A dual-mode storage-computing-encryption integrated circuit and its operation method
By designing a storage-computing-encryption integrated circuit with PUF and eCIM dual modes on edge devices, and utilizing non-volatile transistor arrays and complex Hamming distance comparisons, the problems of high hardware overhead and insufficient security of edge devices are solved, achieving efficient identity authentication and data encryption.
Patent Information
- Application Number
- CN202411909268.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-12-24
AI Technical Summary
Existing edge devices have problems with high hardware overhead and insufficient security in terms of identity authentication and data encryption. Especially when facing identity attacks and asset attacks, the PUF design is easy to crack with simple operations, and the eCIM technology has excessive area overhead.
A storage-computation-encryption integrated circuit with PUF and eCIM dual modes is designed. Hardware multiplexing is achieved through non-volatile transistor arrays and peripheral circuits. Complementary word lines and complex Hamming distance comparison are used to improve security, and in-situ decryption calculations are performed on the memory.
While reducing hardware overhead, it improves the security and computing efficiency of edge devices, resists machine learning modeling attacks, and achieves highly parallel in-situ decryption and authentication.
Smart Images

Figure CN119847979B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of in-memory computing and physically unclonable function design, and in particular to a hardware design based on a non-volatile transistor array that combines encrypted in-memory computing (eCIM) and physically unclonable function (PUF) functions. Background Art
[0002] The widespread deployment of edge devices in sectors such as smart homes, smart cities, industrial electronics, and healthcare has driven a massive demand for cloud-edge data exchange. These numerous and diverse edge hardware devices connect to the cloud, which stores critical private information such as user security keys, behavioral habits, and healthcare. These devices are vulnerable to identity and asset attacks, leading to significant security concerns such as data breaches. Specifically, identity attacks involve fraudulent activity, where attackers impersonate legitimate users to defraud the cloud and illegally access data in networks and systems. Asset attacks involve directly stealing data from edge storage through methods such as reverse engineering, such as private data in sensors and communication devices and pre-trained weights in edge AI networks. Furthermore, compromised IoT devices can lead to functional failure or malfunction, potentially endangering human life in the case of in-vehicle electronics or smart medical devices.
[0003] Therefore, within the constraints of hardware costs such as computing power, power consumption, and area, edge devices need to be assigned unique identifiers for authentication to protect user privacy and pre-trained models in the cloud. Furthermore, edge data assets need to be encrypted during transmission and storage, and decryption reading and computation speeds need to be improved. Physical Unclonable Functions (PUFs) and encrypted computing in memory (eCIMs) can address these two requirements, respectively.
[0004] As a hardware security primitive, PUF leverages process fluctuations in device fabrication or physical randomness during operation as an unpredictable hardware fingerprint. This provides a lightweight identity security solution for devices deployed in unsupervised environments, and is therefore widely used in device authentication and various communication security protocols. As a physical entity, PUF performs externally undetectable and mathematically unpredictable black-box processing on a given input (a challenge signal, C), transforming it into an output (a response signal, R). Because this black-box operation is essentially determined by the PUF's internal physical mechanisms and circuit design, the mapping between its input and output signals, known as the challenge-response pair (CRP), can serve as a unique hardware-level fingerprint for legitimate device authentication. In the actual authentication process, the CRP is binary. The PUF first registers with the cloud in a secure environment. The cloud then sends a sufficient number of different Cs and collects the PUF's returned Rs to build a CRP library for that PUF. In an insecure environment, before the PUF requests to communicate with the cloud, the cloud will randomly select a small number C from the established CRP library and send it to the PUF. The cloud will compare the PUF's response result R with the existing R in the library. If the matching degree exceeds a threshold (such as 95%), the PUF can be considered to be legitimate.
[0005] eCIM is based on in-memory computing technology and further adds in-situ decryption capabilities. In-memory computing technology is implemented through a non-volatile memory array. It can directly perform in-situ computing operations on the data stored in the memory and external input data in the memory, and directly obtain the calculation results without the need for additional data reading and other processing processes. It has the advantages of high parallelism, high throughput, and low cost. eCIM further performs additional encryption protection such as XOR on the data in the memory to prevent attackers from directly reading private data stored in the non-volatile memory. eCIM technology avoids the additional data reading, data decryption, and data calculation processes required by traditional encryption algorithms such as DES and AES, and completes the decryption and calculation processes simultaneously in the memory, greatly improving the computational compatibility of encrypted text and the computational throughput of the encryption system.
