A data generation method, device, electronic device, and storage medium

By obtaining random bits from memory sectors and generating intermediate auxiliary data during the initialization of the chip system, the high cost and high power consumption problems caused by PUF digital generation in the prior art are solved, and the security and practicality are improved.

CN115292084BActive Publication Date: 2025-07-22TELINK SEMICON SHANGHAI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210993515.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-18
Publication Date
2025-07-22
Estimated Expiration
2042-08-18

AI Technical Summary

Technical Problem

The generation of PUF numbers in the prior art requires changing the physical design, resulting in high chip cost and power consumption and poor practicality.

Method used

During the initialization of the chip system, the original random bits are obtained from the two memory sectors, and intermediate auxiliary data is generated based on hash operation and error correction encoding, which is used to generate the same PUF numbers as when initialized during normal operation.

Benefits of technology

It reduces the safety risks of PUF digital leakage, ensures the safety of the chip, and reduces the cost and power consumption of the chip.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115292084B_ABST
    Figure CN115292084B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data generation method, apparatus, electronic device, and storage medium. The method includes: in response to the initialization process of a chip system, obtaining a first original random bit and a second original random bit from two memory sectors respectively; determining a first physical unclonable function (PUF) digit for the chip system based on the first original random bit; generating intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF digit during the normal operation of the chip system, and the second PUF digit is the same as the first PUF digit. The intermediate auxiliary data in the present disclosure can help generate the second PUF digit during the normal operation of the chip system, rather than directly serving as the PUF digit. While ensuring the generation of available PUF digits, it also reduces the potential security risks caused by the leakage of the PUF digit, further ensuring the security of the chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information security technologies, and in particular, to a data generation method, apparatus, electronic device, and storage medium. Background Art

[0002] As an information security technology that has been continuously developed in recent years, the Physical Unclonable Function (PUF) has various advantages such as unpredictability and non-tamperability, can achieve higher security, and has a wide range of uses. For example, it can be applied to service scenarios such as firmware protection, authentication, and signature.

[0003] In related technologies, various methods can be used to generate PUF numbers, but most of these require changing the physical design. For example, special implementation circuits can be specifically designed on an integrated circuit chip (IC chip), and the random deviation of the integrated circuit manufacturing process can be utilized to achieve its unique and non-replicable characteristics.

[0004] For different application scenarios, the above-mentioned methods for generating PUF numbers require designing different implementation circuits, and the complexity of the implementation circuits is usually high, which results in a relatively high overall cost and power consumption of the chip and poor practicability. Summary of the Invention

[0005] Embodiments of the present disclosure at least provide a data generation method, apparatus, electronic device, and storage medium to automatically generate PUF numbers and improve the security of the chip.

[0006] In a first aspect, embodiments of the present disclosure provide a data generation method, including:

[0007] In response to the initialization process of the chip system, obtain a first original random bit and a second original random bit from two memory sectors respectively;

[0008] Determine a first Physical Unclonable Function (PUF) number for the chip system based on the first original random bit;

[0009] Generate intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF number during the normal operation of the chip system, and the second PUF number is the same as the first PUF number.

[0010] In a possible implementation manner, the determining a first Physical Unclonable Function (PUF) number for the chip system based on the first original random bit includes:

[0011] Perform a first hashing operation on the first original random bit to obtain a first hash value;

[0012] Determine the first hash value as the first PUF digit.

[0013] In a possible implementation manner, the generating of the intermediate auxiliary data based on the first original random bit and the second original random bit includes:

[0014] Perform a second hashing operation on the second original random bit to obtain a second hash value;

[0015] Perform error correction coding on the second hash value to obtain a first coded digit, where the number of bits of the first coded digit is the same as the number of bits of the first original random bit;

[0016] Perform an exclusive OR operation on the first coded digit and the first original random bit to obtain the intermediate auxiliary data.

[0017] In a possible implementation manner, after generating the intermediate auxiliary data based on the first original random bit and the second original random bit, the method further includes:

[0018] Store the intermediate auxiliary data in a target storage medium.

