Distributed network with decentralized integrated random number generation devices
By equipping each node of the distributed network with a hardware-based quantum random number generator and employing a vertically integrated structure of entropy source and single-photon detector, the security vulnerabilities of centralized quantum random number generators are solved, achieving efficient and reliable random number generation and improving network security and scalability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ELMOS SEMICON AG
- Filing Date
- 2024-09-19
- Publication Date
- 2026-05-05
AI Technical Summary
In existing technologies, centralized quantum random number generators are easy targets for attacks, leading to security vulnerabilities. Furthermore, they are difficult to use in distributed networks to achieve efficient and reliable random number generation, which affects network security, robustness, and scalability.
Each node is equipped with a hardware-based quantum random number generator, employing a vertically integrated structure of entropy source and single-photon detector to achieve distributed entropy generation, ensuring that each node independently generates high-quality random numbers, and improving network security and scalability through distributed architecture and fault identification and recovery mechanisms.
It enables the autonomous generation of high-quality random numbers in distributed networks, improving network security, robustness, and scalability, reducing the risk of single points of failure, and ensuring the integrity and security of the network in dynamic environments.
Smart Images

Figure CN121986321A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a distributed network with a distributed integrated random number generator, and more particularly to a distributed network with a distributed integrated random number generator having a high random bit data rate, for ensuring network security and robustness.
[0002] A distributed network is proposed, in which each node is equipped with a corresponding, preferably integrated, hardware-based quantum random number generator with a particularly high random bit data rate. In today's networked world, secure and reliable generation of random numbers is becoming increasingly important, especially in distributed networks where nodes do not have a central monitoring authority. In such networks, security often depends directly on the quality and unpredictability of the random numbers used for encryption, authentication, and other security-related operations. However, centralized quantum random number generators can become attractive targets for attacks, potentially leading to serious security vulnerabilities. These weaknesses are eliminated by this invention by distributing the random number generation devices across each node of the network.
[0003] Such quantum random number generators for corresponding nodes in a network with distributed entropy generation preferably each include an entropy source monolithically fabricated in a corresponding semiconductor substrate (i.e., a network-suitable device on the corresponding node) of the corresponding node. The entropy source includes a photon source and a single-photon detector, arranged perpendicular to each other and perpendicular to the surface of the relevant semiconductor substrate, thereby enabling particularly high random number data rates. The corresponding quantum random number generator preferably includes corresponding components for operating the corresponding entropy source, and more preferably includes corresponding components for generating quantum random numbers based on the corresponding entropy source output signal. These quantum random number generators are characterized in that the corresponding photon source and the corresponding single-photon detector of the corresponding entropy source of the corresponding quantum random number generator are arranged vertically relative to each other in the semiconductor substrate of the quantum random number generator, which ensures that the generated random numbers are actually random, unpredictable, and have high entropy. By distributing these quantum random number generators across all nodes of the network, a distributed architecture is achieved, which has significant advantages in terms of network security, robustness, and scalability.
[0004] The corresponding quantum random number generators are preferably implemented as a single unit. The corresponding semiconductor substrate of the corresponding quantum random number generator preferably includes a corresponding entropy source fabricated in the corresponding semiconductor substrate of the corresponding quantum random number generator, and a component for converting the entropy source signal of the entropy source into a random bit data stream. These components preferably include one or more of the following devices: one or more analog amplifiers and / or filter circuits for processing the entropy output signal for subsequent analog-to-digital conversion; one or more bit analog-to-digital converters, which, in the case of a one-bit analog-to-digital converter, may be implemented by a comparator; one or more time / digital converters and / or one or more time / pseudo-random number converters for mapping a unique binary number to a time interval between two pulses of the entropy source; one or more entropy extraction devices for extracting one or more random bits from these binary numbers; one or more finite automata (i.e., so-called finite state machines) for converting the data stream of random bits into random numbers; one or more interfaces for providing access to these random numbers and / or control of the quantum random number generator to one or more external computer systems; one or more means for implementing and / or supporting health checks on one or more devices and their cooperation; and one or more devices for generating internal operating voltages within the quantum random number generator to operate the quantum random number generator.
[0005] The corresponding quantum random number generator is preferably an integrated quantum random number generator (iQRNG), particularly a photonic QRNG monolithically constructed in a shared semiconductor substrate within the same material system in a scalable and fully integrated manner. It consists of a photon source and a detector for single photons directly coupled to the source, and is implemented in a particularly compact and attack-resistant manner on a technology platform for semiconductor structuring that is open for a wide range of applications.
[0006] The fundamental concept of this invention is that each node in a distributed network possesses an inherent hardware-based quantum random number generator that operates independently, thereby contributing to the network's overall entropy and security. This significantly improves security because there is no central component that could be compromised and compromise the entire network. Each node can autonomously generate random numbers that can be used for various security-related applications within the network, such as generating encryption keys, initialization vectors (IVs), one-time passwords (OTPs), and supporting security protocols such as TLS (Transport Layer Security) or IPsec (Internet Protocol Security).
[0007] By using distributed random number generators, the network is also more resilient to the failure of individual nodes because its functionality does not depend on the availability or security of a central node. Even in the event of an attack or a failure of a node, other nodes in the network can continue to function normally and continue to generate and use secure random numbers.
[0008] Another advantage of this distributed architecture is the network's scalability. New nodes can be easily added, each carrying its own inherent source of random numbers. This allows the network to scale flexibly and efficiently without compromising performance or security. The load on the random number generator and other security-related processes is evenly distributed across the network, thus avoiding bottlenecks and performance penalties.
[0009] This invention also includes various fault identification and recovery mechanisms that ensure continuous network monitoring and response to anomalies in random number generation. Upon identification of a problem, an automatic recovery process can be initiated to maintain network integrity and security.
[0010] In summary, this invention provides a robust and secure solution for the generation and utilization of random numbers in distributed networks. It addresses the weaknesses of centralized random number generation systems and ensures network integrity and security even in dynamic and ever-changing environments. The distributed architecture based on a hardware-based quantum random number generator on each node offers significant advantages in security, robustness, and scalability, making this invention a pioneering solution for modern distributed networks. Background Technology
[0011] Securely and efficiently generating random numbers in distributed networks is a major challenge for modern network technology. The importance of random numbers extends from encryption to ensuring the authenticity and integrity of data. However, existing technologies have various shortcomings, which may cause potential security risks, performance bottlenecks, and scalability issues.
[0012] Quantum random number generator In many scientific and technological fields, the determination of random events and probabilities plays a particularly prominent role. Monte Carlo simulations and secure encryption methods, for example, rely heavily on the provision of random numbers. In this context, so-called pseudo-random numbers are typically distinguished from true random numbers. The former are generated by pseudo-random number generators (PRNGs) using deterministic formulas, meaning they are not absolutely random. True random number generators (TRNGs), used to provide true random numbers, are typically based on real, unpredictable processes, such as thermal or atmospheric noise, rather than artificially generated patterns based on deterministic algorithms. However, depending on the underlying random elements, the results of such non-deterministic random number generators based on extrinsic parameters may, due to weak correlation, still tend slightly towards larger or even numbers, thus making the generated random numbers at least partially predictable.
[0013] Quantum random number generators (QRNGs), a special subgroup of TRNGs, are based on the fundamental quantum process of random number generation and are therefore, at least theoretically, independent of other external factors and effects affecting statistics. Thus, quantum random number generators are currently the best available source for truly random numbers. In this context, current digital quantum random number generators can provide entropy rates (i.e., bit sequences with maximum randomness or entropy) of up to hundreds of Mbps. For both traditional encryption and many quantum information science and quantum cryptography methods, the generated random numbers are required to ensure secure key exchange (SKD / QKD). Therefore, unmanipulated, fast QRNGs are absolutely essential for generating secure keys in cryptography.
[0014] Based on the particularly simple implementability of QRNGs, many QRNGs are implemented as photonic QRNGs by leveraging randomness. In this case, a simple concept for generating random numbers is the behavior of photons being reflected or transmitted independently of other photons in a semi-transparent beamguide. Another approach is to utilize the random arrival times of photons on a single-photon detector. This distribution effect, based on the inherent photon statistics of photons from a correlated photon source, which is in principle impossible to calculate deterministically, can also be used to provide truly random numbers with high entropy. The arrival times of photons on a single-photon detector typically follow an exponential distribution.
[0015] In a typical single-photon detector (SPD), a detector pulse is first generated from a single incident photon. This detector pulse is then converted into a timestamped digital representation of the detector event in a time-to-digital converter (TDC) and can be further processed accordingly. In this case, laser diodes (LDs) or simple light-emitting diodes (LEDs) with significantly attenuated single-photon levels are typically used as the photon source or entropy source in the QRNG. The photons emitted by this photon source or entropy source can then be detected in a time-resolved manner by one or more particularly sensitive single-photon avalanche diodes (SPADs) acting as the SPD. In this application, such photon sources that simultaneously provide only one or more photons are also referred to as single-photon sources (SPS). However, it is not necessarily a true single-photon emitter, such as a two-level system based on a single isolation.
[0016] SPADs are photodetectors similar to photodiodes (PDs) and avalanche photodiodes (APDs), but with significantly improved sensitivity. SPADs can be read out and evaluated digitally, even within shared integrated circuits. When such an integrated detector circuit is excited by a single photon, only one electron-hole pair is generated for each excited photon in the sensing active region (absorption region), where the excited electron is drawn to the cathode by an electric field, and the excited hole to the anode. In this case, with respect to SPADs, charge carriers drift through the so-called avalanche region, where charge avalanche is generated through enhanced impact ionization. Therefore, it is a highly sensitive photon receiver element, capable of providing a high charge quantity (approximately 10⁻⁶) upon startup. 5 -10 6 (Electrons) and high temporal resolution.
[0017] SPADs typically operate in Geiger mode above their breakdown voltage, where single photons are detected by the resulting charge avalanche and subsequently recorded as a single event. To reduce dead time during recording, further charge carrier amplification can be actively or passively suppressed or quenched immediately after avalanche formation. Besides SPADs, integrated circuits can also include so-called single-photon counters (SPCs), in which case, instead of directly outputting a single detector pulse, a direct statistical evaluation of the temporal distribution of the measured single-photon event is typically performed.
[0018] In this application, the term quantum random number generator (QRNG) is primarily understood as an abstract definition of a device that provides digitally detectable quantized random events. In this context, a quantum random number generator always includes a so-called entropy source, i.e., the element that actually provides such random events (e.g., an SPS alone or in combination with an SPD). However, the term quantum random number generator is not limited to an entropy source, but may also include, for example, the environment and structural layout of the entropy source within the device or substrate. This term also typically includes corresponding control and evaluation circuitry or an overall circuit layout or logic module for actually outputting random events as directly processable random numbers. These random numbers can be generated directly from the statistics of the entropy source or, for example, by conversion into random values that can be derived therefrom through additional measures. To better distinguish the abstract definition from real circuitry, for simplicity, the latter will also be referred to in part below as a quantum random number generator. However, this is not intended to limit the two terms mentioned above, but merely to emphasize the different aspects. In this regard, the terms quantum random number generator and quantum random number generator can also refer to the same device (i.e., a quantum random number generator as a circuit element as commonly understood), where both devices include at least one entropy source. Therefore, in a circuit block diagram (i.e., at the circuit level), the quantum random number generator according to the invention is also simply referred to as an entropy source, while for better distinction, the circuit represented by the block diagram for outputting directly processable random numbers is called a quantum random number generator.
[0019] The substrate of a quantum random number generator does not necessarily need to include any other components for forming the quantum random number generator; rather, this substrate may simply be a single semiconductor crystal comprising one or more entropy sources. In this case, other components of the quantum random number generator may also be provided externally, for example, on a different substrate.
[0020] For example, statistical evaluations performed in parallel with random number generation can be used to further ensure the security of random number generation, preventing attacks on the process. This is particularly true for non-integrated photonic QRNGs composed of single components, where the required transmission paths within the system offer various attack scenarios. Therefore, to improve security, such systems should be implemented in a compact manner and isolated from the external environment. Besides avoiding potential attack scenarios, another advantage of such compact QRNGs is their ability to minimize natural influences that could compromise random number generation from outside the system. Therefore, correspondingly compact QRNGs based on photonic noise have historically been offered as hybrid integrated systems.
[0021] An integrated quantum random number generator (iQRNG) with an SPS and one or more SPDs is known from EP 3 529 694 B1, wherein the SPS and one or more SPDs are arranged in a fully integrated manner on a single semiconductor substrate using CMOS technology, such that they are closely juxtaposed with each other (see [reference]). Figure 1 (See attached figures). In this case, the SPS is provided by a suitably doped pn junction, such that when the photon source is properly pre-tightened in the forward or reverse direction, this SPS generates the photon current to be detected. The SPD should in particular be a SPAD, which preferably uses the same manufacturing process and has the same chemical structure as the SPS.
[0022] Co-integration allows the photon flow generated by the SPS to flow directly to the SPAD arranged side-by-side, bypassing optical crosstalk within the same semiconductor material, without first overcoming or tunneling through potentially empty coupling gaps that physically separate the two components, as is required in other hybrid integrated QRNGs known in the prior art. This "side-by-side" integration configuration makes the QRNG described in this case more compact and structurally simpler than hybrid QRNGs of the same functional type. Furthermore, due to the integration of all components, the robustness of the random number generator and its immunity to external environmental influences and manipulation attempts by external attackers are significantly improved.
[0023] However, in this case, with the significant increase in cost, there remains, in principle, the possibility of interfering with, influencing, and / or observing the random number generation process during continuous operation of the QRNG. Since the iQRNG disclosed in this case is essentially planar, it is possible to divert or supplementarily introduce single photons from above or below the substrate plane.
[0024] Furthermore, the horizontal side-by-side arrangement of such structures is not ideal in terms of efficiency and required area consumption. In this case, efficiency is particularly limited by the required lateral distance between the SPS and SPADs, and the associated high photon absorption of the semiconductor material. Moreover, without special precautions, photons emitted by the SPS will largely be randomly incident into the material surrounding the SPS, thus only a portion of the generated photons can be detected by the associated SPADs. While multiple SPADs can be arranged around a single SPS to improve efficiency and thus the digital entropy rate by jointly evaluating such connected SPADs, the area consumption of such iQRNGs will increase significantly. On the other hand, even with a single emitter-detector pair, it must be ensured that undetected photons do not propagate uncontrollably within the substrate and cause interference at other locations within the substrate. Therefore, the associated lateral blocking regions also contribute to the increased effective area consumption of the iQRNG.
[0025] A similar iQRNG with a photon source and single-photon detector layout, implemented using CMOS technology (HV-CMOS), is also known by Khanmohammadi et al. ("A monolithic silicon quantum random number generator based on measurement of photon detection time," IEEE Photonics Journal 7.5 (2015): 1-13). The photon source is constructed in a near-surface circular n-well, with the central n-well serving as the cathode. ++ The zone and the ring-shaped arrangement around it serve as multiple p-type anodes. ++ The Si-LEDs between the regions are enclosed by a SPAD ring serving as a single-photon detector (see...). Figure 2 (See attached figures). Thus, photons emitted by the SPS can be measured on all surfaces in the plane, thereby improving efficiency with reduced area consumption compared to the iQRNG known from EP 3 52 694 B1. Therefore, the SPS can be directly integrated into the SPAD. However, in this case, single photons can also be emitted into the substrate or extracted at its surface. Furthermore, this method can also be used to inject corresponding photons from an attacker to influence statistical data.
[0026] Therefore, compared to existing technologies, integrated QRNGs need further miniaturization to further improve security and reduce area consumption. iQRNGs should offer maximum protection against external attacks and achieve the highest possible efficiency and lowest possible substrate loss. To avoid manufacturing technology limitations when designing SoCs (System on Chip), the underlying manufacturing process should be designed in a technologically open manner or based on the most widely applicable technology platform for semiconductor structuring.
[0027] DE 10 2022 125 568 A1 relates to a data processing apparatus comprising an integrated circuit including a data processor and a non-volatile memory storing at least one security code. A first memory located outside the integrated circuit stores data, wherein such data is encrypted and protected in a first format. A second memory located outside the integrated circuit is used to store data. The apparatus is configured such that it transfers data from the first memory to the second memory via the integrated circuit so that the data processor can access such data from the second memory. The integrated circuit is arranged such that it verifies data read from the first memory during transfer using a security code stored in the non-volatile memory. If such data is verified, encryption protection in a second format is applied to the verified data, wherein the security code stored in the non-volatile memory is used. The protected data is stored in the second memory in the second format. This disclosure relates to a computer comprising at least one quantum process-based, differentiable, true random number generator as a random number generator having a high random bit output rate, particularly for encryption. The unpublished applications DE 10 2022 125 569 A1, DE10 2022 125 570 A1, DE 10 2022 125 571 A1, DE 10 2022 125 572 A1, DE 10 2022 125573 A1 and application number DE 10 2022 125 574.3 may also contain the corresponding apparatus.
[0028] Hardware-based centralized quantum random number generator In systems known to date for generating random numbers in networks, software-based random number generators and / or computer- and / or machine-implemented algorithms are commonly used. These random number generators, also known as pseudo-random number generators (PRNGs), are based on deterministic, computer- and / or machine-implemented algorithms that compute random numbers from an initial seed value in a predictable manner. While these methods may be sufficient for many applications, they have significant weaknesses in applications involving high security. Due to the predictable nature of PRNGs by their algorithmic nature, attackers who know or guess the seed value can predict the generated random numbers. This poses a significant security risk, especially in distributed networks where the integrity and security of communications are critical. Recently, AI-based methods using known, simple feedback polynomials based on linear feedback shift registers have attracted considerable attention because these methods can relatively quickly estimate the feedback polynomial and the seed value used, thereby breaking many common encryption algorithms.
[0029] Another approach in the prior art is to use hardware-based centralized quantum random number generators, which utilize physical phenomena such as thermal noise or quantum effects. These methods achieve higher quality and unpredictability of random numbers, but their implementation is often complex and costly. Some monolithic quantum random number generators suffer from the following drawbacks: they rely on the generation of single photons, which are transmitted laterally across the silicon substrate to the SPAD photon receiver. This results in a small effective cross-section and high attenuation in the silicon semiconductor substrate. Only a small fraction of the photons generated by the single-photon source in the silicon substrate are emitted from the single-photon source (preferably a SPAD or Zener diode) towards the single-photon detector (in this case, the SPAD photon receiver), and these photons subsequently attenuate significantly in the typically gray and opaque silicon substrate. This leads to low random number data rates in the prior art. Even using optical waveguides in metallized stacks on silicon semiconductor substrates only slightly improves this situation, because many photons emitted from the single-photon source perpendicular to the silicon semiconductor substrate surface are reflected back by the metallized stack. Furthermore, the centralization of these systems poses a risk, as a single weak point in the system could jeopardize the entire network.
[0030] A decentralized security architecture is achieved by avoiding a central node. Centralized networks, where a single entity is responsible for generating and distributing random numbers, pose a risk of single point of failure. An attack or breach of the central node can severely impact the security of the entire network. Such centralized systems are vulnerable to attacks where attackers attempt to manipulate the central quantum random number generator or predict its output. Such attacks can jeopardize network communications and introduce serious security vulnerabilities. Furthermore, the central quantum random number generator must provide a high random bit rate, which is technically challenging and therefore prone to attack and error.
[0031] Furthermore, centralization can hinder network scalability. As the number of nodes increases, the central node may become a bottleneck because it must generate and distribute centrally generated random numbers to all nodes. This can lead to increased latency, delays, and potential performance degradation. Additionally, centralized systems can be more complex and costly to manage and maintain, especially when the network is geographically dispersed.
[0032] Encryption using random numbers The security of network encryption largely depends on the quality of the random numbers used. However, in current technology, insufficient entropy or systematic flaws in quantum random number generators are common, jeopardizing encryption security. If the random numbers are predictable, the encryption key may be broken, allowing attackers to decrypt encrypted communications and steal confidential information.
[0033] Another problem with using random numbers for encryption is the risk of reusing random numbers. Particularly in PRNGs, after long runs or in the event of a generator initialization error, the same random numbers may be generated, leading to insufficient key strength or completely identical keys. This poses a significant security risk because the same encryption key produces the same ciphertext, which is easier to analyze and decrypt.
[0034] Support security protocols Security protocols such as TLS or IPsec rely on high-quality random numbers to establish secure communication channels between network nodes. However, existing technologies often find that the random number entropy used for these protocols is insufficient or predictable, which may compromise the overall security of the protocol.
[0035] Another issue lies in the implementation and management of these protocols in distributed networks. Many networks use centralized quantum random number generators, so weaknesses or errors in the implementation of these protocols can become potential attack points. Attackers might attempt to exploit vulnerabilities in the random number generator to manipulate key exchange or bypass authentication. This would pose a significant risk to the integrity and confidentiality of network communications.
