Method for controlling activation of a device and related electronic device

By combining static entropy sources and message authentication code operators with embedded keys, the problems of overproduction and unauthorized use of integrated circuits are solved, enabling secure control that allows only authorized customers to activate electronic devices.

CN114626020BActive Publication Date: 2025-12-16PUFSECURITY CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111468750.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-12-11
Filing Date
2021-12-03
Publication Date
2025-12-16
Estimated Expiration
2041-12-03

AI Technical Summary

Technical Problem

In the prior art, integrated circuits manufactured by integrated circuit design companies may be overproduced, and these overproduced integrated circuits may be used by unauthorized persons, leading to security risks.

Method used

By combining a static entropy source and a message authentication code calculator with an embedded key, the correctness of the activation code is determined by a comparison circuit, ensuring that only authorized customers can activate the electronic device.

Benefits of technology

This ensures that only those who know the correct value of the embedded key can activate the electronic device, preventing unauthorized use and avoiding the illegal activation of overproduced integrated circuits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114626020B_ABST
    Figure CN114626020B_ABST
Patent Text Reader

Abstract

A method for controlling activation of an electronic device and the related electronic device are disclosed. The method comprises: providing a static entropy by a static entropy source of the electronic device; performing a predetermined algorithm by a first message authentication code operator of the electronic device to generate a reference code based on the static entropy and an embedded key of the electronic device; receiving an activation code from outside of the electronic device; comparing the activation code with the reference code by a comparison circuit to generate a comparison result; and determining whether to activate at least one functional circuit of the electronic device based on the comparison result. The present invention can ensure that only authorized customers can activate the electronic device, and the problem of overproduction of electronic devices can be avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to device activation, and in particular, to a method for controlling device activation and an electronic device. BACKGROUND

[0002] When an integrated circuit design company completes a design of an integrated circuit, the integrated circuit will be manufactured by a third party, such as a wafer foundry. Even though the integrated circuit design company can request the wafer foundry to manufacture only a certain number of integrated circuits for the design, in practice the integrated circuits can still be overproduced. In some cases, these overproduced integrated circuits can be obtained by some people who are not authorized by the integrated circuit design company. Therefore, a novel method and an electronic device are needed to prevent the overproduced integrated circuits from being used by unauthorized people. SUMMARY

[0003] The present application provides a method for controlling device activation and an electronic device to ensure that only authorized customers can activate the electronic device.

[0004] At least one embodiment of the present application provides a method for controlling device activation. The method can include providing a static entropy by using a static entropy source of the electronic device, performing a predetermined algorithm to generate a reference code according to the static entropy and an embedded key of the electronic device by using a first message authentication code (MAC) operator of the electronic device, receiving an activation code from outside of the electronic device, comparing the activation code and the reference code by using a comparison circuit to generate a comparison result, and determining whether to activate at least one functional circuit of the electronic device according to the comparison result.

[0005] An electronic device is provided. The electronic device can include at least one functional circuit configured to perform at least one predetermined function. The electronic device can further include an authentication circuit coupled to the at least one functional circuit, wherein the authentication circuit is configured to control activation of the at least one functional circuit. The authentication circuit can include a static entropy source, a first message authentication code (MAC) operator, and a comparison circuit. The static entropy source is configured to provide a static entropy. The first MAC operator is coupled to the static entropy source and is configured to perform a predetermined algorithm to generate a reference code based on the static entropy and an embedded key of the electronic device. The comparison circuit is coupled to the first MAC operator and is configured to compare an activation code received from outside of the electronic device with the reference code to generate a comparison result. In particular, the authentication circuit can determine whether to activate the at least one functional circuit based on the comparison result.