[0019] In a possible implementation manner, the method further includes:

[0020] In response to the normal operation process of the chip system, read the intermediate auxiliary data from the target storage medium; and, obtain a new first original random bit from the memory sector corresponding to the first original random bit;

[0021] Determine a second PUF digit for the chip system based on the new first original random bit and the intermediate auxiliary data.

[0022] In a possible implementation manner, the determining of the second PUF digit for the chip system based on the new first original random bit and the intermediate auxiliary data includes:

[0023] Perform an exclusive OR operation on the new first original random bit and the intermediate auxiliary data to obtain pre - decoding data that needs to be error - corrected decoded;

[0024] Perform error - correction decoding on the pre - decoding data to obtain a first decoded digit, where when the difference between the pre - decoding data and the first coded digit meets a preset error - correction requirement, the first decoded digit is the same as the second hash value;

[0025] Determine the second PUF digit based on the first decoded digit and the intermediate auxiliary data.

[0026] In a possible implementation, determining the second PUF digit based on the first decoded digit and the intermediate auxiliary data includes:

[0027] Performing error correction coding on the first decoded digit to obtain a second coded digit, where the second coded digit is the same as the first coded digit;

[0028] Performing an exclusive OR operation on the second coded digit and the intermediate auxiliary data to obtain pre-hash data that needs to be hashed; the pre-hash data is the same as the first original random bit;

[0029] Performing a first hashing operation on the pre-hash data to obtain the second PUF digit.

[0030] In a second aspect, an embodiment of the present disclosure further provides a data generation device, including:

[0031] An acquisition module, configured to obtain a first original random bit and a second original random bit from two memory sectors respectively in response to the initialization process of the chip system;

[0032] A first determination module, configured to determine a first physical unclonable function (PUF) digit for the chip system based on the first original random bit;

[0033] A generation module, configured to generate intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF digit during the normal operation of the chip system, and the second PUF digit is the same as the first PUF digit.

[0034] In a third aspect, an embodiment of the present disclosure further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the data generation method according to any one of the first aspect and its various embodiments is executed.

[0035] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the data generation method according to any one of the first aspect and its various embodiments is executed.

[0036] Using the above data generation method, apparatus, electronic device, and storage medium, during the initialization of the chip system, two corresponding original random bits (i.e., the first original random bit and the second original random bit) can be first obtained from two memory sectors, and then the first PUF digit generated during the initialization can be determined based on the first original random bit, and intermediate auxiliary data can be generated based on the two original random bits. Since this intermediate auxiliary data can help generate the second PUF digit during the normal operation of the chip system, rather than directly serving as the PUF digit, while ensuring the generation of available PUF digits, it also reduces the potential security risks caused by the leakage of PUF digits, further ensuring the security of the chip.

[0037] Other advantages of the present disclosure will be explained in more detail in conjunction with the following description and drawings.

[0038] It should be understood that the above description is only an overview of the technical solution of the present disclosure, so as to more clearly understand the technical means of the present disclosure, and thus it can be implemented according to the content of the specification. In order to make the above and other purposes, features, and advantages of the present disclosure more obvious and understandable, the following specifically illustrates the specific implementation manners of the present disclosure. Description of the Drawings

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings required for use in the embodiments will be briefly introduced below. The drawings herein are incorporated into the specification and constitute a part of this specification. These drawings show embodiments that conform to the present disclosure and are used together with the specification to explain the technical solutions of the present disclosure. It should be understood that the following drawings only show some embodiments of the present disclosure, and thus should not be regarded as a limitation of the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0040] Figure 1 Shows a flowchart of a data generation method provided by an embodiment of the present disclosure;

[0041] Figure 2 Shows an application schematic diagram of a data generation method provided by an embodiment of the present disclosure;

[0042] Figure 3 Shows a schematic diagram of a data generation apparatus provided by an embodiment of the present disclosure;

[0043] Figure 4 Shows a schematic diagram of an electronic device provided by an embodiment of the present disclosure. Detailed Description of the Embodiments

[0044] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0045] In the description of the embodiments of the present disclosure, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, actions, components, parts, or combinations thereof disclosed in this specification, and are not intended to exclude the possibility of the presence of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0046] Unless otherwise specified, " / " means "or". For example, A / B may mean A or B; herein, "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B may mean: A exists alone, A and B exist simultaneously, and B exists alone.