[0006] However, PUFs require dedicated embedded modules in edge devices, incurring additional area and power consumption overhead. Furthermore, in existing PUF designs, most CRP generation processes rely on simpler spatial coupling methods such as linear operations, which poses security risks to machine learning and other modeling attacks, such as speculation attacks based on greedy algorithms and simulated annealing. Furthermore, existing eCIM technology, based on dual-wordline SRAM cells, requires a hardware cost of over 6T, incurring additional area overhead. Therefore, secure, reliable, and low-cost implementation of PUF and eCIM functionality is crucial for edge devices to protect against security risks such as identity and asset attacks. Summary of the Invention
[0007] To address the above-mentioned problems in the existing technologies, this paper proposes a PUF authentication mode that simultaneously performs identity authentication and an eCIM calculation mode that performs in-situ decryption. This design implements an integrated storage-computation-encryption circuit design, significantly reducing hardware overhead while ensuring high security. This paper, for the first time, reuses PUF and eCIM in hardware, proposing an integrated storage-computation-encryption hardware circuit design that simultaneously resists security risks such as asset attacks and identity attacks, significantly optimizing the area and power consumption of the security encryption module at the edge.
[0008] The technical solutions of the present invention are as follows:
[0009] A storage-computation-encryption integrated circuit with PUF and eCIM dual modes is characterized by having two different operating modes, including a physically unclonable function (PUF) mode for security verification and an eCIM mode for secure in-memory computing. The circuit includes: a non-volatile transistor array, as well as a peripheral dual-mode signal processor (Dualsignal encoder), a vector coding circuit (Vector coding), a word line (WL) driving circuit and a bit line (BL) driving circuit, an external signal decoding circuit, a selector circuit (Selector MUX), a comparator circuit (Comparator), an analog-to-digital converter (ADC), and a shift and adder circuit (ADC). The vector coding circuit, dual-mode signal processor, driving circuit, selector circuit, non-volatile transistor array are shared circuit modules, the external signal decoding circuit and comparator circuit are circuit modules called in the PUF mode, and the digital-to-analog converter and shift and adder are circuit modules called in the eCIM mode.
[0010] The non-volatile transistor array is a basic unit composed of two non-volatile transistors connected by circuits to form an n-row n-column array structure. In the array structure, the two word lines WL of each basic unit in each row are connected by circuits. i and Connected to the WL driving circuit; the bit line BL of each column of basic units is connected to the BL driving circuit, and the sense line SL is connected to the selector circuit; in the basic unit, the gates of the two non-volatile transistors are opposite and have an axisymmetric structure, and the gate of one transistor is connected to the word line WL i Connect the gate of another transistor to the complementary word line The drains are connected to the bit line BL and the sources are connected to the sense line SL. In the basic unit, the storage states of the two non-volatile transistors are complementary, and the two word lines WL connected to their gates are connected. i and The level states of the two word lines are also complementary, that is, the two word lines on each row of the array are always complementary.
[0011] The vector encoding circuit is used to encode the input vector in the eCIM mode or the challenge vector of the challenge signal in the PUF mode, and process the "1" and "0" bits in the vector into high / low levels that can be read by subsequent circuits.
[0012] The dual-mode signal processor circuit is used to further process the coded signal output by the vector coding circuit to implement the logical operations required in eCIM or PUF. For PUF mode, the signal processor will convert each bit C in the Challenge vector into i Expanded to C i and C i Supplement The two complementary word lines WL in the WL driving circuit are output respectively i and For eCIM mode, the signal processor will input each bit of the Input vector i Each bit of the key vector Key i Perform logical operations and get two results: Key i and In i AND operation result, Key i In i The AND operation results are used as two complementary word lines WL in the WL driving circuit. i and The high and low levels of , i=1,2,3...,n.
[0013] The WL and BL driving circuits are used to drive the word lines WL and bit lines BL of the non-volatile transistor array, providing gate voltages V for the non-volatile transistors. G and drain voltage V D .
