Key generation method, system and related equipment based on SIP module
Through the key generation method based on the SIP module, the resonant frequency offset characteristics and thermal noise phase jitter signals are extracted by the resonator array to generate a composite key, which solves the problems of insufficient key capacity, vulnerability to attack and large hardware size in the existing technology, and realizes high-security and miniaturized key generation.
Patent Information
- Application Number
- CN202510931873.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-07-07
AI Technical Summary
Existing PUF solutions have shortcomings in terms of limited key capacity, vulnerability to attacks, and large hardware size, making it difficult to meet the high security requirements of IoT devices.
A key generation method based on the SIP module is adopted. The resonant frequency offset characteristics and thermal noise phase jitter signals are extracted through the resonator array to generate static hardware fingerprints and dynamic random sequences. Combined with XOR logic operations, a composite key is generated to enhance anti-interference and anti-attack capabilities, and is suitable for BAW preparation processes.
It increases key capacity, enhances anti-attack capabilities, reduces hardware size, and is suitable for small terminals.
Smart Images

Figure CN120415730B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption technology, and in particular to a key generation method, system and related equipment based on a SIP module. Background Art
[0002] With the rapid development of IoT devices, hardware security threats are becoming increasingly prominent. Traditional encryption technologies rely on software algorithms and pre-stored keys, posing security risks to modeling / side-channel attacks and physical probing. Physically Unclonable Function (PUF) technology, which generates unique keys by extracting physical characteristics inherent in the hardware manufacturing process, has become a core technology for IoT device hardware security.
[0003] Current mainstream PUF solutions (such as SRAM-PUF and ring oscillator PUF) rely on the randomness of CMOS processes, but have significant limitations in practical applications:
[0004] First, the key capacity of a single chip is usually limited to hundreds of bits, which makes it difficult to meet the demand for massive keys in high-security scenarios (such as encrypted communications and device cluster authentication).
[0005] Secondly, traditional static PUF keys are vulnerable to modeling attacks and side-channel attacks, where attackers can obtain stable key characteristics through multiple sampling or physical probing;
[0006] Finally, the hardware supporting the relevant technologies is too bulky to be suitable for small terminals. Summary of the Invention
[0007] The purpose of the present invention is to provide a key generation method, system and related equipment based on the SIP module to solve the shortcomings of the existing technology, effectively improve the key capacity, enhance the anti-interference and anti-attack capabilities, and be suitable for the BAW preparation process, thereby reducing the hardware volume and being suitable for small terminals.
[0008] In a first aspect, the present invention provides a key generation method based on a SIP module, which is applied to a key generation system, wherein the key generation system includes a hardware unit comprising an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix; the key generation method based on the SIP module comprises the following steps:
[0009] S1. By scanning the hardware unit, extracting the resonant frequency offset characteristics of each resonator; the resonant frequency offset characteristics include the offset between a plurality of target resonant frequencies and corresponding target values;
[0010] S2. Using the preset threshold corresponding to each target resonant frequency as an independent criterion, the offset is mapped to a binary bit based on a preset mapping rule to generate a multi-digit static hardware fingerprint;
[0011] S3 obtains the thermal noise phase jitter signal of each resonator;
[0012] S4. Based on the thermal noise phase jitter signal, a dynamic random sequence is generated;
[0013] S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence;
[0014] S6. Obtain a final key based on the composite key of all the resonators.
[0015] The key generation method based on the SIP module provided by the present invention utilizes the random process errors in the thickness of each layer during the resonator processing to form a unique resonant frequency offset characteristic, and uses this as a basis to cooperate with threshold coding to improve the key capacity, and adopts a static and dynamic dual-modal mechanism to generate a composite key to enhance anti-interference and anti-attack capabilities. Finally, the relevant hardware design is suitable for the BAW preparation process, the hardware volume is smaller, and it is effectively applicable to small terminals.
[0016] Furthermore, the specific steps in step S4 include:
[0017] S41. Based on the thermal noise phase jitter signal, collecting a time domain jitter waveform, and outputting the time domain jitter waveform as a digital sequence;
[0018] S42. Generate a dynamic random sequence based on the digital sequence.
[0019] Since the digital sequence comes from random thermal noise, the generated dynamic random sequence is also random and dynamic, and is not easy to predict or model.
[0020] Furthermore, each element in the digital sequence satisfies the following expression:
[0021] ;
[0022] in, is the value of the element corresponding to the k-th sampling in the digital sequence, is the instantaneous noise voltage value corresponding to the kth sampling, is the preset sampling interval, =1μs, is the preset reference voltage.
[0023] This standardized conversion process ensures that the digital sequence accurately captures the random characteristics of thermal noise, providing a reliable digital input for the subsequent generation of high-quality dynamic random sequences.
[0024] Furthermore, each element in the dynamic random sequence satisfies the following expression:
[0025] ;
[0026] in, is the value of the mth element in the dynamic random sequence, Expressed as a pair Execute CRC16 algorithm processing, It is represented as a digital sequence consisting of 17-bit elements obtained from the 2mth to 2m+16th sampling times. Expressed as Performs AND operation with binary numbers.
[0027] The problem of insufficient randomness or statistical deviation that may exist when directly using the original digital sequence is solved, and a dynamic random sequence suitable for key generation is generated.