[0036] Random selection of nodes In distributed networks, particularly blockchain systems or other consensus-based networks, the random selection of nodes for specific tasks is crucial. However, existing technologies often find that the algorithms used for random selection are not entirely random or manipulable. This can lead to uneven task distribution and potentially allow malicious actors to manipulate the system by influencing the selection to favor specific nodes.
[0037] Another problem is the lack of synchronization in network-wide random number generation. In many systems, there is a risk that nodes may not generate random numbers uniformly, potentially leading to predictable patterns. This poses a significant security risk, as attackers can use it to target specific nodes or manipulate task allocation across the network.
[0038] Entropy source enhancement and filtering In existing technologies, various methods are used to generate random numbers through physical processes. These entropy sources (such as thermal noise or quantum effects) are, in principle, capable of generating high-quality random numbers. However, a problem exists: the generated entropy may be affected by environmental conditions, leading to fluctuations in the quality of the random numbers.
[0039] Another problem is that many existing systems do not implement sufficient entropy source enhancement and filtering mechanisms. This may result in the raw data from the entropy source not being adequately enhanced or filtered before being converted into random numbers. Consequently, systematic errors or predictability may be introduced into the generated random numbers, reducing their security and unpredictability.
[0040] Post-processing of random numbers Most known random number generation systems rely on simple methods to process the generated random numbers. These post-processing steps (such as hashing or XOR) are often used to further "improve" the random numbers. However, these methods are often flawed, especially when they are not properly implemented or configured.
[0041] A known problem is that post-processing cannot completely eliminate systematic errors in many cases. Especially when using simple algorithms, certain patterns may remain in the random numbers, which could be exploited by attackers. This reduces the effectiveness of post-processing and jeopardizes the security of the final random numbers.
[0042] Another issue is that entropy may decrease during post-processing. If the processing methods are not properly coordinated, the originally high entropy of random numbers may be reduced due to inefficient or erroneous post-processing steps, thus decreasing the security of random numbers.
[0043] Storage and Access Control Secure storage of random numbers and other security-related data is another core topic in existing technologies. Many existing systems suffer from serious security flaws in storing such data. Random numbers are often stored in insecure storage areas vulnerable to physical and logical attacks. This poses a significant risk because unauthorized access to this data can compromise the security of the entire system.
[0044] Another problem with existing technologies is the inadequacy of access control over stored random numbers and security-related data. Implemented access control mechanisms are often not stringent enough to prevent unauthorized access. This can lead to security vulnerabilities that allow attackers to access or manipulate sensitive data.
[0045] Network control and load distribution Effective control and load distribution in distributed networks is another challenge facing existing technologies. Many existing systems fail to distribute the load evenly across the network, leading to bottlenecks and performance degradation. Particularly in networks with centralized quantum random number generators, the central node often becomes overloaded, impacting the overall network performance.
[0046] Another issue is the lack of flexibility in load distribution. Many systems employ static or simple polling strategies that fail to respond to current network load. This leads to inefficient resource utilization and can limit network scalability. In dynamic networks that rely on flexible and efficient load distribution, such limitations can impact the performance and reliability of the entire system.
[0047] Fault identification and recovery In existing technologies, fault identification and recovery in distributed networks suffer from significant deficiencies. Many systems have only limited or even no mechanisms for continuous monitoring of random number generation and overall network security. This results in faults or anomalies often being detected late, potentially jeopardizing the security and integrity of the network.
[0048] Furthermore, existing recovery processes are often insufficiently automated or fail to respond quickly enough to identified problems. This can lead to longer downtime or even complete network outages. These deficiencies pose a significant risk, especially in security-critical applications where the continuous availability and integrity of the random number generator are paramount. Summary of the Invention
[0049] The solution of the present invention to achieve the above-mentioned objective is the subject matter of the independent claim. Preferred improvements are the subject matter of the dependent claims.
[0050] This invention relates to a distributed network in which each node is equipped with a hardware-based quantum random number generator.
[0051] The distributed network according to the invention specifically comprises multiple nodes, each of which has at least one hardware-based quantum random number generator with at least one entropy source. The quantum random number generator on each node can be adapted to generate truly random numbers (i.e., this quantum random number generator is a TRNG, not a PRNG). The network and / or its sub-devices can be adapted to use these random numbers, particularly to ensure (i.e., within this scope) the security, availability, and robustness of the network. The network and / or its sub-networks and / or its sub-devices can be adapted to generate random numbers in a decentralized manner, thus eliminating the need for a central node to generate or manage random numbers.
[0052] A quantum random number generator may include an entropy source. Preferably, the entropy source is implemented monolithically in a semiconductor substrate having a surface. The entropy source may include a photon source adapted to emit photons (preferably single photons) when correspondingly fed by a current. Furthermore, the entropy source may also include a single-photon detector adapted to detect photons from the photon source and generate an entropy source output signal. The photon source is preferably disposed between the surface of the semiconductor substrate in which the photon source is constructed (this semiconductor substrate may be the same semiconductor substrate in which the entropy source is monolithically constructed) and the single-photon detector. Alternatively, the single-photon detector may also be disposed between the surface of the semiconductor substrate in which the photon source is constructed (this semiconductor substrate may be the same semiconductor substrate in which the entropy source is monolithically constructed) and the single-photon source.
[0053] In other words, the corresponding entropy source of the corresponding quantum random number can have a corresponding vertical integrated structure of the corresponding photon source and the corresponding single-photon detector perpendicular to the surface of the corresponding semiconductor substrate, in which the corresponding single-photon source and the corresponding single-photon detector of the corresponding quantum random number generator are jointly fabricated.
[0054] Particularly preferably, the photon source and the single-photon detector are vertically stacked, for example, when combined as hybrid structures each having its own intrinsic substrate, or when forming a vertically stacked structure in an entropy source monolithically integrated into a semiconductor substrate. The quantum random number generator may include components for generating one or more quantum random numbers based on the output signal of the entropy source. A quantum random number may, for example, include a single quantum random bit or a quantum random data word consisting of multiple quantum random bits. The quantum random number generator may, in particular, be... Figure 8 The quantum random (number) generator is illustrated in the example, wherein the entropy source is preferably constructed in the manner described above.
[0055] Preferably, at least two of the network nodes, and more preferably all of them, are adapted to use random numbers generated by their respective quantum random number generators and / or another quantum random number generator in the network to generate encryption keys and initialization vectors (IVs).
[0056] Preferably, at least two of the network nodes, and more preferably all of them, are adapted to use their respective random numbers and / or random numbers from other nodes in the network to generate one-time passwords (OTPs) for authenticating communication partners.
[0057] Preferably, the network or at least two, preferably all, of its network nodes are adapted to support secure communication protocols such as TLS or IPsec using their respective random numbers and / or random numbers from other nodes in the network and / or random numbers in the network.
[0058] Preferably, the network or at least two, preferably all, of its network nodes are adapted to use their respective random numbers and / or random numbers from other nodes in the network and / or random numbers in the network to execute security protocols that preferably ensure secure communication between nodes.
[0059] Preferably, at least two nodes, or more preferably all nodes, of the network or its plurality of network nodes are adapted to enhance and filter the random numbers generated by the entropy collection unit in order to preferably avoid systematic errors or predictability.
[0060] Preferably, at least two nodes, preferably all nodes, of the network or a plurality of network nodes are adapted to generate their respective random numbers by utilizing physical phenomena such as thermal noise and / or quantum processes.
[0061] Preferably, the network is configured in such a way that the load of random number generation is evenly distributed across these nodes.
[0062] Preferably, at least two of the network nodes, and more preferably all of the nodes, each include a security module adapted to securely store the random number of the respective node and use it and / or provide it to one or more different security-related applications.
[0063] Preferably, at least two of the network nodes, and more preferably all of the nodes, each include a control device adapted to store random numbers in a protected storage area of the control device of the respective node, which can only be accessed by authorized processes in the network.
[0064] Preferably, the corresponding control device is adapted to identify anomalies in random number generation and implement a corresponding recovery process.
[0065] Preferably, the corresponding control device is adapted to post-process the generated random numbers in order to improve their quality through techniques such as hashing or XOR.
[0066] Preferably, the corresponding control device is adapted to use random numbers to manage and use digital certificates that are necessary for authentication and establishing secure connections.
[0067] Preferably, the network has a computer and / or machine-implemented error identification and recovery mechanism to ensure that the network remains functional even when a single node fails and / or a single quantum random number generator fails, for example by exchanging random numbers.
[0068] Preferably, the network is adapted to prevent the use of uncertified vehicle parts or spare parts and / or software components by implementing a random number-based authentication process when such parts or components are installed or started, the random numbers being generated by hardware-based quantum random number generators in the network nodes.
[0069] Preferably, the authentication process includes generating an encryption key via a quantum random number generator at the node, which is then used to verify a digital certificate that confirms the authenticity and integrity of the component or software component to be installed.
[0070] Preferably, the network is adapted to identify breaches of one or more nodes by implementing an intrusion detection system (IDS) that continuously monitors the nodes’ hardware-based quantum random number generators for random numbers and identifies statistical anomalies in the random number generation that indicate (or may indicate) breaches.
[0071] Preferably, the IDS performs continuous entropy analysis on the random numbers generated by the quantum random number generator and sends an alarm message to the central control node in the vehicle network when it determines that there is a deviation from the expected entropy value.
[0072] For communication between different nodes in the network, it is preferable to use different encryption keys and / or encryption methods, which are dynamically selected and generated by random numbers generated by a quantum random number generator, in order to improve the security of communication.
[0073] Preferably, each node in the network is adapted to use a unique encryption method and key combination for each communication, which differs from the combinations of other node pairs, preferably to prevent the destruction of one node from jeopardizing the entire network.
[0074] Preferably, when it is determined that one or more nodes have been compromised, the network is adapted to initiate defensive actions on one or more nodes, specifically by disconnecting the affected nodes from communication within the network and reinitializing their quantum random number generators for additional security checks.
[0075] Preferably, the defensive action enables the involved node to perform a self-check, wherein the integrity of the internal encryption key and the random numbers generated by the quantum random number generator is checked before the node is allowed to communicate with the network again.
[0076] It is preferable to use the random numbers from a quantum random number generator to generate one-time passwords (OTPs), which are necessary for accessing vehicle safety-critical functions, such as unlocking control devices or activating firmware updates.
[0077] The network is preferably adapted to activate a redundant network protocol when a potential threat arises from the destruction of a node or a group of nodes. This network protocol reroutes communication paths within the network and ensures communication security by dynamically generating new random numbers for encryption and authentication.
[0078] The corresponding hardware-based quantum random number generators preferably have the features described in Section 1, "Hardware-based Quantum Random Number Generators on Each Node," particularly the features of their entropy source. These quantum random number generators are preferably integrated in each node of a related subnetwork of the network and used to generate random numbers in a distributed manner, which can be used for various security-related applications within the network.
[0079] 1. Hardware-based quantum random number generator on each node Each node in the network is equipped with a corresponding hardware-based quantum random number generator.
[0080] Such quantum random number generators may include an entropy source monolithically fabricated in a semiconductor substrate, comprising a single-photon source and a single-photon detector arranged perpendicular to each other and to the surface of the associated semiconductor substrate, thereby enabling exceptionally high random number data rates. The corresponding quantum random number generator may include components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal. These quantum random number generators are characterized in that the photon source and the corresponding single-photon detector of the respective entropy source of the respective quantum random number generator are arranged vertically relative to each other in the semiconductor substrate of the quantum random number generator, which ensures that the generated random numbers are actually random, unpredictable, and have high entropy. By distributing these quantum random number generators across all nodes of the network, a distributed architecture is achieved, which offers significant advantages in terms of network security, robustness, and scalability.
[0081] The corresponding quantum random number generators are preferably implemented as a single unit. The corresponding semiconductor substrate of the quantum random number generator preferably includes a corresponding entropy source fabricated within the corresponding semiconductor substrate and components for converting the entropy source signal into a stream of random bit data. These components preferably include one or more of the following device components: one or more analog amplifiers and / or filter circuits for processing the entropy output signal for subsequent analog-to-digital conversion; one or more bit analog-to-digital converters, which, in the case of a one-bit analog-to-digital converter, can be implemented by a comparator; one or more time / digital converters and / or one or more time / pseudo-random number converters for mapping unique binary numbers to the time interval between two pulses of the entropy source; one or more entropy extraction devices for extracting one or more random bits from these binary numbers; one or more finite automata (i.e., so-called finite state machines) for converting the stream of random bit data into random numbers; one or more interfaces for allowing one or more external computer systems to access these random numbers and / or control the quantum random number generator; one or more devices for implementing and / or supporting health checks on one or more device components and their cooperation; and one or more device components for generating internal operating voltages within the quantum random number generator to operate the quantum random number generator.
[0082] These characteristics of quantum random number generators may, for example, utilize specific physical processes involving the type of entropy source or the specific circuit design. Integrating such a corresponding quantum random number generator in each node enables true nondeterministic random number generation, which is crucial for secure network operation.
[0083] Variant Scheme 1 (not claimed for protection): This random number generator can be based on thermal noise, a known method for generating truly random numbers. The advantage of using this technique lies in its thorough research and proven track record, ensuring high reliability and repeatability. However, such generators may be susceptible to environmental conditions (such as temperature variations), which can pose challenges in certain scenarios.
[0084] Variant Scheme 2: Another variant of the invention, as claimed, utilizes quantum processes to generate random numbers independently at each node. Quantum-based generators have the potential to achieve extremely high entropy values and absolute unpredictability. However, a drawback to date is that such systems are generally more expensive and complex to implement, limiting their availability in cost-sensitive environments. The technical principles proposed herein address this problem. According to the invention, such a quantum random number generator preferably comprises an entropy source monolithically fabricated in a semiconductor substrate, the entropy source comprising a single-photon source and a single-photon detector arranged perpendicular to each other and perpendicular to the surface of the associated semiconductor substrate, thereby enabling particularly high random number data rates. The corresponding quantum random number generator includes components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal.
[0085] Variant Scheme 3: Different physical phenomena can be combined with variant scheme 2 to generate random numbers. While this increases the complexity of the system, it is more robust to external influences because the weaknesses of one method can be compensated for by the strengths of another.
[0086] 2. Achieve a decentralized security architecture by avoiding a central node. Distributed random number generators in a network offer significant advantages over centralized systems where all random numbers are generated by a single node. In such a distributed system, each node contributes to the network's total entropy, thereby reducing the risk of individual components being attacked.
[0087] Variant Scheme 1: In a network with a fully distributed architecture, the absence of a central monitoring authority enhances security because a single point of failure cannot compromise the entire network. This variant achieves maximum redundancy and fault tolerance but requires more sophisticated node management and synchronization to ensure consistency and synchronicity.
[0088] Variant Scheme 2: A semi-decentralized variant might involve a small number of nodes in the network playing a broader role in the management or distribution of random numbers. These nodes can act as hubs, exerting a degree of control over the generation of random numbers among neighboring nodes. This reduces network complexity and simplifies management, but increases security risks if one of these hubs is compromised.
[0089] Variant Scheme 3: Another variant might involve implementing a hybrid system where a central entity acts only in monitoring and coordination, without generating random numbers itself. This combines the advantages of centralized management with the security of decentralized random number generation, but also presents the challenge of designing such a system securely and efficiently.
[0090] 3. Encryption using random numbers Random numbers generated by a quantum random number generator can be used to generate encryption keys and initialization vectors (IVs) necessary for secure communication between network nodes.
[0091] Variant Scheme 1: Random numbers can be used directly to generate symmetric encryption keys. This method is relatively efficient and enables fast encryption and decryption of data because symmetric key algorithms such as AES (Advanced Encryption Standard) have low computational requirements. However, its drawback is that the symmetric key must be updated periodically to ensure security.
[0092] Variant Scheme 2: As an alternative, random numbers can be used to generate asymmetric key pairs for use in Public Key Infrastructure (PKI). This variant offers advantages in terms of security and scalability, as keys can be securely distributed over insecure channels. Its disadvantages include higher computational strength and longer encryption and decryption times.
[0093] Variant Scheme 3: Another approach involves using random numbers to generate initialization vectors (IVs), which are then used in block cipher schemes such as CBC (Cyclic Block Chaining). This variant enhances security by ensuring that the same plaintext block generates different ciphertexts, making it difficult for attackers to analyze. Its drawback lies in the added complexity of implementing and managing IVs.
[0094] 4. Supports security protocols These randomly generated random numbers can be used to support security protocols such as TLS (Transport Layer Security) or IPsec (Internet Protocol Security), which are essential for secure communication between network nodes.
[0095] Variant Scheme 1: These random numbers can be directly used for session initialization in the TLS protocol. This allows communication partners to securely negotiate encryption keys and authentication information. The advantage of this variant is the proven security of TLS, but the disadvantages are the complexity of the protocol implementation and the necessary overhead.
[0096] Variant Scheme 2: Another variant involves using random numbers for authentication and key exchange in the IPsec protocol. IPsec offers strong network layer security and is particularly suitable for VPNs (Virtual Private Networks). The disadvantage of this variant is that it may require more configuration work, and the additional security measures may impact network performance.
[0097] Variant Scheme 3: A hybrid solution might involve implementing both TLS and IPsec and using random numbers to support both protocols. This approach offers maximum flexibility and security, but comes with higher implementation and maintenance costs.
[0098] 5. Random selection of nodes In distributed networks, it may be necessary to randomly select nodes for specific tasks, such as verifying transactions in a blockchain network. Distributed, randomly generated numbers can be used to ensure fair and unmanipulated node selection.
[0099] Variant Scheme 1: Random numbers can be used to randomly select nodes in consensus-based networks such as blockchains. This ensures that no single party can influence the selection, thus improving the system's security and fairness. However, this variant may have drawbacks, such as increased complexity and the need for precise synchronization between nodes.
[0100] Variant Scheme 2: Another variant involves randomly selecting nodes for tasks such as data replication or load distribution within the network. This helps to distribute the load evenly and avoid bottlenecks. The advantages of this approach are improved efficiency and flexibility, while the disadvantage may be that uneven node selection can lead to suboptimal performance parameters.
[0101] Variant Scheme 3: Another application area might be randomly selecting nodes to perform security checks or audits within the network. This ensures independent and unpredictable checks on network security. However, a drawback might be that performing such checks incurs additional overhead and consumes system resources.
[0102] 6. Amplification and filtering of entropy sources The entropy collection unit in each node can be designed in a way that amplifies and filters the physical signal before converting it into digital random numbers. This helps ensure the quality and unpredictability of the generated random numbers.
[0103] Variant Scheme 1: One variant could use a highly sensitive amplifier capable of capturing and amplifying even the smallest fluctuations in the entropy source. This improves the accuracy and randomness of the generated numbers, but may be susceptible to environmental interference such as electromagnetic interference.
[0104] Variant Scheme 2: Another variant involves implementing a complex filtering unit that allows only a specific frequency range of the entropy source to pass through, in order to eliminate noise and unwanted signals. The advantage of this approach is improved random number quality, while the disadvantages may include the need for additional computational power and potential delays in the random number generation process.
[0105] Variant Scheme 3: Amplification and filtering can be combined to provide signal strength while reducing noise. This will improve the reliability and stability of random numbers, but it will increase system complexity and implementation cost.
[0106] 7. Post-processing of random numbers After generating random numbers using a hardware-based quantum random number generator, these numbers can be post-processed to eliminate systematic errors or predictability and further improve randomness.
[0107] Variant Scheme 1: A simple post-processing variant might involve applying a hash algorithm such as SHA-256 to the generated random numbers. This ensures that even small deviations in the input values will result in significant changes in the output, thus reducing predictability. However, a drawback might be the additional computation time required for hashing.
[0108] Variant Scheme 2: Another variation might involve XORing the generated random number with a predetermined random mask. This method is simple and fast, but it may not provide the same level of security as more complex methods, because in some cases, the predictability of the random number may still exist.
[0109] Variant Scheme 3: A more sophisticated variant involves applying multiple post-processing steps, including hashing, XORing, and shuffling, to maximize the quality of the random numbers. This ensures extremely high unpredictability and security, but at the cost of system performance and the required computational resources.
[0110] 8. Storage and Access Control The generated random numbers and other security-related data can be stored in a secure storage area that is resistant to both physical and logical attacks. Strict access controls can regulate access to this data to prevent unauthorized access.
[0111] Variant Scheme 1: One variant could be to implement a hardware-based security module that stores random numbers in an isolated storage area. This approach offers extremely high security against physical attacks because this storage area is separate from the main processing unit. However, the downsides might be increased complexity and associated costs.
