Memory device identification system and method based on physically unclonable functions
Patent Information
- Application Number
- CN202210201419.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-08-05
- Filing Date
- 2022-03-02
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2042-03-02
Smart Images

Figure CN115938432B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of this disclosure relate to a scheme for identifying memory devices in a memory system. Background Technology
[0002] The computing environment paradigm has shifted to ubiquitous computing systems that can be used anytime, anywhere. Consequently, the use of portable electronic devices such as mobile phones, digital cameras, and laptops has increased rapidly. These portable electronic devices typically use memory systems with storage devices, or data storage devices. The data storage device serves as either the main memory or auxiliary memory device in the portable electronic device.
[0003] Because memory systems using memory devices have no moving parts, they offer excellent stability, durability, high data access speeds, and low power consumption. Examples of memory systems with these advantages include Universal Serial Bus (USB) memory devices, memory cards with various interfaces (e.g., Universal Flash Memory (UFS)), and solid-state drives (SSDs).
[0004] Even when using the same manufacturing process to manufacture the same type of memory system (or storage device), differences in the physical or electrical parameters of the memory system will inevitably occur. A memory system that utilizes unpredictable differences in the manufacturing process to produce theoretically unpredictable results and possesses the inherent characteristics of the corresponding system is called a Physically Unclonable Function (PUF) circuit. That is, the characteristics of the memory system are identified using a physically unclonable function. In this context, embodiments of the present invention arise. Summary of the Invention
[0005] Aspects of the present invention include systems and methods for identifying memory devices using physically unclonable features.
[0006] In one aspect of the invention, a system includes an identification device comprising a controller and a memory device coupled to the controller and comprising a plurality of blocks. The controller is configured to: perform multiple raw read operations on each page of a block selected from the plurality of blocks; classify the pages of the selected block into a low group and a high group using the average number of "1"s obtained based on the multiple raw read operations; generate a plurality of unordered page pairs by sequentially selecting a page from the low group as the first page of each unordered page pair and selecting a page from the high group as the second page of each unordered page pair; generate a plurality of ordered page pairs by selectively transposing the order of pages in each of the plurality of unordered page pairs based on the address order between the first page of the low group and the next page following the first page of the low group; and generate a sequence for identifying the selected block based on comparing the average number of "1"s of the preceding and following pages in each of the plurality of ordered page pairs.
[0007] In another aspect of the invention, a method for operating an identifiable device includes a controller and a memory device coupled to the controller and including a plurality of blocks. The method includes: performing multiple raw read operations on each page of a block selected from the plurality of blocks; classifying the pages of the selected block into a low group and a high group using the average number of "1"s obtained based on the multiple raw read operations; generating a plurality of unordered page pairs by sequentially selecting a page from the low group as the first page of each unordered page pair and selecting a page from the high group as the second page of each unordered page pair; generating a plurality of ordered page pairs by selectively transposing the order of pages in each of the plurality of unordered page pairs based on the address order between the first page of the low group and the next page following the first page of the low group; and generating a sequence for identifying the selected block based on comparing the average number of "1"s of the preceding and following pages in each of the plurality of ordered page pairs.
[0008] Other aspects of the invention will become apparent from the following description. Attached Figure Description
[0009] Figure 1 This is a block diagram illustrating a data processing system according to an embodiment of the present invention.
[0010] Figure 2 This is a block diagram illustrating a memory system according to an embodiment of the present invention.
[0011] Figure 3 This is a circuit diagram illustrating a memory block of a memory device according to an embodiment of the present invention.
[0012] Figure 4 This is a diagram illustrating a data processing system according to an embodiment of the present invention.
[0013] Figure 5 This is a diagram illustrating a system for generating a sequence of identification memory devices according to an embodiment of the present invention.
[0014] Figure 6 This is a flowchart illustrating a method for generating a sequence for identifying a memory device according to an embodiment of the present invention.
[0015] Figure 7 This is a graph showing the average number of "1"s obtained during the initial read operation of two memory blocks of a memory device according to an embodiment of the present invention.
[0016] Figure 8 It is a graph showing the average number of "1"s obtained and sorted during the initial read operation of two memory blocks of a memory device according to an embodiment of the present invention.
[0017] Figure 9 This is a graph showing the number of "1"s obtained during two raw read operations of two memory blocks in a memory device according to an embodiment of the present invention, as well as the average number of "1"s.
[0018] Figure 10 This is a diagram illustrating the operation of forming a challenge according to an embodiment of the present invention. Detailed Implementation
[0019] Various embodiments of the invention are described in more detail below with reference to the accompanying drawings. However, the invention may be implemented in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art. Furthermore, references herein to “embodiment,” “another embodiment,” etc., are not necessarily directed to only one embodiment, and different references to any such phrases are not necessarily directed to the same embodiment. Throughout this disclosure, the same reference numerals in the drawings and embodiments of the invention refer to the same parts.
