Electronic device, random bit generation method and quantum random number generation method and device

By using optical quantum process generators in automotive systems and using SPAD diodes and optical fiber coupling to generate true random numbers, the problem of insufficient entropy characteristics in the prior art is solved, high security and efficient random number generation are achieved, and the system's anti-attack ability is enhanced.

CN120415698APending Publication Date: 2025-08-01ELMOS SEMICON AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510268062.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-10-06
Filing Date
2022-10-25
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The random number generator used in existing automotive systems lacks entropy characteristics, is difficult to integrate or has poor quantum yield, and is unable to effectively resist piracy and hacker attacks.

Method used

A generator based on optical quantum process is adopted, and the SPAD diode and optical fiber are used for optical coupling to generate true random numbers. Random numbers are generated by detecting the time interval of the photon emission signal, and combined with an error detection unit and a pseudo-random number generator, the reliability and security of the generator are ensured.

Benefits of technology

It improves the entropy characteristics and quantum yield of random number generation, enhances the system's security and resistance to quantum computer attacks, and effectively resists piracy and hacker attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415698A_ABST
    Figure CN120415698A_ABST
Patent Text Reader

Abstract

The invention relates to an electronic device, a random bit generation method and a quantum random number generation method and device. The electronic device comprises: a quantum random number generator (400), wherein the quantum random number generator comprises the following device components: a first SPAD diode (401.1); a second SPAD diode (401.3); an optical fiber (401.2) that optically couples the first SPAD diode (401.1) and the second SPAD diode (401.3) to each other; an amplifier (402) and / or a filter; an analog-to-digital converter (403); a comparator (404.2); a time-to-digital converter (404.3); an entropy extraction device (404.4) converts an output value of the time-to-digital converter (404.3) into a first value and a second value, and generates random bits therefrom.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the patent application with the application number 202280070549.0, the application date of October 25, 2022, and the invention name of "Automotive Processor Supporting PQK Encryption". Technical Field

[0002] The present invention relates to a microcontroller, which particularly includes at least one quantum process-based generator for true random numbers (Quantum Random Number Generator: QRNG) as a random number generator, particularly for encryption. Background Art

[0003] The automotive industry and other branch industries are increasingly subject to various piracy attacks. Counterfeiters copy components and products of relevant industrial manufacturers and usually use their brand names. Another critical point is hacking attacks, such as those affecting data transmission within or to and from products, such as in vehicle-to-vehicle or vehicle-to-x communication or data communication within vehicle components, which is particularly important in autonomous systems and in data communication with and from such autonomous systems to the outside in terms of preventing hacking attacks.

[0004] Most of the entropy characteristics of the random number generators currently used for data encryption in such systems are insufficient. Quantum process-based generators for true random numbers (Quantum Random Number Generator: QRNG) are known in the prior art, but they are difficult to integrate or have a poor quantum yield.

[0005] For example, the details of data and signal processing units using a microcontroller and a quantum process-based generator for generating random numbers are illustrated in the following documents:

[0006] - US - B - 10 802 800

[0007] - Session key. See: Wikipedia, the free encyclopedia. Edit status: October 1, 2020. URL: https: / / en.wikipedia.org / w / index.php?title=Session_key&

[0008] oldid=981281879 [Accessed on May 31, 2022];

[0009] - Integrated circuit. See: Wikipedia, the free encyclopedia. Edit status: October 12, 2021. URL: https: / / en.wikipedia.org / w / index.php?title=Integrated_circuit&

[0010] oldid=1049603915 [Accessed on May 31, 2022];

[0011] -BIOS. See: Wikipedia, the free encyclopedia. Edit status: October 24, 2021. URL: https: / / en.wikipedia.org / w / index.php?title=BIOS&oldid=1051566527 [Accessed on May 31, 2022];

[0012] -BURRI, S. [et al.]: SPADs for Quantum Random Number Generators and beyond. See: 19 th Asia and South Pacific Design Automation Conference (ASP-DAC), January 20 - 23, 2014, Singapore, IEEE, p. 788 - 794. DOI: 10.1109 / ASPDAC.2014.6742986;

[0013] -Fabio Acerbi, Nicola Massari, Leonardo Gasparini, Alessandro Tomasi, Nicola Zorzi, Giorgio Fontana, Lorenzo Pavesi, Alberto Gola in "Structures and Methods for fully-integrated Quantum Random Number Generators", IEEE Journal of selected topics in quantum electronics, Vol. 26, No. 3, May / June 2020. Summary of the Invention

[0014] The object of the present invention is to provide a device and method for generating true random numbers based on an optical quantum process.

[0015] Technical Solution

[0016] This object is achieved by a microcontroller for controlling a device in an automobile, wherein the microcontroller is provided with:

[0017] - a semiconductor substrate,

[0018] - a storage element,

[0019] - at least one internal bus,

[0020] - at least one microcontroller core,

[0021] - one or more data interfaces, and

[0022] - at least one quantum process-based generator for true random numbers,

[0023] - wherein the storage element is connected to the internal bus,

[0024] - wherein the data interface is connected to the internal bus,

[0025] - wherein the quantum process-based generator is connected to the internal bus, and

[0026] - wherein the microcontroller core is connected to the internal bus,

[0027] - wherein the quantum process-based generator generates random numbers especially upon request of the microcontroller core,

[0028] - wherein the quantum process-based generator provides the random numbers,

[0029] - wherein the microcontroller core uses a program from one or more of its storage elements and uses the random numbers to generate keys,

[0030] - wherein the microcontroller core uses a program from one or more of its storage elements and the keys to encrypt and decrypt data exchanged with external devices or internally via the data interface,

[0031] - wherein the semiconductor substrate integrally includes the sub-devices of the secure microcontroller listed herein,

[0032] - wherein the quantum process-based generator includes at least one first SPAD diode as a light source for optical quantum signals,

[0033] - wherein the quantum process-based generator includes at least one second SPAD diode as a photodetector for receiving the optical quantum signals,

[0034] - wherein the quantum process-based generator includes at least one processing circuit,

[0035] - wherein the quantum process-based generator includes at least one optical fiber for optically coupling the at least one first SPAD diode to the at least one second SPAD diode,

[0036] - wherein the quantum-based generator includes an operation circuit for supplying electrical energy for emitting light to the at least one first SPAD diode, and

[0037] - wherein the quantum-based generator includes processing circuitry for detecting signals from the at least one second SPAD diode and for forming a random number from the signals of the at least one second SPAD diode and for providing the random number to the microcontroller core.

[0038] One feature of the microcontroller crucial to the present invention is a quantum-process-based generator (quantum-process-based entropy source) for generating true random numbers. The generator is based on an optical quantum process, namely on a combination of excitation and self-emission of photons of at least one second or receiver SPAD diode, respectively. The receiver SPAD diode is coupled via an optical waveguide to at least one first or transmitter SPAD diode. Both SPAD diodes operate in Geiger mode.

[0039] The invention is characterized in that the optical fiber is formed as at least part or portion of one or more dielectric layers which, as insulating layers, are part of the metallization stack formed on the semiconductor material integrating the first and second SPAD diodes. Alternatively, the optical fiber may also couple two semiconductor substrates together, with at least one first and at least one second SPAD diode formed in each semiconductor substrate. However, the microcontroller with a semiconductor substrate is preferably designed such that all SPAD diodes are integrated into the semiconductor substrate and the optical fiber is arranged on the surface of the semiconductor substrate.

[0040] Due to the occurrence of spontaneous and excitation photon emissions from the second SPAD diode, its emission signal has extremely narrow pulses (hereinafter referred to as spikes) of different heights. Thus, the emission signal includes a first spike that occurs due to single-photon emission. A second spike in the emission signal of the second SPAD diode that is higher than the first spike appears when the self-emission of photons coincides with the excitation photon emission. The occurrence of this combined photon emission is highly random, i.e., quantum-process-based, which is why the evaluation of the time series of the occurrence of the second spike is now suitable for generating true random numbers therefrom.

[0041] In this regard, in an advantageous further development of the invention, it is provided that the emission signal of the at least one second SPAD diode has a first peak and a second peak that is greater than the first peak, wherein the first peak and the second peak are each greater than a definable reference value, wherein the first peak is generated by the self-emission of photons of the at least one second SPAD diode without simultaneously causing the emission of excitation photons of the at least one second SPAD diode, and the second peak is generated by the self-emission of photons of the at least one second SPAD diode excited by the photon reception of the at least one first SPAD diode occurring simultaneously, and the processing circuit of the quantum process-based generator generates a first logical value or a second logical value as a bit for generating the random number based on a comparison of the time interval of the second peak with a threshold or based on a mutual comparison of the time intervals of the second peak.

[0042] According to a variant of the invention, the true random number is generated such that the processing circuit generates the first logical value or the second logical value based on a comparison of the time interval between the two peaks with a threshold, and if the time interval is less than the threshold, the processing circuit outputs the first logical value as a bit of the random number, and if the time interval is greater than the threshold, the second logical value is output as a bit of the random number.

[0043] According to a second variant, the true random number is generated such that the processing circuit generates the first logical value or the second logical value based on a comparison of the time intervals of the second peaks in different pairs of second peaks, and if the time interval of the last-occurring second peak is less than, for example, the time interval between the penultimate second peak and the antepenultimate second peak or between other previous pairs of second peaks, the processing circuit outputs the first logical value as a bit for generating the random number, and if the time interval of the last-occurring second peak is greater than, for example, the time interval between the penultimate second peak and the antepenultimate second peak or between other previous pairs of second peaks, the second logical value is output as a bit for generating the random number.

[0044] For the above two variants of generating a true random number, the following applies: If equality is detected when comparing the time interval with a threshold (variant 1) or comparing them with each other (variant 2), the result is discarded for the random number. Alternatively, the equality comparison result can also be utilized, but this would have to be evaluated purely accidentally as the first logical value or the second logical value.

[0045] For completeness, it should also be mentioned that a third spike can also occur in the emission signal of the second or receiver SPAD diode, which is substantially three times the height of the first spike. Such an event occurs when the photon emission excited by the photons received by the first SPAD diode coincides with the self-emitted photon emission from the second SPAD diode, which in turn is excited. Advantageously, these "triple spikes" are not used. In this regard, when examining the emission signals of the second SPAD diodes, their signals are compared with a predetermined range of reference values within which the signals must lie in order to be evaluated for true random number generation.

[0046] If multiple pairs of first and second SPAD diodes are provided, it is advantageous to generate the individual bits of the true random number in parallel, where the emission signals of the second SPAD diodes can be fed to the processing circuit, and the processing circuit outputs different bits among the bits for generating the random number based on the emission signals of the second SPAD diodes.

[0047] A pair of first and second SPAD diodes is generally sufficient to sequentially generate the individual bits of the true random number, where the processing circuit sequentially outputs the logical values of the bits for generating the random number.

[0048] Another variant of the optical coupling of the first and second SPAD diodes can be seen in that a single first SPAD diode and multiple second SPAD diodes optically coupled to the single SPAD diode are provided, where the emission signals of the second SPAD diodes can be fed to the processing circuit, and the processing circuit outputs different bits among the bits for generating the random number based on the emission signals of the second SPAD diodes.

[0049] In order to be able to detect function errors and still generate random numbers even in the presence of errors, the error detection unit and the pseudo-random number generator can be set in an advantageous manner, where when the error detection unit detects an error in the function of the component of the quantum-based generator responsible for the photon-based process or an error in its processing circuit, the processing circuit of the quantum-based generator switches from outputting bits for generating the random number based on the emission signal of the at least one second SPAD diode to outputting the bits generated by the pseudo-random number generator for generating pseudo-random numbers. Here, it is desirable that when an error is detected, the error detection unit outputs an error signal that particularly indicates the type and / or cause of the error. The error detection unit advantageously not only identifies the presence of an error but also what type of error has occurred. The reaction of the quantum-based generator to such events depends on the application and may, for example, mean performing a self-test. However, preferably, in the case of a failure of the quantum-based generator, it is switched to the pseudo-random number generator, which generates pseudo-random numbers, for example, based on the last bits generated by the quantum-based generator before the error was detected.

[0050] Possible sources of error may be:

[0051] - Power supply voltage failures of the various components of the microcontroller,

[0052] - Error signal generation of the first and / or second SPAD diodes,

[0053] - Failures in the optical fiber and / or when coupling the first SPAD diode and / or the second SPAD diode to the optical fiber,

[0054] - Circuit failures in the analog and / or digital parts of the microcontroller and the quantum random number generator,

[0055] - Incorrect entropy of the provided random numbers, which can be done by tests as described in Chapters 8 and 9 of Random Number Generators–Principles and Practices by David Johnston, 2018, Walter De Gruyter GmbH, Berlin / Bonston, ISBN 978-1-5015-1530-2.

[0056] The above variant of the microcontroller with an error detection unit and a pseudo-random number generator can also be implemented using a microcontroller with a quantum-based generator other than the above generators. In this regard, independent protection requirements for the subject of this further development are proposed.

[0057] In an advantageous configuration of the present invention, it can be provided that the storage element includes one or more read / write memories RAM and / or one or more writable non-volatile memories, in particular EEPROM memories and / or flash memories and / or one-time programmable (OTP) memories, and / or one or more read-only memories and / or one or more non-volatile manufacturer memories, in particular one or more manufacturer ROMs, and / or one or more manufacturer EEPROMs and / or one or more manufacturer flash memories.

[0058] In a preferred configuration of the present invention, it can be provided that the manufacturer ROM includes boot software.

[0059] In another preferred configuration of the present invention, it can be provided that a manufacturer firewall is provided between the manufacturer memory and the internal bus.

[0060] In a preferred further development of the present invention, the microcontroller can be provided with:

[0061] - a basic clock generator,

[0062] - a clock generator circuit, and / or

[0063] - a reset circuit, and / or

[0064] - a power supply or Vcc circuit with a voltage regulator for providing the operating voltage, and / or

[0065] - a ground circuit, and / or

[0066] - an input / output circuit, and / or

[0067] - one or more processing modules,

[0068] - wherein the processing module communicates with the internal bus, and

[0069] - wherein the processing module includes one or more of the following modules:

[0070] - a CRC module (Cyclic Redundancy Check),

[0071] - a clock generator module,

[0072] - with a DES accelerator and / or an AES accelerator,

[0073] - one or more timer modules,

[0074] - a security monitoring and control circuit,

[0075] - a data interface, in particular a universal asynchronous receiver / transmitter.

[0076] In another advantageous configuration of the present invention, it may be provided that

[0077] - the semiconductor substrate includes a surface,

[0078] - the semiconductor substrate includes semiconductor material below its surface,

[0079] - the surface of the semiconductor substrate includes a metallization stack,

[0080] - the metallization stack includes an optically transparent and electrically insulating layer of a typical structure located on the surface of the semiconductor substrate,

[0081] - at least a portion of this transparent and electrically insulating layer forms the at least one optical fiber,

[0082] - the first SPAD diode emits photons from the semiconductor material of the semiconductor substrate into the optical fiber,

[0083] - the at least one optical fiber transports such photons to the second SPAD diode.