[0006] Embodiments of the present application can ensure that only a person / device that knows the correct value of the embedded key can generate a correct activation code to activate the electronic device. In addition, since the static entropy is unique for each electronic device (e.g., different electronic devices have different static entropies), the activation code that needs to be generated based on the static entropy is specific to each electronic device. For example, an activation code for one electronic device cannot be applied to another electronic device. Thus, the present application can ensure that only an authorized customer (e.g., a person / device that knows the correct value of the embedded key) can activate the electronic device. BRIEF DESCRIPTION OF DRAWINGS

[0007] Figure 1 A schematic diagram of an electronic device coupled to an activation device according to an embodiment of the present application.

[0008] Figure 2 A schematic diagram of an electronic device not coupled to an activation device according to an embodiment of the present application. Figure 1 A schematic diagram of an electronic device coupled to an activation device according to an embodiment of the present application.

[0009] Figure 3 A schematic diagram of an electronic device coupled to an activation device according to an embodiment of the present application.

[0010] Figure 4 A schematic diagram of a static entropy source of an electronic device according to an embodiment of the present application. Figure 1 A schematic diagram of a static entropy source of an electronic device according to an embodiment of the present application.

[0011] Figure 5Fig. 1 shows a schematic diagram of a static entropy source of an electronic device according to an embodiment of the present application. Figure 1 Fig. 2 shows a schematic diagram of a static entropy source of an electronic device according to another embodiment of the present application.

[0012] Figure 6 Fig. 3 shows a schematic diagram of a server sequentially activating a plurality of electronic devices according to an embodiment of the present application.

[0013] Figure 7 Fig. 4 shows a schematic diagram of a workflow of a method for controlling device activation according to an embodiment of the present application.

[0014] Figure 8 Fig. 5 shows a schematic diagram of a workflow of an activation device for activating an electronic device according to an embodiment of the present application.

[0015] In the figures, the following reference signs are used:

