Distributed Random Number Generator and Its Random Number Generation Method
By using multiple high-frequency and low-frequency clock pulse generators and DRNGs in the random number generator, and alternately transmitting random digital sequences through multiplexers, the problems of insufficient random number generation capabilities and low attack resistance in the prior art are solved, and random number generation with high throughput and high random degree is achieved.
Patent Information
- Application Number
- CN202110948185.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-08-18
- Filing Date
- 2021-08-18
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2041-08-18
AI Technical Summary
Existing random number generation techniques are difficult to find a balance between high throughput and high randomness, and are also difficult to resist the reduction in randomness caused by malicious attacks.
Multiple high-frequency and low-frequency clock pulse generators and digital random number generators (DRNGs) are used to alternately transmit random digital sequences through multiplexers to form a distributed random number generator to improve the random number generation ability and attack resistance.
It realizes high throughput and high randomness of random number generation, enhances resistance to malicious attacks, and reduces the cost, size and power consumption of random number generators.
Smart Images

Figure CN114077422B_ABST
Abstract
Description
Technical Field
[0001] The present invention mainly relates to random number generation, and more particularly to a method and system for generating a sequence of random digits using multiple random number generators. Background Art
[0002] A variety of random number generation techniques are known in the art. For example, U.S. Patent No. 4,905,176 describes a random number generator that can resist cryptographic attacks. The random number generator operates based on low-frequency sampling of the output of a pseudo-random number generator that operates with the varying frequency of a free-running ring oscillator. Summary of the Invention
[0003] Embodiments of the invention described herein provide a Random-Number Generator (RNG) that includes a plurality of High-Frequency (HF) clock pulse generators, a plurality of Low-Frequency (LF) clock pulse generators, a plurality of Digital Random-Number Generator circuits (DRNGs), and a multiplexer. The HF clock pulse generators are configured to generate HF clock pulse signals in a first frequency range. The LF clock pulse generators are configured to generate LF clock pulse signals in a second frequency range that is lower than the first frequency range. Each DRNG is configured to (i) obtain a high-frequency clock pulse signal extracted from the HF clock pulse signal and (ii) obtain a low-frequency clock pulse signal extracted from the HF clock pulse signal, thereby obtaining a sequence of random digits. The multiplexer is configured to generate an output sequence of random digits from the sequences of random digits generated by the DRNGs.
[0004] In some embodiments, a given DRNG includes: (i) a Linear Feedback Shift Register (LFSR) clocked by a high-frequency clock pulse signal; and (ii) a Flip-Flop (FF) configured to sample the output of the LFSR according to a low-frequency clock pulse signal. In various embodiments, at least two of the LFSRs differ from each other in one or more of the following characteristics: (i) an initial seed value, (ii) a feedback-tap configuration, and (iii) a number of cascaded Flip-Flops. In an alternative embodiment, a given DRNG includes a Flip-Flop configured to sample a high-frequency clock pulse signal according to a low-frequency clock pulse signal.
[0005] In the disclosed embodiments, the DRNG receives different pairs of input clock pulse signals, each pair including a high-frequency clock pulse signal and a low-frequency clock pulse signal. In one embodiment, the high-frequency clock pulse generator, the low-frequency clock pulse generator, and the DRNG are spatially distributed over a region of an Integrated Circuit (IC). In some embodiments, the random number generator further includes one or more analog noise sources configured to add analog noise to one or more of the low-frequency clock pulse generator and the high-frequency clock pulse generator.
[0006] In some embodiments, a multiplexer is configured to perform a multiplexing sequence that alternates between DRNGs to multiplex a random digit sequence. In an exemplary embodiment, the multiplexer is configured to obtain the multiplexing sequence from selected bits of one or more of the random digit sequences in the random digit sequence.
