Hardware stores unique key
By combining a finite state machine with a random number generator in an integrated circuit, random values are generated and stored, accessible only to the cryptographic processor. This solves the problem of cryptographic keys in integrated circuits being vulnerable to attack, and achieves higher data confidentiality and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STMICROELECTRONICS (GRENOBLE 2) SAS
- Filing Date
- 2022-03-17
- Publication Date
- 2026-06-02
AI Technical Summary
In existing technologies, the cryptographic keys of integrated circuits are stored in non-volatile memory, which makes them easily accessible to attackers, resulting in insufficient data confidentiality.
A finite state machine is coupled to a random number generator via a dedicated bus. The generated random values are stored by the finite state machine in a specific area of a non-volatile fuse memory and are accessible only to the cryptographic processor, not to other processors.
It improves the data security of integrated circuits, prevents unauthorized access, ensures the confidentiality of cryptographic keys, and eliminates the need for additional components to generate cryptographic keys.
Smart Images

Figure CN115114678B_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority to French patent application No. FR2102718, filed on March 18, 2021, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure generally relates to electronic circuits, and in certain embodiments, to protecting data stored in a non-volatile fuse-type memory. Background Technology
[0004] Typically, the operation of electronic devices with integrated circuits requires the execution of software code or proprietary protocols used throughout the circuit's lifespan. Data representing the software code and proprietary protocols is linked to certain instances of the circuit, but usually needs to be stored in externally accessible, non-volatile memory. Such data is generally considered critical for confidentiality and needs to be encrypted to prevent access in the event of an attack on the circuit.
[0005] Data encryption and decryption are typically performed by a cryptographic processor, which requires one or more cryptographic keys stored in the device's non-volatile memory. Typically, the generation of these cryptographic keys and the control over their storage in non-volatile memory are performed by a non-secure processor.
[0006] However, these cryptographic keys should not be accessible to any potential attackers of the circuit. Any physical connection between the insecure processor containing the cryptographic keys and the non-volatile memory for the cryptographic keys could be exploited by an attacker. Summary of the Invention
[0007] There is a need to improve the security of data stored in the irreversible programmable nonvolatile memory of integrated circuit devices.
[0008] The embodiments overcome all or some of the disadvantages of known devices with integrated circuits.
[0009] One embodiment provides a method in which random values generated by a random number generator are stored by a finite state machine in a memory region of a non-volatile fuse-type memory of an integrated circuit, the finite state machine being coupled to the generator via a first dedicated bus, and the memory region being accessible only by the finite state machine.
[0010] One embodiment provides an integrated circuit including a random number generator, a finite state machine coupled to the generator via a first dedicated bus, and a non-volatile memory, wherein random values generated by the generator are stored by the state machine in a memory region of the non-volatile memory, the memory region being accessible only by the finite state machine.
[0011] According to one embodiment, the memory region can only be programmed by a finite state machine.
[0012] According to one embodiment, a first dedicated bus exclusively couples a finite state machine to a random number generator.
[0013] According to an embodiment, at each reset phase of the circuit, the contents of the memory region are loaded into the volatile memory element by a finite state machine.
[0014] According to an embodiment, a second dedicated bus exclusively couples the volatile memory element to the first processor.
[0015] According to one embodiment, the first processor is a cryptographic engine.
[0016] According to one embodiment, the finite state machine and volatile memory elements are included in the package.
[0017] According to an embodiment, the transition of the circuit into and out allows the execution of a scan test to generate the deletion of contents stored in the volatile memory element.
[0018] According to an embodiment, when the circuit is in a state where scan testing is allowed to be performed, the non-volatile memory is disconnected from the circuit.