[0020] This invention can be embodied in a variety of ways, including as: a process; an apparatus; a system; a computer program product implemented on a computer-readable storage medium; and / or a processor, such as a processor adapted to execute instructions stored on and / or provided thereto in memory coupled to a processor. In this specification, these embodiments or any other form in which the invention may take the form of a technique may be referred to. Generally, the order of steps of the disclosed process may be varied within the scope of the invention. Unless otherwise stated, components described as suitable for performing a task, such as processors or memory, may be implemented as general components temporarily configured to perform a task at a given time or manufactured as specific components for performing a task. As used herein, the term "processor," etc., refers to one or more means, circuits, and / or processing cores suitable for processing data (e.g., computer program instructions).
[0021] The following provides a detailed description of embodiments of the invention, along with accompanying drawings illustrating aspects of the invention. The invention has been described in conjunction with these embodiments, but is not limited to any particular embodiment. The scope of the invention is limited only by the claims. The invention encompasses many alternatives, modifications, and equivalents within the scope of the claims. Numerous specific details are set forth in the following description to provide a thorough understanding of the invention. These details are provided for illustrative purposes only; the invention may be practiced without some or all of these specific details, according to the claims. For clarity, technical materials known in the art related to the invention have not been described in detail, so as not to unnecessarily obscure the invention.
[0022] Figure 1 This is a block diagram illustrating a data processing system 2 according to an embodiment of the present invention.
[0023] Reference Figure 1 The data processing system 2 may include a host device 5 and a memory system 10. The memory system 10 may receive requests from the host device 5 and operate in response to the received requests. For example, the memory system 10 may store data to be accessed by the host device 5.
[0024] The host device 5 can be implemented using any of a variety of electronic devices. In various embodiments, the host device 5 may include electronic devices such as: a desktop computer, a workstation, a 3D television, a smart television, a digital audio recorder, a digital audio player, a digital picture recorder, a digital picture player, and / or a digital video recorder and a digital video player. In various embodiments, the host device 5 may include portable electronic devices such as: a mobile phone, a smartphone, an e-book reader, an MP3 player, a portable multimedia player (PMP), and / or a portable game console.
[0025] The memory system 10 can be implemented using any of a variety of storage devices such as solid-state drives (SSDs) and memory cards. In various embodiments, the memory system 10 can be configured as a component of a variety of electronic devices such as: computers, ultra-mobile personal computers (UMPCs), workstations, netbooks, personal digital assistants (PDAs), portable computers, network tablets, wireless phones, mobile phones, smartphones, e-book readers, portable multimedia players (PMPs), portable gaming devices, navigation devices, black boxes, digital cameras, digital multimedia broadcasting (DMB) players, 3D televisions, smart televisions, digital audio recorders, digital audio players, digital image recorders, digital image players, digital video recorders, digital video players, data center storage devices, devices capable of receiving and transmitting information in a wireless environment, radio frequency identification (RFID) devices, and a variety of electronic devices for home networks, computer networks, telematics networks, or components of computing systems.
[0026] The memory system 10 may include a memory controller 100 and a semiconductor memory device 200. The memory controller 100 can control all operations of the semiconductor memory device 200.
[0027] The semiconductor memory device 200 can perform one or more erase, program, and read operations under the control of the memory controller 100. The semiconductor memory device 200 can receive commands (CMD), addresses (ADDR), and data (DATA) via input / output lines. The semiconductor memory device 200 can receive power (PWR) via power lines and control signals (CTRL) via control lines. Depending on the design and configuration of the memory system 10, the control signal CTRL may include command latch enable signals, address latch enable signals, chip enable signals, write enable signals, read enable signals, and other operation signals.
[0028] The memory controller 100 and the semiconductor memory device 200 can be integrated into a single semiconductor device such as a solid-state drive (SSD). The SSD may include a storage device for storing data. When the memory system 10 is used in an SSD, the performance of host devices connected to the memory system 10 can be significantly improved (e.g., Figure 1 The operating speed of the main unit 5).
[0029] The memory controller 100 and the semiconductor memory device 200 can be integrated into a single semiconductor device such as a memory card. For example, the memory controller 100 and the semiconductor memory device 200 can be integrated to configure PC cards, compact flash memory (CF) cards, smart media (SM) cards, memory sticks, multimedia cards (MMC), miniature multimedia cards (RS-MMC), micro-versions of MMC (micro MMC), secure digital cards (SD cards), mini secure digital cards (mini SD cards), micro secure digital cards (micro SD cards), secure digital high capacity (SDHC) and / or universal flash memory (UFS).
[0030] Figure 2 This is a block diagram illustrating a memory system according to an embodiment of the present invention. For example, Figure 2 The memory system can be described Figure 1 The memory system 10 shown.
[0031] Reference Figure 2 The memory system 10 may include a memory controller 100 and a semiconductor memory device 200. The memory system 10 can respond to input from a host device (e.g., Figure 1 The host device 5) operates upon request and, in particular, stores data to be accessed by the host device.
[0032] The semiconductor memory device 200 can store data to be accessed by a host device.
