Ring generator based true random number generator for hardware root of trust

CN119998785APending Publication Date: 2025-05-13SIMENS INDASTRI SOFTVEAR INK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280100855.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-08-08
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

Existing hardware roots of trust face trade-offs between meeting security needs and maintaining functionality and testability, and their complexity negatively affects area overhead and design processes, resulting in hesitation in adoption by IC suppliers.

Method used

Using a true random number generator based on the ring generator and the corresponding hardware root of trust circuit, random numbers are generated through a combination of the ring generator and an inverter-based ring oscillator, and a lightweight hardware root of trust is constructed through components such as hash circuits and search circuits.

Benefits of technology

A valid and non-invasive lightweight hardware trust root is implemented to effectively detect intrusions, protect integrated circuits from malicious activities and hackers, while reducing design and testing complexity and cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119998785A_ABST
    Figure CN119998785A_ABST
Patent Text Reader

Abstract

The random number generator includes a ring generator and one or more inverter-based ring oscillators. One or more inverter-based ring oscillators are configured to inject bits into the ring generator at a plurality of positions. If there is more than one inverter-based ring oscillator, the inverter-based ring oscillator may have a different number of inverting elements and may inject bits into the ring generator at different locations. At least one of the one or more inverter-based ring oscillators may be configured to inject bits into the ring generator at different locations from an output of part or all of its inverting elements. The random number generator may further include a blocking circuit configured to convert the ring generator to a cyclic shift register based on the blocking signal by blocking injection from the plurality of inverter-based ring oscillators and internal feedback in the ring generator.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The technology disclosed in the present invention relates to the field of hardware security and trust. Various implementations of the disclosed technology are particularly useful for designing and using true random number generators and associated hardware trust roots to protect circuits from malicious activities and hacker attack attempts. Background Art

[0002] The huge cost of building and maintaining integrated circuit manufacturing has forced many semiconductor companies to move to a fabless model, outsourcing the expensive manufacturing process to foundries. The lack of reliable monitoring and trustworthiness of offshore manufacturing and testing processes increases security threats. Hardware security threats can take many forms, including intellectual property (IP) piracy, overproduction, counterfeiting, reverse engineering, and hardware Trojan insertion.

[0003] To reduce security risks, various defense schemes have been proposed, such as logic locking, circuit obfuscation, password-based authentication, challenge-response protocols, and data encryption. The foundation on which many secure operations of integrated circuits rely is often defined as a hardware root of trust (RoT). A hardware root of trust can perform specific, critical security functions. For example, high-end roots of trust are often integrated into silicon as separate, custom-designed security modules (protected from malware attacks) to handle chip and device identity, cryptographic keys and functions, secure boot processes, attestation, authentication, firmware updates, etc. As a security tool, a hardware root of trust should be able to detect intrusions, prohibit access pending further actions, and / or obfuscate (disguise) the logical operations of the integrated circuit. The selection of an adequate root of trust depends on many factors, such as the threat model, potential risk, desired level of protection, programmability, silicon overhead, impact on performance, or the complexity of encryption algorithms and ciphers.

[0004] Existing hardware roots of trust face many challenges. One challenge is the trade-off between meeting security requirements and maintaining functionality and testability. Another challenge is the complexity of several existing solutions and their impact on area overhead and design flow. These challenges can make IC vendors hesitant to adopt existing solutions. Therefore, an effective and non-intrusive lightweight hardware root of trust is highly desirable.

[0005] Random number generators are commonly used in hardware root of trust modules. Although pseudo-random number generators can generate a large number of non-repeating vector sequences (pattern sequences), these non-repeating vector sequences are deterministic in nature and are therefore vulnerable to cryptanalysis attacks. Unlike pseudo-random number generators based on complex but deterministic vectors, true random number generators can generate random numbers based on various random characteristics such as thermal noise, metastability, quantum effects, phase jitter, or glitches of digital circuits. It is expected that true random number generator circuits can not only generate random numbers using these difficult-to-measure physical properties, but can also be easily designed, synthesized, and implemented using modern digital design blocks. Summary of the invention

[0006] Various aspects of the disclosed technology relate to true random number generators based on ring generators and hardware root of trust circuits constructed based on them. In one aspect, there is a circuit including a random number generator, the random number generator including: a ring generator; and one or more inverter-based ring oscillators. The one or more inverter-based ring oscillators are configured to inject bits into the ring generator at multiple locations.

[0007] If the one or more inverter-based ring oscillators have more than one inverter-based ring oscillator, the one or more inverter-based ring oscillators may have different numbers of inverting elements (inverting devices) and may inject bits into the ring generator at different positions.

[0008] At least one of the one or more inverter-based ring oscillators may be configured to inject bits into the ring generator at different locations from outputs of some or all inverting elements in at least one of the one or more inverter-based ring oscillators.

[0009] The random number generator may also include a blocking circuit configured to convert the ring generator into a circular shift register by blocking both the injection from the one or more inverter-based ring oscillators and the internal feedback in the ring generator based on a blocking signal. The circuit may also include a counter configured to generate the blocking signal. After a predetermined number of clock cycles indicated by the counter, the blocking is enabled. The blocking circuit may include a plurality of AND gates.

[0010] The circuit may also include a hash circuit configured to simulate a hash function capable of converting a random number output from the random number generator into a hash value. The hash circuit may include: a combination circuit including a nonlinear Boolean operator composed of logic gates, the combination circuit configured to receive the random number; and a ring generator configured to be initialized by a secret key and injected with bits from the output of the combination circuit, and output the hash value after a predetermined number of clock cycles.

[0011] The circuit may also include a retrieval circuit configured to use the hash value to retrieve one or more configuration masks from a response signal received by the circuit, wherein the response signal is generated by a computing device based on the random number, and the generation of the response signal includes: generating the hash value of the random number and combining the hash value with the one or more configuration masks.

[0012] The circuit may further include a descrambler, a scrambler, or both. The descrambler is configured to descramble a signal received by the circuit using a configuration mask in the one or more configuration masks; the scrambler is configured to scramble a signal sent by the circuit using a configuration mask in the one or more configuration masks.