[0047] Terms such as "first", "second", etc. are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", etc. may explicitly or implicitly include one or more of these features. In the description of the embodiments of the present disclosure, unless otherwise specified, the meaning of "a plurality" is two or more.

[0048] Through research, it is found that PUF numbers play a very crucial role in the security of various chip systems. In related technologies, various methods can be used to generate PUF numbers, but most of these require changing the physical design. For example, special implementation circuits can be specifically designed on an integrated circuit chip (IC chip), and the unique and non-replicable characteristics can be achieved by utilizing the random deviations of the integrated circuit manufacturing process.

[0049] For different application scenarios, the above-mentioned methods for generating PUF numbers require designing different implementation circuits, and the complexity of the implementation circuits is usually relatively high, which results in a relatively high overall cost and power consumption of the chip and poor practicability.

[0050] In order to at least partially solve one or more of the above problems and other potential problems, the present disclosure provides at least one data generation scheme to automatically generate PUF numbers, alleviating the problems of relatively high chip cost and power consumption caused by complex circuit design, and having higher practicability.

[0051] This solution mainly considers that the content of the memory sector in an electronic device system (such as a chip) is random without initialization when powered on each time, but has a certain degree of certainty, that is, the change in content between two power - ons of the same chip is small, and there are significant differences in the uninitialized content of different chips. Based on this, the source data used in the process of generating PUF numbers in this solution can be the original random bits in the memory sector.

[0052] To facilitate the understanding of this embodiment, first, a data generation method disclosed in this embodiment of the present disclosure will be introduced in detail. The execution subject of the data generation method provided in this embodiment of the present disclosure is generally an electronic device with certain computing capabilities. Such an electronic device includes, for example: a terminal device or other processing devices. The terminal device can be a user equipment (UE), a mobile device, a user terminal, a handheld device, a vehicle - mounted device, a wearable device, etc. In practical applications, the terminal device here can also be a device in relevant application scenarios. For example, it can be an Internet of Things device, and no specific limitation is made here.

[0053] In some possible implementation manners, the data generation method can be implemented by a processor calling computer - readable instructions stored in a memory.

[0054] See Figure 1 As shown in the flowchart of the data generation method provided in this embodiment of the present disclosure, the method includes steps S101 - S103, where:

[0055] S101: In response to the initialization process of the chip system, obtain a first original random bit and a second original random bit from two corresponding memory sectors;

[0056] S102: Determine a first physical unclonable function (PUF) number for the chip system based on the first original random bit;

[0057] S103: Generate intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF number during the normal operation of the chip system, and the second PUF number is the same as the first PUF number.

[0058] To facilitate the understanding of the data generation method provided in this embodiment of the present disclosure, next, the application scenario of this method will be briefly described first. The data generation method in this embodiment of the present disclosure can be mainly applied to the field of IC chip security. The generated PUF numbers can help ensure various service scenarios such as firmware protection, authentication, and signature. Here, it can be directly using the generated PUF numbers for security protection, or using the calculation results for security protection after performing relevant calculations on the PUF numbers, and no specific limitation is made here.

[0059] The data generation method provided by the embodiments of the present disclosure can generate intermediate auxiliary data during the initialization process of the chip system. The intermediate auxiliary data can generate PUF numbers when the chip system is running normally. Despite the randomness of the PUF numbers themselves, when applied to the same chip system, their PUF numbers should be consistent. Based on such considerations, the embodiments of the present disclosure provide a dual PUF number generation scheme. In the process of generating the first PUF number during the initialization of the system, intermediate auxiliary data can also be generated. The auxiliary data can be used to generate the second PUF number during the normal operation process, and the second PUF number is the same as the first PUF number.

[0060] The first PUF number can be determined based on the first original random bits, and the intermediate auxiliary data can be determined by the first original random bits and the second original random bits together. The two original random bits (i.e., the first original random bits and the second original random bits) can be obtained from the corresponding two memory sectors, and different memory sectors correspond to different storage locations.

[0061] Based on the first original random bits, the first PUF number during the initialization process can be directly determined. The first PUF number can be used as the reference PUF number of the chip system. Once the first PUF number is determined, there will be a fixed PUF number for the chip system, and this PUF number has reliability, unpredictability, and uniqueness.