[0033] The semiconductor memory device 200 can be implemented using volatile memory devices such as dynamic random access memory (DRAM) and / or static random access memory (SRAM), or non-volatile memory devices such as read-only memory (ROM), mask ROM (MROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), ferroelectric random access memory (FRAM), phase change RAM (PRAM), magnetoresistive RAM (MRAM) and / or resistive RAM (RRAM).
[0034] The memory controller 100 can control the storage of data in the semiconductor memory device 200. For example, the memory controller 100 can control the semiconductor memory device 200 in response to a request from a host device. The memory controller 100 can provide data read from the semiconductor memory device 200 to the host device, and can store data provided from the host device into the semiconductor memory device 200.
[0035] The memory controller 100 may include a storage device 110 connected via a bus 160, a control component 120 which may be implemented as a processor such as a central processing unit (CPU), an error correction code (ECC) component 130, a host interface (I / F) 140, and a memory interface (I / F) 150.
[0036] Storage device 110 can be used as working memory for memory system 10 and memory controller 100, and stores data for driving memory system 10 and memory controller 100. When memory controller 100 controls the operation of semiconductor memory device 200, storage device 110 can store data used by memory controller 100 and semiconductor memory device 200 for performing operations such as read operations, write operations, programming operations and erase operations.
[0037] Storage device 110 can be implemented using volatile memory such as static random access memory (SRAM) or dynamic random access memory (DRAM). As described above, storage device 110 can store data used by the host device in semiconductor memory device 200 for read and write operations. For storing data, storage device 110 may include program memory, data memory, write buffer, read buffer, mapping buffer, etc.
[0038] The control component 120 can control the general operation of the memory system 10, and in particular, control the corresponding operation of the semiconductor memory device 200 in response to write or read requests from the host device. The control component 120 can drive firmware called a flash translation layer (FTL) to control the general operation of the memory system 10. For example, the FTL can perform operations such as logical-physical (L2P) mapping, wear leveling, garbage collection, and / or bad block disposal. L2P mapping is referred to as logical block addressing (LBA).
[0039] ECC component 130 can detect and correct errors in data read from semiconductor memory device 200 during a read operation. When the number of error bits is greater than or equal to the threshold number of correctable error bits, ECC component 130 may not correct the error bits, but may instead output an error correction failure signal indicating that the correction of the error bits has failed.
[0040] In various embodiments, ECC component 130 may perform error correction operations based on coding modulations such as low-density parity-check (LDPC) codes, Bose-Chaudhuri-Hocquenghem (BCH) codes, turbo codes, turbo product codes (TPC), Reed-Solomon (RS) codes, convolutional codes, recursive systematic codes (RSC), trellis-coded modulation (TCM), or block-coded modulation (BCM). However, error correction is not limited to these techniques. Therefore, ECC component 130 may include any and all circuitry, systems, or devices suitable for error correction operations.
[0041] The host interface 140 can communicate with the host device through one or more of the following interface protocols: Universal Serial Bus (USB), Multimedia Card (MMC), High-Speed Peripheral Component Interconnect (PCI-e or PCIe), Small Computer System Interface (SCSI), Serial SCSI (SAS), Serial Advanced Technology Attachment (SATA), Parallel Advanced Technology Attachment (PATA), Enhanced Small Disk Interface (ESDI), and / or Electronic Integrated Drive (IDE).
[0042] Memory interface 150 provides an interface between memory controller 100 and semiconductor memory device 200, allowing memory controller 100 to control semiconductor memory device 200 in response to requests from host device. Memory interface 150 can generate control signals for semiconductor memory device 200 and process data under the control of control component 120. When semiconductor memory device 200 is flash memory such as NAND flash memory, memory interface 150 can generate control signals for memory and process data under the control of control component 120.
[0043] Semiconductor memory device 200 may include a memory cell array 210, control circuitry 220, voltage generation circuitry 230, row decoder 240, page buffer array 250 (which may be in the form of a page buffer array), column decoder 260, and input / output (I / O) circuitry 270. The memory cell array 210 may include multiple memory blocks 211 capable of storing data. The voltage generation circuitry 230, row decoder 240, page buffer array 250, column decoder 260, and I / O circuitry 270 may form peripheral circuitry for the memory cell array 210. The peripheral circuitry may perform programming, reading, or erasing operations on the memory cell array 210. The control circuitry 220 may control the peripheral circuitry.
[0044] The voltage generation circuit 230 can generate operating voltages of various levels. For example, in an erase operation, the voltage generation circuit 230 can generate operating voltages of various levels, such as erase voltage and pass voltage.
[0045] The line decoder 240 can communicate electrically with the voltage generation circuit 230 and a plurality of memory blocks 211. In response to a line address generated by the control circuit 220, the line decoder 240 can select at least one memory block among the plurality of memory blocks 211 and transmit the operating voltage supplied from the voltage generation circuit 230 to the selected memory block.
