0032] The various and beneficial advantages and effects of the present invention are not limited to those described above and may be more easily understood in the process of explaining specific embodiments of the present invention. Brief explanation of the drawing
[0033] FIG. 1 is a conceptual diagram of a security system according to an embodiment, and FIG. 2 is a block diagram of a security device according to an embodiment, and FIG. 3 is a conceptual diagram for explaining a Physically Unclonable Function (PUF) in a security device according to an embodiment, and FIG. 4 is a conceptual diagram illustrating an exemplary structure of a via or contact array formed on a semiconductor layer of a PUF according to an embodiment, and FIG. 5 is a flowchart of a security method according to an embodiment, and FIG. 6 is a drawing showing a computing device according to an embodiment of the present invention. Specific details for implementing the invention
[0034] The present invention is capable of various modifications and may have various embodiments, and specific embodiments are illustrated and described in the drawings. However, this is not intended to limit the invention to specific embodiments, and it should be understood that the invention includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the invention.
[0035] Terms including ordinal numbers, such as second, first, etc., may be used to describe various components, but said components are not limited by said terms. Such terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the present invention, the second component may be named the first component, and similarly, the first component may be named the second component. The term "and / or" includes a combination of a plurality of related described items or any of a plurality of related described items.
[0036] When it is stated that one component is "connected" or "connected" to another component, it should be understood that while it may be directly connected or connected to that other component, there may also be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.
[0037] The terms used in this application are used merely to describe specific embodiments and are not intended to limit the invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, terms such as "comprising" or "having" are intended to specify the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0038] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which the present invention pertains. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this application.
[0039] Hereinafter, embodiments will be described in detail with reference to the attached drawings, provided that identical or corresponding components are given the same reference number regardless of the drawing symbols, and redundant descriptions thereof will be omitted.
[0040] FIG. 1 is a conceptual diagram of a security system according to an embodiment, FIG. 2 is a block diagram of a security device according to an embodiment, FIG. 3 is a conceptual diagram for explaining a Physically Unclonable Function (PUF) in a security device according to an embodiment, and FIG. 4 is a conceptual diagram illustrating an exemplary structure of a via or contact array formed on a semiconductor layer of a PUF according to an embodiment.
[0041] Referring to FIGS. 1 and FIGS. 2, the security system may include a security device (100) and a server (200).
[0042] In the present invention, the security device (100) according to the embodiment can encrypt a random number using, for example, an encryption algorithm used for signature authentication, and use the same to encrypt or decrypt data (e.g., a message).
[0043] For example, the server (200) can generate a key (e.g., public key) certificate (Public Key of CA, CA: Certification Authority). The public key may correspond to a key that is exposed externally. The public key may be generated by various algorithms. Additionally, the server (200) may issue the public key in the form of a certificate.
[0044] The server (200) can generate a certificate of the public key generated by the security device (one client). The certificate of the public key can be provided to the sender or receiver of the message in the form of the public key data itself or the public key certificate.
[0045] For example, in an encryption algorithm, a public key can refer to the public key of a security device (e.g., a recipient). A private key can primarily refer to the private key of a security device (e.g., a recipient) in an encryption algorithm.
[0046] Furthermore, the concept of a key can encompass symmetric keys, public keys (private keys), and the like. In other words, cryptographic resistance algorithms can be applied to various types of keys.
[0047] Specifically, the security device (100) according to the embodiment may include a random number generator (110), a control unit (120), and a communication unit (130). The security device (100) may perform encryption, etc., using a random number and encryption algorithm as described above. In the embodiment, the operation applied to the random number and encryption algorithm in the security device (100) may be performed by a Physically Unclonable Function (PUF). Accordingly, the security device (100) according to the embodiment may include a Physically Unclonable Function (PUF) implemented in hardware. A description of such a hardware-implemented PUF will be provided later in FIG. 3. Furthermore, the security device (100) may perform the operation described later using the hardware-implemented PUF.
[0048] First, the random number generator (110) can generate random numbers. As an example, the random number generator may include a true random number generator (TRNG).
[0049] Random numbers can be generated based on digital values generated by a Physically Unclonable Function (PUF).
[0050] Here, the PUF can perform the role of entropy. In addition, in the security device (100), the PUF can perform the role of unique identification.
[0051] For example, the random number generated by the random number generator (110) can be generated based on a digital value generated based on a PUF. This PUF can provide a digital value corresponding to the random number generated by each chip. The digital value generated by the PUF may always be the same or a value that is maintained depending on the random number value or the characteristics of the PUF. In this way, the digital value of the PUF may be the initial value of the input for generating random numbers in the random number generator (110). By doing so, security can be further improved.