[0019] According to one embodiment, if the stored random value corresponds to a random value generated by the generator, the finite state machine locks the memory region after storing the random value. Attached Figure Description
[0020] Other advantages and features of this disclosure will become apparent upon review of the detailed description of the implementations and embodiments, and the accompanying drawings, which are by no means limiting, in that:
[0021] Figure 1 This is a schematic diagram of an integrated circuit embodiment;
[0022] Figure 2 This is a schematic diagram of an integrated circuit embodiment;
[0023] Figure 3 This is a flowchart of an embodiment method for creating and storing cryptographic keys; and
[0024] Figure 4 This is a flowchart of an embodiment method for booting or resetting. Detailed Implementation
[0025] This disclosure provides numerous applicable inventive concepts that can be implemented in a wide variety of specific contexts. Specific embodiments are merely illustrative of particular configurations and do not limit the scope of the claimed embodiments. Unless otherwise stated, features from different embodiments can be combined to form additional embodiments.
[0026] The variations or modifications described in one embodiment may also be applied to other embodiments. Furthermore, it should be understood that various changes, substitutions, and alterations may be made without departing from the spirit and scope of this disclosure as defined by the appended claims.
[0027] In the various figures, the same features are indicated by the same reference numerals. In particular, common structural or functional features in various embodiments may have the same reference numerals and may have the same structure, dimensions, and material properties.
[0028] For clarity, only steps and elements useful for understanding the embodiments described herein are shown and described in detail. Specifically, the design of integrated circuits is well known to those skilled in the art, and certain components are not described below.
[0029] Unless otherwise stated, when referring to two elements connected together, it means that there is no direct connection between them except for the conductor, and when referring to two elements coupled together, it means that the two elements can be connected or they can be coupled through one or more other elements.
[0030] In the following disclosure, unless otherwise stated, when referring to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or when referring to relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or when referring to orientation qualifiers, such as "horizontal", "vertical", etc., the orientation shown in the figure is used.
[0031] Unless otherwise stated, the expressions “about,” “approximately,” “basically,” and “in the order of” indicate within 10%, preferably within 5%.
[0032] Figure 1 An embodiment of an electronic device 100 including an integrated circuit 102 is illustrated very schematically in the form of a box, the embodiment being applied to an integrated circuit 102 of this type as an example.
[0033] Electronic device 100 is, for example, an electronic board such as a microcircuit card, computer equipment, or microprocessor circuit. In the application targeted by this disclosure, integrated circuit 102 includes non-rewritable non-volatile fuse memory (FUSE NV MEM) 104. By default, at the end of the manufacture of memory 104, all fuse-type bits of memory 104 are in the same state 104, arbitrarily 0. Depending on the inherent state of the fuse bits, this state corresponds, for example, to the non-conducting or "off" state of the memory element defining the bit. Data is stored in non-volatile memory 104 by switching the state of certain bits of the memory (memory word) to the opposite state 1 (e.g., corresponding to the conducting or "on" state of the corresponding memory element).
[0034] The designation of the corresponding on and off states of a memory bit as "0" or "1" is arbitrary, and alternative conventions may be adopted depending on the application, for example, conversely: 0 for on and 1 for off.
[0035] Because the fuse memory 104 has limited storage capacity, other data is stored in external non-volatile memory 120 (NVMEM), such as flash memory. This data corresponds, for example, to software code or proprietary protocols that ensure the functionality of the electronic device. This data is used throughout the lifespan of the electronic device and is considered critical in terms of confidentiality.
[0036] Critical data is encrypted by the cryptographic processor (cryptographic engine) 112 (CRYPTO) of circuit 102 to protect the contents of external non-volatile memory 120 and ensure its confidentiality in the event of a hacking attack on the circuit.
[0037] In one embodiment, the cryptographic key used for this purpose is stored in non-volatile memory 104 of circuit 102, corresponding to a secure or confidential environment. The cryptographic key should be accessible outside the circuit.
[0038] For this purpose and according to the described embodiments, integrated circuit 102 includes finite state machine 106 (FSM) coupled to random number generator 110 (RNG) via bus 118.
[0039] The random number generator 110 can be a pseudo-random number generator, such as a linear congruential generator, which uses a recursive arithmetic sequence with noisy behavior and a sufficiently long period to appear random. The quality of such a generator depends entirely on the arithmetic parameters used. The generator 110 can also be a true random number generator that uses a random physical source, such as one based on the inherent properties of the material on which the random physical source of the generator is implanted.
