High-reliability key extraction method based on SRAM PUF

By filtering stable nodes in SRAM PUF and adopting lightweight error correction encoding algorithms, the problem of key instability of SRAM PUF under different conditions is solved, simplifying circuit design and improving stability.

CN120074813APending Publication Date: 2025-05-30CHENGDU SANLINGJIA MICRO-ELECTRONICS CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510193846.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing SRAM PUF-based key extraction method has instability under different temperature and voltage conditions, resulting in unstable keys and high complexity of error correction encoding circuits.

Method used

By introducing an automatic screening circuit in SRAM PUF, the power-up value of the stable node is filtered out, the key is generated using only the stable node, and a lightweight error correction encoding algorithm with two-stage cascade is used to simplify the circuit design.

Benefits of technology

The SRAM-PUF stability under different conditions is realized, the error correction capability requirements for the error correction circuit are reduced, the circuit structure is simplified, and the stability of the key generation circuit is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074813A_ABST
    Figure CN120074813A_ABST
Patent Text Reader

Abstract

The invention discloses a high-reliability key extraction method based on an SRAM PUF, and belongs to the technical field of cryptography and integrated circuit design, and the method comprises the steps: screening out a power-on value of a stable node from all nodes of an SRAM; acquiring a key and auxiliary data according to the power-on value of the stable node; and generating a key according to the power-on value of the stable node and the auxiliary data. According to the method, the stability of the SRAM-PUF can be ensured, and the coding and decoding circuit structure of the error correction code can be simplified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical fields of cryptography and integrated circuit design, and particularly relates to a highly reliable key extraction method based on SRAM PUF. Background Art

[0002] SRAM-PUF (Static Random Access Memory Physical Unclonable Function) has the following problems as a key generator: it is sensitive to the working environment, that is, for the same SRAM-PUF on the same chip, under different conditions such as temperature and voltage, there will be some differences in the initial power-on values, resulting in instability of the keys directly generated using the SRAM initial values.

[0003] Traditional SRAM PUF key extraction methods based on error correction coding mainly use the error correction ability of error correction codes to correct the differences between different PUF values. It is divided into a registration process and a reconstruction process. Refer to Figure 1 and Figure 2 , as Figure 1 shown is a schematic diagram of the registration process of the SRAM PUF key extraction method based on error correction coding, and as Figure 2 shown is a schematic diagram of the reconstruction process of the SRAM PUF key extraction method based on error correction coding. In the registration stage, the initial value of the PUF when powered on is XORed with the random number R1 and then subjected to a hash operation to generate the key key_gen. The random number R2 is first subjected to error correction coding and then XORed with the initial value of the PUF when powered on to obtain the auxiliary data W. The auxiliary data is usually stored in a non-volatile memory (such as flash) for restoring the PUF value when powered on again. In the reconstruction stage, the initial value y' when powered on is read from the same PUF, and y' and W are XORed to obtain C'. The difference between C' and C is the same as the difference between y and y'. C' is decoded to obtain R2'. If the error correction ability of the error correction code is greater than the number of differences between y and y', then R2' is equal to R2. R2' is encoded to obtain C'', C'' is XORed with W to obtain y'', and y'' is XORed with the random number R1 and then subjected to a hash operation to restore the key. Thus, it can be seen that when the error correction ability of the error correction code is greater than the number of changes in the SRAM initial power-on value, the key can be correctly reconstructed.

[0004] In order to correct multiple random errors, traditional SRAM PUF key extraction methods based on error correction coding usually select BCH codes, Golay codes, Reed-Muller codes, etc. as error correction codes. However, the encoding and decoding circuits of these error correction codes are relatively complex. Therefore, it is necessary to simplify the design of the error correction circuit without reducing the stability of SRAM-PUF. Summary of the Invention

[0005] The purpose of this application is to provide a highly reliable key extraction method based on SRAM PUF to overcome the defects of the prior art. An automatic screening circuit inside the chip is used to screen out unreliable nodes in the SRAM, and only the stable nodes of the SRAM are selected to generate keys, thereby reducing the requirement for the error correction ability of the fuzzy extractor. The fuzzy extraction algorithm adopts a two-stage cascaded lightweight error correction coding algorithm, which simplifies the circuit design and reduces the area and power consumption.

[0006] The purpose of this application is achieved through the following technical solutions:

[0007] A highly reliable key extraction method based on SRAM PUF, the method comprising:

[0008] Screen out the power-on values of stable nodes from all nodes of the SRAM;

[0009] Obtain the key and auxiliary data according to the power-on values of the stable nodes;

[0010] Generate the key with the power-on values of the stable nodes and the auxiliary data.