[0112] Variant Scheme 2: As an alternative, random numbers can be stored in an encrypted storage area within the node's main memory. This method is less expensive and easier to implement, but its security may be lower compared to physical attacks because the main memory can be more easily accessed.
[0113] Variant Scheme 3: Another approach is to store the random numbers in a secure cloud-based storage device protected by multi-level authentication methods. This variant offers greater flexibility and scalability, but introduces potential security risks due to external access and its correlation with network latency.
[0114] 9. Network control and load distribution The network can be designed in a way that distributes the load of random number generation and other network resources evenly across the nodes. This ensures that nodes are not overloaded and that the network operates efficiently.
[0115] Variant Scheme 1: In one variant, a simple round-robin strategy can be implemented for load distribution, where the random number generation task is evenly distributed among the nodes in a predetermined order. This approach is easy to implement and ensures even load distribution. However, a drawback is that it can lead to inefficiency when some nodes have a higher load than others.
[0116] Variant Scheme 2: Another variant might be dynamic load distribution based on the current load of nodes. In this case, task allocation is based on real-time data about the current load and availability of nodes. This ensures optimal utilization of network resources, but requires more complex algorithms and continuous network monitoring.
[0117] Variant Scheme 3: A hybrid strategy can be adopted, which combines a basic polling strategy with dynamic adaptation when some nodes are overloaded. This achieves a balance between simplicity and efficiency, but may be difficult to implement and maintain.
[0118] 10. Fault Identification and Recovery The network can have a mechanism for continuous anomaly monitoring and can implement an automatic recovery process when a problem is identified. This ensures that the network can continue to function normally and maintain the integrity of random number generation even if a single node fails.
[0119] Variant Scheme 1: A simple variant might involve periodically performing self-checks on the nodes to verify the functionality of the quantum random number generator. Upon detecting anomalies, the affected nodes could be automatically isolated and replaced. The drawback of this approach is that it cannot react to faults in real time, and there may be some delay in fault identification and resolution.
[0120] Variant Scheme 2: A more advanced variant might involve implementing a real-time monitoring system that continuously monitors the performance and status of each node and immediately initiates a recovery process upon detecting a failure. This would minimize response time and maximize network security, but would require complex infrastructure and could potentially increase operating costs.
[0121] Variant Scheme 3: Another approach is to implement a redundant system where each node has a backup instance that is automatically activated in the event of a failure. This variant offers high fault tolerance but may significantly increase network cost and complexity.
[0122] Using distributed networks in vehicles Applying such networks to vehicles is particularly advantageous. Vehicles are high-value assets, constantly threatened by theft and other criminal activities. Therefore, networks protected by quantum cryptography are especially beneficial.
[0123] 11. Prevent the use of uncertified vehicle parts or spare parts and / or software components. In this context, the technical challenge lies in preventing the use of uncertified vehicle parts or spare parts and / or software components. This is particularly important in safety-critical vehicle applications, as installing uncertified parts or software could compromise the vehicle's safety and integrity.
[0124] Variant Scheme 1: In the first variant, a digital authentication process can be initiated upon installation of a new vehicle component. In this case, the network's random number generator produces an encryption key used to verify the digital certificate of the new component. The advantage of this method is its high security, as the random number generators produce high-quality keys that are difficult to manipulate. The disadvantages may include increased computational load and associated latency during the authentication process.
[0125] Variant Scheme 2: The second variant implements a two-factor authentication process, using an encryption key and a one-time generated password (OTP) to verify the authenticity of the component or software. This further enhances security by providing additional protection against unauthorized installations. The drawback of this approach is that it requires a more complex infrastructure to support the OTP mechanism.
[0126] Advantages of monolithically integrated quantum random number generators with high random bit data rates The advantage of a monolithically integrated quantum random number generator with a high random bit data rate in each node of the network is that it enables direct and decentralized authentication using a large number of key bits. This improves the robustness of the system because it does not rely on a central random number generator, which could potentially become a single point of failure. Using a central random number generator offers fewer advantages because it limits the system's flexibility and scalability and makes it vulnerable to targeted attacks.
[0127] Collaboration of random number generators: These monolithically integrated quantum random number generators with high random bit data rates at different nodes in the network preferably cooperate by generating encryption keys and OTPs (On-Point Protocols) with a greater number of random bits than the key bits in parallel for authentication. Distributed generation of authentication data allows the network to respond flexibly to different authentication requirements and improves security by minimizing the attack surface and maximizing key security through increasing key length.
[0128] 12. Security verification of vehicle components or software components during installation or activation: The technical challenge lies in the secure verification of vehicle components or software components during their installation or activation. Insecure verification could lead to the installation of counterfeit or compromised components.
[0129] Variant Scheme 1: The first variant uses a digital certificate, which is verified using a high-key-length encryption key based on random bits from a monolithic integrated quantum random number generator with a high random bit data rate at one or more nodes in the network. Preferably, this key is generated by a monolithic integrated quantum random number generator with a high random bit data rate at one node in the network, thus preventing attacks on random number transmissions between edge nodes. The advantage of this method is its ability to quickly and securely verify components, which can then be immediately put into use once verified. However, a potential disadvantage is its reliance on a digital certificate infrastructure that requires regular maintenance.
[0130] Variant Scheme 2: Another alternative variant may include multi-level verification, where, after the initial certificate check, an additional check is performed by another node to confirm the certificate's integrity. This second node has preferably contributed to the certificate using second certificate information based on one or more random numbers from a monolithically integrated quantum random number generator with a high random bit data rate. The first node has preferably contributed to the certificate using first certificate information based on one or more random numbers from a monolithically integrated quantum random number generator with a high random bit data rate. This dual check based on a monolithically integrated quantum random number generator with a high random bit data rate further enhances security but may prolong the installation process.
[0131] Advantages of monolithically integrated quantum random number generators with high random bit data rates Using a monolithically integrated quantum random number generator with a high random bit data rate at each node enables fast and decentralized certificate verification without sending data to a central node for validation. This reduces latency and lowers the risk of data interception. A central random number generator slows down verification and introduces additional security risks, as it becomes an attractive target for attacks.
[0132] Collaboration of quantum random number generators with high random bit data rate The corresponding control devices of these nodes preferably collaborate using their respective monolithically integrated quantum random number generators with high random bit data rates to perform redundancy checks and ensure the authenticity of components and software. This distributed security architecture prevents a single breach from jeopardizing the entire system.
[0133] 13. Intrusion Detection within the In-Vehicle Network The technical challenge lies in intrusion detection within the vehicle network. Undetected damage could lead to the manipulation or misuse of vehicle functions.
[0134] Variant Scheme 1: One variant involves a corresponding control device at the corresponding node continuously monitoring the random numbers generated by the random number generator through entropy analysis. For this purpose, the corresponding control device preferably has at least one watchdog timer for each of the corresponding control devices, which performs entropy analysis within the corresponding control device and generates one or more corresponding metrics for the corresponding quality of the entropy of the corresponding random data stream generated in the corresponding quantum random number generator of the corresponding network node. The network can be configured in such a way that it quantitatively identifies a corresponding deviation in the expected corresponding entropy value as the corresponding entropy quality value by comparing it with a range of allowed entropy quality values (e.g., by deviating from these allowed ranges of entropy quality values through one or more entropy quality values). Such deviations may indicate corruption. Different tests exist for determining the entropy of random numbers. A common approach is to calculate Shannon entropy, which quantifies the average information content of each character in the source. Higher entropy values indicate higher unpredictability. Therefore, the range of corresponding entropy quality values can be defined by Shannon entropy values (or another applicable entropy metric).
[0135] The advantage of this method lies in the early identification of threats, while the disadvantage is the computational power required for continuous analysis of random numbers. Therefore, it is advantageous that the CPU of the control device not only implements the computer-implemented entropy analysis and / or entropy assessment methods, but also takes the form of a machine-implemented method component as part of the corresponding control device of the corresponding node in the network, which is a hardware acceleration device. These method components are preferably part of the aforementioned corresponding watchdog of the corresponding control device of the corresponding node in the network.
[0136] Variant Scheme 2: Another variant involves the corresponding control device of each node in the network periodically performing computer-implemented and / or machine-implemented random number tests on random numbers generated by a monolithic integrated quantum random number generator with a high data rate, and reporting the results to one or more pre-defined, programmable, or otherwise determined central nodes in the network. The CPU of the control device of such a central node preferably implements one or more computer- or machine-implemented methods to analyze the received data and corresponding suspected deviations. The advantages of this method are more or less centralized management and rapid decision-making capabilities, while the disadvantages are increased communication load and dependence on the availability of one or more central nodes in the network.
[0137] Advantages of monolithic integrated random number generators with high data rates in this regard A monolithically integrated quantum random number generator with a high data rate in each node enables decentralized monitoring of random number generation, thereby improving the system's robustness against targeted attacks. A central random number generator is more susceptible to manipulation and malfunction, which could compromise the overall security of the network.
[0138] Collaboration of quantum random number generators High-data-rate monolithic integrated quantum random number generators at different nodes in the network preferably cooperate. Specifically, they continuously generate random numbers, which are then checked for consistency and security by the CPU of the control device using computer and / or machine-based methods. Deviations in the statistical distribution of random numbers (e.g., variance, mean, fixed-type faults, etc.) can be quickly identified by the CPU of the control device at the corresponding node, and measures can be taken to mitigate threats before significant damage occurs. To this end, the control devices at these nodes in the network preferably exchange their generated random numbers, verify them, and preferably report the verification results to another control device at another corresponding node in the network. In this way, other control devices at other nodes in the network can identify the failure of a high-data-rate monolithic integrated quantum random number generator at another node and notify the remaining nodes in the network. In this case, the affected node can switch to an emergency mode, which may include using random numbers from other high-data-rate monolithic integrated quantum random number generators at other control devices at other nodes in the network.
[0139] 14. Automatically identify and respond to damage to one or more nodes in the network. The technical challenge lies in automatically identifying and responding to damage to one or more nodes in the network. Without such a mechanism, damage may go undetected and could lead to serious security problems.
[0140] Variant Scheme 1: In the first variant, the control devices of these nodes in the network can continuously perform entropy analysis on the random numbers generated by their respective high-data-rate monolithic integrated quantum random number generators, and, if necessary, also on the random numbers generated by high-data-rate monolithic integrated quantum random number generators of other nodes in the network. For this purpose, these control devices preferably use existing watchdog timers. In this case, the control device of a node in the network can preferably send an alarm message to the central control node when it detects an anomaly using a computer and / or machine-implemented method, preferably a statistical method. The advantage of this variant is its ability to quickly identify and centrally coordinate responses, while the disadvantage is that it may overload the central control node.
[0141] Variant Scheme 2: An alternative variation might involve not sending alarm messages to a central node, but instead having relevant control devices on related nodes within the network send them to multiple control nodes. In this case, the CPUs of these multiple control devices typically collaboratively determine subsequent steps using methods preferably implemented by corresponding computers and / or machines that synchronize and exchange signals and / or data, and these steps are usually implemented as computer and / or machine-based actions. While this distributes the load and improves system resilience, it may increase response time.
[0142] Advantages of monolithically integrated quantum random number generators with high random bit data rates A monolithically integrated quantum random number generator with a high random bit data rate in each node can be distributed and used with very long keys to identify and respond to attacks with high security, thereby improving the efficiency and security of the system. A central random number generator, however, becomes a potential target for attacks, potentially jeopardizing the security of the entire network.
[0143] Collaboration of quantum random number generators with high random bit data rates: These monolithically integrated quantum random number generators, with high random bit data rates, independently generate high-quality, resistant random numbers that are continuously monitored, particularly by the aforementioned watchdog control device. Upon detecting anomalies, the relevant nodes in the network can be isolated, and the generated random numbers can be used to assist in restoring the undamaged network.
[0144] 15. Ensure secure communication between network nodes. The technical challenge lies in ensuring secure communication between network nodes by using different encryption keys and / or encryption methods for different node pairs or groups.
[0145] Variant Scheme 1: In the first variant, whenever new communication occurs between two nodes, a new, longer encryption key is generated by a monolithically integrated quantum random number generator with a high random bit data rate on one of the participating nodes. This high random bit data rate allows for the use of longer key lengths. The advantage of this method is a significant improvement in security, as each communication channel is unique, making it difficult for unauthorized third parties to trace or decrypt. Its disadvantage may be the increased computational load resulting from the continuous use of new keys. Ultimately, the data bus bandwidth of the communication channel between nodes decreases as new keys are transmitted for the next key change. However, this increases the ratio of the number of key bits transmitted in the data channel to the number of effective bits transmitted in the communication channel. This reduces the probability of compromise, as the rapid key changes result in fewer effective bits available to an attacker to crack the key.
[0146] Variant Scheme 2: A second variant might involve the control devices of the node group within the network each using specific cryptographic algorithms, implemented in-house or by computer and / or machine. These algorithms utilize random numbers generated by the corresponding node's control device from a monolithically integrated quantum random number generator with a high random bit data rate. To this end, the node's monolithically integrated quantum random number generator with a high random bit data rate preferably generates random numbers more or less permanently. The corresponding control device of the corresponding node preferably updates the corresponding random numbers used by the corresponding control device periodically. This approach offers the advantage of higher security within the node cluster, but may increase the complexity of key management.
[0147] Advantages of monolithically integrated quantum random number generators with high random bit rate The optimal network architecture utilizes a monolithically integrated quantum random number generator with a high random bit data rate in each node, enabling local, real-time generation of the keys required for encryption without relying on a central network resource that risks communication compromise. This reduces the vulnerability of the central system and improves overall communication security. A central random number generator poses a potential risk because its compromise would threaten all communication channels.
[0148] Collaboration of monolithically integrated quantum random number generators with high random bit data rates The monolithically integrated quantum random number generators with high random bit data rates in the nodes generate separate, longer keys and encryption methods for each communication link to use these longer keys. Furthermore, these quantum random number generators enable continuous key exchange. This ensures that communication between nodes is always protected by relatively new and longer military-grade keys, reducing the possibility of attacks due to key reuse or decryption to zero. The monolithically integrated quantum random number generators with high random bit data rates generate truly random numbers; therefore, when the key length is very long, the probability of the same used key reappearing after key exchange is extremely low.
[0149] 16. Avoid security vulnerabilities by using repeated encryption methods or encryption keys within the network. The technical challenge lies in avoiding security vulnerabilities by using repeated encryption methods or encryption keys within the network.
[0150] Variant Scheme 1: In one variant, each communication between the control devices of network nodes is secured by a combination of random numbers and a dynamic, computer- and / or machine-implemented encryption method, determined by a monolithically integrated quantum random number generator with a high random bit data rate on the participating node's control device. For example, a control device can send the same data message multiple times to another control device on the same node, encrypting the message using different keys from different control devices on different nodes, and sending multiple encrypted data messages, as appropriate, along with information about the corresponding keys used, to the control device on the other node. The control device on the first node decrypts the data messages. If the contents of the decrypted data messages are inconsistent, at least one key generation and / or transmission has been compromised. Transmitting the corresponding information about the keys used is not absolutely necessary. Without this information, the receiving control device must attempt to decrypt the encrypted data message using all its available keys, which is time-consuming and quickly leads to NP-hard complexity problems. This method prevents key reuse and significantly improves security. As mentioned above, its disadvantages may include increased computational complexity and the need for effective key management in the respective computer systems of the corresponding control devices on the corresponding nodes in the network.
[0151] Variant Scheme 2: An alternative variation might involve each control device at each node in the network preferably having a fixed key set randomly generated by a monolithically integrated quantum random number generator with a high random bit data rate, which is regenerated at specific, preferably very short, time intervals by the corresponding monolithically integrated quantum random number generator with a high random bit data rate in the corresponding control device of the respective node. This method reduces the need for continuous recalculation, but may compromise security if a node is compromised. However, this method is particularly advantageous if key set synchronization is partially lost due to a high data transmission error rate or if an intrusion is detected. In this case, the control devices can signal this and change to the undisturbed key.
[0152] Advantages of monolithically integrated quantum random number generators with high random bit rate A monolithically integrated quantum random number generator with a high random bit data rate can locally and continuously generate new encryption methods and longer keys, which are unique for each communication. This improves network security by reducing the probability that an attacker could compromise the entire communication channel by decrypting a single message. In this case, a central random number generator is not advantageous, as it could become a single point of failure.
[0153] Collaboration of quantum random number generators with high random bit data rate Monolithic integrated quantum random number generators with high random bit data rates are preferably used in collaboration, specifically by generating a new, unique key for each communication link to ensure that the key is not reused multiple times. This prevents security vulnerabilities and improves network integrity.
[0154] 17. Development of Network Defense Behaviors The technical challenge lies in developing network defense mechanisms that respond to the identification of breaches and maintain network integrity.
[0155] Variant Scheme 1: In the first variant, the control device of the node involved, or its watchdog, can detect the breach and take immediate action, preferably isolating itself from the network. Simultaneously, it uses a monolithically integrated quantum random number generator with a high random bit data rate on the control device of the node involved to generate random numbers to verify its internal security mechanisms. The advantage of this method is its rapid response, while the disadvantage may be that the relevant node becomes temporarily unavailable.
[0156] Variant Scheme 2: However, the impact can be prevented if the affected node first notifies other nodes in the network of its compromise via a pre-broadcast message, and then the affected node switches to a predefined emergency mode, such as one based on an indestructible program in the non-writable memory of its control unit. Therefore, an alternative variant involves the control unit of the affected node, in addition to isolation, sending an alert to one or more remaining nodes in the network, causing these nodes to also activate their internal random number generation and / or random number monitoring and / or random number checking processes to identify and prevent similar threats. This improves the overall security of the network but may increase the load on the nodes.
[0157] Advantages of monolithic integrated quantum random number generator The optimal use of a monolithically integrated quantum random number generator with a high random bit data rate in each control device of each node in the network enables the network to respond to security vulnerabilities in a decentralized and autonomous manner. This ensures that even if one node is attacked, the rest of the network remains secure. A central random number generator cannot provide this flexibility and autonomy, and its failure would jeopardize the entire network.
[0158] Collaboration of quantum random number generators The control unit of a monolithically integrated quantum random number generator with a high random bit data rate collaborates in a way that enables it to react instantly and autonomously to potential threats. This enhances the network's resilience and ensures that the system's integrity is maintained even during attacks.
[0159] 18. Ensure the network's operational capability and integrity. The technical challenge lies in ensuring the network's operational capability and integrity, even when a node is temporarily unavailable or its operational capability is affected.
[0160] Variant Scheme 1: In one variant, the control device of the node involved performs a comprehensive self-check on all verifiable components of the node after isolation, including analyzing random number generation performed by the control device's monolithically integrated quantum random number generator. Furthermore, the control device checks the integrity of the encryption key. For verification, the control device can, for example, store a key set a second time in encrypted form in its specially secure memory. The advantage of this method is its ability to thoroughly verify and restore the node's security, while the disadvantage may be the time-consuming verification process.
[0161] Variant Scheme 2: An alternative variation might involve the control devices of the involved nodes still communicating to a limited extent during self-testing, but only with minimal data through other protected secure channels. In this case, it is preferable not to send or receive particularly sensitive data. This approach ensures a certain level of connectivity but may increase implementation complexity.
[0162] Advantages of monolithically integrated quantum random number generators with high random bit rate A monolithically integrated quantum random number generator with a high random bit data rate can quickly and efficiently verify the security-critical functions of a node without accessing external resources. This enhances the autonomy and security of the node. A central random number generator cannot achieve this because it cannot perform decentralized self-checks.
[0163] Collaboration of quantum random number generators with high random bit rate A monolithically integrated quantum random number generator with a high random bit data rate supports continuous verification and recovery of node integrity by autonomously generating and verifying random numbers, thereby ensuring that the security and operational capability of the network are still guaranteed even when nodes are temporarily isolated.
[0164] 19. Safety Management and Use of Safety-Critical Functions The technical challenge lies in enabling secure management and use of safety-critical functions in vehicles by generating and managing very long one-time ciphers (OTPs) with high randomness quality and strong side-channel security using a monolithic integrated quantum random number generator with a high random bit data rate. This prevents unauthorized access to these safety-critical functions.
[0165] Variant Scheme 1: In one variant, a monolithically integrated quantum random number generator with a high random bit data rate generates very long and therefore highly secure OTPs in the control devices of these nodes. These OTPs are necessary for accessing security-critical functions, such as starting an engine or deactivating a safety device. The advantage of this approach is its high security, as each OTP can only be used once, is difficult to replicate, is extremely long, and is highly random. Its disadvantage may be the need for continuous synchronization between nodes to properly manage the OTPs. This can reduce the effective data rate in the network.
