Hardware root of trust using configuration masks
By adopting a configuration mask-based solution in the hardware trust root and using a random number generator and hash circuit, the problem of difficult to weigh between security and testability of existing hardware trust roots is solved, and a lightweight, effective hardware trust roots are realized, reducing design complexity and area overhead.
Patent Information
- Application Number
- CN202280100849.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-08
- Publication Date
- 2025-05-16
AI Technical Summary
The existing hardware root of trust is difficult to trade off between meeting security needs and maintaining functionality and testability, and its complexity negatively affects area overhead and design processes, causing integrated circuit vendors to hesitate to adopt.
A hardware root of trust scheme based on configuration masks, including a random number generator, hash circuit and search circuit, is adopted to achieve a lightweight, non-invasive hardware root of trust by generating random numbers, calculating hash values and descrambling or scrambling signals using configuration masks.
A valid and lightweight hardware trust root is implemented, reducing security risks, design complexity and area overhead, while maintaining functionality and testability.
Smart Images

Figure CN120019614A_ABST
Abstract
Description
Technical Field
[0001] The technology disclosed in the present invention relates to the field of hardware security and trust. Various implementations of the disclosed technology are particularly useful for designing and using hardware trust roots to protect circuits from malicious activities and hacker attack attempts. Background Art
[0002] The huge cost of building and maintaining integrated circuit manufacturing has forced many semiconductor companies to move to a fabless model, outsourcing the expensive manufacturing process to foundries. The lack of reliable monitoring and trustworthiness of offshore manufacturing and testing processes increases security threats. Hardware security threats can take many forms, including intellectual property (IP) piracy, overproduction, counterfeiting, reverse engineering, and hardware Trojan insertion.
[0003] To reduce security risks, various defense schemes have been proposed, such as logic locking, circuit obfuscation, password-based authentication, challenge-response protocols, and data encryption. The foundation on which many secure operations of integrated circuits rely is often defined as a hardware root of trust (RoT). A hardware root of trust can perform specific, critical security functions. For example, high-end roots of trust are often integrated into silicon as separate, custom-designed security modules (protected from malware attacks) to handle chip and device identity, cryptographic keys and functions, secure boot processes, attestation, authentication, firmware updates, etc. As a security tool, a hardware root of trust should be able to detect intrusions, prohibit access pending further actions, and / or obfuscate (disguise) the logical operations of the integrated circuit. The selection of an adequate root of trust depends on many factors, such as the threat model, potential risk, desired level of protection, programmability, silicon overhead, impact on performance, or the complexity of encryption algorithms and ciphers.
[0004] Existing hardware roots of trust face many challenges. One challenge is the trade-off between meeting security requirements and maintaining functionality and testability. Another challenge is the complexity of several existing solutions and their impact on area overhead and design flow. These challenges can make IC vendors hesitant to adopt existing solutions. Therefore, an effective and non-intrusive lightweight hardware root of trust is highly desirable. Summary of the invention
[0005] Various aspects of the disclosed technology relate to a hardware root of trust scheme based on a configuration mask. In one aspect, there is a circuit comprising: a random number generator configured to generate a random number; a hash circuit configured to simulate a hash function that can convert the random number into a hash value; and a retrieval circuit configured to retrieve one or more configuration masks from a response signal received by the circuit using the hash value, wherein the response signal is generated by a computing device based on the random number, and the generation includes: generating the hash value of the random number and combining the hash value with the one or more configuration masks.
[0006] The circuit may further include: a controller configured to supervise an authentication process. The authentication process includes: generating the random number by the random number generator; converting the random number to the hash value by the hash circuit; and retrieving the one or more configuration masks from the response signal received by the circuit based on the hash value by the retrieval circuit. The controller may also be used to supervise a self-test process. The controller may include a finite state machine.
[0007] The circuit may also include: a descrambler configured to descramble a signal received by the circuit using a configuration mask in the one or more configuration masks. Descrambling the signal may include: retrieving a compressed test vector from an encrypted compressed test vector received by the circuit. The compressed test vector may be transmitted in the circuit via a data bus.
[0008] The circuit may further include a scrambler configured to scramble a signal transmitted by the circuit using a configuration mask of the one or more configuration masks. Scrambling the signal may include encrypting the compressed test response before being transmitted by the circuit.
[0009] The random number generator may include: a ring generator and one or more inverter-based ring oscillators, wherein the one or more inverter-based ring oscillators are configured to inject bits into the ring generator at multiple locations. At least one of the one or more inverter-based ring oscillators may be configured to inject bits from the output of some or all inverting elements (inverting devices) in at least one of the one or more inverter-based ring oscillators. If the one or more inverter-based ring oscillators have more than one inverter-based ring oscillator, the one or more inverter-based ring oscillators may have different numbers of inverting elements and may inject bits into the ring generator at different locations. The random number generator may also include: a blocking circuit configured to convert the ring generator into a circular shift register based on a blocking signal by blocking both the injection from the one or more inverter-based ring oscillators and the internal feedback in the ring generator.
[0010] The hash circuit may include: a combinatorial circuit including a non-linear Boolean operator composed of logic gates, the combinatorial circuit being configured to receive the random number; and a ring generator being configured to be initialized by a secret key and injected with bits from an output of the combinatorial circuit and to output the hash value after a predetermined number of clock cycles.
[0011] The retrieval circuit may include an XOR gate.
[0012] In another aspect, there are one or more non-transitory computer-readable media storing computer-executable instructions for causing one or more processors to perform a method comprising creating the above-described circuit in a circuit design.
[0013] Certain inventive aspects are set out in the accompanying independent and dependent claims. Where appropriate, features of the dependent claims may be combined with features of the independent claims and with features of other dependent claims and not merely as explicitly set out in a claim.
