Key storage device and method for writing key value to one-time programmable device

By designing a key storage device during the chip manufacturing process, writing the key value into a one-time programmable device and clearing the key value in the hardware key device, the problems of insufficient security and high manufacturing cost in the prior art are solved, and secure storage and efficient programming of the key value are realized.

CN119918102APending Publication Date: 2025-05-02PUFSECURITY CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411159419.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-07-11
Filing Date
2024-08-22
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

In the prior art, the key value is stored in visible fuse-like memory during chip manufacturing, resulting in insufficient security, and programming the key value after chip manufacturing requires an additional security environment, increasing manufacturing costs.

Method used

A key storage device is designed, including an energy harvester, a controller, a hardware key device and a one-time programmable device. By collecting energy particles during chip manufacturing to generate a regular voltage, the key transfer program is initiated, the inherent key value is written to the one-time programmable device, and the key value in the hardware key device is cleared after completion.

Benefits of technology

It ensures the security of the key value without increasing manufacturing costs, avoids hackers from obtaining the key value through the microscope, and does not require an additional security environment for programming.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918102A_ABST
    Figure CN119918102A_ABST
Patent Text Reader

Abstract

The invention discloses a key storage device and a method for writing a key value into an OTP (One Time Programmable) device. The key storage device comprises an energy harvester, a controller, a hardware key device and the OTP device. The energy harvester collects energy particles during manufacturing of a wafer including the key storage device to generate a normal voltage, the controller initiates a key transfer procedure when the normal voltage reaches a predetermined level, and the hardware key device provides an intrinsic key value. The controller reads the intrinsic key value from the hardware key device and writes a key value to the OTP device according to the intrinsic key value. And after the OTP device stores the key value, the controller clears the inherent key value in the hardware key device. Therefore, the key transfer program can be automatically started during the manufacturing period of the key storage device, and the key value in the hardware key device can be destroyed after the key transfer program is completed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to key storage in an electronic device, and more particularly to a key storage device and a method for writing a key value into a one-time programmable device. Background Art

[0002] For fuse-type key storage, the key value is programmed at the register-transfer level (RTL) design stage so that the key value is present in the chip when the chip is manufactured. However, the key value stored in the fuse-type memory is visible to hackers under a microscope. Some related technologies can write the key value to an invisible memory after the chip is manufactured, thus requiring an additional secure environment to program the key value, which derives additional manufacturing costs in the process.

[0003] Therefore, a novel key storage and related methods are needed to ensure the security of key values ​​without incurring significant additional costs (such as a secure environment for programming key values ​​after the chip is manufactured). Summary of the invention

[0004] The object of the present invention is to provide a key storage device and a method for writing a key value into a one-time-programmable (OTP) device, so as to solve the problems of the related art without side effects or with less side effects.

[0005] At least one embodiment of the present invention provides a key storage device. The key storage device includes an energy harvester, a controller, a hardware key device and a one-time programmable device, wherein the controller is coupled to the energy harvester, the hardware key device is coupled to the controller, and the one-time programmable device is coupled to the controller. The energy harvester is used to collect multiple energy particles to generate a regular voltage in a manufacturing process of a wafer including the key storage device, the controller is used to start a key transfer program when the regular voltage reaches a predetermined level, and the hardware key device is used to provide a pre-existing key value. The controller reads the pre-existing key value from the hardware key device and writes a key value into the one-time programmable device according to the pre-existing key value. After the one-time programmable device stores the key value, the controller clears the pre-existing key value in the hardware key device.

[0006] At least one embodiment of the present invention provides a method for writing a key value into a one-time programmable device, wherein the method is applicable to a key storage device, and the key storage device includes the one-time programmable device. The method includes: using an energy harvester of the key storage device to collect multiple energy particles in a manufacturing process of a wafer including the key storage device, and generating a regular voltage accordingly; when the regular voltage reaches a predetermined level, using a controller of the key storage device to read an inherent key value from a hardware key device of the key storage device; using the controller to write the key value into the one-time programmable device according to the inherent key value; and after the one-time programmable device stores the key value, using the controller to clear the inherent key value in the hardware key device.