[0014] The external signal decoding circuit operates in PUF mode, obtains and translates the selector circuit control bit from the output of the challenge signal vector encoding circuit, and uses it as the input of the selector circuit MUX to control the column indexes of the specific two columns SL required for current size comparison and response generation during this CRP generation process.
[0015] The selector circuit is connected to the sense lines SL of the non-volatile transistor array and randomly selects the SL currents of any two columns for reading according to the output of the external signal decoding circuit.
[0016] The comparator circuit is used to generate a response signal Response in the PUF mode, and its input is the output of the selector circuit.
[0017] The analog-to-digital converter and shift adder circuit are used for processing the calculation results of the eCIM mode. Digital operations are performed by the analog-to-digital converter ADC and the shift adder circuit to obtain the final calculation result of the eCIM. The input of the analog-to-digital converter ADC and the shift adder circuit is the output of the selector circuit.
[0018] Furthermore, the non-volatile transistor is a floating-gate or charge-trapping field-effect transistor, that is, a storage layer is inserted into the gate stack layer, and the storage layer uses a semiconductor material composed of a floating gate / trapping layer and a tunneling dielectric layer, and the threshold voltage of the transistor is modulated by capturing / detrapping charges in the channel; or it is a ferroelectric field-effect transistor, that is, a layer of non-volatile material with ferroelectric properties is inserted into the gate stack layer, and the threshold voltage of the non-volatile transistor is modulated by changing the polarization state of the ferroelectric material.
[0019] The present invention also provides an operating method for the above-mentioned storage-computation-encryption integrated circuit with PUF and eCIM dual modes, which is used for CRP generation in PUF mode and in-situ decryption calculation in eCIM mode respectively.
[0020] The steps of the CRP generation process in PUF mode include:
[0021] 1) Write the random fingerprint weight matrix rW to the basic unit of the n-row and n-column non-volatile transistor array. rW is a 0 / 1 binary matrix. The two complementary transistors of each basic unit store an element in rW, which are rW ij and i and j represent the row and column positions in the nonvolatile transistor array, respectively;
[0022] 2) The input challenge signal Challenge vector C passes through the vector encoding circuit and will obtain two different parts: the first part of the encoded vector is used to determine the "1" and "0" digital signals input by the complementary word line, which will be further obtained by the dual-mode signal processor circuit Ci and C i Supplement Finally, as the non-volatile transistor array complementary word line WL i and The high and low level inputs of the second part of the encoded vector are used to control the digital signal of the specific column index of the MUX selector circuit, which will be output to the selector circuit MUX through the external signal decoding circuit, and finally used to determine the indexes of the two SL columns for current comparison (here, the indexes of the two specifically selected SL columns are arbitrarily determined by the outside world);
[0023] 3) After determining the complementary word line input signal (first part) and the SL position index to be compared (second part), the non-volatile transistor array will perform an in-memory calculation operation. Each state complementary basic unit will compare the complementary word line input signal value C i 、 The XOR operation of the first part of the n-bit input signal is integrated with the storage value, that is, the first part of the n-bit input signal is XORed with an n-row and n-column storage matrix rW by column, and the XOR results of each unit are summed by column to obtain the Hamming distance HD between the input signal vector and the column storage vector. Its value is reflected as the column current size on a SL. This is the processing process of the first part of the input signal inside the PUF, that is, i and j represent the row and column positions in the nonvolatile transistor array, respectively;
[0024] 4) The selector circuit determines two corresponding SL currents from the multiple SLs in the nonvolatile transistor array based on the output of the external signal decoding circuit. The currents are input to the comparator circuit to compare the two Hamming distances HD1 and HD2. Based on the difference, a 1-bit response signal Response is generated. Response is used for PUF authentication.