[0014] Certain objects and advantages of various inventive aspects have been described herein above. Of course, it should be understood that not all of these objects or advantages may be achieved according to any specific embodiment of the disclosed technology. Thus, for example, those skilled in the art will recognize that the disclosed technology may be embodied or performed in a manner that achieves or optimizes one advantage or a group of advantages taught herein without necessarily achieving other objects or advantages taught or implied herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1An example of a hardware root of trust system that may be implemented according to various embodiments of the disclosed technology is shown.
[0016] Figure 2A Various embodiments according to the disclosed technology can be used to implement Figure 1 An example of an on-chip random number generator in a true random number generator.
[0017] Figure 2B Various embodiments according to the disclosed technology can be used to implement Figure 1 An example of an on-chip random number generator in a true random number generator.
[0018] Figure 3A An example of a 28-bit ring generator implementing the primitive characteristic polynomial is shown.
[0019] Figure 3B An example of a 28-bit dense ring generator implementing the primitive characteristic polynomial is shown.
[0020] Figure 4A An example 28-bit true random number generator based on a 28-bit dense ring generator that can be implemented according to various embodiments of the disclosed technology is shown.
[0021] Figure 4B An example 32-bit true random number generator based on a 32-bit ring generator that can be implemented according to various embodiments of the disclosed technology is shown.
[0022] Figure 5 An example 28-bit true random number generator with built-in block circuitry that may be implemented in accordance with various embodiments of the disclosed technology is shown.
[0023] Figure 6 Various embodiments according to the disclosed technology can be used to implement Figure 1 An example of an on-chip hash circuit in FIG.
[0024] Figure 7 An example combination of a true random number generator and a hash circuit that may be implemented in accordance with various embodiments of the disclosed technology is shown.
[0025] Figure 8 An example descrambler that may be implemented according to various embodiments of the disclosed technology is shown.
[0026] Fig. 9 Various embodiments according to the disclosed technology can be used to implement Figure 1 An example of a controller in the .
[0027] Fig.10A flow chart is shown illustrating a process of generating and applying test vectors to test a circuit with a hardware root of trust that can be implemented according to various examples of the disclosed technology.
[0028] Fig.11 An example of a 6-core system-on-chip design that can be implemented according to various examples of the disclosed technology is shown, where a hardware root of trust ensures the security of the input and output of the stream scanning network.
[0029] Fig.12 An example of a programmable computer system that can be used with various embodiments of the disclosed technology is shown. DETAILED DESCRIPTION
[0030] Various aspects of the disclosed technology relate to a hardware root of trust solution based on a configuration mask. In the following description, many details are set forth for the purpose of explanation. However, one of ordinary skill in the art will appreciate that the disclosed technology can be implemented without using these specific details. In other cases, well-known features have not been described in detail to avoid obfuscating the disclosed technology.
[0031] Some of the techniques described herein may be implemented in software instructions stored on a computer-readable medium, software instructions executed on a computer, or some combination of the two. For example, some of the disclosed techniques may be implemented as part of an electronic design automation (EDA) tool. This method may be performed on a single computer or on a networked computer.
[0032] Although the operations of the disclosed methods are described in a particular order for ease of presentation, it should be understood that such description includes reordering unless specific language described below requires a particular ordering. For example, in some cases, operations described in order may be reordered or performed simultaneously. In addition, for the sake of simplicity, the disclosed flow charts and block diagrams generally do not show the various ways in which a particular method can be used in conjunction with other methods.
[0033] The detailed description of the method or device sometimes uses terms such as "configure", "generate" and "retrieve" to describe the disclosed method or device function / structure. These terms are high-level descriptions. The actual operations or functions / structures corresponding to these terms will vary depending on the specific implementation and are easily recognized by ordinary technicians in this field.
[0034] As used in this disclosure, the singular forms "a", "an", and "the" include the plural forms unless the context clearly dictates otherwise. In addition, the term "include" means "comprise". Furthermore, unless the context dictates otherwise, the term "couple" refers to an electrical or electromagnetic connection or link, and includes a direct connection or direct link as well as an indirect connection or indirect link through one or more intermediate elements that does not affect the intended operation of the circuit.
[0035] Additionally, as used herein, the term "design" is intended to encompass data that describes an entire integrated circuit device. However, the term is also intended to encompass smaller data sets that describe one or more components of the entire device (eg, a portion of an integrated circuit device).
[0036] As mentioned earlier, the hardware root of trust is the foundation on which the circuit security operation depends, including test-related operations. The complexity of traditional hardware root of trust solutions in terms of area overhead and impact on the design process has attracted the attention of potential users. Figure 1 An example of a hardware root of trust system 100 that can be implemented according to various embodiments of the disclosed technology is shown. The hardware root of trust system 100 includes components in both circuit 105 and secure server 190. The components in circuit 105 include random number generator 110, hash circuit 120, and retrieval circuit 130. The components in secure server 190 include hash function unit 195 and configuration mask unit 197.
[0037] A random number generator 110 in circuit 105 may be prompted to generate a random number 115. A request received by circuit 105 to run a particular function, for example, may be configured to cause such an action. Circuit 105 then sends a one-time random number (nonce) 116 (sometimes referred to as a challenge) formed based on random number 115 to secure server 190. One-time random number 116 may contain only random number 115, or may also contain some separate data from circuit 105, such as its electronic design identification number 114.
[0038] The hash circuit 120 in the circuit 105 is configured to emulate the same hash function employed by the hash function unit 195 in the secure server 190. Thus, the hash circuit 120 can convert the random number 115 into a hash value 125.
[0039] In the security server 190, the hash function unit 195 can use a hash function to calculate a hash value 196 for the received one-time random number 116. In normal operation, the hash value 196 should be the same as the hash value 125. The calculation may involve a secret key 193, which is used as an initial value for hashing the random number 115 included in the one-time random number 116. The security server 190 may also include a design identification (Design ID) unit 192. The design identification unit 192 is capable of verifying the electronic design identification number 114 and, based on the electronic design identification number 114, retrieving the secret key 193 to be used by the hash function unit 195.
