Random number generator

By introducing a combined architecture of first-stage and second-stage generators into the random number generator, using static entropy sources and dynamic entropy sources, the problems of existing random number generators in terms of randomness and repetitive patterns are solved, and efficient and excellent quality random number generation is achieved.

CN114978470BActive Publication Date: 2025-06-24PUFSECURITY CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210123872.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-10-08
Filing Date
2022-02-10
Publication Date
2025-06-24
Estimated Expiration
2042-02-10

AI Technical Summary

Technical Problem

Existing random number generators have challenges in improving the overall effectiveness of random number generators, especially true random number generators require high-quality entropy sources, while pseudo-random number generators face the problem of repeated patterns.

Method used

A random number generator is designed, including the first and second stage generators. The first stage generator outputs preliminary random numbers through the static entropy source and the refresh circuit. The second stage generator further processes through the reseed circuit and the dynamic entropy source to finally output high-quality random numbers.

Benefits of technology

Through this architecture, the randomness quality of random numbers is significantly improved and the field of random numbers is expanded. Compared with the pseudo-random number generator of related technologies, the output random numbers are of higher quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114978470B_ABST
    Figure CN114978470B_ABST
Patent Text Reader

Abstract

The present invention discloses a random number generator. The random number generator includes a first-stage generator and a second-stage generator. The first-stage generator outputs a first random number and a second random number at a first time point and a second time point respectively, and the second-stage generator generates a final output based at least on the first random number. In particular, the second-stage generator includes a reseeding circuit for generating a reseeding signal to control whether to generate the final output based on the second random number. When the second-stage generator generates the final output in a current data cycle without using the second random number, the first-stage generator retains the second random number for generating the final output in the next data cycle. The quality of the random numbers generated by the random number generator with multi-stage processing according to the present invention can be greatly improved, and the field of the random numbers can be greatly extended. Therefore, the quality of the random numbers generated based on the pseudo-random number generation mode can also be greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a random number generation mechanism, and more particularly to a random number generator. Background Art

[0002] Random number generators are widely used in electronic systems to implement functions related to information security. Various random number generation mechanisms have been proposed in the related art to generate random numbers, but these random number generation mechanisms have certain problems. For example, a true random number generator requires at least one entropy source to generate random numbers, but the quality of the entropy source regarding randomness is typically not sufficient to pass the test items defined by the National Institute of Standards and Technology (NIST)

[0003] SP800-90B (such as the power-on test). In addition, compared with true random number generators, although pseudo-random number generators can provide a higher random number output rate, the repeating patterns of the random numbers generated by the pseudo-random number generators in the related art are problems that need to be solved.

[0004] Therefore, a novel architecture of a random number generator and related random number generation methods are needed to improve the quality related to the randomness of the generated random numbers. Summary of the Invention

[0005] An object of the present invention is to provide a random number generator to solve the problem of improving the overall performance of the random number generator without side effects or with fewer side effects.

[0006] At least one embodiment of the present invention provides a random number generator, wherein the random number generator includes a first-stage generator and a second-stage generator coupled to the first-stage generator. The first-stage generator is used to output a first preliminary random number and a second preliminary random number among a plurality of preliminary random numbers, wherein the first preliminary random number is output at a first time point, and the second preliminary random number is output at a second time point. The second-stage generator is used to generate a final output at least based on the first preliminary random number. In particular, the second-stage generator includes a reseed circuit to generate a reseed signal, wherein the reseed signal is used to control whether to generate the final output based on the second preliminary random number. In addition, when the second-stage generator generates the final output in a current data cycle of the second-stage generator without using the second preliminary random number, the first-stage generator retains the second preliminary random number for generating the final output in the next data cycle of the second-stage generator.

[0007] At least one embodiment of the present invention provides a random number generator, wherein the random number generator includes a dynamic entropy source, a first-stage generator, and a second-stage generator. The dynamic entropy source is used to provide a first dynamic entropy bit. The first-stage generator includes a static entropy source and a refresh circuit. The static entropy source is used to output a first static entropy number and a second static entropy number respectively according to a first address and a second address, and the refresh circuit is used to generate a refresh signal, wherein the first-stage generator generates a first preliminary random number and a second preliminary random number among a plurality of preliminary random numbers at least according to the first static entropy number, and the refresh signal is used to control whether to generate any one of the plurality of preliminary random numbers according to the second static entropy number. In particular, the first preliminary random number is generated at a first time point, and the second preliminary random number is generated at a second time point after the first time point. The second-stage generator is coupled to the first-stage generator and is used to generate a final output at least according to the first preliminary random number. The second-stage generator includes a reseeding circuit to generate a reseeding signal according to the first dynamic entropy bit, wherein the reseeding signal is used to control whether to generate the final output according to the second preliminary random number.

[0008] By means of the output control mechanism of the first-stage generator, the quality of the random numbers generated by the random number generator provided by the embodiment of the present invention can be greatly improved. In addition, the field of the random numbers can be greatly extended. Therefore, compared with the pseudo-random number generator of the related art, when the random number generator of the present invention operates in a pseudo-random number mode, the random numbers output from the random number generator can have better quality. Brief Description of the Drawings

[0009] Figure 1 Schematic diagram of a random number generator according to an embodiment of the present invention.

[0010] Figure 2 According to an embodiment of the present invention Figure 1 The operation workflow of the shown random number generator.

[0011] Figure 3 A divergence scheme of a true random number generation mode according to an embodiment of the present invention.

[0012] Figure 4 A divergence scheme of a pseudo-random number generation mode according to an embodiment of the present invention.

[0013] Figure 5 Output scheme of a random nature generator based on physical unclonable function (abbreviation: PUF) according to an embodiment of the present invention without any random nature retention mechanism.

[0014] Figure 6 The workflow of a random number generation method according to an embodiment of the present invention.

[0015] Figure 7 According to an embodiment of the present invention, Figure 1 A schematic diagram of certain signals related to the random number generator shown.

[0016] Figure 8 According to another embodiment of the present invention, Figure 1 A schematic diagram of certain signals related to the random number generator shown.

[0017] Figure 9 The output scheme of the PUF-based random essence generator according to an embodiment of the present invention when having a random essence retention mechanism.

[0018] Figure 10 According to an embodiment of the present invention, Figure 1 Certain details of the PUF-based random essence generator shown.

[0019] Figure 11 The output scheme of the PUF numbers read from the PUF array according to an embodiment of the present invention.

[0020] Figure 12 According to an embodiment of the present invention, Figure 10 A schematic diagram of certain signals related to the PUF-based random essence generator shown.