[0166] Variant Scheme 2: An alternative variant might involve having OTPs generated using a monolithically integrated quantum random number generator with a high random bit data rate that are only valid for a finite period of time, automatically being replaced by new OTPs if not used within that timeframe. This further enhances security, but could lead to problems if these OTPs are not synchronized in a timely manner. For this reason, using a software-based, encrypted storage solution is advantageous.
[0167] Advantages of monolithic integrated quantum random number generator A monolithically integrated quantum random number generator with a high random bit data rate in the control unit of a network node can quickly and securely generate longer and more secure OTPs directly in the control unit of the relevant node, without relying on a central system. This improves the security and flexibility of the system. A central random number generator is not suitable here, as it may reduce the security and availability of the OTP if it is compromised or overloaded.
[0168] Collaboration of quantum random number generators The control units of monolithically integrated quantum random number generators with high random bit data rates within the network nodes cooperate to ensure that these OTPs are synchronized and securely distributed across the nodes. This ensures that only authorized users can access security-critical functions and protects these functions from unauthorized access.
[0169] 20. Ensure network communication and operational capabilities. The technical challenge lies in ensuring the network's communication and operational capabilities even when potential threats are identified or one or more nodes are compromised.
[0170] Variant Scheme 1: In one variant, the control device of the involved node can identify a potential threat and switch to a minimum operating mode implemented by a preferred computer and / or machine for the control device of the involved node. Preferably, only the safety-critical functions of the involved node, particularly those in the form of predefined computer and / or machine-implemented emergency response methods, remain active in emergency situations, and communication through the control device of this node is reduced to the necessary minimum. The advantage of this method is its rapid response and maintenance of security functions, while the disadvantage may be the limitation of node functionality.
[0171] Variant Scheme 2: An alternative variation might involve the control unit of the affected node identifying the threat and sending a message to other nodes, which then strengthen their security measures and may use alternative, preferably more secure, communication paths and / or methods to isolate the affected node. This approach improves network security but could increase the load on the remaining nodes.
[0172] Advantages of monolithic integrated quantum random number generator A monolithically integrated quantum random number generator with a high random bit data rate enables the control devices of corresponding nodes to respond quickly and securely to threats by protecting security-critical functions and maintaining communication within the network. A central random number generator cannot guarantee this rapid response and is more vulnerable to attack.
[0173] Collaboration of quantum random number generators The control units of nodes equipped with monolithically integrated quantum random number generators with high random bit data rates cooperate to ensure that security and communication within the network are maintained even in the event of a threat. This enhances the network's resilience and protects it from attacks or failures.
[0174] The above description illustrates the flexibility and adaptability of distributed vehicular networks equipped with monolithically integrated quantum random number generators with high random bit data rates. These monolithically integrated quantum random number generators with high random bit data rates not only provide high quality and security in generating encryption keys and random numbers, but also flexibly adapt to different security requirements and respond quickly to threats. Through the distributed structure of the network and the close cooperation between the node control devices and the monolithically integrated quantum random number generators with high random bit data rates, the attack surface is minimized, and the network's security and resilience are maximized. The above variant schemes illustrate how specific technical challenges are addressed and the advantages of such networks for use in vehicles.
[0175] Another aspect of this disclosure relates to a node-specific integrated quantum random number generator, wherein the quantum random number generator shown as an entropy source preferably has an integrated quantum random number generator (iQRNG) as described in the invention. Here, the terms "quantum random number generator" and "quantum random number generator" are used essentially synonymously. The entropy source of such an integrated quantum random number generator for a network node according to the invention, a sub-network according to the invention, or a network node according to the invention preferably comprises a photon source and a single-photon detector, wherein the photon source and the single-photon detector shown are stacked vertically on a common substrate made of semiconductor material. The entropy source of the iQRNG according to the invention may also comprise multiple photon sources coupled to a single single-photon detector (e.g., for improving photon rate or fault tolerance) or multiple single-photon detectors coupled to a single photon source (e.g., for monitoring purposes). The iQRNG according to the invention may include one or more such entropy sources. Multiple photon sources and single-photon detectors may also be combined into the entropy source of a single iQRNG.
[0176] Therefore, the quantum random number generator as an entropy source preferably includes, in particular, an integrated quantum random number generator (iQRNG), especially a photonic QRNG monolithically constructed in a shared semiconductor substrate in the same material system in a scalable and fully integrated manner, consisting of a photon source and a detector for a single photon directly coupled to the source, implemented in a particularly compact and attack-resistant manner on a technology platform for semiconductor structuring that is open for a wide range of applications.
[0177] According to the present invention, the nodes of the subnetworks of the network according to the present invention are interconnected in data technology via data lines and have one or more such quantum random number generators (iQRNG). An integrated quantum random number generator (iQRNG) may include a photon source and a single-photon detector, wherein the photon source and the single-photon detector are arranged vertically stacked on a common substrate made of semiconductor material. Here, vertical stacking means that the photon source and the single-photon detector are arranged in a manner that stacks on top of each other at different depths relative to the substrate surface (in this case, for example, arranged side-by-side in a horizontal direction). Vertical stacking preferably means that the propagation direction of photons transmitted between the photon source and the single-photon detector has at least one component in the aforementioned vertical direction. Therefore, as long as the photons emitted by the photon source can be detected by the single-photon detector using at least one propagation component in the aforementioned vertical direction, the photon source and the single-photon detector can also be laterally offset from each other or tilted relative to the active region of the substrate surface. Particularly preferably, the propagation of photons essentially (i.e., in the beam optics approximation without diffraction effects) has only one component in the aforementioned vertical direction (i.e., no horizontal component). The iQRNG according to the present invention may also include multiple photon sources coupled to a single single-photon detector (e.g., for improving photon rate or fault tolerance) or multiple single-photon detectors coupled to a single photon source (e.g., for monitoring purposes). Multiple photon sources and single-photon detectors may also be combined into a single iQRNG.
[0178] Therefore, unlike existing technologies, the optoelectronic components in the entropy source of the iQRNG are not arranged side-by-side. Specifically, the photon source and single-photon detector should be compactly stacked on a common substrate made of semiconductor material. Silicon is preferred as the semiconductor material. Direct semiconductors (such as GaAs) or composite semiconductors made of group III / V semiconductor materials or more complex semiconductor materials that can be engineered to utilize bandgap energy can also be considered. Thus, the iQRNG is a particularly compact monolithic 3D integration with minimal required area, wherein these structures are preferably integrally formed. In this case, a particular arrangement is preferred, in particular, in which at least one of the one or more single-photon detectors is arranged deeper in the corresponding semiconductor material compared to at least one of the one or more photon sources (i.e., photon source above, single-photon detector below) to better shield against external influences. However, in another embodiment, the associated exemplary single-photon detector may also be arranged higher in the semiconductor material compared to the associated photon source (i.e., photon source below, single-photon detector above). In addition to reversing the basic structure during the processing of the surface of the substrate (especially a semiconductor substrate), the reversed layout of the components can also be achieved by constructing them from the back side of the semiconductor substrate. In particular, the components can be constructed from both the front and back sides of the semiconductor substrate.
[0179] The photon source is preferably a single-photon source (SPS), which is suitable for providing only one or several photons simultaneously. In this application, such a photon source that provides only one or several photons simultaneously is also referred to as a single-photon source. However, it is not necessarily a true single-photon emitter; for example, it can be based on a single isolated two-level system. More precisely, a conventional light source can also be constructed as an SPS by having a correspondingly higher attenuation of the emitted or fed current. It is preferably a silicon LED or a PN junction in a semiconductor substrate or a pip, pin, or nin structure in a semiconductor substrate or a functionally equivalent semiconductor structure in a semiconductor substrate.
[0180] In this disclosure, a semiconductor substrate refers to the entire semiconductor chip as the host, in which specific device structures are constructed into the semiconductor material, for example by means of CMOS, bipolar, BiCMOS, or other semiconductor process technologies, such as by constructing wells or regions doped in different ways and / or by oxidation, trench etching, and / or under-etching. However, structures can also be formed additively by applying other layers and structures in a structured and / or unstructured manner, or by a series of etching and application steps of such other layers and structures. Such methods are well known from microstructure technology and microelectronics manufacturing methods. Relevant professional literature is cited in the document presented herein. Therefore, in addition to the so-called carrier substrate or bottom substrate (e.g., an unstructured single-crystal semiconductor substrate serving as the basis for the epitaxial growth of other semiconductor layers), the corresponding semiconductor substrate may also include multiple such epitaxial growth layers and other coatings. Therefore, in this application, a semiconductor substrate refers to a material carrier used for the semiconductor structure of the iQRNG according to the present invention, and not a simple carrier substrate or bottom substrate used for applying these structures. In this regard, especially compared to a combination consisting of at least one photon source and at least one single-photon detector that is hybridized and integrated by means of conventional methods (e.g., by means of flip-chip mounting), the iQRNG according to the invention is integrally formed by stacking each other in a common substrate constructed of semiconductor material, particularly for example, confined on a common substrate as a carrier structure.
[0181] The photon source is preferably a light-emitting diode (LED) operating at a point below or near its breakdown voltage, and more preferably a PN diode. A particularly preferred photon source is a light-emitting avalanche Zener diode (Zener-avLED) operating at a point below or near its breakdown voltage. The Zener-avLED preferably has a breakdown voltage of <10 V, more preferably <8 V, and more preferably <7 V. This breakdown voltage can be well tunable according to methods known in the prior art and can be precisely tunable during the design phase using a known device simulator by pre-setting the doping profile and structure. The advantages of using a Zener-avLED as a single-photon source will be described in detail below. This novel single-photon source can achieve high single-photon rates at relatively low operating voltages within or below the Zener breakdown voltage range, and, with the appropriate desired design, the generated photons are preferably directionally radiated into the substrate, thereby radiating towards the single-photon detector. Therefore, the Zener-avLED is particularly suitable as a single-photon source in the entropy source (or iQRNG) of a quantum random number generator.
[0182] One or more single-photon detectors are preferably one or more single-photon avalanche diodes (SPADs). These are detectors that, in principle, are capable of detecting and identifying a single photon based on their exceptionally high sensitivity under high amplification and low (dark) noise conditions.
[0183] Therefore, a key concept of this invention is to provide a particularly compact and secure integrated QRNG by stacking Zener-avLEDs and SPADs on a shared semiconductor substrate. This provides a particularly compact and secure entropy source for each network node of the aforementioned subnetworks of the proposed network, and the binary system enables a higher random number data rate than existing technologies. Thus, from an overall network perspective, the proposed network has the ability to generate high-quality and highly secure random numbers at a high data rate within the network. Therefore, when such a network includes a sufficient number of corresponding nodes with the proposed quantum random number generator, it will outperform all networks with a central quantum random number generator and all networks with conventional iQRNGs.
[0184] One way to improve upon existing iQRNG technologies for the purpose of application is to select a broader technology platform. For SoC designs with the widest applications, integrated circuits employing silicon-based bipolar CMOS-DMOS technology (BCD technology) hold significant potential. Highly efficient SPADs have also been demonstrated and implemented in BCD technology. In this case, BCD technology allows for particularly efficient and optimized integration of these SPADs with multiple other functional groups, such as digital and analog circuit components, especially high-efficiency digital memories and switching elements, general-purpose power and drive electronics, and detector and sensor components.
[0185] In principle, silicon-based SPSs, known from existing technologies, can also be implemented using BCD technology. However, due to the non-directional emission of photons and the fact that implementation typically occurs near the surface, such Si-LEDs are not optimal for achieving particularly efficient and attack-resistant iQRNGs. Even when using Si-LEDs in avalanche mode, near-surface implementation usually introduces degradation. Furthermore, since silicon as an indirect semiconductor is not well-suited for photon generation and can typically only generate these photons through other processes involving additional interactions with the crystal lattice, the selection of possible alternative photon sources based on silicon is very limited.
[0186] In studying Zener diodes provided in different layers via corresponding pn junctions using BCD technology, the inventors discovered, contrary to the general expectation of those skilled in the art, that in this configuration, strong electroluminescence with an efficiency of at least 0.03% can be observed at the Zener diodes at breakdown voltage in avalanche mode. These Zener diodes are optimal even in the breakdown region in terms of their permanent operating point, with the near-surface Zener diode acting as an emitter and the simple pn diode below it acting as a detector in zero-bias mode. In the prior art, the corresponding Zener diodes are generally unsuitable for operation as optoelectronic devices (LEDs).
[0187] In particular, photons emitted in the direction of the lower pn diode are preferred, so that this diode can detect almost all emitted photons. This point can also be demonstrated by the photocurrent in the structure of the present invention (see...). Figures 4 to 7(See attached figures). As can be seen, the Zener diode studied exhibits a low but significant efficiency over the breakdown / Zener voltage range (approximately one photon is detected for every 3000 electrons in the Zener diode current), making it highly suitable as a single-photon source for implementing QRNGs using silicon-based BCD technology. The preferred radiation towards the detector offers a significant advantage compared to the isotropic radiation of conventional photon sources used in the entropy sources of conventional iQRNGs. Silicides, commonly used in CMOS technology, are used to demonstrate a reduced contact resistance between the metal contacts and the semiconductor silicide. Being both opaque and reflective, they can reflect photons originally emitted upwards back into the substrate on the silicide mirror surface. Therefore, unlike known Si-LEDs in the prior art, the Zener diode constructed accordingly and operating as an SPS in avalanche mode is also referred to below as an avalanche light-emitting Zener diode (Zener-avLED).
[0188] The Zener-avLEDs provided in the BCD technology exemplified here emit photons in the visible spectrum and have a relatively low Zener operating voltage, typically below 8 V. Furthermore, since the radiation of Zener-avLEDs is typically oriented in a certain way to preferably emit photons vertically, i.e., away from the surface and into the substrate, stronger isolation of the SPS and the generated photons from the semiconductor material environment can be achieved when applied in iQRNGs, making it more difficult to capture or inject photons on the detector surface. Moreover, with proper construction of the SPAD within the iQRNG, the efficiency of random number generation can be significantly improved and uncontrolled propagation of photons within the semiconductor material can be largely prevented.
[0189] Therefore, the second fundamental component of constructing a compact QRNG is selecting a suitable SPAD design. These SPAD designs are typically implemented near the surface using BCD technology by constructing p-wells or n-wells accordingly. Such near-surface SPADs are similar to SPADs implemented using CMOS technology in the prior art. Therefore, the iQRNG principle known from EP 3 529 694 B1 can also be implemented using the aforementioned Zener-avLED with BCD technology. However, as mentioned above, Zener-avLEDs advantageously emit photons toward the substrate. Side-by-side arrangements of Zener-avLEDs as SPSs and near-surface SPADs, as known in the prior art, are generally achievable, but not necessarily effective. Therefore, when using Zener-avLEDs, it is advantageous to arrange the associated SPADs below the Zener-avLEDs.
[0190] In addition to realizing traditional n-SPAD and p-SPAD, BCD technology can also realize a completely new SPAD concept by using n-type or p-type doped buried layers in the BCD substrate.
[0191] A particularly efficient and deeper single-photon avalanche diode (“deepSPAD”) can be realized through a method recently developed by the inventors, which involves generating a deep pn junction in a BCD process for providing a corresponding BCD substrate with a deep pn junction. This deep SPAD can be easily positioned directly below a Zener-avLED suitable for providing single-photon signals. Therefore, unlike the horizontal integration of CMOS-based QNRGs (or entropy sources of iQRNGs) according to prior art, the combination of Zener-avLED and deep SPAD provides the basic components of a QRNG that are vertically integrated entirely using BCD technology.
[0192] By employing a vertical layout of Zener-avLEDs as transmitters and deep SPADs as receivers via extremely low pn junctions, miniaturized quantum random number generators based on a single silicon chip can be realized using BCD technology, offering high optical coupling, high attack security, and low operating voltage. Therefore, the BCD-based iQRNG design with a vertical entropy source described herein represents the optimal solution for providing the iQRNG according to the present invention. Compared to conventional lateral 2D designs, vertical 3D integration, in particular, further enhances the compactness of the iQRNG (or the entropy source of the iQRNG) and reduces area consumption while providing efficiency.
[0193] Therefore, the iQRNG (or the entropy source of iQRNG) according to the present invention is preferably constructed in a BCD substrate using BCD technology.
[0194] The BCD substrate preferably includes a carrier substrate and an epitaxial layer grown on the carrier substrate, wherein a deep pn junction is generated in the epitaxial layer by diffusion of a dopant in the surface of the carrier substrate below the epitaxial layer between the carrier substrate and the epitaxial layer.
[0195] The preferred substrate is a p-type substrate. However, n-type or intrinsic substrates can also be used. The substrate material is, in particular, silicon. In principle, these methods can also be applied to other semiconductor materials. Boron is a typical dopant used to form the p-region. Phosphorus (P), arsenic (As), or antimony (Sb) can be used to form the n-region. Compared to heavier donors (P, As, or Sb), boron diffuses further in silicon, for example, as a dopant. Furthermore, due to the higher dosage used, the resulting n-region is largely dominant; that is, the phosphorus-doped n-region retains its existing conductivity type even after the supplementary introduction of boron. In conventional BCD processes, additional masking, photolithography, and epitaxial steps are sometimes omitted to provide a deep pn junction.
[0196] The first and second dopants preferably have different diffusion characteristics in the carrier substrate and / or epitaxial layer. The mobility of the second dopant in the carrier substrate and / or epitaxial layer is preferably higher than that of the first dopant. The first and / or second dopants are preferably introduced in a maskless manner or by a masking method. For example, a direct ion beam writing process can be used for maskless introduction. When using a masking method, introduction is performed using a previously provided mask, such as by chemical or physical deposition or by an ion beam writing process. In a top view of the surface of the carrier substrate, the first or second region preferably completely overlaps with the corresponding other region immediately after the introduction of the second dopant. The first region is preferably an n-type buried layer (NBL layer), and the second region is preferably a p-type buried layer (PBL layer).
[0197] The single-photon detector preferably forms an avalanche region in the region surrounding the deep pn junction and includes an absorption region for converting photons into electron-hole pairs, wherein the absorption region is adjacent to the deep pn junction.
[0198] Preferably, this deep pn junction is at least partially constructed between an n-type buried layer serving as the cathode and a p-type buried layer immediately adjacent to the n-type buried layer. This absorption region is also preferably adjacent to the p-type buried layer and is substantially constructed as a p-region. This essentially indicates that this absorption region can also be partially constructed as an intrinsic region. Furthermore, it is constructed as a p-region... + The anode of the region is preferably located adjacent to this absorption region.
[0199] Preferably, a second deep pn junction (e.g., located in the carrier substrate) constructed below the deep pn junction in the epitaxial layer of the single-photon detector is used as an additional photodetector for detecting external attacks. In some embodiments, the second pn junction is generated below the first pn junction using the method described above for generating deep pn junctions in the BCD process (see...). Figure 3(See attached figures). This second pn junction, based on its essentially the same electronic properties, can also be used as a photodetector or a single-photon avalanche diode. Because this additional photodetector is arranged deep within the semiconductor material beneath the actual QRNG, it provides protection against photon injection from the back of the substrate. These photons can be detected close to the QRNG over a wide angular range. This allows for the detection of external attacks with a high probability.
[0200] Furthermore, the additional photodetector can be adapted to monitor the photon count rate via additional evaluation electronics. Under otherwise constant operating conditions, the photon source and associated single-photon detector should have a substantially constant photon count rate, aside from random statistical fluctuations in relation to the measured photon events. However, not all photons emitted by the photon source can be detected by the associated single-photon detector, and external natural influences (such as cosmic rays) and artificial irradiation (such as wireless power) can also induce individual detection events on the additional photodetector. Therefore, the second photodetector also has a certain probability of having a substantially constant background count rate. Thus, deviations from this long-term statistical average can indicate potential errors or external interference within the iQRNG, such as attacker interference. In this case, changes in the background count rate measured on the second photodetector can enable both active intervention by an attacker (e.g., injecting additional photons to alter or influence photon statistics) and passive attacks, such as by selectively thinning the shielding to increase the outward transmission of individual photons (but this could also induce supplemental irradiation from ambient light in this direction).
[0201] Background count rate is also a statistical variable; therefore, machine learning-based evaluation methods are suitable for assessing potential deviations from expected normal values. In particular, artificial intelligence methods can be used for evaluation. It is especially preferable to use at least one corresponding trained artificial neural network (KNN) to determine attacks and / or identify potential sources and events of error. Several different types of artificial neural networks can be found in the literature, and those skilled in the art can typically choose the appropriate method based on their specific requirements.
[0202] In some implementations, at least one ANN may include a random neural network (SNN) that can provide variable outputs for the same photon counting rate. This allows for the investigation of network errors based on existing data or insufficient network training. For example, it can also be used to identify out-of-distribution biases in the training dataset.