[0040] If the electronic design identification number 114 is invalid, the security server 190 can still generate a unique pseudo initial hash value and use it to obfuscate the resulting response. The security server 190 can also track how many times each individual chip requests a response, thereby monitoring any abnormal behavior. The same (valid) secret key 127 can be saved in encrypted form by the circuit 105 and used by the hash circuit 120 in a manner similar to the way the hash function unit 195 uses the secret key 193.
[0041] A configuration mask unit 197 in the security server 190 may combine the hash value 196 with one or more configuration masks to generate a response 199. An example of a configuration mask is a configuration mask that may be used to descramble encrypted data into original data. Another example is a configuration mask that may be used to scramble original data into encrypted data. Through various implementations of the disclosed technology, the configuration mask unit 197 may perform a bitwise XOR operation to combine bits of one or more configuration masks with bits of the hash value 1096. In addition to one or more configuration masks, other items may also be XORed with the hash value 1096. Alternatively or additionally, some bits of the hash value may remain unchanged.
[0042] After circuit 105 receives response 199 from secure server 190, retrieval circuit 130 may use hash value 125 received from hash circuit 120 to retrieve one or more configuration masks 135 from response 199. If one or more configuration masks 135 are XORed with hash value 196 in a bitwise operation performed by configuration mask unit 197 as described above, retrieval circuit 130 may perform a bitwise retrieval operation using an XOR gate.
[0043] The circuit 105 may also include a descrambler 140, a scrambler 150, or both. The descrambler 140 may use one of the one or more configuration masks 135 to retrieve the original data from the encrypted data received by the circuit 105. For example, the descrambler 140 may be configured to retrieve the compressed test vector from the encrypted compressed test vector received by the circuit 105. The scrambler 150 may use another one of the one or more configuration masks 135 to encrypt the data to be sent out by the circuit 105. For example, the scrambler 150 may be configured to encrypt the test response or the compressed test response before the circuit 105 sends them for analysis.
[0044] If both the descrambler 140 and the scrambler 150 are in the circuit 105, an attempt to gain unauthorized access may trigger a double change in the circuit's internal functionality. First, the descrambler 140 and the scrambler 150 become obfuscated due to the corrupted configuration mask. Second, the remaining bits (obfuscation 170) of the response 199, if any, may be used to hide the design functionality from an adversary during a logic obfuscation process. The logic obfuscation may result in signal corruption caused by certain components being activated. Alternatively, any mismatch between some bits of the hash value 125 and the hash value 196 may initiate a simple logic lockout scheme, disabling access to the true functionality of the circuit 105.
[0045] The random number generator is one of the important hardware security primitives of the hardware root of trust. From a security perspective, the random numbers generated by the pseudo-random number generator are safe against some brute force attacks due to the large vector space (pattern space). However, the true random number generator can more effectively resist security risks because the pseudo-random number generator has a deterministic output vector, which is still vulnerable to cryptanalysis attacks. Figure 2A Various embodiments of the disclosed technology are shown for implementing Figure 1 An example of a true random number generator 200 of the on-chip random number generator 110 in FIG. The true random number generator 200 includes a ring generator 210 and a plurality of inverter-based ring oscillators 220. The ring generator 210 and the plurality of inverter-based ring oscillators 220 can both be constructed using digital components. Each of the plurality of inverter-based ring oscillators 220 is configured to inject bits into the ring generator 210 at a unique position. Through various embodiments of the disclosed technology, each of the plurality of inverter-based ring oscillators 220 may include a unique number of inverting elements (inverting devices). Examples of inverting elements are NOT gates and NAND gates.
[0046] The ring generator 210 can generate a pseudo-random number sequence by itself. The injection from the multiple inverter-based ring oscillators 220 converts the ring generator 210 into a true random number generator. Each of the multiple inverter-based ring oscillators 220 injects a logic value of 1 into the ring generator 210 at a frequency that depends on the integrated circuit manufacturing process and the number of inverting elements used. Therefore, the random characteristics present in the integrated circuit manufacturing process provide the required uncertainty (entropy) or randomness. Further, since the clock of the ring generator 210 is essentially asynchronous with the state of each ring oscillator 220, many clock samples can also put pressure on the metastable region of the flip-flop of the ring generator 210 (due to setup time and hold time violations), thereby generating additional randomness.
[0047] Figure 2B Various embodiments of the disclosed technology are shown that can be used to implement Figure 1 Another example of the on-chip random number generator 110 in the embodiment of the present invention is a true random number generator 205. The true random number generator 205 includes a ring generator 215 and an inverter-based ring oscillator 225. Both the ring generator 215 and the inverter-based ring oscillator 225 can be constructed using digital components. The inverter-based ring oscillator 225 is configured to inject bits into the ring generator 115 at multiple locations from the output of multiple inverting elements selected from the inverter-based ring oscillator 225.
[0048] The operating frequency of the inverter-based ring oscillator 225 depends on the circuit manufacturing process, the number of logic elements it deploys, and the delays of its routing paths. Sampling many inverters can fill relatively long intervals with timing jitter, thereby maximizing the probability of capturing at least one noise signal edge in the ring generator 215. Therefore, the ring generator 215 acts as a special form of bit extractor to process the data collected at several stages of the inverter-based ring oscillator 225. In addition, because the clock of the ring generator 115 is inherently asynchronous with the state of the inverter-based ring oscillator 125, some clock samples can stress the metastable region of the ring generator flip-flop (due to setup and hold time violations), thereby generating additional uncertainty (entropy) or randomness.