[0013] Descrambling the signal may include retrieving the compressed test vector from an encrypted compressed test vector received by the circuit.

[0014] The circuit may further include a multi-input signature register configured to compress a test response during a self-test, wherein the random number generator is further configured to operate as a pseudo-random test vector generator by blocking the injection from the one or more inverter-based ring oscillators.

[0015] The circuit may also include a controller configured to supervise an authentication process, the authentication process including: generating the random number by the random number generator, converting the random number to the hash value by the hash circuit, and retrieving the one or more configuration masks from the response signal received by the circuit based on the hash value by the retrieval circuit. The controller may include a finite state machine. The controller is also configured to control a test process for self-testing of the retrieval circuit, the hash circuit, and the random number generator.

[0016] In another aspect, there are one or more non-transitory computer-readable media storing computer-executable instructions for causing one or more processors to perform a method comprising creating the above-described circuit in a circuit design.

[0017] Certain inventive aspects are set out in the accompanying independent and dependent claims. Where appropriate, features of the dependent claims may be combined with features of the independent claims and with features of other dependent claims and not merely as explicitly set out in a claim.

[0018] Certain objects and advantages of various inventive aspects have been described herein above. Of course, it should be understood that not all of these objects or advantages may be achieved according to any specific embodiment of the disclosed technology. Thus, for example, those skilled in the art will recognize that the disclosed technology may be embodied or performed in a manner that achieves or optimizes one advantage or a group of advantages taught herein without necessarily achieving other objects or advantages taught or implied herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1A An example of a true random number generator that may be implemented according to various embodiments of the disclosed technology is shown.

[0020] Figure 1B Another example of a true random number generator that can be implemented according to various embodiments of the disclosed technology is shown.

[0021] Figure 2A An example of a 28-bit ring generator implementing the primitive characteristic polynomial is shown.

[0022] Figure 2B An example of a 28-bit dense ring generator implementing the primitive characteristic polynomial is shown.

[0023] Figure 3A An example 28-bit true random number generator based on a 28-bit dense ring generator that can be implemented according to various embodiments of the disclosed technology is shown.

[0024] Figure 3B An example 32-bit true random number generator based on a 32-bit ring generator that can be implemented according to various embodiments of the disclosed technology is shown.

[0025] Figure 4 An example 28-bit true random number generator with built-in block circuitry that may be implemented in accordance with various embodiments of the disclosed technology is shown.

[0026] Figure 5 An example distribution of 0s and 1s obtained for a 64-bit true random number generator is shown.

[0027] Figure 6 Shown is a histogram of 1s observed on consecutive bits of a number produced by a 64-bit true random number generator.

[0028] Figure 7A 64-bit random sample is shown with respect to the distribution of its counts of 1s.

[0029] Figure 8 An example of a hash circuit that may be implemented according to various embodiments of the disclosed technology is shown.

[0030] Fig. 9 An example of a true random number generator combined with a hash circuit that can be implemented according to various embodiments of the disclosed technology is shown.

[0031] Fig.10 An example of a hardware root of trust system that may be implemented according to various embodiments of the disclosed technology is shown.

[0032] Fig.11 An example descrambler that may be implemented according to various embodiments of the disclosed technology is shown.

[0033] Fig.12 An example of a controller that may be implemented according to various embodiments of the disclosed technology is shown.

[0034] Fig.13 An example of applying three different test vectors to an inverter-based ring oscillator is shown.

[0035] Fig.14 An exemplary self-testable hardware root of trust that can be implemented in accordance with various embodiments of the disclosed technology is shown.

[0036] Fig.15 An example of a programmable computer system that can be used with various embodiments of the disclosed technology is shown. DETAILED DESCRIPTION

[0037] Various aspects of the disclosed technology relate to true random number generators based on ring generators and hardware root of trust circuits constructed based on them. In the following description, many details are set forth for the purpose of explanation. However, one of ordinary skill in the art will appreciate that the disclosed technology can be implemented without these specific details. In other cases, well-known features have not been described in detail to avoid obfuscating the disclosed technology.

[0038] Some of the techniques described herein may be implemented in software instructions stored on a computer-readable medium, software instructions executed on a computer, or some combination of the two. For example, some of the disclosed techniques may be implemented as part of an electronic design automation (EDA) tool. This method may be performed on a single computer or on a networked computer.

[0039] Although the operations of the disclosed methods are described in a particular order for ease of presentation, it should be understood that such description includes reordering unless specific language described below requires a particular ordering. For example, in some cases, operations described in order may be reordered or performed simultaneously. In addition, for the sake of simplicity, the disclosed flow charts and block diagrams generally do not show the various ways in which a particular method can be used in conjunction with other methods.

[0040] The detailed description of the method or device sometimes uses terms like "configuration" and "injection" to describe the disclosed method or device function / structure. These terms are high-level descriptions. The actual operations or functions / structures corresponding to these terms will vary depending on the specific implementation and are easily recognized by ordinary technicians in this field.

[0041] As used in this disclosure, the singular forms "a", "an", and "the" include the plural forms unless the context clearly dictates otherwise. In addition, the term "include" means "comprise". Furthermore, unless the context dictates otherwise, the term "couple" refers to an electrical or electromagnetic connection or link, and includes a direct connection or direct link as well as an indirect connection or indirect link through one or more intermediate elements that does not affect the intended operation of the circuit.

[0042] Additionally, as used herein, the term "design" is intended to encompass data that describes an entire integrated circuit device. However, the term is also intended to encompass smaller data sets that describe one or more components of the entire device (eg, a portion of an integrated circuit device).