[0028] Furthermore, the specific steps in step S5 include:
[0029] S51. Perform an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate the composite key.
[0030] Furthermore, the specific steps in step S51 include:
[0031] S511. Generate the composite key according to the following expression:
[0032] ;
[0033] in, is the value of the nth element in the composite key, is the value of the nth element in the static hardware fingerprint, is the value of the nth element in the dynamic random sequence.
[0034] In a second aspect, the present invention provides a key generation system, comprising a hardware unit comprising an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix; the key generation system further comprises:
[0035] Static key generation module, used to execute steps S1-S2:
[0036] S1. By scanning the hardware unit, extracting the resonant frequency offset characteristics of each resonator; the resonant frequency offset characteristics include the offset between a plurality of target resonant frequencies and corresponding target values;
[0037] S2. Using the preset threshold corresponding to each target resonant frequency as an independent criterion, the offset is mapped to a binary bit based on a preset mapping rule to generate a multi-digit static hardware fingerprint;
[0038] Dynamic random number generation module, used to execute steps S3-S4:
[0039] S3 obtains the thermal noise phase jitter signal of each resonator;
[0040] S4. Based on the thermal noise phase jitter signal, a dynamic random sequence is generated;
[0041] The composite key output module is used to execute steps S5-S6:
[0042] S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence;
[0043] S6. Obtain a final key based on the composite key of all the resonators.
[0044] The key generation system provided by the present invention solves the deficiencies of the prior art in terms of key capacity, anti-attack and hardware size.
[0045] In a third aspect, the present invention provides a key generation device for use in a key generation system, wherein the key generation system includes a hardware unit comprising an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix; the key generation device includes:
[0046] an extraction module, configured to extract a resonant frequency offset characteristic of each of the resonators by scanning the hardware unit; the resonant frequency offset characteristic including offsets between a plurality of target resonant frequencies and corresponding target values;
[0047] A first generating module is configured to use a preset threshold value corresponding to each target resonant frequency as an independent criterion, map the offset into a binary bit based on a preset mapping rule, and generate a multi-digit static hardware fingerprint;
[0048] An acquisition module, configured to acquire a thermal noise phase jitter signal of each resonator;
[0049] A second generating module is configured to generate a dynamic random sequence based on the thermal noise phase jitter signal;
[0050] A third generation module is used to generate a composite key according to the static hardware fingerprint and the dynamic random sequence;
[0051] The composite module is used to obtain a final key according to the composite keys of all the resonators.
[0052] The key generation device provided by this invention utilizes an array structure to significantly increase the number of extractable physical features, thereby improving key capacity. It also leverages the randomness of the manufacturing process to provide hardware uniqueness. The dynamic randomness of thermal noise enhances the key's resistance to attack. The resonator-based structure allows for a smaller hardware footprint.
[0053] In a fourth aspect, the present invention provides an electronic device comprising a processor and a memory, wherein the memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps in the key generation method based on the SIP module provided in the first aspect are executed.
[0054] In a fifth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of the key generation method based on the SIP module provided in the first aspect are executed.
[0055] From the above, it can be seen that the key generation method based on the SIP module provided by the present invention utilizes resonators to form an array structure and combines threshold coding to obtain a larger key capacity, and further combines static fingerprints and dynamic noise to generate composite keys, effectively enhancing anti-interference and anti-attack capabilities. At the same time, the hardware unit can adopt a standard BAW manufacturing process, which can realize single-chip integrated communication filtering and security key functions, thereby effectively reducing the hardware volume and being suitable for small terminals.
[0056] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the embodiments of the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 A flow chart of a key generation method based on a SIP module provided in an embodiment of the present invention.
[0058] Figure 2 A schematic diagram of the structure of a key generation system provided by an embodiment of the present invention.
[0059] Figure 3 A schematic diagram of the structure of a key generation device provided by an embodiment of the present invention.
[0060] Figure 4 A schematic structural diagram of an electronic device provided by an embodiment of the present invention.
[0061] Description of labels:
[0062] 100. Static key generation module; 200. Dynamic random number generation module; 300. Composite key output module; 400. Extraction module; 500. First generation module; 600. Acquisition module; 700. Second generation module; 800. Third generation module; 900. Composite module; 13. Electronic device; 1301. Processor; 1302. Memory; 1303. Communication bus. DETAILED DESCRIPTION
[0063] The embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and are not to be construed as limiting the present invention.
[0064] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "thickness", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise" and the like to indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as limiting the present invention.
[0065] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; mechanical connections, electrical connections, or mutual communication; direct connections or indirect connections through an intermediate medium; and internal communication between two components or interaction between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0066] In the present invention, unless otherwise expressly specified or limited, a first feature being "above" or "below" a second feature may include the first and second features being in direct contact, or may include the first and second features being in contact not directly but through another feature between them. Furthermore, a first feature being "above," "above," and "above" a second feature may include the first feature being directly above or obliquely above the second feature, or may simply mean that the first feature is higher in level than the second feature. A first feature being "below," "below," and "below" a second feature may include the first feature being directly below or obliquely below the second feature, or may simply mean that the first feature is lower in level than the second feature.