[0046] Page buffer array 250 can be accessed via bit line BL ( Figure 3 (As shown) is connected to the memory cell array 210. The page buffer array 250 can precharge the bit line BL with a positive voltage during programming and reading operations, transfer data to and receive data from the selected memory block, or temporarily store the transferred data in response to a page buffer control signal generated by the control circuit 220.
[0047] The column decoder 260 can transmit data to and receive data from the page buffer array 250, or transmit data to and receive data from the input / output circuit 270.
[0048] Input / output circuit 270 can input from external devices (e.g., Figure 1 The memory controller 100 receives commands and addresses and transmits them to the control circuit 220, which transmits data from the external device to the column decoder 260, or outputs data from the column decoder 260 to the external device via the input / output circuit 270.
[0049] The control circuit 220 can control the peripheral circuits in response to commands and addresses.
[0050] Figure 3 This is a circuit diagram illustrating a memory block of a semiconductor memory device according to an embodiment of the present invention. For example, Figure 3 The storage block can be Figure 2 Any one of the storage blocks 211 in the memory cell array 210 shown.
[0051] Reference Figure 3 Storage block 211 may include multiple word lines WL0 to WLn-1, drain select line DSL, and source select line SSL connected to line decoder 240. These lines may be arranged in parallel, with multiple word lines arranged between DSL and SSL.
[0052] The memory block 211 may further include multiple cell strings 221 respectively connected to bit lines BL0 to BLm-1. Each column of cell strings may include one or more drain select transistors (DSTs) and one or more source select transistors (SSTs). In the illustrated embodiment, each cell string has one DST and one SST. Within the cell string, multiple memory cells or memory cell transistors MC0 to MCn-1 may be connected in series between the select transistors DST and SST. Each of the memory cells may be configured as a single-level cell (SLC) storing one bit of data, a multi-level cell (MLC) storing two bits of data, a three-level cell (TLC) storing three bits of data, or a four-level cell (QLC) storing four bits of data.
[0053] The source of each SST in a cell string can be connected to the common source line CSL, and the drain of each DST can be connected to the corresponding bit line. The gate of an SST in a cell string can be connected to SSL, and the gate of a DST in a cell string can be connected to DSL. The gates of all memory cells in a cell string can be connected to their respective word lines. That is, the gate of memory cell MC0 is connected to the corresponding word line WL0, the gate of memory cell MC1 is connected to the corresponding word line WL1, and so on. A group of memory cells connected to a specific word line can be called a physical page. Therefore, the number of physical pages in memory block 211 can correspond to the number of word lines.
[0054] Page buffer array 250 may include multiple page buffers 251 (PB) connected to bit lines BL0 to BLm-1. Page buffers 251 may operate in response to page buffer control signals. For example, page buffers 251 may temporarily store data received through bit lines BL0 to BLm-1 or sense the voltage or current of the bit lines during read or verification operations.
[0055] In some embodiments, memory block 211 may include NAND flash memory cells. However, memory block 211 is not limited to this cell type, but may include NOR flash memory cells. Memory cell array 210 may be implemented as a hybrid flash memory combining two or more types of memory cells, or as a one-NAND flash memory with the controller embedded inside the memory chip.
[0056] Figure 4 This is a diagram illustrating a data processing system 2 according to an embodiment of the present invention.
[0057] Reference Figure 4 The data processing system 2 may include a host device 5 and a memory system 10. The memory system 10 may include a memory controller 100 and a semiconductor memory device 200. The memory controller 100 may include firmware (FW), which is a type of software specifically designed to control various operations (e.g., read operations, write operations, and erase operations) of the semiconductor memory device 200. In some embodiments, the firmware may reside in the storage device 110 and may be generated by... Figure 2 The control component 120 is running.
[0058] Semiconductor memory device 200 may include multiple memory cells (e.g., NAND flash memory cells). The memory cells are arranged in an array of rows and columns, such as... Figure 3 As shown. Cells in a specific row are connected to word lines (e.g., WL0), and cells in a specific column are connected to bit lines (e.g., BL0). These word lines and bit lines are used for read and write operations. During a write operation, the data to be written ("1" or "0") is provided on the bit line when the word line is asserted. During a read operation, the word line is asserted again, and the threshold voltage for each cell can then be obtained from the bit line. Multiple pages can share memory cells belonging to (i.e., connected to) the same word line.
[0059] Physically unclonable functions (PUFs) can be used to identify inherent characteristics of memory devices. Today, PUFs are becoming ubiquitous cryptographic primitives as an alternative to classical cryptographic algorithms in compact digital devices. PUFs utilize uncontrolled manufacturing process variations within integrated circuits (ICs) to provide truly random numbers or unique and reliable cryptographic keys (identifiers). There are various types of PUFs, such as arbiter PUFs, ring oscillator PUFs, SRAM PUFs, and bistable ring PUFs, which are based on different physical characteristics of the IC (e.g., delay difference, frequency, threshold voltage, initial memory state, etc.).