[0016] 50 server

[0017] 52 message authentication code operator

[0018] 53 key

[0019] 56 counter

[0020] 56M one-time programmable element

[0021] 100, 1001, 1002, 1003, 100 N monolithic system

[0022] 110 authentication circuit

[0023] 111 static entropy source

[0024] 111P physically unclonable function source

[0025] 111R deterministic random bit generator

[0026] 111M one-time programmable device

[0027] 112 message authentication code

[0028] 113 embedded key

[0029] 114 comparison circuit

[0030] 115, 115' one-time programmable device

[0031] IP1, IP2, IP3 functional circuit

[0032] ID0, ID PUF , ID DRBG , ID N static entropy

[0033] AC0 reference code

[0034] AC1, AC X , AC N activation code

[0035] T1 input terminal

[0036] S710-S770, S810-S850 steps DETAILED DESCRIPTION

[0037] Figure 1 FIG. 1 shows a schematic diagram of an electronic device coupled to an activation device according to an embodiment of the present application. In this embodiment, the electronic device can be a system on a chip (SoC) 100, and the activation device (such as a server 50 shown) can be implemented as a server key / dongle such as a Universal Serial Bus (USB) dongle, but the present application is not limited thereto. As shown in FIG. 1, the SoC 100 can include a processor 110, a memory 120, and a bus interface 130. The SoC 100 can further include a secure boot module 140, a secure storage module 150, and a secure communication module 160. The SoC 100 can further include a secure boot module 140, a secure storage module 150, and a secure communication module 160. Figure 1 The server 50 can be implemented as a server key / dongle such as a USB dongle, but the present application is not limited thereto. As shown in FIG. 1, the server 50 can include a processor 510, a memory 520, and a bus interface 530. The server 50 can further include a server key module 540, a server key storage module 550, and a server key communication module 560. The server 50 can further include a server key module 540, a server key storage module 550, and a server key communication module 560. Figure 1As shown, the monolithic system 100 may include at least one internal circuit such as functional circuits IP1, IP2, and IP3, each of which is used to perform at least one predetermined function, such as a function requested by a customer. The monolithic system 100 may further include an authentication circuit 110 coupled to the functional circuits IP1, IP2, and IP3, and can be used to control the activation of the functional circuits IP1, IP2, and IP3. In this embodiment, the authentication circuit 110 may include a static entropy source 111, a message authentication code (MAC) arithmetic unit 112 (e.g., a message authentication code circuit), and a comparison circuit 114. The static entropy source 111 is used to provide a static entropy ID0, which can be considered as the identifier (ID) of the monolithic system 100. Message authentication code processor 112 is coupled to static entropy source 111 and is used to execute a predetermined algorithm (e.g., execute a hash function) to generate a reference code AC0 based on static entropy ID0 and an embedded key 113 of the monolithic system 100. For example, message authentication code processor 112 can use the embedded key 113 as a key and the static entropy ID0 as the message to be authenticated in the hash function to generate an authentication code such as reference code AC0, but the invention is not limited thereto. Comparison circuit 114 is coupled to message authentication code processor 112 and is used to compare activation code AC1 from outside the monolithic system 100 with reference code AC0 to generate a comparison result. In particular, authentication circuit 110 can determine whether to activate functional circuits IP1, IP2, and IP3 based on the comparison result. In particular, when the comparison result indicates that activation code AC1 matches reference code AC0, it means that activation code AC1 is a correct activation code (in Figure 1 (The code is labeled "Correct Activation Code" for ease of understanding). The authentication circuit 110 can activate functional circuits IP1, IP2, and IP3 (e.g., control the state of functional circuits IP1, IP2, and IP3 to be active). When the comparison result indicates that the activation code AC1 is inconsistent with the reference code AC0, it means that the activation code AC1 is not a correct activation code, and the authentication circuit 110 will not activate functional circuits IP1, IP2, and IP3.

[0038] In this embodiment, the single-chip system 100 receives the activation code AC1 from the server 50. For example... Figure 1As shown, server 50 may include a message authentication code arbitrator 52 and a counter 56 coupled to the message authentication code arbitrator 52. Server 50 may receive static entropy ID0 from static entropy source 111 of monolithic system 100, and message authentication code arbitrator 52 is used to execute the predetermined algorithm (e.g., execute the same hash function as message authentication code arbitrator 112) to generate activation code AC1 based on static entropy ID0 and a key 53. When the key 53 of server 50 matches the embedded key 113 of monolithic system 100, the comparison result indicates that activation code AC1 matches reference code AC0 (labeled "match" for ease of understanding), and authentication circuit 110 can thus activate functional circuits IP1, IP2, and IP3. In addition, counter 56 is used to generate a count result to indicate how many activation codes have been generated by message authentication code arbitrator 52, and thereby monitor how many electronic devices have been activated by server 50. For example, counter 56 can generate a number of activation codes from the multiple activation codes generated by message authentication code arithmetic unit 52 as the counting result.

[0039] In one embodiment, the embedded key 113 may be a password stored in a read-only memory (ROM) that is not connected to any output port of the system-on-a-chip (SoC) 100, so the password cannot be read from outside the SoC 100. In another embodiment, the embedded key 113 may be implemented as multiple bit-level units, each of which may be coupled to a relatively high voltage (corresponding to a logic value "1") or a relatively low voltage (corresponding to a logic value "0") to represent the value of the embedded key 113. It should be noted that the ROM storing the embedded key 113 is not connected to any output port of the SoC 100, so the embedded key 113 cannot be read by devices outside the SoC 100. Therefore, a circuit design company (e.g., a supplier of the SoC 100) may provide a server 50 (containing a key 53 consistent with the embedded key 113) along with the SoC 100 to authorized customers, allowing authorized customers to activate the SoC 100 using the server 50. In contrast, unauthorized users (e.g., those without server 50) cannot generate correct activation codes. Figure 2 As shown, unauthorized users will enter an incorrect activation code AC. X (exist Figure 2 (The text is marked as "Incorrect activation code" for clarity), and the comparison result indicates the activation code AC. XInconsistent with the reference code AC0 (indicated as "mismatch" for ease of understanding). Thus, the authentication circuit 110 can refrain from activating the functional circuits IP1, IP2, and IP3 in response to the result of "mismatch" (e.g., control the state of the functional circuits IP1, IP2, and IP3 to be inactive), so as to avoid the overproduced device (e.g., the overproduced monolithic system 100) from being utilized by an unauthorized person.