[0084] In an advantageous configuration of the present invention, it may be provided that the optical fiber irradiates the second SPAD diode such that light from inside the optical fiber re-enters the semiconductive material of the semiconductor substrate and hits the device components of the second SPAD diode there.

[0085] In another advantageous configuration of the present invention, it may be provided that

[0086] - at least one operating circuit supplies electrical energy to the at least one first SPAD diode at least temporarily,

[0087] - the at least one first SPAD diode feeds photons into the at least one optical fiber when supplied with sufficient electrical energy,

[0088] - the at least one optical fiber transports such photons to the second SPAD diode, and

[0089] - the at least one optical fiber emits such photons to the second SPAD diode.

[0090] In an advantageous configuration of the present invention, it may be provided that one data bus interface is a wired automotive data bus interface, or one or more of the plurality of data bus interfaces are wired automotive data bus interfaces.

[0091] In another advantageous configuration of the present invention, it may be provided that one or more wired automotive data bus interfaces are configured to:

[0092] - CAN data bus interface, and / or

[0093] - CAN FD data bus interface, and / or

[0094] - Flexray data bus interface, and / or

[0095] - PSI5 data bus interface, and / or

[0096] - DSI3 data bus interface, and / or

[0097] - LIN data bus interface, and / or

[0098] - Ethernet data bus interface, and / or

[0099] - MELIBUS data bus interface.

[0100] In a further preferred development of the invention, it can be provided that one data bus interface is a wireless data bus interface, or one or more of the data bus interfaces among the data interfaces are wireless data bus interfaces.

[0101] In another advantageous configuration of the invention, it can be provided that one or more wireless data bus interfaces are configured as:

[0102] - WLAN interface, and / or

[0103] - Mobile radio interface, and / or

[0104] - Bluetooth interface.

[0105] In a preferred configuration of the invention, it can be provided that one data bus interface is a wired data bus interface, or one or more of the data bus interfaces among the multiple data interfaces are wired data bus interfaces.

[0106] In another preferred configuration of the invention, it can be provided that one or more wired data bus interfaces are configured as:

[0107] - KNX data bus interface, and / or

[0108] - EIB data bus interface, and / or

[0109] - DALI data bus interface, and / or

[0110] - PROFIBUS data bus interface.

[0111] A significant advantage of the present invention is that the semiconductor material integrated with optically coupled SPAD diodes is not used to transmit photons, but rather one or more dielectric layers near the surface of the semiconductor material, i.e., the insulating layer of the metallization stack, are used for transmission. This greatly increases the "yield" of photons reaching the receiver SPAD diodes, which means that more events can be observed in the receiver SPAD in a shorter time, which in turn can be used to generate longer quantum-process-based random numbers in a very short time and generate multiple quantum-process-based random numbers in a very short time respectively. This increases the efficiency of generating quantum-process-based random numbers, which are also secure for so-called post-quantum cryptography (PQK) or quantum-computer-resistant cryptography. BRIEF DESCRIPTION OF THE DRAWINGS

[0112] The present invention will be described in more detail below by means of various exemplary embodiments and with reference to the drawings.

[0113] Figure 1 is a block diagram showing an example of the secure microcontroller 1.

[0114] Figure 2 A diagram showing an exemplary process of protecting a product by a first secure microcontroller (IC1) and by a second secure microcontroller (IC2) according to the present invention. Here, the first secure microcontroller (IC1) and the second secure microcontroller (IC2) exchange data encrypted preferably using one or more quantum-process-based generators 15 for true random numbers with each other.

[0115] Figure 3 Shows the integration of SPAD diodes in a semiconductor material.

[0116] Figure 4 and Figure 5 Shows the combination of a first SPAD diode and a second SPAD diode, both of which are integrated in a semiconductor material and optically coupled by an optical waveguide that is part of the metallization stack (i.e., part of the insulating layer of the metallization stack) applied to the semiconductor material.

[0117] Figure 6 Shows the combination of a quantum-based entropy source of at least one emitter SPAD diode and at least one receiver SPAD diode with an optical fiber that optically couples the at least one emitter SPAD diode and the at least one receiver SPAD diode and includes an evaluation and operation circuit.

[0118] Figure 7 Shows a layout similar to Figure 6 but with a monitoring circuit added.

[0119] Figure 8It is a flowchart showing an entropy extraction method according to an exemplary embodiment of the present invention.

[0120] Figure 9 It is a diagram showing a typical output signal of a receiver SPAD diode.

[0121] Figure 10 Schematically shows the respective method steps for generating quantum random numbers using a light quantum-based process according to the present invention. Detailed implementation

[0122] The drawings show, in an example and simplified manner, the main parts of the proposed device and method. For illustrative purposes, certain examples designed according to the teachings of the present invention will now be described with reference to the drawings.

[0123] The exemplary embodiments of the present invention in the following description and drawings are considered illustrative and are not considered to limit the specific examples or elements described. Multiple examples can be derived from the following description and / or drawings by deformation, combination, or change of certain elements. In addition, those skilled in the art can derive examples or elements not literally described from the specification and drawings.

[0124] The integrated circuit according to the present invention preferably includes a secure microcontroller 1, that is, a microcontroller that supports data security encryption. Figure 1An example of a security microcontroller 1 at the block diagram level is shown. For example, the security microcontroller 1 includes storage elements connected to an internal bus 2. For example, the storage elements may include one or more read / write memories RAM 3 and / or one or more writable non-volatile memories such as EEPROM memory 4 and / or flash memory 4 and / or OTP memory 4. In addition, the security microcontroller 1 preferably includes one or more non-volatile read-only memories 5 such as ROM. Additionally, the security microcontroller 1 preferably contains one or more non-volatile, writable and / or non-writable manufacturer memories 6, which typically include reference data that is important for potential subsequent research on the microcontroller or other electronic devices. In the case of a non-writable manufacturer memory 6, the manufacturer memory 6 may be a manufacturer ROM. Preferably, the manufacturer ROM 6 includes boot software. For example, the security microcontroller 1 includes one or more cryptographic accelerators 7, such as a DES accelerator and / or an AES accelerator 7, which accelerate cryptographic calculations and are connected to the internal bus 2. For example, preferably, at least one manufacturer firewall 8 is provided between the manufacturer memory 6 and the internal bus 2. The microcontroller core 16 accesses the memory via the data bus 2. For example, the security microcontroller 1 includes a processing module that communicates with the microcontroller core 16 via the internal bus 2. The processing module of the microcontroller 1 preferably includes at least one of the following modules: a CRC module (Cyclic Redundancy Check) 11, a clock generator module 12, one or more timer modules 13, a security monitoring and control circuit 14, one or more quantum process-based generators 15 for true random numbers (Quantum Random Number Generator: QRNG), an 8 / 16 / 32 / 64-bit microcontroller core 16, and one or more data interfaces 17, particularly one or more Universal Asynchronous Receivers / Transmitters (UARTs) to support high-speed serial data. Other circuit parts of the security microcontroller 1 include, for example, one or more basic clock generator circuits 21 (CLK) and / or one or more clock generator modules 12, a reset circuit 22, a power supply or Vcc circuit 23 having a voltage regulator that provides the operating voltage, a ground circuit 24, and an input / output circuit 25.

[0125] Preferably, the security microcontroller 1 is constructed such that it is capable of performing security authentication. Thus, in addition to the authentication code, the security microcontroller 1 also stores additional data, such as one or more lifetime and usage duration data and / or, for example, logistics data and / or, for example, commercial data and / or website and email addresses and / or image data, for the instruction set of the control unit of a motor vehicle with which the microcontroller core 16 communicates via the data interface. Additionally, the security microcontroller 1 may store other application data.

[0126] Preferably, the first integrated circuit includes, for example, a security microcontroller 1 that is constructed to facilitate the security authentication of the product.

[0127] Figure 2 Shows an example of a method for manufacturing a circuit of a product including a secure microcontroller 1 according to the present invention. For example, the method includes writing a product ID into a second integrated circuit of the product (block 250). The second integrated circuit preferably includes a second secure microcontroller 1 according to the present application. For example, the method includes writing an authentication code corresponding to the product ID into a memory of a first integrated circuit of the first secure microcontroller 1. The first integrated circuit of the product preferably further includes a secure microcontroller 1 according to the present application. For example, the method includes writing various product IDs and various corresponding authentication codes into memories of respective integrated circuits of respective secure microcontrollers 1. Various product IDs and various corresponding authentication codes may also be written into memories of corresponding integrated circuits of corresponding secure microcontrollers 1 of each product (block 221) such that each product has a unique product ID and a unique authentication code. For example, the latter step provides a secure and unique authentication code for each product.

[0128] For example, some of the features described in this specification can perform secure authentication of a circuit or product while being able to be integrated and manufactured cost-effectively. For example, the second integrated circuit is preferably configured such that it can perform secure authentication. In various examples, different host devices can authenticate the identity of a circuit or product, such as an automobile, a smart phone, a network server, any data processing device, etc. In one example, the interface between the host device and the circuit is established via a control computer of the automobile. In another example, the first integrated circuit of the circuit is configured to store additional data such as product-related codes, product setting information, etc. For example, only after a secure authentication is performed via the first integrated circuit can the host device access, modify, or process such additional data. For example, the first integrated circuit is configured to provide or enable access to the above additional data only after authentication. In one example, the product requires little or no adjustment for different motor vehicle series.

[0129] The internal data bus 2 (refer to Figure 1 ) may include multiple data buses 2 for multiple microcontroller cores 16 such that these microcontroller cores can access different sub-devices of the secure microcontroller 1 independently of each other with time delays and / or overlappingly or simultaneously. However, the secure microcontroller 1 typically includes only one internal data bus 2 and only one microcontroller core 16. Preferably, the microcontroller core 16 is an Advanced Risc Maschine (AMR) processor or the like. Preferably, it is an 8-bit or 16-bit or 32-bit or 64-bit microcontroller computer core.

[0130] Preferably, the secure microcontroller 1 includes one or more read / write memories RAM 3. This can be SRAM and / or MRAM and / or FRAMS, etc. They can also be dynamic read / write memories such as DRAM that must be read and rewritten at regular intervals during an update cycle. The secure microcontroller 1 according to the present invention can have access logic for periodically performing an update process in order to access its memory. However, DRAM usually opens opportunities for attacks and is generally a potential vulnerability. The microcontroller core 16 can preferably access the read / write memory RAM 3 through the internal data bus 2.

[0131] Preferably, the secure microcontroller 1 includes one or more writable and non-volatile memories 4. The microcontroller core 16 can preferably access these writable and non-volatile memories 4 via the internal data bus 2. For example, the non-volatile memory can include an EEPROM memory 4 or a flash memory 4 or an OTP memory 4. OTP stands for "one-time programmable".

[0132] One attack option can be to erase the non-volatile memory 4 by radiation, such as X-rays and / or ionizing radiation and / or heating of the storage cells. For this purpose, the secure microcontroller 1 preferably includes one or more security monitoring and control circuits 14 that monitor the data integrity of the storage cells of the erasable memory 4. Preferably, the storage cells have redundancy such that at least two parity bits are provided for a data word, the data word preferably being a data word with a length of 8 bits, i.e., one byte, and at least one parity bit must always have the content 1, while the other parity bit must always have the content 0. For example, the first parity bit can be the parity bit of the byte, and the second parity bit can be the inverted bit of the parity bit. If an attack such as ionizing radiation occurs now, the attack will reset the two parity bits to the same value. One or more security monitoring and control circuits 14 detect this deviation and prevent the secure microcontroller 1 from further accessing.

[0133] Preferably, each bit of the memory of the secure microcontroller 1 is designed twice such that each logical data bit is implemented as a pair of a first physical data bit having a first internal logical value and a second physical data bit having a second internal logical value. The second internal logical value is usually the logical inverse of the first internal logical value. One or more security monitoring and control circuits 14 preferably monitor that this is always the case. One or more security monitoring and control circuits 14 detect a deviation and, for example, preferably prevent the microcontroller core 16 from further executing a program or certain program parts and / or prevent access to data in the event of a deviation.

[0134] Preferably, the secure microcontroller 1 includes one or more reset circuits 22 (refer to Figure 1) If there are predefined or determinable reset conditions and / or combinations and / or time sequences of such reset conditions, the reset circuit 22 resets the safety microcontroller 1 and / or the sub-devices of the safety microcontroller 1 to a predefined state, respectively. For example, the condition may be a signaling of one or more safety monitoring and control circuits 14. The condition may also be a change in the potential and / or value of the operating voltage of the safety microcontroller. In addition, such a condition may affect the integrity of the housing of the safety microcontroller 1.

[0135] Preferably, the safety microcontroller 1 includes a detector for opening the housing of the safety microcontroller 1. For example, this may be a single wire that surrounds or covers the safety microcontroller 1, such as a textile network or fabric, or at least covers a part of the safety microcontroller 1. It may also be a network of wires that is specifically used to detect an attack and covers the safety microcontroller 1. For example, the safety microcontroller 1 may have a first input / output through which the safety microcontroller 1 can feed current into such a wire and draw the current again at a second input / output. For example, if the current is interrupted, this is a sign of an attack, which is detected by one or more safety monitoring and control circuits 14 and then the attack signal is sent to the microcontroller core 16 of the safety microcontroller 1 according to the present invention. For example, in such a case where a violation of the housing integrity is suspected, one or more of the one or more safety monitoring and control circuits 14 may prohibit write and / or read access to the memory content of the memory of the safety microcontroller 1, or erase the content or set the content to a predefined value, or overwrite them with meaningless data, or manipulate them in other ways. The memory of the safety microcontroller 1 preferably includes one or more non-volatile read-only memories 5 such as ROM, etc. The ROM 6 of the safety microcontroller preferably contains data and / or program instructions defined by the design.

[0136] Preferably, the safety microcontroller 1 (for example, with reference to Figure 1) includes one or more non-volatile, writable and / or non-writable manufacturer memories 6 in which a semiconductor manufacturer or other supplier can store production and security data such as serial numbers. Preferably, the semiconductor manufacturer blocks access to the writable and / or non-writable non-volatile manufacturer memory 6 after the final production test has been performed. Preferably, access to the writable and / or non-writable manufacturer memory 6 can be obtained through a manufacturer password. In some cases, a dual-key procedure makes sense. In this case, the customer (downstream of the semiconductor manufacturer) stores a customer password in a customer lock register which can also be locked against access using a password. Preferably, the semiconductor manufacturer uses the customer password and the manufacturer password to access all storage areas of the secure microcontroller 1. Preferably, the semiconductor manufacturer provides an analysis password by means of which the manufacturer can cause one or more of the one or more security monitoring and control circuits 14, usually with the help of the reset circuit 22, to erase the customer content and then make all storage areas of the secure microcontroller 1 accessible for error analysis. In the case of a non-writable manufacturer memory, the manufacturer memory 6 can, for example, be a manufacturer ROM, the content of which is determined, for example, during the manufacture of the semiconductor circuit of the secure microcontroller.