[0060] Memory cells in memory devices, such as NAND flash memory devices, exhibit relatively low reliability in the data path. This necessitates the use of error correction codes (ECCs) with high error correction capabilities, such as BCH or LDPC codes, in the data path. On the other hand, excluding error correction codes from the data path introduces the possibility of generating unique and unpredictable bits from memory cells. Therefore, embodiments provide a scheme for generating unique and unpredictable identifiers (keys) based on physically unclonable features to identify memory devices (e.g., NAND flash memory devices).
[0061] Figure 5 This is a diagram illustrating a system 500 for generating a sequence for identifying a memory device according to an embodiment of the present invention.
[0062] Reference Figure 5 System 500 can use a Physically Unclonable Function (PUF) to generate unique and unpredictable keys or identifiers. PUFs are typically implemented in integrated circuits and are commonly used in applications with high security requirements, more specifically, applications with encryption requirements. PUFs can be based on unique physical changes that occur naturally during the semiconductor manufacturing process.
[0063] System 500 can be used in a memory system (storage device). System 500 can provide a physically defined "digital fingerprint" response (output), which serves as a unique identifier for a given input and condition (challenge). System 500 may include an identifiable device 510 and an identification server 550. In some embodiments, the identifiable device 510 and the identification server 550 respectively correspond to... Figures 1 to 4 The memory system 10 and the host device 5 are included.
[0064] The identification server 550 can generate a challenge value C and transmit the challenge value C to the identifiable device 510. The identifiable device 510 can generate a response R as a sequence of identifiers based on the challenge value C. The identification server 550 may include a challenge generator 552 and an identification (ID) register 554. The challenge generator 552 can generate the challenge value C. The ID register 554 can receive and store the response R.
[0065] The identifiable device 510 may include a memory device 512, a selection (or sampling) component 514, and a comparison component 516. The memory device 512 may correspond to... Figures 1 to 4 The semiconductor memory device 200. The selection component 514 and the comparator component 516 can correspond to... Figures 1 to 4The memory controller 100. The identifiable device 510 can generate a sequence of identifiers (IDs) or keys for identifying the memory device 512, that is, a response R as a unique and unpredictable bit from the memory device 512 (e.g., a NAND memory cell).
[0066] Figure 6 This is a flowchart illustrating a method 600 for generating a sequence for identifying a memory device according to an embodiment of the present invention. Method 600 can be performed by a memory device 512 and a controller (i.e., a selection component 514 and a comparison component 516).
[0067] Reference Figure 6 Method 600 may include operations 610 to 650. Before performing method 600, memory device 512 may erase a block selected from a plurality of blocks and may write a setting mode to all pages of the selected block. In some embodiments, the setting mode may include an all-zero mode.
[0068] In operation 610, memory device 512 may perform multiple raw read operations on each page of a block selected from a plurality of blocks. In some embodiments, each of the multiple raw read operations may include: performing multiple reads on each page of the selected block without applying error correction codes (ECC) to the read pages; and determining the average number of "1"s in each read page.
[0069] In operation 620, selection component 514 may categorize pages of the selected block into a low group and a high group using the average number of "1"s obtained from multiple raw read operations. In some embodiments, the pages of the selected block may be ordered in ascending order based on the average number of "1"s. In some embodiments, the low group may include a set of pages starting with the page with the lowest average number of "1"s, and the high group may include a set of pages starting with the page with the highest average number of "1"s. In some embodiments, the total number of pages in the low and high groups is less than the number of pages in the selected block.
[0070] In operation 630, selection component 514 can generate multiple unordered page pairs by sequentially selecting a page from the lower group as the first page of each unordered page pair and selecting a page from the higher group as the second page of each unordered page pair. In some embodiments, identification server 550 can provide each challenge value to selection component 514 to select a page from the lower group as the first page and select a page from the higher group as the second page.
[0071] In operation 640, selection component 514 can selectively change the order of pages in each of a plurality of unordered page pairs based on the address order between the first page of the lower group and the next page of the lower group following the first page, generating a plurality of ordered page pairs. In some embodiments, for each of the plurality of unordered page pairs, when the addresses of the first page and the next page of the lower group are in descending order, selection component 514 can change the order of the first page and the second page. Further, when the addresses of the first page and the next page of the lower group are in ascending order, selection component 514 may not change the order of the first page and the second page in each of the plurality of unordered page pairs.
[0072] In operation 650, comparison component 516 can generate a sequence for identifying the selected block based on a comparison of the average number of "1"s in the preceding and following pages of each of a plurality of ordered page pairs. In some embodiments, comparison component 516 can transmit the sequence to identification server 550.
[0073] In some embodiments, for each of a plurality of ordered page pairs, the comparison component 516 can compare the average number of "1"s between the previous and next pages. When the average number of "1"s in the next page is higher than the average number in the previous page, the comparison component 516 can generate a bit with a first value. When the average number of "1"s in the previous page is higher than the average number in the next page, the comparison component 516 can generate a bit with a second value.
[0074] Reference Figure 5 and Figures 7 to 10 Describe the details of the ID generation method for System 500.