[0025] The steps of the in-memory calculation process for in-situ decryption in eCIM mode include:
[0026] 1) Write the encrypted data weight matrix eW into the basic unit of the n-row and n-column non-volatile transistor array. eW is a binary matrix of "1" and "0" obtained by performing an XOR encryption operation on the original weight matrix W to be kept confidential and the key Key; the two complementary transistors of each basic unit store an element of eW, which are eW ij and i and j represent the row and column positions in the nonvolatile transistor array, respectively;
[0027] 2) When in-situ decryption calculations need to be performed, the vector Input to be calculated and the key vector Key for in-situ decryption are input, and the Key is obtained through the vector encoding circuit and the dual-mode signal processor circuit.i and In i AND operation result, Key i Supplement and In i The result of the AND operation is used as the complementary word line WL of the nonvolatile transistor array. i and High and low level input;
[0028] 3) After the dual-mode signal processor circuit outputs the corresponding WL signal, the non-volatile transistor array will perform in-situ in-memory decryption calculation operations; as in the PUF mode, each state complementary basic unit will input the WL signal value In i Key i 、 The XOR operation is performed on the stored value, that is, the n-bit WL input signal is XORed with an n-row and n-column storage matrix eW bit by bit, and the XOR results of each unit are summed column by column to obtain the Hamming distance HD between the input signal vector and the column storage vector, whose value is reflected as the column current on a SL. The difference is that since the input WL signal has been specially processed in step 2), the mathematical operation process completed inside the eCIM is: i and j represent the row and column positions in the array, respectively;
[0029] 4) The selector circuit sequentially reads all SL output currents from the nonvolatile transistor array, ultimately obtaining the in-memory decryption calculation result for each column. This is input to the analog-to-digital converter and shift adder circuit for processing, resulting in the in-memory calculation result of in-situ decryption, i.e., the matrix-vector multiplication result of the In vector and the eW matrix.
[0030] This invention, for the first time, achieves an integrated circuit that combines both PUF and eCIM modes, meeting the diverse security requirements of edge devices while maintaining minimal footprint and power consumption. It can also be flexibly configured and modified based on specific scenarios. This invention avoids security risks such as identity and asset attacks on edge devices, and uses more complex internal operation methods to enhance the security of the PUF and the privacy of the eCIM. Compared to existing technologies, this invention offers the following benefits:
[0031] 1. The present invention integrates and reuses the PUF and eCIM modules, which can be used as both a secure hardware module for identity authentication and a computing module for in-memory computing. This significantly optimizes hardware costs and power consumption, and reduces the difficulty of deploying these requirements on edge devices.
[0032] 2. The PUF model of this invention significantly improves the spatial coupling complexity of the PUF design concept through the complementary wordline scheme. By pairing two state-complementary transistors, a nonlinear XOR operation is implemented in each basic unit. The introduction of the Hamming distance comparison between two columns (HD1 and HD2) extends the conventional PUF design concept of one-dimensional cell cascading to two dimensions, significantly improving the security of the PUF against machine learning modeling attacks.
[0033] 3. The eCIM mode of the present invention protects the encrypted data weight matrix stored in the transistor through XOR encryption, and can achieve high-energy-efficiency and high-parallelism in-memory computing operations through the non-volatile transistor array; it uses complementary word lines to complete high-parallelism in-situ decryption in-memory computing, significantly improving the throughput of eCIM and reducing its latency cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A schematic diagram of the security risks of different types of attacks that edge devices may face;
[0035] Figure 2 This is a diagram of the architecture of the dual-mode storage-computing-encryption integrated circuit design described in the present invention;
[0036] Figure 3 A circuit design diagram and logic operation principle of a dual-mode signal processor according to an embodiment of the present invention;
[0037] Figure 4 A non-volatile transistor array circuit design diagram and a mathematical principle diagram according to an embodiment of the present invention;
[0038] Figure 5 This is an embodiment of the nonvolatile transistor of the present invention, namely, a device structure of the nonvolatile transistor. The leftmost and rightmost characteristic curves in the device transfer characteristic curve represent a low threshold voltage (storing data "1") and a high threshold voltage (storing data "0"), respectively.
[0039] Figure 6 This is a schematic diagram of the abstract mathematical operations performed by the dual-mode storage-computation-encryption integrated circuit of the present invention when operating in different PUF and eCIM modes. DETAILED DESCRIPTION
[0040] The present invention will be further clearly and completely described below through specific embodiments, with reference to the accompanying drawings. Although specific embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. Rather, these embodiments are provided to enable a more thorough understanding of the present invention and to fully convey the scope of the present invention to those skilled in the art.
