Shared secret chip, device, and shared secret chip preparation method and application method
By using the process deviation of the integrated circuit module to form secret sharing in the shared secret chip, the key storage and security problems in PUF technology are solved, and high-reliability key sharing and information security improvement without external storage are achieved.
Patent Information
- Application Number
- CN202210512541.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-11
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2042-05-11
AI Technical Summary
The existing physical non-clone function (PUF) technology has the risk of information leakage and model attacks in key storage and security. How to improve the security of the key so that it cannot be copied or read is an urgent problem.
By using the electronic components on the first and second integrated circuit modules in the shared secret chip, secret sharing is formed using process deviations to realize secret sharing between the first and second integrated circuit modules, and avoiding the need for key storage.
High-reliability key sharing without external storage devices is realized, key maintenance costs are reduced, and information security is improved by generating session keys.
Smart Images

Figure CN115795566B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security technology, and in particular to a shared secret chip, a device, and a shared secret chip preparation method and application method. Background Art
[0002] Physically Unclonable Function (PUF) is a newly emerging security encryption technology. Its uniqueness and unclonability have made it a popular technology for information security. PUF exploits process variations in chip manufacturing to generate unique data. This data is extracted as the chip's signature, enabling a unique correspondence between stimulus and response signals, creating a "chip fingerprint" similar to a human fingerprint.
[0003] However, PUFs still face some security issues. For example, weak PUFs require storing the key after reading it, necessitating a secure one-time interface to read the key and properly storing the key to avoid the risk of information leakage. Strong PUFs require a mathematical model to securely store multiple key-value pairs, necessitating protection against attacks targeting the model and ensuring the secure storage of model parameters. Improving key security and preventing it from being copied or read is a pressing research priority. Summary of the Invention
[0004] In view of the above problems, the present invention provides a shared secret chip, a device, and a shared secret chip preparation method and application method to solve the above problems.
[0005] The first aspect of the present disclosure provides a shared secret chip, comprising: a first integrated circuit module; a plurality of first electronic components, arranged on the first integrated circuit module; a second integrated circuit module; a plurality of second electronic components, arranged on the second integrated circuit module; the first electronic components correspond to the second electronic components one-to-one, and each first electronic component is the same as the corresponding second electronic component; the plurality of first electronic components constitute a first secret sequence, and the corresponding plurality of second electronic components constitute a second secret sequence, and the states of the corresponding first electronic components and second electronic components in the first secret sequence and the second secret sequence are different, forming a secret sharing of the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on the process deviation between the two during the preparation process.
[0006] Optionally, the first electronic component includes a transistor.
[0007] Optionally, the first electronic component includes a ring oscillator.
[0008] When the first electronic component includes a ring oscillator, optionally, the first electronic component also includes: a signal comparator, including a first input terminal, a second input terminal and an output terminal, the output terminal being connected to the input terminal of the ring oscillator, wherein when at least one of the first input terminal and the second input terminal inputs a low level, the output terminal outputs a low level signal; an asynchronous counter, connected to the output terminal of the ring oscillator, and used to record the number of flips of the ring oscillator; a counting comparator, having an input terminal connected to the output terminal of the asynchronous counter and an output terminal connected to the second input terminal, and being used to compare the flip number with a preset constant, and outputting a high level when the flip number is less than the preset constant, and outputting a low level when the flip number is greater than the preset constant.
[0009] Optionally, the multiple first electronic components are all the same.
[0010] Optionally, the multiple first electronic components are not completely the same.
[0011] The second aspect of the present disclosure provides a shared secret device, comprising: a first shared secret chip, comprising at least one first integrated circuit module, the first integrated circuit module comprising a plurality of first electronic components; a second shared secret chip, comprising at least one second integrated circuit module, the second integrated circuit module comprising a plurality of second electronic components; in the corresponding first integrated circuit module and the second integrated circuit module, the first electronic components correspond one-to-one to the second electronic components, and each first electronic component is the same as the corresponding second electronic component; a plurality of the first electronic components constitute a first secret sequence, and a corresponding plurality of the second electronic components constitute a second secret sequence, and the states of the corresponding first and second electronic components in the first secret sequence and the second secret sequence are different, forming secret sharing of the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on process deviations between the two during the preparation process.