[0007] The key storage device and method provided by the embodiments of the present invention can enable the key transfer procedure from the hardware key device to the one-time programmable device to be automatically started during the manufacture of the key storage device, and the key value in the hardware key device can be destroyed after the key transfer procedure is completed. Therefore, hackers cannot obtain the key value from the hardware key device through a microscope. In addition, there is no need to arrange an additional security environment for manually programming the key value in the one-time programmable device. Therefore, the present invention can solve the problems of the related art without side effects or with less side effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 FIG. 4 is a schematic diagram of a key storage device manufactured on a wafer according to an embodiment of the present invention.

[0009] Figure 2 A method for writing a key value into a one-time programmable device according to an embodiment of the present invention

[0010] Schematic representation of the workflow of the method.

[0011] Figure 3 According to an embodiment of the present invention Figure 2 A schematic diagram of the detailed workflow of the method is shown.

[0012] The reference numerals are described as follows:

[0013] 10 Wafer

[0014] 100 Key storage device

[0015] 110 Energy Harvester

[0016] 120 Controller

[0017] 130 Boost Voltage Generator

[0018] 140 Hardware key device

[0019] 150 One-time Programmable Device

[0020] Steps S210~S240, S310~S390 DETAILED DESCRIPTION

[0021] Figure 1 FIG. 1 is a schematic diagram of a key storage device 100 manufactured on a wafer 10 according to an embodiment of the present invention. Figure 1 As shown, the key storage device 100 may include an energy harvester 110, a controller 120, a hardware key device 140 such as a metal key storage device or a fuse type storage device, and a one-time programmable (OTP) 150, wherein the controller 120 is coupled to the energy harvester 110, the hardware key device 140 is coupled to the controller 120, and the one-time programmable device 150 is coupled to the controller 120. The energy harvester 110 is used to collect a plurality of energy particles to generate a regular voltage during the manufacturing process (e.g., semiconductor manufacturing process) of the wafer 10 including the key storage device 100, the controller 120 is used to start a key transfer procedure when the regular voltage reaches a predetermined level, and the hardware key device 140 is used to provide an inherent key value. The controller 120 can read the inherent key value from the hardware key device 140, and write a key value into the one-time programmable device 150 according to the inherent key value. After the one-time programmable device 150 stores the key value, the controller 120 may clear the inherent key value in the hardware key device 140 .

[0022] The energy harvester 110 can obtain energy from inherent high energy sources, especially from high energy plasma in the semiconductor manufacturing process. Plasma-based reactive ion etching (RIE) is one of the most well-known etching equipment in the semiconductor manufacturing process, which emits high energy plasma ions to process silicon materials and metal layers. Due to the antenna effect, the current derived from the high energy plasma ions is very strong, and the energy harvester 110 can collect the energy of these high energy plasma ions to serve as a stable power source required for the key transfer process.

[0023] The key storage device 100 may be implemented in a plurality of previously manufactured metal layers, and the plurality of energetic particles (such as the high energy plasma ions) collected by the energy harvester 110 are used for manufacturing at least one subsequently manufactured metal layer, wherein the plurality of previously manufactured metal layers are manufactured before the at least one subsequently manufactured metal layer. For example, the key storage device 100 may be implemented in the first metal layer to the sixth metal layer, wherein when the process enters the manufacturing of the seventh metal layer to the eighth metal layer, the key storage device 100 has been implemented on the wafer 10, and the high energy plasma ions used for etching the seventh metal layer to the eighth metal layer may be collected by the energy harvester 110 to generate the regular voltage. When the regular voltage reaches the predetermined level, the operation of the controller 120 may be automatically started.