[0137] Secure microcontrollers are generally adapted to receive and / or transmit encrypted data and / or program code portions and / or instructions by means of encryption methods stored in their memories and executed by the microcontroller core 16. Some of these methods require considerable computing power. Therefore, it has proven useful for the microcontroller core 16 not to execute certain program portions of these encryption methods in the form of sub-steps of these encryption methods, but rather for one or more special hardware accelerators, preferably in the form of one or more cryptographic accelerators 7, to execute these program portions at an accelerated rate using specially synthesized hardware logic instead of the microcontroller core 16. For this purpose, for example, the secure microcontroller 1 preferably has a DES accelerator for the Data Encryption Standard (DES) algorithm and / or an AES accelerator 7 for executing the Advanced Encryption Standard (AES) algorithm. The microcontroller core 16 generally addresses these hardware accelerators 7 via an internal data bus 2. Preferably, the microcontroller core 16 has a redundant clock system in order to be able to recognize accesses to the clock system. One or more of the one or more security monitoring and control circuits 14 monitor the consistency of the logical content of the preferably multiple redundant clock systems and can thus detect attacks and errors. Preferably, one or more manufacturer memory firewalls 8 prevent the microcontroller core 16 and test logic of the secure microcontroller 1 from accessing the manufacturer memory. They can preferably be unlocked using the manufacturer password as described. Preferably, the number of error entries is very limited in order to minimize the probability of a successful attack.

[0138] Preferably, the secure microcontroller includes one or more CRC modules (Cyclic Redundancy Check) 11 to generate CRC data for serial data communication in the case of transmission on the one hand, and CRC data is used to detect faulty data transmission in most data protocols, and on the other hand, it is capable of verifying the correct reception of data messages during reception. Preferably, the secure microcontroller 1 includes one or more clock generator modules 12 (clock drivers, CLK) which generate one or more clocks for operating the circuits of the secure microcontroller. Preferably, one or more clock generator modules (clock drivers, CLK) generate 12 redundant clocks representing an attack on the clock system. Generally, the secure microcontroller 1 includes one or more timer modules 13 such as required for detecting timeouts. Preferably, the secure microcontroller 1 includes one or more watchdog timers for monitoring the execution of various program parts. The watchdog timer may be part of one or more security monitoring and control circuits 14.

[0139] According to the present invention (for example, with reference to Figure 1),The security microcontroller 1 includes at least one generator 15 based on quantum processes. Quantum-based processes have the advantage of being based on true coincidence. In the 1970s, the physicist Bell proved that the "hidden parameter" theory was wrong. This means that the randomness of quantum mechanical events has no hidden causes such as photon emission. For example, the microcontroller core 16 can be an 8-bit microcontroller core or a 16-bit microcontroller core or a 32-bit microcontroller core or a 64-bit microcontroller core or a 128-bit microcontroller core, etc. The security microcontroller 1 can include one or more 8 / 16 / 32 / 64 / 128-bit microcontroller cores 16, which can preferably access other sub-devices via one or more internal data buses 2. Preferably, the security microcontroller 1 includes one or more data interfaces 17. For example, such a data interface can be one or more universal asynchronous receivers / transmitters (UARTs) to support high-speed serial data. Preferably, the security microcontroller 1 includes one or more basic clock generators 21 (CLK), and each basic clock generator preferably provides a basic clock 12 to one or more clock generator modules (clock drivers, CLK). Preferably, the basic clock generator 21 (CLK) is an oscillator. Preferably, the security microcontroller 1 further includes one or more power supplies or Vcc circuits 23 with voltage regulators, and the voltage regulators provide the operating voltage for the security microcontroller 1. Preferably, the security microcontroller 1 further includes one or more ground circuits 24 (i.e., circuits inserted into the ground wire or "ground" circuits, which are a single line in the simplest case), which include, for example, reverse polarity protection and protection circuits to prevent the potential of the semiconductor substrate from being manipulated. For example, it is useful if one or more ground circuits 24 have reverse polarity protection. For example, it is useful if one or more ground circuits 24 and / or one or more power supplies or Vcc circuits 23 interact such that the modulation of the power consumption and / or internal resistance and / or voltage drop between the power supply voltage terminals of the security microcontroller does not allow any conclusions to be drawn about the operating process and / or state of the security microcontroller, at least temporarily.

[0140] To control other devices and / or communicate with other devices and / or monitor other devices, it is generally useful for the security microcontroller to have one or more input / output circuits 25, and the input / output circuits 25 are generally designed as digital inputs and / or digital outputs, which can preferably also exhibit a tri-state condition. The security microcontroller 1 can include an analog-to-digital converter, which allows the security microcontroller 1 to monitor internal analog values such as the operating voltage and external analog values. Possibly, the security microcontroller 1 can be provided with, for example, a driver stage for driving an actuator. The actuator can be a motor and / or other resistive and / or inductive and / or capacitive loads, etc. For example, such a driver stage can be a half-bridge and / or an H-bridge, etc. It is also conceivable that it can be a power current source, for example, for a lamp such as an LED.

[0141] Therefore, the present invention (e.g., with reference to Figure 1 ) proposes a safety microcontroller 1 for controlling devices in an automobile, which includes a semiconductor substrate. Preferably, the safety microcontroller 1 is manufactured using CMOS circuit technology or bipolar circuit technology or BiCMOS circuit technology. The safety microcontroller preferably includes a storage element, one or more internal data buses 2, one or more 8 / 16 / 32 / 64-bit microcontroller cores 16, one or more data interfaces, and one or more quantum process-based generators 15. The one or more quantum process-based generators 15 distinguish the safety microcontroller 1 proposed herein from the prior art, which is based on so-called true random number generators that exhibit poor von Neumann entropy of the generated random numbers, and accordingly, the random numbers are "less random".

[0142] The internal data bus 2 may include multiple data buses. The storage element of the safety microcontroller 1 is typically connected to the internal data bus 2. The data interfaces are also typically connected to the internal data bus 2. One or more quantum process-based generators 15 are preferably also connected to the internal data bus 2. One or more microcontroller cores 16 are preferably also connected to the internal data bus 2. One or more quantum process-based generators 15 preferably and typically generate one or more random numbers upon request of the microcontroller cores 16. These generators are characterized by particularly favorable entropy compared to the random numbers of the prior art true random number generators. Preferably, one or more microcontroller cores 16 use the corresponding programs from one or more of their storage elements and use one or more of the generated random numbers to generate one or more keys. Typically, one or more microcontroller cores 16 encrypt and / or decrypt data, and the microcontroller cores 16 typically use the corresponding programs respectively from one or more of their storage elements of the corresponding microcontroller cores 16 and use the corresponding keys from among the possible multiple keys to exchange the data with devices external to the safety microcontroller via one or more data interfaces. Typically, the semiconductor substrate substantially integrally includes all the sub-devices of the safety microcontroller 1. <s

[0143] In a first further development of the safety microcontroller 1 (with reference to Figure 1 ), the storage element of the safety microcontroller 1 includes one or more read / write memories RAM 3 and / or one or more writable non-volatile memories 4, particularly EEPROM memories 4, and / or flash memories 4 and / or OTP memories 4 and / or one or more read-only memories and / or one or more non-volatile manufacturer memories. For example, one or more manufacturer memories may include one or more manufacturer ROMs 6 and / or one or more manufacturer EEPROMs and / or one or more manufacturer flash memories.

[0144] In a second further development, the manufacturer memory, in particular the manufacturer ROM 6, includes boot software for securely starting the secure microcontroller.

[0145] In a third further development (refer to Figure 1 ), the secure microcontroller 1 includes a manufacturer memory firewall 8 between the manufacturer memory 6 and the internal bus 2, which prevents access to the manufacturer memory without authentication.

[0146] In a fourth further development (refer to Figure 1 ), the secure microcontroller 1 includes one or more of the following components: a basic clock generator 21 (CLK), a clock generator circuit 12, a reset circuit 22, a power supply or Vcc circuit 23 having a voltage regulator for providing an operating voltage, a ground circuit 24, an input / output circuit 25, and one or more processing modules. The processing modules communicate with the internal data bus 2 and thus typically with the microcontroller core 16. The processing modules preferably include one or more of the following components: a CRC module (Cyclic Redundancy Check) 11, a clock generator module 12, an encryption accelerator, in particular a DES accelerator and / or an AES accelerator 7, one or more timer modules 13, one or more security monitoring and control circuits 14, one or more data interfaces, in particular one or more Universal Asynchronous Receivers / Transmitters (UARTs) 17 (refer to Figure 1 ).

[0147] In a fourth further development of the secure microcontroller 1 (refer to Figure 4 and Figure 5 ), the secure microcontroller 1 includes at least one first SPAD diode 44 and at least one second SPDAD diode 45, at least one optical fiber 50, at least one processing circuit, and at least one operating circuit. The circuit integration of the SPAD diodes (e.g., the SPAD diode 44 or 45) is again as Figure 3 shown. In a fourth further development according to Figure 4 , a generator 15 based on a quantum process (refer to Figure 1)It includes at least a first SPAD diode 44 as a light quantum signal source and a second SPAD diode 45 as a photodetector of the light quantum signal. In addition, in the fourth further development, the generator 15 based on the quantum process includes at least a processing circuit and an optical fiber 50. In the fourth further development, at least one optical fiber 50 generally optically couples at least one first SPAD diode 44 with at least one second SPAD diode 45. A working voltage supplies electrical energy to the first SPAD diode 44 such that the first SPAD diode 44 emits photons. This is the case when the first SPAD diode 44 has a sufficient electrical bias voltage. In the fourth further development, the processing circuit detects the (output) signal of the second SPAD diode 45 and thereby forms a random number.

[0148] However, in Figure 4 the exemplary embodiment of, it is assumed that the optical fiber 50 is formed by an electrically insulating layer applied on the surface 46 of the semiconductor substrate, Figure 5 An exemplary embodiment is shown in which, for example, two optically transparent and electrically insulating insulating layers 34', 34” form the optical fiber 50.

[0149] Then, the processing circuit preferably provides the thus formed random number to one or more of one or more microcontroller cores 16 via an internal data bus 2 ( Figure 1 ). The construction of the processing circuit will be discussed below in conjunction with Figures 6 to 9 .

[0150] In the sixth further development of the present invention (refer to Figure 4 and Figure 5 ), the semiconductor substrate includes a surface 46. Generally, the semiconductor substrate includes semiconductor material below its surface 46. In particular, when using conventional manufacturing processes for semiconductor circuits, such as CMOS processes, bipolar processes, and BiCMOS processes, there is usually a metallization stack of structured metal layers on the surface 46 of the semiconductor substrate, and the metal layers have electrically insulating insulating layers thereon, where at least one of the insulating layers 34 at least partially or partly forms the optical fiber 50. The structured metal layers generally form conductive paths electrically separated from each other by the insulating layers. Thus, the metallization stack includes, for example, an optically transparent and electrically insulating layer 34 of a typical structure of silicon oxide located on the surface 46 of the semiconductor substrate. Preferably, at least a part of the insulating layer 34 on the surface 46 of the semiconductor substrate (i.e., a part of the insulating layer extending laterally and / or vertically) forms the optical fiber 50. In Figure 4 and Figure 5Schematically shown above the insulating layer 34 is a part of the metallization stack. The first SPAD diode 44 generally emits light 47 of the semiconductor material from the semiconductor substrate into the optical fiber 50. This means that, compared with the prior art, the first SPAD diode 44 generally irradiates upward perpendicular to the surface 46, rather than laterally irradiating the semiconductor substrate with high attenuation. This allows the device to directly couple more photons of the first SPAD diode 44 to the second SPAD diode 45. The optical fiber 50 transmits the photons 48 of the first SPAD diode 44 in the optical fiber 50 to the second SPAD diode 45 with little loss compared with the prior art. The lowest layer of the metallization stack 43 is used to reflect light (photons). The optical fiber 50 irradiates the second SPAD diode 45 with the photons 48 of the first SPAD diode 44, so that the light 49 inside the optical fiber 50 re-enters the semiconductor material of the semiconductor substrate from the surface 46 and hits the device components of the second SPAD diode 44 there. Then, the second SPAD diode 45 generates an output signal according to the irradiation of the photons 48 (of the light 49), thereby generating a random number based on a quantum process, which will be further described below.

[0151] Generally, at least one operation circuit supplies electrical energy to at least one first SPAD diode 44 at least temporarily. When sufficient electrical energy is supplied, at least one first SPAD diode 44 then feeds photons 47 into at least one optical fiber 50. Then, the optical fiber 50 further transmits the photons 48. Then, at least one optical fiber 50 irradiates the photons 48 into the second SPAD diode 45 substantially "from above" as photons 49. Since this transmission of photons from the first SPAD diode 44 to the second SPAD diode 45 loses significantly fewer photons than the prior art structure using a strongly absorbing semiconductor substrate due to the low attenuation in the optical fiber 50, the quantum efficiency is much higher. Therefore, in the structure proposed herein, a pair of a single first SPAD diode 44 and a single second SPAD diode 45 is sufficient (nevertheless, multiple pairs of SPAD diodes can also be used according to the present invention). The prior art always uses several SPAD diodes on both the emitter and receiver sides.

[0152] Figure 5Two or more dielectric layers (i.e., optically transparent insulating layers 34', 34") that are directly adjacent to each other in at least some regions (i.e., in these regions, there is no metallization layer separating them) form the optical fiber 50'. In the present exemplary embodiment, the contacts 51 and 52 of the SPAD diodes 44 and 45 are positioned such that they are arranged in pairs on both sides of the central region of the optical fiber 50', so that the optical fiber transmits the photons 47 of the SPAD diodes in this part of the insulating layers 34', 34" that are adjacent to each other at the plane 53, as shown at 48, not necessarily only in the upper part of the two insulating layers 34', 34", but also through both of them until they meet the SPAD diode 45 at 49. The contacts 51, 52 are also advantageously used to reflect photons and thus "introduce" the photons into the SPAD diode 45. In this regard, the contacts 51, 52 of the SPAD diode 44 are also used to reflect and "redirect" the photons 47 emerging from the SPAD diode 44 in the direction of the SPAD diode 45.

[0153] In a further development of the safety microcontroller 1 according to the present invention, at least one of the one or more data interfaces is a wired automotive data bus interface. In this case, the wired automotive data bus interface can be, for example, a CAN data bus interface or a CAN FD data bus interface or a Flexray data bus interface or a PSI5 data bus interface or a DSI3 data bus interface or a LIN data bus interface or an Ethernet data bus interface or a MELIBUS data bus interface.

[0154] In a further development of the safety microcontroller 1 according to the present invention, at least one data interface is a wireless data bus interface. For example, the wireless data bus interface can be a WLAN interface or a Bluetooth interface.

[0155] In a further development of the safety microcontroller 1 according to the present invention, at least one data interface is a wired data bus interface. For example, the wireless data bus interface can be a KNX data bus interface or an EIB data bus interface or a DALI data bus interface or a PROFIBUS data bus interface.