[0021] Among them, the reference numerals are explained as follows:

[0022] 10 Random number generator

[0023] 20 Dynamic entropy source

[0024] 50 Random number extractor

[0025] 51 First linear feedback shift register

[0026] 52 New stage generator

[0027] 53 Reseeding control circuit

[0028] 54 Processing circuit

[0029] 100 PUF-based random essence generator

[0030] R1, R2 Registers

[0031] OUT PREG 、OUT R1 、OUT R2 、OUT LFSR1 、OUTRNG Random number

[0032] B DYN1 , B DYN2 Dynamic entropy bit

[0033] MODE CTRL Mode control signal

[0034] EN RESEED1 Reseed enable signal

[0035] Steps S21~S26

[0036] States S0, S1a, S1b, S2a~S2d, SNa~SNb

[0037] States T1a~T1d, T2a~T2h, P1a~P1b, P2a~P2b

[0038] Random numbers RE[1]~RE[9]

[0039] Steps S61~S65

[0040] CLK master clock

[0041] Random numbers L1~L7, L5’, L6’, L7’

[0042] Random number RN1

[0043] 110 PUF array

[0044] 120 Address counter

[0045] 130 Second linear feedback shift register

[0046] 140 Stage refresh circuit

[0047] 150 Processing circuit

[0048] 160 Essential retention logic

[0049] CLK PREG Internal clock

[0050] ADDR X , ADDR Y , ADDR Z Address

[0051] PUF X , PUF Y , PUF Z Number of PUF

[0052] OUT LFSR2 Random number

[0053] STAGE NEW New random number

[0054] EN RESEED2 Reseeding enabling signal

[0055] EN REFRESH Refresh enabling signal

[0056] P X [1] to P X

[32] , P Y [1] to P Y

[32] , P Z [1] PUF number

[0057] D 1,1 ~D 32,32 Data Detailed implementation manners

[0058] Figure 1 FIG. is a schematic diagram of a random number generator 10 according to an embodiment of the present invention. As Figure 1 shown, the random number generator 10 may include a dynamic entropy source 20, a first-stage generator such as a random essence generator 100 based on a Physical Unclonable Function (PUF for short) (hereinafter referred to as PREG100), and a second-stage generator such as a random number extractor 50, wherein the random number extractor 50 is coupled to the dynamic entropy source 20 and the PREG 100. The dynamic entropy source 20 is used to provide at least one dynamic entropy bit, for example, to provide a dynamic entropy bit B DYN1 to the random number extractor 50 and provide a dynamic entropy bit B DYN2 to the PREG 100. The dynamic entropy bits output from the dynamic entropy source 20 can dynamically vary between a first logical value and a second logical value in a random and unpredictable manner (for example, vary between "0" and "1"). The dynamic entropy source 20 can be implemented by any component that can output an unpredictable and random signal. Examples of the dynamic entropy source 20 may include (but are not limited to) thermal noise sampling circuits, timing perturbation sampling circuits (such as ring oscillators), metastability of static random access memory cells, and the like.

[0059] In some embodiments, the dynamic entropy bit B DYN1 and the dynamic entropy bit B DYN2 may be consistent with each other (for example, the dynamic entropy source 20 provides the same dynamic entropy bit to both the PREG 100 and the random number extractor 50). In some embodiments, the dynamic entropy bit B DYN1 and the dynamic entropy bit B DYN2may be different from each other, and even in the case where one of the dynamic entropy bits B DYN1 and the dynamic entropy bit B DYN2 is cracked, as long as the other one is not cracked, there can be at least one dynamic entropy bit involved therein and thus ensure the randomness of the overall operation of the random number generator 10. For example, when the dynamic entropy bit B DYN1 is cracked but the dynamic entropy bit B DYN2 is not cracked, the randomness of the operation of the PREG 100 (to be described in the subsequent paragraphs) can be ensured. Another example, when the dynamic entropy bit B DYN2 is cracked but the dynamic entropy bit B DYN1 is not cracked, the randomness of the operation of the random number extractor 50 can be ensured.

[0060] In this embodiment, the PREG 100 is used to output a plurality of preliminary random numbers such as the preliminary random number OUT PREG , where the preliminary random number OUT PREG output at a first time point can be used as a first preliminary random number, and the preliminary random number OUT PREG output at a second time point can be used as a second preliminary random number. The random number extractor 50 is used to generate a final output such as the random number OUT RNG at least based on the first preliminary random number. As Figure 1 shown, the random number extractor 50 may include registers R1 and R2, a first linear feedback shift register (LFSR) 51 (labeled as "LFSR-1" in Figure 1 for simplicity), a new stage generator 52 such as an exclusive OR logic, a reseeding circuit such as a reseeding control circuit 53, and a processing circuit 54 (represented by a circle with a "+" marked therein for simplicity).

[0061] For example, at a time point t = 1 (e.g., in a first output cycle of the PREG 100), the random number OUT PREG output from the PREG100 is RE[1]; at a time point t = 2 (e.g., in a second output cycle of the PREG 100), the random number OUT PREG output from the PREG 100 is RE[2], and RE[1] is stored in the register R1 (e.g., the random number OUT R1 output from the register R1 is RE[1]); and at a time point t = 3 (e.g., in a third output cycle of the PREG 100), the random number OUT PREGFor RE[3], RE[2] is stored in register R1 (e.g., the random number OUT output from register R1 R1 is RE[2]), and RE[1] is stored in register R2 (e.g., the random number OUT output from register R2 R2 is RE[1]). The random numbers OUT R1 and OUT R2 (e.g., RE[1] and RE[2]) can be examples of the first preliminary random numbers, and the random number OUT PREG (e.g., RE[3]) at time point t = 3 can be an example of the second preliminary random number.

[0062] The reseeding control circuit 53 is used to generate a reseeding enable signal EN DYN1 based on the dynamic entropy bit B RESEED1 . For example, the reseeding control circuit 53 can generate the reseeding enable signal EN DYN1 based on the dynamic entropy bit B RNG and the random number OUT RESEED1 , especially the reseeding enable signal EN RESEED1 can be an exclusive - OR result of a predetermined bit in the dynamic entropy bit B DYN1 and the random number OUT RNG (e.g., the L - th bit of the random number OUT RNG , where L is a positive integer), but the present invention is not limited thereto. Based on the processing of the reseeding control circuit 53, low - quality dynamic entropy (e.g., the occurrence rates of "0" and "1" are unbalanced) such as the dynamic entropy bit B DYN1 can be mixed with high - quality random bits (e.g., the occurrence rates of "0" and "1" are approximately equal) such as the L - th bit in the random number OUT RNG to generate high - quality random control bits with dynamic entropy involved therein.

[0063] In this embodiment, the reseeding enable signal EN RESEED1 is used to control whether to generate the random number OUT RNG based on the second preliminary random number. Specifically, the reseeding enable signal EN RESEED1 is used to control whether to reseed the first linear feedback shift register 51 with the second preliminary random number to generate an output (e.g., the random number OUT LFSR1) Note that the initial state of the linear feedback shift register can be determined by an initial seed, and its output bits are a linear function of its previous state. Preferably, the linear function is defined by a primitive polynomial, which enables the state of the linear feedback shift register (e.g., the output of the linear feedback shift register) to be switched according to a predetermined rule of the primitive polynomial. The first linear feedback shift register 51 can be an example of the linear feedback shift register and is used to output a linear feedback shift register random number such as the random number OUT LFSR1 . When the reseeding enable signal EN RESEED1 is shown as a first logic value (e.g., "0"), the first linear feedback shift register 51 can output the random number OUT according to a first predetermined rule (a rule corresponding to a first primitive polynomial) without using a second preliminary random number such as RE[3] LFSR1 , that is, the first linear feedback shift register 51 is not reseeded. When the reseeding enable signal EN RESEED1 is shown as a second logic value (e.g., "1"), the first linear feedback shift register 51 can output the random number OUT according to the second preliminary random number LFSR1 . Specifically, the new stage generator 52 can generate a new seed according to the second preliminary random number such as RE[3] and the random number OUT RNG (for example, the new seed can be the exclusive OR result of RE[3] and the random number OUT RNG ), and the new seed can be written into the first linear feedback shift register 51 as its next state when the reseeding enable signal EN RESEED1 is shown as the second logic value (e.g., "1"), and this operation can be called reseeding the first linear feedback shift register 51. In addition, the processing circuit 54 is used to generate the random number OUT R1 , OUT R2 and OUT LFSR1 to generate the random number OUT RNG . For example, the processing circuit 54 can perform an exclusive OR operation on the random number OUT R1 and OUT R2 to generate a preliminary exclusive OR result, and then perform an exclusive OR operation on this preliminary exclusive OR result and the random number OUT LFSR1 to generate the random number OUT RNG , but the present invention is not limited thereto