[0075] The ID generation method of System 500 can be based on raw read operations that bypass error correction codes (ECC) and scrambling processes on the read data in the data path. The ID generation method can include a first stage (registration), a second stage (uniqueness extraction), and a third stage (ID generation). The first stage (registration) can include erasing a selected block of the NAND flash memory and writing a set pattern (e.g., all-zero mode) to all pages within the selected block. Multiple raw read operations can then be performed. During the multiple raw read operations, each page can be characterized by the average number of "1"s obtained through each read operation. The second stage (uniqueness extraction) can include generating a sequence of page addresses using page statistics calculated during registration. In some embodiments, the number of pages can be the same as twice the ID length. The third stage (ID generation) can include comparing the number of "1"s from the pages selected during the raw read operations, thereby allowing the generation of unique ID bits. For two selected and compared pages, if the number of "1"s in the first page is less than that in the second page, an ID bit with a value of 0 can be generated. Otherwise, an ID bit with a value of 1 is generated.
[0076] A page can be the smallest unit of reading in NAND flash memory and can be characterized by the number of bits that flip their values during a read operation. To highlight the flipped bits, a set mode (e.g., all-zero mode) can be programmed into the page. The average number of "1"s obtained during the read operation after multiple raw read operations (i.e., bypassing ECC and scrambling processes) can characterize a page. These statistics can be obtained during the registration phase. In some embodiments, the registration phase may include: erasing the memory block; programming the all-zero mode into all pages of the block in raw mode; reading each page N in raw mode. r Times; and calculate N r The average number of "1"s during the next raw read operation.
[0077] For example, Figure 7 The statistics (N) of two blocks at addresses “0xBE0” and “0x2F0” of memory device 512 are shown. r =100).
[0078] The distribution of the average number of "1"s on the page ( 1≤i≤N p N p The number of pages in a memory block is unique for each block in memory device 512. Therefore, this subtle inherent difference in distribution can be used to design physically unclonable functions based on NAND flash memory. A block diagram of the proposed PUF design for ID generation has been provided. Figure 5 As shown in the image.
[0079] Return to reference Figure 5 In order to generate a single response bit R, the identifiable device 510 can compare the number p of "1"s obtained from two different pages during the original read operation. j and p j (i≠j, 1≤i, j≤N) p It is possible to select p from two different pages based on the challenge value C = (i,j). i and p j The challenge value C can be an ordered pair of page addresses i and j, and its possible values are... One of the values. If p i <p j If the condition is met, then R = 0. Otherwise, R = 1.
[0080] The identifiable device 510 can generate K possible response bits based on the challenge value C. To generate an L-bit ID (L≤K), the identification server 550 can generate L challenges (2L page addresses) and send the L challenges to the identifiable device 510. Therefore, the identifiable device 510 can generate L response bits that uniquely identify the device.
[0081] Due to the inherent instability of NAND, the value p i and p j The values may differ between one read operation and another. This results in inconsistent response values R generated during different read operations for the same address values i and j. Furthermore, the value p... i and p j The order may be different (p i <p j or p i >p j Therefore, a subset of the challenge values must be found to provide a reliable identifier (i.e., a stable response).
[0082] When sorting the average number of "1"s obtained during the registration phase, the average number of "1"s can be divided into... The two groups have lower and higher values. Figure 8 The sorting values are shown.
[0083] Reference Figure 8 The average number of "1"s obtained for each of the two pages in the two blocks "0xBE0" and "0x2F0". and (For example, The larger the difference between i and j), the more likely the order of p will be maintained between the average number of "1"s obtained during any read operation. i >p jThe higher the probability, the better. This observation can also be confirmed based on experimental data obtained from block "0x2F0". Figure 9 The data (i.e., the number of "1"s) obtained during two original read operations (e.g., the 10th and 100th reads) and their average value are shown.
[0084] Reference Figure 9 The p on both pages i (Taken from Pages with higher values) and p j (Taken from The difference between pages with lower values (p) i -p j The sign value (p) can be changed, but for all read operations from 1 to at least 100, the sign value (p) remains unchanged. i -p j The probabilities of the same value being the same are relatively high. Therefore, in order to generate an L-bit identifier, L challenge values C should be selected based on the registration data. k = (i,j), 1≤k≤L. There are multiple ways to do this. In some embodiments, system 500 can generate L challenges to generate an L-bit identification sequence, such as Figure 10 As shown.
[0085] Reference Figure 10 System 500 can generate L challenges through an algorithm that includes the following four steps.
[0086] (1) System 500 can average the number of "1"s obtained during the original read operation. Sort all pages of the selected block in a predetermined order (e.g., ascending order). Therefore, the sequence of page addresses corresponding to the sort value can be represented as follows:
[0087] (2) System 500 can divide the sequence into two L-element subsequences, i.e. The lower value of group A low =(A1,A2,…,A) L )and High value high group In the example shown, the total number of pages in the low and high groups is less than the total number of pages in the selected block.