[0052] Thus, the control unit (120) can encrypt the public key using a random number and an encryption algorithm. Alternatively, the control unit (120) can encrypt the random number or encrypt the data (message) using an encryption algorithm.
[0053] The control unit (120) can generate a key (encryption key) by encrypting a random number with a public key using an encryption algorithm. The control unit (120) can then encrypt data (e.g., a message) using the encryption key.
[0054] In an example, the control unit (120) can generate a Public Key Infrastructure (PKI) key pair by using a random number (generated by a random number generator) based on a digital value (random number value) provided from a PUF in a quantum-resistant cryptography (PQC) algorithm. In this case, in applying the quantum-resistant cryptography algorithm, the control unit may use a quantum multiplier, which is a quantum calculator, a logic operation device.
[0055] As described above, the security device may include a PUF. The ID or entropy of the PUF may differ for each PUF or for each chip containing the PUF. Accordingly, a digital value generated from any one selected from among a plurality of PUFs may be a random number or a random value. However, as described above, although the value generated by the PUF itself is a unique value, it may possess randomness because it is selected based on a random number. For example, the digital value may be a random unique ID.
[0056] In an example, the ID of the PUF can be generated to be approximately several thousand bits. For instance, the PUF ID can be generated to be approximately 2,000 bits. A random number generator (e.g., TRNG) can generate random numbers through the value of the PUF. That is, the value of the PUF can be the initial value of the input for generating random numbers in the random number generator. A control unit can control the generation of random numbers through the PUF. The encryption algorithm may include a Post-Quantum Cryptography (PQC) algorithm. In an example, the encryption algorithm may include at least one of lattice-based algorithms, code-based algorithms, multivariate algorithms, hash-based algorithms, and isogeny algorithms.
[0057] The key exchange mechanism of these quantum-resistant cryptography (PQC) algorithms can encrypt and decrypt messages using symmetric keys.
[0058] As an example of use, after the random number generator (110) generates a random number, the control unit (120) can generate a symmetric key using a key derivation function (KDF). For instance, the key size can be significantly reduced by not using padding.
[0059] In addition, in security systems, the digital signature method of the quantum-resistant cryptography (PQC) algorithm signs a message using the sender's private key, and the receiver can verify the signed message using the sender's public key.
[0060] A control unit (120) may be provided in a transmitting device intended to transmit data (e.g., text information as a message, as well as various information such as measurement information, multimedia information, etc.) to a receiver. In this specification, "sender" may refer to various terminals used by a sender who corresponds to a natural person. Likewise, "receiver" may refer to various terminals used by a receiver who corresponds to a natural person.
[0061] The control unit (120) communicates with the random number generator (110) and can obtain a random number from the random number generator. In addition, in an embodiment, the random number generator (110) can generate a random number as a digital value generated by a Physically Unclonable Function (PUF). Accordingly, the random number may be a VIA PUF generated according to process deviations occurring in the semiconductor manufacturing process.
[0062] Additionally, the control unit (120) may include a logical operation device that performs encryption by applying an encryption algorithm. For example, the control unit (120) may encrypt multiple public keys by applying multiple encryption algorithms.
[0063] The logic operation unit may include a logic unit of a hardware device. For example, the logic operation unit may include a multiplier. As an example, the security device or the logic operation unit may be implemented as a Physically Unclonable Function (PUF) in hardware.
[0064] More specifically, referring to FIGS. 3 and FIGS. 4, the PUF can be implemented as described below.
[0065] For example, FIG. 3 illustrates vias formed between a metal 1 layer (202) and a metal 2 layer (201) in a semiconductor manufacturing process.
[0066] And in the group (210) where the via size is made sufficiently large according to the design rule, all vias short-circuit the metal 1 layer (202) and the metal 2 layer (201), and when the short-circuit status is expressed as a digital value, all become 0.
[0067] Meanwhile, in the group (230) where the via size is too small, not all vias are able to short-circuit the metal 1 layer (202) and the metal 2 layer (201). Therefore, if the short-circuit status is expressed as a digital value, all of them become 1.
[0068] And in a group (220) with via sizes between group (210) and group (230), some vias short-circuit the metal 1 layer (202) and the metal 2 layer (201), while other vias do not short-circuit the metal 1 layer (202) and the metal 2 layer (201).
[0069] A random number generator or logic operation device implemented with a PUF according to an embodiment of the present invention may be configured such that some vias short-circuit the metal 1 layer (202) and the metal 2 layer (201), as in a group (220), and other vias do not short-circuit the metal 1 layer (202) and the metal 2 layer (201), by setting the via sizes.