[0041] Figure 1 It shows the security risks that edge devices widely deployed in scenarios such as smart homes, smart cities, industrial electronics, and healthcare may face, including identity fraud, asset theft, reverse engineering, and other illegal intrusions, which may lead to the leakage of various data such as user privacy information, commercial confidential data, and pre-trained model weights in the cloud.
[0042] The storage-computing-encryption integrated circuit architecture designed by the present invention is as follows Figure 2 As shown, the circuit includes circuit modules used in both PUF and eCIM modes. The dual-mode signal processor, driver circuit, selector circuit, and non-volatile transistor array are shared circuit modules. The challenge signal vector encoding circuit, external signal decoding circuit, and comparator circuit are used in PUF mode, while the input vector encoding circuit, digital-to-analog converter, and shift adder are used in eCIM mode. In PUF mode, the non-volatile transistor array stores the random fingerprint matrix rW, while in eCIM mode, it stores the encrypted data matrix eW. The input vector, key vector, challenge signal vector, and rW and eW matrices in the circuit are all binary 0 / 1 numbers. In PUF mode, the circuit generates a CRP based on the input challenge signal vector and the internally stored rW matrix. The comparator circuit generates the corresponding response for PUF authentication. In eCIM mode, the circuit uses the input key to perform in-memory decryption, obtaining the matrix-vector multiplication result between the input vector and the eW matrix via the analog-to-digital converter and shift adder circuits.
[0043] Figure 2 An embodiment of the circuit corresponding to the dual-mode signal processor is as follows Figure 3 As shown, different modes and different previous stage inputs can be processed to obtain the WL input signal required by the subsequent non-volatile transistor array. One implementation method of the dual-mode signal processor circuit is to use two NOT gates and two NOR gates. The two inputs of NOR gate 1 are the outputs of NOR gate 1 and NOR gate 2, and the two inputs of NOR gate 2 are the output of NOR gate 1 and the input of NOR gate 2. In PUF mode, the input of NOR gate 1 is always high level "1", and the input of NOR gate 2 is the challenge signal C i , according to the Boolean logic of the circuit The output C of NOR gate 1 will be i , at the output of NOR gate 2 Then the two complementary word lines WL are output to the array through the WL driver circuit. i and In eCIM mode, the input of NOT gate 1 is the input vector In to be calculated.i , the input of NOT gate 2 is the encryption key vector Key i , and at this time the output of NOR gate 1 is In i Key i , the output of NOR gate 2 is Similarly, the two complementary word lines WL are output to the array through the WL driving circuit. i and superior.
[0044] In PUF mode, a binary random fingerprint weight matrix rW is first written into the basic unit of the n-row and n-column non-volatile transistor array. Then the challenge signal Challenge is input through the vector encoding circuit, and two different parts are obtained. The first part of the encoded vector is used to determine the "1" and "0" digital signals input by the complementary word line, which serves as the complementary word line WL of the non-volatile transistor array. i and The first part is a digital signal that controls the column index of the MUX selector circuit, determining the index of the two SL columns to be compared. After determining the complementary wordline input signal (the first part) and the position index of the SL to be compared (the second part), the non-volatile transistor array performs an in-memory calculation. Finally, the selector circuit determines the corresponding two SL currents from multiple SLs based on the output of the external signal decoding circuit. These are input to the comparator circuit to compare the two Hamming distances HD1 and HD2. Based on the difference, a 1-bit response signal Response is generated for PUF authentication.
[0045] In the eCIM mode, the binary encrypted data weight matrix eW is written into the non-volatile transistor array, and the original weight matrix W that needs to be kept secret is encrypted by XOR operation with the key Key. When the in-memory calculation of in-situ decryption needs to be performed, the vector Input to be calculated and the key vector Key for in-situ decryption are input, and the Key is obtained through the vector encoding circuit and the dual-mode signal processor circuit. i and In i AND operation result, Key i Supplement and In i The result of the AND operation is used as the complementary word line WL of the nonvolatile transistor array. i and The dual-mode signal processor circuit outputs the corresponding WL signal, and the non-volatile transistor array performs in-situ decryption calculations. Finally, the selector circuit sequentially reads all SL output currents from the non-volatile transistor array, obtaining the in-situ decryption calculation results for each column. These are then input to the analog-to-digital converter and shift adder circuit for processing, yielding the in-situ decrypted in-situ calculation results.
