ONE-WAY FUNCTION
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- STMICROELECTRONICS (ROUSSET) SAS
- Filing Date
- 2020-07-08
- Publication Date
- 2026-04-22
AI Technical Summary
Existing product authentication processes are inefficient and insecure, particularly in distinguishing between genuine and counterfeit consumables, which poses challenges for manufacturers and authorized suppliers.
Implementing a one-way function in electronic devices using a family of one-way functions that modify clock signals and node states based on previous results, combined with authentication, encryption, and hashing processes, to ensure robust and secure authentication.
Enhances the efficiency and security of product authentication by ensuring identical behavior across identical circuits, making it difficult for counterfeit products to mimic genuine ones.
Description
technical field
[0001] This description relates generally to electronic circuits and systems, and more specifically to electronic devices adapted to implement one-way functions, used, for example, in a mechanism for verifying the authenticity of a product associated with a consumable. Previous technique
[0002] The presence of counterfeit consumables for a product poses a problem for both the product manufacturer and authorized suppliers of genuine consumables, particularly in the event of returns due to functional issues. It is therefore important to be able to distinguish between genuine and counterfeit products.
[0003] The purpose of authentication processes is to verify that the consumable paired with the product is genuine or authorized. To this end, consumables and associated products are equipped with electronic circuits that execute authenticity verification protocols when a new consumable is installed, or periodically thereafter.
[0004] It would be desirable to be able to improve, at least in part, certain aspects of product authentication processes and, more particularly, certain aspects of the implementation processes of functions used in authentication processes.
[0005] EP 1 430 391 A2 constitutes the relevant prior art. Summary of the invention
[0006] The scope of the invention is defined by the independent claims.
[0007] There is a need for more efficient and secure product authentication processes.
[0008] One embodiment overcomes all or part of the drawbacks of known product authentication methods.
[0009] An embodiment provides a method for implementing a first one-way function, belonging to a family of one-way functions, by a device: in which a second function takes into account states of digital nodes distributed in circuits of the device implementing third functions; said states of the nodes depend on a previous result of the first function; and in which the second function and / or the third functions are one-way functions.
[0010] According to one embodiment, the first function is selected from said family of one-way functions using a parameter (P) provided by an activation function (555) to configure the third functions.
[0011] According to one embodiment, the first function is selected from said family of one-way functions using the previous R result to influence the configuration of the third functions.
[0012] According to one embodiment, the previous result of the first function influences the results of the third functions.
[0013] According to one embodiment, said result is further used to modify clock signals of the device.
[0014] According to one embodiment, said result is also used to modify clock signals that influence the implementation of third functions.
[0015] Another embodiment provides for a method of authenticating a first electronic device by a second electronic device, using the method described above.
[0016] Another embodiment provides for an encryption method using the method described above.
[0017] Another embodiment provides for a hashing process using the process described above.
[0018] Another embodiment provides for an electronic device comprising a circuit adapted to implement the process described above.
[0019] According to one embodiment, the device is a consumable.
[0020] According to one embodiment, the device is adapted to implement the authentication process described above.
[0021] According to one embodiment, the device is adapted to implement the encryption process described above.
[0022] According to one embodiment, the device is adapted to implement the hashing process described above. Brief description of the drawings
[0023] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the attached figures, among which: there figure 1 represents, in a very schematic and block-based way, a method of implementing an electronic circuit of the type used in a consumable and a product; the figure 2 represents, in a very schematic and block-based way, a method of implementing a circuit that is part of an authentication circuit; the figure 3 represents, in a very schematic and block-based way, another way of implementing the circuit of the figure 2 ; and the figure 4 represents an organizational chart illustrating a method of implementing an authentication process. Description of the implementation methods
[0024] The same elements have been designated by the same reference numerals in the different figures. In particular, structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.
[0025] For the sake of clarity, only the steps and elements useful for understanding the implementation methods described have been represented and are detailed.
[0026] Unless otherwise specified, when referring to two connected elements, this means directly connected without any intermediate elements other than conductors, and when referring to two linked or coupled elements, this means that these two elements can be connected or linked or coupled through one or more other elements.
[0027] In the description that follows, when referring to absolute positional qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative positional qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientational qualifiers, such as the terms "horizontal", "vertical", etc., unless otherwise specified, it refers to the orientation of the figures.
[0028] Unless otherwise specified, the expressions "approximately", "roughly", "about", and "on the order of" mean within 10%, preferably within 5%.