[0040] According to the embodiment, bus 118 exclusively couples finite state machine 106 to random number generator 110.
[0041] Finite state machine 106 is typically further coupled to non-volatile memory 104 via a data bus. To ensure accounting between data available from random number generator 110 and data stored in non-rewritable non-volatile memory 104, circuitry 102 includes wrapper 108. In an embodiment, wrapper 108 itself includes finite state machine 106.
[0042] The cryptographic processor 112 is configured to decrypt critical data using a cryptographic key contained in non-volatile memory 104, making it usable for operation of the electronic device. The cryptographic processor 112 is coupled to a portion of the wrapper 108 via a data bus 116. Figure 1 (Not described in detail). The data bus 116 exclusively couples the cryptographic processor 112 to the wrapper 106.
[0043] The circuit also includes a non-secure multipurpose processor 114 (CPU) that is typically coupled to a portion (not shown) of the package 108 via a data bus.
[0044] External non-volatile memory 120 is wired to portions of non-secure multi-purpose processor 114 and package 108.
[0045] For example, memory 120 is coupled via an external bus to a portion of the data bus that couples the non-secure multi-purpose processor 114 to the package 108.
[0046] Figure 2 By Figure 1 A more detailed block diagram schematically illustrates an embodiment of an integrated circuit type to which the described embodiment is applied, as an example.
[0047] At the end of manufacturing, finite state machine 106 sends a request to random number generator 110 via bus 118. Generator 110 then generates a random value, which is still transmitted to finite state machine 106 via bus 118. Bus 118 exclusively couples finite state machine 106 to generator 110, and multi-purpose processor 114 cannot access the random value generated in this operation.
[0048] According to the described embodiments, the non-volatile fuse memory 104 includes a plurality of different memory areas.
[0049] The first region 202 is formed by a word of multiple bits (e.g., 16 or 32 bits) that can only be programmed by the finite state machine 106. Once a random value is generated and transmitted to the finite state machine 106, the finite state machine 106 stores the value in a portion of region 202 by programming the bits that form the value.
[0050] The second region 204 of the non-volatile memory 104 is reserved for storing critical information. Storage in the non-volatile memory is performed, for example, by a non-secure multi-purpose processor 114.
[0051] In this embodiment, the operation is performed by the end user of the circuit or by an intermediary entity between the manufacturer and the user.
[0052] The random value stored in memory region 202 is used as a cryptographic key. It will be used by cryptographic processor 112 to encrypt or decrypt data stored in region 210 of external non-volatile memory 120. This value must remain inaccessible to any processing unit other than cryptographic processor 112.
[0053] Therefore, in this embodiment, in addition to the finite state machine 106, the wrapper 108 also includes two different volatile memory elements 206 and 208. In this embodiment, elements 206 and 208 are registers.
[0054] During each reset or boot of the circuit, before the reset of the non-secure multipurpose processor 114 is complete, the contents of region 202 are loaded into volatile memory element 206, and other fuse values in region 204 are loaded into register 208.
[0055] Memory element 206 is coupled to cryptographic processor 112 via dedicated data bus 216. Data bus 216 exclusively couples element 206 to processor 112, thereby making data stored in memory element 206 inaccessible to circuit components other than cryptographic processor 112.
[0056] For example, in the event of a malfunction in electronic device 100, a scan test can be performed during the circuit's lifetime. However, the contents of word 202 and volatile memory 206 should remain inaccessible outside the circuit. To perform the scan test, circuit 102 must enter scan mode.
[0057] In this embodiment, the scan test can only be performed in scan mode. In scan mode, non-volatile memory 104 is disconnected from the rest of the circuit to isolate the contents of regions 202 and 204. In this embodiment, any transition into or out of scan mode causes a chip reset. Therefore, when switching into or out of scan mode, the contents of volatile memory elements 206 and 208 are erased.