[0046] Figure 2 An embodiment of the circuit corresponding to the nonvolatile transistor array in Figure 4 As shown. The random fingerprint matrix rW or the encrypted data matrix eW required in the PUF mode and eCIM mode will be stored in a non-volatile transistor array in a complementary manner. The circuit is based on an AND-type transistor array, and its basic unit is two non-volatile transistors ( Figure 4 The two word lines WL connected to the gate terminals of the two complementary non-volatile transistors i and The levels of the transistors in the same column are always complementary during operation, and the source terminals of the transistors in the same column are connected to the sense line SL. The input n-bit signal is input into the array as the level of WL complementarily, and 1 bit signal corresponds to one row, where the "1" / "0" value of the i-th bit signal is used as the word line WL of the i-th row. i and High / low level.
[0047] like Figure 5 for Figure 4 The structure and electrical characteristics of the non-volatile transistor are shown in the array. The additional functional layer in the gate stack can non-volatilely control the potential of the channel, thereby changing the threshold voltage of the device, achieving the ability to non-volatilely store "1" or "0" data. Since the non-volatile transistor only inputs a voltage level V at the high gate terminal, G = High, storage data is 1 (w ij =1) can output the on-state current I only when both are met on , in other cases it is in the off state I off , so it is essentially a V G and w ij Perform AND operation in the analog domain. Since the word line gate levels and weights in the same basic unit are complementary, the sum of the currents of the two transistors in the basic unit of the i-th row and j-th column is So the sum of the SL currents of the n 2T cells in the jth column is That is, the jth column SL current and the input voltage vector WL on WL i and the jth column weight vector w j is proportional to the Hamming distance.
[0048] Assuming that the size of the non-volatile transistor storage array is n×n, at the array level, the above operation can be mathematically equivalent to the n-bit column vector WL=[WL1, WL2, ... WL n ] T With the stored matrix w ijEach column vector of is subjected to bit-by-bit XOR and column-by-column summation (i.e., the Hamming distance between two column vectors), and the result obtained in the jth column is Where i is the index of the row.
[0049] The equivalent mathematical formula for the in-memory calculation operation during the operation of the embodiment of the present invention is as follows: Figure 6 As shown. In PUF mode, due to the word line WL i and The input comes from the output of the dual-mode signal processor C i and Therefore, the actual mathematical operation performed on the jth column SL is:
[0050]
[0051] Furthermore, through a selector circuit and external signals, two columns of the SL output are randomly selected and input into a comparator circuit for comparison, generating a "1" or "0" response signal based on the result. Because the number of 1s and 0s in matrices and vectors is essentially equal and evenly distributed, the mathematical expectation of comparing the currents of any two SL columns is equally likely to be "1" or "0."
[0052] In the eCIM mode, since the word line WL i and The input comes from the output of the dual-mode signal processor In i Key i and Therefore, the actual mathematical operation performed on the jth column SL is:
[0053]
[0054] Ultimately, the analog current signal is converted into the corresponding in-memory calculation result through subsequent analog-to-digital converters and shift adder circuits. This result is the desired matrix-vector multiplication of the input vector In and the original data matrix W. This process eliminates the need for additional readout and decryption steps, directly achieving highly parallel in-situ decrypted in-memory calculations.
[0055] This embodiment fully and in detail illustrates the design and implementation principles of a PUF / eCIM dual-mode storage-computation-encryption integrated circuit based on a non-volatile transistor array and peripheral circuits. This approach simultaneously implements the PUF module required for identity authentication and the eCIM module required for secure computing at a low hardware cost and power consumption, significantly improving hardware reuse compared to other solutions. Furthermore, its PUF mode utilizes a more complex spatial coupling scheme, enhancing the PUF's security against machine learning modeling and providing reconfigurable functionality. The eCIM mode securely stores encrypted data in non-volatile memory and implements highly parallel in-situ decryption and in-memory computing.
[0056] Finally, it should be noted that the purpose of disclosing the embodiments is to facilitate a further understanding of the present invention. However, those skilled in the art will appreciate that various substitutions and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the contents disclosed in the embodiments, and the scope of protection claimed by the present invention shall be determined by the scope defined in the claims.