[0064] In this embodiment, during an initial program of the random number generator 10, the reseeding control circuit 53 generates the reseeding enable signal EN according to the dynamic entropy bit B DYN1 during multiple data cycles of the random number extractor 50 RESEED1During an output program of the random number generator 10 after the initial program, the random number generator 10 determines whether to operate in a true random number generating (TRNG) mode or a pseudo random number generating (PRNG) mode according to a mode control signal MODE. CTRL Specifically, the PREG 100 and the reseeding control circuit 53 can receive the mode control signal MODE CTRL to determine whether to operate in the pseudo random number generating mode or the true random number generating mode. When the random number generator 10 operates in the true random number generating mode (for example, when the mode control signal MODE CTRL is shown as the logical value "0"), the reseeding control circuit 53 can generate the reseeding enable signal EN DYN1 according to the dynamic entropy bit B as described above. RESEED1 When the random number generator 10 operates in the pseudo random number generating mode (for example, when the mode control signal MODE CTRL is shown as the logical value "1"), the reseeding control circuit 53 can generate the reseeding enable signal EN DYN1 without using the dynamic entropy bit B RESEED1 (for example, the reseeding control circuit 53 can output the predetermined bit in the above-mentioned random number OUT RNG as the reseeding enable signal EN RESEED1 ).

[0065] In some embodiments, a quality inspection circuit (not shown) in the random number generator 10 can be coupled to the processing circuit 54 to receive the random number OUT RNG and check the quality of the random number OUT RNG (for example, check whether the hamming weight of the random number OUT RNG meets a predetermined standard). If the hamming weight of the random number OUT RNG does not meet the predetermined standard, the quality inspection circuit can issue a warning to the outside of the random number generator 10 to notify the processor coupled to the random number generator 10 that the random number OUT RNG is unavailable at this time. In some embodiments, when the processor coupled to the random number generator 10 receives a warning from the quality inspection circuit, the processor can transmit a reset signal to reset or restart the random number generator 10, but the present invention is not limited thereto.

[0066] Figure 2 is according to an embodiment of the present invention Figure 1The operation workflow of the random number generator 10 shown, where the workflow is applicable to Figure 1 the random number generator 10 shown. It should be noted that one or more steps can be Figure 2 added, deleted, or modified in the workflow shown, and these steps do not have to be executed exactly in the Figure 2 order shown if it does not prevent the achievement of the overall result. For example, the above quality inspection can be added to the workflow if necessary.

[0067] In step S21, after the random number generator 10 is powered on, the random number generator 10 can use an initial reseeding determination with dynamic entropy to make the output of the first linear feedback shift register 51 diverge step by step. This step can be an example of the above initial procedure and is labeled as "Linear feedback shift register level divergence: Initial reseeding determination using dynamic entropy" in Figure 2 for clarity.

[0068] In step S22, after the field of the output of the first linear feedback shift register 51 has been extended to a certain extent, the random number generator 10 can decide whether to operate in the pseudo-random number generation mode or the true random number generation mode according to the mode control signal MODE CTRL . This step is labeled as "Mode selection: PRNG / TRNG" in Figure 2 for clarity. If the pseudo-random number generation mode ( Figure 2 labeled as "PRNG" for clarity) is selected, the workflow proceeds to step S23; and if the true random number generation mode ( Figure 2 labeled as "TRNG" for clarity) is selected, the workflow proceeds to step S25. Step S22 and subsequent steps can be examples of the above output procedure.

[0069] In step S23, the random number generator 10 can start outputting pseudo-random numbers.

[0070] In step S24, the random number generator 10 can control the reseeding control circuit 53 to generate a reseeding enable signal EN DYN1 without using the dynamic entropy bit B RESEED1 (for example, using the predetermined bit in the random number OUT RNG as the reseeding enable signal EN RESEED1 ), and this step is labeled as "Reseeding determination without dynamic entropy".

[0071] In step S25, the random number generator 10 can start outputting true random numbers.

[0072] In step S26, the random number generator 10 can control the reseeding control circuit 53 according to the dynamic entropy bit B DYN1 to generate a reseeding enable signal EN RESEED1 (for example, taking the exclusive - OR result of the predetermined bit in the dynamic entropy bit B DYN1 and the random number OUT RNG as the reseeding enable signal EN RESEED1 ), and this step is labeled as "reseeding determination with dynamic entropy".

[0073] Figure 3 is a divergence scheme of a true random number generation mode according to an embodiment of the present invention. Assume that S0 represents the initial seed of the first linear feedback shift register 51, and this initial seed can diverge into two states S1a and S1b respectively in response to the case of no reseeding and the case of reseeding. When the state of the first linear feedback shift register 51 is S1a, the state S1a can diverge into two states S2a and S2b respectively in response to the case of no reseeding and the case of reseeding. When the state of the first linear feedback shift register 51 is S1b, the state S1b can diverge into two states S2c and S2d respectively in response to the case of no reseeding and the case of reseeding. Therefore, after N - level divergence, the initial seed S0 can diverge into 2 N states such as SNa to SNb, and the random number generator 10 can start to output random numbers. When the state of the first linear feedback shift register 51 is SNa, the output of the random number generator 10 can diverge into two states T1a and T1b respectively in response to the case of no reseeding and the case of reseeding. When the state of the first linear feedback shift register 51 is SNb, the output of the random number generator 10 can diverge into two states T1c and T1d respectively in response to the case of no reseeding and the case of reseeding. Random numbers T2a - T2h can be obtained by similar divergence methods and are not repeated here for simplicity. As Figure 3 shown, the random number generator 10 can continuously extend the field of its output by means of the above - mentioned reseeding determination mechanism in the true random number generation mode.

[0074] Figure 4 is a divergence scheme of a pseudo - random number generation mode according to an embodiment of the present invention, where the details of the initial N - level divergence in the pseudo - random number generation mode are the same as those in the true random number generation mode and are not repeated here for simplicity. After the completion of the initial N - level divergence, the random number generator 10 can stop using the dynamic entropy bit B DYN1 to control whether to reseed the first linear feedback shift register 51. Therefore, the reseeding determination is only determined by the static entropy, where this static entropy can be related to the divergence result of the initial N - level divergence, and after the random number generator 10 stops using the dynamic entropy bit B DYN1Control whether reseeding the first linear feedback shift register 51 will no longer change (stop diverging) after that. Since the reseeding determination for the first linear feedback shift register 51 is no longer affected by any dynamic entropy, the first linear feedback shift register 51 can act as a static entropy source. In some embodiments, this static entropy source may be related to the static entropy implemented by the PUF array and will be further described in subsequent paragraphs related to the details of Figure 10 the PREG 100 shown. Since dynamic entropy is no longer involved in the above reseeding determination, the output of random numbers for each state of the first linear feedback shift register 51 (such as any one of SNa to SNb) can have a single modality (such as P1a to P2a for state SNa and P1b to P2b for state SNb) and will no longer diverge. Although the random number generator 10 operating in the pseudo-random number generation mode cannot continuously extend the field of its output after the initial N-stage divergence is completed, the output of random numbers can be performed without spending time collecting dynamic entropy, so a higher output rate can be achieved compared to the true random number generation mode.