[0156] Figure 6 A simplified block diagram of a quantum-based random number generator QRNG 400 according to an exemplary embodiment of the present invention is schematically shown. Preferably, Figure 6 The digital circuits of the exemplary device shown are clocked with a preferably universal clock. The structure includes an entropy source 401 based on a quantum process, a preferably broadband radio frequency amplifier 402, an analog-to-digital converter 403 having, for example, a 14-bit resolution and a sampling rate of, for example, 125 MS / s, and a field programmable gate array (FPGA) 404.

[0157] The entropy source 401 includes a 2D array of single-photon avalanche diodes (SPADs) 401.1 and 401.3. The SPAD diodes operate in Geiger mode with a supply voltage higher than the breakdown voltage. Additionally, quenching resistors 401.4 are connected in series with each SPAD diode. In the case of triggering a carrier avalanche, the quenching resistor 401.4 prevents thermal breakdown of the diode. The current signal of the SPAD diode is measured via a shunt resistor, which can be the quenching resistor or a resistor provided in addition thereto. In Figure 6 the example of, the SPAD diode array consists of, for example, four (active or emitter) SPAD diodes 401.1 and twelve (passive or receiver) SPAD diodes 401.3. The SPAD diodes 401.3 are coupled to the SPAD diodes 401.1 via optical waveguides 401.2, as described above with reference to Figure 4 and Figure 5 for the optical fiber 50. The active SPAD diodes 401.1 emit light. They correspond to Figure 4 and Figure 5 the first SPAD diode 44. The active SPAD diodes 401.1 are preferably located inside the SPAD diode array. The proposed device supplies an increased supply voltage to the active SPAD diodes 401.1, and thus effectively operates the active SPAD diodes 401.1 above the breakdown voltage. This increases the dark count rate, resulting in a higher number of spontaneously emitted photons 47. The optical waveguides 401.2 forward some of the photons as photons 48 to the passive SPAD diodes 401.3. For example, the optical waveguides 401.2 correspond to Figure 4 and Figure 5 the optical fiber 50. For example, each passive SPAD diode 401.3 corresponds to Figure 4 and Figure 5 the second SPAD diode 45. The proposed device supplies an increased supply voltage to the passive SPAD diodes 401.3 and operates the passive SPAD diodes 401.3 slightly above the breakdown voltage. Preferably, the passive SPAD diodes 401.3 are arranged in a ring around the active SPAD diodes 401.2. The passive SPAD diodes 401.3 detect the photons arriving via the waveguide 401.2. Depending on the arriving photons, the passive SPAD diodes 401.3 generate, for example, a current flowing through the shunt resistor, thereby generating a voltage signal.

[0158] The voltage signal 405 of the entropy source 401 is preferably fed to a broadband, such as a 40 dB high-frequency amplifier 402. The high-frequency amplifier 402 preferably has a bandwidth of 30 to 4000 MHz and preferably has a 1 dB compression point of 20 dBm. The voltage swing of the voltage signal 405 of the entropy source 401 is typically in the sub-millivolt range. The high-frequency amplifier 402 amplifies the voltage swing of the voltage signal 405 of the entropy source 401 to, for example, 50 mV to 150 mV.

[0159] For example, the amplifier output signal 406 of the high-frequency amplifier 402 is transmitted to the FPGA 404 after being subjected to analog-to-digital conversion in the ADC 403. Of course, other discrete or ASIC-based solutions are also possible. In this regard, the FPGA is just one of many different implementations of the technical teachings presented in this exemplary embodiment. The FPGA 404 preferably includes a microcontroller. For example, the FPGA 404 can be a Zynq7010 of Xilinx with a dual-core ARM Cortex-A9 MPCore. This is part of the SPAD evaluation circuit of this exemplary embodiment. In addition, in Figure 4 and Figure 5 example, the circuit has an ADC 403 with, for example, 14 bits, an exemplary sampling rate of 125 megasamples per second, and an exemplary bandwidth of 50 MHz. The amplified voltage signal is available as the amplifier output signal 406 at the input of the high-frequency amplifier 402. The ADC 403 samples the amplifier output signal 406 of the high-frequency amplifier 402. For example, the ADC 403 digitally transmits the determined samples of the amplifier output signal 406 of the high-frequency amplifier 402 to the built-in FPGA 404 of the measurement board with a bit width of, for example, 14 bits.

[0160] In Figure 6 is shown in simplified form as a block diagram, the device includes a comparator 404.2, a time-to-digital converter (TDC) 404.3, an entropy extraction device 404.4, and a finite state machine 404.8.

[0161] For example, comparator 404.2 compares the 14-bit digital value 407 of ADC 403 with a reference value 404.1 representing a threshold. If the value at the output of ADC 403 is greater than the reference value 404.1, a 1-bit output pulse of two clock lengths is generated as the output signal 409 of comparator 404.2. The output signal 409 of comparator 404.2 is fed to time-to-digital converter 404.3. Time-to-digital converter 404.3 preferably has a 32-bit counter. For example, the 32-bit counter counts in time using a SPAD evaluation circuit. The bit width of the counter can vary according to the application. For example, the frequency of this clock can be 125 MHz. The 1-bit output signal of comparator 404.2 preferably resets the counter reading of this counter. Time-to-digital converter 404.3 transmits the counter reading that exists at this time (i.e., the counter reading that existed immediately before the reset) to its output 410. For an exemplary 125 MHz clock, the resolution of the counting result is 1 / 125 MHz = 8 ns. The output 410 of time-to-digital converter (TDC) 404.3 passes the exemplary 32-bit counting result (also called raw data RD) of time-to-digital converter 404.3 to entropy extraction device 404.4. Entropy extraction device 404.4 converts the raw data RD of the signal at the output 410 of time-to-digital converter (TDC) 404.3 to a 1-bit random number RN 411 at the output of entropy extraction device 404. The raw data RD is random with respect to its composition and sequence. The output 411 of entropy extraction device 404.4 is connected to the input of finite state machine (FSM) 404.8.

[0162] FSM 404.8 has the task of receiving data from entropy extraction device 404.4 and generating QRNG random numbers therefrom. FSM 404.8 stores the random numbers in the memory RAM 404.9 of FPGA 404. After a successful write operation, FSM 404.8 sets the completion flag 404.10. The completion flag 404.10 is not set at system startup. Microcontroller 404.11, such as a dual-core Arm Cortex-A9 MPCore, accesses the RAM 404.9 block and reads the random numbers from RAM 404.9. Microcontroller 404.11 is thus, for example, a microcontroller core according to the present invention.

[0163] Figure 7 An exemplary extended FPGA design is shown that monitors the signal for the random number RN at the output 411 of entropy extraction device 404.4 and includes an additional backup system in the event of potential errors during the generation of QRNG-based random numbers.

[0164] According to Figure 7The expansion of the device involves an additional watchdog 404.5, a linear feedback shift register 404.6 as an example of a PRN generator, a signal multiplexer 404.7, and a voltage monitor 413. The microcontroller 404.11 can also be externally configured together with these components.

[0165] The output 411 of the entropy extraction device 404.4 is now connected to the watchdog 404.5 and the signal multiplexer 404.7. The watchdog 404.5 monitors the validity of the 1-bit random number RN at the output 411 of the entropy extraction device 404.4. The watchdog 404.5 detects at least three defined error conditions. For example, the watchdog 404.5 sends the last valid random number as the seed S output signal 412 to the linear feedback shift register 404.6. If an error occurs, the watchdog sets an error bit in an undrawn error register ER of the microcontroller 404.11. Which error bit the watchdog 404.5 sets in the error register of the microcontroller 404.11 preferably depends on the type of error. Additionally, the watchdog 404.5 is connected to the voltage monitor 413 via one or more preferably digital input-output signal lines 414.

[0166] For example, the voltage monitor 413 monitors the operating voltage of the entropy source 401. If the operating voltage of one of the circuits of the SPAD diodes 401.1 and 401.3 is too low, i.e., the quantity is below the lower SPAD operating voltage threshold, or too high, i.e., the quantity is above the higher SPAD operating voltage threshold, the voltage monitor 413 detects this voltage deviation. In the case of such a voltage deviation, the voltage monitor 413 sends this signal to the watchdog 404.5 or directly to the microcontroller 404.11. For example, in the case of sending a signal to the watchdog 404.5, the watchdog 404.5 can generate an interrupt signal for the microcontroller 404.11. For example, if the power supply voltage of the entropy source 401 or the radio frequency amplifier 402 or another device part of the quantum random number generator QRNG 400 is faulty, the watchdog 404.5 can trigger such an interrupt of the microcontroller 404.11 or other sub-devices of the application system.

[0167] If the watchdog 404.5 detects an error, the quantum random number generator 400 switches to an emergency state. To this end, the watchdog 404.5 sets the selection signal 416 of the signal multiplexer 404.7 such that the signal multiplexer 404.7 applies the pseudo-random number PRN generated by the linear feedback shift register 404.6 in the form of a pseudo-random bit stream via the pseudo-random number signal line 417 to the input of the FSM 404.8 instead of the output 411 of the entropy extraction device 404.4, as an alternative to the potentially erroneous 1-bit random number RN that appears at the output 411 of the entropy extraction device 404.4.

[0168] The linear feedback shift register 404.6 is connected to the output 412 of the watchdog 404.5 and receives its seed S output signal 412 therefrom. In case of an error, the watchdog 404.5 activates the linear feedback shift register 404.6 (reference connection 418). The linear feedback shift register 404.6 then generates a pseudo-random number PRN. The seed S of the watchdog output signal 412 preferably includes the last, for example, still valid 16 random numbers (for example, 1 bit each). The watchdog 404.5 preferably applies the last valid random numbers to the input of the linear feedback shift register 404.6. The seed S thus serves as a random PQC-secure initial value of the generator polynomial for the feedback of the linear feedback shift register 404.6 for generating the pseudo-random number PRN for the pseudo-random signal line 417. The generator polynomial and the degree of the generator polynomial are preferably freely selectable.

[0169] The signal of the output 411 of the entropy extraction device 404.4 having a 1-bit random number RN of the entropy extraction device 404.4 and the signal of the pseudo-random signal line 417 of the linear feedback shift register 404.6 having a pseudo-random number PRN are respectively connected to the inputs of the signal multiplexer 404.7. The signal multiplexer 404.7 forwards one of its two input signals to the FSM 404.8 according to the value SEL of the selection signal 416. If the application requires, it is conceivable to use a multiplexer with more than two inputs and a more complex control signal. Thus, the number of inputs of the signal multiplexer 404.7 is generally greater than or equal to two.

[0170] The FSM 404.8 in turn has the task of receiving the random number RN or the pseudo-random number PRN from the output of the signal multiplexer 404.7 and writing them into the memory RAM 404.9 of the FPGA 404. If the writing process is successful, the FSM 404.8 sets the completion flag 404.10 again. The microcontroller 404.11 can then access the memory 404.9 RAM and read the random number and use it for, for example, encryption, authentication, signature, etc.

[0171] Figure 8 Shown, for example, by Figure 6 and Figure 7Flowchart 500 of the entropy extraction method performed by the entropy extraction device 404.4 of the QRNG 400. In the first step 501 of this method, two values of the output 410 of the time-to-digital converter 404.3 are first determined and stored in the shift register of the entropy extraction device 404.4. If two values are stored in the shift register of the entropy extraction device 404.4, the entropy extraction device 404.4 compares these two values in the second step 502. Thus, the two values in the shift register of the entropy extraction device 404.4 include a first value and a second value, both of which are determined by the time-to-digital converter 404 through two different measurements of the corresponding periods between two signal pulses above the reference value 404.1. In the third step 503, the entropy extraction device 404.4 evaluates these two values. If the first value is less than the second value and the difference between value 1 and value 2 is greater than the minimum difference ∈, the entropy extraction device 404.4 sets the value of its output 411 to the first logical value. If the first value is greater than the second value and the difference between the first value and the second value is greater than the minimum difference ∈, the entropy extraction device 404.4 sets its output to a second logical value different from the first logical value.

[0172] If the difference between the first value and the second value is less than the minimum difference ∈, the entropy extraction discards the first value and the second value. In this case, the entropy extraction method preferably causes the watchdog (in the Figure 7 device) to increment the error counter by a first error counter increment. The first error counter increment can be negative. Conversely, if the difference between the first value and the second value is greater than the minimum difference ∈, the entropy extraction device 404.4 can decrement the error counter of the watchdog by a second error counter increment. The second error counter increment can be the same as the first error counter increment. Generally, the signs of the first error counter increment and the second error counter increment are the same. Preferably, the microcontroller 404.11 can set the error counter increment as well as the initial value and the error counter threshold of the error counter. If the count reading of the error counter exceeds the error counter threshold, the watchdog 404.5 preferably sends a signal indicating a critical error state by interrupting or sending another signal to the microcontroller. The microcontroller 404.11 then generally starts a self-test program to test each part of the quantum random number generator 400 according to Figure 7 the QRNG 400. Preferably, the microcontroller can, for example, set the analog-to-digital converter 403 to a state where the microcontroller 404.11 can write a test value to the output register of the analog-to-digital converter, and the subsequent signal chain then processes this test value as if it were a real sampled value. Since the test value is pre-known, the correct response of the rest of the system, such as the increment of the error counter in the watchdog 404.5, can be monitored and evaluated by the microcontroller 404.11. Preferably, the microcontroller 404.11 can thus monitor all storage nodes of the FPGA 404 and read their logical states.

[0173] If the value is less than the minimum value, it is a value within the dead time of the SPAD diode. Such values are preferably discarded and the error counter is incremented by a first error increment. In this case, the entropy extraction device 404.4 waits for the time-to-digital converter 404.3 to determine the next value.

[0174] Once the random bits have been extracted in this way, the method starts again from the beginning.

[0175] For example, if the error counter exceeds or reaches the error counter threshold, there may be an error where the time-to-digital converter provides a constant digit.

[0176] Therefore, the device is able to detect faults in the power supply of the entropy source or other parts of the device. The microcontroller 404.11 can also record the voltages and currents in the ADC 403 and the quantum random number generator 400 for test purposes, and compare the values determined in this way with the expected value ranges within which these values must lie. The microcontroller 404.11 can also record digital values within the quantum random number generator 400. For example, for test purposes, the microcontroller 404.11 can set the reference value 404.1 so low that the time-to-digital converter 404.3 is substantially controlled by the signal noise at its input. Then, the value of the time-to-digital converter 404.3 should satisfy the expected statistics within the tolerance range. If this is not the case, there is an error.

[0177] The watchdog 404.5 can monitor the entropy of the random numbers provided. If the average entropy of the bits during the entropy measurement period deviates by more than, for example, 50% from the allowed entropy deviation value, the watchdog concludes that an error has occurred and increments the error counter. Preferably, the watchdog then stops using these random bits at the output 411 of the entropy extraction device 404.4 to prevent the transmission of plaintext. "Plaintext" refers to information that can be understood by a third party using statistical methods or directly due to poor information encryption. It is conceivable that even a properly functioning sub-device can randomly produce a logic "permanent one" or a logic "permanent zero". Therefore, it makes sense to limit the maximum length of the bit sequence at the output of the entropy extraction device to a value that can be programmed by the microcontroller 404.11.