[0012] A third aspect of the present disclosure provides a method for preparing a shared secret chip, comprising: arranging a plurality of first electronic components in a first integrated circuit module of the shared secret chip, and arranging a plurality of second electronic components in a second integrated circuit module of the shared secret chip, wherein the first electronic components correspond one-to-one to the second electronic components, and each first electronic component is identical to the corresponding second electronic component; matching the first electronic components with the corresponding second electronic components, comprising: simultaneously testing the first electronic components and the corresponding second electronic components under a first measurement condition, and based on process deviations between the first electronic components and the corresponding second electronic components, causing one of the first electronic component and the second electronic component to first meet a preset condition, thereby changing the state of the first electronic component or the second electronic component that meets the preset condition; wherein the plurality of first electronic components constitute a first secret sequence, and the corresponding plurality of second electronic components constitute a second secret sequence, and the states of the corresponding first and second electronic components in the first secret sequence and the second secret sequence are different, thereby forming a secret sharing between the first integrated circuit module and the second integrated circuit module.
[0013] Optionally, the first electronic component and the corresponding second electronic component are transistors, and the first electronic component and the corresponding second electronic component are tested simultaneously under the first measurement condition. Based on the process deviation of the first electronic component and the corresponding second electronic component, one of the first electronic component and the second electronic component is made to meet the preset condition first, so as to change the state of the first electronic component or the second electronic component that meets the preset condition, including: simultaneously applying the same preset voltage to the gate of the first electronic component and the corresponding second electronic component until the oxide layer of one of the first electronic component and the second electronic component is exhausted, and the gate voltage is lowered so that the other one is protected.
[0014] Optionally, the first electronic component and the corresponding second electronic component are ring oscillators, and the first electronic component and the corresponding second electronic component are tested simultaneously under the first measurement condition. Based on the process deviation of the first electronic component and the corresponding second electronic component, one of the first electronic component and the second electronic component is made to meet a preset condition first, so as to change the state of the first electronic component or the second electronic component that meets the preset condition. The method includes: using the same voltage signal to enable the first ring oscillator and the second ring oscillator; recording the oscillation frequency of the first ring oscillator and the second ring oscillator based on the counting circuit on the first integrated circuit module and the second integrated circuit module until the oscillation frequency of one of the first ring oscillator and the second ring oscillator reaches a preset threshold; and performing a one-time burning on the first ring oscillator or the second ring oscillator whose oscillation frequency reaches the preset threshold, so that the burning states of the corresponding first ring oscillator and the second ring oscillator are different.
[0015] The fourth aspect of the present disclosure provides a shared secret chip application method, which is applied to the shared secret chip as described in any one of the first aspects, including: obtaining data to be encrypted through a first integrated circuit module; controlling the first integrated circuit module to generate a random session key, and using the session key to encrypt the data to be encrypted to obtain encrypted data; controlling the first integrated circuit module to obtain a first secret sequence, and encrypting the session key according to the first secret sequence; sending the encrypted data and the encrypted session key to the second integrated circuit module through the first integrated circuit module; controlling the second integrated circuit module to obtain a second secret sequence, and decrypting the session key according to the second secret sequence, so that the second integrated circuit module decrypts the encrypted data according to the session key.
[0016] Optionally, controlling the first integrated circuit module to obtain the first secret sequence includes: controlling the first integrated circuit module to detect multiple first electronic components on the first integrated circuit module to identify the status of the multiple first electronic components; generating the first secret sequence based on the status of the multiple first electronic components; controlling the second integrated circuit module to obtain the second secret sequence includes: controlling the second integrated circuit module to detect multiple second electronic components on the second integrated circuit module to identify the status of the multiple second electronic components; generating the second secret sequence based on the status of the multiple second electronic components.