[0075] To improve the performance related to the power on test, the PREG 100 can have a random-essence-hold mechanism. Specifically, when the random number extractor 50 generates a random number OUT in a current data cycle (such as the T-th data cycle) of the random number extractor 50 without using a second preliminary random number (such as RE[3]) RNG the PREG 100 can retain the second preliminary random number (such as RE[3]) for generating a random number OUT in the next data cycle (such as the (T + 1)-th data cycle) of the random number extractor 50 RNG .

[0076] Figure 5 This is the output scheme of the PREG 100 according to an embodiment of the present invention without a random-essence-hold mechanism (for example, when the random-essence-hold mechanism is disabled). To facilitate understanding of the impact of low-quality dynamic entropy bits B DYN2 assuming that the PREG 100 outputs random numbers only based on the static entropy therein (such as the static entropy source such as the PUF array therein). After the first power-on of the random number generator 10, the PREG 100 sequentially outputs random numbers RE[1], RE[2], RE[3], RE[4], RE[5], RE[6], RE[7], RE[8], and RE[9], where the random numbers RE[1], RE[2], and RE[3] are used to generate a random number OUT in a first data cycle (such as T = 1) RNG, RE[4], RE[5], and RE[6] are used to generate a random number OUT during a second data cycle (e.g., T = 2). RNG , and RE[7], RE[8], and RE[9] are used to generate a random number OUT during a third data cycle (e.g., T = 3). RNG . After the random number generator 10 is powered on for the second time, the PREG 100 will generate an output similar to or the same as that during the first power-on due to the low quality of the dynamic entropy bit B. DYN2 That is, the components used to generate the random number OUT during the T-th cycle after the first power-on RNG can be similar to or consistent with the components used to generate the random number OUT during the T-th cycle after the second power-on, RNG and thus the random number OUT RNG cannot pass the power-on test. Therefore, the randomness retention mechanism is preferably enabled.

[0077] Figure 6 is a workflow of a random number generation method according to an embodiment of the present invention, where the workflow can be applied to a random number generator (e.g., Figure 1 the random number generator 10 shown). It should be noted that one or more steps can be added, deleted, or modified in the Figure 6 shown workflow, and these steps do not have to be executed exactly in the Figure 6 shown order if it does not prevent the achievement of the overall result.

[0078] In step S61, the random number generator can provide a first dynamic entropy bit using a dynamic entropy source.

[0079] In step S62, the random number generator can output a preliminary random number using a first-stage generator, where the preliminary random number output at the first time point is used as a first preliminary random number, and the preliminary random number output at the second time point is used as a second preliminary random number.

[0080] In step S63, the random number generator can generate a final random number using a second-stage generator based at least on the first preliminary random number.

[0081] In step S64, the random number generator can use a reseeding circuit to generate a reseeding signal based on the first dynamic entropy bit, where the reseeding signal is used to control whether to generate the final random number based on the second preliminary random number.

[0082] In step S65, when the second-stage generator generates the final random number in a current data cycle of the second-stage generator without using the second preliminary random number, the random number generator can utilize the first-stage generator to retain the second preliminary random number for use in generating the final random number in the next data cycle of the second-stage generator.

[0083] For ease of understanding, please refer to Figure 7 , which is a schematic diagram of certain signals (such as the main clock CLK of the random number generator 10, the reseed enable signal EN Figure 1 , the random number OUT RESEED1 , OUT LFSR1 , OUT PREG , and OUT RNG , and the dynamic entropy bit B DYN1 ) related to the random number generator 10 according to an embodiment of the present invention. It should be noted that the random number OUT RNG is additionally synchronized by an output clock of the random number extractor 50, such that the random number OUT RNG is updated once every four cycles of the main clock CLK, wherein the random number OUT RNG generated in the current data cycle of the output clock is output in the next data cycle of the output clock. After the random number generator 10 is powered on and before the main clock CLK starts to switch, the random number OUT LFSR1 is in an initial state (such as the initial seed of the first linear feedback shift register 51). The dynamic entropy bit B DYN1 can switch randomly between "0" and "1" (marked as "H / L" in Figure 7 for ease of understanding). In the embodiment of Figure 7 , since the reseed enable signal EN RESEED1 is maintained at "0", the random number OUT LFSR1 output from the first linear feedback shift register 51 is switched according to the first predetermined rule (such as the first linear feedback shift register 51 sequentially outputs L1, L2, L3, L4, L5, L6, and L7 in cycles marked "t = 1", "t = 2", "t = 3", "t = 4", "t = 5", "t = 6", and "t = 7") without any reseeding operation. PREG 100 sequentially outputs random numbers RE[1], RE[2], and RE[3], wherein the random number OUT RNG (such as the random number RN1 output in the cycle marked "t = 5") is generated in a current data cycle without using the random number RE[3], and PREG 100 can retain the random number RE[3] as shown in Figure 7 to allow the random number RE[3] to be used to generate the random number OUT RNG。

[0084] Please refer to Figure 8 , which is related to certain signals (such as the main clock CLK of the random number generator 10, the reseeding enable signal EN Figure 1 shown in FIG. ) associated with the random number generator 10 according to another embodiment of the present invention RESEED1 , the random number OUT LFSR1 , OUT PREG and OUT RNG , and the dynamic entropy bit B DYN1 ). Compared with the embodiment shown in Figure 7 , Figure 8 the reseeding enable signal EN shown in RESEED1 is shown as "1" in the cycle marked "t = 4", and the first linear feedback shift register 51 is thus reseeded and outputs the random number L5' in the cycle marked "t = 5", where the random number OUT LFSR1 is L6' and L7' respectively in the cycles marked "t = 6" and "t = 7". In addition, since Figure 8 the reseeding enable signal EN shown in RESEED1 is shown as "1" in the cycle marked "t = 4", which means that the random number OUT RNG (such as the random number R1 output in the cycle marked "t = 5") is generated based on the random numbers RE[1], RE[2] and RE[3], so PREG 100 outputs the random numbers RE[4], RE[5] and RE[6] respectively in the cycles marked "t = 5", "t = 6" and "t = 7".

