Hash circuit for hardware root of trust
By using hash circuits and ring generators to simulate hash functions in the hardware trust root, the trade-off between security requirements and functionality and testability is solved, and a lightweight, non-invasive hardware trust root is achieved, reducing design complexity and area overhead.
Patent Information
- Application Number
- CN202280100844.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-08
- Publication Date
- 2025-05-13
AI Technical Summary
Existing hardware roots of trust face trade-offs between meeting security needs and maintaining functionality and testability, and their complexity negatively affects area overhead and design processes, resulting in hesitation in adoption by IC suppliers.
Using a hash circuit and associated hardware root circuit, the hash function is simulated by a combination circuit and a ring generator, the random number is converted to a hash value, and the final hash value is generated through a secret key initialization and a rotation process of multi-clock cycles.
A lightweight, non-invasive hardware trust root is implemented, capable of effectively detecting intrusions, prohibiting access and obfuscating integrated circuit logic operations, while reducing design complexity and area overhead.
Smart Images

Figure CN119999141A_ABST
Abstract
Description
Technical Field
[0001] The technology disclosed in the present invention relates to the field of hardware security and trust. Various embodiments of the disclosed technology are particularly useful for designing and using hash circuits and associated hardware trust roots to protect circuits from malicious activities and hacking attempts. Background Art
[0002] The huge cost of building and maintaining integrated circuit manufacturing has forced many semiconductor companies to move to a fabless model, outsourcing the expensive manufacturing process to foundries. The lack of reliable monitoring and trustworthiness of offshore manufacturing and testing processes increases security threats. Hardware security threats can take many forms, including intellectual property (IP) piracy, overproduction, counterfeiting, reverse engineering, and hardware Trojan insertion.
[0003] To reduce security risks, various defense schemes have been proposed, such as logic locking, circuit obfuscation, password-based authentication, challenge-response protocols, and data encryption. The foundation on which many secure operations of integrated circuits rely is often defined as a hardware root of trust (RoT). A hardware root of trust can perform specific, critical security functions. For example, high-end roots of trust are often integrated into silicon as separate, custom-designed security modules (protected from malware attacks) to handle chip and device identity, cryptographic keys and functions, secure boot processes, attestation, authentication, firmware updates, etc. As a security tool, a hardware root of trust should be able to detect intrusions, prohibit access pending further actions, and / or obfuscate (disguise) the logical operations of the integrated circuit. The selection of an adequate root of trust depends on many factors, such as the threat model, potential risk, desired level of protection, programmability, silicon overhead, impact on performance, or the complexity of encryption algorithms and ciphers.
[0004] Existing hardware root of trust faces many challenges. One challenge is the trade-off between meeting security requirements and maintaining functionality and testability. Another challenge is the complexity of several existing solutions and their impact on area overhead and design flow. These challenges can make IC vendors hesitant to adopt existing solutions. Therefore, an effective and non-intrusive lightweight hardware root of trust is highly desirable. .
[0005] Hardware root of trust solutions typically use a hash function that converts a random number generated by a circuit into a hash value. Random numbers are sometimes also referred to as one-time random numbers (nonce). The one-time random number may contain additional information, such as an electronic identification code for the circuit. The hash process can be performed simultaneously by an on-chip hash circuit and an off-chip security processor. The security processor can use the hash value to generate a response to the received one-time random number. The hash value generated on the chip and the response received by the circuit can then be used to perform various security functions, such as authentication and obfuscating (disguising) logic operations. Given the complexity of actual hardware implementation, the on-chip hash circuit is preferably easily designed, synthesized, and implemented using modern digital design blocks. Summary of the invention
[0006] Various aspects of the disclosed technology relate to a hash circuit and a hardware root of trust circuit using the hash circuit. In one aspect, there is a circuit comprising: a hash circuit configured to simulate a hash function, the hash function being capable of converting a random number into a hash value, the hash circuit comprising: a combination circuit comprising a logic gate configured to function as a nonlinear Boolean operator, an input of the combination circuit receiving bits of the random number; and a ring generator configured to be initialized by a secret key and injected with bits from an output of the combination circuit, and outputting a hash value after a predetermined number of clock cycles.
[0007] The circuit may also include a non-volatile storage device configured to store the secret key.
[0008] The combinatorial circuit may be configured to receive a preset number of bits of the random number per clock cycle and to continuously inject the bits into the ring generator over a plurality of clock cycles.
[0009] The circuit may also include a random number generator configured to generate random numbers. The random number generator may include: a ring generator and one or more inverter-based ring oscillators, the one or more inverter-based ring oscillators being configured to inject bits into the ring generator at multiple locations. At least one of the one or more inverter-based ring oscillators may be configured to inject bits from the output of some or all of the inverting elements (inverting devices) in the at least one of the one or more inverter-based ring oscillators. The random number generator may also include: a blocking circuit configured to convert the ring generator into a circular shift register based on a blocking signal by blocking both the injection from the one or more inverter-based ring oscillators and the internal feedback in the ring generator.