[0024] In this embodiment, the key storage device 100 may further include a boosted voltage generator 130 such as a charge pump circuit, wherein the boosted voltage generator 130 is coupled to the controller 120 and is used to generate a boosted voltage according to the regular voltage when the controller 120 starts the key transfer procedure. For example, the controller 120 may send a corresponding instruction to the boosted voltage generator 130, and the boosted voltage generator 130 may generate the boosted voltage in response to the instruction. In this embodiment, the regular voltage provided by the energy harvester 110 may serve as a power supply for the controller 120, the boosted voltage generator 130, the hardware key device 140, and the one-time programmable device 150, wherein the controller 120 may write the key value into the one-time programmable device 150 with the boosted voltage provided by the boosted voltage generator 130, and the controller 120 may clear the inherent key value in the hardware key device 140 with the boosted voltage provided by the boosted voltage generator 130. It should be noted that the boosted voltage used to write the key value into the one-time programmable device 150 and the boosted voltage used to clear the inherent key value in the hardware key device 140 are not necessarily the same. For example, the boosted voltage may include a first boosted voltage and a second boosted voltage, wherein the controller 120 may write the key value into the one-time programmable device 150 with the aid of the first boosted voltage and clear the inherent key value in the hardware key device 140 with the aid of the second boosted voltage, but the present invention is not limited thereto.

[0025] In this embodiment, after the controller 120 writes the key into the one-time programmable device 150, the controller 120 may verify whether the key value read from the one-time programmable device 150 matches the inherent key value read from the hardware key device 140. When the controller 120 verifies that the key value read from the one-time programmable device 150 matches the inherent key value read from the hardware key device 140, the controller 120 may determine that the key value has been correctly written into the one-time programmable device 150. After the controller 120 writes the key value into the one-time programmable device 150 (especially when the controller 120 determines that the key value has been correctly written into the one-time programmable device 150), the controller 120 may further program a flag in the one-time programmable device 150 to indicate that the key transfer procedure has been completed. Therefore, if the controller 120 is powered on again by the energy harvester 110 in a subsequent manufacturing process, the controller 120 may skip the key transfer procedure in response to the flag read from the one-time programmable device 150.

[0026] In this embodiment, after the one-time programmable device 150 stores the key value (especially after the controller 120 verifies that the key value stored in the one-time programmable device 150 matches the inherent key value read from the hardware key device 140), the controller 120 may clear the inherent key value in the hardware key device 140 by programming all cells in the hardware key device 140 to the same logic value (e.g., logic value "1"), so as to prevent hackers from obtaining the key value through a microscope. It should be noted that the hardware key device 140 may be a fuse-type storage device. For example, each of the plurality of cells in the hardware key device 140 is in an initial state (represented by a short circuit formed by a conductive path) or a final state (represented by an open circuit formed by a fuse path), wherein the cell in the initial state may indicate a first logic value (e.g., logic value "0") and the cell in the final state may indicate a second logic value (e.g., logic value "1"), and each cell in the final state cannot be reversed back to the initial state. Therefore, the controller 120 can read all the cells in the hardware key device 140 to obtain the inherent key value (e.g., an inherent digital key value), and after the one-time programmable device 150 stores the key value (especially after the controller 120 verifies that the key value stored in the one-time programmable device 150 matches the inherent key value read from the hardware key device 140), the controller 120 programs all the cells in the initial state to the final state (e.g., by converting the above-mentioned conduction path into a fuse path by means of the boost voltage). That is, the inherent key value in the hardware key device 140 can be destroyed.

[0027] Figure 2A method for writing a key value into a one-time programmable device (eg Figure 1 The one-time programmable device 150 shown in FIG. 1 is a schematic diagram of the workflow of the method, wherein the method is applicable to a key storage device (eg, Figure 1 The key storage device 100 shown in FIG. 1 ) and the key storage device includes the one-time programmable device. It should be noted that, Figure 2 The workflow shown is for illustrative purposes only and is not intended to limit the present invention. For example, one or more steps may be Figure 2 The steps shown in the figure may be added, deleted, or modified. In addition, these steps do not have to be exactly the same if the same results are achieved. Figure 2 Execute in the order shown.

[0028] In step S210, the key storage device may utilize an energy harvester (eg Figure 1 The energy harvester 110 shown collects a plurality of energy particles during a semiconductor manufacturing process of a wafer including the key storage device and generates a regular voltage accordingly.