[0085] Figure 9 is the output scheme of PREG 100 according to an embodiment of the present invention with a randomness retention mechanism (for example, when the randomness retention mechanism is enabled). In a first data cycle (for example, T = 1) after the first power-on, PREG 100 outputs the random numbers RE[1], RE[2] and RE[3], where it is assumed that the reseeding enable signal EN RESEED1 is shown as "1" in the first data cycle, which means that the random number OUT LFSR1 is generated based on the random number RE[3]. Therefore, the random number OUT RNG in the first data cycle is based on the random numbers RE[1] and RE[2] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated based on the random number RE[3]). In a second data cycle (for example, T = 2) after the first power-on, PREG 100 further outputs the random numbers RE[4], RE[5] and RE[6], where it is assumed that the reseeding enable signal EN RESEED1is shown as "0" in the second data cycle, which means the random number OUT RNG is generated without using the random number RE[6], and the PREG 100 can reserve the random number RE[6] for use in a third data cycle (e.g., T = 3) after the first power-on. Therefore, in the second data cycle, the random number OUT RNG is based on the random numbers RE[4] and RE[5] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated without using the random number RE[6]). In the third data cycle after the first power-on, the PREG 100 additionally outputs the random numbers RE[7] and RE[8], where it is assumed that the reseeding enable signal EN RESEED1 is shown as "1" in the third data cycle, which means the random number OUT LFSR1 is generated based on the random number RE[8]. Therefore, in the third data cycle, the random number OUT RNG is based on the random numbers RE[6] and RE[7] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated based on the random number RE[8]).

[0086] In contrast, in a first data cycle (e.g., T = 1) after the second power-on, the PREG 100 outputs the random numbers RE[1], RE[2], and RE[3], where it is assumed that the reseeding enable signal EN RESEED1 is shown as "0" in the first data cycle, which means the random number OUT RNG is generated without using the random number RE[3], and the PREG 100 can reserve the random number RE[3] for use in a second data cycle (e.g., T = 2) after the second power-on. Therefore, in the first data cycle, the random number OUT RNG is based on the random numbers RE[1] and RE[2] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated without using the random number RE[3]). In the second data cycle (e.g., T = 2) after the second power-on, the PREG 100 additionally outputs the random numbers RE[4] and RE[5], where it is assumed that the reseeding enable signal EN RESEED1 is shown as "0" in the second data cycle, which means the random number OUT RNG is generated without using the random number RE[5], and the PREG100 can reserve the random number RE[5] for use in a third data cycle (e.g., T = 3) after the second power-on. Therefore, in the second data cycle, the random number OUT RNGis based on the random numbers RE[3] and RE[4] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated without using the random number RE[5]). In the third data cycle after the second power-on (e.g., T = 3), PREG 100 additionally outputs the random numbers RE[6] and RE[7], where it is assumed that the reseeding enable signal EN RESEED1 shows as "0" in the second data cycle, which indicates that the random number OUT RNG is generated without using the random number RE[7], and PREG 100 can retain the random number RE[7] for use in the next data cycle after the third data cycle after the second power-on. Therefore, the random number OUT RNG in the third data cycle is based on the random numbers RE[5] and RE[6] (which respectively correspond to the outputs of register R2 and register R1) and the random number OUT LFSR1 (which is generated without using the random number RE[7]).

[0087] Since the time point when the reseeding enable signal EN RESEED1 shows as "1" after the first power-on can be different from the time point when the reseeding enable signal EN RESEED1 shows as "1" after the second power-on, the components used to generate the random number OUT RNG in the T-th data cycle after the first power-on can be different from the components used to generate the random number OUT RNG in the T-th data cycle after the second power-on, and the random number OUT RNG can thus pass the power-on test. For example, assuming that the randomness retention mechanism is disabled, the random numbers OUT R2 and OUT R1 and OUT PREG in the N-th data cycle (e.g., T = N) are always RE[3N - 2], RE[3N - 1], and RE[3N] respectively after the first power-on and the second power-on. Therefore, the random number OUT RNG is always the XOR result of the random numbers RE[3N - 2] and RE[3N - 1] and the random number OUT LFSR1 in the cases of the first power-on and the second power-on, where if a reseeding event occurs in the N-th data cycle (e.g., the reseeding enable signal EN RESEED1 shows as "1"), the random number used to reseed the first linear feedback shift register 51 is always RE[3N] in the cases of the first power-on and the second power-on. Another example, assuming Figure 9 the randomness retention mechanism shown in the embodiment of RNGThe random numbers can be RE[4] and RE[5], but are used to generate the random number OUT during the second data cycle (e.g., T = 2) of the second power-on. RNG The random numbers can be RE[3] and RE[4]. Additionally, for a certain data cycle, the random numbers used by the new stage generator 52 are also unpredictable for different power-on events. In particular, the random numbers used to generate the random number OUT RNG The complexity of the possible combinations of the random numbers can also increase as T increases (e.g., after more data cycles). Therefore, the randomness retention mechanism can be beneficial to the results of the power-on test.

[0088] Figure 10 As shown in an embodiment of the present invention Figure 1 Some details of the PREG 100 shown. In this embodiment, the PREG 100 may include a static entropy source value implemented by a static entropy array such as the PUF array 110, an address counter 120, a second linear feedback shift register 130 (labeled "LFSR-2" in Figure 10 for simplicity), a refresh circuit such as a first-stage refresh circuit 140, a processing circuit 150 (represented by a circle with a "+" marked inside for simplicity), and a clock control circuit such as an entropy retention logic 160. The PUF array 110 can be regarded as a chip fingerprint. Since the physical characteristics of different chips have slight differences due to some uncontrollable factors in the manufacturing process, these differences cannot be replicated or predicted. Additionally, since these differences are determined after the chip is manufactured and will not change, the PUF array 110 can be used as a "static" entropy source. In some embodiments, the static entropy array can be a register array storing data read from an external PUF array connected to the random number generator 10. In some cases, the speed of reading the register array can be much faster than the speed of reading the external PUF array. Therefore, when the random number generator 10 is powered on, all the PUF data stored in the external PUF array can be first stored in the register array, and all subsequent operations related to the PUF data can be performed by reading the register array without reading the external PUF array, but the present invention is not limited thereto.

[0089] In this embodiment, the PUF array 110 is used to output a first static entropy number such as the PUF number PUF according to a first address such as the address ADDR X 、output a second static entropy number such as the PUF number PUF according to a second address such as the address ADDR X 、and output a third static entropy number such as the PUF number PUF according to a third address such as the address ADDR Y 、 Y 、and output a third static entropy number such as the PUF number PUF according to a third address such as the address ADDR Z 、and output a third static entropy number such as the PUF number PUFZ . The address counter 120 is used to generate addresses ADDR X , ADDR Y and ADDR Z to control the outputs of the PUF numbers PUF X , PUF Y and PUF Z . For ease of understanding, please refer to Figure 11 , which is the output scheme of the PUF numbers PUF X , PUF Y and PUF Z read from the PUF array 110 according to an embodiment of the present invention. As Figure 11 shown, the data of each PUF cell stored in the PUF array 110 can be represented by D RA,CA , where RA can represent the row address and CA can represent the column address. For example, the data stored in the first row of the PUF array 110 can be {D 1,1 , D 1,2 , D 1,3 , …, D 1,31 , D 1,32}; the data stored in the second row of the PUF array 110 can be {D 2,1 , D 2,2 , D 2,3 , …, D 2,31 , D 2,32}; and the rest can be inferred accordingly. For example, the data stored in the thirty-second row of the PUF array 110 can be {D 32,1 , D 32,2 , D 32,3 , …, D 32,31 , D 32,32}. In addition, the PUF array 110 can output the PUF number PUF X by collecting the data read from a first group of PUF cells arranged in a first direction (for example, arranged vertically) as a group, and the first group of PUF cells corresponds to the address ADDR X , where the value of the address ADDR X can be represented by nx, and the PUF number PUF X corresponding to a value different from the address ADDR X can be {P X (nx)|nx = 1, 2, 3, …, 32} = {D 1,nx , D 2,nx , D 3,nx , …, D 31,nx , D 32,nxThe PUF array 110 may collect data read from a second group of PUF units arranged in a second direction (eg, arranged in a horizontal direction) into a group to output a PUF number PUF Y , and the second group of PUF units corresponds to address ADDR Y , where address ADDR Y The value of can be represented by ny, and the address ADDR Y PUF number corresponding to different values Y Available Y (ny)|ny=1,2,3,…,32}={D ny,1 ,D ny,2 ,D ny,3 ,…,D ny,31 ,D ny,32 The PUF array 110 may collect data read from a third group of PUF units arranged in a third direction (eg, arranged in a skewed direction) into one group to output a PUF number PUF Z , and the third group of PUF units corresponds to address ADDR Z , where address ADDR Z The value of can be represented by nz, and the address ADDR Z PUF number corresponding to different values Z Available Z (nz)|nz=1,2,3,…,32}. For example, P Z (1) = {D 1,1 ,D 2,2 ,D 3,3 ,…,D 31,31 ,D 32,32}, P Z (2) = {D 1,2 ,D 2,3 ,D 3,4 ,…,D 31,32 ,D 32,1}, and the rest can be deduced in the same way, for example, P Z (32) = {D 1,32 ,D 2,1 ,D 3,2 ,…,D 31,30 ,D 32,31}.