[0178] Basically, the quantum random number generator 400 as described above can thus identify the following errors and capture them in an emergency mode at a lower security level using the linear feedback shift register 404.6 or another PRN generator:

[0179] - Power supply voltage failure,

[0180] - Error signal generation of SPAD diodes 401.1 and 401.3

[0181] - Coupling faults of optical fiber 401.2 and / or SPAD diodes 401.1 and 401.3 with optical fiber 401.2

[0182] - Circuit faults in FPGA 404 (i.e., the digital part of quantum random number generator 400)

[0183] - Incorrect entropy of the provided random numbers, which can be done by testing 1-bit random numbers RN, as described in Chapters 8 and 9 of David Johnston, "Random Number Generators – Principles and Practices", 2018, Walter De Gruyter GmbH, Berlin / Bonston, ISBN 978-1-5015-1530-2

[0184] It is conceivable to use a second fully quantum random number generator 400 to replace the linear feedback shift register 404.6, and the signal at the output of its entropy extraction device 404.4 is then used in the emergency mode instead of the signal of the pseudo-random signal line 417

[0185] Figure 9 An exemplary oscillogram of the voltage signal 405 at the output of the entropy source 401 is shown. It can be seen that the first spike appears at the first height level 601 and the second spike appears at the second height level 602. The scatter of the first height level 601 of the first spike and the scatter of the second height level of the second spike are so small in various cases that the two height levels 601, 602 can be clearly separated by the cut-off level 603. The cut-off level 603 corresponds to the value 404.1 set by the microcontroller 404.11 as the reference value. For the first and second spikes (second spike) formed due to the simultaneous occurrence of spontaneous and excited photon emissions of the second SPAD diode or one of the second SPAD diodes, and the first and second spikes (first spike) formed only due to the self-emission of photons of the second SPAD diode or one of the second SPAD diodes, please refer to the above description in the test

[0186] Figure 10Schematically shows the proposed method 3700 for generating quantum random numbers. Method 3700 starts at 3710: generating a random single-photon current (47, 48, 49, 401.2) through one or more first SPAD diodes (401.1, 44). Method 3700 continues at 3720: transmitting the random single-photon current (47, 48, 49, 401.2) through an optical fiber (44, 401.2) different from the semiconductor substrate (49, 48) to one or more second SPAD diodes (401.3, 45). Next is 3730: converting the random single-photon current (47, 48, 49, 401.2) into a detection signal in the form of a voltage signal 405 of an entropy source 401, where the entropy source 401 preferably includes the first SPAD diode 401.1, the optical fiber 401.2, and the second SPAD diode 401.3. Next is 3740: conditioning the detection signal, in particular amplifying and / or filtering and / or analog-to-digital converting it into a conditioned detection signal, in particular a 14-bit digital value 407 of an analog-to-digital converter 403. Then is 3750: separating, by comparing the conditioned detection signal with a threshold, in particular in a comparator (refer to Figure 6 and Figure 7 in 404.2), the pulses of the conditioned detection signal generated by the emission coupling of the first SPAD diode 401.1 and the second SPAD diode 401.3 from the pulses of the conditioned detection signal generated only by spontaneous emission, and generating a corresponding output signal 409 of the comparator 404.2 in particular. Next is 3760: determining a first time interval between a first pulse and a second pulse of a first pair of two consecutive photons generated by the coupling of the self-emitted photons of the first SPAD diode 401.1 and the photon emission of the second SPAD diode 401.3 excited by the photon emission, and determining a second time interval between a third pulse and a fourth pulse of a second pair of two consecutive pulses of the conditioned detection signal generated by the same type of coupling of the emissions of the first SPAD diode 401.1 and the second SPAD diode 401.3, in particular for determining a first value of the output 410 of the time-to-digital converter 404.3 and a second value of the output 410 of the time-to-digital converter 404.3. Then is 3670: determining the bit value of a random bit based on this by comparing the value of the first time interval with the value of the second time interval. The last step 3680: checking whether the number n of the determined random bits is still less than the number m of the random bits of the required quantum random number. If not, repeat the above steps. Otherwise, the process of generating quantum random numbers is completed.

[0187] Advantages

[0188] The secure microcontroller proposed in this text has improved entropy for at least one of its random number generators. Therefore, compared with the prior art, the encryption that can be achieved using the microcontroller is more efficient and is also post-quantum secure. However, the advantages of the present invention are not limited to this.

[0189] The above description is not claimed to be exhaustive and is not limited to the examples shown. Other variations of the examples described herein can be understood and practiced by those of ordinary skill in the art with reference to the drawings, the description, and the claims. The indefinite singular article "a" does not exclude a plurality, and the mention of a certain number of elements does not exclude the possibility of there being more or fewer elements. A single unit can perform the functions of several elements mentioned in the description, and vice versa, several elements can perform the function of one unit. Many alternatives, equivalents, variations, and combinations are possible without departing from the scope of the present application.

[0190] Unless otherwise stated, all features of the present invention can be freely combined with each other. This applies to the entire application presented herein. Unless otherwise stated, the features described in the drawings can also be freely combined with other features that are features of the present invention. There is no express provision restricting the individual features of the exemplary embodiments to combinations with other features of the exemplary embodiments. Additionally, the apparatus features of an apparatus can also be reformulated as method features, and method features can be reformulated as apparatus features of an apparatus. Such reformulations are thus also automatically disclosed.

[0191] In the foregoing detailed description, reference has been made to the drawings. The examples in the description and the drawings are to be regarded as illustrative and not as limiting the specific examples or elements described. Some examples can be derived from the foregoing description and / or the drawings and / or the claims by variation, combination, or alteration of certain elements. Additionally, those skilled in the art can derive examples or elements not literally described from the description and / or the drawings.

[0192] The present invention has been illustrated above with reference to a microcontroller for automotive applications. However, it will be clear to those skilled in the art that the intended use in this regard based on the disclosure in the priority-generating patent application and this PCT application is not limited. On the contrary, the microcontroller according to the present invention can be used in all devices involving PQK-secure encryption and / or PQR signatures of data and the editing and processing of security-related data. Preferably, one of the following methods can be used to perform PQR encryption:

[0193] BIKE1-L1-CPA, BIKE1-L3-CPA, BIKE1-L1-FO, BIKE1-L3-FO, Kyber512, Kyber768, Kyber1024, Kyber512-90s, Kyber768-90s, Kyber1024-90s, LEDAcryptKEM-LT12, LEDAcrypt-KEM-LT32, LEDAcryptKEM-LT52, NewHope-512-CCA, NewHope-1024-CCA, NTRU-HPS-2048-509, NTRU-HPS-2048-677, NTRU-HPS-4096-821, NTRU-HRSS-701, LightSaber-KEM, Saber-KEM, FireSaber-KEM, BabyBear, BabyBearEphem, Mama-Bear, MamaBearEphem, PapaBear, PapaBearEphem, FrodoKEM-640-AES, FrodoKEM-640-SHAKE, FrodoKEM-976-AES, FrodoKEM-976-SHAKE, FrodoKEM-1344-AES, FrodoKEM-1344-SHAKE, SIDH-p434, SIDH-p503, SIDH-p610, SIDH-p751, SIDH-P434-compressed, SIDH-P503-compressed, SIDH-P610-compressed, SIDH-P751-compressed, SIKE-P434', SIKE-P503, SIKE-P610', 'SIKE-P751, SIKE-P434-compressed, SIKE-P503-compressed, SIKE-P610-compressed, SIKE-P751-compressed.

[0194] Preferably, one of the following methods can be used to create a PQR signature:

[0195] DILITHIUM_2, DILITHIUM_3, DILITHIUM_4, MQDSS-31-48, MQDSS-31-64, SPHINCS+-Haraka-128f-robust, SPHINCS+-Haraka-128f-simple, SPHINCS+-Haraka-128s-robust, SPHINCS+-Haraka-128s-simple, SPHINCS+-Haraka-192f-robust, SPHINCS+-Haraka-192f-simple, SPHINCS+-Haraka-192s-robust, SPHINCS+-Haraka-192s-simple, SPHINCS+-Haraka-256f-robust, SPHINCS+-Haraka-256f-simple, SPHINCS+-Haraka-256s-robust, 'SPHINCS+-Haraka-256s-simple, SPHINCS+-SHA256-128f-robust, SPHINCS+-SHA256-128f-simple, SPHINCS+-SHA256-128s-robust, SPHINCS+-SHA256-128s-simple, SPHINCS+-SHA256-192f-robust, SPHINCS+-SHA256-192f-simple, SPHINCS+-SHA256-192s-robust, SPHINCS+-SHA256-192s-simple, SPHINCS+-SHA256-256f-robust, SPHINCS+-SHA256-256f-simple, SPHINCS+-SHA256-256s-robust, SPHINCS+-SHA256-256s-simple, SPHINCS+-SHAKE256-128f-robust, SPHINCS+-SHAKE256-128f-simple, SPHINCS+-SHAKE256-128s-robust, SPHINCS+-SHAKE256-128s-simple, SPHINCS+-SHAKE256-192f-robust, SPHINCS+-SHAKE256-192fsimple, SPHINCS+-SHAKE256-192s-robust, SPHINCS+-SHAKE256-192s-simple,SPHINCS+-SHAKE256-256f-robust, SPHINCS+-SHAKE256-256fsimple, SPHINCS+-SHAKE256-256s-robust, SPHINCS+-SHAKE256-256s-simple, picnic_L1_FS, picnic_L1_UR, picnic_L3_FS, picnic_L3_UR, picnic_L5_FS, picnic_L5_UR, 'picnic2_L1_FS', picnic2_L3_FS, picnic2_L5_FS, qTesla-p-I, qTesla-p-III'.

[0196] For example, the concept according to the invention can be used to generate addresses in a communication bus system having an automatic addressing of users by a bus master in the bus master or the user to be addressed. Thus, the invention can be used not only in encryption techniques for generating PQK security codes. PQK stands for "post-quantum cryptography" and refers to a subfield of cryptography, namely the subfield of quantum computer-resistant cryptography, which, unlike most of the asymmetric cryptosystems currently in use, deals with cryptographic primitives that are almost impossible to decrypt even using a quantum computer (see the definition in Wikipedia). Different codes can also be used to better distinguish the signals emitted by systems of essentially any design in order to separate these signals and separate them from adjacent systems that may interfere with each other in terms of signal technology. For example, if you think of ultrasonic measuring devices in the automotive industry, it may be advantageous to make the individual received signals distinguishable in terms of their origin (i.e., the transmitting emitter from which the signal originated).

[0197] Features of the invention

[0198] The following list of the invention again summarizes the features of the invention and its further developments. The application of the technical teachings can combine the features with each other, provided that these combinations do not lead to factual contradictions. In this regard, the dependencies and references given herein only represent particularly preferred exemplary embodiments.

[0199] 1) A safety microcontroller 1 for controlling a device in a motor vehicle

[0200] - comprising a semiconductor substrate, and

[0201] - comprising a storage element, and

[0202] - comprising at least one internal bus 2, and

[0203] - comprising at least one 8 / 16 / 32 / 64-bit microcontroller core 16, and

[0204] - comprising one or more data interfaces, and

[0205] - comprising at least one quantum process-based generator 15, and

[0206] - wherein the storage element is connected to the internal bus 2, and

[0207] - wherein the data interface is connected to the internal bus 2, and

[0208] - wherein the quantum process-based generator 15 is connected to the internal bus 2, and

[0209] - wherein the microcontroller core 16 is connected to the internal bus 2, and

[0210] - wherein the quantum process-based generator 15 generates random numbers upon request of the microcontroller core 16, and

[0211] - wherein the microcontroller core 16 uses a program from one or more of its storage elements and uses the random numbers to generate keys, and

[0212] - wherein the microcontroller core 16 uses a program from one or more of its storage elements and the keys to encrypt and decrypt data exchanged with devices external to the secure microcontroller, and

[0213] - wherein the semiconductor substrate integrally includes the sub-devices of the secure microcontroller 1,

[0214] - wherein the sub-devices of the secure microcontroller 1 include storage elements, an internal bus 2, at least one 8 / 16 / 32 / 64-bit microcontroller core 16, data interfaces, and a quantum process-based generator 15.

[0215] 2) The secure microcontroller 1 according to item 1),

[0216] - wherein the storage element includes one or more read / write memories RAM 3 and / or one or more writable non-volatile memories, in particular EEPROM memories 4 and / or flash memories 4 and / or OTP memories 4, and / or one or more read-only memories and / or one or more non-volatile manufacturer memories, in particular one or more manufacturer ROMs 6, and / or one or more manufacturer EEPROMs and / or one or more manufacturer flash memories.

[0217] 3) The secure microcontroller 1 according to item 2),

[0218] : - wherein the manufacturer ROM 6 includes boot software.

[0219] 4) The secure microcontroller 1 according to item 2) or item 3),

[0220] - wherein a manufacturer firewall 8 is provided between the manufacturer memory 6 and the internal bus 2.

[0221] 5) The secure microcontroller 1 according to one or more of items 1) to 4),

[0222] - including one or more of the following components:

[0223] - a basic clock generator 21 (CLK),

[0224] - a clock generator circuit 12, and / or

[0225] - a reset circuit 22, and / or

[0226] - a power supply or Vcc circuit 23 having a voltage regulator for providing an operating voltage, and / or

[0227] - a ground circuit 24, and / or

[0228] - an input / output circuit 25, and / or

[0229] - one or more processing modules,

[0230] - wherein the processing module communicates with the internal bus 2, and

[0231] - wherein the processing module includes one or more of the following modules:

[0232] - a CRC module (Cyclic Redundancy Check) 11,

[0233] - a clock generator module 12,

[0234] - including a DES accelerator and / or an AES accelerator 7,

[0235] - one or more timer modules 13,

[0236] - a security monitoring and control circuit 14,

[0237] - a data interface, in particular a Universal Asynchronous Receiver / Transmitter (UART) 17.

[0238] 6) The secure microcontroller 1 according to one or more of items 1) to 5),

[0239] - including at least one first SPAD diode 44, and

[0240] - including at least one second SPAD diode 45, and

[0241] - comprising at least one optical fiber 50, and

[0242] - comprising at least one processing circuit, and

[0243] - comprising at least one operating circuit,

[0244] - wherein the quantum - process - based generator 15 comprises at least the first SPAD diode 44 as a light quantum signal light source, and

[0245] - wherein the quantum - process - based generator 15 comprises at least the second SPAD diode 45 as a photodetector for light quantum signals, and

[0246] - wherein the quantum - process - based generator 15 comprises at least the processing circuit, and

[0247] - wherein the quantum - process - based generator 15 comprises at least an optical fiber, and

[0248] - wherein the at least one optical fiber 50 optically couples the at least one first SPAD diode 44 with the at least one second SPAD diode 45, and

[0249] - wherein the operating circuit supplies electrical energy to the first SPAD diode 44 such that the first SPAD diode emits light 44, and

[0250] - wherein the processing circuit detects the signal of the second SPAD diode 45 and forms a random number therefrom, and supplies the latter to the microcontroller core 16.