[0070] The design rule for such via size varies depending on the semiconductor manufacturing process. For example, if the design rule for the via is set to 0.25 microns in a CMOS (Complementary metal oxide semiconductor) process of 0.18 micrometers, the via size in the random number generator and encryption algorithm according to one embodiment of the present invention is set to 0.19 microns so that the short circuit between the metal layers is probabilistically distributed.
[0071] In addition, the probability distribution of the aforementioned short circuit is ideally set to have a short circuit probability of 50%, and the random number generator and logic operation device according to one embodiment of the present invention can be configured by setting the via size so that the probability distribution is as close as possible to 50%. In setting the via size in this way, the via size can be determined by experiment according to the process.
[0072] FIG. 4 is an exemplary structure of a via or contact array formed on a semiconductor layer of a circuit implemented as a random number generator and a logic operation unit, or a multiplier, for generating random numbers.
[0073] For example, FIG. 4 shows a configuration in which a total of M*N vias are formed between metal layers stacked on a semiconductor substrate, with M vias in the horizontal row and N vias in the vertical row (where M and N are natural numbers).
[0074] The random number generator and the logic operation device can be implemented as a circuit that generates M*N bits of random numbers depending on whether each of the M*N vias short-circuits the metal layers (digital value 0) or fails to short-circuit them (digital value 1), or performs a logic operator (multiplier) based on the structure of such short-circuit status.
[0075] For example, in the case of random numbers, the M*N bit key generated in this way can be provided to the control unit as a digital value.
[0076] In this way, the logic operation device of the random number generator (110) and the control unit (120) in the security device (100) according to the embodiment may be made of hardware.
[0077] With this configuration, as a part of the random number generator or logic operation unit is implemented as the aforementioned PUF-based hardware, the security device according to the embodiment can provide an acceleration effect for cryptographic operations and flexibility for various cryptographic resistance algorithms.
[0078] That is, the security device according to an embodiment of the present invention may be provided within or outside a system semiconductor (SoC), and may have common hardware for logical operations (multipliers) or random number generation in encryption using a quantum-resistant cryptographic algorithm. In addition, the implementation of the algorithm may be implemented in software, i.e., through data processing. By doing so, easy miniaturization of the size of the security device can be provided in addition to the effects described above. Furthermore, improvements in computational speed and performance enhancement through hardware implementation can be provided.
[0079] In addition, if the multiplier is implemented solely by hardware circuitry, a highly reliable authentication process that is impossible to tamper with can be provided because, unlike in the case of software, changes to the system are impossible.
[0080] For example, the aforementioned hardware-based multiplier can be provided in a security device as a function of a Root of Trust security chip based on a PUF. In an embodiment, the multiplier (or security device) may include a memory (e.g., SRAM) (or memory device) to which a PUF is applied. Accordingly, to generate a unique device key (security key) within the SRAM, each region or section of the SRAM, which may have slight differences depending on the process, may be utilized. Based on this, the multiplier generates an unclonable key based on the PUF while in an operating or on state, and a hardware-linked key storage may be utilized based on this.
[0081] Furthermore, since the control unit (120) uses a quantum-resistant cryptography based on random numbers generated from a hardware-based PUF for the encryption algorithm, hardware acceleration can be applied to the encryption algorithm. That is, hardware acceleration functions for multiple algorithms (quantum-resistant cryptography) can be provided through encryption acceleration hardware embedded in a PUF-based security device (or chip).
[0082] Furthermore, by generating random numbers based on PUF values, the security of quantum-resistant cryptographic algorithms can be further improved by utilizing the characteristics of the random number generator.
[0083] The communication unit (130) can transmit an encrypted public key. For example, the communication unit (130) can transmit it to a recipient, a server (another server), etc.
[0084] In addition, the control unit (120) can encrypt multiple public keys by applying multiple encryption algorithms. For example, when multiple algorithms are applied, the control unit can generate random numbers in units of PUF areas corresponding to the bits used.
[0085] In addition, as another use case, the control unit (120) can schedule operations when multiple algorithms are applied.
[0086] Multiple algorithms applied to a common multiplier may differ in speed and other characteristics. For example, multivariable-based cryptographic algorithms and lattice-based cryptographic algorithms may have fast computation speeds. In contrast, isogeny-based cryptographic algorithms may provide relatively slower computation speeds compared to other algorithms. Accordingly, the control unit can set a priority among the multiple algorithms in response to the computation speeds of the multiple algorithms. For example, the control unit may preferentially apply algorithms with relatively slower computation speeds to a logic operation unit (multiplier) implemented with PUFs.