[0043] As mentioned above, a true random number generator is one of the important hardware security primitives of the hardware root of trust. Preferably, the true random number generator can be easily synthesized by using digital components. Figure 1A An example of a true random number generator 100 that can be implemented according to various embodiments of the disclosed technology is shown. The true random number generator 100 includes a ring generator 110 and a plurality of inverter-based ring oscillators 120. The ring generator 110 and the plurality of inverter-based ring oscillators 120 can both be constructed using digital components. Each of the plurality of inverter-based ring oscillators 120 is configured to inject a bit into the ring generator 110 at a unique position. Through various implementations of the disclosed technology, each of the plurality of inverter-based ring oscillators 120 can include a unique number of inverting elements (inverting devices). Examples of inverting elements are NOT gates and NAND gates.

[0044] Figure 1BAn example of a true random number generator 105 that can be implemented according to various embodiments of the disclosed technology is shown. The true random number generator 105 includes a ring generator 115 and an inverter-based ring oscillator 125. Both the ring generator 115 and the inverter-based ring oscillator 125 can be constructed using digital components. The inverter-based ring oscillator 125 is configured to inject bits into the ring generator 115 at multiple locations from the output of multiple inverting elements selected from the inverter-based ring oscillator 125.

[0045] It should be noted that Figure 1A and Figure 1B The schemes shown in can be combined. For example, the true random number generator may include a ring generator and two inverter-based ring oscillators. Each or one of the inverter-based ring oscillators injects bits into the ring generator at multiple locations.

[0046] A ring generator is a linear finite state machine that can be derived by changing the canonical form (external feedback, internal feedback) of a linear feedback shift register while maintaining their transfer functions. An example of the change is the m-sequence-preserving transformation described in "Ring Generators—New Devices for Embedded Test Applications" (IEEE Trans. Computer-Aided Design, Vol. 23, No. 9, pp. 1306-1320, 2004) by G.Mrugalski, J.Rajski, and J.Tyszer. Like a linear feedback shift register, a ring generator can be used for various circuit test applications, such as pseudo-random test vector generation, on-chip test data decompression, test response compression, etc. It has been shown that, compared with conventional linear feedback shift registers and cellular automata, after applying the transformation to the linear feedback shift register in a certain order, the resulting ring generator has the characteristics of significantly reduced levels of XOR logic, minimized internal fan-out, and simplified circuit layout and routing. The ring generator thus has a highly modular structure and can operate at high speeds.

[0047] Figure 2AAn example of a 28-bit ring generator 200 that implements a primitive characteristic polynomial 210 is shown. The 28-bit ring generator 200 includes 28 state elements 220 and 5 XOR gates 230. Each of the XOR gates 230 is located at the feedback position in the ring formed by the state element 220, and one of the inputs of the XOR gate 230 is connected to the feedback tap by a feedback line. The state element 220 can be implemented using a flip-flop. As shown in the figure, the feedback logic of the 28-bit ring generator 200 has only one double-input XOR gate per feedback line, so the logic level is 1, which is less than 2 for cellular automata and log2k (k is the number of XOR gates) for the external feedback form of the linear feedback shift register. As shown in the figure, the 28-bit ring generator 200 does not use the long feedback line required for the internal feedback form of the linear feedback shift register. Therefore, the ring generator is faster than both the linear feedback shift register and the cellular automaton of the two canonical forms.

[0048] Figure 2B An example of a 28-bit dense ring generator 240 that implements a primitive characteristic polynomial 250 is shown. The 28-bit dense ring generator 240 includes 28 state elements 260 and 11 XOR gates 270. The large number of XOR gates 270 results in a dense characteristic polynomial 250 that has thirteen non-zero terms compared to the seven non-zero terms of the primitive characteristic polynomial 210. When used for test data decompression, the dense ring generator is able to drive a large number of scan chains by using outputs taken directly from feedback logic or phase shifters tapped locally from consecutive locations. This can allow the designer to minimize routing complexity, optimize wiring size, and make the overall layout compact. It should be noted that either a conventional ring generator (such as the 28-bit ring generator 200) or a dense ring generator (such as the 28-bit dense ring generator 240) can be used to implement Figure 1A The ring generator 110 and Figure 1B The ring generator 115 in.

[0049] Figure 3A An example 28-bit true random number generator 300 based on a 28-bit dense ring generator 310 that can be implemented according to various embodiments of the disclosed technology is shown. The 28-bit dense ring generator 310 is similar to Figure 2BThe 28-bit dense ring generator 240 in FIG. 3 is the same as the 28-bit dense ring generator 240 in FIG. In addition to the 28-bit dense ring generator 310, the 28-bit true random number generator 300 includes a 3-inverter ring oscillator 320 and a 5-inverter ring oscillator 330. The 3-inverter ring oscillator 320 and the 5-inverter ring oscillator 330 can inject bits into the 28-bit dense ring generator 310 through an XOR gate at two different locations, respectively. Different numbers of inverting elements can enhance the randomness of the sequence of generated random numbers. The input 325 for the 3-inverter ring oscillator 320 and the input 335 for the 5-inverter ring oscillator 330 can be used to apply test stimuli to test these ring oscillators, which will be discussed in detail later.

[0050] Figure 3B An example of a 32-bit true random number generator 305 based on a 32-bit ring generator 315 that can be implemented according to various embodiments of the disclosed technology is shown. In addition to the 32-bit ring generator 315, the 32-bit true random number generator 305 includes a 5-inverter ring oscillator 335. The outputs of the 5 inverting elements (4 inverters and 1 NAND gate) of the 5-inverter ring oscillator 335 can be respectively injected into the 32-bit ring generator 315 through XOR gates at 5 different positions. It should be noted that in some embodiments of the disclosed technology, not all outputs of the inverting elements are used to inject bits into the ring generator.

[0051] Return to reference Figure 1A As described above, the ring generator 110 can generate a pseudo-random number sequence by itself. The injection from the multiple inverter-based ring oscillators 120 converts the ring generator 110 into a true random number generator. Each of the multiple inverter-based ring oscillators 120 injects a logic value of 1 into the ring generator 110 at a frequency that depends on the integrated circuit manufacturing process and the number of inverting elements used. Therefore, the random characteristics present in the integrated circuit manufacturing process provide the required uncertainty (entropy) or randomness. Further, since the clock of the ring generator 110 is inherently asynchronous with the state of each ring oscillator 120, many clock samples can also put pressure on the metastable region of the flip-flop of the ring generator 110 (due to setup time and hold time violations), thereby generating additional randomness.