[0040] In addition, the authentication circuit 110 can further include a one-time programmable (OTP) device 115 (indicated as "OTP" for simplicity) coupled to the comparison circuit 114. In a first authentication procedure (e.g., an authentication procedure performed when the monolithic system 100 is first powered on or powered up), the monolithic system 100 receives the activation code AC1 from the outside (e.g., from the server 50), and the authentication circuit 110 writes the activation code AC1 into the one-time programmable device 115. The comparison circuit 114 can retrieve the activation code AC1 from the one-time programmable device 115, and generate the comparison result (e.g., a first comparison result of the first authentication procedure) to determine whether to activate the functional circuits IP1, IP2, and IP3 in the first authentication procedure. In detail, since the one-time programmable device 115 is one-time programmable, after the server 50 activates the monolithic system 100 for the first time and writes the activation code AC1 into the one-time programmable device 115, the one-time programmable device 115 can act as a read-only memory, and the functional circuits IP1, IP2, and IP3 no longer need the server 50 to be activated thereafter. For example, in a second authentication procedure (e.g., an authentication procedure performed when the monolithic system 100 is powered on or powered up next time), the comparison circuit 114 can retrieve the activation code AC1 (which is consistent with the reference code AC0) from the one-time programmable device 115 to generate another comparison result (e.g., a second comparison result of the second authentication procedure) to determine whether to activate the functional circuits IP1, IP2, and IP3 according to the other comparison result. Thus, the functional circuits IP1, IP2, and IP3 can be activated in the second authentication procedure without the server 50.

[0041] In another embodiment, the activation code AC1 from the server 50 can not be stored in the one-time programmable device 115. In detail, the monolithic system 100 includes a one-time programmable device 115' (indicated as "OTP" for simplicity) coupled to the output of the comparison circuit 114, as shown in FIG. 2B. In the first authentication procedure, the authentication circuit 110 writes the activation code AC1 into the one-time programmable device 115'. In the second authentication procedure, the comparison circuit 114 can retrieve the activation code AC1 from the one-time programmable device 115' to generate the comparison result (e.g., the second comparison result of the second authentication procedure) to determine whether to activate the functional circuits IP1, IP2, and IP3 according to the comparison result. Figure 3 Figure 3 ​As shown. The comparison circuit 114 can obtain the activation code AC1 from an external source (e.g., server 50) when the single-chip system 100 is first powered on or supplied with power (e.g., during the first authentication process described above). The authentication circuit 110 can write the comparison result generated by the comparison circuit 114 into the one-time programmable device 115'. The authentication circuit 110 can determine whether to activate functional circuits IP1, IP2, and IP3 based on the comparison result stored in the one-time programmable device 115'. Therefore, after the server 50 first activates the single-chip system 100 and the comparison result generated based on the correct activation code AC1 is written to the one-time programmable device 115', the one-time programmable device 115' can function as a read-only memory, and the functional circuits IP1, IP2, and IP3 do not require activation by the server 50 thereafter. For example, the identification circuit 110 can refer to the comparison result stored in the one-time programmable device 115' when the single-chip system 100 is next powered on or supplied (e.g., during the second identification procedure described above), and the functional circuits IP1, IP2 and IP3 can be activated based on them without the server 50.