Claims
1. A storage-computation-encryption integrated circuit with PUF and eCIM dual modes, characterized in that: It also has two different operating modes, including a physically unclonable function (PUF) mode for security verification and an eCIM mode for secure in-memory computing. The circuit includes a non-volatile transistor array, as well as a peripheral dual-mode signal processor, a vector encoding circuit, a word line (WL) driver circuit, a bit line (BL) driver circuit, an external signal decoding circuit, a selector circuit, a comparator circuit, an analog-to-digital converter, and a shift adder circuit. The non-volatile transistor array is a basic unit composed of two non-volatile transistors connected by circuits to form an n-row n-column array structure, and the two word lines WL of each basic unit in each row are connected by circuits. i and Connected to the WL driving circuit; the bit line BL of each column of basic cells is connected to the BL driving circuit, and the sense line SL is connected to the selector circuit; The vector encoding circuit is used to encode the input vector in the eCIM mode or the challenge vector of the challenge signal in the PUF mode, and process the "1" and "0" bits in the vector into high / low levels that can be read by subsequent circuits; The dual-mode signal processor circuit is used to further process the encoded signal output by the vector encoding circuit to implement the logical operations required in the eCIM or PUF; The WL and BL driving circuits are used to drive the word lines WL and bit lines BL of the non-volatile transistor array, providing gate voltages V for the non-volatile transistors. G and drain voltage V D ; The external signal decoding circuit operates in PUF mode, obtains and translates the selector circuit control bit from the output of the challenge signal vector encoding circuit, and uses it as the input of the selector circuit to control the column indexes of the specific two columns of SL required for current size comparison and response generation in this CRP generation process; The selector circuit is connected to the sense lines SL of the non-volatile transistor array and randomly selects the SL currents of any two columns for reading according to the output of the external signal decoding circuit; The comparator circuit is used to generate a response signal Response in the PUF mode, and its input is the output of the selector circuit; The analog-to-digital converter and shift adder circuit are used for processing the calculation results of the eCIM mode. Digital operations are performed by the analog-to-digital converter ADC and the shift adder circuit to obtain the final calculation result of the eCIM. The input of the analog-to-digital converter ADC and the shift adder circuit is the output of the selector circuit.
2. The storage-computing-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, characterized in that: The vector encoding circuit, dual-mode signal processor, driving circuit, selector circuit and non-volatile transistor array are shared circuit modules, the external signal decoding circuit and comparator circuit are circuit modules called in the PUF mode, and the digital-to-analog converter and shift adder are circuit modules called in the eCIM mode.
3. The storage-computing-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, characterized in that: In the basic unit composed of two non-volatile transistors, the gates of the two non-volatile transistors are opposite to each other and are in an axisymmetric structure, and the gate of one transistor is aligned with the word line WL. i Connect the gate of another transistor to the complementary word line The drains of the two non-volatile transistors are connected to the bit line BL and the sources are connected to the sense line SL. The storage states of the two non-volatile transistors are complementary, and the two word lines WL connected to their gates are connected. i and The level states of the two word lines are also complementary, that is, the two word lines on each row of the nonvolatile transistor array are always complementary.
4. The storage-computing-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, characterized in that: The dual-mode signal processor circuit, for the PUF mode, will convert each bit C in the Challenge vector i Expanded to C i and C i The complement of the two complementary word lines WL in the WL driving circuit are output respectively. i and For eCIM mode, the signal processor will input each bit of the Input vector i Each bit of the key vector Key i Perform logical operations and get two results: Key i and In i AND operation result, Key i In i The AND operation results are used as two complementary word lines WL in the WL driving circuit. i and The high and low levels of , i=1,2,3...,n.
5. The storage-computing-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, characterized in that: The non-volatile transistor is a floating-gate or charge-trapping field-effect transistor, i.e., a storage layer is inserted into the gate stack. The storage layer uses a semiconductor material composed of a floating gate / trapping layer and a tunneling dielectric layer. The threshold voltage of the transistor is modulated by capturing / detrapping charge in the channel. Alternatively, it is a ferroelectric field-effect transistor, i.e., a layer of ferroelectric non-volatile material is inserted into the gate stack. The threshold voltage of the non-volatile transistor is modulated by changing the polarization state of the ferroelectric material.