[0062] Based on the first original random bits and the second original random bits, intermediate auxiliary data can be generated. After the initialization process is completed, the intermediate auxiliary data can be stored in a non-volatile storage medium. In this way, during the normal operation process of the chip system, the intermediate auxiliary data can be read from the non-volatile storage medium, and the intermediate auxiliary data can be used to generate the second PUF number during the normal operation process. The second PUF number is the same as the above-mentioned first PUF number. In this way, no matter which time the chip system is run, it can be ensured that a unique PUF number is generated for the same chip system.

[0063] The PUF numbers here utilize the random variations in the memory parameters of the chip system to generate unique values for the chip. These variations are unpredictable, and so are the generated values. Thus, they can serve as the "fingerprint" of the device. Even if the attacker captures the intermediate auxiliary data, they cannot restore the PUF numbers, making it highly resistant to invasive attacks and largely resistant to reverse engineering as well. Therefore, it can be widely applied. For example, the keys generated by the PUF are used to establish a security library in the on-chip non-volatile memory (such as EEPROM, Flash, or OTP); another example is that the keys generated by the PUF can be used to encrypt and protect some software algorithms; also, the random numbers generated by the PUF are sent to the device to be authenticated, and then the device uses its private key to sign the random numbers, etc.

[0064] Next, the generation of the first PUF number and the second PUF number will be introduced respectively in combination with the processes of initializing and normally operating the chip system.

[0065] First aspect: The embodiments of the present disclosure can generate the first PUF number according to the following steps:

[0066] Step 1: Perform a first hash operation on the first original random bits to obtain a first hash value;

[0067] Step 2: Determine the first hash value as the first PUF number.

[0068] Here, in the process of determining the first PUF number, it can be determined based on the first hash operation on the first original random bits. The hash operation accepts an input of unlimited length and returns an output of a fixed length. Here, it is a process of mapping the given first original random bits to a hash number of a fixed length, and the hash number of the fixed length can be a 256-bit string.

[0069] Second aspect: The embodiments of the present disclosure can generate the second PUF number according to the following steps:

[0070] Step 1: In response to the normal operation process of the chip system, read the intermediate auxiliary data from the target storage medium; and, obtain new first original random bits from the memory sector corresponding to the first original random bits;

[0071] Step 2: Based on the new first original random bits and the intermediate auxiliary data, determine the second PUF number for the chip system.

[0072] The second PUF number here can be generated based on the new first original random bits and the intermediate auxiliary data read from the target storage medium. The target storage medium is the above-mentioned non-volatile storage medium (such as Flash, etc.).

[0073] Since the new first original random bit is obtained from the memory sector corresponding to the first original random bit, that is, the two first original random bits can be read from the same random bit source, and the same bit source means that the generation method of random bits during normal operation is exactly the same as that during the startup process. For example, the two random bits can be read from the same unstarted system memory. Usually, due to the uncertainty in the electrical process of the chip system, the two random bits are usually different, but usually only a small part of the bits are different. Using this characteristic, by combining the new original random bit with the intermediate auxiliary data generated during initialization, the PUF digits generated during the initialization process can be restored, that is, the second PUF digit for the normally operating chip system can be determined.

[0074] Considering the key role of the generation of intermediate auxiliary data in the generation of the second PUF digit, the process of generating intermediate auxiliary data can be described in detail next, which specifically includes the following steps:

[0075] Step 1: Perform a second hashing operation on the second original random bit to obtain a second hash value;

[0076] Step 2: Perform error correction coding on the second hash value to obtain a first coded digit, and the number of bits of the first coded digit is the same as the number of bits of the first original random bit;

[0077] Step 3: Perform an exclusive OR operation on the first coded digit and the first original random bit to obtain intermediate auxiliary data.

[0078] Here, first, a second hashing operation can be performed on the second original random bit, and then error correction coding is performed based on the obtained second hash value to obtain a first coded digit. Finally, intermediate auxiliary data is obtained based on the exclusive OR operation between the first coded digit and the first original random bit.