[0052] Return to reference Figure 1B, the operating frequency of the inverter-based ring oscillator 125 depends on the circuit manufacturing process, the number of logic elements it deploys, and the delays of its routing paths. Sampling many inverters can fill relatively long intervals with timing jitter, thereby maximizing the probability of capturing at least one noise signal edge in the ring generator 115. Therefore, the ring generator 115 acts as a special form of bit extractor to process the data collected at several stages of the inverter-based ring oscillator 125. In addition, because the clock of the ring generator 115 is inherently asynchronous with the state of the inverter-based ring oscillator 125, some clock samples can stress the metastable region of the ring generator flip-flop (due to setup and hold time violations), thereby generating additional uncertainty (entropy) or randomness.

[0053] Figure 1A True random number generator 100 and Figure 1B The performance of the true random number generator 105 in can be tested experimentally.

[0054] exist Figure 1A In the embodiment of the present invention, the true random number generator 100 may further include a blocking circuit 130 configured to convert the ring generator 110 into a circular shift register by blocking both injection from the plurality of inverter-based ring oscillators 120 and internal feedback in the ring generator 110 based on a blocking signal 145. The blocking signal 145 may be configured to change from unblocking to blocking when the contents of the ring generator 110 are ready to be sent out. Typically, the change occurs after a predetermined number of clock cycles specified by the counter 140. The counter 140 may be internal or external to the controller. The contents of the ring generator 110 may be sent out via the serial output 160, the parallel output 150, or both.

[0055] Similarly, in Figure 1B In the embodiment, the true random number generator 105 may further include a blocking circuit 135 configured to convert the ring generator 115 into a circular shift register by blocking both the injection from the inverter-based ring oscillator 125 and the internal feedback in the ring generator 115 based on a blocking signal 146. The counter 141 may provide the blocking signal 146. The counter 141 may be internal or external to the controller. The contents of the ring generator 115 may be sent out via the serial output 165, the parallel output 155, or both.

[0056] Figure 4 An example 28-bit true random number generator 400 with built-in block circuitry that can be implemented according to various embodiments of the disclosed technology is shown. Figure 3AThe 28-bit true random number generator 300 in the embodiment of the present invention comprises a 28-bit dense ring generator 410, a 3-inverter ring oscillator 420 and a 5-inverter ring oscillator 430. Further, the 28-bit true random number generator 400 comprises 11 AND gates 440 (one on each feedback line of the 28-bit dense ring generator 410), 1 AND gate 450 (gating the output of the 3-inverter ring oscillator 420) and 1 AND gate 460 (gating the output of the 5-inverter ring oscillator 430). These AND gates 440, 450 and 460 constitute a block circuit and are controlled by a blocking signal 470. When the blocking signal 470 is "1", the 28-bit dense ring generator 410 operates as a ring generator and has injections from the 3-inverter ring oscillator 420 and the 5-inverter ring oscillator 430. When the blocking signal 470 changes to "0", the 28-bit dense ring generator 410 becomes a circular shift register, and its content can be shifted out through the OR gate 480. Some outputs of the state elements of the 28-bit dense ring generator 410 can be configured to be used as parallel outputs of the 28-bit true random number generator 400.

[0057] Figure 5 An exemplary distribution of 0s and 1s obtained for a 64-bit true random number generator is shown. The 64-bit true random number generator includes a 64-bit dense ring generator that implements the primitive characteristic polynomial h(x)=x 64 +x 62 +x 60 +x 58 +x 56 +x 54 +x 52 +x 50 +x 48 +x 46 +x 44 +x 42 +x 40 +x 38 +x 36 +x 34 +x 32 +x 30 +x 28 +x 26 +x 23 +x 20 +x 18 +x 16 +x 14 +x 12 +x 10 +x 8 +x 6 +x 4+1 and four ring oscillators, which include 3, 5, 7 and 11 inverters as injectors respectively. The injection positions are distributed in every 8 flip-flops in the upper layer of the ring generator. This 64-bit true random number generator can be built using a Xilinx Artix-7 FPGA on a Cmod A7-15t board, which has a port for collecting true random numbers. The circuit is powered on 100,000 times and after 2 11 After a clock cycle, the obtained value is scanned out ( Figure 5 The first 768 random samples obtained in this way are shown for closer inspection.

[0058] An ideal true random number generator produces independent random combinations and its behavior is otherwise easily predictable. In particular, the correlation between any pair of bits in all sampled random outputs can be measured, effectively collecting n(n–1) / 2 correlation coefficients, where n is the size of the true random number generator. Given s consecutive samples, b i and b k The correlation coefficient between

[0059] ρ i,k = s –1 Σ(b i – 0.5)(b k – 0.5) (1)

[0060] It should be close to 0 to confirm that there is no strong, discernible, and systematic relationship between the two locations.

[0061] The random numbers generated by 64-bit, 128-bit, and 256-bit true random number generators were tested, with 100,000 samples selected in each case. The results showed that the average (absolute value) correlation value of the 64-bit true random number generator in all (64×63) / 2=2016 bit combinations was 0.002611, with the minimum and maximum values ​​being equal to ρ 5,41 =0.00001 and ρ 7,55 =0.0127. In fact, compared to the N(0,1) distribution, at level α = 0.01 (or less), none of the recorded coefficients differ significantly from 0, indicating that the generated samples show no observable correlation between any pair of their bits. Similar results were obtained for other true random number generators.

[0062] Whether the logical value 1 appears approximately half of the time at each bit position can also be used to verify the feasibility of the disclosed true random number generator. It is desirable that the number of 1s that appear at each bit in the s samples generated has a symmetric binomial distribution with a mean of s·p, where p=0.5. This can be easily verified by, for example, a chi-square test. A histogram of 1s observed at consecutive bits of a number generated by a 64-bit true random number generator is shown in Figure 1. Figure 6 Similarly, the number of n-bit sequences consisting of k 0s and nk 1s is binomially distributed, as Figure 7 Again, a goodness-of-fit hypothesis test was used to verify this observation.