[0049] A ring generator is a linear finite state machine that can be derived by changing the canonical form (external feedback, internal feedback) of a linear feedback shift register while maintaining their transfer functions. An example of the change is the m-sequence-preserving transformation described in "Ring Generators—New Devices for Embedded Test Applications" (IEEE Trans. Computer-Aided Design, Vol. 23, No. 9, pp. 1306-1320, 2004) by G.Mrugalski, J.Rajski, and J.Tyszer. Like a linear feedback shift register, a ring generator can be used for various circuit test applications, such as pseudo-random test vector generation, on-chip test data decompression, test response compression, etc. It has been shown that, compared with conventional linear feedback shift registers and cellular automata, after applying the transformation to the linear feedback shift register in a certain order, the resulting ring generator has the characteristics of significantly reduced levels of XOR logic, minimized internal fan-out, and simplified circuit layout and routing. The ring generator thus has a highly modular structure and can operate at high speeds.
[0050] Figure 3A An example of a 28-bit ring generator 300 that implements a primitive characteristic polynomial 310 is shown. The 28-bit ring generator 300 includes 28 state elements 320 and 5 exclusive OR (XOR) gates 330. Each of the XOR gates 330 is located at a feedback position in the ring formed by the state elements 320, and one of the inputs of the XOR gate 330 is connected to a feedback tap via a feedback line. The state elements 320 can be implemented using flip-flops. As shown, the feedback logic of the 28-bit ring generator 300 has only one dual-input XOR gate per feedback line, so the logic level is 1, which is less than 2 for cellular automata and log of the external feedback form for linear feedback shift registers, respectively. 2 k (k is the number of XOR gates). Also as shown, the 28-bit ring generator 300 does not use the long feedback lines required by the internal feedback form of the linear feedback shift register. Therefore, the ring generator is faster than both the linear feedback shift register and the cellular automaton in both canonical forms.
[0051] Figure 3BAn example of a 28-bit dense ring generator 340 that implements a primitive characteristic polynomial 350 is shown. The 28-bit dense ring generator 340 includes 28 state elements 360 and 11 XOR gates 370. The large number of XOR gates 370 results in a dense characteristic polynomial 350 that has thirteen non-zero terms compared to the seven non-zero terms of the primitive characteristic polynomial 310. When used for test data decompression, the dense ring generator is able to drive a large number of scan chains by using outputs taken directly from feedback logic or phase shifters tapped locally from consecutive locations. This can allow the designer to minimize routing complexity, optimize wiring size, and make the overall layout compact. It should be noted that either a conventional ring generator (such as the 28-bit ring generator 300) or a dense ring generator (such as the 28-bit dense ring generator 340) can be used to implement Figure 2A The ring generator 210 and Figure 2B The ring generator 215 in.
[0052] Figure 4A An example 28-bit true random number generator 400 based on a 28-bit dense ring generator 410 that can be implemented according to various embodiments of the disclosed technology is shown. The 28-bit dense ring generator 410 is similar to Figure 3B The 28-bit dense ring generator 340 in FIG. 4 is the same as the 28-bit dense ring generator 340 in FIG. In addition to the 28-bit dense ring generator 410, the 28-bit true random number generator 400 includes a 3-inverter ring oscillator 420 and a 5-inverter ring oscillator 430. The 3-inverter ring oscillator 420 and the 5-inverter ring oscillator 430 can inject bits into the 28-bit dense ring generator 410 through XOR gates at two different locations, respectively. Different numbers of inverting elements can enhance the randomness of the sequence of generated random numbers. The input 425 for the 3-inverter ring oscillator 420 and the input 435 for the 5-inverter ring oscillator 430 can be used to apply test stimuli to test these ring oscillators.
[0053] Figure 4B An example of a 32-bit true random number generator 470 based on a 32-bit ring generator 480 that can be implemented according to various embodiments of the disclosed technology is shown. In addition to the 32-bit ring generator 480, the 32-bit true random number generator 470 includes a 5-inverter ring oscillator 490. The outputs of the 5 inverting elements (4 inverters and 1 NAND gate) of the 5-inverter ring oscillator 490 can be respectively injected into the 32-bit ring generator 480 through XOR gates at 5 different positions. It should be noted that in some embodiments of the disclosed technology, not all outputs of the inverting elements are used to inject bits into the ring generator.
[0054] Return to reference Figure 2A, the true random number generator 200 may also include a blocking circuit 230, which is configured to convert the ring generator 210 into a circular shift register by blocking both injection from the plurality of inverter-based ring oscillators 220 and internal feedback in the ring generator 210 based on a blocking signal 245. The blocking signal 245 may be configured to change from unblocking to blocking when the contents of the ring generator 210 are ready to be sent out. Typically, the change occurs after a predetermined number of clock cycles specified by the counter 240. The counter 240 may be internal or external to the controller. The contents of the ring generator 210 may be sent out via the serial output 260, the parallel output 250, or both.
[0055] Similar to the true random number generator 200, Figure 2B The true random number generator 205 in the controller may also include a blocking circuit 235 configured to convert the ring generator 215 into a circular shift register by blocking both injection from the inverter-based ring oscillator 225 and internal feedback in the ring generator 215 based on a blocking signal 246. The counter 141 may provide the blocking signal 246. The counter 241 may be internal or external to the controller. The contents of the ring generator 2615 may be sent out via the serial output 265, the parallel output 255, or both.
[0056] Figure 5 An example 28-bit true random number generator 500 with built-in block circuitry that can be implemented according to various embodiments of the disclosed technology is shown. Figure 4A 28-bit true random number generator 400, 28-bit true random number generator 500 includes 28-bit dense ring generator 510, 3-inverter ring oscillator 520 and 5-inverter ring oscillator 530. Further, 28-bit true random number generator 500 includes 11 AND gates 540 (one on each feedback line of 28-bit dense ring generator 510), 1 AND gate 550 (gating the output of 3-inverter ring oscillator 520) and 1 AND gate 560 (gating the output of 5-inverter ring oscillator 530). These AND gates 540, AND gates 550 and AND gates 560 constitute a block circuit and are controlled by a blocking signal 570. When the blocking signal 570 is "1", the 28-bit dense ring generator 510 operates as a ring generator and has injections from the 3-inverter ring oscillator 520 and the 5-inverter ring oscillator 530. When the blocking signal 570 changes to "0", the 28-bit dense ring generator 510 becomes a circular shift register, and its content can be shifted out through an OR gate 580. Some outputs of the state elements of the 28-bit dense ring generator 510 can be configured to be used as parallel outputs of the 28-bit true random number generator 500.