[0010] The circuit may also include a retrieval circuit configured to retrieve one or more configuration masks from a response signal received by the circuit using a hash value, wherein the response signal is generated by the computing device based on a random number, and the generation of the response signal includes: generating a hash value of the random number, and combining the hash value with the one or more configuration masks.
[0011] The circuit may also include a descrambler, a scrambler, or both, wherein the descrambler is configured to descramble a signal received by the circuit using a configuration mask in the one or more configuration masks, and the scrambler is configured to scramble a signal to be transmitted by the circuit using a configuration mask in the one or more configuration masks.
[0012] Descrambling the signal may include retrieving the compressed test vector from an encrypted compressed test vector received by the circuit.
[0013] The circuit may also include a controller configured to supervise an authentication process, the authentication process including: generating a random number by a random number generator, converting the random number into a hash value by a hash circuit, and retrieving one or more configuration masks from a response signal received by the circuit based on the hash value by a retrieval circuit. The controller may include a finite state machine.
[0014] In another aspect, there are one or more non-transitory computer-readable media storing computer-executable instructions for causing one or more processors to perform a method comprising creating the above-described circuit in a circuit design.
[0015] Certain inventive aspects are set out in the accompanying independent and dependent claims. Where appropriate, features of the dependent claims may be combined with features of the independent claims and with features of other dependent claims and not merely as explicitly set out in a claim.
[0016] Certain objects and advantages of various inventive aspects have been described herein above. Of course, it should be understood that not all of these objects or advantages may be achieved according to any specific embodiment of the disclosed technology. Thus, for example, those skilled in the art will recognize that the disclosed technology may be embodied or performed in a manner that achieves or optimizes one advantage or a group of advantages taught herein without necessarily achieving other objects or advantages taught or implied herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 Examples of hash circuits that may be implemented according to various embodiments of the disclosed technology are shown.
[0018] Figure 2A An example of a 28-bit ring generator implementing the primitive characteristic polynomial is shown.
[0019] Figure 2B An example of a 28-bit dense ring generator implementing the primitive characteristic polynomial is shown.
[0020] Figure 3 An example process for verifying a hash circuit that may be implemented in accordance with various embodiments of the disclosed technology is shown.
[0021] Figure 4 shows an example bar graph summarizing Figure 3 The result of the hash circuit verification process shown in .
[0022] Figure 5 A table is shown which summarizes the Figure 3 Results obtained for different one-time random number sizes, different sizes of ring generators, and two durations of the hash circuit verification process shown in .
[0023] Fig. 6A An example of a true random number generator that can be used to implement an on-chip random number generator according to various embodiments of the disclosed technology is shown.
[0024] Figure 6B An example of a true random number generator that can be used to implement an on-chip random number generator according to various embodiments of the disclosed technology is shown.
[0025] Figure 6C An example of a 32-bit true random number generator based on a 32-bit ring generator that can be implemented according to various embodiments of the disclosed technology is shown.
[0026] Figure 7 An example of a combination of a hash circuit and a true random number generator that can be implemented according to various embodiments of the disclosed technology is shown.
[0027] Figure 8 An example of a hardware root of trust system that may be implemented in accordance with various embodiments of the disclosed technology is shown.
[0028] Fig. 9 An example descrambler is shown that may be implemented in accordance with various embodiments of the disclosed technology.
[0029] Fig.10 An example of a controller that may be implemented according to various embodiments of the disclosed technology is shown.
[0030] Fig.11 An example of a programmable computer system is shown with which various embodiments of the disclosed technology may be used. DETAILED DESCRIPTION
[0031] Various aspects of the disclosed technology are related to hash circuits and hardware root of trust circuits using hash circuits. In the following description, many details are listed for ease of explanation. However, one of ordinary skill in the art will appreciate that the disclosed technology can be implemented without using these specific details. In other cases, in order to avoid obscuring the disclosed technology, well-known features are not described in detail.
[0032] Certain techniques described herein may be implemented by software instructions stored on a computer-readable medium, software instructions executed on a computer, or some combination of the two. For example, certain disclosed techniques may be implemented as part of an electronic design automation (EDA) tool. These methods may be performed on a single computer or on a networked computer.
[0033] Although the operations of the disclosed methods are described in a particular order for ease of presentation, it should be understood that such description includes rearrangement unless specific language below requires a particular order. For example, operations described in order may be rearranged or performed simultaneously in some cases. In addition, for simplicity, the disclosed flow charts and block diagrams generally do not show the various ways in which a particular method can be used in combination with other methods.