[0029] In step S220, after the normal voltage reaches a predetermined level, the key storage device may utilize a controller (eg, Figure 1 The controller 120 shown in the figure has a hardware key device (eg Figure 1 The hardware key device 140 shown, such as a metal key storage device, reads an inherent key value.

[0030] In step S230 , the key storage device may utilize the controller to write the key value into the one-time programmable device according to the inherent key value.

[0031] In step S240 , after the one-time programmable device stores the key value, the key storage device may utilize the controller to clear the inherent key value in the hardware key device.

[0032] Figure 3 According to an embodiment of the present invention Figure 2 Schematic diagram of the detailed workflow of the method shown. It should be noted that Figure 3 The workflow shown is for illustrative purposes only and is not intended to limit the present invention. For example, one or more steps may be Figure 3 The steps shown in the figure may be added, deleted, or modified. In addition, these steps do not have to be exactly the same if the same results are achieved. Figure 3 Execute in the order shown.

[0033] In step S310 , the energy harvester 110 that collects high energy plasma ions (such as plasma ions) may generate a supply voltage (such as the above-mentioned regular voltage) to circuit blocks such as the boost voltage generator 130 , the hardware key device 140 , and the one-time programmable device 150 .

[0034] In step S320 , the controller 120 may initiate the key transfer procedure in response to the supply voltage generated by the energy harvester 110 reaching a predetermined level.

[0035] In step S330, the controller 120 may check whether the key transfer procedure has been completed by referring to the flag of the one-time programmable 150. If the check result is "yes", the workflow ends. If the check result is "no", the workflow proceeds to step S340.

[0036] In step S340 , the controller 120 may read a unique hardware key value from the hardware key device 140 (eg, a metal key storage device).

[0037] In step S350 , the controller 120 may activate the boost voltage generator 130 to generate the boost voltage.

[0038] In step S360 , the controller 120 may write the inherent hardware key value into the one-time programmable device 150 and verify the key value stored in the one-time programmable device 150 .

[0039] In step S370 , the controller 120 may program all cells in the hardware key device 140 to a same logic value such as “1”.

[0040] In step S380 , the controller 120 may program a flag of the one-time programmable device 150 (hereinafter referred to as “OTP flag”) to indicate that the key transfer process has been completed.

[0041] In step S390 , the controller 120 may turn off the boost voltage generator 130 , and the workflow ends.

[0042] In summary, the key storage device and method provided by the embodiments of the present invention utilize an energy harvester to collect high-energy plasma ions (which are used for reactive ion etching during the semiconductor manufacturing process) to generate a supply voltage for the key transfer device (e.g., the controller 120, the boost voltage generator 130, the hardware key device 140, and the one-time programmable device 150). Therefore, the key transfer procedure can be completed during the semiconductor manufacturing process without providing the key value to a third party, thereby avoiding the risk of side-channel attacks due to programming keys. In addition, the inherent key value in the fuse-type storage device can be destroyed after the key transfer procedure is completed, and the key value stored in the one-time programmable device is invisible, and security can be greatly improved compared to the related art. In addition, special facilities (e.g., a secure environment for programming key values) and additional testing time are no longer required. Therefore, the present invention can solve the problems of the related art without side effects or with less side effects.

[0043] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A key storage device, characterized in that: Include: An energy harvester for collecting a plurality of energy particles during a manufacturing process of a wafer including the key storage device to generate a regular voltage; a controller, coupled to the energy harvester, configured to initiate a key transfer procedure when the normal voltage reaches a predetermined level; a hardware key device, coupled to the controller, for providing an inherent key value; a one-time programmable device coupled to the controller; in: The controller reads the inherent key value from the hardware key device, and writes a key value into the one-time programmable device according to the inherent key value; as well as After the one-time programmable device stores the key value, the controller clears the inherent key value in the hardware key device.