[0011] Further, the screening out the power-on values of stable nodes from all nodes of the SRAM includes:

[0012] Screen out unstable nodes from all nodes of the SRAM PUF, and sequentially store the position information of the unstable nodes in a non-volatile memory;

[0013] According to all the unstable node position information obtained from the non-volatile memory, discard the initial values of the unstable nodes to obtain the power-on values of the stable nodes.

[0014] Further, the obtaining the key and auxiliary data according to the power-on values of the stable nodes includes:

[0015] XOR the power-on values of the stable nodes with a first random number and then perform a hash operation to obtain the key, and at the same time XOR the power-on values of the stable nodes with an error correction code to obtain the auxiliary data.

[0016] Further, the SRAM operates in an independent power domain, and the SRAM is powered off and on separately. The method further includes:

[0017] When powering off, clamp the output of the SRAM to a low level for power-off isolation.

[0018] Further, by comparing the changes in the initial power-on values of the SRAM nodes multiple times, it is determined whether it is a stable node. If there is a change, it is determined as an unstable node.

[0019] Further, the coding method of the error correction code includes:

[0020] Intercept a second random number of a preset length of m bits from the random number generator;

[0021] Perform two-level concatenated repetition coding on the second random number;

[0022] The first-level coding includes:

[0023] According to the formula and H = [h 0 , h 1 ... h 2k+1 for transformation to obtain the first variable H, where R2 is the second random number, B n is a group of constants of length m bits, and different B n are uncorrelated, n = 1, 2,.. 2k + 1, represents the exclusive OR operation;

[0024] The second-level coding includes:

[0025] Perform (2t + 1, 1, t) repeated coding on the first variable to obtain the second variable C, where 2t + 1 is the number of repetitions and t is the number of correctable bits.

[0026] Furthermore, the decoding method of the error correction coding includes:

[0027] Perform the first-level decoding:

[0028] The data to be decoded is a third variable of the same length as the second variable. Decode every 2t + 1 bits of the third variable according to the formula H′(l) = sum(C′(l*(2t + 1)),... C′(l*(2t + 1)+2t)) ≥ (t + 1) to obtain a fourth variable of the same length as the first variable, where l = 0, 1,… m*(2k + 1)-1, H′ represents the fourth variable, C′ represents the third variable, and the x-th bit of C′ is denoted as C′(x);

[0029] Decode the fourth variable to obtain the third random number.

[0030] Furthermore, the decoding of the fourth variable specifically includes:

[0031] Group the fourth variable by m bits to obtain 2k + 1 fifth variables, and perform transformation according to the formula to obtain 2k + 1 sixth variables, where h′ n is the fifth variable and R2′ n is the sixth variable.

[0032] According to the formula R2′(x) = (sum(R2′ 1 (x), R2′2 (x)...R2′ 2k+1 (x))≥(k + 1)), for each bit of R2′ n make a decision to obtain the decoding result R2′, where the x-th bit of R2′ n is denoted as R2′ n (x), x = 0, 1,... m - 1.

[0033] The beneficial effects of this application are as follows:

[0034] This application combines the stable node screening method with the error - correcting coding of two - level repeated coding in cascade, which can not only ensure the stability of SRAM - PUF, but also simplify the circuit structure. The SRAM - PUF key generation circuit designed by the key extraction method based on SRAM PUF provided in this application has high stability. Brief Description of the Drawings

[0035] Figure 1 is a schematic diagram of the registration process of the SRAM PUF key extraction method based on error - correcting coding;

[0036] Figure 2 is a schematic diagram of the reconstruction process of the SRAM PUF key extraction method based on error - correcting coding;

[0037] Figure 3 is a schematic diagram of the registration process after unstable node screening in the embodiment of this application;

[0038] Figure 4 is a schematic diagram of the reconstruction process after unstable node screening in the embodiment of this application;

[0039] Figure 5 is a schematic diagram of SRAM power control in the embodiment of this application. Detailed Embodiments

[0040] The following uses specific specific examples to illustrate the implementation manners of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0041] Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this application.

[0042] To correct multiple random errors, SRAM PUF key extraction methods based on error correction coding usually select BCH codes, Golay codes, Reed-Muller codes, etc. as error correction codes. However, the encoding and decoding circuits of these error correction codes are relatively complex. Therefore, it is necessary to simplify the design of the error correction circuit without reducing the stability of the SRAM-PUF. By screening unreliable nodes in the storage cells of the SRAM-PUF and selecting reliable nodes to participate in the operation, the change in the power-on initial value of the SRAM-PUF under different conditions is reduced, which can lower the requirement for the error correction ability of the error correction circuit. However, traditional screening algorithms require external auxiliary circuits of the chip to complete the screening.