[0088] (3) In order to generate the k-th bit identifier, the system 500 can form unordered address pairs. Where A k In low group A low middle, In high group A high In the middle. If A k and It is corresponding to A low and A high If selected from the group, then The probability is relatively high. Therefore, disordered pairs should be transformed into ordered pairs (challenge value C) through some unique characteristics. k ).
[0089] (4) System 500 can handle each unordered pair Convert to challenge value or This conversion can be based on low group A. low This is accomplished using a unique address sequence, as shown below:
[0090] (4-a) Consider A low The kth element (A) k ) and the next element (A) k+1 );
[0091] (4-b) If A k <A k+1 Then the unordered pairs will be Convert to
[0092] (4-c) Otherwise, there will be no ordered pairs Convert to as well as
[0093] (4-d) If k = L, then A L+1 Each element is taken from a complete sorted sequence of values.
[0094] The algorithm described above is given as an example only, and can be changed to other algorithms to select the most stable response.
[0095] During the ID generation phase, system 500 can perform 2L raw read operations from the selected page. To generate the k-th bit, the value can be... and Compare them. If this pair of addresses is in most cases... Then the value 0 can be generated. If this pair of addresses is in most cases... Then the value 1 can be generated.
[0096] Therefore, an L-bit identifier can be generated using 2L raw read operations. The challenge value C is... k It can be stored in the memory (not shown) of the identifiable device 500 for better reliability, or generated by selecting L pairs from K possible options.
[0097] The following is an example of how the ID is generated for System 500.
[0098] Figure 7The results of the registration phase for block "0x2F0" are shown.
[0099] The uniqueness extraction stage includes the following operations.
[0100] (Operation 1) Press The list of page addresses sorted by value is as follows: 324, 325, 266, ..., 1, 5, 7 (a total of 576 addresses).
[0101] (Operation 2) To generate an L = 128-bit identifier, the sequence can be divided into two groups, each containing 128 addresses: A low = (A1, A2, A3, ..., A 126 A 127 A 128 )=(324,325,266,...,254,301,242); Ahigh=(A 449 A 450 A 451 A 574 A 575 A 576 ) = (30, 159, 179, ..., 1, 5, 7).
[0102] (Operation 3) Merge the two groups into the sequence represented in List 1:
[0103] List 1:
[0104]
[0105] The ID generation phase can be executed based on the sequence generated in the uniqueness extraction phase, as shown in Listing 2:
[0106] List 2:
[0107]
[0108] The experimental results of the ID generation method for System 500 are described below.
[0109] The 128-bit ID is generated from two different samples (each with 10 blocks at the same address) - a total of 20 IDs.
[0110] Reliability indicates the stability of the IDs generated during T tests (repeated generation). It can be calculated using the following equation:
[0111] In the equation above, HD represents the Hamming distance, and ID... t This represents the ID generated during the t-th test.
[0112] The ideal reliability value is 1.0, meaning that the generated IDs are stable and their values do not change during repeated generation. In the experiment, R = 1.0 for all generated IDs, except for three that were 0.980, 0.989, and 0.990 respectively.
[0113] Uniqueness indicates the difference between IDs generated from different samples (inter-die uniqueness) or different blocks within the same sample (intra-die uniqueness). The ideal value for uniqueness is 0.5, which is the maximum bit difference percentage that can be obtained between binary vectors.
[0114] The uniqueness of m IDs within a die can be calculated as follows:
[0115] For m = 10 IDs (for each sample), the U of sample 1 intra =0.502, U of sample 2 intra =0.498.
[0116] The uniqueness of m IDs located at the same address in two different samples within the die can be calculated as follows:
[0117] Two identical samples (m = 10 for each sample) U inter =0.518.
[0118] Furthermore, the ID generation method of System 500 has undergone a stress test with 10,000 erase cycles. IDs are generated after each of the five erase cycles. Therefore, 50,000 IDs were generated during the test. Only 16 of these had a single bit flip, while the remaining 49,984 IDs were identical (without bit flips). The reliability value of this test is R = 0.9999975.
[0119] As described above, the embodiments provide a scheme for generating unique, reliable, unpredictable, and non-cloneable IDs for flash memory devices.
[0120] Although the foregoing embodiments have been shown and described in detail for clarity and understanding, the invention is not limited to the details provided. As those skilled in the art will understand from the foregoing disclosure, many alternative ways of carrying out the invention exist. Therefore, the disclosed embodiments are exemplary and not restrictive. The invention is intended to cover all modifications and substitutions falling within the scope of the appended claims. Furthermore, embodiments can be combined to form other embodiments.