[0063] For 64-bit, 128-bit, and 256-bit true random number generators, high pass rates were also achieved when running statistical tests according to the NIST-SP800-22, NIST-SP800-90B, and AIS31 suites. These tests are described in L. Bassham et al., "Statistical Test Suite for Random and Pseudo-Random Number Generators for Cryptographic Applications" (NIST Special Publication, Tech. Rep. 800-22 Rev 1a, 2010) and W. Killmann and W. Schindler, "AIS 31: Functionality classes and evaluation methodology for true (physical) random number generators, version 3.1" (Proc. Bundesamt Sicherheit der Informationstechnik (BSI), Bonn, Germany, 2001, pp. 1-9), respectively.

[0064] A true random number generator can be combined with a hash circuit to be used as part of a hardware root of trust. On the secure server side, the processor can use a hash function to calculate a hash value from a one-time random number (nonce) generated by the circuit. The hash value can be used as a one-time random number or to generate a response to a one-time random number. On the circuit side, the hash circuit can simulate a hash function to convert a one-time random number into a hash value that is the same as the hash value calculated by the processor. The circuit can then use the response and the hash value generated on-chip to perform security-related tasks.

[0065] Figure 8An example of a hash circuit 800 that can be implemented according to various embodiments of the disclosed technology is shown. The hash circuit 800 includes a combination circuit 810 and a ring generator 820. The combination circuit 810 includes logic gates and can be selected from a class of hash functions. Each member of the class includes a plurality of nonlinear Boolean operators and simple logic functions in their canonical form. The selection of a particular hash function can be determined based on the size of the random number 840 and the size of the ring generator 820. The combination circuit 810 can convert the random number 840 into an intermediate hash value 850. The ring generator 820 is capable of mutating the intermediate hash value 850 and converting it into a hash value 860. During the hashing process, the ring generator 820 is first initialized by a secret key 870. The secret key 870 can be stored in a non-volatile on-chip tamper-proof memory in an encoded form. The secret key 870 can be serially uploaded to the ring generator 820 before the actual hash clock cycle. After initialization, the bits of the intermediate hash value 850 are injected into the ring generator 820 from the output of the combination circuit 810. During the injection process, several bits of the intermediate hash value 850 are continuously available at the output of the combinational circuit 810. After a predetermined number of clock cycles (which is sufficient to rotate the contents of the ring generator 820 multiple times), the hash value 860 is finalized and ready for subsequent use. The ring generator 810 can be generated by using a conventional ring generator (such as Figure 2A 28-bit ring generator 200 in ) or a dense ring generator (such as Figure 2B This is achieved using the 28-bit dense ring generator 240 in FIG.

[0066] Fig. 9 An example of a true random number generator 910 combined with a hash circuit 920 that can be implemented according to various embodiments of the disclosed technology is shown. The true random number generator 910 includes a ring generator 940, two inverter-based ring oscillators 930, a blocking circuit formed by 13 AND gates 735, and an OR gate 945 configured to control the serial output of the true random number generator 910. The ring generator 940 is a 28-bit dense ring generator, similar to Figure 2B The two inverter-based ring oscillators 930 can be implemented by two ring oscillators with different numbers of inverting elements, such as Figure 4 A 3-inverter ring oscillator 420 and a 5-inverter ring oscillator 430 are shown.

[0067] When the logic value of the blocking signal 925 is changed to zero, the AND gate 935 converts the ring generator 940 into a circular shift register by blocking both the injection from the inverter-based ring oscillator 930 and the internal feedback in the ring generator 940. Typically, the change occurs after a predetermined number of clock cycles that can be controlled by a counter (not shown in the figure). The blocking signal 935 can also control the serial output of the true random number generator 910 through the OR gate 945. The serial output can be used to form a one-time random number that is sent to a secure server outside the chip.

[0068] The hash circuit 920 includes a combinational circuit 950 and a ring generator 960. The combinational circuit 950 includes an AND gate, an OR gate, and an inverter, and has 13 inputs and 6 outputs. The combinational circuit 950 is configured to generate an intermediate hash value using bits output from the ring generator 940 after the blocking signal 935 converts the ring generator 940 into a circular shift register. The conversion spans several stages of the circular shift register. The final hash value is generated by the ring generator 960. As discussed previously, the secret key 965 is used to initialize the ring generator 960 before the actual hash clock cycle, and the ring generator 960 can then mutate the intermediate hash value based on the primitive feedback polynomial it adopts. The hashing process performed in the ring generator 960 includes injecting a number of bits that are continuously available at the six outputs of the combinational circuit 950 and rotating the contents of the ring generator 960 multiple times. This can be controlled by a counter, which is not shown. Fig. 9 The counter may be the same counter used to control the change of the blocking signal 925. It should be noted that in addition to the counter, there may be other control circuits, some of which may be placed between the true random number generator 910 and the hash circuit 920 and / or placed in each of the true random number generator 910 and the hash circuit 920.

[0069] Fig.10 An example of a hardware root of trust system 1000 that can be implemented according to various embodiments of the disclosed technology is shown. The hardware root of trust system 1000 includes components in both a circuit 1005 and a secure server 1090. The components in the circuit 1005 include: a random number generator 1010, a hash circuit 1020, a retrieval circuit 1030, and a controller 1060. The components in the secure server 1090 include a hash function unit 1095 and a configuration mask unit 1097.

[0070] The random number generator 1010 may be prompted to generate a random number 1015. A request received by the circuit 1005 to run a particular function, for example, may be configured to cause such an action. The circuit 1005 then sends a one-time random number 1016 formed based on the random number 1015 to the secure server 1090. The one-time random number 1016 may contain only the random number 1015, or may also contain some separate data from the circuit 1005, such as its electronic design identification number 1014. The random number generator 1010 includes a ring generator 1017 and one or more inverter-based ring oscillators 1018. It should be noted that although the random number generator 1010 is shown as being identical to the random number generator 1017, the random number generator 1016 may be configured to generate a random number 1015. Figure 1A The true random number generator in is similar, but also uses Figure 1B The random number generator 1010 is implemented by the true random number generator 105 in or a mixture of the two.