[0057] Another important hardware security primitive for hardware root of trust is a hash circuit. On-chip hash circuits are preferably easily designed, synthesized, and implemented using modern digital design blocks. Figure 6 Various embodiments according to the disclosed technology can be used to implement Figure 1 An example of a hash circuit 600 of the on-chip hash circuit 120 in FIG. The hash circuit 600 includes a combinatorial circuit 610 and a ring generator 620. The combinatorial circuit 610 includes logic gates and can be selected from a class of hash functions. Each member of the class includes a plurality of nonlinear Boolean operators and simple logic functions in their canonical form. The selection of a particular hash function can be determined based on the size of the random number 640 and the size of the ring generator 620. The combinatorial circuit 610 can convert the random number 640 into an intermediate hash value 650. The ring generator 620 is capable of mutating the intermediate hash value 650 and converting it into a hash value 660. During the hashing process, the ring generator 620 is first initialized by a secret key 670. The secret key 670 can be stored in a non-volatile on-chip tamper-proof memory in an encoded form. The secret key 670 can be serially uploaded to the ring generator 620 before the actual hash clock cycle. After initialization, the bits of the intermediate hash value 650 are injected into the ring generator 620 from the output of the combinatorial circuit 610. During the injection process, several bits of the intermediate hash value 650 are continuously available at the output of the combinational circuit 610. After a predetermined number of clock cycles (which is sufficient to rotate the contents of the ring generator 620 multiple times), the hash value 660 is finalized and ready for subsequent use. The ring generator 610 can be generated by using a conventional ring generator (such as Figure 3A 28-bit ring generator 300 in ) or a dense ring generator (such as Figure 3B This is achieved using the 28-bit dense ring generator 340 in FIG.
[0058] Figure 7 An example combination of a true random number generator 710 and a hash circuit 720 that can be implemented according to various embodiments of the disclosed technology is shown. The true random number generator 710 includes a ring generator 740, two inverter-based ring oscillators 730, a blocking circuit formed by 13 AND gates 735, and an OR gate 745 configured to control the serial output of the true random number generator 710. The ring generator 740 is a 28-bit dense ring generator similar to Figure 3B The two inverter-based ring oscillators 730 can be implemented by two ring oscillators with different numbers of inverting elements, such as Figure 5 A 3-inverter ring oscillator 520 and a 5-inverter ring oscillator 530 are shown.
[0059] When the logic value of the blocking signal 725 is changed to zero, the AND gate 735 converts the ring generator 740 into a circular shift register by blocking both the injection from the inverter-based ring oscillator 730 and the internal feedback in the ring generator 740. Typically, the change occurs after a predetermined number of clock cycles that can be controlled by a counter (not shown in the figure). The blocking signal 735 can also control the serial output of the true random number generator 710 through the OR gate 745. The serial output can be used to form a one-time random number that is sent to a secure server outside the chip.
[0060] The hash circuit 720 includes a combinational circuit 750 and a ring generator 760. The combinational circuit 750 includes an AND gate, an OR gate, and an inverter, and has 13 inputs and 6 outputs. The combinational circuit 750 is configured to generate an intermediate hash value using bits output from the ring generator 740 after the blocking signal 735 converts the ring generator 740 into a circular shift register. The conversion spans several stages of the circular shift register. The final hash value is formed by the ring generator 760. As discussed previously, the secret key 765 is used to initialize the ring generator 760 before the actual hash clock cycle, and the ring generator 760 can then mutate the intermediate hash value based on the primitive feedback polynomial it employs. The hashing process performed in the ring generator 760 includes injecting a number of bits that are continuously available at the six outputs of the combinational circuit 750 and rotating the contents of the ring generator 760 multiple times. This can be controlled by a counter, which is not shown. Figure 7 The counter may be the same counter used to control the change of the blocking signal 725. It should be noted that in addition to the counter, there may be other control circuits, some of which may be placed between the true random number generator 710 and the hash circuit 720 and / or placed in each of the true random number generator 710 and the hash circuit 720.
[0061] Figure 8An example descrambler 800 that can be implemented according to various embodiments of the disclosed technology is shown. The descrambler 800 includes a 32-bit ring generator 810 and an XOR gate 820, and uses the Vernan stream cipher principle. The bits of the configuration mask 830 are injected into the 32-bit ring generator 810 through its feedback line. The XOR gate 820 retrieves the original data 840 from the encrypted data 1150 using a pseudo-random sequence generated by the 32-bit ring generator 810. As previously discussed, the ring generator can operate at high speed, thereby enabling the descrambler based on the ring generator to work with other high-speed circuits in the circuit. Further, the modular and programmable feedback network properties of the ring generator allow a variety of characteristic polynomials to be implemented. This in turn allows people to select a suitable secret configuration mask, which can correspond to the primitive polynomial according to other security requirements.
[0062] The scrambler can use the same principles as described above. The configuration mask for scrambling is injected into the ring generator in the same manner as the configuration mask 830. The bits of the data to be scrambled are XORed with the bits of the pseudo-random sequence generated by the ring generator. For scrambling, the positions of the encrypted data 850 and the original data 840 are switched.
[0063] When the response from the secure server does not match what is expected, an attempted unauthorized access is detected. This detection can result in an erroneous descrambling mask. An erroneous descrambling mask can trigger a unique feedback polynomial that will produce a pseudo-random sequence (not even necessarily its own maximum length) that effectively obfuscates the encrypted input data. The scrambler can obfuscate the output data following the same principle.