2. The key storage device according to claim 1, wherein: The key storage device is implemented in multiple previously manufactured metal layers, the multiple energy particles collected by the energy harvester are used for manufacturing at least one subsequently manufactured metal layer, and the multiple previously manufactured metal layers are manufactured before the at least one subsequently manufactured metal layer.

3. The key storage device according to claim 1, wherein: Also includes: A boost voltage generator is used to generate a boost voltage according to the regular voltage when the controller starts the key transfer procedure.

4. The key storage device according to claim 3, characterized in that: The controller writes the key value into the one-time programmable device by means of the boosted voltage.

5. The key storage device according to claim 3, wherein: The controller clears the inherent key value in the hardware key device by means of the boosted voltage.

6. The key storage device according to claim 3, wherein: The boosted voltage includes a first boosted voltage and a second boosted voltage, and the controller writes the key value into the one-time programmable device by means of the first boosted voltage and clears the inherent key value in the hardware key device by means of the second boosted voltage.

7. The key storage device according to claim 1, wherein: The controller clears the inherent key value in the hardware key device by programming all units in the hardware key device to a same logic value.

8. The key storage device according to claim 1, wherein: Each of the multiple units in the hardware key device is in an initial state or a final state, each unit in the final state cannot be reversed back to the initial state, and after the one-time programmable device stores the key value, the controller programs all the units in the initial state to the final state.

9. The key storage device according to claim 1, wherein: After the controller writes the key value into the one-time programmable device, the controller verifies whether the key value read from the one-time programmable device matches the inherent key value read from the hardware key device.

10. The key storage device according to claim 1, wherein: After the controller writes the key value into the one-time programmable device, the controller further programs a flag in the one-time programmable device to indicate that the key transfer procedure has been completed.

11. A method for writing a key value into a one-time programmable device, characterized in that: The method is applicable to a key storage device, the key storage device includes the one-time programmable device, and the method includes: Using an energy harvester of the key storage device to collect a plurality of energy particles during a manufacturing process of a wafer including the key storage device, and generating a regular voltage accordingly; After the normal voltage reaches a predetermined level, using a controller of the key storage device to read an inherent key value from a hardware key device of the key storage device; Using the controller to write the key value into the one-time programmable device according to the inherent key value; as well as After the one-time programmable device stores the key value, the controller is used to clear the inherent key value in the hardware key device.

12. The method according to claim 11, characterized in that The key storage device is implemented in multiple previously manufactured metal layers, the multiple energy particles collected by the energy harvester are used for manufacturing at least one subsequently manufactured metal layer, and the multiple previously manufactured metal layers are manufactured before the at least one subsequently manufactured metal layer.

13. The method according to claim 11, characterized in that Also includes: A boost voltage generator of the key storage device is used to generate a boost voltage according to the regular voltage.

14. The method according to claim 13, characterized in that The operation of writing the key value into the one-time programmable device is performed by means of the boost voltage.

15. The method according to claim 13, characterized in that The operation of clearing the inherent key value in the hardware key device is performed by means of the boost voltage.

16. The method according to claim 13, characterized in that The boost voltage includes a first boost voltage and a second boost voltage. The operation of writing the key value into the one-time programmable device is performed with the help of the first boost voltage, and the operation of clearing the inherent key value in the hardware key device is performed with the help of the second boost voltage.

17. The method according to claim 11, characterized in that Using the controller to clear the inherent key value in the hardware key device includes: All cells in the hardware key device are programmed to a same logic value.

18. The method according to claim 11, characterized in that Each of the plurality of units in the hardware key device is in an initial state or a final state, each unit in the final state cannot be reversed back to the initial state, and clearing the inherent key value in the hardware key device using the controller includes: All cells in the initial state are programmed to the final state.

19. The method according to claim 11, characterized in that Also includes: After the controller writes the key value into the one-time programmable device, the controller is used to verify whether the key value read from the one-time programmable device matches the inherent key value read from the hardware key device.

20. The method of claim 11, wherein: Also includes: After the controller writes the key value into the one-time programmable device, the controller is used to program a flag in the one-time programmable device to indicate that the key transfer procedure has been completed.