[0042] In one embodiment, the static entropy source 111 may include, for example: Figure 4 The Physically Unclonable Function (PUF) shown is source 111P ( Figure 4 (The label is "PUF source" for simplicity), and the static entropy ID output from the physically non-replicable functional source 111P. PUF Can be used as Figure 1 The example shown is the static entropy ID0. Because the physical properties of different wafers can vary slightly due to certain uncontrollable factors during the manufacturing process, these differences cannot be replicated or predicted, and these differences are reflected in the static entropy ID output from the physically unreplicable functional source 111P. PUF Above. In another embodiment, the static entropy source 111 may include a deterministic random bit generator (DRBG) 111R ( Figure 5 (Designated as "DRBG" for brevity) and a one-time programmable device such as Figure 5 The one-time programmable device 111M shown Figure 5 (The Chinese label is "OTP" for brevity). The deterministic random bit generator 111R includes an input terminal T1, wherein the deterministic random bit generator 111R is used to receive a random number from a dynamic entropy source via the input terminal T1 to generate a sequence of random bits, and a one-time programmable device 111M is used to store the sequence of random bits output from the deterministic random bit generator 111R as a static entropy ID. DRBGOnce the sequence of random bits is written into the one-time programmable device 111M, the static entropy ID DRBG is not changed again and can be used as Figure 1 an example of the static entropy ID 0 is shown.

[0043] Figure 6 The server 50 according to an embodiment of the present application sequentially activates a plurality of electronic devices such as the single-chip systems 1001, 1002, 1003,... and 100 N , where N represents a positive integer, and each of the single-chip systems 1001, 1002, 1003,... and 100 N can be used as Figure 1 an example of the single-chip system 100 is shown. As described in the previous embodiment, only a person who has obtained / accessed the server 50 from a developer (e.g., an integrated circuit design company) of the single-chip system 100 can activate the single-chip system 100 (e.g., any one of the single-chip systems 1001, 1002, 1003,... and 100 N ). For example, when a person who is not authorized by the developer (e.g., an integrated circuit design company) of the single-chip system 100 illegally obtains any one of the single-chip systems 1001, 1002, 1003,... and 100 N , the person still cannot activate the single-chip system because the person does not have the server 50 (which includes the embedded key 113 therein) or any device having the server 50 built therein. Thus, this ensures that only an authorized person or company (who legally obtains / accesses the server 50 from the developer of the single-chip system 100 or has a device having the server 50 built therein) can activate the single-chip system 100. In this embodiment, the server 50 can further control how many electronic devices can be activated by means of the counter 56 to avoid overproduction of the electronic devices being activated. Assume that the server 50 has activated (N-1) single-chip systems, and will activate the Nth single-chip system (i.e., the single-chip system 100 N ). The message authentication code generator 52 can determine whether to output the activation code AC N to the single-chip system 100 N according to the counting result. For example, if the counting result has not reached a predetermined threshold TH AC , the message authentication code generator 52 can output the activation code AC N to the single-chip system 100 N according to the static entropy ID N and the key 53. For another example, if the counting result reaches the predetermined threshold TH AC , the message authentication code generator 52 can stop outputting the activation code AC N according to the static entropy IDAnd key 53 outputs any activation code (e.g., avoid outputting activation code AC). N ) to single-chip system 100 N Therefore, the number of electronic devices activated by server 50 can be determined by a predetermined threshold TH. AC Limitations are imposed to prevent the activation of overproduced electronic devices.