[0017] At least one of the above technical solutions adopted in the embodiments of the present disclosure can achieve the following beneficial effects:
[0018] The shared secret chip or shared secret device provided by the disclosed embodiments pairs a first electronic component with its corresponding second electronic component based on process variations. Once multiple electronic component pairs are paired, a shared secret exists solely between the first integrated circuit module and the second integrated circuit module (or between the first shared secret chip and the second shared secret chip). This shared secret does not require external storage devices, is highly reliable, easy to implement, and has low production and maintenance costs. This shared secret can be further used to generate session keys to support other cryptographic applications, enhancing information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] For a more complete understanding of the present disclosure and its advantages, reference will now be made to the following description taken in conjunction with the accompanying drawings, in which:
[0020] Figure 1 The following schematically shows the composition of a shared secret chip provided by one embodiment of the present disclosure;
[0021] Figure 2 A schematic diagram of secret sharing of a shared secret chip provided by one embodiment of the present disclosure is shown schematically;
[0022] Figure 3A A schematic diagram schematically illustrates a secret sharing structure of a shared secret chip provided by one embodiment of the present disclosure;
[0023] Figure 3B A schematic diagram of completing pairing of a shared secret chip provided by one embodiment of the present disclosure is shown schematically;
[0024] Figure 4 A schematic diagram schematically illustrates a secret sharing structure of a shared secret chip provided by another embodiment of the present disclosure;
[0025] Figure 5 The following schematically shows the composition of a shared secret device provided by one embodiment of the present disclosure;
[0026] Figure 6A A schematic diagram schematically illustrates a secret sharing structure of a shared secret device provided by one embodiment of the present disclosure;
[0027] Figure 6B A schematic diagram illustrating the composition of a secret sharing structure of a shared secret device provided by another embodiment of the present disclosure is shown;
[0028] Figure 7 A flowchart schematically illustrates a method for preparing a shared secret chip according to one embodiment of the present disclosure;
[0029] Figure 8The following schematically shows a flow chart of an application method of a shared secret chip provided by one embodiment of the present disclosure. DETAILED DESCRIPTION
[0030] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0031] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0032] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0033] The accompanying drawings show some block diagrams and / or flow charts. It should be understood that some blocks in the block diagrams and / or flow charts, or combinations thereof, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when these instructions are executed by the processor, they can create a device for implementing the functions / operations described in the block diagrams and / or flow charts.
[0034] Therefore, the technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). In addition, the technology of the present disclosure can take the form of a computer program product on a computer-readable medium having instructions stored thereon, which can be used by an instruction execution system or in combination with an instruction execution system. In the context of the present disclosure, a computer-readable medium can be any medium that can contain, store, convey, propagate, or transmit instructions. For example, a computer-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, device, or propagation medium. Specific examples of computer-readable media include: a magnetic storage device, such as a magnetic tape or hard disk (HDD); an optical storage device, such as a compact disc (CD-ROM); a memory, such as a random access memory (RAM) or flash memory; and / or a wired / wireless communication link.
[0035] The disclosed embodiments provide a Physically Twin Function (PTF) shared secret chip. PTF is a method for establishing a shared secret between two entities by extracting and comparing their intrinsic properties. The entities can be integrated circuit modules or chips.
[0036] Figure 1 The figure schematically shows the composition of a shared secret chip provided by one embodiment of the present disclosure.
[0037] like Figure 1 As shown, a shared secret chip provided by an embodiment of the present disclosure includes: a first integrated circuit module and a second integrated circuit module. The first integrated circuit module is provided with a plurality of first electronic components, and the second integrated circuit module is provided with a plurality of second electronic components. The first electronic components correspond to the second electronic components one-to-one, and each first electronic component is identical to the corresponding second electronic component.
[0038] It can be understood that the corresponding first electronic component and the second electronic component can correspond in function, position in the integrated circuit, or even coding. The correspondence between the two can be defined according to actual needs and is not limited here.
[0039] Optionally, the first electronic components on the first integrated circuit module may all be the same, and the second electronic components on the second integrated circuit module may be the same as the first electronic components.
[0040] Optionally, the multiple first electronic components on the first integrated circuit module are not completely identical. For example, assume that the first integrated circuit module is provided with 10 first electronic components for secret sharing, of which 3 first electronic components are of one type and 7 second electronic components are of another type. In this embodiment, the second electronic components are required to be identical to the corresponding first electronic components. Therefore, when the multiple first electronic components on the first integrated circuit module are not completely identical, the multiple second electronic components on the second integrated circuit module remain identical to the corresponding first electronic components.
[0041] According to a shared secret chip provided by an embodiment of the present disclosure, multiple first electronic components on a first integrated circuit module constitute a first secret sequence, and multiple second electronic components on a second integrated circuit module constitute a second secret sequence. The states of the first electronic components and the second electronic components corresponding to the first secret sequence and the second secret sequence are different, forming a secret sharing between the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on the process deviation between the two during the preparation process.
[0042] Specifically, the different states of the first electronic component and the corresponding second electronic component may be different working states, for example, different switch states, different output signals, or different detection feedback, etc. Since the first electronic component and the corresponding second electronic component are the same electronic components and have the same basic performance, but since process deviations cannot be avoided in the manufacturing process, there are still slight differences between the first electronic component and the corresponding second electronic component. For example, for two identical transistors, due to process deviations, if the same stress voltage (StressVoltage) is applied to the two transistors, there are slight differences in the time required for the oxide layer to be depleted, and the breakdown moment of one transistor will be slightly earlier than the other transistor. In the embodiment of the present disclosure, the states of the first electronic component and the corresponding second electronic component can be different based on the process deviation of a certain characteristic of the two.