[0067] The disclosure below provides many different embodiments or examples for realizing different structures of the present invention. In order to simplify the disclosure of the present invention, the components and settings of specific examples are described below. Of course, they are merely examples and are not intended to limit the present invention. In addition, the present invention may repeat reference numbers and / or reference letters in different examples. Such repetition is for the purpose of simplicity and clarity and does not in itself indicate the relationship between the various embodiments and / or settings discussed. In addition, the present invention provides examples of various specific processes and materials, but those skilled in the art will recognize the application of other processes and / or the use of other materials.
[0068] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of the embodiments. The components of the embodiments of the present invention generally described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present invention.
[0069] It should be noted that similar numbers and letters represent similar items in the following figures, so once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. In addition, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, features defined as "first" and "second" may explicitly or implicitly include one or more of the said features. In the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used to distinguish descriptions and are not to be understood as indicating or implying relative importance.
[0070] Reference Attachment Figure 1 The present invention provides a key generation method based on a SIP module, which is applied to a key generation system. The key generation system includes a hardware unit comprising an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix; the resonator includes a bottom electrode, a piezoelectric layer, and a top electrode stacked in sequence; the key generation method based on the SIP module includes the following steps:
[0071] S1. Extract the resonant frequency offset characteristics of each resonator by scanning the hardware unit. The resonant frequency offset characteristics include the offsets between multiple target resonant frequencies and corresponding target values. Due to random process errors (depending on the specific process, such as ±10nm) in the thickness of each layer during the resonator processing, different resonators have unique resonant frequency offset characteristics. The target resonant frequencies include series resonant frequency and parallel resonant frequency.
[0072] S2. Using the preset thresholds corresponding to the target resonant frequencies as independent criteria, the offsets are mapped to binary bits based on preset mapping rules to generate a multi-digit static hardware fingerprint;
[0073] S3. Obtain the thermal noise phase jitter signal of each resonator;
[0074] S4. Generate a dynamic random sequence based on the thermal noise phase jitter signal;
[0075] S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence;
[0076] S6. Obtain the final key based on the composite key of all resonators.
[0077] The hardware unit uses a two-dimensional matrix array composed of multiple resonators. Each resonator in the array can be independently accessed and controlled, and each resonator is connected to a row driver circuit and a column driver circuit, forming an independently addressable two-dimensional matrix. The resonator structure is formed by stacking a bottom electrode (made of materials such as Mo, Al, Ti, and Au), a piezoelectric layer (made of materials such as AlN, AlScN, ZnO2, PZT, and LN), and a top electrode (made of materials such as Mo, Al, Ti, and Au).
[0078] Step S1 measures and extracts the resonant frequency offset characteristics of each resonator in the array by scanning them. This characteristic is caused by random variations in the thickness of each layer during the manufacturing process, resulting in a unique frequency response for each resonator. The extracted characteristics include the offset of the series and parallel resonant frequencies relative to the target values (i.e., the preset target frequencies, which are ideal values).
[0079] Step S2 uses the frequency offset extracted in step S1 and refers to a preset threshold as a judgment standard to convert the continuous offset value into a discrete binary value through a mapping rule, thereby forming a static hardware fingerprint representing the inherent characteristics of the hardware.
[0080] Step S3 obtains the thermal noise phase jitter signal of each resonator in the working state. Thermal noise is an inherent random phenomenon of physical devices, and its phase jitter signal is unpredictable.
[0081] In step S4, based on the thermal noise phase jitter signal obtained in step S3, a time domain jitter waveform is acquired through an analog-to-digital converter (eg, a 12-bit ADC), and then a dynamic random sequence that varies with time is generated through entropy extraction.
[0082] Step S5 combines the static hardware fingerprint generated in step S2 with the dynamic random sequence generated in step S4, such as a bit-by-bit logical operation, to generate a composite key that combines the hardware's inherent identity information with real-time random change information.
[0083] Step S6 aggregates the composite keys generated by all resonators in the array and obtains the final key through a specific combination method (such as splicing or hashing).
[0084] Specifically, this method uses a resonator array as its physical foundation, extracting its inherent physical properties and real-time random noise to generate a key. First, each resonator in the array is scanned to measure the deviation of its series and parallel resonant frequencies from the target values. These deviations are caused by randomness in the manufacturing process and provide a unique physical fingerprint for each resonator. Using a preset threshold, these frequency deviations are converted into binary data to form a static hardware fingerprint. This portion of the key is relatively stable and reflects the identity of the hardware. Simultaneously, the thermal noise phase jitter signal generated by each resonator is obtained. This noise is random and varies over time. Based on this noise signal, a dynamic random sequence is generated. This portion of the key is highly random and unpredictable. The static hardware fingerprint and the dynamic random sequence are then combined, for example, through an XOR operation, to generate a composite key. This combination ensures that the generated key contains both the hardware's identity information and time-varying randomness, enhancing resistance to static attacks. Finally, the composite keys generated by all resonators in the array are aggregated to form the final key. The array structure significantly increases the number of physical features that can be extracted, thereby improving key capacity. The randomness of the manufacturing process is leveraged to provide hardware uniqueness. The dynamic randomness of thermal noise enhances the key's resistance to attack. The resonator-based structure allows for a smaller hardware footprint. This approach addresses the shortcomings of existing technologies in key capacity, attack resistance, and hardware size.