[0044] In detail, the counter 56 may include a predetermined number of one-time programmable elements 56M for recording the counting results, wherein the predetermined number may correspond to a predetermined threshold TH. AC (For example, the predetermined quantity may be equal to the predetermined threshold TH) AC Server 50 can write a specific logic value into one of the one-time programmable elements 56M each time the message authentication code arithmetic unit 52 generates an activation code. For example, server 50 can write the logic value "1" when server 50 generates a first activation code for the first monolithic system such as monolithic system 1001. Figure 6 The first one-time programmable element (IPA) from the leftmost position in the one-time programmable element 56M shown; server 50 can write the logic value "1" when server 50 generates a second activation code for a second monolithic system such as monolithic system 1002. Figure 6 The second one-time programmable element from the left in the one-time programmable element 56M shown; server 50 can write the logic value "1" when server 50 generates a third activation code for a third monolithic system such as monolithic system 1003. Figure 6 The third one-time programmable element from the left in the 56M one-time programmable element shown; and the others can be deduced in the same way, where Figure 6 Any one-time programmable element 56M that has not yet been written with the logic value "1" is shown in the diagram. Figure 6 The indicator is set to "0" for ease of understanding. When the message authentication code calculator 52 bases its input from the single-chip system 100... N Static entropy ID N And key 53 generates activation code AC N At this time, server 50 may refer to counter 56 to determine whether all one-time programmable elements 56M have stored the specific logic value (e.g., logic value "1"). For example, when the counting result indicates that at least one of the one-time programmable elements 56M has not been written with the logic value "1", server 50 (e.g., counter 56) may allow message authentication code arithmetic unit 52 to output AC normally. N To activate the single-chip system 100 N For example, when the counting result indicates that all one-time programmable elements 56M have stored the logic value "1", the message authentication code calculator 52 can stop calculating based on the static entropy ID.N and the key 53 outputs the activation code to the electronic device coupled to the server 50. In particular, the server 50 can avoid the message authentication code 52 outputting the activation code AC N to the single-chip system 100 N . Thus, after all the one-time programmable elements 56M have stored the logic value "1", the server 50 can regard any electronic device coupled to the server 50 as an overproduced electronic device, and can avoid activating the electronic device.

[0045] Figure 7 a workflow of a method for controlling activation of a device according to an embodiment of the present application, which is applicable to an electronic device such as the single-chip system 100 shown in Figure 1 . Note that one or more steps can be added, deleted, or modified in the workflow shown in Figure 7 , and these steps do not necessarily have to be performed in the order shown in Figure 7 if it does not hinder the overall result.

[0046] In step S710, the electronic device (e.g., the single-chip system 100 shown in Figure 1 ) can provide a static entropy (e.g., static entropy ID0) using a static entropy source (e.g., static entropy source 111) of the electronic device.

[0047] In step S720, the electronic device can perform a predetermined algorithm using a first message authentication code operator (e.g., message authentication code operator 112) of the electronic device to generate a reference code (e.g., reference code AC0) according to the static entropy and an embedded key (e.g., embedded key 113) of the electronic device. Figure 1

[0048] In step S730, the electronic device can receive an activation code (e.g., correct activation code from the server 50 or incorrect activation code AC X from another device) from outside of the electronic device.

[0049] In step S740, the electronic device can compare the activation code with the reference code using a comparison circuit (e.g., comparison circuit 114) to generate a comparison result. Figure 1

[0050] ​​In step S750, the electronic device may determine whether to activate at least one internal circuit (e.g., functional circuits IP1, IP2, and IP3) based on the comparison result. If the comparison result indicates that the activation code matches the reference code (e.g., AC1 and AC0 are consistent), the workflow proceeds to step S760; otherwise, if the comparison result indicates that the activation code does not match the reference code (e.g., AC1 and AC0 are consistent), the workflow proceeds to step S760. X If it is inconsistent with AC0, the workflow proceeds to step S770.

[0051] In step S760, the electronic device can activate the at least one internal circuit.

[0052] In step S770, the electronic device can avoid activating the at least one internal circuit.

[0053] Figure 8 According to an embodiment of the present invention, this is used to activate electronic devices (e.g., monolithic systems 1001, 1002, 1003, ... and 100...). N An activation device (e.g.) Figure 6 The diagram illustrates the workflow of server 50. It should be noted that one or more steps can be performed simultaneously. Figure 8 The steps shown in the workflow may be added, deleted, or modified, and do not necessarily need to be followed exactly as described. Figure 8 Execute in the order shown.

[0054] In step S810, the activation device (e.g. Figure 6 The server 50 shown can read a static entropy from an electronic device (e.g., from a single-chip system 100). N Read ID N ).