[0034] The detailed description of the method or device sometimes uses terms such as "configuration", "conversion" and "injection" to describe the disclosed method or device function / structure. These terms are high-level descriptions. The actual operations or functions / structures corresponding to these terms will vary depending on the specific implementation and are easily recognized by ordinary technicians in the field.
[0035] As used in this disclosure, the singular forms "a", "an" and "the" include the plural forms unless the context clearly dictates otherwise. In addition, the term "include" means "comprise". Furthermore, unless the context dictates otherwise, the term "couple" refers to an electrical or electromagnetic connection or link, and includes a direct connection or direct link as well as an indirect connection or indirect link through one or more intermediate elements that do not affect the intended operation of the circuit.
[0036] Additionally, as used herein, the term "design" is intended to encompass data that describes an entire integrated circuit device. However, the term is also intended to encompass smaller data sets that describe one or more components of the entire device (eg, a portion of an integrated circuit device).
[0037] As mentioned earlier, hardware root of trust usually uses a hash algorithm. On the secure server side, the processor can use a hash function to calculate a hash value from a one-time random number generated by the circuit. The hash value can be used as or to generate a response to the one-time random number. On the circuit side, the hash circuit can simulate a hash function to convert the one-time random number into a hash value that is the same as the hash value calculated by the processor. The circuit can then use the response and the hash value generated on-chip to perform security-related tasks.
[0038] Figure 1 An example of a hash circuit 100 that can be implemented according to various embodiments of the disclosed technology is shown. The hash circuit 100 includes a combinational circuit 110 and a ring generator 120. The combinational circuit 110 includes logic gates and can be obtained from a class of hash functions. Each member in the class includes some non-linear Boolean operators and simple logic functions in typical form. The selection of a specific hash function can be determined based on the size of the random number 140 and the size of the ring generator 120. The combinational circuit 110 can convert the random number 140 into an intermediate hash value 150. The ring generator 120 is configured to mutate the intermediate hash value 150 and convert it into a hash value 160. In order to perform the conversion, the ring generator 120 is first initialized by a secret key 170 and then injected with certain bits of the intermediate hash value 150 from the output of the combinational circuit 110. The secret key 170 can be stored in a non-volatile on-chip tamper-proof memory in an encoded form. The secret key 170 can be serially uploaded to the ring generator 120 before the actual hash clock cycle. During the actual hash clock cycle, several bits of the intermediate hash value 150 may continue to be available at the output of the combinational circuit 110. After a predetermined number of clock cycles sufficient to rotate the contents of the ring generator 120 multiple times, the hash value 160 is finalized and ready for subsequent use.
[0039] A ring generator is a linear finite state machine that can be derived by changing the canonical form (external feedback, internal feedback) of a linear feedback shift register while maintaining their transfer functions. An example of the change is the m-sequence-preserving transformation described in "Ring Generators—New Devices for Embedded Test Applications" (IEEE Trans. Computer-Aided Design, Vol. 23, No. 9, pp. 1306-1320, 2004) by G.Mrugalski, J.Rajski, and J.Tyszer. Like a linear feedback shift register, a ring generator can be used for various circuit test applications, such as pseudo-random test vector generation, on-chip test data decompression, test response compression, etc. It has been shown that, compared with conventional linear feedback shift registers and cellular automata, after applying the transformation to the linear feedback shift register in a certain order, the resulting ring generator has the characteristics of significantly reduced levels of XOR logic, minimized internal fan-out, and simplified circuit layout and routing. The ring generator thus has a highly modular structure and can operate at high speeds.
[0040] Figure 2A An example of a 28-bit ring generator 200 implementing a primitive characteristic polynomial 210 is shown. The 28-bit ring generator 200 includes 28 state elements 220 and 5 exclusive or (XOR) gates 230. Each of the XOR gates 230 is located at the feedback position in the ring formed by the state element 220, and one of the inputs of the XOR gate 230 is connected to the feedback tap by a feedback line. The state element 220 can be implemented using a flip-flop. As shown in the figure, the feedback logic of the 28-bit ring generator 200 has only one double-input XOR gate per feedback line, so the logic level is 1, which is less than 2 for cellular automata and log2k (k is the number of XOR gates) for the external feedback form of the linear feedback shift register (respectively). As shown in the figure, the 28-bit ring generator 200 does not use the long feedback line required for the internal feedback form of the linear feedback shift register. Therefore, the ring generator is faster than both the linear feedback shift register and the cellular automaton of the two canonical forms.
[0041] Figure 2BAn example of a 28-bit dense ring generator 240 that implements a primitive characteristic polynomial 250 is shown. The 28-bit dense ring generator 240 includes 28 state elements 260 and 11 XOR gates 270. The large number of XOR gates 270 results in a dense characteristic polynomial 250 that has thirteen non-zero terms compared to the seven non-zero terms of the primitive characteristic polynomial 210. When used for test data decompression, the dense ring generator is able to drive a large number of scan chains by using outputs taken directly from feedback logic or phase shifters tapped locally from consecutive locations. This can allow the designer to minimize routing complexity, optimize wiring size, and make the overall layout compact. It should be noted that either a conventional ring generator (such as the 28-bit ring generator 200) or a dense ring generator (such as the 28-bit dense ring generator 240) can be used to implement Figure 1 The ring generator 110 in the hash circuit 100 in FIG.