[0007] In one embodiment, the high-frequency clock pulse generators and the low-frequency clock pulse generators are arranged in pairs, each pair including a high-frequency clock pulse generator and a low-frequency clock pulse generator. In another embodiment, at least two of the high-frequency clock pulse generators are configured to generate high-frequency clock pulse signals having different frequencies from each other. Additionally or alternatively, at least two of the low-frequency clock pulse generators may be configured to generate low-frequency clock pulse signals having different frequencies from each other. Even more additionally or alternatively, at least two of the high-frequency clock pulse generators may be configured to be triggered at different times. In another embodiment, at least two of the low-frequency clock pulse generators are configured to be triggered at different times.
[0008] In addition, according to an embodiment of the present invention, there is further provided a method for generating random numbers, including: generating a plurality of high-frequency clock pulse signals within a first frequency range; generating a plurality of low-frequency clock pulse signals within a second frequency range that is lower than the first frequency range; obtaining a plurality of random digit sequences, each random digit sequence being obtained from (i) one of the high-frequency clock pulse signals and (ii) one of the low-frequency clock pulse signals; and generating an output sequence of random digits according to the random digit sequences. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] This disclosure will be better understood from the following description of exemplary embodiments in conjunction with the accompanying drawings.
[0010] Figure 1 is a block diagram of an integrated circuit (IC) including a distributed random number generator, as illustrated according to an embodiment of the present invention.
[0011] Figure 2 is a flowchart of a method for distributed random number generation, as illustrated according to an embodiment of the present invention.
[0012]
REFERENCE SIGNS
[0013] 20: Integrated Circuit (IC)
[0014] 24: Random Number Generator (RNG)
[0015] 28A, 28B: Analog Random Number Generator (ARNG)
[0016] 32A - 32D: Digital Random Number Generator (DRNG)
[0017] 36: Multiplexer
[0018] 40, 44: Clock Pulse Generator
[0019] 48: Linear Feedback Shift Register (LFSR)
[0020] 52: Flip-Flop (FF)
[0021] 60, 64, 68, 72, 76: Steps DETAILED DESCRIPTION
[0022] Overview
[0023] Embodiments of the present invention described herein provide improved methods and circuits for generating random numbers. The disclosed Random-Number Generator (RNG) generates random numbers with high throughput and a high degree of randomness. The disclosed random number generator also has a high degree of resilience to malicious attacks that attempt to reduce or cut the randomness of the output sequence of random digits.
[0024] In some embodiments, the random number generator includes a plurality of free-running high-frequency clock pulse generators and a plurality of free-running low-frequency clock pulse generators. The high-frequency clock pulse generators are arranged to generate high-frequency clock pulse signals within a first frequency range (e.g., about megahertz (MHz)). The low-frequency clock pulse generators are arranged to generate low-frequency clock pulse signals within a second frequency range that is lower than the first frequency range (e.g., about kilohertz (kHz)). In some embodiments, an analog noise source can be added to any of the clock pulse generators. The addition of such noise is particularly effective for the low-frequency clock pulse generators.
[0025] The random number generator further includes a plurality of Digital Random-Number Generator circuits (DRNGs). Each DRNG has a selected pair of {high-frequency clock pulse signal, low-frequency clock pulse signal} as inputs. Generally, different DRNGs have different pairs of {high-frequency clock pulse signal, low-frequency clock pulse signal}, even though any individual clock pulse signal (high or low frequency) can be used to drive more than one DRNG.
[0026] Each DRNG is arranged to use the high-frequency and low-frequency clock pulse signals it has to generate a random digit sequence. In some embodiments, each DRNG includes a Linear Feedback Shift Register (LFSR) clocked by the high-frequency clock pulse signal and a Flip-Flop (FF) that samples the output of the LFSR according to the low-frequency clock pulse signal. Since the output of the LFSR is sampled at a much lower frequency than the actual LFSR clock pulse frequency and since the low-frequency sampling clock pulse is typically noisy, the resulting random digit sequence is indeed highly random.
[0027] The random number generator further includes a multiplexer configured to generate an output sequence of random digits from the sequence of random digits generated by the DRNG. By multiplexing the outputs of multiple DRNGs, the disclosed random number generator can provide a high throughput of random numbers. In some embodiments, the multiplexer further enhances the randomness of its output by using a multiplexing order that alternates between multiple DRNGs.