[0087] Additionally, as an embodiment, the control unit (120) may schedule operations preferentially to the algorithm with the highest priority when multiple algorithms are applied. The priority may correspond to a weight or proportion. For example, operations may be performed preferentially on the algorithm with the highest priority or weight.
[0088] For example, the control unit (120) can prioritize scheduling an algorithm that performs the entire function among a plurality of algorithms. For example, the control unit (120) can prioritize scheduling operations that are prerequisites or essential for computation among a plurality of algorithms. Accordingly, switching for the application of algorithms is reduced, thereby reducing the risk of overhead. Additionally, if one algorithm is monopolized or applied until it is finished, priority computation can be performed on the algorithm of high priority so that the application of the quantum-resistant cryptographic algorithm can be processed more quickly.
[0089] In addition, the control unit (120) can schedule multiple algorithms to be executed alternately as another example. By doing so, the algorithms are used alternately, thereby providing a parallel processing effect.
[0090] Additionally, the control unit (120) can schedule based on the available resources of multiple algorithms. For example, hardware can be allocated or assigned to two algorithms in equal halves (each ratio being 50%). At this time, although there is a reduction in the acceleration effect, the control unit can provide the advantage or effect of being able to perform partial acceleration in parallel.
[0091] FIG. 5 is a flowchart of a security method according to an embodiment.
[0092] Referring to FIG. 5, the security method according to the embodiment may include the step of generating a random number (S310), the step of encrypting a public key using the random number and an encryption algorithm (S320), and the step of transmitting the encrypted public key (S330).
[0093] Each of these steps can be performed on a security device.
[0094] First, the random number generator in the security device can generate a random number (S310). As described above, the random number can be generated from a digital value output from a structure (e.g., a via) that is generated according to process deviations occurring in the semiconductor manufacturing process based on a PUF. That is, in the step of generating a random number (S310), the random number can be generated based on a digital value generated by a PUF (Physically Unclonable Function).
[0095] Furthermore, the control unit can generate a Public Key Infrastructure (PKI) key pair by using a random number (generated by the random number generator) based on a digital value (random value) provided from the PUF in a quantum-resistant cryptography (PQC) algorithm. Then, encryption of the public key can be performed (S320).
[0096] The communications unit can transmit an encrypted public key externally. Authentication methods such as public key generation can also be applied to digital signatures.
[0097] Furthermore, the control unit may utilize a quantum-resistant cryptography based on random numbers generated from a hardware-based PUF for the encryption algorithm. In the security method according to the embodiment, hardware acceleration may be applied to the encryption algorithm, that is, encryption acceleration hardware embedded in a PUF-based security device (or chip). Accordingly, a hardware acceleration function for multiple algorithms (quantum-resistant cryptography) may be provided. Therefore, faster authentication can be achieved.
[0098] In addition, as described above, by generating random numbers based on PUF values, the security of quantum-resistant cryptographic algorithms can be further improved by utilizing the characteristics of the random number generation unit.
[0099] Furthermore, when multiple algorithms are applied, the control unit can schedule operations preferentially to the algorithm with the highest priority. This applies in the same way to the control unit described above.
[0100] The control unit can encrypt the key using a random number and an encryption algorithm (S320). At this time, as described above, since a part of the random number generator or the logic operation unit is implemented as the aforementioned PUF-based hardware, the security device according to the embodiment can provide an acceleration effect for encryption operations and flexibility for various quantum-resistant cryptographic algorithms.
[0101] The communication unit can transmit an encrypted key (S330). For example, an encrypted public key may be provided to the recipient. The recipient can then verify the signed message using the sender's public key.
[0102] FIG. 6 is a drawing showing a computing device according to an embodiment of the present invention.
[0103] Referring to FIG. 6, the computing device (1000) according to the embodiment may be a device described in the present specification (e.g., a security device, etc.).
[0104] In the embodiment of FIG. 6, the computing device (1000) may include at least one processor (1100), a transmitting / receiving device (1200), and a memory (1300). Additionally, the computing device (1000) may further include a storage device (1400), an input interface device (1500), an output interface device (1600), etc. The components included in the computing device (1000) may be connected by a bus (1700) to communicate with each other.
[0105] The processor (1100) can execute a program command stored in at least one of the memory (1300) and the storage device (1400). The processor (1100) may refer to a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which methods according to embodiments of the present invention are performed. The processor (1100) may be configured to implement procedures, functions, and methods, etc., described in relation to embodiments of the present invention. The processor (1100) can control each component of the computing device (1000).