[0055] In step S820, the activation device may utilize a message authentication code calculator of the activation device (e.g., Figure 1 The message authentication code arithmetic unit 52 shown executes a predetermined algorithm (e.g., with the monolithic system 100). N The message authentication code arithmetic unit 112 executes the same algorithm as the static entropy and a key (e.g., Figure 6 The key shown in 53) generates an activation code (e.g. Figure 6 The activation code shown is AC N ).

[0056] In step S830, the activation device may refer to a counter ( Figure 6 The counter 56 shown records a counting result COUNT ACto determine whether the electronic device is allowed to output the activation code from the message authentication code generator. If the counting result COUNT AC has not reached a predetermined threshold (e.g., "COUNT AC <TH AC ", the workflow proceeds to step S840; if the counting result COUNT AC has reached the predetermined threshold (e.g., "COUNT AC <TH AC ", the workflow proceeds to step S850.

[0057] In step S840, the activation device can allow the message authentication code generator to output the activation code.

[0058] In step S850, the activation device can prevent the message authentication code generator from outputting the activation code.

[0059] In summary, the embodiments of the present application can control the device activation of an electronic device (e.g., the single-chip system 100) by means of an activation device (e.g., the server 50). In the embodiments of the present application, only the activation device is allowed to activate the electronic device, and the number of activated electronic devices can also be controlled by the method of the present application. Therefore, the present application can ensure that only the authorized customers (e.g., the activation device with the correct value of the embedded key in the electronic device) are allowed to activate the electronic device, and the problem of overproduction of electronic devices can be avoided. In addition, the embodiments of the present application do not substantially increase the additional cost. Therefore, the present application can solve the problems of the related art without or with less side effects.

[0060] The above descriptions are only the preferred embodiments of the present application, and are not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for controlling activation of a device, the method comprising: Comprising: providing a static entropy with an electronic device; performing a predetermined algorithm with a first message authentication code operator of the electronic device to generate a reference code from the static entropy and an embedded key of the electronic device; receiving an activation code from outside the electronic device; comparing the activation code with the reference code with a comparison circuit to generate a comparison result; and determining whether to activate at least one functional circuit of the electronic device according to the comparison result; wherein the electronic device is coupled to an activation device, and the method further comprises: receiving the static entropy from the electronic device with the activation device; performing the predetermined algorithm with a second message authentication code operator of the activation device to generate the activation code from the static entropy and a key, wherein when the key is identical to the embedded key of the electronic device, the comparison result indicates that the activation code is identical to the reference code, and the at least one functional circuit is activated; and generating a count result with a counter to indicate how many activation codes have been generated by the second message authentication code operator.

2. The method of claim 1, wherein, The at least one functional circuit is activated when the comparison result indicates that the activation code is identical to the reference code.

3. The method of claim 1, wherein, The static entropy source comprises a physically unclonable function source.

4. The method of claim 1, wherein, The providing of the static entropy with the electronic device comprises: generating a sequence of random bits with a deterministic random bit generator; and storing the sequence of random bits as the static entropy with a one-time programmable device.

5. The method of claim 1, wherein, The activation code is received in a first authentication procedure, and the comparison result is generated in the first authentication procedure to determine whether to activate the at least one functional circuit, and the method further comprises: writing the activation code into a one-time programmable device of the electronic device in the first authentication procedure; after determining whether to activate the at least one functional circuit in the first authentication procedure, retrieving the activation code from the one-time programmable device with the comparison circuit in a second authentication procedure; comparing the activation code from the one-time programmable device with the reference code with the comparison circuit in the second authentication procedure to generate another comparison result; and determining whether to activate the at least one functional circuit according to the another comparison result in the second authentication procedure.

6. The method of claim 1, wherein, Further comprising: writing the comparison result into a one-time programmable device of the electronic device; wherein the determining whether to activate the at least one functional circuit of the electronic device according to the comparison result comprises determining whether to activate the at least one functional circuit according to the comparison result stored in the one-time programmable device.