[0203] Another possible use of the second deep pn junction as an additional photodetector is to provide independent random numbers based on another independent photon source located below the second deep pn junction or arranged on or near the back of the substrate. For this purpose, the second deep pn junction is preferably also configured as a single-photon detector or SPAD in a manner similar to the first deep pn junction above it. The absorption of photons in the region of the first single-photon detector can also be affected by a probability distribution, and depending on the specific implementation of the layout of the various elements, a single photon from the actual photon source of the iQRNG according to the invention can also enter the region of the second deep pn junction. Therefore, these photons can also be used as the basis for providing quantum random numbers, for example, as an accessory independent iQRNG.
[0204] However, regardless of whether the second deep pn junction is used as an additional photodetector, the iQRNG (or corresponding quantum random generator) according to the invention may also include another photodetector independent of the aforementioned deep pn junction. This other photodetector is preferably also integrated into the iQRNG according to the invention, but it may also be connected to the iQRNG according to the invention in a hybrid manner. This other photodetector is particularly preferably also a single-photon detector, such as a SPAD. The additional photodetector can also be used to monitor the functionality and security of the iQRNG according to the invention in a manner similar to the above-described application of the second deep pn junction.
[0205] The first deep pn junction and the second deep pn junction are preferably interconnected via a common internal terminal (e.g., a common anode or cathode). Typically, a pn junction suitable for operation as a single-photon detector is directly connected to one side of this pn junction via the substrate. However, particularly when employing BCD technology, due to the conventional shielding or isolation of these structures and circuits from the substrate, the corresponding terminals are usually placed on the substrate surface for contact. However, in the embodiment of the invention with a dual pn junction structure, a common terminal region (anode or cathode) is directly formed, which can be jointly controlled via separate contacts (e.g., on the substrate surface).
[0206] In the region of the iQRNG (or the entropy source of the iQRNG), the top and / or bottom sides of the substrate are preferably mirror-coated or include a light-blocking layer on the surface. Mirror coating of the substrate surface (e.g., by means of a metallization layer or the application of a dichroic layer) and the application of a light-blocking layer are both known in the prior art and have been discussed above. In the iQRNG according to the invention, these methods can also be used to shield external photons (“light blocking”) and to improve efficiency by back-reflecting photons generated by the relevant photon source. Furthermore, as an alternative or supplementary solution, appropriate encapsulation can be performed in the region of the iQRNG or the region can be surrounded by a metal enclosure.
[0207] The surface of the substrate is preferably covered with a silicide layer in the region of the iQRNG (or the entropy source of the iQRNG) and then covered with a metallization layer. The metallization layer in the region of the iQRNG is preferably closed. This metallization layer can be used as a mirror coating for the internal regions and / or as a wavelength-independent shielding against external photons. The same applies to the constructed silicide layer.
[0208] Preferably, a combination of at least one of the following elements—a metal overlay, sidewall contacts, and vias—is used to prevent photons provided by a photon source or a single photon source from escaping onto the substrate surface and / or the substrate back side. These elements enable essentially complete shielding or encapsulation of the iQRNG (or its entropy source), thereby ensuring high immunity to external interference in addition to outward shielding.
[0209] However, in terms of potential attack scenarios, besides purely optical influences or reading out the emitted photons, other external access paths are conceivable. Therefore, another aspect of the invention lies in further strengthening the iQRNG according to the invention, which, based on the specific layout of its included photon source and associated single-photon detector, already possesses significantly improved security compared to the prior art against unauthorized access and external influences (e.g., the influence of observers or attackers). The aforementioned and possible optical shielding, for example, could potentially enable further attacks based on targeted assessments or influences of the chemical or electronic properties of the iQRNG according to the invention.
[0210] As mentioned above, quantum random number generators (QRNGs) utilize the principles of quantum mechanics to generate truly random numbers, which can be used in cryptography and other security-critical applications. These random numbers are crucial because they form the basis for secure encryption keys and other encryption processes. However, despite the theoretical security of QRNGs, they are vulnerable to various types of side-channel attacks, which can compromise the integrity and confidentiality of the generated random numbers.
[0211] One possible attack vector is electromagnetic radiation. QRNGs can emit electromagnetic signals that attackers can intercept and analyze. These signals can reveal information about the internal state of the QRNG, allowing attackers to reconstruct or predict the generated random numbers. To prevent such attacks, QRNGs should be properly shielded and protected from electromagnetic radiation.
[0212] Another attack vector is power consumption. The power consumption of a QRNG varies as random numbers are generated. An attacker can measure these fluctuations and infer the generated random numbers from them. This can be achieved by using highly sensitive current measurement devices that can detect even the smallest changes in power consumption. To prevent such attacks, the QRNG should be designed in a way that its power consumption remains constant, independent of the generated random numbers.
[0213] Temperature dependence also plays a role. QRNG performance may be temperature-dependent; that is, changes in ambient temperature can affect random number generation. Attackers could manipulate the device's temperature to influence or predict these random numbers. To prevent such attacks, QRNGs should operate in temperature-controlled environments and have mechanisms to maintain stable performance independent of temperature fluctuations.
[0214] With respect to optical QRNGs (such as the iQRNG according to the present invention), attackers can also attempt to influence the light source or monitoring detector in order to manipulate the generated random numbers. This can be achieved by introducing additional light or by blocking light. To prevent such attacks, the QRNG should be well shielded and protected against external influences.
[0215] There are also so-called timing attacks. By measuring the time it takes for a QRNG to generate random numbers, an attacker can identify patterns and predict random numbers. This can be achieved by using high-precision time measurement devices that can detect even the smallest differences in generation time. To prevent such attacks, QRNGs should be designed in a way that their generation time remains constant, independent of the random numbers generated.
[0216] Chemical attacks on semiconductor integrated QRNGs are a less studied but potentially very serious risk. These attacks may, for example, be designed to alter the physical properties of the semiconductor components in order to affect or disrupt random number generation.
[0217] One possible form of chemical attack involves altering semiconductor materials through chemical reactions. This can be achieved through the action of corrosive substances that damage the integrity of the semiconductor structure. Such attacks could affect the performance of QRNGs by reducing the efficiency of the light source or detector, or by altering the electrical characteristics of the circuitry.
[0218] Another potential chemical attack could involve targeted doping of semiconductor materials. By introducing impurity atoms into the semiconductor layer, an attacker could alter the material's electronic properties, thereby affecting random number generation. This could make the generated random numbers predictable, severely compromising the security of QRNGs.
[0219] Although chemical attacks on QRNGs are currently theoretical and not widely used in practice, these potential threats should be considered and measures should be taken to ensure the chemical stability and integrity of QRNGs. This can be achieved, for example, by using protective coatings, selecting chemically resistant materials, and implementing monitoring mechanisms to identify chemical changes.
[0220] These potential attack scenarios demonstrate that even state-of-the-art QRNGs are not entirely immune to side-channel attacks. Therefore, additional security measures are needed to ensure the integrity and confidentiality of the generated random numbers. These measures include physically shielding the device, implementing mechanisms to stabilize power consumption and generation time, and operating in a controlled environment.
[0221] In the iQRNG according to the invention, the aforementioned shielding can be achieved directly through the implementation of the structural system itself or by embedding the entropy source within the substrate. For example, shielding against electromagnetic and optical radiation or irradiation can be achieved through a shared and continuous metallization layer on the substrate surface above the entire structural space of the iQRNG (or the associated entropy source). Alternatively, a metallization layer can be applied at a corresponding location on the bottom side of the substrate to shield the lower structural space. In addition to the shielding function, these individual metallization layers also enable electrical contact in a single region of the iQRNG. In this case, it is preferable to stack multiple metallization layers to increase the layer thickness (e.g., 12-15 layers).
[0222] Multilayer metal shielding generally provides better shielding than single-layer metal shielding. This is because multiple layers composed of different or identical metals can be combined to achieve maximum shielding effectiveness. One reason is that each metal layer can reflect and absorb electromagnetic waves. Combining multiple layers increases the possibility of multiple reflections and absorptions of electromagnetic waves, thus improving overall shielding. Different metals have different shielding properties. More effective shielding can be achieved by combining metals with complementary properties. For example, a layer of highly conductive metal (such as copper) can be combined with a layer of ferromagnetic material (such as nickel). Multiple layers also help dampen penetration effects that might occur when using a single layer. This is especially important for high-frequency electromagnetic waves that tend to penetrate thinner metal layers. Furthermore, multilayer shielding provides additional safety planes. Even if one layer is damaged or corroded, the other layers can still provide effective shielding.
[0223] Instead of one or more metal layers, a layer made of polycrystalline silicon can be applied to the substrate surface in the region of the iQRNG to shield against electromagnetic radiation, including photons. Polycrystalline silicon is commonly used in the semiconductor industry, particularly for manufacturing transistors and solar cells. Although polycrystalline silicon does not provide the same shielding performance as metals, and generally has higher optical transmittance for photons at the same thickness, it is a more advantageous process in terms of manufacturing technology.
[0224] In addition to the aforementioned shielding layer or as a single element, it is preferable to cover one (or a region or portion thereof) of a circuit or IC including the iQRNG according to the invention using a layer made of silicon nitride (SiN). This layer allows a pre-defined hydrogen content (H2) in the IC to be kept as constant as possible, since the SiN layer has very low permeability to this. A constant hydrogen content is particularly important for the manufacture and operation of the IC for several reasons. First, hydrogen helps avoid defects in semiconductor materials (e.g., silicon). These defects can impair the electrical properties of semiconductor devices and cause malfunctions. A constant hydrogen content minimizes such defects and ensures the reliability of the IC. Furthermore, hydrogen is often used to passivate the surfaces of semiconductor materials. That is, hydrogen bonds to surface atoms, thereby reducing the number of free electrons that could cause undesirable chemical reactions. A constant hydrogen concentration ensures that passivation remains effective. Hydrogen also helps reduce the oxidation of metal compounds in the IC. Oxidation can reduce the conductivity of metal compounds, thereby impairing the performance of the IC. A constant hydrogen content helps control oxidation and maintain the conductivity of metal compounds. Finally, fluctuations in hydrogen content can cause changes in the electrical properties of semiconductor materials. This can affect the performance and reliability of ICs and can also open up chemical attack vectors. In this case, a constant hydrogen content helps maintain stable electrical properties and ensures consistent performance.
[0225] The lateral regions surrounding the iQRNG or its included entropy sources can be achieved by correspondingly deep doping of the substrate or by designing it as a conductive region. This arrangement can be used simultaneously for deep contacts within the substrate region, such as for buried layer contacts, in a manner similar to metallization layers on the substrate surface. However, to avoid additional electromagnetic radiation caused by these structures, it is preferable not to use them for transmitting modulated signals. In the exemplary embodiment of the iQRNG according to the invention, as shown in the figures, this shielding region can be identified as an isolated external deep structure extending vertically from the surface into the substrate. In a preferred embodiment of the iQRNG according to the invention, the "detector surface" of the single-photon detector is constructed as a circular structure, such that the lateral shielding is preferably formed as a closed annular cylindrical structure (but this shielding can have any shape, preferably laterally closed). This arrangement for lateral shielding against electromagnetic radiation values is also referred to as a so-called sealing ring (iQRNG sealing ring).
[0226] Isolation trap regions, typically constructed using BCD technology, are used for shielding, particularly around photon sources and single-photon detectors. These regions are often used to electrically isolate different areas within the substrate, allowing for the provision of different reference potentials (GND) in these areas, for example. However, this localized isolation also provides current cutoff for signal transmission and, with proper construction of the individual trap regions, can effectively suppress electromagnetic coupling within the isolation areas.
[0227] As a further shielding element, the iQRNG according to the invention (or an IC comprising one or more iQRNGs according to the invention) can be conventionally encapsulated using common potting materials (such as plastics). The plastic can be, in particular, a thermosetting plastic. In this case, processable silica (such as SiO2) can be added to the thermosetting plastic to adjust the coefficient of thermal expansion of the interconnected materials.
[0228] Preferably, multiple iQRNGs according to the invention or multichannel QRNG systems comprising multiple iQRNGs according to the invention (e.g., having one or more entropy sources according to the invention) are implemented on the same substrate to improve the data rate of quantum random bits. In this case, by combining the compact shielding of the entropy sources of a single iQRNG, extremely high integration density can be achieved by means of one or more sealed and preferably decoupled entropy sources of one or more iQRNGs, thereby achieving a high overall effective random number rate. Regarding the entropy sources of iQRNGs in the prior art, the integration density is mainly limited by the juxtaposition of individual component structures.
[0229] The iQRNG according to the invention preferably includes electronic circuitry for generating and outputting a sequence of digital random numbers based on a statistical evaluation of the timing of signals from one or more single-photon detectors (single-photon detector signals).
[0230] Another aspect of the invention relates to an integrated electronic circuit (IC) comprising at least one iQRNG according to the invention. It is particularly suitable as an IC for use in security-related system-on-chip (SoC) applications.
[0231] Preferably, the iQRNG (or the entropy source of the iQRNG) according to the invention is placed within the pad frame (also called the pad edge) of the integrated electronic circuit. The electronic circuitry for generating and outputting digital random number sequences is also preferably located within this pad frame. For non-pad-specific integrated electronic circuits, there is typically a large amount of free area within the pad frame, but this free area is generally unusable for digital circuits or larger analog circuit blocks. However, the iQRNG according to the invention, having both the entropy source according to the invention and the electronic circuitry according to the invention for generating and outputting digital random number sequences, is correspondingly smaller in size due to its extremely compact structure, and subsequent circuitry typically includes only a small number of gates; therefore, such a QRNG can still be fully or at least partially integrated into a conventional pad frame. Due to the extremely compact structure of the iQRNG according to the invention, it can also be implemented in existing integrated electronic circuit designs in a space-saving and cost-effective manner. This significantly reduces area consumption compared to conventional methods of integrating QRNGs. In this case, the advantages of the iQRNG according to the invention can be fully utilized.
[0232] Compared to known implementations in the prior art, the advantages of the iQRNG according to the present invention lie primarily in the further miniaturization of the entire random number generator structure and the resulting high degree of integration and miniaturization of the structure. Since the SPS and associated SPAD are completely isolated from the environment, the security of random number generation is significantly improved. The directional vertical radiation from the Zener-avLED used as the SPS also contributes to improved security and significantly increases the efficiency of random number generation, thereby increasing the number of random bits and the random number rate.
[0233] Especially when using common low-cost planar techniques (i.e., processing only from one side of the substrate without using other complex methods, such as hybrid integration, for example by chip method), the co-integration of suitable photon sources and single-photon detectors on the same vertical layout cross-section of a shared substrate has been impossible in the prior art until now.
[0234] A second deep pn junction, constructed beneath the pn junction of the SPAD using novel BCD technology, can be used as an additional photodetector to monitor attacks, particularly from the backside of the iQRNG substrate of the relevant node in the network according to the invention. The optical coupling efficiency, isolation, and security of the relevant SPAD can be further improved by using internal metal and silicide mirrors. Compared to existing technologies, the Zener-av LED used as a photon source requires only a relatively low operating voltage of <8 V. Furthermore, the absorption length of the emitted visible light in silicon is also short (i.e., the associated absorption coefficient is high), thus enabling very good optical isolation between adjacent elements. This allows for layouts in arrays with high cell density and correspondingly high generation or entropy rates.
[0235] Other aspects of the invention are disclosed in the appendices or the following description of the drawings. Attached Figure Description
[0236] The invention will now be described in conjunction with the accompanying drawings and embodiments. Wherein: Figure 1 This is a top view schematic diagram of a first embodiment of iQRNG according to the prior art; Figure 2 This is a side view schematic diagram of a second embodiment of the iQRNG according to the prior art; Figure 3 A schematic diagram of a BCD substrate provided for a method of providing a deep pn junction using BCD technology, and a TCAD diagram of the resulting dopant distribution; Figure 4 This is a schematic diagram of an exemplary first embodiment of the iQRNG according to the present invention; Figure 5 This is a schematic diagram of an exemplary second embodiment of the iQRNG according to the present invention; Figure 6 This is a schematic diagram of an exemplary third embodiment of the iQRNG according to the present invention; Figure 7 A graph illustrating the correlation between the ratios of the SPAD current and the Zener current within the iQRNG according to the present invention (a) and b) the SPAD current and the Zener current, and the Zener reverse voltage under different SPAD reverse voltages (less than, equal to, and greater than the breakdown voltage). Figure 8 A schematic diagram of an exemplary electronic circuit for generating and outputting sequences of digital random numbers; Figure 9 A top view schematic diagram of an exemplary layout of integrated electronic circuitry with an iQRNG according to the present invention within a pad frame; Figure 10This is a schematic diagram of nodes in a distributed network, where each node is equipped with comprehensive control devices; and Figure 11 For by multiple reasons Figure 10 A schematic diagram of a distributed network composed of nodes. Detailed Implementation
[0237] Detailed embodiments, exemplarily illustrated in the accompanying drawings, will be described. The function and features of these embodiments will be explained with reference to the drawings. In these drawings, the same elements are represented by the same symbols, and redundant descriptions are omitted. This disclosure may be implemented in different forms and should not be construed as limited to the embodiments shown herein. Rather, these embodiments are illustrative to make this disclosure comprehensive and complete, so as to fully convey aspects and features of this disclosure to those skilled in the art.
[0238] Therefore, methods, elements, and techniques that are not essential for a full understanding of the aspects and features of this disclosure to those skilled in the art are not described. In these figures, the relative dimensions of elements, layers, and regions may be exaggerated for clarity.
[0239] As used herein, the term "and / or" includes all combinations of one or more of the listed elements. Furthermore, in the description of embodiments of this disclosure, "may" means "one or more embodiments of this disclosure." In the following description of embodiments, singular terms may also include plural terms unless the context clearly indicates otherwise.
[0240] Although the terms "first" and "second" are used to describe different elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. A first element may be referred to as a second element, and a second element may also be referred to as a first element, without departing from the scope of application of this disclosure. Expressions such as "at least one," when placed before a list of elements, modify the entire list, not just a single element in the list.
[0241] Terms such as “basically” and “approximately” are used as approximate terms rather than descriptions of degree, and should take into account the inherent biases of the measured or calculated values that are generally recognized by those knowledgeable in the relevant field. When the term “basically” is used in conjunction with a characteristic that can be expressed numerically, unless otherwise defined, the term “basically” means a range of at least + / - 5% centered on the numerical value.
[0242] Figure 1This is a top view schematic diagram of a first embodiment of an iQRNG (or an entropy source of an iQRNG) according to the prior art. This illustration is based on the corresponding diagram of EP 3 529 694 B1 and shows the surface O of a related substrate 110 into which the QRNG is integrated. A ring photon source 120 having a pn junction suitable for providing photons is powered and excited via corresponding contacts to emit single photons 128. To detect the emitted photons 128, a corresponding single-photon detector 130 in the form of a SPAD is arranged next to the photon source 120. However, similar to conventional hybrid methods for photon QNRGs, the photon source 120 and the single-photon detector 130 are structurally and functionally independent components, and integration is achieved only by arranging these components side-by-side in a shared substrate.
[0243] Then, the current pulses generated by the single-photon detector 130 upon absorption of photon 128 can first be recorded and evaluated in the relevant electronic sampling means 152 to generate a bit sequence, specifically based on the number of photons measured in the single-photon detector 130. Furthermore, an electronic post-processing means 154 is provided, which should be configured in a certain way to process the binary sequence from the electronic sampling means 152, thereby performing a so-called "whitening" operation. This operation should include multiple compression operations to improve the statistical properties of the generated binary sequence. This subsequent processing step should increase the entropy level of the QRNG. However, in this case, it must be ensured that the compression operations used do not introduce deterministic correlations during application, thereby compromising the predictability of the generated random numbers in principle.
[0244] To improve the efficiency of random number generation, i.e., the effective entropy rate, a light inhibitor filter 150 is used to protect the photonic portion of the QRNG on the surface O of the substrate 110. This light inhibitor filter is used to shield against external light incidence. In this case, the light inhibitor filter 150 can be provided by a metallization layer, which can be directly applied during the manufacturing process, for example, using CMOS technology as the final metallization plane. This makes the photon detector 130 unaffected by external light and makes the photon detector sensitive only to photons that pass through the substrate 110 due to crosstalk from the photon source 120. In addition, the optical coupling of the photons 128 emitted by the photon source 120 can also be improved by the metallization layer, specifically by reflecting these photons inward, thereby preventing these photons from escaping from the surface O of the substrate 110.