[0058] Figure 3 This is a flowchart illustrating the steps of an implementation mode for creating and storing a cryptographic key. When circuit 102 is first fabricated, finite state machine 106 can be invoked to send a request to random number generator 110. Random number generator 110 then generates a random value (box 301 RN generation). The generated value is sent to finite state machine 106 via dedicated data bus 118. Data bus 118 exclusively couples random number generator 110 to finite state machine 106. Therefore, in this operation, the random value is not accessible to a non-secure multi-purpose processor.
[0059] The finite state machine then verifies whether the random value is acceptable (e.g., in binary writing, it is not a value consisting only of 0s or only of 1s). If the finite state machine deems the quality unacceptable, the method regenerates a new random value. If the quality of the random value is deemed acceptable, the finite state machine 106 stores it in non-volatile memory 104 (box 303, stored in FUSE NV MEM) by programming a portion of the bits of word 202.
[0060] Step 303 is immediately followed by step 304 (readback) and step 305 (verification?) to read the stored value and compare it with the resulting value to ensure that the fuse bit programming has been performed correctly. These steps are performed by finite state machine 106. If the two values are different (output N in box 305), an error exists during the programming of the bits of word 202 by the finite state machine, and the method ends (end in box 309). If the two values match (output Y in box 305), the finite state machine 106 programs the additional bits of word 202 (box 307, "Fuse Word Locking"). For example, if word 202 consists of 32 bits, and if the storage of random values occupies the 24 least significant bits of word 202, the finite state machine will program them, for example, by switching the remaining 8 most significant bits to state 1. This action locks word 202 and verifies the stored cryptographic key, and the method ends (end in box 309).
[0061] The length of word 202 can vary depending on the embodiment, just like the length of the generated cryptographic key. During the use of the circuit, only the portion of word 202 corresponding to the cryptographic key (corresponding to a random value) is read and used.
[0062] Figure 4 This is a flowchart illustrating the steps a circuit follows during a boot or reset operation.
[0063] The password key has been stored correctly (e.g., according to...). Figure 3After the steps shown in the diagram are in the non-volatile memory 104, the circuit 102 is reset (box 401 reset).
[0064] In this embodiment, once the wrapper 108 emerges from a reset, a word 202 or a portion 202 corresponding to the random value generated in step 301 is loaded (box 403, loading the key into VMEM) into the volatile memory element 206. It should be noted that the volatile memory element 206 is not accessible by the multipurpose processor 114 and is accessible only by the cryptographic processor 112. The method terminates in step 405 (CPU reset complete) when the multipurpose processor 114 has finished its reset.
[0065] Loading of the contents of the volatile memory element 206 by the cryptographic processor 112 is performed via a dedicated data bus 116. Therefore, the multipurpose processor 114, and more generally, any component of the circuit 102 other than the cryptographic processor 112, never has access to the cryptographic key stored in the volatile memory element 206.
[0066] The advantage of the described embodiment is that no processing unit other than the cryptographic processor can access the memory containing the cryptographic keys. This access restriction significantly limits the possibility of reading critical data from outside the circuitry.
[0067] Another advantage of the described embodiments is that they do not require additional components to generate the cryptographic key. In practice, a random number generator is typically present in such circuits for other security purposes.
[0068] The fact that random numbers are never visible allows the use of only one random number (one word). Therefore, its advantage (compared to solutions that must use and store multiple random numbers) is that random numbers can have a larger size, and are therefore more secure.
[0069] Another advantage of the embodiments described is that the implementation of the finite state machine requires simple combinatorial logic that can be implemented in a robust manner.
[0070] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations can be combined, and other variations will occur to those skilled in the art.
[0071] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variations is within the capabilities of those skilled in the art. In particular, the size of the cryptographic key or word 202 can be changed.