[0042] A desired property of a hash function is the "avalanche effect": a small change in the input of the hash function can result in a significant change in the output of the hash function. The avalanche effect can make the hash value statistically indistinguishable from a random number. The hash circuit 100 can be verified by the following process to show whether the hash circuit 100 causes the avalanche effect: flip a bit of the random number; then check how many bits of the hash value change as a result, which is equivalent to determining the Hamming distance of the new hash value from the original hash value. This process can be repeated multiple times to calculate the average Hamming distance.
[0043] Figure 3 An example process for verifying a hash circuit that can be implemented according to various embodiments of the disclosed technology is shown. The hash circuit 300 includes a 127-bit ring generator that can convert a 256-bit random number 310 into a 127-bit hash value 320. By flipping one bit of the 256-bit random number 310, a new 256-bit random number 315 can be obtained. The Hamming distance between the new 256-bit random number 315 and the 256-bit random number 310 is obviously 1. The hash circuit 300 can convert the new 256-bit random number 315 into a new 127-bit hash value 325. After performing the above flipping process multiple times, the average Hamming distance between the new 127-bit hash value 325 and the 127-bit hash value 320 is determined to be about 63. This shows a good avalanche effect, that is, a single-bit complement of the random value will cause about half of the response bits to flip relative to the hash value obtained for the base random value. In other words, every time a bit of the random number is completed, each bit of the hash value will change with a probability of 0.5.
[0044] Figure 4 An example histogram is shown, which summarizes Figure 3The result of the hash circuit verification process shown in . The histogram is obtained for 500,000 256-bit random numbers. For each of the 500,000 256-bit random numbers, one bit is flipped at a time to generate 64 different derived random numbers (every fourth bit of the base random number is flipped). The base random number and its derived random numbers are all passed through the hash circuit (such as Figure 1 The hash circuit 110 in FIG. 1 is used to perform the hashing, which uses a 127-bit ring generator running for 1,500 clock cycles. To obtain the kth entry of the histogram, the number of hash values that have a Hamming distance k from the hash value obtained for the base random number needs to be counted. The results show that on average 63.8266 bits (i.e., about 50%) change in response to a single bit flip, corresponding to a standard deviation equal to 5.78981. Similar results are obtained for different one-time random number sizes, different sizes of ring generators, and two durations of the hashing process, Figure 5 They are summarized in the table in . The table also shows the number of feedback taps used for each characteristic polynomial. It can be seen that these examples exhibit good avalanche behavior, i.e., a single-bit complement of the nonce value results in approximately half of the response bit flips relative to the hash value obtained for the underlying nonce.
[0045] Return to reference Figure 1 , the random number 140 may be generated by an on-chip random number generator 180. From a security perspective, the random numbers generated by a pseudo-random number generator are secure against some brute force attacks due to the large pattern space. However, a true random number generator may be more effective against security risks because a pseudo-random number generator has a deterministic output pattern, which is still vulnerable to cryptanalysis attacks. Fig. 6A An example true random number generator 600 that can be used to implement the on-chip random number generator 180 according to various embodiments of the disclosed technology is shown. The true random number generator 600 includes a ring generator 610 and a plurality of inverter-based ring oscillators 620. Each of the plurality of inverter-based ring oscillators 620 is configured to inject bits into the ring generator 610 at a unique position. In various embodiments of the disclosed technology, each of the plurality of inverter-based ring oscillators 620 may include a unique number of inverting elements (inverting devices). Examples of inverting elements are NOT gates and NAND gates.
[0046] The ring generator 610 can be formed by using a conventional ring generator (such as Figure 2A 28-bit ring generator 200 in ) or a dense ring generator (such as Figure 2BThe ring generator 610 is implemented as a 28-bit dense ring generator 240 in FIG. As previously described, the ring generator 610 itself can generate a pseudo-random number sequence. The injection from the multiple inverter-based ring oscillators 620 transforms the ring generator 610 into a true random number generator. Each of the multiple inverter-based ring oscillators 620 injects a logic value of 1 into the ring generator 610 at a frequency that depends on the integrated circuit manufacturing process and the number of inverting elements used. Therefore, the random characteristics present in the integrated circuit manufacturing process provide the required uncertainty (entropy) or randomness. In addition, since the clock of the ring generator 610 is essentially asynchronous with the state of each ring oscillator 620, many clock samples will also put pressure on the metastable region of the flip-flop of the ring generator 610 (due to setup time and hold time violations), thereby generating additional randomness.