[0043] Figure 2 The figure schematically shows a secret sharing diagram of a shared secret chip provided by one embodiment of the present disclosure.
[0044] like Figure 2 As shown, the first integrated circuit module includes 12 first electronic components, and the second integrated circuit module includes 12 second electronic components, wherein each first electronic component corresponds to a second electronic component (such as the first and second electronic components in corresponding positions on the left and right as shown in the figure). After the corresponding first and second electronic components are paired, the states of the first and second electronic components are different (the two states are represented by black and white in the figure). Assuming that "0" represents the state represented by white and "1" represents the state represented by black, the first electronic components form a first secret sequence "010101011010", and the second electronic components form a second secret sequence "101010100101". These two secret sequences are complementary and uniquely exist in the first and second integrated circuit modules, thereby forming a shared secret between the first and second integrated circuit modules.
[0045] Furthermore, a pair of a first electronic component and a second electronic component may be selected as decoding bits for decoding the first secret sequence and the second secret sequence into the same sequence code. Figure 2 As shown, the last first electronic component of the first integrated circuit module is selected as the decoding bit, and correspondingly, the last second electronic component of the second integrated circuit module is selected as the decoding bit. The decoding bit is used to perform an XOR operation with the corresponding secret sequence to achieve decoding. Figure 2As shown, the first 11 bits of the first electronic components form a first secret sequence of "01010101101". After the XOR operation with the decoding bit "0", the decoding sequence is "01010101101". The first 11 bits of the second electronic components form a second secret sequence of "10101010010". After the XOR operation with the decoding bit "1", the decoding sequence is "01010101101". If the decoding sequences of the first and second secret sequences are the same, the first integrated circuit module and the second integrated circuit module can be fully shared.
[0046] Figure 3A A schematic diagram of a secret sharing structure of a shared secret chip provided in one embodiment of the present disclosure is shown schematically.
[0047] like Figure 3A As shown, one embodiment of the present disclosure provides a shared secret structure based on transistors. It can be understood that in actual application scenarios, Figure 3A The two transistors shown in the figure are respectively arranged on a first integrated circuit module and a second integrated circuit module. For two identical transistors, if a forced voltage is applied to the gates of these two transistors at the same time, the process deviations during the production process will cause the thickness of the oxide layer to be inconsistent, and the time for the oxide layer to be exhausted will be different. When the oxide layer of one transistor is exhausted and breaks down, the gate voltage is pulled down, thereby protecting the oxide layer of the other transistor, thus completing the process deviation pairing of this pair of transistors. Because the state difference between the two transistors is generated based on the random process deviation, when multiple pairs of transistors on the first integrated circuit module and the second integrated circuit module complete the process deviation pairing, the first integrated circuit module and the second integrated circuit module establish a shared secret that exists only between the two.
[0048] Figure 3B The figure schematically shows a schematic diagram of completing pairing of a shared secret chip provided by one embodiment of the present disclosure.
[0049] like Figure 3BAs shown, when the same voltage is applied to the gates of corresponding transistors on the first and second integrated circuit modules, based on process variation matching, the gate voltage of one transistor is a low level "0" and the gate voltage of the other transistor is a high level "1." If the multiple transistors on the first integrated circuit module form a first secret sequence "1010011," the multiple transistors on the second integrated circuit module correspondingly form a second secret sequence "0101100." The first and second secret sequences are essentially composed of electronic components and are generated based on process variations, resulting in randomness. This shared secret exists only between the first and second integrated circuit modules, eliminating the need for secure key storage and external storage or maintenance, reducing key maintenance costs.
[0050] Figure 4 A schematic diagram of a secret sharing structure of a shared secret chip provided by another embodiment of the present disclosure is schematically shown.
[0051] like Figure 4 As shown, another embodiment of the present disclosure provides a secret sharing structure based on a ring oscillator. The figure only schematically shows the secret sharing structure in the first integrated circuit module (Chip1). The secret sharing structure in the second integrated circuit module (Chip2) is the same as the first integrated circuit module. The secret sharing structure includes multiple ring oscillators, a signal comparator, an asynchronous counter (Asyh-cnt) and a counter comparator (Const). The signal comparator includes a first input terminal, a second input terminal and an output terminal. When at least one of the first input terminal and the second input terminal inputs a low level, the output terminal outputs a low level signal; multiple ring oscillators are connected in parallel, and the input terminal is connected to the output terminal of the signal comparator. One of the ring oscillators can be selected to be enabled by a multiplexer; the asynchronous counter is connected to the output terminal of the ring oscillator and is used to record the number of flips of the ring oscillator when a certain ring oscillator is enabled; the input terminal of the counter comparator is connected to the output terminal of the asynchronous counter, and the output terminal is connected to the second input terminal of the signal comparator. It is used to compare the flip number with a preset constant. When the flip number is less than the preset constant, it outputs a high level, and when the flip number is greater than the preset constant, it outputs a low level.