[0090] exist Figure 10 In the embodiment of the present invention, the level refresh circuit 140 is used to update the dynamic entropy bit B from the dynamic entropy source 20. DYN2 Generate a refresh signal, wherein an example of the refresh signal may include a refresh enable signal EN REFRESH and a reseeding enable signal EN RESEED2, but the present invention is not limited thereto. For example, the stage refresh circuit 140 may generate a refresh signal (e.g., a refresh enable signal EN DYN2 and a reseed enable signal EN PREG ), based on the dynamic entropy bit B REFRESH and the random number OUT RESEED2 . In particular, the refresh signal may be the exclusive OR result of a predetermined bit in the dynamic entropy bit B DYN2 and the random number OUT PREG (e.g., the Mth bit of the random number OUT PREG , where M is a positive integer), but the present invention is not limited thereto. Based on the processing of the stage refresh circuit 140, high-quality random control bits involving dynamic entropy (e.g., any one of the refresh enable signal EN REFRESH and the reseed enable signal EN RESEED2 ) can be generated. The PREG 100 generates at least the random number OUT X based on the PUF numbers PUF Y , and the refresh signal (e.g., the reseed enable signal EN PREG ) is used to control whether to generate the random number OUT RESEED2 based on the PUF numbers PUF Z . The second linear feedback shift register 130 can be another example of a linear feedback shift register and is used to output a linear feedback shift register random number such as the random number OUT PREG . When the refresh signal (e.g., the reseed enable signal EN LFSR2 ) shows a first logic value (e.g., "0"), the second linear feedback shift register 130 can output the random number OUT RESEED2 according to a second predetermined rule (e.g., a rule corresponding to a second primitive polynomial) without using the PUF numbers PUF Z . It should be noted that the first linear feedback shift register 51 and the second linear feedback shift register 130 are preferably implemented with different primitive polynomials (e.g., the first primitive polynomial is different from the second primitive polynomial). When the refresh signal (e.g., the reseed enable signal EN LFSR2 ) shows a second logic value (e.g., "1"), the second linear feedback shift register 130 can output the random number OUT RESEED2 based on the PUF numbers PUF Z . In this embodiment, the stage refresh circuit 140 can generate a new random number STAGE LFSR2 based on the PUF numbers PUF Z to reseed the second linear feedback shift register 130. For example, the stage refresh circuit 140 can generate a new random number STAGE NEW based on the PUF numbers PUF Z and the random number OUT PREGGenerate new random number STAGE NEW (For example, the new random number STAGE NEW can be the XOR result of PUF number PUF Z and random number OUT PREG ), but the present invention is not limited thereto. The processing circuit 150 is used to generate the random number OUT X based on PUF number PUF Y , PUF number PUF LFSR2 and random number OUT PREG . For example, the processing circuit 150 can perform an XOR operation on PUF number PUF X and PUF Y to generate a preliminary XOR result, and then perform an XOR operation on this preliminary XOR result and random number OUT LFSR2 to generate the random number OUT PREG , but the present invention is not limited thereto.

[0091] In addition, the addresses ADDR X and ADDR Y are refreshed (for example, incremented by one unit step) in each of the multiple output cycles of the PREG 100, and the refresh signal (for example, the refresh enable signal EN REFRESH ) is used to control whether to refresh the address ADDR Z . For example, when the refresh enable signal EN REFRESH shows a first logic value (for example, "0"), the address counter 120 can avoid refreshing the address ADDR Z , and when the refresh enable signal EN REFRESH shows a second logic value (for example, "1"), the address counter 120 can refresh (for example, increment by one unit step) the address ADDR Z . The refresh enable signal EN REFRESH is preferably related to the reseeding enable signal EN RESEED2 . In some embodiments, the stage refresh circuit 140 can provide the same enable signal to the address counter 120 and the second linear feedback shift register 130 (for example, EN REFRESH = EN RESEED2 ) to ensure that the PUF number PUF Z corresponding to each value of the address ADDR Z can be used without being skipped.

[0092] In this embodiment, the stage refresh circuit 140 can receive the mode control signal MODE CTRL to determine whether to operate in the pseudo-random number generation mode or the true random number generation mode. When the random number generator 10 operates in the true random number generation mode (for example, when the mode control signal MODECTRL displayed as a logical value "0"), the stage refresh circuit 140 can generate a refresh signal (e.g., a reseeding enable signal EN DYN2 and a refresh enable signal EN RESEED2 based on the above-mentioned dynamic entropy bit B REFRESH When the random number generator 10 operates in the pseudo-random number generation mode (e.g., when the mode control signal MODE CTRL is displayed as a logical value "1"), the stage refresh circuit 140 can generate a refresh signal (e.g., a reseeding enable signal EN DYN2 and a refresh enable signal EN RESEED2 without using the dynamic entropy as the source B REFRESH For example, the stage refresh circuit 140 can output the predetermined bit in the above-mentioned random number OUT PREG as a refresh signal such as a reseeding enable signal EN RESEED2 and a refresh enable signal EN REFRESH either one.

[0093] In some embodiments, the PUF array 110 transmits the PUF number PUF Y and PUF Z to the processing circuit 150 and transmits the PUF number PUF X to the stage refresh circuit 140, where the addresses ADDR Y and ADDR Z are updated (e.g., incremented by one unit step) in each of the multiple output cycles of the PREG 100, and the refresh signal (e.g., the refresh enable signal EN REFRESH ) is used to control whether to refresh the address ADDR X , but the present invention is not limited thereto. In some embodiments, the PUF array 110 transmits the PUF number PUF Z and PUF X to the processing circuit 150 and transmits the PUF number PUF Y to the stage refresh circuit 140, where the addresses ADDR Z and ADDR X are updated (e.g., incremented by one unit step) in each of the multiple output cycles of the PREG 100, and the refresh signal (e.g., the refresh enable signal EN REFRESH ) is used to control whether to refresh the address ADDR Y , but the present invention is not limited thereto.