[0085] In some specific embodiments, a 32x32 resonator array can be used as a hardware unit. Each resonator is independently addressed by a row select line and a column select line. In step S1, each selected resonator is frequency scanned by a radio frequency scanning circuit, its impedance characteristic curve is measured, and the series resonant frequency and the parallel resonant frequency are extracted therefrom. For example, the target value of the series resonant frequency is set to f_s0, and the target value of the parallel resonant frequency is set to f_p0. The actual series frequency f_s and parallel frequency f_p are measured. The offsets Δf_s=f_s-f_s0 and Δf_p=f_p-f_p0 are calculated. In step S2, two thresholds T_s and T_p are preset. The mapping rules are set as:
[0086] Δf_s>T_s, then b1=1; where b1 is the first bit key generated by the resonator;
[0087] Δf_s≤T_s, then b1=0;
[0088] Δf_p>T_p, then b2=1; where b2 is the second key generated by the resonator;
[0089] Δf_p≤T_p, then b2=0;
[0090] Thus, the key combination is b1b2∈{11,10,01,00}, and each resonator can generate four 2-bit static hardware fingerprints (that is, the entire 32*32 resonator array can generate 32*32*4=4096 static hardware fingerprints, with a length of 32*32*2=2048 bits). In step S3, the thermal noise signal output by the resonator is collected using a low-noise amplifier and an analog-to-digital converter, and phase jitter information is extracted from it. In step S4, the collected digitized phase jitter signal is processed, such as by performing a cyclic redundancy check (CRC) or other post-processing algorithm, to generate a dynamic random sequence. In step S5, the static hardware fingerprint is XORed with the dynamic random sequence to generate a composite key for the resonator. In step S6, the composite keys generated by all resonators in the array are concatenated to obtain the final key.
[0091] In this embodiment, the relevant hardware design is suitable for the BAW (bulk acoustic wave) preparation process, and a single chip realizes integrated communication filtering and security key functions. Taking a 32x32 bulk acoustic wave resonator as an example, the chip area of its hardware unit is only 1 square millimeter.
[0092] It should be noted that in actual application, two thresholds can be set to perform dual-threshold encoding to form a static hardware fingerprint as described above, or more groups of thresholds can be set to perform multi-threshold encoding to form more static hardware fingerprints.
[0093] In some embodiments, the specific steps in step S4 include:
[0094] S41. Based on the thermal noise phase jitter signal, a time domain jitter waveform is collected and the time domain jitter waveform is output as a digital sequence;
[0095] S42. Generate a dynamic random sequence based on the digital sequence.
[0096] The raw data used to generate the random sequence is obtained from the thermal noise phase jitter signal. By acquiring the time-domain jitter waveform of the thermal noise phase jitter signal, the continuous analog signal is converted into a discrete digital sequence. This step converts the analog noise signal into digital form, laying the foundation for subsequent digital processing. The acquisition and output of the time-domain jitter waveform as a digital sequence digitally represents the randomness of the noise. Using the resulting digital sequence as input, a specific algorithm or processing procedure is executed to generate the final dynamic random sequence. This digital sequence incorporates the random characteristics of thermal noise. Generating a dynamic random sequence based on this digital sequence ensures both randomness and dynamism.
[0097] Specifically, this technical solution addresses the problem of converting a thermal noise phase jitter signal into a format suitable for generating a dynamic random sequence. First, by acquiring the time-domain jitter waveform of the thermal noise phase jitter signal, the continuously varying analog signal is sampled at preset time intervals. This results in a series of instantaneous signal values at specific time points. These instantaneous values are then converted into corresponding digital values using an analog-to-digital converter. These digital values are arranged in the chronological order of sampling to form a digital sequence. This digital sequence retains the random characteristics of the original thermal noise phase jitter signal, but is in the digital domain, facilitating subsequent digital processing. Based on this digital sequence, a specific algorithm or function is then applied to generate a dynamic random sequence. For example, the digital sequence can be grouped, and a calculation or transformation performed on each group of data to produce one or more output bits, which together constitute the dynamic random sequence. Because the digital sequence originates from the random nature of thermal noise, the generated dynamic random sequence also exhibits randomness and dynamicity, making it difficult to predict or model.
[0098] In some specific embodiments, the thermal noise phase jitter signal is amplified and filtered by an analog front-end circuit. The processed analog signal is input into an analog-to-digital converter (ADC). The ADC samples the analog signal at a preset sampling rate, for example, 1 MHz. The ADC has a certain resolution, for example, 12 bits. Each sample converts the instantaneous voltage value of the analog signal into a 12-bit digital codeword. These digital codewords are stored in a buffer in the sampling order, forming a digital sequence. For example, collecting 1024 sampling points yields a sequence of 1024 12-bit numbers. This digital sequence is then fed into a processing unit. The processing unit divides the digital sequence into multiple subsequences, for example, each subsequence consists of 16 numbers. A preset function is applied to each subsequence, for example, calculating the sum of all numbers in the subsequence. The least significant bit of the result is then taken as a bit of the dynamic random sequence. This process is repeated until the entire digital sequence is processed, generating a dynamic random sequence of the corresponding length. Thus, the analog thermal noise signal is converted into a usable digital random sequence.