[0052] For ease of explanation, the following description adds the word "first" before the name of each component in the first integrated circuit module, and adds the word "second" before the name of each component in the second integrated circuit module to distinguish them.
[0053] like Figure 4As shown, each of the first and second integrated circuit modules has two ports, defined here as port 1 (the upper port) and port 2 (the lower port) based on their vertical position. These ports are connected to the two input ports of the signal comparator in each module. Port 1 of the first integrated circuit module is connected to port 2 of the second integrated circuit module, and the signal transmitted between the ports is En2. Port 2 of the first integrated circuit module is connected to port 1 of the second integrated circuit module, and the signal transmitted between the ports is En1. The difference in the frequency counts of the first and second ring oscillators is solely due to process variations during the production process. When signals En1 and En2 are both high, the selected first and second ring oscillators on the first and second integrated circuit modules are enabled, and their rollover counts are tracked by an asynchronous counter. When the rollover count of one of the ring oscillators reaches a preset threshold first, the corresponding signal comparator outputs a low signal, causing both the first and second ring oscillators to stop oscillating. By performing a one-time programming on the ring oscillator with the higher oscillation frequency, it can be disabled, thus completing the pairing of a set of ring oscillators.
[0054] In practical applications, simply checking whether the first ring oscillator and the corresponding second ring oscillator can start oscillating can determine their pairing status. Once multiple pairs of ring oscillators on the first and second integrated circuit modules are paired, the first and second integrated circuit modules establish a shared secret that exists only between them.
[0055] It should be noted that the first secret sequence and the second secret sequence are not stored as data in the first integrated circuit module and the second integrated circuit module, but are only represented by the working status of the multiple first electronic components and the multiple second electronic components. Therefore, the outside world cannot obtain them through intrusion.
[0056] A shared secret chip, according to embodiments of the present disclosure, can establish a shared secret between a first integrated circuit module and a second integrated circuit module based on process variations between identical electronic components. This shared secret, which cannot be accessed externally, can be used to generate session keys for use with other cryptographic functions, thereby enhancing the security of encrypted information. This shared secret chip has a simple structure and low security maintenance costs, making it widely applicable in the information security field.
[0057] Understandably, Figure 3A 、 4 The two types of secret sharing structures shown are only two feasible embodiments, and the secret sharing structure is not limited to the following. Figure 3A 、 4The two types shown can be further expanded to enable electronic components or circuits that are paired based on process deviations to form a secret sharing structure.
[0058] Figure 5 The figure schematically shows the composition of a shared secret device provided by one embodiment of the present disclosure.
[0059] like Figure 5 As shown, one embodiment of the present disclosure provides a shared secret device, comprising a first shared secret chip and a second shared secret chip. In this embodiment, the first shared secret chip can be provided with at least one first integrated circuit module (only one module is schematically shown in the figure), and the second shared secret chip can be provided with at least one second integrated circuit module. The first integrated circuit module is provided with a plurality of first electronic components, and the second integrated circuit module is provided with a plurality of second electronic components.
[0060] In the corresponding first integrated circuit module and the second integrated circuit module, the first electronic components correspond to the second electronic components one by one, and each first electronic component is the same as the corresponding second electronic component. A plurality of first electronic components constitute a first secret sequence, and a corresponding plurality of second electronic components constitute a second secret sequence. The states of the first electronic components and the second electronic components corresponding to the first secret sequence and the second secret sequence are different, forming a secret sharing between the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on the process deviation between the two during the preparation process. The principle of achieving state matching of the first electronic components and the second electronic components based on process deviation is similar to Figure 1 、 2 The matching principle is the same as that described in , so it will not be repeated here.
[0061] Figure 6A The following schematically shows a secret sharing structure of a shared secret device provided by one embodiment of the present disclosure.