[0251] 7) The secure microcontroller 1 according to item 6),

[0252] - wherein the semiconductor substrate comprises a surface 46, and

[0253] - wherein the semiconductor substrate comprises semiconductor material below its surface 46, and

[0254] - wherein the surface 46 of the semiconductor substrate comprises a metallization stack, and

[0255] - wherein the metallization stack comprises an optically transparent and electrically insulating layer 34 of a typical structure, and

[0256] - wherein at least a part of the optically transparent and electrically insulating layer of the typical structure of the surface 46 forms the optical fiber 50, and

[0257] - wherein the first SPAD diode 44 irradiates into the optical fiber 50 from the semiconductor material of the semiconductor substrate,

[0258] - A device component in which the optical fiber irradiates the second SPAD diode 44 such that light from inside the optical fiber 50 re-enters the semiconductor material of the semiconductor substrate from the surface and hits the second SPAD diode 44 there.

[0259] 8) The secure microcontroller 1 according to item 6) and / or item 7),

[0260] - Wherein at least one operation circuit supplies electrical energy to the at least one first SPAD diode 44 at least temporarily, and

[0261] - Wherein the at least one first SPAD diode 44 feeds photons into the at least one optical fiber 50 when supplied with sufficient electrical energy, and

[0262] - Wherein the at least one optical fiber 50 emits such photons to the second SPAD diode 45.

[0263] 9) The secure microcontroller 1 according to one or more of the preceding items,

[0264] - Wherein the data interface in one or more data interfaces is a wired automotive data bus interface, and

[0265] - The wired automotive data bus interface particularly includes:

[0266] - A CAN data bus interface, and / or

[0267] - A CAN FD data bus interface, and / or

[0268] - A Flexray data bus interface, and / or

[0269] - A PSI5 data bus interface, and / or

[0270] - A DSI3 data bus interface, and / or

[0271] - A LIN data bus interface, and / or

[0272] - An Ethernet data bus interface, and / or

[0273] - A MELIBUS data bus interface.

[0274] 10) The secure microcontroller 1 according to one or more of the preceding items,

[0275] - Wherein the data interface in one or more data interfaces is a wireless data bus interface, and

[0276] - The wireless data bus interface particularly includes:

[0277] - A WLAN interface, and / or

[0278] - A Bluetooth interface.

[0279] 11) According to the security microcontroller 1 as described in one or more of the foregoing items,

[0280] - Wherein the data interface among the one or more data interfaces is a wired data bus interface, and

[0281] - Wherein the wireless data bus interface particularly includes

[0282] - A KNX data bus interface, and / or

[0283] - An EIB data bus interface, and / or

[0284] - A DALI data bus interface, and / or

[0285] - A PROFIBUS data bus interface.

[0286] 12) A device

[0287] - Wherein the device includes an integrated circuit 4 having a first processor 10-1 and a non-volatile memory 16, and

[0288] - Wherein the device includes a first memory,

[0289] - Wherein the non-volatile memory stores at least one security code,

[0290] - The first memory stores data thereon, and

[0291] - Wherein the data in the first memory is encrypted and protected in a first format, and

[0292] - Wherein the integrated circuit is configured to verify the data read from the first memory during the transmission of data from the first memory, and

[0293] - Wherein the device includes a quantum random number generator 28, and

[0294] - Wherein the integrated circuit and the quantum random number generator 28 are fabricated in a semiconductor crystal, and

[0295] - Wherein the semiconductor crystal has a surface 46, and

[0296] - Wherein the semiconductor crystal includes semiconductor material below its surface 46, and

[0297] - wherein the surface 46 of the semiconductor crystal includes a metallization stack, and

[0298] - wherein the metallization stack includes an optically transparent and electrically insulating layer 34 of a typical structure, and

[0299] - wherein at least a part of the optically transparent and electrically insulating layer 34 of the typical structure of the surface 46 forms an optical fiber 50, and

[0300] - wherein the first SPAD diode 44 radiates photons 47 from the semiconductor material of the semiconductor substrate into the optical fiber 50, and

[0301] - wherein the at least one optical fiber 50 transmits such photons 48 to a second SPAD diode 45, and

[0302] - wherein the optical fiber 50 irradiates the second SPAD diode 45 such that light 49 from inside the optical fiber 50 re-enters the semiconductor material of the semiconductor substrate from the surface 46 and hits the device part of the second SPAD diode 45, and

[0303] - wherein the first SPAD diode 44 and the second SPAD diode 45 and the optical fiber 50 are part of the quantum random number generator 28.

[0304] 13) The device according to item 12),

[0305] - wherein the device includes at least one operating circuit, and

[0306] - wherein the at least one operating circuit at least temporarily supplies electrical energy to the at least one first SPAD diode 44, and

[0307] - wherein the at least one first SPAD diode 44 feeds photons 47 into the at least one optical fiber 50 when supplied with sufficient electrical energy, and

[0308] - wherein the at least one optical fiber 50 transmits such photons 48 to the second SPAD diode 45, and

[0309] - wherein the at least one optical fiber 50 emits such photons 49 into the second SPAD diode 45.

[0310] 14) The device according to item 13),

[0311] - wherein the quantum random number generator 28 includes at least the first SPAD diode 44 as a light quantum signal light source, and

[0312] - wherein the quantum random number generator 28 includes at least the second SPAD diode 45 as a photodetector for the optical quantum signal, and

[0313] - wherein the quantum random number generator 28 includes at least one processing circuit, and

[0314] - wherein the quantum random number generator 28 includes at least an optical fiber 50, and

[0315] - wherein the at least one optical fiber 50 optically couples the at least one first SPAD diode 44 to the at least one second SPAD diode 45, and

[0316] - wherein the operation circuit supplies electrical energy to the first SPAD diode 44 such that the first SPAD diode emits light 44, and

[0317] - wherein the processing circuit detects the signal of the second SPAD diode 45 and forms the random number therefrom, and provides the latter to the data processor 10 or other device components.

[0318] 15) The device according to any one of items 12) to 14),

[0319] - wherein the first memory is external to the integrated circuit, and

[0320] - wherein the device includes a second memory for storing data, and

[0321] - wherein the first memory is external to the integrated circuit;

[0322] - wherein the device is configured to

[0323] - transfer data from the first memory to the second memory via the integrated circuit for access by the data processor from the second memory, and

[0324] - wherein the integrated circuit is configured to

[0325] - verify the data read from the first memory during the transfer of data from the first memory to the second memory using a security code stored in a non-volatile memory, and

[0326] - if the data is verified, apply cryptographic protection to the verified data in a second format using the security code stored in the non-volatile memory, and

[0327] - store the data protected in the second format in the second memory.

[0328] 16) The apparatus according to any one of items 12) to 15), wherein the first memory comprises a read-only memory.

[0329] 17) The apparatus according to any one of items 15) to 16), wherein the second memory comprises a random access memory.

[0330] 18) The apparatus according to any one of items 15) to 17), wherein the password protection applied to the data in the first memory is different from the password protection applied to the data in the second memory.

[0331] 19) The apparatus according to any one of items 12) to 18),

[0332] - wherein the integrated circuit comprises a memory for storing data to be processed by the data processor, and

[0333] - wherein the apparatus is configured to store some of the data in the verified data set in the memory, and store the remaining data in the second memory.

[0334] 20) The apparatus according to any one of items 15) to 19), wherein the first memory stores data in a first data format, and the second memory is arranged to store data in a different second data format.

[0335] 21) The apparatus according to item 20),

[0336] - wherein the data stored in the first memory is protected by a first authentication technique, and

[0337] - wherein the apparatus is configured to protect the data in the second memory by a different second authentication technique.

[0338] 22) The apparatus according to any one of items 15) to 21),

[0339] - wherein the data in the first memory is stored in at least one data set, and the data set or each data set is encrypted and protected as a set, and

[0340] - wherein the apparatus is configured to store words or word groups of the verified data set in the second memory, wherein each word or word group is individually encrypted and protected.

[0341] 23) The apparatus according to item 22), configured to

[0342] - read the words or word groups from the second memory, and

[0343] - Verifying the read word or word group by using a security code stored in the non-volatile memory, and

[0344] - Processing the read and verified word or word group in the data processor.

[0345] 24) The apparatus according to item 23),

[0346] - Wherein the integrated circuit includes a hash calculator, and

[0347] - Wherein the data processor and the hash calculator are arranged such that they

[0348] - a) Calculating a hash function for each word or word group according to a security code stored in the non-volatile memory, and storing the hash associated with the word or word group in the second memory,

[0349] - b) Retrieving the stored word or word group from the second memory, recalculating the hash function of the retrieved word or word group by using the security code, and comparing the newly calculated hash with the stored hash, and

[0350] - c) Only allowing the data processing system to process the retrieved word or word group if the newly calculated and stored hashes have a specific relationship with each other.

[0351] 25) The apparatus according to item 24), wherein the hash calculator is a circuit in the integrated circuit.

[0352] 26) The apparatus according to any one of items 12) to 25), wherein the non-volatile memory of the integrated circuit is a one-time programmable memory.

[0353] 27) The apparatus according to any one of items 12) to 26), wherein the data set or each data set stored in the first memory is encrypted and protected by a corresponding digital signature.

[0354] 28) The apparatus according to any one of items 12) to 28), wherein the data set or each data set stored in the first memory is encrypted and protected by a corresponding digital signature by means of at least one random number in the quantum random number generator.

[0355] 29) The apparatus according to item 27) or item 28), wherein the security code is stored in the non-volatile memory of the integrated circuit, and the security code has been generated at least partially by at least one random number of the quantum random number generator (28).

[0356] 30) The apparatus according to any one of items 27) to 29), wherein the apparatus is configured to verify the digital signature of the data set by referring to the security code stored in the non-volatile memory of the integrated circuit or the security code.

[0357] 31) A data processing apparatus,

[0358] - wherein the data processing apparatus includes an integrated circuit, and

[0359] - wherein the integrated circuit includes a data processor, and

[0360] - wherein the integrated circuit includes a non-volatile memory, and

[0361] - wherein the non-volatile memory stores at least one security code, and

[0362] - wherein the integrated circuit includes a hash calculator, and

[0363] - wherein the integrated circuit has an interface at the boundary of the integrated circuit, and

[0364] - wherein the integrated circuit includes a quantum random number generator, and

[0365] - wherein the integrated circuit and the quantum random number generator are fabricated in a semiconductor crystal, and

[0366] - wherein the semiconductor crystal has a surface 46, and

[0367] - wherein the semiconductor crystal includes semiconductor material below its surface 46, and

[0368] - wherein the surface 46 of the semiconductor crystal includes a metallization stack, and

[0369] - wherein the metallization stack includes an optically transparent and electrically insulating layer 34 of a typical structure, and

[0370] - wherein at least a part of the optically transparent and electrically insulating layer 34 of the typical structure on the surface 36 forms an optical fiber 50, and

[0371] - wherein the first SPAD diode 44 radiates photons 47 from the semiconductor material of the semiconductor substrate into the optical fiber 50, and

[0372] - wherein the at least one optical fiber 50 transmits such photons 48 to the second SPAD diode 45, and

[0373] - wherein the optical fiber 50 irradiates the second SPAD diode 45 such that light 49 from inside the optical fiber 50 re - enters the semiconductor material of the semiconductor substrate from the surface 46 and hits the device components of the second SPAD diode 45, and

[0374] - wherein the first SPAD diode 44, the second SPAD diode 45, and the optical fiber 50 are part of a quantum random number generator 28.

[0375] 32) The data processing device according to item 31), wherein the data processor and / or other device parts of the data processing device encrypt or decrypt data by means of at least one random number of the quantum random number generator.

[0376] 33) The data processing device according to item 31) or item 32),

[0377] - wherein the data processing device includes a memory, and

[0378] - wherein the memory is adapted to store data when being used by the processor; and

[0379] - wherein the memory is coupled to the data processor to receive words from the data processor and transfer words to the digital processor.

[0380] 34) The data processing device according to any one of items 31) to 33),

[0381] - wherein the memory is external to the integrated circuit, and

[0382] - wherein the memory is coupled to the data processor via the interface at the boundary of the integrated circuit to receive words from the data processor and transfer words to the digital processor.

[0383] 35) The data processing device according to any one of items 31) to 34),

[0384] - wherein the data processor and the hash calculator are arranged such that they

[0385] a) calculate the hash function of each word according to a security code stored in the non - volatile memory and store the hash in association with the word,

[0386] b) retrieve the stored words from the memory, recalculate the hash function for each retrieved word using the security code, and compare the recalculated hash value with the stored hash value, and

[0387] c) The data processing system is only allowed to process the retrieved word if the newly calculated and stored hash has a previously defined relationship.

[0388] 36. A device, comprising the following:

[0389] - An integrated circuit, which includes a data processing device and a non-volatile memory device for storing at least one security code;

[0390] - A first device for storing data, wherein the data is encrypted and protected in a first format by at least one authentication code; and

[0391] - A quantum random number generator 28 as part of the integrated circuit,

[0392] - wherein the quantum random number generator includes a first SPAD diode 44 and a second SPAD diode 45, which are connected to each other or can be connected to each other via an optical fiber 50 manufactured outside the semiconductor substrate of the integrated circuit on the surface of the integrated circuit, and

[0393] - wherein the device at least temporarily uses at least one random number of the quantum random number generator 28 to encrypt or decrypt the date or the authentication code.

[0394] 37) The device according to item 36),

[0395] - wherein the device particularly includes a second device outside the integrated circuit for storing data, and

[0396] - wherein the device includes a transmission device for transmitting data from the first memory to the second memory via the integrated circuit for the data processor to access from the second memory, and

[0397] - wherein the device includes a verification device for verifying the data read from the first memory by using the security code stored in the non-volatile memory during transmission, and

[0398] - wherein the device includes an encryption protection application device for applying encryption protection including at least one verification code to the verified data by using the security code stored in the non-volatile memory in a second format when verifying the data, and

[0399] - wherein the device includes a storage device for storing the protected data in the second format in the second memory.

[0400] 38) A device particularly according to any one of items 12) to 37),

[0401] - wherein the device includes a quantum random number generator 400, and

[0402] - wherein the quantum random number generator includes the following device components:

[0403] - a first SPAD diode 404.1,

[0404] - a second SPAD diode 404.3,

[0405] - an optical fiber 404.2 that optically couples the first SPAD diode 404.1 and the second SPAD diode 404.3 to each other,

[0406] - an amplifier 403 and / or a filter,

[0407] - an analog-to-digital converter 403,

[0408] - a comparator 404.2,

[0409] - a time-to-digital converter 404.3,

[0410] - an entropy extraction device 404.4 that converts the output value of the time-to-digital converter 403 into a first value and a second value, and generates random bits therefrom.