[0099] In some embodiments, each element in the digital sequence satisfies the following expression:
[0100] ;
[0101] in, is the value of the element corresponding to the kth sampling in the digital sequence, is the instantaneous noise voltage value corresponding to the kth sampling, is the preset sampling interval, =1μs, is the preset reference voltage.
[0102] This expression defines the specific quantization process of converting the analog time-domain jitter waveform into a discrete digital sequence. Represents the analog noise voltage signal obtained at a specific sampling time. As a reference voltage, it is used to scale the instantaneous noise voltage and realize normalization. The normalized ratio is multiplied by 4096 (the quantization level of ADS, 2 9 = 4096), which maps the analog voltage range to a specific integer range in the digital domain. This scaling factor is typically related to the resolution of the analog-to-digital converter. The square brackets indicate a rounding operation, which quantizes the scaled result to a discrete integer value, forming an element of the digital sequence. = 1μs specifies a fixed sampling interval, ensuring that data points are extracted from the time-domain jitter waveform at a constant rate. This provides a standardized and repeatable method for digitizing analog noisy signals.
[0103] Specifically, this solution provides a clear mathematical expression to define the conversion process when converting analog time-domain jitter waveforms into discrete digital sequences, which may cause randomness loss or deviation due to uncertainty in the quantization method. , collect instantaneous noise voltage. This voltage value is consistent with the preset reference voltage Compare and normalize. The normalized value is multiplied by the scaling factor 4096 to map the analog signal range to the digital representation range. Finally, the result is quantized to an integer by rounding. This process occurs at each sampling interval. This process is repeated to convert the continuous analog time-domain jitter waveform into a series of discrete digital values, forming a digital sequence. This standardized conversion process ensures that the digital sequence accurately captures the random characteristics of thermal noise, providing a reliable digital input for the subsequent generation of high-quality dynamic random sequences.
[0104] In some embodiments, each element in the dynamic random sequence satisfies the following expression:
[0105] ;
[0106] in, is the value of the mth element in the dynamic random sequence, Expressed as a pair Execute CRC16 algorithm processing, It is represented as a digital sequence consisting of 17-bit elements obtained from the 2mth to 2m+16th sampling times. Expressed as Performs AND operation with binary numbers.
[0107] This embodiment aims to generate a dynamic random sequence with better random characteristics by performing specific processing on the digital sequence obtained from the thermal noise phase jitter signal. As input, a sequence of numbers It is obtained by sampling and quantizing the thermal noise signal. In order to generate a dynamic random sequence , the scheme selects a digital sequence A continuous segment , the segment contains 17 bits. The CRC16 algorithm is performed on this 17-bit segment. The CRC16 algorithm is a cyclic redundancy check algorithm that performs polynomial operations on the input data to generate a check value. Although CRC is mainly used for error detection, its operation process has the effect of mixing the input data bits, which can disrupt the simple correlation in the input data and disperse the randomness of the input segment into the output check value. After obtaining the CRC16 processing result, it is compared with the binary number Perform a bitwise AND operation. The bitwise AND operation with 0x01 extracts the least significant bit of the CRC16 result. Extracting the least significant bit helps convert the multi-bit CRC result into a single-bit random sequence element and may remove some statistical bias in the CRC result. Repeat the above CRC16 processing and bitwise AND operation with 0x01 for different segments (the starting position is determined by m) to generate a dynamic random sequence This processing method utilizes the hybrid characteristics of the CRC algorithm to enhance randomness, and by extracting the least significant bit for binarization and deviation elimination, it solves the problems of insufficient randomness or statistical deviation that may exist when directly using the original digital sequence, and generates a dynamic random sequence suitable for key generation.
[0108] Specifically, the time domain jitter waveform is acquired from the thermal noise phase jitter signal of the resonator and output as a digital sequence The number sequence The elements in may have certain correlation or statistical deviation, which is not directly suitable as a high-quality random sequence. In order to solve this problem, a processing method is adopted. This method is used to calculate the number of random sequences. Select a segment containing 17 consecutive elements from , for example, to generate , select from arrive . The CRC16 algorithm is performed on the digital sequence fragment composed of the selected 17-bit elements. The CRC16 algorithm performs a polynomial calculation on the input data to generate a 16-bit check value. This calculation process can effectively mix the bits in the input data. Even if there is a weak correlation between the elements in the input data fragment, the output check value has better random distribution characteristics after CRC16 processing. Further, the 16-bit output result of the CRC16 algorithm is bitwise ANDed with the binary number 0x01. This operation extracts the least significant bit of the CRC16 result. By extracting the least significant bit, the 16-bit CRC result is converted into a single-bit binary value, that is This process not only achieves binarization, but also the least significant bit usually has better randomness than the high bit, which helps to eliminate the statistical deviation that may exist in the CRC result. The fragment selection, CRC16 processing and bitwise AND operation with 0x01 are repeated at different starting positions (controlled by m) to generate a series of binary values of units to form a dynamic random sequence. Compared with the original digital sequence, the dynamic random sequence It has enhanced randomness and can meet the needs of generating high-quality dynamic random sequences, thereby solving the problem of insufficient random characteristics of the original digital sequence.