[0245] The disadvantage of this side-by-side arrangement of optical components lies in the distance between them, which reduces coupling strength due to the lower illumination angle and the potential photon absorption in different materials. Furthermore, despite the partial application of the light-blocking layer 150, optical access and attacks are still possible from the substrate 110 to the surface O or even from the back side of the substrate. For example, additional photons can be selectively injected or extracted, ultimately affecting and disrupting the counting statistics, and consequently affecting and disrupting the entropy of the generated random numbers. Moreover, as can be seen in the figure, individual photons 128 are emitted isotropically in all spatial directions; therefore, only a small fraction of photons 128 can be detected by the photon detector 130 for statistical evaluation. On the one hand, this significantly reduces the efficiency of random number generation; on the other hand, it causes multiple photons 128 to be emitted into the substrate 110 unused, where they can be extracted by an observer or attacker at other locations or potentially cause interference.
[0246] Figure 2 This is a side view schematic diagram of a second embodiment of an iQRNG (or an entropy source of iQRNG) according to the prior art. This illustration is based on a corresponding illustration known by Khanmohammadi et al. (“A monolithic silicon quantum random number generator based on measurement of photon detection time,” by A. Khanmohammadi, R. Enne, M. Hofbauer, and H. Zimmermann, published in IEEE Photonics Journal, Vol. 7, No. 5, pp. 1-13, October 2015, No. 7500113). In this example, the basic structure of a photon source 120 (Si-LED) and a single-photon detector 130 (SPAD) arranged side by side can also be clearly seen, with the photon source 120 adapted to emit a single photon 128. However, with Figure 1 The layout shown differs; the photon source 120 is provided here as a circular central element, which is essentially completely surrounded by a correspondingly adapted circular single-photon detector 130. A common radial symmetry axis R is correspondingly located at the center of the iQRNG thus constructed (or the center of the entropy source thus constructed). In this case, the photon source 120 is realized by an n-well constructed in a deep n-well, with the n-photon source centered around the radial symmetry axis R and introduced into the surface O of the substrate 110 (p-substrate). ++ The area (as cathode 122) and the p arranged next to it ++The region (serving as anode 124) powers this n-well. Outside the deep n-well, a single-photon detector 130 also powers the n-well via the introduced region serving as cathode 132. ++ The region and the p, which serves as the anode 134, are arranged away from the radial axis of symmetry R. ++ The region contacts surface O. A p-well is connected below the cathode 132. A p-well is constructed below the anode 134 in a deep p-well. Here, the photon source 120 is provided as a component within the structure of the photon detector 130, thus distinguishing it from... Figure 1 This forms structural and functional units.
[0247] In this example of an iQRNG (or an entropy source of iQRNG) based on existing technology, photons 128 are essentially emitted into the substrate 110 from all directions, therefore, regarding Figure 1 The disadvantages described in the illustrated implementation regarding security for observers or attackers and reduced efficiency also apply. However, with Figure 1 In contrast, integration density can be further increased through a special structure in a ring layout and the structural connection between the single-photon detector 130 and the photon source 120. Besides reducing the area consumption required to construct the iQRNG (or the entropy source of the iQRNG), this also includes advantages such as improved attack resistance and random number generation efficiency or entropy rate. This is particularly due to the reduction of photon 128 loss caused by material absorption and unfavorable emission directions by shortening all distances. Furthermore, this also locks out the area that might be attacked. However, in addition to this, there is also the possibility that an attacker could output coupling or inject single photons 128 at other locations, particularly on surface O and substrate 110, to affect the counting statistics. Therefore, this side-by-side layout of the two optical components of the QRNG has the following disadvantages that hinder particularly secure, compact, and reliable random number generation for SoC applications.
[0248] Figure 3A schematic diagram of a BCD substrate 110 provided for a method of providing deep pn junctions 50 and 52 using a BCD process, and a TCAD illustration of the resulting dopant distribution. One embodiment of the method of providing deep pn junctions 50 and 52 using a BCD process includes: providing a carrier substrate 10; introducing a first dopant into a surface S of the carrier substrate 10 to form a first region 22 (e.g., NBL) of a first conductivity type (negative for NBL); introducing a second dopant into the surface S of the carrier substrate 10 to form a second region 32 (e.g., PBL) of a second conductivity type (positive for NBL), wherein the first region 22 (NBL) and the second region 32 (PBL) at least partially overlap; and growing an epitaxial layer 40 onto the surface S of the carrier substrate 10, wherein the first region 22 (NBL) and the second region 32 (PBL) are extended by diffusion of the first and second dopants in the epitaxial layer 40, thereby forming a pn junction 50 located in the epitaxial layer.
[0249] In this diagram, region 22 is a deep NBL layer, and region 32 is a deep PBL layer. However, this order can be reversed; therefore, region 22 can also be a deep PBL layer, and region 32 can also be a deep NBL layer. The layering of pn junctions 50 and 52 can also be reversed by adjusting the diffusion length of individual dopants accordingly, for example, in... Figure 3 The NBL and PBL layers at pn junctions 50 and 52 can also be interchanged.
[0250] The difference between the above method and conventional methods for providing BCD substrate 110 according to the prior art lies particularly in that the first region 22 (NBL) and the second region 32 (PBL) at least partially overlap. In a top view of the surface S of the carrier substrate 10, particularly after the introduction of the second dopant, the first region 22 or the second region 32 may completely overlap with the corresponding other region (32, 22). Therefore, in the illustrated embodiment, in a top view of the surface S of the carrier substrate 10, after the introduction of the second dopant to form the second region 32 (PBL), this second region is then completely located within the first region 22 (NBL). In order to form a pn junction 50 in the epitaxial layer, the first and second dopants preferably have different diffusion characteristics in the carrier substrate 10 and / or the epitaxial layer 40. As shown, the diffusion mobility (and diffusion length) of the second dopant in the second region 32 (PBL) in the carrier substrate 10 and the epitaxial layer 40 may be particularly higher than that of the first dopant in the first region 22 (NBL).
[0251] To enhance diffusion, the carrier substrate 10 can be heated after the introduction of the first dopant and / or the second dopant. Furthermore, the carrier substrate 10 can be heated after the epitaxial layer 40 has grown to enhance dopant diffusion. In the described method, the first dopant and / or the second dopant can be introduced either without a mask or by a masking method. For the illustrated BCD wafer, it can be assumed that the first region 22 (NBL) completely overlaps with a single second region 32 (PBL). However, in conventional cases, the first and second regions 22 and 32 are constructed spatially separated from each other. The distance between them is typically, in particular, at least large enough that no overlapping region is created even after the diffusion of a single dopant.
[0252] The TCAD (Technology Computer-Aided Design) diagram shown below illustrates the dopant distribution within the contacted BCD substrate 110, simulating the corresponding integrated diode structure. In the shown side view, based on the dual structure shown in this embodiment, with an upper pn junction 50 in the epitaxial layer 40 and a lower pn junction 52 in the carrier substrate 10, the n-region NBL in the regions of pn junctions 50 and 52 is effectively contracted by the two p-regions PBL surrounding this n-region NBL. Two pn junctions 50 and 52 can be constructed to provide mutually independent SPADs with doping density and field strength distributions suitable for generating an avalanche effect.
[0253] This allows for the creation of particularly deep SPADs (“deepSPADs”) using a corresponding BCD substrate 110 further used for BCD technology. In this case, there is still sufficient structural space above the SPAD for integrating other optoelectronic components. Therefore, according to the invention, Zener-avLEDs built above deep SPADs can be used to realize particularly compact vertically constructed iQRNGs, wherein single photons 128 are emitted by the Zener-avLEDs preferably toward the upper pn junction 50, thus providing them as single-photon detectors for detection by the SPADs built directly below the Zener-avLEDs located at the upper pn junction 50 (see...). Figure 4 (and related accompanying illustrations).
[0254] Figure 4This is a schematic diagram of an exemplary first embodiment of the iQRNG 200 (or entropy source) according to the present invention. The integrated QRNG 200 shown includes a photon source 120 and a single-photon detector 130, wherein the photon source 120 and the single-photon detector 130 are arranged vertically stacked in a common substrate made of semiconductor material. The photon source 120 is preferably a single-photon source (SPS), which is adapted to provide only one or more photons 128 simultaneously. The photon source 120 is preferably a light-emitting avalanche Zener diode (Zener-avLED) operating at an operating point below or close to the breakdown voltage. The single-photon detector 130 is preferably a single-photon avalanche diode (SPAD).
[0255] The iQRNG 200 (or its entropy source) is preferably constructed in a BCD substrate 110 using BCD technology. The BCD substrate 110 preferably includes a carrier substrate 10; and an epitaxial layer 40 grown on the carrier substrate 10, wherein a deep pn junction 50 located in the epitaxial layer is formed between the carrier substrate 10 and the epitaxial layer 40 by introducing diffusion of dopants in the surface S of the carrier substrate 10 below the epitaxial layer 40 (see...). Figure 3 The single-photon detector 130 preferably forms an avalanche region in the area surrounding the deep pn junction 50 and includes an absorption region PW / HPW. This absorption region has a high-voltage p-type well (HPW) and a p-type well (PW) for converting photons into electron-hole pairs, wherein the absorption region PW / HPW is adjacent to the regions NBL and PBL where the deep pn junction 50 is formed. In this case, the fully convex high-voltage p-type well (HPW) enables optimal connection between the deep pn junction 50 and the anode.
[0256] Preferably, the deep pn junction 50 is at least partially constructed between the n-type buried layer NBL, which serves as the cathode 132, and the p-type buried layer PBL adjacent to the n-type buried layer NBL. The absorption region PW / HPW is adjacent to the p-type buried layer PBL and is substantially constructed as a p-region (optionally including the intrinsic region). + The anode 134 in the region is adjacent to the absorption region PW / HPW.
[0257] In the illustrated embodiment, the corresponding anodes 124 and 134 of the photon source 120 and the single-photon detector 130 are combined together. These anodes can be electrically contacted, for example, through a shared second metallization layer MET2 on the surface S of the BCD substrate 110. The shared and continuous second metallization layer MET2 can also achieve shielding to cover the entire underlying structural space. The shared anodes 124 and 134 of the photon source 120 and the single-photon detector 130 are connected, on the one hand, to a high-voltage p-well HPW and a p-type buried layer PBL via a p-well PW to contact the first pn junction 50, and on the other hand, to a p-type doped body PBODY to contact the pn junction 121 of the photon source 120. The associated cathodes 122 and 132 are exemplarily implemented separately, electrically contacted through a first associated first metallization layer MET1, and preferably at a reference potential GND. The iQRNG according to the invention can be constructed as a circular structure (equivalent to a spatial rotation of the illustrated plane along a vertical direction around an imaginary central axis). However, the structure shown can also be designed in other ways.
[0258] For the feed voltage, the cathode 132 of the single-photon detector 130 can be connected, for example, to a second positive power supply voltage on the second power supply voltage line VENT2 via an operating resistor R2. When detecting a photon, current flows through the pn junction 50 of the single-photon detector 130, which is polarized along the cutoff direction. This causes, for example, a voltage drop across the operating resistor R2, in the form of a voltage signal 405 that typically increases rapidly at the output of the entropy source and then decreases exponentially (see [link to further possible processing]). Figure 8 (Exemplary electronic circuitry of the quantum random generator 400 shown). Analog-to-digital converter (ADC) Figure 8 For example, the entropy output signal can be evaluated using ADC (403). ADC (403) may also include an amplifier and / or filter for conditioning the voltage signal (405). Furthermore, the operating resistor R2 limits the current flowing through the single-photon detector 130.
[0259] The cathode 122 of the single-photon detector 130 can be connected, for example, via a first working resistor R1 to a preferred monitored first positive power supply voltage on a first power supply voltage line VENT1. The first working resistor R1 limits the current flowing through the photon source 120. When a photon is emitted, the reverse current of the pn junction 121 of the photon source 120, which is polarized along the cutoff direction, typically increases in a spike-like manner. This increase in reverse current causes a voltage pulse on the first working resistor R1. This voltage pulse can be evaluated. The ADC (403) can be configured, for example, via a correlation device within the ADC, to evaluate only the pulses on the voltage signal 405 at the entropy source output that are associated with the voltage pulse on the first working resistor R1, such as the pulse associated with the optional correlation signal 430. In this case, only such pulses on the voltage signal 405 are evaluated as pulses of the single-photon detector 130 associated with the emission of photons through the photon source 120. This improves the quality of the entropy of the provided quantum random number.
[0260] Figure 5 This is a schematic diagram of an exemplary second embodiment of the iQRNG (or entropy source) according to the present invention. The illustrated embodiment is largely consistent with... Figure 4 The first embodiment shown is equivalent. Therefore, the symbols and their correspondence with the various features apply accordingly. However, with Figure 4 In contrast, high-voltage p-wells (HPWs) have been structurally replaced by tapered high-voltage p-wells (HPWs) and weakly n-type doped regions or intrinsic epitaxial regions (NEPIs). Here, the high-voltage p-well (HPW) with absorber regions (PW / HPW) only exists in... Figure 2 A narrow channel is formed between the upper p-well PW and the p-type buried layer PBL of the deep pn junction 50, as shown in the diagram. The environment of this channel is defined by the weakly n-type doped region or intrinsic epitaxial region NEPI. This channel allows connection from the anode to the deep pn junction 50 without additional penetration / breakthrough of the weakly n-type doped region or intrinsic epitaxial region NEPI.
[0261] Figure 6 This is a schematic diagram of an exemplary third embodiment of the iQRNG (or entropy source) according to the present invention. The illustrated embodiment is largely consistent with... Figure 5 The first embodiment shown is equivalent. Therefore, the symbols and their correspondence with the various features are applied accordingly. Figure 4 In comparison, the channel-shaped high-voltage p-well HPW in the absorption region PW / HPW is eliminated, and the weakly n-type doped region or intrinsic epitaxial region NEPI extends throughout the entire lower region. In this respect, compared to Figure 4 In contrast, the high-voltage p-well (HPW) has been structurally replaced by a weakly n-type doped region or an intrinsically epitaxial region (NEPI). Therefore, the deep pn junction 50 can only be connected from the anode after supplementally penetrating / breaking through the weakly n-type doped region or the NEPI, which will cause decoupling of potentially multiple parallel-connected cells.
[0262] Figure 7 It is a diagram showing the correlation of a) the SPAD current and b) the ratio between the SPAD current and the Zener current with respect to the Zener reverse voltage under different SPAD reverse voltages (less than, equal to, greater than the breakdown voltage) in the iQRNG according to the present invention. Among them, the correlation shown in a) clearly shows that in the range of 5.6 V to 6.6 V, the SPAD current increases exponentially with the Zener reverse voltage. This applies to all operating modes of the SPAD, that is, below its inherent breakdown voltage (<VBD, linear range), close to the breakdown voltage (~VBD, avalanche range), and above the breakdown voltage (>VBD), and thus also applies to the Geiger mode.
[0263] The lower curve (<VBD) shown in b) indicates that for different Zener reverse voltages in the range of 5.8 to 6.6 V, the measured current ratio between the SPAD current and the Zener current is about 1:4000. In the range of the breakdown voltage (~VBD) of the SPAD, this ratio increases to about 1:10. The reason is the so-called multiplication factor of the SPAD, which will leave the linear range in the range of the breakdown voltage. Finally, the upper curve gives the corresponding ratio (about 1:1) of the SPAD operating above the relevant breakdown voltage (>VBD). This indicates that when the operating voltage of the SPAD is higher than the relevant breakdown voltage (>VBD), the generated photocurrent and the Zener current of the Zener-avLED are approximately the same in magnitude, and an obvious measurement signal can be measured on the SPAD through the coupling of photons.
[0264] Figure 8 It is a schematic diagram of an exemplary electronic circuit of the quantum random generator 400 for generating and outputting a digital random number sequence. The entropy source 401 shown can be, in particular, the photon source 120 and the single-photon detector 130 of the iQRNG 200 according to the present invention, where different power supply voltages are supplied to the iQRNG 200 (or its entropy source) with respect to the reference potential on the reference potential line GND through the first power supply voltage line VENT1 and the second power supply voltage line VENT2 connected to the voltage converter 408. It should be noted that in some embodiments, generally (especially as shown in this example), the quantum random generator 400 can directly correspond to, for example, a semiconductor structure when additional circuit components are added. Figures 4 to 6The iQRNG 200 according to the present invention is shown in the figure. The photon source 120 and the single-photon detector 130 of the iQRNG 200 according to the present invention can be collectively regarded as the entropy source 401 of the illustrated quantum random generator 400, that is, in the case of the iQRNG 200 according to the present invention, the combination of the photon source 120 and the single-photon detector 130 can also be referred to as the entropy source. First, the voltage signal 405 generated by the entropy source 401 is digitized in the analog-to-digital converter (ADC) 403 powered by the reference voltage line VREF, and this voltage signal is transmitted as a digital output signal 407 to the pulse extension circuit 406. The power supply voltage line VENT and the reference voltage line VREF are monitored by the voltage monitor 413, wherein the voltage converter 408 and the voltage monitor 413 are powered by the reference potential on the reference potential line GND relative to the positive power supply voltage line VDD. The voltage converter 408 is connected to the voltage monitor 413 via the voltage converter line 421.
[0265] The pulse extension circuit 406 can be a monostable multivibrator (MF). This monostable multivibrator can be used to extend the pulse on the line of the digital output signal 407 of the ADC 403 according to a specific preset system clock, for example, to the length of at least one clock cycle of the system clock.
[0266] Then, the pulse extension circuit 406 outputs a single synchronous voltage signal 415, such as a pulse with a specific minimum length, and transmits it to a time-to-pseudo-random-number converter (TPRC) 404.3. This time-to-random-number converter can be composed of single-stage or multi-stage components. The TPRC 404.3 may include, for example, analog instruments, time-to-analog converters (TACs), and / or analog-to-pseudo-random-number converters (APRCs), which may also be provided together as the TPRC 404.3. The pseudo-random number generator of the TPRC 404.3 may include a feedback shift register, depending on the design, which shifts its value left or right around a position every clock cycle of the system clock and feeds back the feedback value of a preset feedback polynomial to the release bit. The feedback polynomial is preferably a simple primitive feedback polynomial. TPRC 404.3 can be directly connected to the internal data bus 419. In addition, the output signal 410 of TPRC 404.3 can be further fed to entropy extraction 404.4.
[0267] Therefore, starting from the initial value (so-called seed value) of the pseudo-random number generator, the pseudo-random number of the pseudo-random number generator can be precisely double-shotted to each clock of the system clock from the falling edge of the single synchronization voltage signal 415. In this case, the time position of the relevant clock of the system clock after the falling edge of the single synchronization voltage signal 415 can be inferred from the value of the pseudo-random number.
[0268] Therefore, a pseudo-random number generator can be used instead of a conventional digital counter in the prior art. The advantage is that even if an attacker successfully interferes with the single synchronization voltage signal 415, the randomness of the quantum random bit at the output 411 of the entropy extractor 404.4 is only slightly affected, because the attacker must know the relevant feedback polynomial. Preferably, it can be randomly selected from multiple schemes. This also applies to the seed value of the pseudo-random number generator, in which case the attacker must determine this seed value. Another advantage of using a pseudo-random number generator instead of a simple digital counter is that the feedback logic using a simple primitive feedback polynomial requires less area compared to a binary counter. If the linear feedback shift register of the pseudo-random number generator is long enough, each clock pulse between two pulses of the voltage signal 405 generated by the entropy source 401 typically corresponds to a unique pseudo-random number.
[0269] Entropy extraction 404.4 can be used to determine errors (i.e., undesirable states) in the output signal 410 of TPRC 404.3. For this purpose, entropy extraction 404.4 can specifically have two linear feedback shift registers that can be compared with each other via comparators. Therefore, a conventional binary counter can be omitted. Depending on the register depth, feedback can also be provided using a simple primitive polynomial as the feedback polynomial. In this case, the length of the linear feedback shift register is freely adjustable. Longer shift registers typically have lower data rates and improved random statistics. In contrast, shorter shift registers allow for higher data rates but poorer random distribution. The advantage of using shift registers in this respect is that fewer gates are required compared to existing technologies, resulting in a smaller logic depth and thus a higher clock rate. Consequently, the probability of two identical numbers appearing is lower, and the random bit rate is higher.
[0270] The entropy extraction method can be configured such that, firstly, two values of the output signal 410 of TPRC 404.3 are measured and stored in the shift register of entropy extraction 404.4. If the shift register of entropy extraction 404.4 stores two values, then entropy extraction 404.4 can compare these two values. Therefore, the values in the shift register of entropy extraction 404.4 include a first value and a second value, which TPRC 404.3 measures. Subsequently, entropy extraction 404.4 can evaluate these two values. If the first value is less than the second value and the difference between the first value and the second value is greater than a minimum difference ε, then entropy extraction 404.4 can set the value of its output terminal 411 to a first logic value. If the first value is greater than the second value and the difference between the first value and the second value is greater than a minimum difference ε, then entropy extraction 404.4 can set its output terminal 411 to a second logic value that differs from the first logic value. If the difference between the first logic value and the second logic value is less than the minimum difference ε, then entropy extraction 404.4 can discard both the first and second logic values.