[0079] The logical relationship of the above exclusive OR operation is: when A and B are different, the output P = 1; when A and B are the same, the output P = 0. That is, the first coded digit obtained through error correction coding can largely represent the relevant characteristics of the first original random bit, so that the determined intermediate auxiliary data can enable the first original random bit to be restored through error correction decoding during the subsequent normal operation process, so that the second PUF digit identical to the first PUF digit can be determined.

[0080] To better understand the above process of generating intermediate auxiliary data, it can be further illustrated by Figure 2 the application schematic diagram shown.

[0081] As Figure 2As shown, when the IC chip is powered on and starts running for the first time, intermediate auxiliary data (H) can be generated. First, the first raw random bit and the second raw random bit are obtained from Memory Sector 1 and Memory Sector 2 respectively. These two random bits can come from an uninitialized system memory. Due to process differences, these bits are usually different from one IC to another.

[0082] Among them, the first raw random bit is used to create a vector V (corresponding to the first raw random bit), whose length is the same as that of the first encoded digit C. The second raw random bit is hashed (corresponding to Hash) to create a vector R (corresponding to the second hash value). R is encoded using a block error correction code (Block Encode) to generate C.

[0083] On the one hand, V and C are XORed to generate a vector H. H, as intermediate auxiliary data, can be stored in a non-volatile memory such as Flash; on the other hand, V is hashed to create a security key K (i.e., the first PUF digit). K or its variant here can be used to protect the information on the IC, for example, firmware protection, authentication, signature, etc.

[0084] In the case of obtaining the intermediate auxiliary data, the second PUF digit can be determined according to the following steps, which can be specifically implemented through the following steps:

[0085] Step 1: XOR the new first raw random bit and the intermediate auxiliary data to obtain the pre-decoding data that needs to be error-corrected and decoded.

[0086] Step 2: Perform error-correction decoding on the pre-decoding data to obtain the first decoded digit. Among them, when the difference between the pre-decoding data and the first encoded digit meets the preset error-correction requirements, the first decoded digit is the same as the second hash value.

[0087] Step 3: Determine the second PUF digit based on the first decoded digit and the intermediate auxiliary data.

[0088] Here, the first decoded digit can be determined by XOR operation and error-correction decoding. The first decoded digit can be the reverse operation corresponding to the error-correction coding. That is, the first decoded digit obtained through error-correction decoding can largely characterize the relevant characteristics of the new first raw random bit. Then, combined with the intermediate auxiliary data, the first raw random bit can be restored, and thus a unique PUF digit can be obtained.

[0089] Among them, regarding obtaining the second PUF digit based on the first decoded digit and the intermediate auxiliary data, it specifically includes the following steps:

[0090] Step 1: Perform error correction coding on the first decoded digit to obtain a second encoded digit, which is the same as the first encoded digit;

[0091] Step 2: Perform an exclusive OR operation on the second encoded digit and the intermediate auxiliary data to obtain the data before hashing that needs to be hashed; the data before hashing is the same as the first original random bit;

[0092] Step 3: Perform a first hashing operation on the data before hashing to obtain a second PUF digit.

[0093] Here, error correction coding can be performed on the first decoded digit obtained by decoding, and then through exclusive OR operation and hashing operation in sequence, the first PUF digit can be restored.

[0094] For a better understanding of the generation process of the above second PUF digit, it can also be further illustrated through Figure 2 the application schematic diagram shown.

[0095] As Figure 2 shown, when powering on again after the initialization process of the IC chip, the normal operation mode is used. Here, first, the same random bits can be read from memory sector 1 to create a vector V' (corresponding to the new first original random bit). V' is usually different from V and can contain a small number of different bits. The vector V' is exclusive ORed with the stored intermediate auxiliary data H to generate the data C' before decoding.

[0096] Since V' may be different from V, C' is also different from C. Here, the block error correction decoding (BlockDecode) process is used to decode C' into the first decoded digit R'. Here, as long as the number of differences between C and C' is within the error correction range, R' will be the same as R.

[0097] Then, R' is re-encoded using the same block error correction code as in the initialization process, and the second encoded digit C'' is generated. C'' will also be the same as C. Then C'' is exclusive ORed with H to reproduce the data V'' before hashing, which will also be the same V. V'' generates a security key K' (i.e., the second PUF digit) through the hashing process, which is the same as the first PUF digit K.