[0062] like Figure 6A As shown, optionally, multiple first integrated circuit modules can be set on the first shared secret chip, and the multiple first integrated circuit modules can correspond to multiple second integrated circuit modules on a second shared secret chip. Each first integrated circuit module forms a secret sharing with the corresponding second integrated circuit module, so that the shared secret can be used to achieve information security protection specific to a certain integrated circuit module.
[0063] Figure 6B The following schematically shows the composition of a secret sharing structure of a shared secret device provided by another embodiment of the present disclosure.
[0064] like Figure 6B As shown, optionally, multiple first integrated circuit modules can be set on the first shared secret chip, and the multiple first integrated circuit modules respectively form secret sharing with the second integrated circuit modules on the multiple second shared secret chips, so that the first shared secret chip and each second shared secret chip respectively have a unique shared secret.
[0065] Figure 7 The present invention schematically shows a flow chart of a method for preparing a shared secret chip provided in one embodiment of the present disclosure.
[0066] like Figure 7 As shown, the method for preparing a shared secret chip provided by an embodiment of the present disclosure includes operations S710 to S720.
[0067] In operation S710 , a plurality of first electronic components are provided in a first integrated circuit module of a shared secret chip, and a plurality of second electronic components are provided in a second integrated circuit module of the shared secret chip.
[0068] In the disclosed embodiment, the first electronic components correspond one-to-one with the second electronic components, and each first electronic component is identical to the corresponding second electronic component. Optionally, the first electronic components on the first integrated circuit module may be all identical or not, but the second electronic components on the second integrated circuit module are identical to the first electronic components.
[0069] In operation S720, the first electronic component is matched with the corresponding second electronic component, including: simultaneously testing the first electronic component and the corresponding second electronic component under a first measurement condition, and based on a process deviation between the first electronic component and the corresponding second electronic component, making one of the first electronic component and the second electronic component meet a preset condition first, so as to change the state of the first electronic component or the second electronic component that meets the preset condition.
[0070] References Figure 3A In the illustrated embodiment, the first electronic component and the corresponding second electronic component are transistors, and the first measurement condition is to apply the same gate voltage to both transistors. Due to process variations during production, the oxide layer thicknesses can be inconsistent, resulting in different times for the two oxide layers to deplete. When the oxide layer of one transistor depletes and breaks down, the gate voltage is lowered, thereby protecting the oxide layer of the other transistor, thereby completing the process variation matching of the pair of transistors.
[0071] Referring to the embodiment shown in FIG3 , in this embodiment, the first and second electronic components are ring oscillators. The first measurement condition is to enable the first and second ring oscillators using the same voltage signal. During this process, a counting circuit (including an asynchronous counter and a counter comparator) records their oscillation frequencies (i.e., rollover counts), and the asynchronous counter keeps track of the counts. When the rollover count of one of the ring oscillators reaches a preset threshold first, both the first and second ring oscillators are stopped, and the ring oscillator with the higher oscillation frequency is once-programmed, rendering it inoperable, thereby completing the pairing of a pair of ring oscillators.
[0072] According to the method for fabricating a shared secret chip provided by an embodiment of the present disclosure, multiple first electronic components form a first secret sequence, and corresponding multiple second electronic components form a second secret sequence. The first and second secret sequences have different states for the corresponding first and second electronic components, thereby forming a secret sharing mechanism that exists only between the first and second integrated circuit modules. This method has the advantages of being simple, easy to implement, and having low fabrication costs.
[0073] It is understood that the shared secret chip prepared based on this method should be implemented in a safe and reliable environment to avoid leaking secrets during the preparation process. The first measurement condition can be specifically selected based on the type of process deviation of the first electronic component and the second electronic component, and is not limited here.
[0074] This method can also be used for Figure 5 、 6A The shared secret devices shown in 6B are prepared in the same manner and will not be described in detail here.
[0075] Figure 8 The following schematically shows a flow chart of an application method of a shared secret chip provided by one embodiment of the present disclosure.
[0076] like Figure 8 As shown, an application method of a shared secret chip provided by an embodiment of the present disclosure includes operations S810 to S850.
[0077] In operation S810, data to be encrypted is obtained through a first integrated circuit module.
[0078] In operation S820, the first integrated circuit module is controlled to generate a random session key, and the session key is used to encrypt the data to be encrypted to obtain encrypted data.
[0079] In operation S830 , the first integrated circuit module is controlled to obtain a first secret sequence and encrypt a session key according to the first secret sequence.