[0047] The true random number generator 600 may also include a blocking circuit 630 configured to convert the ring generator 610 into a circular shift register by blocking injection from the plurality of inverter-based ring oscillators 620 and internal feedback in the ring generator 610 based on a blocking signal 645. The blocking signal 645 may be configured to change from unblocking to blocking when the contents of the ring generator 610 are ready to be sent out. Typically, the change occurs after a predetermined number of clock cycles specified by the counter 640. The counter 640 may be located inside or outside the controller. The contents of the ring generator 610 may be sent out via the serial output 660, the parallel output 650, or both.
[0048] Figure 6B Various embodiments according to the disclosed technology can be used to implement Figure 1 Another example of an on-chip random number generator 180 in the embodiment of the present invention is a true random number generator 605. The true random number generator 605 includes a ring generator 615 and an inverter-based ring oscillator 625. Both the ring generator 615 and the inverter-based ring oscillator 625 can be constructed using digital components. The inverter-based ring oscillator 625 is configured to inject bits into the ring generator 615 at multiple locations from the output of multiple selected inverting elements in the inverter-based ring oscillator 625.
[0049] The ring generator 615 can be formed by using a conventional ring generator (such as Figure 2A 28-bit ring generator 200 in ) or a dense ring generator (such as Figure 2BThe operating frequency of the inverter-based ring oscillator 625 depends on the circuit manufacturing process, the number of logic elements used, and the delay of its routing path. Sampling many inverters can fill relatively long time intervals with timing jitter, thereby maximizing the probability of capturing at least one noise signal edge in the ring generator 615. Therefore, the ring generator 615 can be used as a special form of bit extractor to process data collected at multiple stages of the inverter-based ring oscillator 625. In addition, because the clock of the ring generator 615 is inherently asynchronous with the state of the inverter-based ring oscillator 625, certain clock sampling may stress the metastable region of the ring generator flip-flop (due to setup and hold time violations), thereby generating additional uncertainty (entropy) or randomness.
[0050] Similar to the true random number generator 600, the true random number generator 605 can further include a blocking circuit 635 configured to convert the ring generator 615 into a circular shift register by blocking the injection from the inverter-based ring oscillator 625 and the internal feedback of the ring generator 615 based on the blocking signal 646. The counter 641 can provide the blocking signal 646. The counter 641 can be located inside or outside the controller. The content of the ring generator 615 can be sent out through the serial output 665, the parallel output 655, or both.
[0051] Figure 6C An example of a 32-bit true random number generator 670 based on a 32-bit ring generator 680 that can be implemented according to various embodiments of the disclosed technology is shown. In addition to the 32-bit ring generator 680, the 32-bit true random number generator 670 includes a 5-inverter ring oscillator 690. The outputs of the 5 inverting elements (4 inverters and 1 NAND gate) of the 5-inverter ring oscillator 690 can be respectively injected into the 32-bit ring generator 680 through XOR gates at 5 different positions. It should be noted that in some embodiments of the disclosed technology, not all outputs of the inverting elements are used to inject bits into the ring generator.
[0052] Figure 7 An example of a hash circuit 720 combined with a true random number generator 710 that can be implemented according to various embodiments of the disclosed technology is shown. The true random number generator 710 includes a ring generator 740, two inverter-based ring oscillators 730, a blocking circuit formed by 13 AND gates 735, and an OR gate 745 configured to control the serial output of the true random number generator 710. The ring generator 740 is a 28-bit dense ring generator similar to Figure 2BThe two inverter-based ring oscillators 730 may be implemented using two ring oscillators with different numbers of inverting elements (eg, a 3-inverter ring oscillator and a 5-inverter ring oscillator).
[0053] When the logic value of the blocking signal 725 is changed to zero, the AND gate 735 converts the ring generator 740 into a circular shift register by blocking both the injection from the inverter-based ring oscillator 730 and the internal feedback in the ring generator 740. Typically, the change occurs after a predetermined number of clock cycles that can be controlled by a counter (not shown in the figure). The blocking signal 735 can also control the serial output of the true random number generator 710 through the OR gate 745. The serial output can be used to form a one-time random number that is sent to a secure server outside the chip.
[0054] The hash circuit 720 includes a combinational circuit 750 and a ring generator 760. The combinational circuit 750 includes an AND gate, an OR gate, and an inverter, and has 13 inputs and 6 outputs. The combinational circuit 750 is configured to generate an intermediate hash value using bits output from the ring generator 740 after the blocking signal 735 converts the ring generator 740 into a circular shift register. The conversion spans several stages of the circular shift register. The final hash value is formed by the ring generator 760. As discussed previously, the secret key 765 is used to initialize the ring generator 760 before the actual hash clock cycle, and the ring generator 760 can then mutate the intermediate hash value based on the primitive feedback polynomial it employs. The hashing process performed in the ring generator 760 includes injecting a number of bits that are continuously available at the six outputs of the combinational circuit 750 and rotating the contents of the ring generator 760 multiple times. This can be controlled by a counter, which is not shown. Figure 7 The counter may be the same counter used to control the change of the blocking signal 725. It should be noted that in addition to the counter, there may be other control circuits, some of which may be placed between the true random number generator 710 and the hash circuit 720 and / or placed in each of the true random number generator 710 and the hash circuit 720.