[0098] It can be known that in the embodiments of the present disclosure, two uninitialized memory sectors can be used to generate the original bits of the PUN process. One sector serves as the seed of the key, and the other sector is used as the seed to create random information bits for the block error correction code for protection. The block error correction key bit code is used to generate the intermediate auxiliary data. The block error correction code is used to generate a consistent key between power cycles of the IC, and the key randomly uses a hashing function to generate a system-unique key for security functions, which makes the overall cost and power consumption of the chip lower, and thus has a wider practicality.

[0099] For example, with the rapid rise of the Internet of Things (IoT), the demand for encryption has been accelerated. For a large number of IoT devices, if the existing circuit transformation scheme is adopted to obtain PUF, it will pose serious challenges to device production and its applications. By using the above data generation scheme provided by the embodiments of the present disclosure, a more secure environment can be provided for the application of the physical network and its devices, and the cost can be reduced to a greater extent.

[0100] In the description of this specification, the descriptions with reference to terms such as "some possible implementation manners", "some implementation manners", "examples", "specific examples", or "some examples" etc. mean that the specific features, structures, materials or characteristics described in connection with the implementation manner or example are included in at least one implementation manner or example of the present disclosure. In this specification, the schematic expressions of the above terms do not necessarily refer to the same implementation manner or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more implementation manners or examples. In addition, without contradiction, those skilled in the art can combine and combine the different implementation manners or examples described in this specification and the features of different implementation manners or examples.

[0101] Regarding the method flowcharts of the embodiments of the present disclosure, certain operations are described as different steps executed in a certain order. Such flowcharts are illustrative rather than restrictive. Certain steps described herein can be grouped together and executed in a single operation, certain steps can be split into multiple sub-steps, and certain steps can be executed in an order different from that shown herein. Each step shown in the flowchart can be implemented in any way by any circuit structure and / or tangible mechanism (for example, by software running on a computer device, hardware (such as a processor or logic function implemented by a chip), etc., and / or any combination thereof).

[0102] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not constitute any limitation to the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.

[0103] Based on the same inventive concept, a data generation device corresponding to the data generation method is further provided in the embodiments of the present disclosure. Since the principle of solving problems by the device in the embodiments of the present disclosure is similar to the above data generation method of the embodiments of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.

[0104] Refer to Figure 3As shown in the figure, it is a schematic diagram of a data generation device provided by an embodiment of the present disclosure. The device includes: an acquisition module 301, a first determination module 302, and a generation module 303; wherein,

[0105] The acquisition module 301 is configured to, in response to the initialization process of the chip system, acquire a first original random bit and a second original random bit from two memory sectors respectively;

[0106] The first determination module 302 is configured to determine a first physical unclonable function (PUF) number for the chip system based on the first original random bit;

[0107] The generation module 303 is configured to generate intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF number during the normal operation of the chip system, and the second PUF number is the same as the first PUF number.

[0108] By using the above data generation device, during the initialization process of the chip system, two corresponding original random bits (i.e., the first original random bit and the second original random bit) can be first acquired from two memory sectors, and then the first PUF number generated during the initialization process can be determined based on the first original random bit, and the intermediate auxiliary data can be generated based on the two original random bits. Since the intermediate auxiliary data can help generate the second PUF number during the normal operation of the chip system, rather than directly serving as the PUF number, while ensuring the generation of available PUF numbers, it also reduces the potential security risks caused by the leakage of the PUF number, further ensuring the security of the chip.

[0109] In a possible implementation manner, the first determination module 302 is configured to determine the first physical unclonable function (PUF) number for the chip system based on the first original random bit according to the following steps:

[0110] Perform a first hash operation on the first original random bit to obtain a first hash value;

[0111] Determine the first hash value as the first PUF number.

[0112] In a possible implementation manner, the generation module 303 is configured to generate intermediate auxiliary data based on the first original random bit and the second original random bit according to the following steps:

[0113] Perform a second hash operation on the second original random bit to obtain a second hash value;

[0114] Perform error correction coding on the second hash value to obtain a first coded number, and the number of bits of the first coded number is the same as the number of bits of the first original random bit;

[0115] XOR the first encoded digit with the first original random bit to obtain intermediate auxiliary data.