[0043] To solve the above technical problems, the following various embodiments of a highly reliable key extraction method based on SRAM PUF of the present application are proposed.

[0044] Embodiment 1

[0045] This embodiment provides a highly reliable key extraction method based on SRAM PUF. In this embodiment, by screening unreliable nodes in the storage cells of the SRAM-PUF and selecting reliable nodes to participate in the operation, the change in the power-on initial value of the SRAM-PUF under different conditions is reduced, thereby reducing the requirement for the error correction ability of the error correction circuit.

[0046] Refer to Figure 3 and Figure 4 As Figure 3 shown is a schematic diagram of the registration process after screening unstable nodes, and as Figure 4 shown is a schematic diagram of the reconstruction process after screening unstable nodes.

[0047] The screening algorithm is responsible for screening out unstable nodes from all nodes and storing their location information in the non-volatile memory in sequence. In the registration stage, according to all the unstable node location information X obtained from the non-volatile memory, the screening circuit discards the initial values of the unstable nodes to obtain the power-on values y 0 of the stable nodes. After XORing y 0 with R1 and performing a hash operation, the key can be obtained. At the same time, XORing y 0 with the error correction code C to obtain the auxiliary data W, which is stored in the non-volatile memory. Similarly, in the reconstruction stage, according to the unstable node location information X obtained from the non-volatile memory, the selection circuit discards the initial values of the unstable nodes to obtain the power-on values y 0 of the stable nodes, which are sent to the subsequent circuit to complete the reconstruction of the PUF value.

[0048] As an implementation, since traditional screening algorithms require external auxiliary circuits of the chip to complete screening, this embodiment proposes a single-chip screening method, in which the screening of stable nodes can be completed inside the chip. Refer to Figure 5 , as Figure 5 shown is the schematic diagram of SRAM power control in this embodiment.

[0049] The SRAM operates in an independent power domain, and power-on and power-off control of the SRAM can be performed separately. When powering off, in order to avoid the output signal of the SRAM affecting other circuits, the output of the SRAM is clamped to a certain fixed level through a power-off isolation unit. When powering off, first set the Iso_en signal to 1, so that the output of the SRAM will not affect the subsequent circuit, and then set the Pwr_en to 0, so that the power switch is disconnected and the SRAM is powered off. When powering on, first set the Pwr_en to 1, and the power supply VDD starts to supply power to the SRAM, and then set the Iso_en signal to 0, so that the output Q of the SRAM can be correctly reflected on the RDATA port.

[0050] The screening algorithm provided in this embodiment determines whether a node is a stable node by comparing the changes in the initial values of multiple power-on of the SRAM nodes. If a change occurs, it is determined as an unstable node, and the position of this point is stored in the flash. According to the tests in the experiment, when the number of reads is 100 or more, the average minimum entropy value of all nodes of the SRAM tends to be stable, that is, all unstable nodes can basically change once or multiple times. Therefore, this embodiment selects the number of reads as 100 times. If the real-time requirement for the screening algorithm in the application scenario is not high, this algorithm can be implemented by firmware.

[0051] As an implementation, in order to reduce the complexity of the error correction coding and decoding circuits in this embodiment, an error correction algorithm of two-stage cascaded repetition coding is proposed. Specifically, the process of the coding algorithm is described as follows:

[0052] Intercept a random number R2 with a length of m bits from the random number generator.

[0053] The first-stage coding algorithm: Transform R2 according to formula (1) to obtain a random variable H with a length of m*(2k + 1) bits. B n is a constant with a length of m bits, and different Bs n are not correlated with each other. Arrange [g 0 , h 1 ...h 2k+1 in a row to obtain a variable H with a length of m*(2k + 1) bits.

[0054]

[0055] Second-level encoding algorithm: Perform (2t + 1, 1, t) repeated encoding on H to obtain a variable C with a length of m * (2k + 1) * (2t + 1) bits, that is, repeat each bit of H 2t + 1 times. Each 2t + 1 bits of this encoding can correct t bit errors. When the number of error bits in 2t + 1 bits is greater than t, decoding errors will occur.

[0056] The process of the decoding algorithm is described as follows:

[0057] First-level decoding: Repeated encoding decoding algorithm. The input data of the decoder is a variable C' with a length of m * (2k + 1) * (2t + 1) bits. The x-th bit of C' is denoted as C'(x). Decode every 2t + 1 bits according to formula (2) to obtain a single-bit H'(n). After decoding C', a variable H' with a length of m * (2k + 1) bits is obtained.