[0055] Figure 8 An example of a hardware root of trust system 800 that can be implemented according to various embodiments of the disclosed technology is shown. The hardware root of trust system 800 includes components in a circuit 805 and a secure server 890. The components in the circuit 805 include a random number generator 810, a hash circuit 820, a retrieval circuit 830, and a controller 860. The components in the secure server 890 include a hash function unit 895 and a configuration mask unit 897.
[0056] The random number generator 810 may be prompted to generate a random number 815. For example, a request received by the circuit 805 to run a particular function may be set to result in such an action. The circuit 805 may then send a one-time random number 816 generated based on the random number 815 to the secure server 890. The one-time random number 816 may contain only the random number 815, or may also contain some separate data from the circuit 805, such as its electronic design identification code 814. According to various embodiments of the disclosed technology, the random number generator 810 may use Fig. 6A True random number generator in 600 or Figure 6B It is implemented by the true random number generator 605 in.
[0057] The hash circuit 820 includes a combination circuit 822 and a ring generator 826. Figure 1 Similar to the hash circuit 100 in FIG. 8 , the combination circuit 822 can convert the random number 815 into an intermediate hash value. Then, the ring generator 826 can convert the intermediate hash value into the hash value 825. The overall hash function of the hash circuit 820 is configured to simulate the same hash function used by the hash function unit 895 in the secure server 890.
[0058] The hash function unit 895 uses a hash function to calculate a hash value 896 of the received one-time random number 816. In normal operation, the hash value 896 should be the same as the hash value 825. The calculation may involve a secret key 893, which is used as an initial value for hashing the random number 815 contained in the one-time random number 816. The security server 890 may also include a design identification (DesignID) unit 892. The design identification unit 892 can verify the electronic design identification number 814 and retrieve the secret key 893 to be used by the hash function unit 895 based on the electronic design identification number. If the electronic design identification code 814 is invalid, the security server 890 can still generate a unique fake initial hash value and use it to confuse the resulting response. The security server 890 can also track the number of times each individual chip requests a response and monitor any abnormal behavior. The same (valid) secret key 827 can be saved in encrypted form by the circuit 805 and used by the hash circuit 820 in a manner similar to the way the hash function unit 895 uses the secret key 893.
[0059] The configuration mask unit 897 in the security server 890 can combine the hash value 896 with one or more configuration masks to generate a response 899. An example of a configuration mask is a configuration mask that can be used to descramble encrypted data into original data. Another example is a configuration mask that can be used to scramble original data into encrypted data. In various embodiments of the disclosed technology, the configuration mask unit 897 can perform a bitwise XOR operation that combines the bits of one or more configuration masks with the bits of the hash value 896. In addition to one or more configuration masks, other items can also be XORed with the hash value 896. Alternatively, some bits of the hash value 896 can also remain unchanged.
[0060] After circuit 805 receives response 899 from secure server 890, retrieval circuit 830 may retrieve one or more configuration masks 835 from response 899 using hash value 825 received from hash circuit 820. If one or more configuration masks 835 are XORed with hash value 896 in a bitwise operation of configuration mask cell 897 as described above, retrieval circuit 830 may use an XOR gate to perform a bitwise retrieval operation.
[0061] Circuit 805 may also include a descrambler 840, a scrambler 850, or both. Descrambler 840 may use one or more configuration masks 835 to retrieve the original data from the encrypted data received by circuit 805. For example, descrambler 840 may be configured to retrieve a compressed test vector from an encrypted compressed test vector received by circuit 805. Scrambler 850 may use another mask in one or more configuration masks 835 to encrypt data to be sent out by circuit 805. For example, scrambler 850 may be configured to encrypt a test response or a compressed test response before circuit 805 sends it out for analysis.
[0062] If both descrambler 840 and scrambler 850 are in circuit 805, an unauthorized access attempt may trigger a dual change in the internal functionality of the circuit. First, descrambler 840 and scrambler 850 are obfuscated due to the corruption of the configuration mask. Second, the remaining bits (obfuscation 870) of response 899 (if any) can be used to hide the design functionality from the adversary in the process of logical obfuscation. Logical obfuscation can result in signal corruption caused by activating certain components. Alternatively, any mismatch between certain bits of hash value 825 and hash value 896 can initiate a simple logical lockout scheme that prohibits access to the true functionality of circuit 805.