[0028] Since the clock pulse generators (high-frequency and low-frequency) operate freely without synchronization with each other and are noisy, and since each DRNG has a different pair of {high-frequency clock pulse signal, low-frequency clock pulse signal}, the sequences of random digits generated by different DRNGs are almost or completely uncorrelated with each other. As a result, the multiplexed sequence of bits generated by the multiplexer has a high degree of randomness.
[0029] By reusing the same high-frequency clock pulse signal and low-frequency clock pulse signal in different combinations, a number of high-frequency clock pulse generators and low-frequency clock pulse generators can be used to drive a large number of DRNGs without sacrificing randomness. This feature reduces the cost, size, and power consumption of the random number generator.
[0030] In some embodiments, the random number generator is implemented in a partial integrated circuit (IC), and the various components of the random number generator (high-frequency clock pulse generator, low-frequency clock pulse generator, and DRNG) are spatially dispersed over the IC area. Thus, different clock pulse generators are responsible for improving the noise with different statistical values, helping to reduce the correlation between different clock pulse signals. In addition, even if an attack successfully causes a specific DRNG to output a deterministic sequence, the overall random number generator will still maintain a high degree of randomness. This property is further enhanced when the multiplexing order is random.
[0031] Various exemplary implementations and variations of the random number generator disclosed herein are described.
[0032] System Description
[0033] Figure 1 is a block diagram of an integrated circuit (IC) 20 including a distributed random number generator (RNG) 24, as illustrated in an embodiment of the present invention. In various embodiments, the IC 20 may include, for example, a secure controller, a secure memory device, or any other type of IC that utilizes random numbers. For clarity, circuits other than the RNG 24 are omitted from the drawing. In other embodiments, the IC 20 may be dedicated to generating random numbers.
[0034] RNG 24 includes two or more analog random number generator circuits (ARNGs) 28, represented in this example as ARNG 28A and ARNG 28B for two ARNGs. Each ARNG is arranged to generate a high-frequency (represented as HF in Figure 1 ), and a low-frequency (represented as LF in Figure 1 ) clock pulse signal. In some embodiments, the low-frequency clock pulse signal has a frequency of about kilohertz (KHz), and the high-frequency clock pulse signal has a frequency of about megahertz (MHz), although any other suitable frequency range may be used.
[0035] RNG 24 further includes two or more digital random number generator circuits (DRNGs) 32, represented in this example as four DRNGs 32A - 32D. Each DRNG 32 is arranged to obtain a random digit sequence from the high-frequency and low-frequency clock pulse signals. The high-frequency and low-frequency clock pulse signals provided to a given DRNG 32 may be generated by the same ARNG 28 or different ARNGs 28. A given clock pulse signal (high-frequency clock pulse signal or low-frequency clock pulse signal) may be provided to a single DRNG 32 or multiple DRNGs 32. Generally, different DRNGs 32 have different pairs of {high-frequency clock pulse signal, low-frequency clock pulse signal}.
[0036] RNG 24 further includes a multiplexer 36, also referred to as a combiner. The multiplexer 36 is arranged to multiplex the random digit sequences generated by the DRNGs 32 to output a high-frequency sequence of random digits (represented as RNG OUT in Figure 1 ). This sequence is provided as the output of RNG 24. As will be explained below, the multiplexer 36 is generally not a simple multiplexer that selects one from multiple inputs, but rather a circuit that concatenates bits or groups of bits to form a random bitstream.
[0037] Located at Figure 1 The bottom illustration shows the internal structure of the ARNG 28 and the DRNG 32. ARNG 28B and DRNG 32D are depicted as examples; other ARNGs and DRNGs generally have similar internal structures respectively.
[0038] As shown in the left illustration, each ARNG 28 includes (i) a high-frequency free-running clock pulse generator 40 that generates a high-frequency clock pulse signal (represented as HF OUT in Figure 1 ), and (ii) a low-frequency free-running clock pulse generator 44 that generates a low-frequency clock pulse signal (represented as LF in Figure 1represented as LF OUT in the [Chinese text]). Generally, the clock pulse generators 40 and 44 in a given ARNG 28 are not synchronized with each other, nor are they synchronized with the clock pulse generators 40 and 44 of other ARNGs 28.