6. The method for operating the storage-computation-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, wherein: The steps in the CRP generation process in PUF mode include: 1) Write the random fingerprint weight matrix rW to the basic unit of the n-row and n-column non-volatile transistor array. rW is a 0 / 1 binary matrix. The two complementary transistors of each basic unit store an element in rW, which are rW ij and i and j represent the row and column positions in the nonvolatile transistor array, respectively; 2) The challenge signal Challenge vector C is input and passed through the vector encoding circuit to obtain two different parts: the first part of the encoded vector is used to determine the "1" and "0" digital signals input by the complementary word line, which will be further obtained through the dual-mode signal processor circuit C i and C i Supplement Finally, as the non-volatile transistor array complementary word line WL i and The high and low level inputs of the second part of the encoded vector are used to control the digital signal of the specific column index of the selector circuit, which will be output to the selector circuit through the external signal decoding circuit and finally used to determine the index of the two SL columns for current comparison; 3) After determining the complementary word line input signal, i.e., the first part obtained in step 2), and the SL position index to be compared, i.e., the second part obtained in step 2), the non-volatile transistor array will perform an in-memory calculation operation. Each state complementary basic unit will compare the complementary word line input signal value C i 、 The XOR operation of the first part of the n-bit input signal is integrated with the storage value, that is, the first part of the n-bit input signal is XORed with an n-row and n-column storage matrix rW by column, and the XOR results of each unit are summed by column to obtain the Hamming distance HD between the input signal vector and the column storage vector. Its value is reflected as the column current size on a SL. This is the processing process of the first part of the input signal inside the PUF, that is, i and j represent the row and column positions in the nonvolatile transistor array, respectively; 4) The selector circuit determines two corresponding SL currents from the multiple SLs in the nonvolatile transistor array based on the output of the external signal decoding circuit. The currents are input to the comparator circuit to compare the two Hamming distances HD1 and HD2. Based on the difference, a 1-bit response signal Response is generated. Response is used for PUF authentication.
7. The method for operating a storage-computation-encryption integrated circuit with PUF and eCIM dual modes according to claim 1, wherein: The in-memory calculation process for in-situ decryption in eCIM mode includes the following steps: 1) Write the encrypted data weight matrix eW into the basic unit of the n-row and n-column non-volatile transistor array. eW is a binary matrix of "1" and "0" obtained by performing an XOR encryption operation on the original weight matrix W to be kept confidential and the key Key; the two complementary transistors of each basic unit store an element of eW, which are eW ij and i and j represent the row and column positions in the nonvolatile transistor array, respectively; 2) When in-situ decryption calculations need to be performed, the vector Input to be calculated and the key vector Key for in-situ decryption are input, and the Key is obtained through the vector encoding circuit and the dual-mode signal processor circuit. i and In i AND operation result, Key i Supplement and In i The result of the AND operation is used as the complementary word line WL of the nonvolatile transistor array. i and High and low level input; 3) After the dual-mode signal processor circuit outputs the corresponding WL signal, the non-volatile transistor array will perform the in-situ decryption calculation operation; as in the PUF mode, each state complementary basic unit will input the WL signal value. The XOR operation is performed on the stored value, that is, the n-bit WL input signal is XORed with an n-row and n-column storage matrix eW bit by bit, and the XOR results of each unit are summed column by column to obtain the Hamming distance HD between the input signal vector and the column storage vector, whose value is reflected as the column current on a SL. The difference is that since the input WL signal has been specially processed in step 2), the mathematical operation process completed inside the eCIM is: i and j represent the row and column positions in the array, respectively; 4) The selector circuit sequentially reads all SL output currents from the nonvolatile transistor array, ultimately obtaining the in-memory decryption calculation result for each column. This is input to the analog-to-digital converter and shift adder circuit for processing, resulting in the in-memory calculation result of in-situ decryption, i.e., the matrix-vector multiplication result of the In vector and the eW matrix.
Citation Information
Patent Citations
Physical unclonable function circuit based on ferroelectric transistor array and application thereof
CN116170161A
In-memory calculation circuit and system and method based on in-memory calculation
CN116844595A