[0116] In a possible implementation, after generating the intermediate auxiliary data based on the first original random bit and the second original random bit, the above device further includes:

[0117] A storage module 304, configured to store the intermediate auxiliary data into a target storage medium.

[0118] In a possible implementation, the above device further includes:

[0119] A second determination module 305, configured to, in response to the normal operation of the chip system, read the intermediate auxiliary data from the target storage medium; and obtain a new first original random bit from the memory sector corresponding to the first original random bit; determine a second PUF digit for the chip system based on the new first original random bit and the intermediate auxiliary data.

[0120] In a possible implementation, the second determination module 305 is configured to determine a second PUF digit for the chip system based on the new first original random bit and the intermediate auxiliary data according to the following steps:

[0121] XOR the new first original random bit with the intermediate auxiliary data to obtain pre-decoding data that needs to be error-corrected and decoded;

[0122] Perform error-correction decoding on the pre-decoding data to obtain a first decoded digit, where, when the difference between the pre-decoding data and the first encoded digit meets a preset error-correction requirement, the first decoded digit is the same as the second hash value;

[0123] Determine the second PUF digit based on the first decoded digit and the intermediate auxiliary data.

[0124] In a possible implementation, the second determination module 305 is configured to determine the second PUF digit based on the first decoded digit and the intermediate auxiliary data according to the following steps:

[0125] Perform error-correction encoding on the first decoded digit to obtain a second encoded digit, where the second encoded digit is the same as the first encoded digit;

[0126] XOR the second encoded digit with the intermediate auxiliary data to obtain pre-hash data that needs to be hashed; the pre-hash data is the same as the first original random bit;

[0127] Perform a first hash operation on the pre-hash data to obtain the second PUF digit.

[0128] It should be noted that the device in the embodiments of the present application can implement each process of the foregoing method embodiments, and achieve the same effects and functions, which will not be elaborated here.

[0129] The embodiments of the present disclosure also provide an electronic device, as Figure 4 shown, which is a schematic structural diagram of the electronic device provided by the embodiments of the present disclosure, including: a processor 401, a memory 402, and a bus 403. The memory 402 stores machine-readable instructions executable by the processor 401 (for example, Figure 3 the execution instructions corresponding to the acquisition module 301, the first determination module 302, and the generation module 303 in the device in

[0130] In response to the process of initializing the chip system, obtain a first original random bit and a second original random bit from two memory sectors respectively;

[0131] Determine a first physical unclonable function PUF number for the chip system based on the first original random bit;

[0132] Generate intermediate auxiliary data based on the first original random bit and the second original random bit; the intermediate auxiliary data is used to generate a second PUF number during the normal operation of the chip system, and the second PUF number is the same as the first PUF number.

[0133] The embodiments of the present disclosure also provide a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the data generation method described in the foregoing method embodiments. Among them, the storage medium can be a volatile or non-volatile computer-readable storage medium.

[0134] The embodiments of the present disclosure also provide a computer program product, which carries program codes. The instructions included in the program codes can be used to execute the steps of the data generation method described in the foregoing method embodiments. For details, refer to the foregoing method embodiments, which will not be elaborated here.

[0135] Among them, the above computer program product can be specifically implemented in a manner of hardware, software, or a combination thereof. In an optional embodiment, the computer program product is specifically embodied as a computer storage medium. In another optional embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.

[0136] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the device, equipment, and computer-readable storage medium, since they are basically similar to the method embodiments, their descriptions are simplified, and the relevant parts can be referred to the partial descriptions of the method embodiments.

[0137] The device, equipment, and computer-readable storage medium provided by the embodiments of this application correspond one-to-one with the method. Therefore, the device, equipment, and computer-readable storage medium also have beneficial technical effects similar to those of the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the device, equipment, and computer-readable storage medium will not be elaborated here.

[0138] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a device (equipment or system), or a computer-readable storage medium. Therefore, the present disclosure can be in the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can be in the form of a computer-readable storage medium implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0139] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, devices (equipment or systems), and computer-readable storage media according to the embodiments of the present disclosure. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0140] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0141] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, causing a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one process Figure 1 one process or a plurality of processes and / or boxes Figure 1 steps for implementing the functions specified in one box or a plurality of boxes.