[0039] To enhance randomness, in some embodiments, analog noise (represented as NOISE in the [Chinese text]) is added to one or both of the clock pulse generators 40 and 44. The analog noise can be deliberately generated by a circuit dedicated for this purpose. The noise can be added to the supply voltage of the clock pulse generator (represented as VDD in the [Chinese text]), or added at any other point that helps randomize the output of the clock pulse generator. Alternatively, the clock pulse generator can be responsible for improving the analog noise from its surrounding environment without additional circuitry. Figure 1 As shown in the illustration on the right, each DRNG 32 includes a Linear Feedback Shift Register (LFSR) 48 and a sampling flip-flop (FF) 52. Each LFSR 48 includes a series of multiple flip-flops with one or more feedback taps. In each DRNG, the LFSR 48 is clocked by the high-frequency clock pulse signal provided to the DRNG (as HF IN), and thus outputs a sequence of pseudo-random numbers at the frequency of the high-frequency clock pulse signal. The flip-flop 52 samples a portion of the output of the LFSR 48 at this frequency according to the low-frequency clock pulse signal provided to the DRNG (represented as LF IN in the [Chinese text]). The sequence of random digits at the output of the flip-flop 52 (represented as Q in the [Chinese text]) is provided as the output of the DRNG (represented as RN OUT in the [Chinese text]). RN OUT has the same frequency as the low-frequency clock pulse signal (LF IN). Figure 1 The multiple RN OUTs generated by multiple DRNGs 32 are provided as inputs to the multiplexer 36. The multiplexer 36 multiplexes the multiple RN OUT random digit sequences to generate a high-frequency RNG OUT random digit sequence.
[0040] As shown in the illustration on the right, each DRNG 32 includes a Linear Feedback Shift Register (LFSR) 48 and a sampling flip-flop (FF) 52. Each LFSR 48 includes a series of multiple flip-flops with one or more feedback taps. In each DRNG, the LFSR 48 is clocked by the high-frequency clock pulse signal provided to the DRNG (as HF IN), and thus outputs a sequence of pseudo-random numbers at the frequency of the high-frequency clock pulse signal. The flip-flop 52 samples a portion of the output of the LFSR 48 at this frequency according to the low-frequency clock pulse signal provided to the DRNG (represented as LF IN in the [Chinese text]). The sequence of random digits at the output of the flip-flop 52 (represented as Q in the [Chinese text]) is provided as the output of the DRNG (represented as RN OUT in the [Chinese text]). RN OUT has the same frequency as the low-frequency clock pulse signal (LF IN). Figure 1 The multiple RN OUTs generated by multiple DRNGs 32 are provided as inputs to the multiplexer 36. The multiplexer 36 multiplexes the multiple RN OUT random digit sequences to generate a high-frequency RNG OUT random digit sequence. Figure 1 The multiple RN OUTs generated by multiple DRNGs 32 are provided as inputs to the multiplexer 36. The multiplexer 36 multiplexes the multiple RN OUT random digit sequences to generate a high-frequency RNG OUT random digit sequence. Figure 1 The multiple RN OUTs generated by multiple DRNGs 32 are provided as inputs to the multiplexer 36. The multiplexer 36 multiplexes the multiple RN OUT random digit sequences to generate a high-frequency RNG OUT random digit sequence.
[0041] The multiple RN OUTs generated by multiple DRNGs 32 are provided as inputs to the multiplexer 36. The multiplexer 36 multiplexes the multiple RN OUT random digit sequences to generate a high-frequency RNG OUT random digit sequence.
[0042] In some embodiments, the ARNG 28 and the DRNG 32 are deliberately not placed together, but are spatially dispersed over the area of the IC 20. This spatial distribution is advantageous for many reasons. For example, when spatially dispersed, different ARNGs are responsible for improving the simulated noise with different statistical values, helping to reduce the correlation between different clock pulse signals (high frequency or low frequency). As another example, a malicious attack on a specific area of the IC 20 is less likely to damage parts other than a single ARNG or DRNG. Even if an ARNG or DRNG is damaged resulting in a fixed or deterministic bit sequence being output by the ARNG or DRNG, the likelihood of a reduction in the randomness of the overall RNG OUT sequence is small because the other ARNGs and DRNGs are still operating normally.