[0071] According to various embodiments of the disclosed technology, hash circuit 1020 may use Figure 8 The hash circuit 800 is implemented in Figure 8 Similar to the hash circuit 800 in FIG. 1 , the hash circuit 1020 may include a combination circuit and a ring generator. The combination circuit may convert the random number 1015 into an intermediate hash value. The ring generator may then convert the intermediate hash value into a hash value 1025. The overall hash function of the hash circuit 1020 is configured to simulate the same hash function used by the hash function unit 1095 in the secure server 1090.

[0072] The hash function unit 1095 uses a hash function to calculate a hash value 1096 for the received one-time random number 1016. In normal operation, the hash value 1096 should be the same as the hash value 1025. The calculation may involve a secret key 1093, which is used as an initial value for hashing the random number 1015 included in the one-time random number 1016. The security server 1090 may also include a design identification (Design ID) unit 1092. The design identification unit 1092 can verify the electronic design identification number 1014 and retrieve the secret key 1093 to be used by the hash function unit 1095 based on the electronic design identification number 1014. If the electronic design identification number 1014 is invalid, the security server 1090 can still generate a unique pseudo initial hash value and use it to confuse the resulting response. The security server 1090 can also track how many times each individual chip requests a response, thereby monitoring any abnormal behavior. The same (effective) secret key 1027 may be stored in encrypted form by circuit 1005 and used by hash circuit 1020 in a manner similar to how hash function unit 1095 uses secret key 1093 .

[0073] A configuration mask unit 1097 in the security server 1090 may combine the hash value 1096 with one or more configuration masks to generate a response 1099. An example of a configuration mask is a configuration mask that may be used to descramble encrypted data into original data. Another example is a configuration mask that may be used to scramble original data into encrypted data. Through various implementations of the disclosed technology, the configuration mask unit 1097 may perform a bitwise XOR operation to combine bits of one or more configuration masks with bits of the hash value 1096. In addition to one or more configuration masks, other items may also be XORed with the hash value 1096. Alternatively or additionally, some bits of the hash value may remain unchanged.

[0074] After circuit 1005 receives response 1099 from secure server 1090, retrieval circuit 1030 may retrieve one or more configuration masks 1035 from response 1099 using hash value 1025 received from hash circuit 1020. If one or more configuration masks 1035 are XORed with hash value 1096 in a bitwise operation performed by configuration mask unit 1097 as described above, retrieval circuit 1030 may perform a bitwise retrieval operation using an XOR gate.

[0075] The circuit 1005 may also include a descrambler 1040, a scrambler 1050, or both. The descrambler 1040 may use one of the one or more configuration masks 1035 to retrieve the original data from the encrypted data received by the circuit 1005. For example, the descrambler 1040 may be configured to retrieve the compressed test vector from the encrypted compressed test vector received by the circuit 1005. The scrambler 1050 may use another one of the one or more configuration masks 1035 to encrypt the data to be sent out by the circuit 1005. For example, the scrambler 1050 may be configured to encrypt the test response or the compressed test response before the circuit 1005 sends it out for analysis.

[0076] If both the descrambler 1040 and the scrambler 1050 are in the circuit, an attempt to gain unauthorized access may trigger a dual change in the functionality of the circuit. First, the descrambler 1040 and the scrambler 1050 become obfuscated due to the corrupted configuration mask. Second, the remaining bits (obfuscation 1070) of the response 1099, if any, can be used to hide the design functionality from the adversary in a logic obfuscation process. The logic obfuscation may result in signal corruption caused by certain components being activated. Alternatively, any mismatch between some bits of the hash value 1025 and the hash value 1096 may initiate a simple logic lockout scheme, thereby disabling access to the true functionality of the circuit 1005.

[0077] Fig.11An example descrambler 1100 that can be implemented according to various embodiments of the disclosed technology is shown. The descrambler 1100 includes a 32-bit ring generator 1110 and an XOR gate 1120, and uses the Vernan stream cipher principle. The bits of the configuration mask 1130 are injected into the 32-bit ring generator 1110 through its feedback line. The XOR gate 1120 retrieves the original data 1140 from the encrypted data 1150 using the pseudo-random sequence generated by the 32-bit ring generator 1110. As previously discussed, the ring generator can operate at high speed, so that the descrambler based on the ring generator can work with other high-speed circuits in the circuit. Further, the modular and programmable feedback network properties of the ring generator allow a variety of characteristic polynomials to be implemented. This in turn allows people to select a suitable secret configuration mask, which can correspond to the primitive polynomial according to other security requirements.

[0078] The scrambler can use the same principles as described above. The configuration mask for scrambling is injected into the ring generator in the same manner as the configuration mask 1130. The bits of the data to be scrambled are XORed with the bits of the pseudo-random sequence generated by the ring generator. For scrambling, the positions of the encrypted data 1150 and the original data 1140 are switched.

[0079] When the response from the secure server does not match what is expected, an attempted unauthorized access is detected. This detection can result in an erroneous descrambling mask. An erroneous descrambling mask can trigger a unique feedback polynomial that will produce a pseudo-random sequence (not even necessarily its own maximum length) that effectively obfuscates the encrypted input data. The scrambler can obfuscate the output data following the same principle.

[0080] Return to reference Fig.10 , the security components in circuit 1005, such as random number generator 1010, hash circuit 1020 and / or search circuit 1030, can be controlled by controller 1060. Controller 1060 can be implemented using a simple finite state machine. As previously discussed, ring generator 1017 requires a preset number of clock cycles before it is ready to output random number 1015. Hash circuit 1020 can use Figure 8 800 in . It will also require at least a certain number of clock cycles, sufficient to rotate the contents of the ring generator 820 multiple times before the hash value 1025 is finalized and ready for subsequent application. Accordingly, the controller 1060 may include a counter for determining the time required for the operation of the random number generator 1010 and the hash circuit 1020. In addition to the finite state machine and the counter, the controller 1060 may also include other components for additional functions (such as self-testing).