[0064] Return to reference Figure 1 , the circuit 105 may also include a controller 160, which is configured to control security components in the circuit 105, such as the random number generator 110, the hash circuit 120 and / or the retrieval circuit 130. The controller 160 can be implemented using a simple finite state machine. As discussed above, the random number generator 110 may require a preset number of clock cycles before it is ready to output the random number 115. The hash circuit 120 may also require at least a certain number of clock cycles before the hash value 125 is finalized and ready for subsequent applications. Accordingly, the controller 160 may include a counter to determine the time required for the operation of the random number generator 110 and the hash circuit 120. In addition to the finite state machine and the counter, the controller 160 may also include other components for additional functions (e.g., self-testing).
[0065] Fig. 9 Various embodiments of the disclosed technology are shown for implementing Figure 1An example of a controller 900 of the controller 160 in FIG. Controller 900 includes a control unit 910, a counter 920, a control decoder 930, and a multiplexer 940. The control unit 910 can be implemented using a finite state machine circuit (FSM). Counter 930 can control the activity cycle of the random number generator and the hash circuit through output 931 and output 932, respectively. When the highest output bit of counter 930 changes from 0 to 1, counter 930 can also send a signal to control unit 910, which can be used to terminate the operation. Multiplexer 940 and control decoder 930 can be used for self-testing. For example, the control decoder 930 can be used to provide an excitation to test a ring oscillator in a true random number generator. Multiplexer 940 can allow a sequence from counter 930 to be used as a test excitation to test the following shift register: The shift register is typically used to store a response from a secure server.
[0066] Scan-based circuit testing is a type of structural testing that has been widely adopted. A major advantage of structural testing is that it enables test generation to focus on testing a limited number of relatively simple circuit elements, rather than having to deal with an exponentially increasing number of functional states and state transitions. Despite the availability of efficient automatic test vector generation (ATPG) and test design (DFT schemes), new test challenges continue to emerge. Unprecedentedly small technology nodes and corresponding new fault models have led to an explosive growth in test data. The test community has responded to these challenges by introducing test data compression. Test data compression can significantly reduce test costs and has a significant impact on the test environment. According to this model, the tester (usually automatic test equipment (ATE)) stores compressed test vectors and transmits them to an on-chip decompressor that drives the scan chain with actual test stimuli. Similarly, the test responses are moved out through the scan chain to the on-chip compressor and sent back to the tester for further processing. This approach reduces test application time, ATE memory, and I / O channels. To address the challenges associated with on-chip systems, various techniques for transmitting test data to circuit blocks over data buses have been recently developed. One example is Stream Scan Networking (SSN) technology, which enables high-speed data distribution and efficient processing of imbalances between consecutive circuit blocks.
[0067] Despite the groundbreaking significance of scan-based test solutions, the exact same schemes can provide unrestricted access to the internal state of the circuit under test, and therefore they can open a backdoor for serious security threats. Attackers can transfer corrupted data (controllability attacks) and transfer out confidential data (observability attacks). These so-called scan-based attacks may not be feasible if the switching between functional mode and test mode is disabled. However, tinkering with the test interface hinders more advanced operations, including debugging, post-firmware upgrade testing, diagnostics for field return (field return), or in-system and field test applications. With the advent of test compression, additional on-chip test infrastructure as well as encoded test data make circuits more resistant to scan attacks. Unfortunately, test compression facilities may not be as effective as expected against anti-scan-initiated attacks. The development of streaming scan networks can form another line of defense to protect complex designs from malicious activities and hacking attempts. Nevertheless, it is still necessary to apply access restrictions and protect the test infrastructure of the device under test to prevent any confidential information from being leaked when performing tests.
[0068] The disclosed techniques can be used to reduce security risks associated with testing infrastructure. Fig.10 A flowchart 1000 is shown, showing a process of generating and applying test vectors to test circuits with hardware trust roots that can be implemented according to various examples of the disclosed technology. In operation 1010, compressed test vectors are generated by one or more computing systems. Test vectors for scan testing are typically generated by an automatic test vector generation (ATPG) process. ATPG typically focuses on a set of faults derived from gate-level fault models. Defects are flaws or physical defects that occur in devices during the manufacturing process. A fault model (or simply a fault) is a description of how a defect changes the behavior of a design. For a given target fault, ATPG includes two stages: fault activation and fault propagation. Fault activation establishes a signal value at the fault site that is opposite to the signal value generated by the fault. Fault propagation propagates the fault effect forward by sensitizing the path from the fault site to the scan unit or the main output. If the test response value captured by the scan unit or the main output is different from the expected value, the test vector can be said to have detected the fault at the site.
[0069] The test vectors generated by the ATPG process can be compressed mainly because only 1% to 5% of the test vector bits are usually designated bits (care bits), while the rest are undesignated bits (don't-care bits). Undesignated bits can take any value that does not affect fault coverage. Test compression can also take advantage of the fact that test cubes tend to be highly correlated. Test cubes are deterministic test vectors that ATPG does not fill with don't care bits. This correlation exists because the faults in the circuit are structurally correlated. Various test compression techniques have been developed. Embedded Deterministic Testing (EDT) is an example test compression technique. EDT compression of test cubes is performed by treating external test data as Boolean variables. Conceptually, scan cells are filled with symbolic expressions that are linear functions of input variables injected into the decompressor. In the case of a decompressor including a ring generator and an associated phase shifter, a set of linear equations corresponding to the scan cells can be used, where the values of the scan cells are specified. By solving the system of equations, the compressed vector can be determined. Test vector generation and test vector compression can be performed sequentially by the same or different computing systems. Alternatively, both processes may be performed simultaneously. For example, when generating a test cube, it is determined whether the test cube is compressible or encodable.