[0043] In various embodiments, the multiplexer 36 can multiplex the random digit sequences generated by the DRNG 32 in various ways. Refer to Figure 1 the setting where the outputs of the DRNGs 32A - 32D are represented by stream1 - stream4 respectively. In some embodiments, the multiplexer 36 multiplexes the random digit sequences in a predefined, deterministic, cyclic multiplexing order. For example, the multiplexer 36 can output n bits (e.g., n = 2) from stream1, then n bits from stream2, n bits from stream3, n bits from stream4, and then again n bits from stream1, and so on. In alternative embodiments, any other suitable deterministic multiplexing order can be used.
[0044] In other embodiments, the multiplexer 36 can multiplex the random digit sequences generated by the DRNG 32 in a multiplexing order that randomly alternates between multiple DRNGs. In this context, the term "randomly alternate" means that (i) the order of alternating from one random digit sequence to another is random, and / or (ii) the number of bits extracted from a given random digit sequence when accessed is random. In another embodiment, the multiplexer 36 obtains a random number multiplexing order from selected bits of one or more random digit sequences. For example, the multiplexer 36 can execute the following procedure:
[0045] ■ Extract one bit from stream1. If the bit value is "0", then extract two bits from stream2, concatenate two bits from stream3, concatenate two bits from stream4, and concatenate two bits from stream1. If the bit value is "1", then extract two bits from stream3, concatenate two bits from stream1, concatenate two bits from stream2, and concatenate two bits from stream4.
[0046] ■Extract one bit from stream2. If the value of this bit is "0", then extract two bits from stream1, concatenate two bits of stream3, concatenate two bits of stream4, and concatenate two bits of stream2. If the value of this bit is "1", then extract two bits from stream3, concatenate two bits of stream2, concatenate two bits of stream4, and concatenate two bits of stream1.
[0047] ■Extract one bit from stream3, and then continue to execute this program in a similar manner.
[0048] The multiplexing sequence of the examples given above is for illustrative purposes only. In alternative embodiments, the multiplexer 36 may use any other suitable multiplexing sequence and any other suitable program for obtaining the multiplexing sequence, such as selected bits from a random digit sequence generated by one or more DRNGs 32.
[0049] As Figure 1 The RNG 24 and its components shown are exemplary arrangements depicted only for conceptual clarity. In alternative embodiments, any other suitable arrangement may be used. For example, the RNG 24 may include any other suitable number of ARNGs 28 and any other suitable number of DRNGs 32. The interconnection scheme between the ARMG and the DRNG (i.e., which high-frequency clock pulse signal and which low-frequency clock pulse signal are selected to be provided to each DRNG) may also be set in any other suitable manner. Alternatively, the high-frequency clock pulse generator 40 and the low-frequency clock pulse generator 44 are not necessarily arranged in a combined pair. More generally, the number of high-frequency clock pulse generators 40 may be different from the number of low-frequency clock pulse generators 44.
[0050] In some embodiments, the high-frequency clock pulse generator 40 generates high-frequency clock pulse signals all having the same frequency. In other embodiments, at least two of the high-frequency clock pulse generators generate high-frequency clock pulse signals having different frequencies from each other. Correspondingly, in some embodiments, the low-frequency clock pulse generator 44 generates low-frequency clock pulse signals all having the same frequency. In other embodiments, at least two of the low-frequency clock pulse generators generate low-frequency clock pulse signals having different frequencies from each other.
[0051] In some embodiments, in order to enhance randomness, at least two of the high-frequency clock pulse generators 40 are set to trigger at different times. Additionally or alternatively, at least two of the low-frequency clock pulse generators 44 may be set to trigger at different times.