[0271] In this case, entropy extraction 404.4 preferably causes the so-called watchdog 404.5 to increment the error counter by a first error counter step. This first error counter step can be negative. Conversely, if the difference between the first and second values is greater than the minimum difference ε, then entropy extraction 404.4 can decrement the error counter of the watchdog 404.5 by a second error counter step. This second error counter step can be equal to the first error counter step.
[0272] In addition, the watchdog timer 404.5 is connected to the internal data bus 419. Alternatively, the watchdog timer 404.5 can be connected to the voltage monitor 413 via one or more preferred digital input / output signal lines 414. The watchdog timer 404.5 preferably monitors the voltage value measured by the voltage monitor 413. It has been proven that the voltage monitor 413 can measure and monitor not only the voltage in the quantum random generator 400, but also other voltages in the corresponding application circuitry. The voltage monitor 413 can be, for example, an ADC (Analog-to-Digital Converter).
[0273] However, the actual task of the watchdog 404.5 is to monitor the quantum random number RN at the output 411 of the entropy extract 404.4. In this case, the watchdog 404.5 preferably detects at least three defined error conditions. The watchdog 404.5 can forward the valid quantum random number at output 411 to another optional linear feedback shift register as a backup pseudo-random number generator (PRNG) 404.6, provided a seed value S 412 is generated. The watchdog 404.5 preferably prevents the use of valid quantum random bits via the finite state machine 404.8. If an error occurs, the watchdog 404.5 can set certain error bits for further evaluation.
[0274] If the watchdog timer 404.5 detects, for example, an error in the quantum random number generator 400, it preferably switches the quantum random number generator 400 to an emergency state. To this end, the watchdog timer 404.5 preferably sets a selection signal 416 for the signal multiplexer 404.7 downstream of the random number generation, such that the signal multiplexer 404.7 replaces the random number RN at the output 411 of the entropy extractor 404.4, and places the pseudo-random number PRN of the optional PRNG 404.6 as a pseudo-random bit stream as an alternative to the potentially erroneous random number RN at the output 411 of the entropy extractor 404.4 at the input of the finite state machine 404.8 via the pseudo-random signal line 417.
[0275] An optional additional linear feedback shift register of PRNG 404.6 can be used to generate pseudo-random numbers (PRNs). The seed value S412 preferably has the last remaining valid quantum random bits at the output 411 of entropy extraction 404.4. The watchdog 404.5 then preferably places these last valid quantum random bits at output 411 at the input of the optional PRNG 404.6. Thus, the seed value S can be used as a random, secure starting value for the generator polynomial of the optional additional linear feedback shift register of PRNG 404.6, used to generate pseudo-random numbers (PRNs) and signal them via pseudo-random signal line 417. In this case, the generator polynomial and its degree are preferably freely selectable. In the event of an error, a secure random number can be provided at least intermittently by an optional backup pseudo-random number generator.
[0276] The task of finite state machine 404.8 is to receive the random number RN or pseudo-random number PRN at the output of signal multiplexer 404.7 and write the corresponding quantum random data word 418 into volatile memory (RAM) or FIFO memory (first-in, first-out) 404.9 via pseudo-random signal line 417. If the write process is successfully completed, finite state machine 404.8 can set a completion flag 404.10 via internal data bus 419. Then, the processor can access volatile memory (RAM) or FIFO memory (first-in, first-out) 404.9, read the random number, and use it, for example, for encryption.
[0277] Furthermore, the quantum random number generator 400 may include a temperature sensor or other sensors, by means of which a watchdog timer 404.5 or another component of the quantum random number generator 400 may, as appropriate, monitor the physical parameters (e.g., temperature) of the environment of the quantum random number generator 400 via an ADC 403 or another analog-to-digital converter and / or other components (such as sensor amplifiers and / or filters) and take countermeasures when the values of such physical parameters exceed predetermined ranges. Such countermeasures may include sending signals to other devices, such as via an internal data bus 419, or emergency operation, such as using a PRGNG 404.6 and multiplexer 404.7, and / or changing internal operating parameters (such as the voltage level of the internal power supply), for example via a voltage converter 408, and / or shutting down random number generation, etc. This effectively shuts down side channels affecting the quantum random number generator 400.
[0278] Figure 9 This is a top view schematic diagram of an exemplary layout of an integrated electronic circuit 500 having an iQRNG 200 (or its entropy source) according to the invention within a pad frame 503. The integrated electronic circuit 500 (e.g., a microcontroller) has an internal region 505 in which the basic sub-circuits of the integrated electronic circuit 500 are located. The internal region 505 is generally surrounded by a wiring region 504, in particular where power supply voltage lines, data bus lines, and other lines can be routed.
[0279] The wiring area 504 and internal area 505 of the integrated electronic circuit 500 are typically surrounded by a pad frame 503 (also called a pad edge), which includes connection pads 502 (connection surfaces) for electrical bonding connections or other electrical connections.
[0280] Preferably, the iQRNG 200 according to the invention or, for example, in Figure 8The corresponding quantum random access generator 400 (or its entropy source) shown is entirely or at least largely housed within the pad frame 503 because the gaps between individual connection pads 502 are typically not filled with electronic circuit components. However, these gaps still need to be processed together when manufacturing the integrated electronic circuit 500, thus incurring unnecessary manufacturing costs. Therefore, housing the iQRNG 200 or the corresponding quantum random access generator 400 (or its entropy source) according to the invention entirely or at least largely within the pad frame 503 significantly reduces the additional costs of providing these devices.
[0281] Preferably, at least the photon source 120 and the single-photon detector 130 (entropy source 401) can be housed in a pad frame 503 between the two connecting pads 502. Additionally, the ADC 403, the voltage converter 408 supplying power to the entropy source 403, the pulse extension circuit 406, and / or analog components (such as amplifiers) of the quantum random generator 400 according to the invention can also be housed in the pad frame 503 between the two connecting pads 502.
[0282] Figure 10 This diagram illustrates nodes in a distributed network, each equipped with a comprehensive control unit. This control unit can be designed in a way that integrates multiple components crucial to the node's operation, communication, and security. Each node's control unit plays a central role in secure and efficient communication within the network.
[0283] The control device 1000 may include a quantum random number generator 1010, a CPU 1020, volatile memory 1040, non-volatile memory 1050, encryption and decryption unit 1060, internal data bus 1030, voltage regulator 1070, reset circuit 1080, interrupt controller 1090, clock system 1100 with oscillator 1110, JTAG test interface 1120, and optional watchdog 1130. The control device 1000 is adapted to perform security-related tasks and control communication between nodes in a network, wherein random numbers from the quantum random number generator 1010 are used for encryption applications.
[0284] At the heart of this control unit is a central processing unit (CPU) capable of handling all computational and control tasks within the node. This CPU is adaptable to various computer and / or machine-based methods for encrypting data messages, generating and verifying signatures, generating keys and key pairs, and using spreading codes and watermarks to mark and hide information. These diverse functions can be supported by tightly integrating the CPU with other components of the control unit.
[0285] An internal data bus connects the CPU to all other components of the control device, enabling efficient communication between them. Through the internal data bus, the CPU can control the quantum random number generator of the control device, read the generated random numbers, and receive interrupt signals that may indicate specific activities or fault states as needed. In this case, the quantum random number generator is particularly important because it helps generate high-quality random numbers with high bit data rates. According to the invention, such a quantum random number generator preferably includes an entropy source monolithically fabricated in a semiconductor substrate. This entropy source includes a single-photon source and a single-photon detector, which are arranged perpendicular to each other and perpendicular to the surface of the associated semiconductor substrate, thereby enabling a particularly high random number data rate, i.e., the bit data rate mentioned above. The corresponding quantum random number generator may include components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal.
[0286] In addition to the quantum random number generator, the CPU can communicate with the volatile and non-volatile memory of the control unit via an internal data bus. Temporary data and programs can be stored in volatile memory, while non-volatile memory can be used for long-term storage of keys and other security-related information. The CPU can access the memory to read and write the required data.
[0287] Another key component of this control device is the encryption and decryption unit, which can also be connected to the CPU via an internal data bus. This unit is responsible for encrypting and decrypting the transmitted and received data messages. Encryption is preferably performed using random numbers generated by a quantum random number generator. According to the invention, this quantum random number generator preferably includes an entropy source monolithically fabricated in a semiconductor substrate. This entropy source preferably includes a single-photon source and a single-photon detector, arranged perpendicular to each other and perpendicular to the surface of the associated semiconductor substrate, thereby enabling particularly high random number data rates (i.e., the aforementioned bit data rate) and quantum computer-secure encryption. The corresponding quantum random number generator may include components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal.
[0288] The CPU can also control a voltage regulator via an internal data bus, which provides the necessary internal power supply voltage to the control device. This regulator ensures a stable power supply to all components of the control device, which is crucial for the reliable operation of the entire device.
[0289] A CPU-controlled reset circuit can also be included to restart the control device in a predefined state when necessary. The CPU can activate this reset circuit via the internal data bus and monitor its status.
[0290] The interrupt controller is another important component that enables communication with the CPU. This controller collects and manages all interrupt signals from different components of the control unit and forwards these interrupt signals to the CPU. The CPU can receive these signals via the internal data bus and take appropriate actions.
[0291] An oscillator-driven clock system ensures precise control of the time flow within the control unit. The CPU can synchronize its activity with this clock system, which is also connected to the CPU via an internal data bus. In this case, the oscillator can provide the base frequency, which is crucial for the clocking of the CPU and other components.
[0292] Another important interface for this control unit is the JTAG test interface, which enables testing and debugging of the control unit. This interface, which optionally also supports boundary scan, can connect to the CPU via the internal data bus to read and analyze the status of the control unit.
[0293] An optional watchdog circuit monitors both the correct operation of the CPU and the status of the quantum random number generator. This watchdog circuit can be equipped with an ADC (analog-to-digital converter) to measure voltages within the control unit, particularly the operating voltage of the quantum random number generator. Furthermore, the watchdog monitors the entropy quality of the random numbers generated by the quantum random number generator. This monitoring ensures that the quantum random number generator continuously generates high-quality random numbers and ensures early identification of potential deviations or interference. The watchdog can communicate with the CPU via the internal data bus, providing it with monitoring data and possible alarm signals.
[0294] This control device may also include multiple data interfaces through which the CPU can communicate with other nodes in the network. These data interfaces enable nodes to exchange data messages, with communication preferably encrypted using random numbers generated by a quantum random number generator. This encrypted data ensures the security of communication and protects the transmitted information from unauthorized access.
[0295] In addition to the components mentioned above, the control unit can also integrate other components commonly found in modern IoT networks, particularly in vehicular networks. These include sensors for collecting environmental data, communication modules for wireless networks, or dedicated security modules for processing encryption algorithms. These additional components can also be seamlessly integrated into the control unit by connecting to the CPU via an internal data bus.
[0296] Figure 10The control device illustrated demonstrates a highly integrated and powerful architecture optimized for operation in distributed networks. In this case, the vertical arrangement of the corresponding photon source and corresponding photodetector perpendicular to the surface of the corresponding semiconductor substrate plays a central role, as it facilitates the generation of high-quality, high-bit-data-rate random numbers in the corresponding nodes of the network. The entropy source of the corresponding quantum random number generator is preferably fabricated monolithically within this semiconductor substrate. The CPU controls and monitors all components of the control device, ensuring their low-friction and efficient collaboration to guarantee the security and reliability of the nodes in the network.
[0297] Figure 10 Specifically, a schematic diagram illustrating an exemplary implementation of a node in a distributed network is shown, the node including a central control unit 1000. The control unit 1000 is adapted to perform security-critical tasks within the network and control communication between nodes. Each node is autonomously operated and equipped with a hardware-based quantum random number generator 1010, which generates high-quality random numbers with a high bit rate. This ensures that the quantum random number generator is a monolithically fabricated entropy source in a semiconductor substrate according to the invention. This entropy source preferably includes a single-photon source and a single-photon detector, arranged perpendicular to each other and perpendicular to the surface of the associated semiconductor substrate, thereby enabling particularly high random number data rates (i.e., the aforementioned bit data rates), particularly high random quality, and secure encryption for quantum computers. The corresponding quantum random number generator includes components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal.
[0298] The control device 1000 includes a central processing unit (CPU) 1020, which performs all computational and control tasks. The CPU 1020 is adapted to implement computer and / or machine-based methods for encrypting data messages, generating signatures, verifying signatures, generating keys and key pairs, and marking and hiding information using spreading codes and / or watermarks. These tasks are supported by the tight integration of the CPU 1020 with other device components of the control device.
[0299] An internal data bus 1030 connects the CPU 1020 to all other components of the control device 1000, enabling efficient communication between them. Through the internal data bus 1030, the CPU 1020 controls the quantum random number generator 1010, reads the generated random numbers, and receives interrupt signals from the quantum random number generator 1010 when specific events occur. The quantum random number generator 1010 utilizes an entropy source, preferably monolithically fabricated in a semiconductor substrate according to the invention, to incorporate this high-quality entropy source into the proposed network nodes, then into the proposed sub-networks, and finally into the proposed network. This entropy source preferably includes a single-photon source and a single-photon detector, arranged perpendicular to each other and perpendicular to the surface of the relevant semiconductor substrate, thereby enabling particularly high random number data rates (the aforementioned bit data rate), particularly high random quality, and quantum computer-secure encryption. The corresponding quantum random number generator 1010 includes components for operating the entropy source and components for generating quantum random numbers based on the entropy source output signal.
[0300] The CPU 1020 also communicates with volatile memory 1040 and non-volatile memory 1050 via an internal data bus 1030. Volatile memory 1040 is used to temporarily store data and programs during operation, while non-volatile memory 1050 is used to store security-related information such as encryption keys long-term. The CPU 1020 can access non-volatile memory 1050 at any time to read or write encryption keys required for secure communication over the network.
[0301] To enable encryption and decryption of data messages with the help of other nodes in the network, the control device 1000 is equipped with an encryption and decryption unit 1060. This unit 1060 is controlled by the CPU 1020 via an internal data bus 1030. During a special encryption process, the CPU 1020 reads the processed data and receives an interrupt signal from the unit 1060. Communication between nodes in the network is preferably performed in an encrypted manner using random numbers generated by the quantum random number generator 1010. To generate high-quality random numbers with a high random number rate, the quantum random number generator 1010 preferably includes an entropy source monolithically fabricated in a semiconductor substrate. This entropy source preferably includes a single-photon source and a single-photon detector, which are arranged perpendicular to each other and perpendicular to the surface of the relevant semiconductor substrate, thereby enabling particularly high random number data rates (the aforementioned bit data rate) and particularly high random quality, and enabling quantum computer-secure encryption of subnetworks or communications within the network. The corresponding quantum random number generator 1010 includes components for operating an entropy source and components for generating quantum random numbers based on the entropy source output signal of the entropy source.
[0302] The voltage regulator 1070 within the control unit 1000 ensures the supply of internal power supply voltage. The CPU 1020 controls the voltage regulator 1070 and monitors the voltage level via the internal data bus 1030 to ensure a stable power supply to the control unit 1000.
[0303] The reset circuit 1080 enables the CPU 1020 to reset the control device 1000 to a predefined initial state as needed. This is particularly important in the event of a fault or interference to ensure the operational capability of the control device 1000. The CPU 1020 controls this reset circuit 1080 via the internal data bus 1030.
[0304] Interrupt controller 1090 collects and manages all interrupt signals generated by different device components of control unit 1000. CPU 1020 receives and processes these signals via internal data bus 1030 to respond quickly to critical events.
[0305] The clock system 1100, driven by oscillator 1110, ensures precise synchronization of processes within the control unit 1000. The CPU 1020 is connected to the clock system 1100 via internal data bus 1030 and synchronizes its activity according to the clock signal generated by oscillator 1110.
[0306] Optionally, the JTAG test interface 1120, which also has boundary scan capability, is integrated into the control unit 1000 to support external diagnostics and troubleshooting functions. The CPU 1020 is connected to the JTAG test interface 1120 via the internal data bus 1030 and can read diagnostic data and trigger tests.
[0307] An optional watchdog timer 1130 continuously monitors the operational capabilities of the CPU 1020 and the quantum random number generator 1010. The watchdog timer 1130 is equipped with an ADC 1140, which monitors the voltage supply and the entropy quality of the random numbers. If a deviation from normal operating conditions is detected, the watchdog timer 1130 can reset either the CPU 1020 or the quantum random number generator 1010 to ensure the operational capability of the control unit 1000.
[0308] Preferably, the CPU 1020 of the control device 1000 is capable of implementing computer and / or machine-based methods for generating encryption keys and initialization vectors (IVs). These keys and IVs can be stored in volatile memory 1040 and used for security-critical applications supported by encryption and decryption unit 1060.
[0309] Preferably, the CPU 1020 can implement a computer- and / or machine-based method for generating one-time passwords (OTPs), which can be used as an additional security layer for continued authentication within the network. These OTPs are based on random numbers generated by the quantum random number generator 1010 and can be managed in the volatile memory 1040.
[0310] To support secure communication protocols, CPU 1020 preferably implements a computer- and / or machine-based method for executing TLS or IPsec protocols. In this case, random numbers from the quantum random number generator 1010 can be used to securely negotiate session keys, which can then be used by the encryption and decryption unit 1060 to encrypt data messages.
[0311] Preferably, the CPU 1020 can implement a computer- and / or machine-based method for randomly selecting nodes in the network, ensuring a fair and manipulation-resistant selection process. Random numbers generated by the quantum random number generator 1010 can be used as the basis for randomly assigning tasks within the network.
[0312] Furthermore, the control device 1000 can support methods for generating high-quality random numbers by incorporating physical phenomena such as thermal noise or quantum processes into computer and / or machine implementations. These random numbers can then be used for security-critical applications in the network.
[0313] To amplify and filter the entropy source, the CPU 1020 can implement computer- and / or machine-based methods that ensure optimal amplification and filtering of the entropy source signal before it is converted into random numbers. This ensures the high quality and reliability of the generated random numbers.
[0314] Preferably, the CPU (1020) can implement computer and / or machine-based methods for post-processing the generated random numbers. In this case, different techniques such as hashing or XOR operations can be used to further improve the quality of the random numbers and eliminate systematic errors.
[0315] To securely store and control access to security-related data, CPU 1020 may implement computer and / or machine-based methods that regulate access to non-volatile memory 1050 and ensure that only authorized processes can access this data.
[0316] Preferably, the CPU 1020 can implement computer- and / or machine-based methods for continuous monitoring and fault identification to ensure that the control device 1000 always remains in normal working order. Preferably, this also includes automatic recovery in the event of a fault to maintain system integrity.
[0317] In addition, the control device 1000 can perform other functions that can be controlled by the CPU 1020. These include implementing fault identification and recovery processes, managing and using digital certificates, supporting consensus mechanisms in distributed networks, and / or executing additional security and optimization protocols to maximize network performance and security.
[0318] In order to implement the corresponding functions in the node control device 1000, the CPU 1020 can implement different computer and / or machine implementation methods that are specifically tailored to the requirements of these functions.
[0319] To distribute load across the network, CPU 1020 can implement computer- and / or machine-based methods for dynamically managing network resources. In this case, CPU 1020 can, for example, analyze the current load of nodes in the network and allocate tasks in a certain manner to avoid overloading individual nodes. The internal data bus 1030 enables CPU 1020 to access necessary information and process it efficiently, thereby distributing the load evenly across the network.
[0320] To continuously monitor the network and identify anomalies, CPU 1020 can implement computer- and / or machine-based methods that monitor network activity and identify anomalies in real time. In this case, interrupt controller 1090 plays a crucial role, specifically by providing CPU 1020 with all relevant signals that may indicate anomalous activity or potential security threats. CPU 1020 then processes this information via internal data bus 1030 to respond quickly to any problems that arise.
[0321] To manage digital certificates and use them in a network, CPU 1020 can implement computer- and / or machine-based methods, including the generation, storage, and distribution of certificates. In this case, CPU 1020 preferably accesses non-volatile memory 1050 to securely store certificates and retrieve them as needed. These certificates can be used to ensure the authenticity and integrity of communications in the network, where CPU 1020 can use encryption and decryption unit 1060 to securely transmit certificate-based data.