[0094] In addition, the essential retention logic 160 is used to generate an internal clock CLK RESEED1 based on the reseeding enable signal EN PREG, wherein the stage refresh circuit 140, the address counter 120, and the second linear feedback shift register 130 operate according to the internal clock CLK PREG When the reseeding enable signal EN RESEED1 is shown as a first logic value (e.g., "0"), which means that the random number extractor 50 generates the random number OUT without using the second preliminary random number during the current data cycle of the random number extractor 50 RNG , the essential retention logic 160 can disable the internal clock CLK PREG (e.g., make the internal clock CLK PREG stop switching) to stop the operation of the stage refresh circuit 140, the address counter 120, and the second linear feedback shift register 130, so as to retain the second preliminary random number (e.g., retain the random number OUT generated in the current data cycle PREG ).

[0095] Figure 12 is related to certain signals (such as the main clock CLK of the random number generator 10, the refresh enable signal EN Figure 10 , the random number OUT REFRESH , PUF LFSR2 , PUF X , PUF Y , PUF Z and OUT PREG , and the dynamic entropy bit B DYN2 ) shown according to an embodiment of the present invention. After the random number generator 10 is powered on and before the main clock CLK starts to switch, the random number OUT LFSR2 is in an initial state (e.g., an initial seed of the second linear feedback shift register 130), and it is assumed that the second linear feedback shift register 130 can sequentially output random numbers M1, M2, M3, M4, M5, M6, and M7 without being reseeded at all. The dynamic entropy bit B DYN2 can switch randomly between "0" and "1" (marked as "H / L" in Figure 12 for easy understanding). In the cycle marked "t = 1", the random number PUF Z is Pz[1], and the second linear feedback shift register 130 outputs the random number M1, where the refresh enable signal EN REFRESH is shown as "0" (indicating that the second linear feedback shift register 130 will not be reseeded and the random number PUF Z will not be refreshed in the next cycle). In the cycle marked "t = 2", the random number PUF Z remains at Pz[1], and since the second linear feedback shift register 130 is not reseeded, the second linear feedback shift register 130 outputs the random number M2, where the refresh enable signal ENREFRESH is shown as "0" (indicating that the second linear feedback shift register 130 will not be reseeded and the random number PUF Z will not be refreshed) in the cycle marked "t = 3", the random number PUF Z is maintained at Pz[1], and since the second linear feedback shift register 130 is not reseeded, the second linear feedback shift register 130 outputs the random number M3, where the refresh enable signal EN REFRESH is shown as "1" (indicating that the second linear feedback shift register 130 will be reseeded and the random number PUF Z will be refreshed) in the cycle marked "t = 4", the random number PUF Z is refreshed to Pz[2], and since the second linear feedback shift register 130 is reseeded, the second linear feedback shift register 130 outputs the random number M4' (instead of M4 corresponding to the case where the second linear feedback shift register 130 is not reseeded), where the refresh enable signal EN REFRESH is shown as "1" (indicating that the second linear feedback shift register 130 will be reseeded and the random number PUF Z will be refreshed) in the cycle marked "t = 5", the random number PUF Z is refreshed to Pz[3], and since the second linear feedback shift register 130 is reseeded, the second linear feedback shift register 130 outputs the random number M5" (instead of M5' corresponding to the case where the second linear feedback shift register 130 is not reseeded), where the refresh enable signal EN REFRESH is shown as "0" (indicating that the second linear feedback shift register 130 will not be reseeded and the random number PUF Z will not be refreshed) in the cycle marked "t = 6", the random number PUF Z is maintained at Pz[3], and since the second linear feedback shift register 130 is not reseeded, the second linear feedback shift register 130 outputs the random number M6", where the refresh enable signal EN REFRESH is shown as "1" (indicating that the second linear feedback shift register 130 will be reseeded and the random number PUF Z will be refreshed) in the cycle marked "t = 7", the random number PUF Z is refreshed to Pz[4], and since the second linear feedback shift register 130 is reseeded, the second linear feedback shift register 130 outputs the random number M7''' (instead of M7'' corresponding to the case where the second linear feedback shift register 130 is not reseeded), where the refresh enable signal EN REFRESHis displayed as "0" (indicating that the second linear feedback shift register 130 will not be reseeded and the random number PUF Z will not be refreshed).

[0096] The reseeding determination performed by the reseeding control circuit 53 and / or the stage refresh circuit 140 can be used to change / disturb the output pattern of the first linear feedback shift register 51 and / or the second linear feedback shift register 130. Additionally, by means of the randomness retention mechanism, the timing of any random number output from the PREG 100 for generating the random number OUT RNG can become unpredictable (for example, RE[5] is used in the second cycle after the first power-on but RE[5] is used in the third cycle after the second power-on, as Figure 9 shown), which is beneficial to the results of the power-on test. Therefore, the quality of the random numbers generated by the random number generator provided by the embodiments of the present invention with multi-stage (such as multi-loop) processing can be greatly improved. In particular, even if the quality of the dynamic entropy elements of the random number generator is low, as long as at least one of the dynamic entropy bits B DYN1 and B DYN2 is used, the reseeding determination and the randomness retention mechanism can be carried out as described above with the benefits of dynamic entropy, and the random number generator can still output high-quality random numbers. Additionally, the field of random numbers can be greatly extended, so compared with the related art, the quality of the random numbers generated based on the pseudo-random number generation mode of the present invention can be greatly improved.

[0097] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A random number generator, characterized in that, Comprising: A first-stage generator for outputting a first preliminary random number and a second preliminary random number among a plurality of preliminary random numbers, wherein the first preliminary random number is output at a first time point, and the second preliminary random number is output at a second time point; And A second-stage generator coupled to the first-stage generator for generating a final output at least based on the first preliminary random number, wherein the second-stage generator comprises: A reseeding circuit for generating a reseeding signal, wherein the reseeding signal is used to control whether the second-stage generator generates the final output based on the first preliminary random number and the second preliminary random number when generating the final output; Wherein when the second-stage generator generates the final output in the current data cycle of the second-stage generator without using the second preliminary random number, the first-stage generator retains the second preliminary random number for generating the final output in the next data cycle of the second-stage generator.

2. The random number generator according to claim 1, characterized in that, Further comprising: A dynamic entropy source for providing a first dynamic entropy bit and a second dynamic entropy bit; Wherein during the true random number generation mode, the first-stage generator is used to output the plurality of preliminary random numbers based on the second dynamic entropy bit, and the reseeding circuit of the second-stage generator is used to generate the reseeding signal based on the first dynamic entropy bit.

3. The random number generator according to claim 1, characterized in that, The second-stage generator further comprises: A linear feedback shift register for outputting a linear feedback shift register random number; and A processing circuit for generating the final output based on the first preliminary random number and the linear feedback shift register random number; Wherein when the reseeding signal shows a first logic value, the linear feedback shift register outputs the linear feedback shift register random number according to a predetermined rule without using the second preliminary random number, and when the reseeding signal shows a second logic value, the linear feedback shift register outputs the linear feedback shift register random number based on the second preliminary random number.

4. The random number generator according to claim 1, wherein The first-stage generator comprises: A static entropy array for respectively outputting a first static entropy number, a second static entropy number, and a third static entropy number based on a first address, a second address, and a third address; and A refresh circuit for generating a refresh signal; Wherein the first-stage generator generates the plurality of preliminary random numbers at least based on the first static entropy number and the second static entropy number, and the refresh signal is used to control whether any one of the plurality of preliminary random numbers is generated based on the third static entropy number.