[0052] In some embodiments, all of the LFSRs 48 in all of the DRNGs 32 are initialized to the same seed value (reset value). In other embodiments, at least two of the LFSRs (possibly all of the LFSRs) are initialized to different seed values. In an exemplary embodiment, the LFSRs 48 are independently initialized to respective random values. The initialization of the random number seed value can be implemented, for example, by performing one or more flip-flops of the LFSR without reset logic, such that the flip-flops are set to arbitrary values upon reset.
[0053] In some embodiments, all of the LFSRs 48 in all of the DRNGs 32 have the same feedback tap configuration (same sequence generation polynomial). In other embodiments, at least two of the LFSRs (possibly all of the LFSRs) have different feedback tap configurations from each other. In some embodiments, all of the LFSRs 48 in all of the DRNGs 32 have the same number of cascaded flip-flops. In other embodiments, at least two of the LFSRs (possibly all of the LFSRs) have different numbers of cascaded flip-flops from each other.
[0054] In another embodiment, the LFSR 48 in at least one of the DRNGs 32 can be completely omitted. In such a DRNG, the flip-flops 52 directly sample the high-frequency clock pulse signal using the low-frequency clock pulse signal.
[0055] In various embodiments, the RNG 24 and its components can be implemented using any suitable hardware, such as an Application-Specific Integrated Circuit (ASIC) or a Field-Programmable Gate Array (FPGA). In other embodiments, certain functions of the RNG 24 can be implemented by a general-purpose processor that executes the functions described herein in a program in software. The software can be downloaded to the processor in electronic form, for example, via a network. Alternatively, or additionally, the software can be provided and / or stored on a non-transitory tangible medium, such as a magnetic memory, an optical memory, or an electronic memory.
[0056] Description of the random number generation method
[0057] Figure 2FIG. 0 is a flowchart of a method for generating decentralized random numbers using the RNG 24 in the IC 20, as depicted in an embodiment of the present invention. The method starts with a step 60 of generating high-frequency clock pulses, where a freely operating high-frequency clock pulse generator 40 generates a plurality of high-frequency clock pulse signals. At the same time, in a step 64 of generating low-frequency clock pulses, a freely operating low-frequency clock pulse generator 44 generates a plurality of low-frequency clock pulse signals with noise.
[0058] In a step 68 of selection, a plurality of pairs {high-frequency clock pulse signal, low-frequency clock pulse signal} are selected. In a step 72 of sequence generation, each DRNG 32 uses the {high-frequency clock pulse signal, low-frequency clock pulse signal} pair it has to generate a random digit sequence. For a given DRNG, the high-frequency clock pulse signal is used to clock the LFSR 48, and the low-frequency clock pulse signal is used to clock the flip-flop 52 (i.e., sample the LFSR output).
[0059] In a step 76 of multiplexing, a multiplexer 36 multiplexes the random digit sequences generated by the DRNGs 32 and outputs the multiplexed random digit sequences. As explained above, the multiplexing order can be deterministic or random.
[0060] It should be understood that the above embodiments are cited as examples, and the present invention is not limited to what is specifically shown or described above. On the contrary, the scope of the present invention includes combinations and sub-combinations of the various features described above, as well as variations and modifications that can be conceived by those skilled in the art upon reading the above description and that are not disclosed in the prior art. The documents incorporated by reference in this patent application should be understood as an integral part of this application, unless to the extent that any term in these incorporated documents is defined in a manner that conflicts with the definition explicitly or implicitly set forth in this specification, in which case only the definition in this specification should be considered.
Claims
1. A random number generator RNG, characterized in that, Comprising: A plurality of high-frequency clock pulse generators configured to generate a plurality of high-frequency clock pulse signals within a first frequency range; A plurality of low-frequency clock pulse generators configured to generate a plurality of low-frequency clock pulse signals within a second frequency range lower than the first frequency range; A plurality of digital random number generators DRNG, each DRNG configured to (i) a high-frequency clock pulse signal extracted from the high-frequency clock pulse signals and (ii) a low-frequency clock pulse signal extracted from the low-frequency clock pulse signals, thereby obtaining a random digit sequence; And A multiplexer configured to generate an output sequence of random digits from the random digit sequences generated by the DRNG.