[0029] In the following description, a consumable will be defined as an electronic device designed to be used with an electronic product in order to function. Consumables are generally interchangeable once their use is complete. For example, a memory card is a consumable in relation to a digital camera. The same is true for an ink cartridge in relation to a printer, an interchangeable battery in relation to a mobile phone, an e-liquid cartridge in relation to an electronic cigarette, and a video game cartridge in relation to a console. The embodiments described in relation to the figures 1 to 4 are applicable to any consumable-product pair.
[0030] There figure 1 represents, in a very schematic way and in block form, a method of implementation of an electronic circuit, or device 3 of the type of those equipping a device and a consumable.
[0031] Circuit 3 includes: a computing unit 31 (PU), for example a state machine, a microprocessor, a programmable logic device, etc.; one or more volatile and / or non-volatile storage areas 33 (MEM) for storing all or part of the data and programs; one or more data, address, and / or command buses 35 between the various internal elements of the circuit 3; an input / output (I / O) interface 37 for communication with the outside of the circuit 3; and various other circuits depending on the application, symbolized in figure 1 by a block 39 (FCT).
[0032] According to the embodiment shown, circuit 3 further includes an authentication circuit or function 4 (ALGO) implementing an authentication process. For this purpose, block 4 is a device executing cryptographic functions in hardware (hardwired logic) to, for example, implement an authentication process.
[0033] An authentication mechanism based on a signature, or code, is planned, which is unique in that it is linked to the topography of the integrated circuit or the part of the circuit involved in authentication and executing this signature. We will subsequently refer to the authentication circuit, but what is described here may only concern a part of this circuit. Topography here refers to the arrangement of the components forming the circuit on an electronic chip or substrate.
[0034] It is also planned to equip products and consumables with identical authentication circuits, meaning circuits with identical topologies, so that a process executed on one circuit results in identical behavior when executed on the other circuit. By behavior, we mean that the electrical behavior of the circuit is identical when executing the same calculation, program, or operation.
[0035] There figure 2 represents, very schematically and in block form, a way of implementing a circuit 5 which carries out a function used by the authentication circuit 4 which is itself part of circuit 3 of the figure 1 In other words, circuit 5 is part of circuit 4.
[0036] Circuit 5 is suitable for implementing a one-way function that can be used in an authentication process.
[0037] Circuit 5 comprises various logic circuits 53 implementing cryptographic functions. Circuit 5 comprises at least two logic circuits 53 (three circuits 53 are represented in figure 3The more logic circuits 53 comprise in circuit 5, the more complex the function implemented by circuit 5. Input and output nodes of these logic circuits 53 are digital points, or nodes, 51 of circuit 5, having high states, "1", or low states, "0". Alternatively, the nodes 51 can also be internal nodes of the logic circuits 53. The distribution of the digital nodes 51 depends on the topology of circuit 5. The number of nodes 51 taken by circuit 5 and whose electrical states are taken into account for the signature determines the robustness of the calculated signature. For example, it is expected that the circuits 53 will each provide 64 internal nodes to obtain a complex function.
[0038] The circuits 53 are also used by circuit 4 for other operations, for example, encryption operations, hashing operations, etc. The distribution of the nodes 51 of the circuits 53 taken into account in the signature calculation depends on the application of the function of circuit 5. The more the nodes are distributed over a large area of circuit 3, the more complex the one-way function implemented by circuit 5.
[0039] Circuit 5 further includes a main device represented by a block 55 (ID). Device 55 includes, in particular: a 551 block (ONE-WAY) representing a cryptographic function; a 553 block (CYCLE) representing a function for managing a cycle or iteration count; and a 555 block (ID MODE) representing a function for activating an authentication process.
[0040] The cryptographic function of block 551 is designed to provide a result called the code R from the states of the nodes 51. More generally, block 551 is designed to implement a family of functions capable of providing the result R. To choose which function from this family is implemented, the blocks 53 can receive a parameter P from block 555. In other words, the parameter P configures the cryptographic function implemented by each block 53. The function, selected and implemented by block 551, can be used over several iterations, the number of which is managed by the function in block 553. In one embodiment, at each new iteration, the code R, or portions of the code R calculated in the previous iteration, are injected into the circuits 53 to modify their internal states and thus their operation.More specifically, injecting the R code or portions of the R code adds arguments to the functions implemented by the circuits 53, thereby modifying the operation of said functions. The state of the digital points 51 is thus modified. This aims to make the calculation of the R code more complex. Once the iterations are complete, the function of the circuit 5 provides a final signature Rf.
[0041] When the function in circuit 5 is used for an authentication process, the signature calculation function executed by block 551 does not need to be complex. The important thing is that the final signature Rf is produced by two identical authentication circuits. Thus, any calculation is suitable, for example, a hash function, or even a direct comparison of a word representing all the sampled states. However, providing a combination, a cryptographic process, or a one-way function to calculate a signature increases the robustness of the authentication. More specifically, the function in block 551 is, for example, a one-way function, preferably a hash function. If the function in block 551 is not a one-way function, then at least one function in block 53 is a one-way function.