[0411] 39) The device according to item 27), wherein the device includes a watchdog 404.5 that monitors the device components of the quantum random number generator 400.

[0412] 40) The device according to any one of items 38) and 39), wherein the device includes a voltage monitor 413 that detects and monitors the analog value of an analog signal.

[0413] 41) The device according to any one of items 38) to 40), wherein the device includes a pseudo-random number generator 404.6, particularly in the form of a linear feedback shift register 404.6.

[0414] 42) The device according to any one of items 38) to 41), wherein the device includes a signal multiplexer that, in the event of an error, switches the signal from the output 411 of the entropy extraction device to the signal of an equivalent random number generator or an equivalent pseudo-random number generator 404.6.

[0415] 43) The device according to any one of items 38) to 42), wherein, in the event of an error, the initial value of the pseudo-random number generator 404.6 depends on the random bits previously and correctly generated by the quantum random number generator 400.

[0416] 44) A method for generating random bits, comprising the following steps:

[0417] - Generating a pulse sequence with random intervals through at least two SPAD diodes,

[0418] - Wherein the pulse sequence includes pulses of a first height level 601 and a second height level 602;

[0419] - Separating the pulses of the first height level 601 from the pulses of the second height level 602 by a cutting level 603, 404.1;

[0420] - Detecting 501 a first value of the time interval between a first pulse of the second height level 602 and a second pulse of the second height level 602 different from the first pulse;

[0421] - Detecting 501 a second value of the time interval between a third pulse of the second height level 602 different from the first pulse and a fourth pulse of the second height level 602 different from the first pulse, the second pulse, and the third pulse,

[0422] - Comparing 502 the first value with the second value, and

[0423] - If the first value is greater than the second value, outputting a first logic value as a random bit 503, and

[0424] - If the first value is less than the second value, outputting a second logic value different from the first logic value as the random bit 503.

[0425] 45) A method for generating a quantum random number QZ with m random bits 3700, comprising the following steps:

[0426] - 3710: Generating a random single - photon current 47, 48, 49, 401.2 from single photons through one or more first SPAD diodes 401.1, 44;

[0427] - 3720: Transmitting the random single - photon current 47, 48, 49, 401.2 to one or more second SPAD diodes 401.3, 45 through an optical fiber 50, 401.2 different from the semiconductor substrate 39, 38;

[0428] - 3730: Converting the random single - photon current 47, 48, 49, 401.2 into a detection signal through the one or more second SPAD diodes 401.3, 45;

[0429] - 3740: Adjusting the detection signal to an adjusted detection signal;

[0430] -3750: By comparing the adjusted detection signal with a threshold of 404.1, separating the pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode 401.1 among the one or more first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45 among the one or more second SPAD diodes 401.3, 45 from the pulses of the adjusted detection signal generated by the spontaneous emission of the second SPAD diodes 401.3, 45;

[0431] -3760: Determining a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45, and determining a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45;

[0432] -3670: Determining the bit value of a random bit by comparing the value of the first time interval and the value of the second time interval;

[0433] -3680: If the number 3680n of the determined random bits is less than the desired number m of the random bits of the quantum random number QZ to be generated, repeating the above steps 3710 to 3770, and if the number n of the determined random bits is greater than or equal to the desired number m of the random bits of the quantum random number QZ to be generated, terminating the process of generating the quantum random number.

[0434] 46) An apparatus, comprising the following:

[0435] - An integrated circuit, which includes data processing means and a non-volatile memory device storing at least one security code;

[0436] - A first means for storing data, wherein the data is encrypted and protected in a first format by at least one authentication code; and

[0437] - A quantum random number generator 28 as part of the integrated circuit,

[0438] - Wherein the quantum random number generator includes a first SPAD diode 44 and a second SPAD diode 45, which are connected to each other or can be connected to each other via an optical fiber 50 manufactured outside the semiconductor substrate of the integrated circuit on the surface of the integrated circuit, and

[0439] - wherein the device at least temporarily uses at least one random number of the quantum random number generator 28 to encrypt or decrypt the date or the authentication code.

[0440] 47) The device according to item 46,

[0441] - wherein the device particularly includes a second device outside the integrated circuit for storing data, and

[0442] - wherein the device includes a transmission device for transmitting data from the first memory to the second memory via the integrated circuit for the data processor to access from the second memory, and

[0443] - wherein the device includes a verification device for verifying the data read from the first memory by using a security code stored in the non-volatile memory during transmission, and

[0444] - wherein the device includes an encryption protection application device for applying encryption protection including at least one verification code to the verified data in a second format by using a security code stored in the non-volatile memory when verifying the data, and

[0445] - wherein the device includes a storage device for storing the protected data in the second format in the second memory.

[0446] 48) The device according to item 46) or item 47),

[0447] - wherein the device includes a quantum random number generator 400, and

[0448] - wherein the quantum random number generator includes the following device components:

[0449] - a first SPAD diode 404.1,

[0450] - a second SPAD diode 404.3,

[0451] - an optical fiber 404.2 that optically couples the first SPAD diode 404.1 and the second SPAD diode 404.3 to each other,

[0452] - an amplifier 403 and / or a filter,

[0453] - an analog-to-digital converter 403,

[0454] - a comparator 404.2,

[0455] - a time-to-digital converter 404.3,

[0456] - An entropy extraction device 404.4 that converts the output value of the time-to-digital converter 403 into a first value and a second value and generates random bits for a random number therefrom.

[0457] 49) The device according to item 48), wherein the device includes a watchdog 404.5 that monitors the device components of the quantum random number generator 400.

[0458] 50) The device according to any one of items 48) and 49), wherein the device includes a voltage monitor 413 that detects and monitors an analog value of an analog signal.

[0459] 51) The device according to any one of items 48) to 50), wherein the device includes a random number generator or a pseudo-random number generator 404.6, in particular in the form of a linear feedback shift register 404.6.

[0460] 52) The device according to any one of items 48) to 51), wherein the device includes a signal multiplexer that, in the event of an error, switches the signal from the output 411 of the entropy extraction device to the signal of an equivalent random number generator or an equivalent pseudo-random number generator 404.6.

[0461] 53) The device according to any one of items 48) to 52), wherein, in the event of an error, the initial value of the pseudo-random number generator 404.6 depends on the random bits previously and correctly generated by the quantum random number generator 400.

[0462] 54) A method for generating random bits, comprising the following steps:

[0463] - Generating a pulse sequence with random intervals by at least two SPAD diodes,

[0464] - wherein the pulse sequence includes pulses of a first height level 601 and a second height level 602;

[0465] - Separating the pulses of the first height level 601 from the pulses of the second height level 602 by a cut-off level 603, 404.1;

[0466] - Detecting 501 a first value of a time interval between a first pulse of the second height level 602 and a second pulse of the second height level 602 different from the first pulse;

[0467] - Detect 501 a second value of a time interval between a third pulse different from the first pulse and a fourth pulse different from the first, second, and third pulses of the second height level 602.

[0468] - Compare 502 the first value with the second value, and

[0469] - If the first value is greater than the second value, output a first logic value as a random bit 503, and

[0470] - If the first value is less than the second value, output a second logic value different from the first logic value as the random bit 503.

[0471] 55) A method 3700 for generating a quantum random number QZ with m random bits, comprising the following steps:

[0472] - 3710: Generate 47, 48, 49, 401.2 a random single-photon current from single photons through one or more first SPAD diodes 401.1, 54;

[0473] - 3720: Transmit 47, 48, 49, 401.2 the random single-photon current through an optical fiber 50, 401.2 different from the semiconductor substrate 39, 38 to one or more second SPAD diodes 401.3, 45;

[0474] - 3730: Convert 47, 48, 49, 401.2 the random single-photon current into a detection signal through the one or more second SPAD diodes 401.3, 45;

[0475] - 3740: Adjust the detection signal to an adjusted detection signal;

[0476] - 3750: Separate 47, 48, 49, 401.2 pulses of the adjusted detection signal generated by emission coupling of a first SPAD diode 401.1 in the one or more first SPAD diodes 401.1, 44 and a second SPAD diode 401.3, 45 in the one or more second SPAD diodes 401.3, 45 from pulses of the adjusted detection signal generated by spontaneous emission of the second SPAD diode 401.3, 45 by comparing the adjusted detection signal with a threshold 404.1;

[0477] -3760: Determine a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the regulated detection signal generated by coupling emissions of the first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45, and determine a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the regulated detection signal generated by coupling emissions of the first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45;

[0478] -3670: Determine a bit value of a random bit by comparing a value of the first time interval with a value of the second time interval;

[0479] -3680: If a number 3680n of the determined random bits is less than an expected number m of the random bits of the quantum random number QZ to be generated, repeat the above steps 3710 to 3770, and if the number n of the determined random bits is greater than or equal to the expected number m of the random bits of the quantum random number QZ to be generated, terminate the process of generating the quantum random number.

[0480] 56) An apparatus for generating a quantum random number QZ,

[0481] - Comprising one or more first SPAD diodes 401.1, 44, which generate a random single - photon current 47, 48, 49, 401.2 based on an optical quantum process from single photons, and

[0482] - Comprising one or more second SPAD diodes 401.3, 45, and

[0483] - Comprising optical fibers 50, 401.2 different from the semiconductor substrates 39, 38, which transmit the random single - photon current 47, 48, 49, 401.2 to one or more second SPAD diodes 401.3, 45 3720, and

[0484] - Wherein the one or more second SPAD diodes 401.3, 45 convert the random single - photon current 47, 48, 49, 401.2 into a detection signal 3730, and

[0485] - Wherein a signal processing device, particularly an amplifier 402, regulates the detection signal into a regulated detection signal 3740, and

[0486] - wherein the comparator 404.02 or a functionally equivalent device separates the pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode 401.1 among the one or more first SPAD diodes 401.1, 44 and the second SPAD diode 401.3 among the one or more second SPAD diodes 401.3, 45 from the pulses of the adjusted detection signal generated by the spontaneous emission of the second SPAD diodes 401.3, 45 by comparing the adjusted detection signal with a threshold 404.1, and

[0487] - wherein the time-to-digital converter 404.3 determines a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diodes 401.1, 44 and the second SPAD diodes 401.3, 45, and determines a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diodes 401.4, 44 and the second SPAD diodes 401.3, 45; and

[0488] - wherein the entropy extraction device 404.4 determines the bit value of a random bit by comparing the value of the first time interval and the value of the second time interval, and

[0489] - wherein the finite state machine 404.8 generates a quantum random number QZ 417 from the bit data stream of the random bits 411.

[0490] Application reference

[0491] This PCT application claims the priority of German national patent applications 10 2021 128005.2 of October 27, 2021, DE 10 2021 130 107.6 of November 18, 2021, DE 10 2022 110 713.2 of May 2, 2022, DE 10 2022 125 574.3 of October 4, 2022, DE 10 2022 125 617.0 of October 5, 2022, and DE 10 2022125 768.1 of October 6, 2022, the contents of which are hereby incorporated by reference into the subject matter of this application.

[0492] List of reference numerals

[0493] 1 Safety microcontroller

[0494] 2 One or more internal data buses

[0495] 3 One or more read / write memories RAM

[0496] 4 One or more writable non-volatile memories; for example, the non-volatile memory may include EEPROM memory or flash memory or OTP memory

[0497] 5 One or more non-volatile read-only memories, such as ROM, etc.

[0498] 6 One or more non-volatile, writable and / or non-writable manufacturer memories; for example, in the case of non-writable manufacturer memories, the manufacturer memory may be a manufacturer ROM

[0499] 7 One or more cryptographic accelerators, such as DES accelerators and / or AES accelerators

[0500] 8 One or more manufacturer memory firewalls

[0501] 11 One or more CRC modules (Cyclic Redundancy Check)

[0502] 12 One or more clock generator modules (CLK)

[0503] 13 Timer module

[0504] 14 One or more security monitoring and control circuits

[0505] 15 Quantum process-based generator

[0506] 16 Microcontroller core

[0507] 17 Data interface, in particular one or more Universal Asynchronous Receiver / Transmitters (UARTs) to support high-speed serial data

[0508] 21 One or more basic clock generators (CLK)

[0509] 22 One or more reset circuits

[0510] 23 One or more power supplies or Vcc circuits having a voltage regulator for providing the operating voltage to the secure microcontroller

[0511] 24 One or more ground circuits

[0512] 25 One or more input / output circuits

[0513] 30 Exemplary SPAD diode of a sensor element used as a single-photon detector

[0514] 31 Shallow Trench Isolation STI of the exemplary SPAD diode

[0515] 32 Anode contact of the exemplary SPAD diode

[0516] 33 Cathode contact of an exemplary SPAD diode; the cathode contact of the exemplary SPAD diode is preferably made of indium tin oxide (ITO) or other transparent conductive materials

[0517] 34 Insulating layer

[0518] 34' Insulating layer

[0519] 34” Insulating layer

[0520] 35 First linear highly doped first connection region; for example, in CMOS technology with p-doped wafer material, it can be an n + doped region

[0521] 36 First doped tray of the second linear type; for example, in CMOS technology with p-doped wafer material, it can be a less doped region in the semiconductor substrate material of the SPAD diode 1820, that is, p -- doped region

[0522] 37 Second doped tray of the second linear type; for example, in CMOS technology with p-doped wafer material, it can be a less doped region in the semiconductor substrate material of the SPAD diode, that is, p - doped region

[0523] 38 Second linear epitaxial layer; for example, in CMOS technology with p-doped wafer material, it can be a p-doped epitaxial layer in the semiconductor substrate material of the SPAD diode

[0524] 39 Substrate of a semiconductor single wafer with the second conductivity type; for example, in CMOS technology with p-doped wafer material, it is a p-doped single crystal semiconductor wafer

[0525] 40 Second doped tray of the second linear type under the anode contact; for example, in CMOS technology with p-doped wafer material, it can be a p-doped region in the semiconductor substrate material of the SPAD diode

[0526] 41 Second linear highly doped second connection region; for example, in CMOS technology with p-doped wafer material, it can be a p + doped region

[0527] 42 Insulation, such as oxide or the like

[0528] 43 Metal cover of the optical fiber

[0529] 44 The first SPAD diode; the first SPAD diode is at least temporarily used as a light source for irradiating a second SPAD diode with photons from the first SPAD diode

[0530] 45 The second SPAD diode; the second SPAD diode is at least temporarily used as a photodetector for light from the first SPAD diode, for example

[0531] 46 The wafer surface according to the present application

[0532] 47 Light emitted vertically upward in a direction perpendicular to the surface by the first SPAD diode

[0533] 48 Light transmitted horizontally in an optical fiber, which is part of the light vertically emitted by the first SPAD diode into the optical fiber

[0534] 49 Light emitted vertically downward from the optical fiber by the first SPAD diode into the second SPAD diode in a direction perpendicular to the surface, which is emitted by the first SPAD diode as vertical light into the optical fiber and then transmitted horizontally from the optical fiber to the second SPAD diode;

[0535] 50 An optical fiber for transmitting photons from the first SPAD diode to the second SPAD diode; the optical fiber is formed by a covering oxide or other optically transparent insulating layer on the circuit of an exemplary SPAD diode.