[0063] Fig. 9An example descrambler 900 that can be implemented according to various embodiments of the disclosed technology is shown. Descrambler 900 includes a 32-bit ring generator 910 and an XOR gate 920, and uses the Vernan stream cipher principle. The bits of the configuration mask 930 are injected into the 32-bit ring generator 910 through its feedback line. The XOR gate 920 retrieves the original data 940 from the encrypted data 950 using the pseudo-random sequence generated by the 32-bit ring generator 910. As previously discussed, the ring generator can operate at high speed, so that the descrambler based on the ring generator can work with other high-speed circuits in the circuit. Further, the modular and programmable feedback network properties of the ring generator allow various characteristic polynomials to be implemented. This in turn allows people to select a suitable secret configuration mask, which can correspond to the primitive polynomial according to other security requirements.
[0064] The scrambler can use the same principles as described above. The configuration mask for scrambling is injected into the ring generator in the same manner as the configuration mask 930. The bits of the data to be scrambled are XORed with the bits of the pseudo-random sequence generated by the ring generator. For scrambling, the positions of the encrypted data 950 and the original data 940 are switched.
[0065] When the response from the secure server does not match what is expected, the attempted unauthorized access is detected. This detection can result in an erroneous descrambling mask. An erroneous descrambling mask can trigger a unique feedback polynomial that will produce a pseudo-random sequence (not even necessarily its own maximum length) that effectively obfuscates the encrypted input data. The scrambler can obfuscate the output data following the same principle.
[0066] Please look back Figure 8 , the security components in circuit 805, such as random number generator 810, hash circuit 820 and / or retrieval circuit 830, can be controlled by controller 860. Controller 860 can be implemented using a simple finite state machine. As discussed above, random number generator 810 can use true random number generator 600 of FIG. 6 or Figure 6B 815. The ring generator 610 in the true random number generator 600 requires a preset number of clock cycles to be ready to output the random number 815. Similarly, the hash circuit 820 also requires at least a certain number of clock cycles sufficient to rotate the contents of the ring generator 826 multiple times before the hash value 825 can be finally determined and ready for subsequent applications. Therefore, the controller 860 may include a counter for determining the time required for the operation of the random number generator 810 and the hash circuit 820. In addition to the finite state machine and the counter, the controller 860 may also include other components for additional functions such as self-testing.
[0067] Fig.10 An example of a controller 1000 that can be implemented according to various embodiments of the disclosed technology is shown. The controller 1000 includes a control unit 1010, a counter 1020, a control decoder 1030, and a multiplexer 1040. As previously described, the control unit 1010 can be implemented using a finite state machine circuit (FSM). The counter 1030 can control the activity cycle of the random number generator and the hash circuit through output 1031 and output 1032, respectively. When the highest output bit of the counter 1030 changes from 0 to 1, the counter 1030 can also send a signal to the control unit 1010, which can be used to terminate the operation. The multiplexer 1040 and the control decoder 1030 can be used for self-testing. For example, the control decoder 1030 can be used to provide an excitation to test a ring oscillator in a true random number generator. The multiplexer 1040 can allow a sequence from the counter 1030 as a test excitation to test the following shift register: The shift register is typically used to store responses from a secure server.
[0068] Return to reference Figure 8 , the security server 890 can be implemented by one or more computing systems / devices. Therefore, one or more of the hash function unit 895, the configuration mask unit 897, and the design identification unit 892 can be implemented by executing programming instructions on one or more processors in one or more computing systems / devices. It should be understood that although the hash function unit 895, the configuration mask unit 897, and the design identification unit 892 are Figure 8 Although shown as separate units in the drawings, a single computing system / device may be used to implement some or all of these units at different times, or to implement components of these units at different times.
[0069] Various examples of the disclosed technology can be implemented by executing software instructions via a computing device (such as a programmable computer). Fig.11 An example of a computing device 1101 is shown. As shown, the computing device 1101 includes a computing unit 1103 having a processing unit 1105 and a system memory 1107. The processing unit 1105 can be any type of programmable electronic device for executing software instructions, but it will typically be a microprocessor. The system memory 1107 can include both a read-only memory (ROM) 1109 and a random access memory (RAM) 1111. It will be appreciated by those of ordinary skill in the art that both the read-only memory (ROM) 1109 and the random access memory (RAM) 1111 can store software instructions for execution by the processing unit 1105.