[0080] In this embodiment, an encryption detection code can be pre-installed in the chip or system where the first integrated circuit module is located. When the code detects data to be encrypted, it controls the first integrated circuit module to detect multiple first electronic components on the first integrated circuit module to identify the status of the multiple first electronic components. For example, assuming that the first electronic components are transistors, a preset detection circuit can sequentially apply detection voltages to the gates of the multiple first electronic components on the first integrated circuit module and detect the high and low output levels of the multiple first electronic components. The output level of the first electronic component with a depleted oxide layer is low, and the output level of the first electronic component with an undepleted oxide layer is high. Based on the status of the multiple first electronic components, a first secret sequence is generated.
[0081] In this embodiment, the first secret sequence is not stored as data within the first integrated circuit module. Instead, it represents the operating status of the first and second electronic components. This secret sequence is known only to the first integrated circuit module during the encryption process, making it inaccessible to outsiders through intrusion, resulting in high security. Therefore, compared to session keys encrypted using an encryption algorithm, session keys encrypted using the first shared secret sequence are less vulnerable to attack, thereby enhancing the security of encrypted data based on session key encryption.
[0082] In operation S840, the encrypted data and the encrypted session key are sent to the second integrated circuit module through the first integrated circuit module.
[0083] In operation S850, the second integrated circuit module is controlled to obtain the second secret sequence and decrypt the session key according to the second secret sequence, so that the second integrated circuit module decrypts the encrypted data according to the session key.
[0084] In this embodiment, a decryption detection code can be pre-set in the chip or system where the second integrated circuit module is located. When the decryption detection code detects the encrypted data to be decrypted, the second integrated circuit module is controlled to detect the multiple second electronic components on the second integrated circuit module to identify the status of the multiple second electronic components. For example, assuming that the multiple second electronic components are ring oscillators, a starting voltage can be applied to the multiple second electronic components in sequence through a preset detection circuit to detect whether they can oscillate. Based on the oscillation status of the multiple second electronic components, a second secret sequence is generated. Since the second electronic components and the first electronic components on the first integrated circuit module are matched during the preparation process, the corresponding states of the second electronic components and the first electronic components are different. Therefore, when the second integrated circuit module identifies the status of the multiple second electronic components, the first secret sequence can be correspondingly obtained, thereby implementing decryption.
[0085] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways, even if such combinations and / or couplings are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or couplings are intended to fall within the scope of this disclosure.
[0086] Although the present disclosure has been shown and described with reference to certain exemplary embodiments thereof, it will be understood by those skilled in the art that various changes in form and details may be made to the present disclosure without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents. Therefore, the scope of the present disclosure should not be limited to the above-described embodiments, but should be determined not only by the appended claims but also by the equivalents of the appended claims.
Claims
1. A shared secret chip, characterized in that: include: a first integrated circuit module; a plurality of first electronic components, provided on the first integrated circuit module; a second integrated circuit module; a plurality of second electronic components, provided on the second integrated circuit module; The first electronic components correspond to the second electronic components one by one, and each first electronic component is identical to the corresponding second electronic component; A plurality of the first electronic components constitute a first secret sequence, and a corresponding plurality of the second electronic components constitute a second secret sequence. The states of the first electronic components and the second electronic components corresponding to the first secret sequence and the second secret sequence are different, forming a secret sharing between the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on the process deviation between the two during the preparation process.
2. The shared secret chip according to claim 1, characterized in that The first electronic component includes a transistor.
3. The shared secret chip according to claim 1, characterized in that The first electronic component includes a ring oscillator.
4. The shared secret chip according to claim 3, characterized in that The first electronic component further includes: a signal comparator comprising a first input terminal, a second input terminal and an output terminal, wherein the output terminal is connected to the input terminal of the ring oscillator, wherein when at least one of the first input terminal and the second input terminal inputs a low level, the output terminal outputs a low level signal; an asynchronous counter connected to the output end of the ring oscillator and used to record the number of flips of the ring oscillator; A counting comparator, whose input end is connected to the output end of the asynchronous counter and whose output end is connected to the second input end, is used to compare the flip number with a preset constant, and output a high level when the flip number is less than the preset constant, and output a low level when the flip number is greater than the preset constant.
5. The shared secret chip according to claim 1, characterized in that The multiple first electronic components are all the same.
6. The shared secret chip according to claim 1, characterized in that The multiple first electronic components are not completely the same.