[0072] Although this specification has been described in detail, it should be understood that various changes, substitutions, and alterations can be made without departing from the spirit and scope of this disclosure as defined by the appended claims. In the various drawings, the same elements are designated by the same reference numerals. Furthermore, the scope of this disclosure is not intended to be limited to the specific embodiments described herein, as it will be readily understood by those skilled in the art from this disclosure that existing or future processes, machines, manufactures, compositions of matter, means, methods, or steps can perform substantially the same functions or achieve substantially the same results as the corresponding embodiments described herein. Therefore, the appended claims are intended to include such processes, machines, manufactures, compositions of matter, means, methods, or steps within their scope.
[0073] Therefore, the specification and drawings are to be considered merely as a description of this disclosure as defined by the appended claims, and are to be considered to cover any and all modifications, variations, combinations or equivalents falling within the scope of this disclosure.
Claims
1. A method for operating an integrated circuit, the method comprising: Random values are generated using a random number generator circuit; The random value is stored in the memory area of a non-volatile fuse-type memory using a finite state machine. The finite state machine is coupled to the random number generator circuit via a first dedicated bus, and the memory area can only be accessed by the finite state machine. In each reset phase of the integrated circuit, the contents of the memory region are loaded into volatile memory by the finite state machine. The state transitions of the integrated circuit entering and exiting the scan test generate deletion of the contents stored in the volatile memory, and In response to the integrated circuit being in a state where a scan test can be performed, the non-volatile fuse memory is disconnected from the integrated circuit.
2. The method of claim 1, wherein the memory region can only be programmed by the finite state machine, and wherein the first dedicated bus exclusively couples the finite state machine to the random number generator circuit.
3. The method of claim 1, wherein a second dedicated bus exclusively couples the volatile memory to a first processor, and wherein the first processor is a cryptographic engine.
4. The method of claim 3, wherein the contents of the memory region are loaded into the volatile memory before the reset of the second processor of the integrated circuit is completed, the second processor being a non-secure multi-purpose processor.
5. The method of claim 4, wherein the method further comprises loading additional values stored in another region of the non-volatile fuse-type memory at each reset phase of the integrated circuit into additional volatile memory by the finite state machine, the additional volatile memory being accessible by the second processor.
6. The method of claim 3, wherein the finite state machine and the volatile memory are contained in a wrapper.
7. The method of claim 1, wherein, in response to the stored random value corresponding to a random value generated by the random number generator circuit, the finite state machine locks the memory region after storing the random value.
8. An integrated circuit, comprising: Non-volatile fuse memory; A random number generator circuit is configured to generate random values; A finite state machine, coupled to the random number generator circuit via a first dedicated bus, is configured to store the random value in a memory region of the non-volatile fuse-type memory, the memory region being accessible only by the finite state machine. In each reset phase of the integrated circuit, the contents of the memory region are loaded into the volatile memory by the finite state machine, and In response to the integrated circuit being in a state where a scan test can be performed, the non-volatile fuse memory is disconnected from the integrated circuit.
9. The integrated circuit of claim 8, wherein the memory region can only be programmed by the finite state machine.
10. The integrated circuit of claim 8, wherein the first dedicated bus exclusively couples the finite state machine to the random number generator circuit.
11. The integrated circuit of claim 8, wherein a second dedicated bus exclusively couples the volatile memory to a first processor, and wherein the first processor is a cryptographic engine.
12. The integrated circuit of claim 8, wherein the finite state machine and the volatile memory are contained in a package.
13. The integrated circuit of claim 8, wherein the transition of the state in which the integrated circuit enters and exits allows the execution of the scan test to generate the deletion of the contents stored in the volatile memory.
14. The integrated circuit of claim 8, wherein, in response to the stored random value corresponding to a random value generated by the random number generator circuit, the finite state machine locks the memory region after storing the random value.
15. A device comprising an integrated circuit according to any one of claims 8-14.
16. The device of claim 15, wherein the memory region is programmable only by the finite state machine, wherein the first dedicated bus exclusively couples the finite state machine to the random number generator circuit, and wherein the second dedicated bus exclusively couples the volatile memory to the first processor, and wherein the first processor is a cryptographic engine.