[0070] In operation 1020, the compressed test vector is encrypted by a computing system using a configuration mask. The computing system may be the same or different than the system used in the previous operation. One method of encrypting the compressed test vector is to XOR the compressed test vector with the bits generated from the configuration mask in a bitwise operation. As previously described, according to Figure 8 A circuit fabricated using the principles of the descrambler 800 in FIG. 8 can be used to encrypt data using a configuration mask. A computing system in the present operation can simulate such operation of the circuit to generate an encrypted compressed test vector.
[0071] In operation 1030 , the encrypted compressed test vector is loaded into the circuit under test by a tester, such as automatic test equipment (ATE).
[0072] In operation 1040, a descrambler of the hardware root of trust of the circuit under test retrieves the compressed test vector from the encrypted compressed test vector using the configuration mask. The descrambler may use Figure 8 The configuration mask is encrypted in the response transmitted to the circuit under test by the security server. The security server can encrypt the configuration mask using a hash value. The hash value is generated by the security server in response to a one-time random number received from the circuit under test. After the response is transmitted to the circuit under test, the retrieval circuit of the hardware root of trust in the circuit under test retrieves the configuration mask from it. Figure 1The hardware root of trust system 100 in implements the entire hardware root of trust.
[0073] In operation 1050, the compressed test vector is decompressed into a test vector by a decompressor in the circuit under test. In an EDT-based compression scheme, the decompressor may include a ring generator and an associated phase shifter.
[0074] In operation 1060, the test vector is applied to the circuit through the scan chain. Operation 1050 and operation 1060 can be performed simultaneously. After the first compressed test vector is decompressed and shifted into the circuit, the second compressed test vector is loaded into the decompressor. After the scan chain captures the test response for the first decompressed test vector, the decompressed second test vector is shifted into the scan chain, while the test response is shifted out and the third compressed test vector is loaded into the decompressor. The above process continues until all test vectors are applied to the circuit under test.
[0075] As previously mentioned, data bus-based test data delivery, such as streaming scan networks, can be employed to cope with the enormous complexity of system-on-chips in an automated and scalable manner and to address various test issues in a hierarchical manner. In particular, streaming scan networks can address system-on-chip test issues, including the inability to drive an ever-increasing number of cores simultaneously due to the limited number of chip pins, different scan lengths, different number of vectors, or internal shift speed limitations that limit the ability to move data in and out of the chip at a high rate. In addition, streaming scan networks can facilitate balanced broadcasting of test data to the same cores without incurring test time inefficiencies, high planning efforts, and physical design / timing closure issues.
[0076] Although streaming scan networking solves many of the scan data distribution challenges in large SoCs or 3D designs, it can be vulnerable to certain types of attacks for the same or similar reasons as observed in traditional scan-based designs. Streaming scan networking technology can be secured by adding a die-centric hardware root of trust, protecting streaming scan network-based designs from unauthorized access and extended threats. Since streaming scan networking is compliant with IEEE Std1838’s flexible parallel port for 3D test access, the hardware root of trust can leverage its central DFT entry to protect a single top-level test access point shared by IEEE1687 (IJTAG) compliant IP blocks. In 3D integrated circuits, the hardware root of trust can be distributed to each silicon die or only to the master die.
[0077] Fig.11An example of a 6-core system-on-chip design 1100 that can be implemented according to various examples of the disclosed technology is shown, wherein a hardware root of trust 1130 ensures the security of the input and output of the stream scan network. The stream scan network includes a parallel data bus 1140 configured to transmit payload scan data and a single-bit IEEE 1687 IJTAG network 1150 for configuring the stream scan network nodes before applying the test vector. The stream scan network also includes a stream scan host (SSH) 1121 to 1126, one for each of the six cores 1101 to 1106 of the system-on-chip design 1100, thereby driving local scan resources to load and unload scan chains (or channels) using data transmitted on the parallel data bus 1140. For example, the stream scan host 1126 can be connected to the EDT logic 1127 interface.
[0078] Typically, each of the stream scan hosts 1121 to 1126 has two external ports for interfacing with the parallel data bus 1140 and the IEEE 1687 IJTAG network 1150, respectively. Through the IJTAG network 1150, each of the stream scan hosts 1121 to 1126 is preloaded with data about the active bus width, its position in the node series being driven, the number of shift cycles per scan vector, and other information required to track the flow operation. After this setup, the compressed test vectors can be applied as packet scan data streamed through the parallel data bus 1140 by the stream scan hosts 1121 to 1126. Each of the six stream scan hosts 1121 to 1126 can determine when it is necessary to (1) read scan data from the bus, (2) place scanned data on the bus, or (3) pass data to other nodes.
[0079] The hardware root of trust 1130 includes a descrambler 1131 and a scrambler 1132 mounted on the input of the flow scan network, respectively. Both devices can decrypt / encrypt the contents of the parallel data bus 1140 and the IJTAG network 1150. Therefore, they form an effective barrier that can obfuscate many control and data signals in combination with the root of trust controller and its access authentication mechanism, thereby preventing a wide range of attempts to destroy the design. In the event of unauthorized access, the random obfuscated test data generated by both the descrambler 1131 and the scrambler 1132 will cause the six-core system-on-chip design 1100 to enter an abnormal test mode. In this mode, the DFT logic architecture becomes completely unpredictable, causing the attacker to be confused or give false feedback. In addition, the same signal can trigger other internal on-chip mechanisms that do not allow normal IP behavior.
[0080] Various examples of the disclosed technology can be implemented by executing software instructions through a computing device (e.g., a programmable computer). Fig.12A schematic example of a computing device 1201 is shown. As shown in the figure, the computing device 1201 includes a computing unit 1203, which has a processing unit 1205 and a system memory 1207. The processing unit 1205 can be any type of programmable electronic device for executing software instructions, but it will typically be a microprocessor. The system memory 1207 can include both a read-only memory (ROM) 1209 and a random access memory (RAM) 1211. It will be understood by those of ordinary skill in the art that both the read-only memory (ROM) 1209 and the random access memory (RAM) 1211 can store software instructions for execution by the processing unit 1205.