7. A shared secret device, characterized in that include: A first shared secret chip includes at least one first integrated circuit module, wherein the first integrated circuit module includes a plurality of first electronic components; a second shared secret chip, comprising at least one second integrated circuit module, wherein the second integrated circuit module comprises a plurality of second electronic components; In the corresponding first integrated circuit module and the second integrated circuit module, the first electronic components correspond to the second electronic components one by one, and each first electronic component is the same as the corresponding second electronic component; A plurality of the first electronic components constitute a first secret sequence, and a corresponding plurality of the second electronic components constitute a second secret sequence. The states of the first electronic components and the second electronic components corresponding to the first secret sequence and the second secret sequence are different, forming a secret sharing between the first integrated circuit module and the second integrated circuit module, wherein the different states of the first electronic components and the corresponding second electronic components are achieved based on the process deviation between the two during the preparation process.
8. A method for preparing a shared secret chip, characterized in that: include: A plurality of first electronic components are provided in a first integrated circuit module of the shared secret chip, and a plurality of second electronic components are provided in a second integrated circuit module of the shared secret chip, wherein the first electronic components correspond to the second electronic components one-to-one, and each first electronic component is identical to the corresponding second electronic component; Matching the first electronic component with the corresponding second electronic component includes: Simultaneously testing the first electronic component and the corresponding second electronic component under a first measurement condition, and based on process deviations between the first electronic component and the corresponding second electronic component, causing one of the first electronic component and the second electronic component to first meet a preset condition, thereby changing the state of the first electronic component or the second electronic component that meets the preset condition; Among them, multiple first electronic components constitute a first secret sequence, and corresponding multiple second electronic components constitute a second secret sequence. The states of the first electronic components and the second electronic components corresponding to the first secret sequence and the second secret sequence are different, forming a secret sharing between the first integrated circuit module and the second integrated circuit module.
9. The method according to claim 8, characterized in that The first electronic component and the corresponding second electronic component are transistors, and the simultaneously testing the first electronic component and the corresponding second electronic component under the first measurement condition, and based on process deviations between the first electronic component and the corresponding second electronic component, making one of the first electronic component and the second electronic component meet a preset condition first, thereby changing the state of the first electronic component or the second electronic component that meets the preset condition, includes: The same preset voltage is applied to the gates of the first electronic component and the corresponding second electronic component simultaneously until the oxide layer of one of the first electronic component and the second electronic component is exhausted, thereby lowering the gate voltage and protecting the other one.
10. The method according to claim 8, characterized in that The first electronic component and the corresponding second electronic component are ring oscillators, and the simultaneously testing the first electronic component and the corresponding second electronic component under the first measurement condition, and based on the process deviation of the first electronic component and the corresponding second electronic component, making one of the first electronic component and the second electronic component meet the preset condition first, so as to change the state of the first electronic component or the second electronic component that meets the preset condition, includes: enabling the first ring oscillator and the second ring oscillator using the same voltage signal; recording the oscillation frequencies of the first ring oscillator and the second ring oscillator based on counting circuits on the first integrated circuit module and the second integrated circuit module until the oscillation frequency of one of the first ring oscillator and the second ring oscillator reaches a preset threshold; The first ring oscillator or the second ring oscillator whose oscillation frequency reaches a preset threshold is programmed once, so that the programming states of the corresponding first ring oscillator and second ring oscillator are different.
11. A shared secret chip application method, applied to the shared secret chip according to any one of claims 1 to 6, characterized in that: include: obtaining data to be encrypted through the first integrated circuit module; Controlling the first integrated circuit module to generate a random session key, and encrypting the data to be encrypted using the session key to obtain encrypted data; controlling the first integrated circuit module to obtain a first secret sequence, and encrypting the session key according to the first secret sequence; sending the encrypted data and the encrypted session key to the second integrated circuit module through the first integrated circuit module; The second integrated circuit module is controlled to obtain a second secret sequence and decrypt the session key according to the second secret sequence, so that the second integrated circuit module decrypts the encrypted data according to the session key.
12. The method according to claim 11, characterized in that The controlling the first integrated circuit module to obtain the first secret sequence includes: controlling the first integrated circuit module to detect a plurality of first electronic components on the first integrated circuit module to identify states of the plurality of first electronic components; generating the first secret sequence based on the states of the plurality of first electronic components; The controlling the second integrated circuit module to obtain the second secret sequence comprises: controlling the second integrated circuit module to detect a plurality of second electronic components on the second integrated circuit module to identify states of the plurality of second electronic components; The second secret sequence is generated based on the states of the plurality of second electronic components.
Citation Information
Patent Citations
Systems and methods for stable physical non-cloning functions
CN107017990A
Integrated circuit configured to perform symmetric encryption operations with secret key protection
CN113204800A