[0109] In some embodiments, it is assumed that the digital sequence acquired and quantized from the thermal noise phase jitter signal To generate the first element of a dynamic random sequence, , select a sequence of numbers The 17-bit elements from index 2*0=0 to 2*0+16=16 in . Take the sequence of 17 elements as input, execute the CRC16 algorithm to get a 16-bit CRC check value. For example, suppose The result of executing the CRC16 algorithm is the binary number 0110101100101101. Further, the CRC result is bitwise ANDed with the binary number 0x01 (i.e. binary 0000000000000001). 0110101100101101 & 00000000000000001 = 00000000000000001. Therefore, is determined to be 1. In order to generate the next element of the dynamic random sequence , select a sequence of numbers The 17-bit elements from index 2*1=2 to 2*1+16=18 in .right Execute the CRC16 algorithm to get another 16-bit CRC check value. Perform a bitwise AND operation on this check value and 0x01 to get Repeat this process and by changing the value of m, you can get Extract different 17-bit element fragments, process them with CRC16 and perform bitwise AND operation with 0x01 to generate the entire dynamic random sequence This implementation effectively improves the randomness of the generated sequence by segmenting the original digital sequence, mixing it with CRC16, and extracting the least significant bit for binarization.
[0110] In some embodiments, the specific steps in step S5 include:
[0111] S51. Perform an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate a composite key.
[0112] The static hardware fingerprint is a multi-digit binary sequence, and the dynamic random sequence is a multi-digit binary sequence. The process of generating a composite key involves performing an XOR operation on each bit of the static hardware fingerprint with the corresponding bit of the dynamic random sequence. An XOR operation is a logical operation where the result is 1 when the two input bits are different and 0 when the two input bits are the same. Through this bit-by-bit operation, the uniqueness of the static hardware fingerprint and the randomness of the dynamic random sequence are combined into the composite key.
[0113] Specifically, during the key generation process, a static hardware fingerprint of each resonator is first obtained. This fingerprint reflects the inherent physical properties of the resonator. Simultaneously, a dynamic random sequence is generated based on the phase jitter signal of the resonator's thermal noise, which exhibits temporal random variability. To generate a composite key, the binary bit sequence of the static hardware fingerprint is XORed with the binary bit sequence of the dynamic random sequence. For example, the nth bit of the static hardware fingerprint is XORed with the nth bit of the dynamic random sequence to obtain the nth bit of the composite key. This process is repeated for all bits until a complete composite key is generated. Thus, the composite key inherits the binding relationship between the static hardware fingerprint and a specific hardware unit while incorporating the unpredictability of the dynamic random sequence. This combination ensures that the generated composite key has both hardware-related uniqueness and time-varying randomness, enhancing key security and effectively combating modeling attacks and side-channel attacks targeting a single static fingerprint.
[0114] In some embodiments, it is assumed that a static hardware fingerprint generated by a resonator is a binary sequence =10110100, the dynamic random sequence obtained is a binary sequence =01101011. Generate a composite key The process is to and Perform bit-by-bit XOR operation. The specific operation is as follows:
[0115] :10110100
[0116] :01101011
[0117] -----------------------(XOR operation)
[0118] :11011111
[0119] The resulting composite key is the binary sequence 11011111. This composite key combines the fixed nature of a static fingerprint with the random nature of a dynamic sequence. Dynamic random sequences obtained at different times will vary, and therefore the resulting composite key will also vary, making it more difficult for attackers to predict the key.
[0120] In some embodiments, the specific steps in step S51 include:
[0121] S511. Generate a composite key based on the following expression:
[0122] ;
[0123] in, is the value of the nth element in the composite key, is the value of the nth element in the static hardware fingerprint, is the value of the nth element in the dynamic random sequence.
[0124] This expression defines how the composite key is generated. Represents a static hardware fingerprint extracted from the inherent physical characteristics of the hardware. Represents the dynamic random sequence part extracted from the hardware thermal noise phase jitter signal. ⊕ represents the bitwise exclusive OR logic operation. Thus, the corresponding part of the generated composite key , by using static hardware fingerprint Corresponding part of dynamic random sequence This operation combines the inherent uniqueness of the hardware with the randomness of the noise.
[0125] Specifically, during the key generation process, a static hardware fingerprint generated by the inherent characteristics of the hardware is first obtained. At the same time, obtain the dynamic random sequence generated by hardware thermal noise To generate a composite key, the static hardware fingerprint With dynamic random sequence Perform bit-by-bit XOR operation. This operation is performed according to the above expression. Thus, the composite key corresponding to the nth sampling is generated. This method provides a clear calculation rule that solves the problem of how to specifically combine static fingerprints and dynamic sequences, ensuring the feasibility of the composite key generation process. By combining the uniqueness of static hardware fingerprints with the randomness of dynamic random sequences, the security of the generated key is enhanced.