7. The method of claim 1, wherein, The second message authentication code operator stops outputting the activation code to the electronic device from the key and the static entropy when the count result reaches a predetermined threshold.

8. The method of claim 7, wherein, The generating of the count result with the counter to indicate how many activation codes have been generated by the second message authentication code operator comprises: A specific logic value is written into one of a predetermined number of one-time programmable elements in the counter when the second message authentication code generator generates an activation code, wherein the predetermined number corresponds to the predetermined threshold, and the second message authentication code generator stops outputting the activation code to the electronic device based on the key and the static entropy when all of the one-time programmable elements have stored the specific logic value.

9. An electronic device, comprising: Comprising: at least one functional circuit for performing at least one predetermined function; and an authentication circuit coupled to the at least one functional circuit for controlling activation of the at least one functional circuit, wherein the authentication circuit comprises: a static entropy source for providing a static entropy; a first message authentication code generator coupled to the static entropy source for performing a predetermined algorithm to generate a reference code based on the static entropy and an embedded key of the electronic device; and a comparison circuit coupled to the first message authentication code generator for comparing an activation code received from outside of the electronic device with the reference code to generate a comparison result; wherein the authentication circuit determines whether to activate the at least one functional circuit based on the comparison result wherein the electronic device is coupled to an activation device, and the activation device comprises: a second message authentication code generator for performing the predetermined algorithm to generate the activation code based on the static entropy read from the static entropy source of the electronic device and a key, wherein when the key is identical to the embedded key of the electronic device, the comparison result indicates that the activation code is identical to the reference code, and the authentication circuit activates the at least one functional circuit; and a counter coupled to the second message authentication code generator for generating a count result to indicate how many activation codes have been generated by the second message authentication code generator. 10.The electronic device of claim 9, wherein, The authentication circuit activates the at least one functional circuit when the comparison result indicates that the activation code is identical to the reference code. 11.The electronic device of claim 9, wherein The static entropy source comprises a physically unclonable function source. 12.The electronic device of claim 9, wherein, The static entropy source comprises: a deterministic random bit generator for generating a sequence of random bits; and a one-time programmable device for storing the sequence of random bits as the static entropy. 13.The electronic device of claim 9, wherein, The activation code is received in a first authentication procedure, the comparison result is generated in the first authentication procedure for determining whether to activate the at least one functional circuit, and the authentication circuit further comprises: a one-time programmable device coupled to the comparison circuit; wherein the authentication circuit writes the activation code into the one-time programmable device in the first authentication procedure; after determining whether to activate the at least one functional circuit in the first authentication procedure, the comparison circuit retrieves the activation code from the one-time programmable device using the comparison circuit in a second authentication procedure; the comparison circuit compares the activation code from the one-time programmable device with the reference code to generate another comparison result in the second authentication procedure; and the authentication circuit determines whether to activate the at least one functional circuit according to the another comparison result in the second authentication procedure. 14.The electronic device of claim 9, wherein, The authentication circuit further comprises: a one-time programmable device coupled to the comparison circuit; wherein the authentication circuit writes the comparison result into the one-time programmable device, and determines whether to activate the at least one functional circuit according to the comparison result stored in the one-time programmable device. 15.The electronic device of claim 9, wherein, The second message authentication code generator stops outputting the activation code to the electronic device according to the key and the static entropy when the count result reaches a predetermined threshold.

16. The electronic device of claim 15, wherein, The counter comprises: a predetermined number of one-time programmable elements for recording the count result, wherein the predetermined number corresponds to the predetermined threshold; wherein the activation device writes a specific logic value into one of the one-time programmable elements each time the second message authentication code generator generates an activation code, and the second message authentication code generator stops outputting the activation code to the electronic device according to the key and the static entropy when all of the one-time programmable elements have stored the specific logic value.

Citation Information

Patent Citations

  • Device authentication using physically unclonable function based key generation system

    CN104838385A

  • Hardware device and authorization method therefor

    CN108604275A