[0081] The processing unit 1205 and the system memory 1207 are directly or indirectly connected to one or more peripheral devices via the bus 1213 or an alternative communication structure. For example, the processing unit 1205 or the system memory 1207 can be directly or indirectly connected to one or more additional memory storage devices, such as a "hard disk" disk drive 1215, a removable disk drive 1217, an optical drive 1219, or a flash memory card 1221. The processing unit 1205 and the system memory 1207 can also be directly or indirectly connected to one or more input devices 1223 and one or more output devices 1225. The input device 1223 can include, for example, a keyboard, a pointing device (such as a mouse, a touchpad, a stylus, a trackball, or a joystick), a scanner, a camera, and a microphone. The output device 1225 can include, for example, a monitor display, a printer, and a speaker. In various examples of the computing device 1101, one or more of the peripheral devices 1215 to 1225 can be housed internally with the computing unit 1203. Alternatively, one or more of the peripheral devices 1215 to 1225 may be located outside the housing of the computing unit 1203 and connected to the bus 1213 via, for example, a Universal Serial Bus (USB).
[0082] In some embodiments, the computing unit 1203 may be directly or indirectly connected to one or more network interfaces 1227 for communicating with other devices constituting the network. The network interface 1227 converts data and control signals from the computing unit 1203 into network messages according to one or more communication protocols, such as the Transmission Control Protocol (TCP) and the Internet Protocol (IP). In addition, the network interface 1227 may be connected to the network using any suitable connection agent (or combination of agents), for example, including a wireless transceiver, a modem, or an Ethernet connection. Such network interfaces and protocols are well known in the art and will not be discussed in detail herein.
[0083] It should be understood that computing device 1201 is illustrated as an example only and is not intended to be limiting. Fig.12 Various embodiments of the disclosed technology may be implemented using one or more computing devices of the components of the computing device 1201 shown in FIG. Fig.12 A subset of the components shown in, or an alternative combination of components, including Fig.12 For example, various embodiments of the disclosed technology may be implemented using a multi-processor computer, multiple single-processor and / or multi-processor computers arranged in a network, or some combination of the two.
[0084] in conclusion
[0085] Having illustrated and described the principles of the disclosed technology, it will be apparent to those skilled in the art that the disclosed embodiments may be modified in arrangement and detail without departing from these principles. In view of the many possible embodiments to which the principles of the disclosed technology may be applied, it should be recognized that the embodiments shown are merely preferred examples of the technology and should not be considered to limit the scope of the disclosed technology. Instead, the scope of the disclosed technology is defined by the following claims and their equivalents. Therefore, we claim all that fall within the scope and spirit of these claims as our disclosed technology.
Claims
1. A circuit comprising: a random number generator configured to generate random numbers; A hash circuit configured to simulate a hash function capable of converting the random number into a hash value; and a retrieval circuit configured to retrieve one or more configuration masks from a response signal received by the circuit using the hash value; The response signal is generated by a computing device based on the random number, and the generation includes: generating the hash value of the random number and combining the hash value with the one or more configuration masks.
2. The circuit according to claim 1, further comprising: A controller configured to oversee an authentication process, the authentication process comprising: The random number is generated by the random number generator; The hash circuit converts the random number into the hash value; The one or more configuration masks are retrieved by the retrieval circuit from the response signal received by the circuit based on the hash value.
3. The circuit according to claim 2, wherein: The controller is also configured to supervise a self-testing process.
4. The circuit according to claim 2, wherein: The controller includes a finite state machine.
5. The circuit according to claim 1, further comprising: A descrambler is configured to descramble a signal received by the circuit using a configuration mask of the one or more configuration masks.
6. The circuit according to claim 5, wherein: Descrambling the signal includes retrieving a compressed test vector from an encrypted compressed test vector received by the circuit.
7. The circuit according to claim 6, wherein: The compressed test vector is transmitted in the circuit via a data bus.
8. The circuit of claim 1 , further comprising: A scrambler is configured to scramble a signal transmitted from the circuit using a configuration mask of the one or more configuration masks.
9. The circuit according to claim 8, wherein Scrambling the signal includes encrypting the compressed test response before being transmitted by the circuit.
10. The circuit of claim 1, wherein: The random number generator comprises: Ring generator; and One or more inverter-based ring oscillators configured to inject bits into the ring generator at a plurality of locations.
11. The circuit according to claim 10, wherein: The random number generator also includes: A blocking circuit is configured to convert the ring generator into a circular shift register by blocking the injection from the one or more inverter-based ring oscillators and internal feedback in the ring generator based on a blocking signal.
12. The circuit according to claim 10, wherein: At least one of the one or more inverter-based ring oscillators is configured to inject bits from outputs of some or all inverting elements in the at least one of the one or more inverter-based ring oscillators.
13. The circuit according to claim 10, wherein: If the one or more inverter-based ring oscillators have more than one inverter-based ring oscillator, the one or more inverter-based ring oscillators have different numbers of inverting elements and inject bits into the ring generator at different positions.
14. The circuit of claim 1, wherein: The hash circuit comprises: a combinatorial circuit comprising a non-linear Boolean operator composed of logic gates, the combinatorial circuit being configured to receive the random number; and A ring generator is configured to be initialized by a secret key and injected with bits from the output of the combinatorial circuit and output the hash value after a predetermined number of clock cycles.
15. The circuit of claim 1, wherein: The retrieval circuit includes an XOR gate.
16. One or more computer-readable media storing computer-executable instructions for causing a computer to perform a method comprising: In the circuit design, a circuit according to any one of claims 1 to 15 is created.