[0126] Reference Attachment Figure 2 The present invention provides a key generation system, comprising a hardware unit comprising an array of multiple resonators, wherein the array is a two-dimensional matrix that can be addressed independently; the key generation system further comprises:
[0127] The static key generation module 100 is used to execute steps S1-S2:
[0128] S1. Extracting the resonant frequency offset characteristics of each resonator by scanning the hardware unit; the resonant frequency offset characteristics include the offset between multiple target resonant frequencies and corresponding target values;
[0129] S2. Using the preset thresholds corresponding to the target resonant frequencies as independent criteria, the offsets are mapped to binary bits based on preset mapping rules to generate a multi-digit static hardware fingerprint;
[0130] The dynamic random number generation module 200 is used to execute steps S3-S4:
[0131] S3. Obtain the thermal noise phase jitter signal of each resonator;
[0132] S4. Generate a dynamic random sequence based on the thermal noise phase jitter signal;
[0133] The composite key output module 300 is used to execute steps S5-S6:
[0134] S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence;
[0135] S6. Obtain the final key based on the composite key of all resonators.
[0136] In some embodiments, the dynamic random number generation module 200 performs the following when executing step S4:
[0137] S41. Based on the thermal noise phase jitter signal, a time domain jitter waveform is collected and the time domain jitter waveform is output as a digital sequence;
[0138] S42. Generate a dynamic random sequence based on the digital sequence.
[0139] In some embodiments, when the composite key output module 300 is used to perform step S5, it performs:
[0140] S51. Perform an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate a composite key.
[0141] In some embodiments, the composite key output module 300 performs the following operations when performing an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate the composite key:
[0142] S511. Generate a composite key based on the following expression:
[0143] ;
[0144] in, is the value of the nth element in the composite key, is the value of the nth element in the static hardware fingerprint, is the value of the nth element in the dynamic random sequence.
[0145] Please refer to Figure 3 , Figure 3 In some embodiments of the present invention, a key generation device is used in a key generation system. The key generation device is integrated into a back-end control device in the form of a computer program. The key generation system includes a hardware unit comprising an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix. The key generation device includes:
[0146] An extraction module 400 is configured to extract a resonant frequency offset characteristic of each resonator by scanning the hardware unit; the resonant frequency offset characteristic includes an offset between a plurality of target resonant frequencies and corresponding target values;
[0147] The first generating module 500 is configured to use the preset thresholds corresponding to the target resonant frequencies as independent criteria, map the offsets to binary bits based on preset mapping rules, and generate a multi-digit static hardware fingerprint;
[0148] An acquisition module 600 is configured to acquire a thermal noise phase jitter signal of each resonator;
[0149] The second generating module 700 is configured to generate a dynamic random sequence based on the thermal noise phase jitter signal;
[0150] The third generation module 800 is used to generate a composite key based on the static hardware fingerprint and the dynamic random sequence;
[0151] The composite module 900 is used to obtain a final key based on the composite keys of all resonators.
[0152] In some embodiments, when used to generate a dynamic random sequence based on a thermal noise phase jitter signal, the second generating module 700 performs:
[0153] S41. Based on the thermal noise phase jitter signal, a time domain jitter waveform is collected and the time domain jitter waveform is output as a digital sequence;
[0154] S42. Generate a dynamic random sequence based on the digital sequence.
[0155] In some embodiments, the third generation module 800 performs the following when generating a composite key based on a static hardware fingerprint and a dynamic random sequence:
[0156] S51. Perform an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate a composite key.
[0157] In some embodiments, the third generation module 800 performs the following when performing an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate a composite key:
[0158] S511. Generate a composite key based on the following expression:
[0159] ;
[0160] in, is the value of the nth element in the composite key, is the value of the nth element in the static hardware fingerprint, is the value of the nth element in the dynamic random sequence.
[0161] Please refer to Figure 4 , Figure 4 This is a schematic structural diagram of an electronic device provided in an embodiment of the present invention. The present invention provides an electronic device 13, comprising: a processor 1301 and a memory 1302. The processor 1301 and the memory 1302 are interconnected and communicate with each other via a communication bus 1303 and / or other connection mechanism (not shown). The memory 1302 stores computer-readable instructions executable by the processor 1301. When the electronic device is in operation, the processor 1301 executes the computer-readable instructions to perform the SIP module-based key generation method in any optional implementation of the above-mentioned embodiment, thereby achieving the following functions: extracting a resonant frequency offset characteristic of each resonator by scanning hardware units; the resonant frequency offset characteristic includes offsets between multiple target resonant frequencies and corresponding target values; using preset thresholds corresponding to each target resonant frequency as independent criteria, mapping the offsets to binary bits based on preset mapping rules to generate a multi-digit static hardware fingerprint; obtaining a thermal noise phase jitter signal for each resonator; generating a dynamic random sequence based on the thermal noise phase jitter signal; generating a composite key based on the static hardware fingerprint and the dynamic random sequence; and obtaining a final key based on the composite keys of all resonators.
[0162] An embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the key generation method based on the SIP module in any optional implementation of the above embodiment is executed to achieve the following functions: extracting the resonant frequency offset characteristics of each resonator by scanning the hardware unit; the resonant frequency offset characteristics include the offsets between multiple target resonant frequencies and corresponding target values; using the preset thresholds corresponding to each target resonant frequency as independent criteria, mapping the offsets to binary bits based on preset mapping rules to generate a multi-digit static hardware fingerprint; obtaining the thermal noise phase jitter signal of each resonator; generating a dynamic random sequence based on the thermal noise phase jitter signal; generating a composite key based on the static hardware fingerprint and the dynamic random sequence; and obtaining a final key based on the composite keys of all resonators.