[0058] H'(l) = sum(C'(l * (2t + 1)),... C'(l * (2t + 1) + 2t)) ≥ (t + 1),

[0059] where l = 0, 1,... m * (2k + 1) - 1 Formula (2)

[0060] Second-level decoding: Decode H' with a length of m * (2k + 1) bits to obtain m-bit information bits R2'. First, group H' by m bits to obtain 2k + 1 variables h n ', perform the transformation shown in formula (3) on h n ' to obtain 2k + 1 variables R2' n . Each R2' n is a variable with a length of m bits. The x-th bit of R2' n is denoted as R2' n (x). According to formula (4), make a decision on each bit of R2' n to obtain R2'. In summary, the computational complexity of the second-level decoding circuit is equivalent to that of a decoder for (2k + 1, 1, k) repeated encoding.

[0061]

[0062] R2'(x) = (sum(R2' 1 (x), R2' 2 (x)... R2' 2k+1 (x)) ≥ (k + 1)),

[0063] where x = 0, 1,... m - 1 Formula (4)

[0064] This embodiment combines the stable node screening method with the error correction coding of two - level repeated coding cascading, which can not only ensure the stability of the SRAM - PUF, but also simplify the circuit structure. Without reducing the stability of the SRAM - PUF, it simplifies the design of the error correction circuit. The SRAM - PUF key generation circuit designed by the method of this embodiment has high stability.

[0065] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A high-reliability key extraction method based on SRAM PUF, characterized in that: The method comprises: Filter out the power-on values ​​of stable nodes from all nodes of SRAM; Acquire a key and auxiliary data according to a power-on value of the stable node; A key is generated using the power-on value of the stable node and the auxiliary data.

2. The key extraction method based on SRAM PUF as claimed in claim 1, characterized in that: The step of selecting the power-on value of a stable node from all nodes of the SRAM includes: Screening out unstable nodes from all nodes of the SRAM PUF, and storing the position information of the unstable nodes in a non-volatile memory in sequence; According to all the unstable node position information obtained from the non-volatile memory, the initial values ​​of the unstable nodes are discarded to obtain the power-on values ​​of the stable nodes.

3. The key extraction method based on SRAM PUF as claimed in claim 1, characterized in that: The acquiring of the key and the auxiliary data according to the power-on value of the stable node comprises: The power-on value of the stable node is XORed with the first random number and then a hash operation is performed to obtain a key, and at the same time, the power-on value of the stable node is XORed with the error correction code to obtain auxiliary data.

4. The key extraction method based on SRAM PUF as claimed in claim 1, characterized in that: The SRAM operates in an independent power domain, and the SRAM is powered off and powered on separately. The method further includes: When power is lost, the output of the SRAM is clamped to a low level for power-off isolation.

5. The key extraction method based on SRAM PUF as claimed in claim 4, characterized in that: By comparing the changes in the initial values ​​of the SRAM nodes after multiple power-ons, it is determined whether it is a stable node. If a change occurs, it is determined to be an unstable node.

6. The key extraction method based on SRAM PUF as claimed in claim 3, characterized in that: The encoding method of the error correction coding comprises: Extract a second random number with a preset length of m bits from a random number generator; Performing two-stage cascade repeated encoding on the second random number; The first level of coding includes: According to the formula and H=[h0,h1...h 2k+1 ] to obtain the first variable H, where R2 is the second random number, B n is a constant of length m bits, different B n Unrelated to each other, n = 1, 2, .. 2k + 1, ⊕ represents XOR operation; The second level of coding includes: The first variable is repeatedly encoded with (2t+1,1,t) to obtain a second variable C, where 2t+1 is the number of repetitions and t is the number of correctable bits.

7. The key extraction method based on SRAM PUF as claimed in claim 6, characterized in that: The decoding method of the error correction coding comprises: Perform the first level of decoding: The data to be decoded is a third variable of the same length as the second variable, and every 2t+1 bits of the third variable are decoded according to the formula H′(l)=sum(C′(l*(2t+1)),...C′(l*(2t+1)+2t))≥(t+1) to obtain a fourth variable of the same length as the first variable, wherein l=0,1,…m*(2k+1)-1, H′ represents the fourth variable, C′ represents the third variable, and the xth bit of C′ is recorded as C′(x); The fourth variable is decoded to obtain a third random number.

8. The key extraction method based on SRAM PUF as claimed in claim 7, characterized in that: The decoding of the fourth variable specifically includes: Group the fourth variable by m bits to obtain 2k+1 fifth variables, according to the formula Transform to obtain 2k+1 sixth variables, among which h′ n is the fifth variable, R2′ n is the sixth variable. According to the formula R2′(x)=(sum(R2′1(x),R2′2(x)...R2′ 2k+1 (x))≥(k+1)), for R2′ n Each bit is judged to obtain the decoding result R2′, where R2′ n The xth bit of n (x), where x = 0, 1, ... m-1.