[0322] To implement a consensus mechanism in a distributed network, CPU 1020 can implement computer and / or machine-based methods that ensure all nodes in the network have a unified view of the network's current state. To this end, CPU 1020 preferably uses random numbers generated by these nodes to ensure a fair and manipulation-resistant consensus process. These processes can be supported by a quantum random number generator 1010, which can be connected to CPU 1020 via an internal data bus 1030 and provide the random numbers required for consensus.
[0323] To achieve network scalability and fault tolerance, CPU 1020 can implement computer- and / or machine-based methods for managing new nodes and integrating them into the network. In this case, CPU 1020 can ensure that new nodes are seamlessly integrated into the existing network and immediately contribute to overall performance and security. To this end, internal data bus 1030 enables CPU 1020 to perform the necessary setup and coordinate communication between new and existing nodes.
[0324] Figure 10 Overall, a comprehensive and highly integrated control device 1000 is shown, providing all the functionality required for secure, efficient, and scalable communication in a distributed subnetwork or network. A CPU 1020 preferably controls and monitors all processes in a network node, a portion of which is the control device, and a portion of which is the associated CPU 1020.
[0325] In this case, using the quantum random number generator 1010 according to the invention in the control device of the network node of the sub-network according to the invention can play a central role in ensuring network performance and security. In this case, the corresponding entropy source of the corresponding quantum random number generator, preferably monolithically fabricated in a semiconductor substrate according to the invention, ensures the corresponding random quality and a correspondingly high overall random number rate relative to the entire sub-network according to the invention. According to the invention, these corresponding entropy sources preferably each include a relative single-photon source and a corresponding single-photon detector, which are arranged perpendicular to each other and perpendicular to the surface of the relevant semiconductor substrate, thereby enabling a particularly high total random number data rate (i.e., the aforementioned total bit data rate) and a particularly high total random quality, and enabling quantum computer-secure encryption of the corresponding sub-network of the network according to the invention. The corresponding quantum random number generator of the network node according to the invention preferably includes corresponding components for operating the corresponding entropy source and corresponding components for generating corresponding quantum random numbers based on the output signal of the corresponding entropy source of the corresponding quantum random number generator of the corresponding control device of the corresponding sub-network according to the invention.
[0326] Through the close integration and cooperation of different device components, the control device 1000 can reliably perform the tasks according to the invention, thereby ensuring a high level of security and efficiency in the network.
[0327] Figure 11 For by multiple reasons Figure 10 A schematic diagram of a distributed network composed of nodes. Figure 11 Specifically, a network consisting of multiple nodes is shown, where each node is equipped with, for example... Figure 10The described control device allows nodes to communicate with each other and use random numbers generated by a quantum random number generator 1010 to support secure communication protocols, generate encryption keys and initialization vectors (IVs), generate one-time passwords (OTPs), and randomly select nodes for specific tasks within the network. The decentralized structure of this network ensures high security, scalability, and fault tolerance.
[0328] In this network, the nodes cooperate to ensure secure and efficient communication. The central element of this network is a distributed structure, implemented by integrating a hardware-based quantum random number generator in each node. According to the invention, these quantum random number generators preferably each include an entropy source monolithically fabricated in a semiconductor substrate. Each entropy source preferably includes a corresponding single-photon source and a corresponding single-photon detector, arranged perpendicular to each other and to the surface of the relevant semiconductor substrate. This enables exceptionally high random number data rates (i.e., the aforementioned bit data rate) and exceptionally high random quality, and allows for quantum-computer-secure encryption of corresponding communications of the corresponding network nodes in the network according to the invention. This allows the entire sub-network of the network according to the invention to achieve exceptionally high total random number data rates (i.e., the aforementioned total bit data rate) and exceptionally high total random quality, and enables quantum-computer-secure encryption of communications within the network according to the invention. Each quantum random number generator in the network preferably includes corresponding components for operating the entropy source and corresponding components for generating corresponding quantum random numbers based on the corresponding entropy source output signal. Using the quantum random number generator according to the invention in these network nodes of the network according to the invention generally helps to improve the overall random quality of random numbers in the network and increase the overall random bit data rate in the network according to the invention.
[0329] exist Figure 11 In the diagram shown, multiple nodes are connected to each other by lines, which are intended to illustrate the communication paths between the nodes. In this scenario, each node can autonomously generate random numbers and use them to encrypt and authenticate communication data.
[0330] This is achieved by a corresponding quantum random number generator in the network according to the invention, preferably in each node of the network according to the invention.
[0331] The corresponding quantum random number generator preferably includes a corresponding entropy source monolithically fabricated in a semiconductor substrate. This corresponding entropy source preferably includes a corresponding single-photon source and a corresponding single-photon detector, which are arranged perpendicular to each other and perpendicular to the corresponding surfaces of the associated semiconductor substrate, thereby enabling a particularly high corresponding random number data rate (i.e., the aforementioned corresponding bit data rate) and a particularly high corresponding random quality, and enabling the corresponding quantum computer to securely encrypt communications in the sub-network or the network according to the invention. In this case, the corresponding quantum random number generator 1010 preferably includes corresponding components for operating the corresponding entropy source and corresponding components for generating corresponding quantum random numbers based on the corresponding entropy source output signal. This achieves a particularly high corresponding random quality and density of the corresponding random numbers. This further ensures a particularly high overall random quality and overall density of random numbers in the sub-network of the network according to the invention.
[0332] Advantages of Distributed Networking: The distributed layout of these nodes in the network significantly improves security. Because each node generates its own inherent random number, there is no central point that could compromise the entire network. Even if a few individual nodes are compromised, the integrity of the random numbers in the remaining nodes remains unaffected, thus enhancing the overall security of the network.
[0333] Another advantage of decentralization is improved fault tolerance. If one node fails, the remaining nodes can continue to perform their functions without affecting the overall functionality of the network. This is especially important in security-critical applications where continuous availability and integrity of communication are required.
[0334] Efficiency and scalability: Figure 11 The network structure shown also achieves high efficiency and scalability. By evenly distributing random number generation across all nodes, the load is uniformly distributed, thus avoiding bottlenecks and performance degradation. Each node contributes to the total entropy of the network, achieving uniform and efficient resource utilization.
[0335] This network can be easily scaled by adding new nodes equipped with built-in quantum random number generators. This allows for flexible adaptation to growing demands without requiring significant changes to existing infrastructure. New nodes are seamlessly integrated into the network and contribute to overall performance and security.
[0336] Cooperative security protocols: Nodes in a network can also implement cooperative security protocols through decentralized random number generation. These protocols utilize the random numbers generated by each node for secure communication, key exchange, and authentication. The corresponding random numbers are based on physical phenomena within a corresponding entropy source, which preferably includes a corresponding single-photon source and corresponding single-photon detectors directly coupled to it, arranged perpendicularly to each other and to the corresponding surfaces of the relevant semiconductor substrates. This enables exceptionally high random number data rates (i.e., the aforementioned bit data rates) and exceptionally high random quality, allowing the corresponding quantum computer to securely encrypt the corresponding communications within the sub-network or network. Therefore, it achieves exceptionally high security against manipulation and prediction.
[0337] The corresponding entropy sources of the corresponding quantum random number generator 1010, monolithically fabricated in a semiconductor substrate, are used for this purpose. Each of these entropy sources preferably includes a corresponding single-photon source and a corresponding single-photon detector, which are arranged perpendicular to each other and to the corresponding surfaces of the respective semiconductor substrates, thereby enabling a particularly high corresponding random number data rate (i.e., the aforementioned corresponding bit data rate) and a particularly high corresponding random quality, and enabling the corresponding quantum computer to securely encrypt corresponding communications within the sub-network or network. For this purpose, the corresponding quantum random number generator 1010 preferably includes corresponding components for operating the respective entropy sources and corresponding components for generating corresponding quantum random numbers based on the corresponding entropy source output signals.
[0338] Figure 11 Networks in this context can, for example, use a distributed TLS protocol, where randomly generated keys are exchanged between nodes to establish secure communication channels. Randomly selecting nodes for specific tasks (such as verifying transactions in a blockchain network) is also supported by a decentralized structure, increasing the difficulty of manipulation and targeted attacks.
[0339] Reduce delay time: Figure 11 The network structure shown also helps reduce latency. Each node generates its own inherent random number and does not rely on a central node, thus enabling these nodes to respond to requests and exchange data more quickly. This makes communication in the network faster and more efficient overall.
[0340] Enhancing security through vertically integrated entropy sources: The vertical integration of the corresponding photon sources and photodetectors in these quantum random number generators plays a crucial role in improving the security characteristics of the network. This ensures the highest quality of the generated random numbers, which is essential for secure encryption and authentication within the network. The resulting high bit data rate of these random numbers enables the network to maintain secure and stable communication even under high data traffic.
[0341] Synchronization and consensus: Figure 11 Another important feature of the network shown is its ability to synchronize and reach consensus among nodes. Since each node generates its own random number independently, it is crucial that these nodes synchronize their activities to ensure consistent and coherent results. This can be achieved by implementing consensus protocols that ensure all nodes in the network react based on the same random events.
[0342] Node synchronization is supported by the high quality and speed of random number generation, which can be achieved through the vertical integration of the corresponding photon source and corresponding photodetector of the corresponding entropy source of the quantum random number generator. This ensures that all nodes can operate synchronously without inconsistencies or delays.
[0343] Health check-ups and self-monitoring: Figure 11 Another core element of the network is node self-monitoring, specifically through a watchdog that can be integrated into each node. This watchdog not only monitors the proper functioning of the central processing unit (CPU) but also performs periodic health checks on the quantum random number generator. The watchdog continuously checks the operating voltage and the entropy quality of the random numbers to ensure the quantum random number generator is operating correctly.
[0344] This monitoring capability helps improve network security and reliability. If the watchdog detects an anomaly, it can isolate the affected nodes or issue an alert to minimize potential security risks.
[0345] Communication between nodes: These nodes in the network can communicate with each other through the data interface of their control devices. This communication is preferably encrypted, where random numbers from quantum random number generators can be used for encryption. The high quality of the random numbers ensured by the vertical integration of the corresponding entropy sources, corresponding photon sources, and corresponding photodetectors of these quantum random number generators ensures the security of the communication channels between these nodes and protects the data from unauthorized access.
[0346] Furthermore, these nodes can exchange different types of data, including encrypted data messages, digital signatures, and authentication data. This data can be securely stored in the control unit's storage module and processed by the CPU as needed. The CPU can control the entire communication process and ensure that this data is correctly encrypted and decrypted before being forwarded or processed.
[0347] Scalability and adaptability: Figure 11The network shown also exhibits scalability and adaptability. New nodes can be easily integrated into the network by simply connecting them to existing communication channels. Each new node carries its own inherent source of random numbers, further enhancing the network's overall entropy and security.
[0348] By leveraging its distributed structure and the vertical integration of corresponding photon sources and photodetectors within a quantum random number generator with corresponding entropy sources, this network can flexibly adapt to evolving requirements and new technologies. This makes it forward-looking and suitable for a wide range of applications, from industrial control systems to IoT networks in the automotive industry.
[0349] In conclusion, Figure 11 Overall, a robust and secure network based on decentralized random number generation is presented. The vertical integration of the corresponding entropy source, photon source, and photodetector of these quantum random number generators contributes to achieving the highest quality of the generated random numbers and facilitates random number generation at high bit data rates. These features not only improve the security and efficiency of the network but also enable fast and reliable communication between nodes. This network is scalable, flexible, and resilient to failures and attacks, making it an ideal solution for modern distributed applications.
[0350] Appendix Label Table 10 carrier substrates 22. First District (e.g., NBL) 32. Second Division (e.g., NBL) 40 epitaxial layers 50. First pn junction (e.g., the upper pn junction in a dual structure) 52. Second pn junction (e.g., the lower pn junction in a dual structure) 110 substrate 120 photon source (e.g., single photon source, SPS) 122 Cathode (n+, photon source) 124 Anode (p+, photon source) 128 photons 130 Single-photon detectors (e.g., single-photon avalanche diodes, SPADs) 132 cathode (n+, single-photon detector) 134 Anode (p+, single-photon detector) 150 light blocking layer 152 Electronic Detection Components 154 Electronic Post-processing Components 200iQRNG 400 quantum random generators (e.g., based on iQRNG) 401 entropy sources (e.g., iQRNG) 403 Analog-to-Digital Converter (ADC) 404.3 Time-to-Pseudo-Random-Number Converter (TPRC) 404.4 Entropy Extraction 404.5 Watchdog 404.6 Pseudo-Random-Number-Generator (PRNG, e.g., a linear feedback shift register) 404.7 signal multiplexer 404.8 Finite State Machine 404.9 Volatile Memory (RAM) / FIFO Memory (First In First Out) 404.10 Completion Mark 405 voltage signal (entropy source) 406 pulse extension circuit (e.g., monostable multivibrator, MF) 407 Output Signal (ADC) 408 voltage converter 410 Output Signal (TPRC) 411 Output Terminal (Entropy Extraction) 412 seed value S 413 Voltage Monitor 414 digital input / output signal lines 415 Single synchronous voltage signal (e.g., a pulse with a minimum length) 416 Selection Signal 417 Pseudo-random signal line 418 quantum random data words 419 Internal Data Bus 420 interrupt signal 421 Voltage Converter Circuit 430 related signals (optional) 500 Integrated Circuit (IC) 501 Semiconductor Chip 502 connection pad (connection surface) 503 pad frame 504 cabling area 505 interior area 1000-node control device 1010 quantum random number generator (e.g., 400, based on iQRNG) 1020 CPU (Central Processing Unit); 1030 internal data bus 1040 volatile memory 1050 non-volatile memory 1060 encryption and decryption units 1070 voltage regulator 1080 reset circuit 1090 Interrupt Controller 1100 clock system 1110 oscillator 1120 JTAG test interface 1130 watchdog (e.g., 404.5) 1140ADC (Analog-to-Digital Converter); 1150 Sensors for Environmental Data Acquisition 1160 Wireless Network Communication Module 1170 is a security module used for processing encryption algorithms. 1180 is a data interface for communicating with other nodes in the network. NBLn type buried layer (English: "n-type buried layer") PBLp type buried layer (English: "p-type buried layer") H(V)PW high-voltage p-type well H(V)NW high-voltage n-type well (English translation: "high-voltage n-type well") PWp well (also known as "p-type well") PBODY p-type doped region (English: "p-type body") NEPI weakly n-type doped region or (approximately) intrinsic epitaxial region MET1, MET2 metallization layers CONT contact STI (shallow trench isolation) polycrystalline silicon layer P + p + district N + n + district VDD positive power supply line GND reference potential line V ENT1 First power supply voltage line (entropy source) V ENT2 Second power supply voltage line (entropy source) V REF Reference Voltage Line (ADC) RN random numbers (e.g., 1-bit random numbers) PRN pseudo-random numbers S-surface (carrier substrate, such as BCD substrate) O surface (substrate, such as BCD substrate) R radial symmetry axis
Claims
1. A distributed network comprising multiple nodes, Each of the plurality of nodes has at least one hardware-based quantum random number generator, and the quantum random number generator has at least one entropy source. The quantum random number generator on each node is adapted to generate truly random numbers. The network and / or its sub-devices are adapted to use the random number to ensure the security, availability, and robustness of the network. The network and / or its sub-networks and / or its sub-devices are adapted to generate the random numbers in a decentralized manner, thereby eliminating the need for a central node to generate or manage the random numbers. The quantum random number generator mentioned above includes an entropy source. The entropy source is implemented monolithically in a semiconductor substrate with a surface. The entropy source includes a photon source adapted to emit photons during current feeding. The entropy source includes a single-photon detector, which is adapted to detect photons from the photon source and generate an entropy source output signal. The photon source is disposed between the surface of the semiconductor substrate and the single-photon detector, or the single-photon detector is disposed between the surface of the semiconductor substrate and the single-photon source. The photon source and the single-photon detector of the monolithic entropy source are stacked vertically on top of each other, and The quantum random number generator includes components for generating one or more quantum random numbers based on the entropy source output signal.
2. The network of claim 1, wherein at least two nodes, preferably all nodes, of the plurality of nodes in the network are adapted to generate encryption keys and initialization vectors (IVs) using random numbers generated by their respective quantum random number generators and / or another quantum random number generator in the network.
3. The network according to claim 1 or 2, wherein at least two nodes, preferably all nodes, of the plurality of nodes in the network are adapted to use their respective random numbers and / or the random numbers of other nodes in the network to generate one-time passwords (OTPs) for authenticating communication partners.
4. The network according to any one of the preceding claims, wherein the network or at least two, preferably all, of the plurality of nodes of the network are adapted to support secure communication protocols such as TLS or IPsec using their respective random numbers and / or the random numbers of other nodes in the network and / or random numbers in the network.
5. The network according to any one of the preceding claims, wherein the network or at least two, preferably all, of the plurality of nodes of the network are adapted to perform a security protocol using their respective random numbers and / or the random numbers of other nodes in the network and / or the random numbers in the network, the security protocol ensuring secure communication between the nodes.
6. The network according to any one of the preceding claims, wherein the network or at least two, preferably all, of the plurality of nodes of the network are adapted to enhance and filter the random numbers generated by the network through an entropy collection unit in order to avoid systematic errors or predictability.
7. The network according to any one of the preceding claims, wherein the network is configured in such a way that the load of the random number generation is evenly distributed across the nodes.
8. The network according to any one of the preceding claims, wherein at least two nodes, preferably all nodes, of the plurality of nodes in the network each include a security module adapted to securely store random numbers of the respective nodes and use and / or provide them to one or more different security-related applications.
9. The network according to any one of the preceding claims, wherein at least two nodes, preferably all nodes, of the plurality of nodes in the network each include a control device adapted to store the random number in a protected storage area of the control device of the respective node, the storage area being accessible only to authorized processes in the network.
10. The network of claim 9, wherein the corresponding control device is adapted to identify anomalies in the random number generation and implement a corresponding recovery process.
11. The network according to claim 9 or 10, wherein the corresponding control device is adapted to post-process the generated random number using techniques such as hashing or XOR.
12. The network according to any one of the preceding claims, wherein the corresponding control device is adapted to use the random number to manage and use a digital certificate, which is necessary for authentication and establishing a secure connection.
13. The network according to any one of the preceding claims, wherein the network has a computer and / or machine-implemented error identification and recovery mechanism to ensure that the network remains functional even when a single node fails and / or a single quantum random number generator fails, for example by exchanging random numbers.
14. The network according to any one of the preceding claims, wherein the network is adapted to prevent the use of uncertified vehicle parts or spare parts and / or software components, specifically by implementing a random number-based authentication process when such parts or components are installed or started, the random number being generated by a hardware-based quantum random number generator in a node of the network.
15. The network of claim 14, wherein the authentication process includes generating an encryption key via the quantum random number generator of a node, the key being used to verify a digital certificate confirming the authenticity and integrity of the component to be installed or the software component.
16. The network according to any one of the preceding claims, wherein the network is adapted to identify breaches of one or more nodes by implementing an intrusion detection system (IDS), the system continuously monitoring the random numbers generated by a hardware-based quantum random number generator of the nodes and identifying statistical anomalies in the random number generation that indicate breaches.
17. The network of claim 16, wherein the IDS performs continuous entropy analysis on the random numbers generated by the quantum random number generator and sends an alarm message to the central control node in the vehicle network when it determines that there is a deviation from the expected entropy value.
18. The network according to any one of the preceding claims, wherein, for communication between different pairs of nodes in the network, different encryption keys and / or encryption methods are used, which are dynamically selected and generated by random numbers generated by the quantum random number generator.
19. The network of claim 20, wherein each node of the network is adapted to use a unique encryption method and key combination in each communication, the combination being different from the combinations of other node pairs.
20. The network according to any one of the preceding claims, wherein upon determining that one or more nodes have been compromised, the network is adapted to initiate defensive actions on one or more nodes, specifically by the node in question disconnecting from communication in the network and reinitializing its quantum random number generator for additional security checks.
21. The network of claim 20, wherein the defensive behavior enables the involved nodes to perform self-checks, wherein, The integrity of the internal encryption key and the random numbers generated by the quantum random number generator is checked before the node is allowed to communicate with the network again.
22. The network according to any one of the preceding claims, wherein the random number generated by the quantum random number generator is used to generate one-time passwords (OTPs) that are necessary for accessing security-critical functions of the vehicle, such as unlocking control devices or activating firmware updates.
23. The network according to any one of the preceding claims, wherein the network is adapted to activate a redundant network protocol when a potential threat arising from the destruction of a node or a group of nodes is identified, the network protocol rerouting communication paths within the network and ensuring communication security by dynamically generating new random numbers for encryption and authentication.
Citation Information
Patent Citations
Device for data processing
DE102022125568A1
Device for data processing
DE102022125569A1
Device for data processing
DE102022125570A1
Device for data processing
DE102022125571A1
Device for data processing
DE102022125572A1