[0163] Among them, the computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0164] In the embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed may be through some communication interface, the indirect coupling or communication connection of the device or unit may be electrical, mechanical or other forms.
[0165] In addition, the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0166] Furthermore, the functional modules in the various embodiments of the present invention may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.
[0167] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.
[0168] Descriptions with reference to the terms "one embodiment," "certain embodiments," "illustrative embodiments," "examples," "specific examples," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, illustrative uses of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0169] The foregoing description is merely an embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A key generation method based on a SIP module, applied to a key generation system, characterized in that: The key generation system includes a hardware unit composed of an array of multiple resonators, wherein the array is an independently addressable two-dimensional matrix; the key generation method based on the SIP module includes the following steps: S1. By scanning the hardware unit, extracting the resonant frequency offset characteristics of each resonator; the resonant frequency offset characteristics include the offset between a plurality of target resonant frequencies and corresponding target values; S2. Using the preset threshold corresponding to each target resonant frequency as an independent criterion, the offset is mapped to a binary bit based on a preset mapping rule to generate a multi-digit static hardware fingerprint; S3 obtains the thermal noise phase jitter signal of each resonator; S4. Based on the thermal noise phase jitter signal, a dynamic random sequence is generated; S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence; S6. Obtain a final key based on the composite key of all the resonators.
2. The key generation method based on the SIP module according to claim 1, characterized in that: The specific steps in step S4 include: S41. Based on the thermal noise phase jitter signal, collecting a time domain jitter waveform, and outputting the time domain jitter waveform as a digital sequence; S42. Generate a dynamic random sequence based on the digital sequence.
3. The key generation method based on the SIP module according to claim 2, characterized in that: Each element in the digital sequence satisfies the following expression: ; in, is the value of the element corresponding to the k-th sampling in the digital sequence, is the instantaneous noise voltage value corresponding to the kth sampling, is the preset sampling interval, =1μs, is the preset reference voltage.
4. The key generation method based on the SIP module according to claim 2, characterized in that: Each element in the dynamic random sequence satisfies the following expression: ; in, is the value of the mth element in the dynamic random sequence, Expressed as a pair Execute CRC16 algorithm processing, It is represented as a digital sequence consisting of 17-bit elements obtained from the 2mth to 2m+16th sampling times. Expressed as Performs AND operation with binary numbers.
5. The key generation method based on the SIP module according to claim 1 is characterized in that: The specific steps in step S5 include: S51. Perform an XOR logic bit-by-bit operation on the static hardware fingerprint and the dynamic random sequence to generate the composite key.
6. The key generation method based on the SIP module according to claim 5, characterized in that: The specific steps in step S51 include: S511. Generate the composite key according to the following expression: ; in, is the value of the nth element in the composite key, is the value of the nth element in the static hardware fingerprint, is the value of the nth element in the dynamic random sequence.
7. A key generation system, characterized in that: A hardware unit comprising an array of a plurality of resonators, wherein the array is a two-dimensional matrix that can be addressed independently; the key generation system further comprising: Static key generation module, used to execute steps S1-S2: S1. By scanning the hardware unit, extracting the resonant frequency offset characteristics of each resonator; the resonant frequency offset characteristics include the offset between a plurality of target resonant frequencies and corresponding target values; S2. Using the preset threshold corresponding to each target resonant frequency as an independent criterion, the offset is mapped to a binary bit based on a preset mapping rule to generate a multi-digit static hardware fingerprint; Dynamic random number generation module, used to execute steps S3-S4: S3 obtains the thermal noise phase jitter signal of each resonator; S4. Based on the thermal noise phase jitter signal, a dynamic random sequence is generated; The composite key output module is used to execute steps S5-S6: S5. Generate a composite key based on the static hardware fingerprint and the dynamic random sequence; S6. Obtain a final key based on the composite key of all the resonators.
8. A key generation device, applied to a key generation system, characterized in that: The key generation system includes a hardware unit comprising an array of multiple resonators, wherein the array is a two-dimensional matrix that can be addressed independently; the key generation device includes: an extraction module, configured to extract a resonant frequency offset characteristic of each of the resonators by scanning the hardware unit; the resonant frequency offset characteristic including offsets between a plurality of target resonant frequencies and corresponding target values; A first generating module is configured to use a preset threshold value corresponding to each of the target resonant frequencies as an independent criterion, map the offset to a binary bit based on a preset mapping rule, and generate a multi-digit static hardware fingerprint; An acquisition module, configured to acquire a thermal noise phase jitter signal of each resonator; A second generating module is configured to generate a dynamic random sequence based on the thermal noise phase jitter signal; A third generation module is used to generate a composite key according to the static hardware fingerprint and the dynamic random sequence; The composite module is used to obtain a final key according to the composite keys of all the resonators.
9. An electronic device, characterized in that: The invention comprises a processor and a memory, wherein the memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps of the key generation method based on the SIP module according to any one of claims 1 to 6 are executed.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the key generation method based on the SIP module are executed.
Citation Information
Patent Citations
Lightweight key unit design method based on PCIe architecture
CN119070988A
Resonator phase noise suppression method based on Kalman filtering
CN119254189A