[0106] For example, the processor (1100) can perform a cryptographic resistance algorithm. That is, the cryptographic resistance algorithm can be performed by software processing by the processor (1100). However, as described above, the random number generator or the logic operation unit can be implemented as PUF-based hardware.
[0107] Each of the memory (1300) and the storage device (1400) can store various information related to the operation of the processor (1100). Each of the memory (1300) and the storage device (1400) may be composed of at least one of a volatile storage medium and a non-volatile storage medium. For example, the memory (1300) may be composed of at least one of read-only memory (ROM) and random access memory (RAM).
[0108] The transmitting and receiving device (1200) can transmit or receive wired signals or wireless signals. The transmitting and receiving device (1200) can be connected to a network to perform communication.
[0109] The term "part" as used in this embodiment refers to a software or hardware component, such as a field-programmable gate array (FPGA) or an ASIC, and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or configured to run one or more processors. Thus, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." In addition, the components and '~parts' may be implemented to play one or more CPUs within the device or secure multimedia card.
[0110] Although the invention has been described above with reference to embodiments, this is merely illustrative and does not limit the invention. Those skilled in the art will understand that various modifications and applications not exemplified above are possible within the scope of the essential characteristics of the embodiments. For example, each component specifically shown in the embodiments may be modified and implemented. Furthermore, differences related to such modifications and applications should be interpreted as being included within the scope of the invention as defined in the appended claims.
Claims
Claim 1 A security device comprising: a random number generator that generates a random number; a control unit that encrypts a key using the random number and an encryption algorithm; and a communication unit that transmits the encrypted key; wherein the operation applied to the random number or the encryption algorithm is performed based on a Physically Unclonable Function (PUF), the random number generator generates the random number based on a digital value generated by the Physically Unclonable Function (PUF), the encryption algorithm is a Quantum-Resistant Cryptography (PQC) algorithm, the control unit includes a logic operation device that encrypts multiple keys by applying multiple encryption algorithms, the logic operation device includes a multiplier, and the control unit schedules operations when multiple algorithms are applied and prioritizes the application of the logic operation device implemented with a PUF to algorithms with relatively slower operation speeds. Claim 2 In claim 1, the control unit is a security device that generates a public key-based key pair by applying the random number to a quantum-resistant cryptography (PQC) algorithm. Claim 3 A security device in which the digital value of the PUF is the initial value of the input that generates the random number in the random number generator in claim 1. Claim 4 In paragraph 2, the above digital value is a security device that is a VIA PUF generated according to process deviations occurring in the semiconductor manufacturing process. Claim 5 A security device according to claim 1, wherein the encryption algorithm comprises at least one of lattice-based algorithms, code-based algorithms, multivariate algorithms, hash-based algorithms, and isogeny algorithms. Claim 6 delete Claim 7 delete Claim 8 In claim 1, the multiplier of the logic operation device is a security device implemented in hardware. Claim 9 In claim 1, the logic operation device is a security device that includes a Physically Unclonable Function (PUF) in hardware. Claim 10 In claim 1, the logic operation device is a security device driven by a security key generated based on a PUF. Claim 11 In claim 1, the control unit is a security device that generates the random number in PUF area units corresponding to the bits used when a plurality of algorithms are applied. Claim 12 In paragraph 1, the encryption algorithm is a security device to which hardware acceleration is applied. Claim 13 delete Claim 14 In claim 1, the control unit is a security device that prioritizes scheduling operations to the algorithm with the highest priority when multiple algorithms are applied. Claim 15 delete Claim 16 In claim 1, the control unit is a security device that schedules based on available resources of a plurality of algorithms. Claim 17 delete Claim 18 In paragraph 1, the random number generator is a security device including a true random number generator (TRNG). Claim 19 A security device comprising: a random number generator that generates a random number; a control unit that encrypts a key using the random number and an encryption algorithm; and a communication unit that transmits the encrypted key; wherein the random number is generated based on a Physically Unclonable Function (PUF); the control unit utilizes a multiplier implemented in hardware in the encryption algorithm; the control unit includes a logic operation device that encrypts multiple keys by applying multiple encryption algorithms; the logic operation device includes the multiplier; and the control unit schedules operations when multiple algorithms are applied and prioritizes the application of the logic operation device implemented as a PUF to algorithms with relatively slower operation speeds. Claim 20 delete
Citation Information
Patent Citations
Technologies for accelerating compute intensive operations using solid state drives
KR1020170034425A
Bidirectional message authentication chip based on physical unclonable function for IoT device
KR1020200144407A
Module-LWE based Crypto-Processor System and Method for Post-Quantum Cryptography
KR102462395B1