2. The random number generator RNG according to claim 1, characterized in that, A given DRNG comprises: (i) A linear feedback shift register LFSR clocked by the high-frequency clock pulse signal; and (ii) A flip-flop configured to sample an output of the LFSR according to the low-frequency clock pulse signal.
3. The random number generator RNG according to claim 2, characterized in that, At least two LFSRs among the plurality of DRNGs differ from each other in one or more of the following characteristics: (i) An initial seed value, (ii) A feedback tap configuration, and (iii) A plurality of cascaded flip-flops.
4. The random number generator RNG according to claim 1, characterized in that, A given DRNG comprises: A flip-flop configured to sample the high-frequency clock pulse signal according to the low-frequency clock pulse signal.
5. The random number generator RNG according to claim 1, characterized in that, The DRNG receives different pairs of input clock pulse signals, each pair of input clock pulse signals comprising a high-frequency clock pulse signal and a low-frequency clock pulse signal.
6. The random number generator RNG according to claim 1, wherein The high-frequency clock pulse generators, the low-frequency clock pulse generators, and the DRNG are spatially dispersed over an area of an integrated circuit.
7. The random number generator RNG according to claim 1, characterized in that, Further comprising one or more analog noise sources configured to add analog noise to one or more of the low-frequency clock pulse generators and the high-frequency clock pulse generators.
8. The random number generator RNG according to claim 1, characterized in that, The multiplexer is configured to perform a multiplexing sequence of randomly alternating between the DRNGs to multiplex the random digit sequences.
9. The random number generator RNG according to claim 8, characterized in that, The multiplexer is configured to obtain the random digit sequence from selected bits of one or more of the random digit sequences.
10. The random number generator RNG according to claim 1, wherein, The high-frequency clock pulse generators and the low-frequency clock pulse generators are arranged in pairs, each pair comprising a high-frequency clock pulse generator and a low-frequency clock pulse generator.
11. The random number generator RNG according to claim 1, characterized in that, At least two of the high-frequency clock pulse generators are configured to generate high-frequency clock pulse signals having different frequencies from each other.
12. The random number generator RNG according to claim 1, characterized in that, At least two of the low-frequency clock pulse generators are configured to generate low-frequency clock pulse signals having different frequencies from each other.
13. The random number generator RNG according to claim 1, characterized in that, At least two of the high-frequency clock pulse generators are configured to be triggered at different times.
14. The random number generator RNG according to claim 1, characterized in that, At least two of the low-frequency clock pulse generators are configured to be triggered at different times.
15. A method for generating random numbers, characterized in that, Comprising: Generating a plurality of high-frequency clock pulse signals within a first frequency range; Generating a plurality of low-frequency clock pulse signals within a second frequency range lower than the first frequency range; Obtain a plurality of random digit sequences, where each of the random digit sequences is obtained from (i) one of the high-frequency clock pulse signals and (ii) one of the low-frequency clock pulse signals; and Generate an output sequence of random digits according to the random digit sequences.
16. The method for generating random numbers according to claim 15, wherein The step of obtaining a given random digit sequence among the random digit sequences includes: (i) clocking a linear feedback shift register (LFSR) by the high-frequency clock pulse signal; and (ii) sampling an output of the LFSR according to the low-frequency clock pulse signal by a flip-flop.
17. The method for generating a random number according to claim 15, wherein The step of obtaining a given random digit sequence among the random digit sequences includes: sampling the high-frequency clock pulse signal by a flip-flop according to the low-frequency clock pulse signal.
18. The method for generating random numbers according to claim 15, characterized in that, The step of generating the output sequence includes: performing a multiplexing sequence that alternates among the random digit sequences to multiplex the random digit sequences.
19. The method for generating a random number according to claim 18, wherein The step of multiplexing the random digit sequences includes: obtaining the multiplexing sequence from selected bits of one or more random digit sequences among the random digit sequences.
Citation Information
Patent Citations
Random number generator circuit
US4905176A
True random number generation method and true random number generator
CN111124363A
Pseudo random number generation device, and pseudo random number generation method
JP2013064898A