5. The random number generator according to claim 4, characterized in that, The first-stage generator further comprises: A linear feedback shift register for outputting a linear feedback shift register random number; and A processing circuit for generating the plurality of preliminary random numbers based on the first static entropy number, the second static entropy number, and the linear feedback shift register random number; When the refresh signal shows a first logic value, the linear feedback shift register outputs the linear feedback shift register random number according to a predetermined rule without using the third static entropy number, and when the refresh signal shows a second logic value, the linear feedback shift register outputs the linear feedback shift register random number according to the third static entropy number.

6. The random number generator according to claim 5, wherein The first-stage generator further includes: An address counter for generating the first address, the second address, and the third address; wherein the first address and the second address are refreshed in each of a plurality of output cycles of the first-stage generator, and the refresh signal is further used to control whether to refresh the third address.

7. The random number generator according to claim 6, wherein The first-stage generator further includes: A clock control circuit for generating an internal clock according to the reseeding signal, wherein the refresh circuit, the address counter, and the linear feedback shift register operate according to the internal clock; When the second-stage generator generates the final output in the current data cycle of the second-stage generator without using the second preliminary random number, the clock control circuit disables the internal clock to stop the operation of the refresh circuit, the address counter, and the linear feedback shift register to retain the second preliminary random number.

8. The random number generator according to claim 4, wherein The static entropy array outputs the first static entropy number by collecting data read from a first group of static entropy units arranged in a first direction in the static entropy array as a group, the static entropy array outputs the second static entropy number by collecting data read from a second group of static entropy units arranged in a second direction in the static entropy array as a group, and the static entropy array outputs the third static entropy number by collecting data read from a third group of static entropy units arranged in a third direction in the static entropy array as a group, wherein the first group of static entropy units, the second group of static entropy units, and the third group of static entropy units respectively correspond to the first address, the second address, and the third address.

9. The random number generator according to claim 8, wherein, The first group of static entropy units are arranged in a vertical direction, the second group of static entropy units are arranged in a horizontal direction, and the third group of static entropy units are arranged in a skew direction.

10. The random number generator according to claim 4, characterized in that, The static entropy array is a physically unclonable function array or a register array storing data read from a physically unclonable function array.

11. A random number generator, characterized in that, Comprising: A dynamic entropy source for providing a first dynamic entropy bit; A first-stage generator, comprising: A static entropy source for outputting a first static entropy number and a second static entropy number respectively according to a first address and a second address; And A refresh circuit for generating a refresh signal; Wherein the first-stage generator generates at least a first preliminary random number and a second preliminary random number among a plurality of preliminary random numbers according to the first static entropy number, and the refresh signal is used to control whether the first-stage generator generates any one of the plurality of preliminary random numbers according to the first static entropy number and the second static entropy number when generating the plurality of preliminary random numbers; The first preliminary random number is generated at a first time point, and the second preliminary random number is generated at a second time point after the first time point; and A second-stage generator, coupled to the first-stage generator, is configured to generate a final output based at least on the first preliminary random number, wherein the second-stage generator includes: A reseeding circuit configured to generate a reseeding signal based on the first dynamic entropy bit; wherein the reseeding signal is used to control whether the second-stage generator generates the final output based on the first preliminary random number and the second preliminary random number when generating the final output.

12. The random number generator according to claim 11, wherein, When the second-stage generator generates the final output in the current data cycle of the second-stage generator without using the second preliminary random number, the first-stage generator retains the second preliminary random number for generating the final output in the next data cycle of the second-stage generator.

13. The random number generator according to claim 11, wherein, The first-stage generator is further configured to generate the plurality of preliminary random numbers based on a second dynamic entropy bit provided by the dynamic entropy source, and the first dynamic entropy bit is different from the second dynamic entropy bit.

14. The random number generator according to claim 11, characterized in that, The second-stage generator further includes: A linear feedback shift register configured to output a linear feedback shift register random number; and A processing circuit configured to generate the final output by calculating the first preliminary random number and the linear feedback shift register random number; wherein when the reseeding signal indicates a first logic value, the linear feedback shift register outputs the linear feedback shift register random number according to a predetermined rule without using the second preliminary random number, and when the reseeding signal indicates a second logic value, the linear feedback shift register outputs the linear feedback shift register random number according to the second preliminary random number.

15. The random number generator according to claim 14, wherein: During an initial program of the random number generator, the reseeding circuit generates the reseeding signal based on the first dynamic entropy bit in a plurality of data cycles of the second-stage generator; and During an output program of the random number generator after the initial program, the random number generator determines whether to operate in a true random number generation mode or a pseudo-random number generation mode according to a mode control signal.

16. The random number generator according to claim 11, characterized in that, The first-stage generator further includes: A linear feedback shift register configured to output a linear feedback shift register random number; and A processing circuit configured to generate the plurality of preliminary random numbers based on the first static entropy number and the linear feedback shift register random number; wherein when the refresh signal indicates a first logic value, the linear feedback shift register outputs the linear feedback shift register random number according to a predetermined rule without using the second static entropy number, and when the refresh signal indicates a second logic value, the linear feedback shift register outputs the linear feedback shift register random number according to the second static entropy number.

17. The random number generator according to claim 16, wherein The first-stage generator further includes: An address counter configured to generate the first address and the second address; The first address is refreshed in each of the multiple output cycles of the first-stage generator, and the refresh signal is further used to control whether to refresh the second address.

18. The random number generator according to claim 17, wherein, The first-stage generator further includes: a clock control circuit for generating an internal clock according to the reseeding signal, wherein the refresh circuit, the address counter, and the linear feedback shift register operate according to the internal clock; wherein when the second-stage generator generates the final output in the current data cycle of the second-stage generator without using the second preliminary random number, the clock control circuit disables the internal clock to stop the operation of the refresh circuit, the address counter, and the linear feedback shift register to retain the second preliminary random number.

19. The random number generator according to claim 11, characterized in that, The static entropy source is implemented by a static entropy array. The static entropy array collects the data read from a first set of static entropy units arranged in a first direction in the static entropy array into a set to output the first static entropy number, and the static entropy array collects the data read from a second set of static entropy units arranged in a second direction in the static entropy array into a set to output the second static entropy number; wherein: the first set of static entropy units and the second set of static entropy units respectively correspond to the first address and the second address; and either the first direction or the second direction represents one of a vertical direction, a horizontal direction, and a skew direction, and the first set of static entropy units and the second set of static entropy units are arranged in different directions.

20. The random number generator according to claim 19, characterized in that, The static entropy source is further used to collect the data read from a third set of static entropy units arranged in a third direction in the static entropy array into a set to output a third static entropy number according to a third address, the third direction represents one of the vertical direction, the horizontal direction, and the skew direction, wherein the first set of static entropy units, the second set of static entropy units, and the third set of static entropy units are arranged in different directions; wherein the first-stage generator generates the plurality of preliminary random numbers at least according to the first static entropy number and the third static entropy number.

21. The random number generator according to claim 11, wherein The first-stage generator is further used to output a third preliminary random number of the plurality of preliminary random numbers, and the final output is generated at least according to the first preliminary random number and the third preliminary random number, wherein the third preliminary random number is generated at a third time point before the second time point.

Citation Information

Patent Citations

  • Random number generator

    EP3709157A1