Claims
1. An identification system, comprising: The identifiable device includes a controller and a memory device, the memory device being coupled to the controller and comprising multiple blocks. The controller mentioned above: Perform multiple raw read operations on each page of the block selected from the plurality of blocks; The selected block's pages are classified into low and high groups using the average number of "1"s obtained from the multiple raw read operations. Multiple unordered page pairs are generated by sequentially selecting one page from the lower group as the first page of each unordered page pair and selecting one page from the higher group as the second page of each unordered page pair. Multiple ordered page pairs are generated by selectively changing the order of pages in each of the multiple unordered page pairs based on the address order between the first page of the lower group and the next page after the first page of the lower group; and Based on a comparison of the average number of "1"s in the preceding and following pages of each of the plurality of ordered page pairs, a sequence for identifying the selected block is generated.
2. The identifiable system according to claim 1, further comprising: The identification server provides each challenge value to the controller to select a page from the low group as the first page and select a page from the high group as the second page.
3. The identifiable system according to claim 2, wherein the controller further transmits the sequence to the identification server.
4. The identifiable system according to claim 1, wherein the controller further: Before performing the aforementioned multiple raw read operations. Erase the block selected from the plurality of blocks; and Write the setting pattern to all pages of the selected block.
5. The identifiable system according to claim 4, wherein the setting mode includes an all-zero mode.
6. The identifiable system of claim 1, wherein the pages of the selected block are sorted in ascending order based on the average number of "1"s. The low group comprises a set of pages starting with the page with the lowest average number of "1"s, and The high group includes a set of pages starting with the page with the highest average number of "1".
7. The identifiable system of claim 6, wherein the total number of pages in the low group and the high group is less than the number of pages in the selected block.
8. The identifiable system according to claim 1, wherein the controller: For each of the plurality of unordered page pairs When the addresses of the first page and the next page in the lower group are in descending order, the order of the first page and the second page is changed. When the addresses of the first page and the next page of the lower group are in ascending order, the order of the first page and the second page in each of the plurality of unordered page pairs is not changed.
9. The identifiable system according to claim 1, wherein the controller: For each of the plurality of ordered page pairs Compare the average number of "1"s on the previous page and the next page; When the average number of "1"s on the subsequent page is higher than the average number on the previous page, a bit with a first value is generated; and When the average number of "1"s on the previous page is higher than the average number of "1"s on the next page, a bit with a second value is generated.
10. The identifiable system according to claim 1, wherein each of the multiple original read operations comprises: Each page of the selected block is read multiple times without applying error correction codes (ECC) or scrambling to the read pages; and Determine the average number of "1"s for each page read.
11. A method of operating an identifiable device, the identifiable device comprising a controller and a memory device, the memory device being coupled to the controller and comprising a plurality of blocks, the method comprising: Perform multiple raw read operations on each page of the block selected from the plurality of blocks; The selected block's pages are classified into low and high groups using the average number of "1"s obtained from the multiple raw read operations. Multiple unordered page pairs are generated by sequentially selecting one page from the lower group as the first page of each unordered page pair and selecting one page from the higher group as the second page of each unordered page pair. Multiple ordered page pairs are generated by selectively changing the order of pages in each of the multiple unordered page pairs based on the address order between the first page of the lower group and the next page after the first page of the lower group; and Based on a comparison of the average number of "1"s in the preceding and following pages of each of the plurality of ordered page pairs, a sequence for identifying the selected block is generated.
12. The method of claim 11, further comprising: Each challenge value is received from the identification server to select a page from the low group as the first page and a page from the high group as the second page.
13. The method of claim 12, further comprising: The sequence is transmitted to the identification server.
14. The method of claim 11, further comprising: Before performing the aforementioned multiple raw read operations. Erase the block selected from the plurality of blocks; and Write the setting pattern to all pages of the selected block.
15. The method of claim 14, wherein the setting mode includes an all-zero mode.
16. The method of claim 11, wherein the selected block's pages are sorted in ascending order based on the average number of "1"s. The low group comprises a set of pages starting with the page with the lowest average number of "1"s, and The high group includes a set of pages starting with the page with the highest average number of "1".
17. The method of claim 16, wherein the total number of pages in the low group and the high group is less than the number of pages in the selected block.
18. The method of claim 11, wherein generating the plurality of ordered page pairs comprises: For each of the plurality of unordered page pairs When the addresses of the first page and the next page in the lower group are in descending order, the order of the first page and the second page is changed. When the addresses of the first page and the next page of the lower group are in ascending order, the order of the first page and the second page in each of the plurality of unordered page pairs is not changed.
19. The method of claim 11, wherein generating the sequence comprises: For each of the plurality of ordered page pairs Compare the average number of "1"s on the previous page and the next page; When the average number of "1"s on the subsequent page is higher than the average number on the previous page, a bit with a first value is generated; and When the average number of "1"s on the previous page is higher than the average number of "1"s on the next page, a bit with a second value is generated.
20. The method of claim 11, wherein each of the plurality of original read operations comprises: Each page of the selected block is read multiple times without applying error correction codes (ECC) or scrambling to the read pages; and Determine the average number of "1"s for each page read.
Citation Information
Patent Citations
Method of generating Anti-collusion fingerprint codes using
US20080056497A1
Method and System for Determining Soft Information Offsets
US20160274969A1
Cryptographic device and memory based puf
US20190221139A1