[0081] Fig.12 An example of a controller 1200 that can be implemented according to various embodiments of the disclosed technology is shown. The controller 1200 includes a control unit 1210, a counter 1220, a control decoder 1230, and a multiplexer 1240. The control unit 1210 can be implemented using a finite state machine circuit (FSM). The counter 1230 can control the activity cycle of both the random number generator and the hash circuit through output 1231 and output 1232, respectively. When the highest output bit of the counter 1230 changes from 0 to 1, the counter 1230 can also send a signal to the control unit 1210, which can be used to terminate the operation. The multiplexer 1240 and the control decoder 1230 can be used for self-testing, which will be discussed below.

[0082] It is desirable that the secure components of a hardware root of trust system be able to be tested in an autonomous process that relies entirely or mostly on internal on-chip resources that do not interfere with other circuit test components. Since logic built-in self-test (LBIST) provides neither full observability nor full controllability of internal storage elements from circuit interfaces, it can be used to test components of a hardware root of trust system while blocking potential Boolean satisfiability (SAT)-based attacks and making scan-based attacks infeasible.

[0083] In logic built-in self-test, the original circuit is usually attached with additional modules designed to generate test vectors and compress test responses. However, the hardware root of trust implemented according to various embodiments of the disclosed technology can facilitate self-testing based on existing blocks due to its simplicity and inherent iteration capabilities. Fig.10 In the hardware root of trust system 1000, the true random number generator 1018 can be reused as a pseudo-random test vector generator during self-test by disabling the feedback loop of the inverter-based ring oscillator 1018. Pseudo-random data and possible errors can easily propagate through the hash circuit 1020 due to its original function. One of the counter outputs in the controller 1060 can be reused to provide a test stimulus (001100110011...) for testing a shift register that is typically used to store the response 1099 before processing by the retrieval circuit 1030. The shift register can be a component of the retrieval circuit 1030.

[0084] The inverter-based ring oscillators 1018 can be tested by breaking their own feedback loops and applying different vectors multiple times to detect stuck-at faults in the inverter-based ring oscillators 1018 and injecting deterministic data into the ring generator 1017 . Fig.13An example of applying three different test vectors to the inverter-based ring oscillator 1300 is shown. It is noteworthy that all networks in the inverter-based ring oscillator 1300 can assume two values: 0 and 1 during the test process. This allows all stuck-at-1 faults and stuck-at-0 faults to be stimulated separately. The first vector (001) disables the feedback loop at gate 1310, while the second vector (010) disables the feedback loop at gate 1320. The last vector (111) blocks the loop at the auxiliary OR gate 1330, which allows faults on the feedback network (and thus faults on the input of gate 1310) to be detected and observed. The output of the OR gate 1330 can be directly connected to an observation point to observe the response associated with faults affecting the feedback line and stuck-at-1 faults on the input of gate 1310 (note that these faults cannot propagate to the oscillator output due to the dominant signals assigned to the inputs of gates 1310 and 1320).

[0085] For testing Fig.10 The test vectors for the inverter-based ring oscillator in may be provided by a control decoder in controller 1060, as Fig.12 The same as the control decoder 1230 in the controller 1200 in FIG. Fig.12 As shown, based on signals from control unit 12010 and counter 1202, control decoder 1230 can provide test vectors to stimulate the inverter-based ring oscillator through output 1233. If one of the outputs (e.g., Fig.13 If gates 1310 to 1330 in are fixed at uncontrolled values, and the fault causes one of these inputs to change from a dominant value to an uncontrolled value, the inverter-based ring oscillator will oscillate, effectively producing a series of erroneous values ​​entering the random number generator.

[0086] Finally, a multiple-input signature register (MISR) for compressing the test response may be added. The test response outputs from both the inverter-based ring oscillator 1018 and the retrieval circuit 1030 may be coupled to the multiple-input signature register to produce the final signature of the test response. Fig.14An example hardware root of trust 1400 capable of self-testing that can be implemented according to various embodiments of the disclosed technology is shown. The controller 1410 can configure the hardware root of trust 1400 into a self-test mode. In the self-test mode, the random number generator 1420 can be changed to a pseudo-random number generator to generate a test stimulus. The counter in the controller 1410 can provide a test stimulus to test the response register 1430. The test responses output from both the hash circuit and the response register 1430 are combined by the XOR gate 1460. The result is sent to the multi-input feature register 1440. At the same time, the control decoder in the controller 1410 can provide a test stimulus to test the inverter-based ring oscillator in the random number generator 1420. The test response is also collected by the multi-input feature register 1440. The test process can be simulated for a fault-free circuit to generate a good machine signature, and the test process can be simulated for a potential fault to determine the fault coverage. The signature generated by the multi-input feature register can be compared with the good machine signature to determine whether a fault is detected.

[0087] Return to reference Fig.10 , the security server 1090 can be implemented by one or more computing systems / devices. Accordingly, one or more of the hash function unit 1095, the configuration mask unit 1097, and the design identification unit 1092 can be implemented by executing programming instructions on one or more processors in the one or more computing systems / devices. It should be understood that when the hash function unit 1095, the configuration mask unit 1097, and the design identification unit 1092 are shown as Fig.10 When separate units in the present invention are described herein, a single computing system / device may be used to implement some or all of these units at different times, or components of these units may be implemented at different times.

[0088] Various examples of the disclosed technology can be implemented by executing software instructions through a computing device (e.g., a programmable computer). Fig.15 A schematic example of a computing device 1501 is shown. As shown in the figure, the computing device 1501 includes a computing unit 1503, which has a processing unit 1505 and a system memory 1507. The processing unit 1505 can be any type of programmable electronic device for executing software instructions, but it will typically be a microprocessor. The system memory 1507 can include both a read-only memory (ROM) 1509 and a random access memory (RAM) 1511. It will be understood by those of ordinary skill in the art that both the read-only memory (ROM) 1509 and the random access memory (RAM) 1511 can store software instructions for execution by the processing unit 1505.