[0142] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0143] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0144] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile discs (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. Additionally, although the operations of the methods of the present disclosure are depicted in the figures in a particular order, this is not required or implied to perform the operations in that particular order, or to perform all of the illustrated operations to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step and performed, and / or one step may be decomposed into multiple steps and performed.

[0145] Although the spirit and principles of the present disclosure have been described with reference to several specific embodiments, it should be understood that the present disclosure is not limited to the specific embodiments disclosed, and the division of aspects does not mean that the features in these aspects cannot be combined for benefit. This division is only for convenience of expression. The present disclosure aims to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

Claims

1. A data generation method, characterized in that, Including: In response to the initialization process of the chip system, obtaining a first original random bit and a second original random bit from two memory sectors respectively; Determining a first physical unclonable function (PUF) number for the chip system based on the first original random bit; Performing a second hashing operation on the second original random bit to obtain a second hash value; Performing error correction coding on the second hash value to obtain a first coded number, where the number of bits of the first coded number is the same as that of the first original random bit; Performing an exclusive OR operation on the first coded number and the first original random bit to obtain intermediate auxiliary data; In response to the normal operation process of the chip system, obtaining a new first original random bit from the memory sector corresponding to the first original random bit; Determining a second PUF number for the chip system based on the new first original random bit and the intermediate auxiliary data, where the second PUF number is the same as the first PUF number.

2. The method according to claim 1, wherein The determining the first physical unclonable function (PUF) number for the chip system based on the first original random bit includes: Performing a first hashing operation on the first original random bit to obtain a first hash value; Determining the first hash value as the first PUF number.

3. The method according to claim 1, characterized in that, The method further includes: Storing the intermediate auxiliary data in a target storage medium.

4. The method according to claim 3, wherein The method further includes: In response to the normal operation process of the chip system, reading the intermediate auxiliary data from the target storage medium.

5. The method according to claim 4, characterized in that The determining the second PUF number for the chip system based on the new first original random bit and the intermediate auxiliary data includes: Performing an exclusive OR operation on the new first original random bit and the intermediate auxiliary data to obtain pre-decoding data that needs to be error correction decoded; Performing error correction decoding on the pre-decoding data to obtain a first decoded number, where when the difference between the pre-decoding data and the first coded number meets a preset error correction requirement, the first decoded number is the same as the second hash value; Determining the second PUF number based on the first decoded number and the intermediate auxiliary data.

6. The method according to claim 5, wherein The determining the second PUF number based on the first decoded number and the intermediate auxiliary data includes: Performing error correction coding on the first decoded number to obtain a second coded number, where the second coded number is the same as the first coded number; Performing an exclusive OR operation on the second coded number and the intermediate auxiliary data to obtain pre-hashing data that needs to be hashed; the pre-hashing data is the same as the first original random bit; Performing a first hashing operation on the pre-hashing data to obtain the second PUF number.

7. A data generation device, characterized in that, Including: An obtaining module, configured to obtain a first original random bit and a second original random bit from two memory sectors respectively in response to the initialization process of the chip system; A first determining module, configured to determine a first physical unclonable function (PUF) number for the chip system based on the first original random bit; A generation module is configured to perform a second hashing operation on the second original random bits to obtain a second hash value; perform error correction coding on the second hash value to obtain a first coded digit, where the number of digits of the first coded digit is the same as that of the first original random bits; perform an exclusive OR operation on the first coded digit and the first original random bits to obtain intermediate auxiliary data; in response to the normal operation process of the chip system, obtain new first original random bits from the memory sector corresponding to the first original random bits; determine a second PUF digit for the chip system based on the new first original random bits and the intermediate auxiliary data, where the second PUF digit is the same as the first PUF digit.

8. An electronic device, characterized in that, Comprising: A processor, a memory, and a bus, where the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the data generation method according to any one of claims 1 to 6 is executed.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is run by the processor, the data generation method according to any one of claims 1 to 6 is executed.

Citation Information

Patent Citations

  • Embedded microprocessor unclonable function secret key certification system and method

    CN103544410A

  • Method and device for generating non-repetitive application data on basis of chip

    CN107229578A