[0536] 50' An optical fiber for transmitting photons from the first SPAD diode to the second SPAD diode; the optical fiber is formed by a covering oxide or other optically transparent insulating layer on the circuit of an exemplary SPAD diode, or is formed by two optically transparent insulating layers (e.g., a metallization stack) arranged one above the other.

[0537] 51 Contact

[0538] 52 Contact

[0539] 53 Plane between two electrically insulating layers of a waveguide

[0540] 400 Quantum random number generator QRNG

[0541] 401 Entropy source

[0542] 401.1 One or more first SPAD diodes

[0543] 401.2 Optical fiber

[0544] 401.3 One or more second SPAD diodes

[0545] 402 High-frequency amplifier

[0546] 403 Analog-to-Digital Converter (ADC)

[0547] 404 Measurement Board with FPGA

[0548] 404.1 Constants

[0549] 404.2 Comparator

[0550] 404.3 Time-to-Digital Converter

[0551] 404.4 Entropy Extraction Device

[0552] 404.5 Watchdog

[0553] 404.6 Linear Feedback Shift Register; the feedback is preferably a simple primitive polynomial to generate a pseudo-random bit sequence;

[0554] 404.7 Signal Multiplexer

[0555] 404.8 Finite State Machine

[0556] 404.9 RAM

[0557] 404.10 Completion Flag

[0558] 404.11 Microcontroller

[0559] 405 Voltage Signal of Entropy Source 401

[0560] 406 Amplified Output Signal 406 of High-Frequency Amplifier 402

[0561] 407 14-bit Digital Value 407 of Analog-to-Digital Converter 403; other bit widths are also conceivable 408 Signal of Constant 404.1

[0562] 409 Output Signal 409 of Comparator 404.2

[0563] 410 Output of Time-to-Digital Converter 404.3

[0564] 411 Output of Entropy Extraction 404.4

[0565] 412 Seed S

[0566] 413 Voltage Monitor

[0567] 414 Signal Line

[0568] 416 Selection Signal

[0569] 417 Pseudo-Random Signal Line

[0570] 418 Random Data Word

[0571] Internal data bus of the 419 quantum random number generator 400; preferably, this is the internal data bus of the control device 4

[0572] 420 Interrupt signals of the control device 4 for the watchdog 404.5 and the fuse 1 of the quantum random number generator 400 respectively

[0573] 500 Flowchart 500 of the entropy extraction method

[0574] 501 First step 501 of determining a first value of the output 410 of the time-to-digital converter 404.3 and a second value of the output 410 of the time-to-digital converter 404.3 and storing them in the shift register of the entropy extraction 404.4 502 Second step of comparing the first value with the second value 503 Third step of evaluating the first value and the second value and generating random bits

[0575] 601 First spike

[0576] 602 Second spike

[0577] 603 Cutting level

[0578] 3700 Method for generating a quantum random number QZ with m random bits

[0579] 3710 Generating a random single-photon current (57, 58, 59, 401.2) through one or more first SPAD diodes (401.1, 54)

[0580] 3720 Transmitting the random single-photon current (57, 58, 59, 401.2) through an optical fiber (44, 401.2) different from the semiconductor substrate (49, 48) to one or more second SPAD diodes (401.3, 55)

[0581] 3730 Converting the random single-photon current (57, 58, 59, 401.2) into a detection signal in the form of a voltage signal 405 of the entropy source 401, the entropy source 401 preferably including the first SPAD diode 401.1 and the optical fiber 401.2 and the second SPAD diode 401.3

[0582] 3740 Adjusting the detection signal, in particular amplifying and / or filtering and / or analog-to-digital converting it into an adjusted detection signal, in particular the 14-bit digital value 407 of the analog-to-digital converter 403

[0583] 3750 separates the pulses of the conditioned detection signal generated by coupling the emissions of the first SPAD diode 401.1 and the second SPAD diode 401.3 from the pulses of the conditioned detection signal generated by spontaneous emission, in particular by comparing the conditioned detection signal with a threshold in a comparator 404.2, and generates a corresponding output signal 409, in particular the output signal of the comparator 404.2

[0584] 3760 determines a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the conditioned detection signal generated by coupling the emissions of the first SPAD diode 401.1 and the second SPAD diode 401.3, and determines a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the conditioned detection signal generated by coupling the emissions of the first SPAD diode 401.1 and the second SPAD diode 401.3, and, in particular, determines a first value of the output 410 of the time-to-digital converter 404.3 and a second value of the output 410 of the time-to-digital converter 404.3

[0585] 3670 determines the bit value of a random bit by comparing the value of the first time interval with the value of the second time interval

[0586] 3680 If the number n of random bits determined up to this step is less than the number m of random bits required for the desired quantum random number, the above steps are repeated. Otherwise, the process is terminated to generate a quantum random number with m random bits.

Claims

1. An electronic device, comprising: - A quantum random number generator (400), - wherein the quantum random number generator includes the following device components: - A first SPAD diode (401.1), - A second SPAD diode (401.3), - An optical fiber (401.2) that optically couples the first SPAD diode (401.1) and the second SPAD diode (401.3) to each other, - An amplifier (402) and / or a filter, - An analog-to-digital converter (403), - A comparator (404.2), - A time-to-digital converter (404.3), - An entropy extraction device (404.4) that converts the output value of the time-to-digital converter (404.3) into a first value and a second value, and generates random bits therefrom.

2. The electronic device according to claim 1, wherein the electronic device includes a watchdog (404.5), and the watchdog monitors the device components of the quantum random number generator (400).

3. The electronic device according to claim 1 or 2, wherein the electronic device includes a voltage monitor (413), and the voltage monitor (413) detects and monitors the analog value of an analog signal.

4. The electronic device according to claim 1 or 2, wherein the electronic device includes a pseudo-random number generator (404.6), particularly in the form of a linear feedback shift register (404.6).

5. The electronic device according to claim 1 or 2, wherein the electronic device includes a signal multiplexer, and in the event of an error, the signal multiplexer switches the signal from the output (411) of the entropy extraction device to the signal of an equivalent random number generator or an equivalent pseudo-random number generator (404.6).

6. The electronic device according to claim 5, wherein in the event of an error, the initial value of the pseudo-random number generator (404.6) depends on the random bits previously and correctly generated by the quantum random number generator (400).

7. A method for generating random bits, comprising the following steps: - Generating a pulse sequence with random intervals by at least two SPAD diodes, - wherein the pulse sequence includes pulses of a first height level (601) and a second height level (602); - Separating the pulses of the first height level (601) from the pulses of the second height level (602) by a cutting level (603, 404.1); - Detecting a first value of the time interval between a first pulse of the second height level (602) and a second pulse of the second height level (602) different from the first pulse; - Detecting a second value of the time interval between a third pulse of the second height level (602) different from the first pulse and a fourth pulse of the second height level (602) different from the first pulse, the second pulse, and the third pulse, - Comparing the first value with the second value, and - If the first value is greater than the second value, outputting a first logical value as a random bit, and - If the first value is less than the second value, output a second logic value different from the first logic value as the random bit.

8. A method for generating quantum random numbers, comprising the following steps: - Generate random single-photon currents (47, 48, 49, 401.2) from single photons through one or more first SPAD diodes (401.1, 44); - Transmit the random single-photon currents (47, 48, 49, 401.2) to one or more second SPAD diodes (401.3, 45) through optical fibers (50, 401.2) different from the semiconductor substrate (39, 38); - Convert the random single-photon currents (47, 48, 49, 401.2) into detection signals through the one or more second SPAD diodes (401.3, 45); - Adjust the detection signal to an adjusted detection signal; - Separate the pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1) in the one or more first SPAD diodes (401.1, 44) and the second SPAD diode (401.3, 45) in the one or more second SPAD diodes (401.3, 45) from the pulses of the adjusted detection signal generated by the spontaneous emission of the second SPAD diode (401.3, 45) by comparing the adjusted detection signal with a threshold (404.1); - Determine a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1, 44) and the second SPAD diode (401.3, 45), and determine a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1, 44) and the second SPAD diode (401.3, 45); - Determine the bit value of the random bit by comparing the value of the first time interval with the value of the second time interval; - If the number of determined random bits is less than the expected number of random bits of the quantum random number to be generated, repeat the above steps, and if the number of determined random bits is greater than or equal to the expected number of random bits of the quantum random number to be generated, terminate the process of generating quantum random numbers.

9. An electronic device, comprising: - An integrated circuit, which includes data processing means and a non-volatile memory device storing at least one security code; - A first device for storing data, wherein the data is encrypted and protected in a first format by at least one authentication code; and - A quantum random number generator as part of the integrated circuit - wherein the quantum random number generator includes a first SPAD diode (44) and a second SPAD diode (45), which are connected to each other or can be connected to each other via an optical fiber (50) manufactured outside the semiconductor substrate of the integrated circuit on the surface of the integrated circuit, and - wherein the electronic device at least temporarily uses at least one random number of the quantum random number generator to encrypt or decrypt the date or the authentication code.

10. The electronic device according to claim 9, - wherein the electronic device particularly includes a second device outside the integrated circuit for storing data, and - wherein the electronic device includes a transmission device for transmitting data from the first device to the second device via the integrated circuit for the data processor to access from the second device, and - wherein the electronic device includes a verification device for verifying the data read from the first device by using a security code stored in the non-volatile memory during transmission, and - wherein the electronic device includes an encryption protection application device for applying encryption protection including at least one verification code to the verified data in a second format by using the security code stored in the non-volatile memory when verifying the data, and - wherein the electronic device includes a storage device for storing the protected data in the second format in the second device.

11. The electronic device according to claim 9 or 10, - wherein the electronic device includes a quantum random number generator (400), and - wherein the quantum random number generator includes the following device components: - a first SPAD diode (401.1), - a second SPAD diode (401.3), - an optical fiber (401.2) that optically couples the first SPAD diode (401.1) and the second SPAD diode (401.3) to each other, - an amplifier (402) and / or a filter, - an analog-to-digital converter (403), - a comparator (404.2), - a time-to-digital converter (404.3), - an entropy extraction device (404.4) that converts the output value of the time-to-digital converter (404.3) into a first value and a second value, and generates random bits for a random number therefrom.

12. The electronic device according to claim 11, wherein the electronic device includes a watchdog (404.5) that monitors the device components of the quantum random number generator (400).

13. The electronic device according to claim 11, wherein the electronic device includes a voltage monitor (413) that detects and monitors the analog value of an analog signal.

14. The electronic device according to claim 11, wherein the electronic device includes a random number generator or a pseudo-random number generator (404.6), particularly in the form of a linear feedback shift register (404.6).

15. The electronic device according to claim 11, wherein the electronic device includes a signal multiplexer, and in the event of an error, the signal multiplexer switches from the signal at the output (411) of the entropy extraction device to the signal of an equivalent random number generator or an equivalent pseudo-random number generator (404.6).

16. The electronic device according to claim 15, wherein in the event of an error, the initial value of the pseudo-random number generator (404.6) depends on the random bits previously and correctly generated by the quantum random number generator (400).

17. A method for generating random bits, comprising the steps of: - generating a pulse sequence with random intervals through at least two SPAD diodes, - wherein the pulse sequence includes pulses of a first height level (601) and a second height level (602); - separating the pulses of the first height level (601) from the pulses of the second height level (602) by a cutting level (603, 404.1); - detecting a first value of a time interval between a first pulse of the second height level (602) and a second pulse of the second height level (602) different from the first pulse; - detecting a second value of a time interval between a third pulse of the second height level (602) different from the first pulse and a fourth pulse of the second height level (602) different from the first pulse, the second pulse, and the third pulse, - comparing the first value with the second value, and - if the first value is greater than the second value, outputting a first logic value as a random bit, and - if the first value is less than the second value, outputting a second logic value different from the first logic value as the random bit.

18. A method for generating quantum random numbers, comprising the steps of: - generating a random single-photon current (47, 48, 49, 401.2) from single photons through one or more first SPAD diodes (401.1, 44); - transmitting the random single-photon current (47, 48, 49, 401.2) to one or more second SPAD diodes (401.3, 45) through an optical fiber (50, 401.2); - converting the random single-photon current (47, 48, 49, 401.2) into a detection signal through the one or more second SPAD diodes (401.3, 45); - adjusting the detection signal to an adjusted detection signal; - By comparing the adjusted detection signal with a threshold (404.1), separating the pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1) among the one or more first SPAD diodes (401.1, 44) and the second SPAD diodes (401.3, 45) among the one or more second SPAD diodes (401.3, 45) from the pulses of the adjusted detection signal generated by the spontaneous emission of the second SPAD diodes (401.3, 45); - Determining a first time interval between a first pulse and a second pulse in a first pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1, 44) and the second SPAD diodes (401.3, 45), and determining a second time interval between a third pulse and a fourth pulse in a second pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1, 44) and the second SPAD diodes (401.3, 45); - Determining the bit value of a random bit by comparing the value of the first time interval with the value of the second time interval; - If the number of the determined random bits is less than the desired number of the random bits of the quantum random number to be generated, repeating the above steps, and if the number of the determined random bits is greater than or equal to the desired number of the random bits of the quantum random number to be generated, terminating the process of generating the quantum random number.

19. A device for generating a quantum random number, comprising: - One or more first SPAD diodes (401.1, 44) that generate a random single-photon current (47, 48, 49, 401.2) based on an optical quantum process from single photons, - One or more second SPAD diodes (401.3, 45), and - An optical fiber (50, 401.2) different from the semiconductor substrate (39, 38) that transmits the random single-photon current (47, 48, 49, 401.2) to the one or more second SPAD diodes (401.3, 45), and - Wherein the one or more second SPAD diodes (401.3, 45) convert the random single-photon current (47, 48, 49, 401.2) into a detection signal, and - Wherein a signal processing device, particularly an amplifier (402), adjusts the detection signal to an adjusted detection signal, and - wherein the comparator (404.2) or a functionally equivalent device separates the pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1) among the one or more first SPAD diodes (401.1, 44) and the second SPAD diode (401.3, 45) among the one or more second SPAD diodes (401.3, 45) from the pulses of the adjusted detection signal generated by the spontaneous emission of the second SPAD diode (401.3, 45) by comparing the adjusted detection signal with a threshold (404.1), and - wherein the time-to-digital converter (404.3) determines a first time interval between a first pulse and a second pulse of a first pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.1, 44) and the second SPAD diode (401.3, 45), and determines a second time interval between a third pulse and a fourth pulse of a second pair of two consecutive pulses of the adjusted detection signal generated by the emission coupling of the first SPAD diode (401.4, 44) and the second SPAD diode (401.3, 45); and - wherein the entropy extraction device (404.4) determines the bit value of a random bit by comparing the value of the first time interval and the value of the second time interval, and - wherein the finite state machine (404.8) generates quantum random numbers from the bit data stream of the random bits.