[0070] The processing unit 1105 and the system memory 1107 are directly or indirectly connected to one or more peripheral devices via the bus 1113 or an alternative communication structure. For example, the processing unit 1105 or the system memory 1107 may be directly or indirectly connected to one or more additional memory storage devices, such as a "hard disk" disk drive 1115, a removable disk drive 1117, an optical drive 1119, or a flash memory card 1121. The processing unit 1105 and the system memory 1107 may also be directly or indirectly connected to one or more input devices 1123 and one or more output devices 1125. For example, the input devices 1123 may include a keyboard, a pointing device (such as a mouse, a touchpad, a stylus, a trackball, or a joystick), a scanner, a camera, and a microphone. The output devices 1125 may include, for example, a display, a printer, and a speaker. In various examples of the computing device 1101, one or more peripheral devices 1115 to 1125 may be housed internally with the computing unit 1103. Alternatively, one or more peripheral devices 1115 - 1125 may be located external to the housing of computing device 1103 and connected to bus 1113 via a universal serial bus (USB) connection or the like.
[0071] In some embodiments, the computing unit 1103 may be directly or indirectly connected to one or more network interfaces 1127 for communicating with other devices that make up the network. The network interface 1127 converts data and control signals from the computing unit 1103 into network information according to one or more communication protocols, such as the Transmission Control Protocol (TCP) and the Internet Protocol (IP). In addition, the network interface 1127 may also be connected to the network using any suitable connection agent (or combination of agents), for example, including a wireless transceiver, a modem, or an Ethernet connection. These network interfaces and protocols are well known in the art and will not be discussed in detail herein.
[0072] It should be understood that computing device 1101 is described only as an example and is not intended to be limiting. Various embodiments of the disclosed technology may be implemented using one or more computing devices, including Fig.11 Components of computing device 1101 shown in, or only including Fig.11 A subset of the components shown in, or an alternative combination of components, including Fig.11 For example, various embodiments of the disclosed technology may be implemented using a multi-processor computer, multiple single-processor and / or multi-processor computers arranged in a network, or some combination of the two.
[0073] in conclusion
[0074] Having illustrated and described the principles of the disclosed technology, it will be apparent to those skilled in the art that the arrangements and details of the disclosed embodiments may be modified without departing from these principles. In view of the fact that the principles of the disclosed technology can be applied to many possible embodiments, it should be recognized that the embodiments shown are only preferred examples of the technology and should not be regarded as limitations on the scope of the disclosed technology. Instead, the scope of the disclosed technology is defined by the following claims and their equivalents. Therefore, we claim all that fall within the scope and spirit of these claims as our disclosed technology.
Claims
1. A circuit comprising: A hash circuit configured to simulate a hash function capable of converting a random number into a hash value, the hash circuit comprising: a combinatorial circuit comprising logic gates configured to function as non-linear Boolean operators, an input of the combinatorial circuit receiving bits of the random number; and A ring generator is configured to be initialized by a secret key and injected with bits from the output of the combinatorial circuit and output the hash value after a predetermined number of clock cycles.
2. The circuit according to claim 1, further comprising: A non-volatile storage device is configured to store the secret key.
3. The circuit according to claim 1, wherein: The combinatorial circuit is configured to receive a preset number of bits of the random number per clock cycle and continuously inject the bits into the ring generator over a plurality of clock cycles.
4. The circuit according to claim 1, further comprising: A random number generator is configured to generate the random number.
5. The circuit according to claim 4, wherein: The random number generator comprises: a ring generator; and One or more inverter-based ring oscillators configured to inject bits into the ring generator at a plurality of locations.
6. The circuit according to claim 5, wherein: The random number generator also includes: A blocking circuit is configured to convert the ring generator into a circular shift register by blocking both the injection from the one or more inverter-based ring oscillators and internal feedback in the ring generator based on a blocking signal.
7. The circuit according to claim 5, wherein: At least one of the one or more inverter-based ring oscillators is configured to inject bits from outputs of some or all inverting elements in the at least one of the one or more inverter-based ring oscillators.
8. The circuit according to claim 4, further comprising: a retrieval circuit configured to retrieve one or more configuration masks from a response signal received by the circuit using the hash value, The response signal is generated by a computing device based on a random number, and the generation of the response signal includes: generating the hash value of the random number, and combining the hash value with the one or more configuration masks.
9. The circuit according to claim 8, further comprising: A descrambler is configured to descramble a signal received by the circuit using a configuration mask from the one or more configuration masks.
10. The circuit according to claim 9, wherein: Descrambling the signal includes retrieving a compressed test vector from an encrypted compressed test vector received by the circuit.
11. The circuit of claim 8, further comprising: The scrambler is configured to scramble a signal to be transmitted by the circuit using a configuration mask in the one or more configuration masks.
12. The circuit of claim 8, further comprising: A controller configured to oversee an authentication process, the authentication process comprising: Generate the random number by the random number generator; converting the random number into the hash value by the hash circuit, and The one or more configuration masks are retrieved, by the retrieval circuit, from the response signal received by the circuit based on the hash value.
13. The circuit of claim 12, wherein: The controller includes a finite state machine.
14. One or more computer-readable media storing computer-executable instructions for causing a computer to perform a method comprising: In the circuit design, a circuit according to any one of claims 1 to 13 is created.