[0089] The processing unit 1505 and the system memory 1507 are directly or indirectly connected to one or more peripheral devices via the bus 1513 or an alternative communication structure. For example, the processing unit 1505 or the system memory 1507 can be directly or indirectly connected to one or more additional memory storage devices, such as a "hard disk" disk drive 1515, a removable disk drive 1517, an optical drive 1519, or a flash memory card 1521. The processing unit 1505 and the system memory 1507 can also be directly or indirectly connected to one or more input devices 1523 and one or more output devices 1525. The input device 1523 can include, for example, a keyboard, a pointing device (such as a mouse, a touchpad, a stylus, a trackball, or a joystick), a scanner, a camera, and a microphone. The output device 1525 can include, for example, a monitor display, a printer, and a speaker. In various examples of the computing device 1501, one or more of the peripheral devices 1515 to 1525 can be housed internally with the computing unit 1503. Alternatively, one or more of the peripheral devices 1515 to 1525 may be located outside the housing of the computing unit 1503 and connected to the bus 1513 via, for example, a Universal Serial Bus (USB).

[0090] In some embodiments, the computing unit 1503 may be directly or indirectly connected to one or more network interfaces 1527 for communicating with other devices constituting the network. The network interface 1527 converts data and control signals from the computing unit 1503 into network messages according to one or more communication protocols, such as the Transmission Control Protocol (TCP) and the Internet Protocol (IP). In addition, the network interface 1527 may be connected to the network using any suitable connection agent (or combination of agents), for example, including a wireless transceiver, a modem, or an Ethernet connection. Such network interfaces and protocols are well known in the art and will not be discussed in detail herein.

[0091] It should be understood that computing device 1501 is illustrated as an example only and is not intended to be limiting. Fig.15 Various embodiments of the disclosed technology may be implemented using one or more computing devices of the components of computing device 1501 shown in FIG. Fig.15 A subset of the components shown in, or an alternative combination of components, including Fig.15 For example, various embodiments of the disclosed technology may be implemented using a multi-processor computer, multiple single-processor and / or multi-processor computers arranged in a network, or some combination of the two.

[0092] in conclusion

[0093] Having illustrated and described the principles of the disclosed technology, it will be apparent to those skilled in the art that the disclosed embodiments may be modified in arrangement and detail without departing from these principles. In view of the many possible embodiments to which the principles of the disclosed technology may be applied, it should be recognized that the embodiments shown are merely preferred examples of the technology and should not be considered to limit the scope of the disclosed technology. Instead, the scope of the disclosed technology is defined by the following claims and their equivalents. Therefore, we claim all that fall within the scope and spirit of these claims as our disclosed technology.

Claims

1. A circuit comprising: A random number generator, the random number generator comprising: Ring generator; and One or more inverter-based ring oscillators configured to inject bits into the ring generator at multiple locations.

2. The circuit according to claim 1, wherein If the one or more inverter-based ring oscillators have more than one inverter-based ring oscillator, the one or more inverter-based ring oscillators have different numbers of inverting elements and inject bits into the ring generator at different positions.

3. The circuit according to claim 1, wherein: At least one of the one or more inverter-based ring oscillators is configured to inject bits into the ring generator at different locations from outputs of some or all inverting elements in at least one of the one or more inverter-based ring oscillators.

4. The circuit according to claim 1, wherein: The random number generator also includes: A blocking circuit is configured to convert the ring generator into a circular shift register by blocking the injection from the one or more inverter-based ring oscillators and internal feedback in the ring generator based on a blocking signal.

5. The circuit according to claim 4, further comprising: A counter is configured to generate the blocking signal, and the blocking is enabled after a predetermined number of clock cycles indicated by the counter.

6. The circuit according to claim 4, wherein: The blocking circuit includes a plurality of AND gates.

7. The circuit according to claim 1, further comprising: A hash circuit is configured to simulate a hash function capable of converting a random number output from the random number generator into a hash value.

8. The circuit according to claim 7, wherein: The hash circuit comprises: a combinatorial circuit comprising a non-linear Boolean operator composed of logic gates, the combinatorial circuit being configured to receive the random number; and A ring generator is configured to be initialized by a secret key and injected with bits from the output of the combinatorial circuit and output the hash value after a predetermined number of clock cycles.

9. The circuit according to claim 7, further comprising: a retrieval circuit configured to retrieve one or more configuration masks from a response signal received by the circuit using the hash value; The response signal is generated by a computing device according to the random number, and the generation of the response signal includes: generating the hash value of the random number, and combining the hash value with the one or more configuration masks.

10. The circuit according to claim 9, further comprising: A descrambler is configured to descramble a signal received by the circuit using a configuration mask of the one or more configuration masks.

11. The circuit according to claim 10, wherein: Descrambling the signal includes retrieving a compressed test vector from an encrypted compressed test vector received by the circuit.

12. The circuit of claim 9, further comprising: A scrambler is configured to scramble a signal transmitted from the circuit using a configuration mask of the one or more configuration masks.

13. The circuit of claim 9, further comprising: a multiple-input signature register configured to compress a test response during a self-test; Wherein, the random number generator is further configured to operate as a pseudo-random test vector generator by blocking the injection from the one or more inverter-based ring oscillators.

14. The circuit of claim 9, further comprising: A controller configured to oversee an authentication process, the authentication process comprising: The random number is generated by the random number generator; converting the random number into the hash value by the hash circuit; and The one or more configuration masks are retrieved by the retrieval circuit from the response signal received by the circuit based on the hash value.

15. The circuit of claim 14, wherein: The controller includes a finite state machine.

16. The circuit of claim 14, wherein: The controller is also configured to control a test process for self-testing of the retrieval circuit, the hash circuit, and the random number generator.

17. One or more computer-readable media storing computer-executable instructions for causing a computer to perform a method comprising: In the circuit design, a circuit according to any one of claims 1 to 16 is created.