[0042] The function for activating an authentication process in block 555 is a function that allows starting an activation process for circuit 3 of the figure 1 .
[0043] In this example, a circuit authentication process involves generating a signature, or code, using the function implemented by circuit 5. During an initial phase, or first iteration, the circuits 53 are initialized by processor 31, or are left in their initial state. Thus, the states of the nodes 51 are in an initial state, and a first code R is loaded by the function of block 551 from these states. During subsequent iterations, the code R from the previous iteration is used to modify the functions implemented by the blocks 53. Thus, at each iteration, the states of the nodes 51 are modified, and a new code R is generated from these states and the code R from the previous iteration.
[0044] There figure 3represents, very schematically and in block form, another way of implementing an authentication circuit 5'.
[0045] Circuit 5' in Figure 5 includes elements common to circuit 5 of the figure 3 These elements will not be detailed again below.
[0046] Circuit 5' further includes a 557 block (CLK CTRL) representing a function for managing various clock signals used by circuits 53 and by the function of block 551 of the figure 2 . Block 557 thus provides one or more CLK clock signals to circuits 53 and block 551.
[0047] Block 557 can receive information from block 551, such as the R code or portions of the R code. This information can be used, for example, to modify the clock signals, such as triggering or not triggering a new cycle, or by changing the frequencies of the clock signals. More specifically, the R code can be used to slow down or speed up the execution of functions implemented by circuits 53, and thus modify the R code of the next iteration by changing the states of nodes 51.
[0048] One advantage of this implementation is that using R code to modify the clock signals makes it possible to further complicate obtaining the final Rf signature.
[0049] There figure 4 is a flowchart illustrating an implementation method for an example of an authentication process using one of the circuits 5 or 5' described in relation to the figures 2 Or 3As an example, this authentication process can be implemented by a product and a consumable.
[0050] At step 61 (INITIAL STATE), circuit 5 is connected, either wired or wirelessly, to another identical circuit, or one that includes identical parts of an authentication circuit. The authentication process is then initiated by the authentication process activation functions (block 555) of each circuit 3, for example, by the exchange of initial data. A first step is the initialization of the logic circuits in blocks 53.
[0051] At step 62 (INITIAL STATE ID), the functions comprising the authentication device 55 are initialized. As an example, the function selection parameter P for block 551 is generated.
[0052] At step 63 (ID ENABLE), a control signal requests the activation of the authentication mode of circuit 3.
[0053] At step 64 (ID RDY), it is checked whether the authentication mode is ready to be used. If activation of this mode is not possible (output N of block 64), then the next step is again step 62; otherwise (output Y of block 64), the next step is step 65.
[0054] At step 65 (START ID), the authentication process begins.
[0055] At a step 66 (R DET), the first code R is generated by the signature function of block 551, from the states of the digital points 51. The iterations then begin and the code is modified over the course of them, to finally provide the final signature Rf.
[0056] At step 67 (Cycle End?), the function in block 553 checks if the number of iterations defined by the function in block 553 has been reached. If so (output Y of block 67), the next step is step 68 (COMP). If not (output N of block 67), then the next step is again step 66, and the signature function continues the iterations.
[0057] At step 68, the final signature Rf of circuit 3 is obtained, and it can be compared to the signature obtained in parallel by the circuit against which circuit 3 wishes to authenticate. If the two signatures are identical, then the authentication has succeeded; otherwise, it has failed.
[0058] According to one embodiment variant, step 68 can be a linking step to other calculations taking as input the final signature Rf.
[0059] Various embodiments and variants have been described. Those skilled in the art will understand that certain features of these various embodiments and variants could be combined, and other variants will become apparent to them.
[0060] The described embodiments are simplified to illustrate the principles of the authentication process. The calculations and exchanges may be accompanied by any other standard protection measures, such as symmetric or asymmetric encryption of transmissions between the circuits to be authenticated.
[0061] Furthermore, the one-way function of circuit 5 can be used in the same way as a one-way function, that is, for example, for a circuit authentication process, for a data encryption process, or for a data hashing process.
Claims
1. A method of implementation of a first one-way function, being part of a family of one-way functions, by a circuit (5') suitable to implement said family of functions, wherein: - a second function (551) of the circuit (5') takes into account states of digital nodes (51) distributed in at least two logic circuits (53) of the circuit (5') implementing third functions; - said states of the nodes (51) depend on a previous result (R) of the second function (551) injected into logic circuits (53); and - wherein the second function (551) and / or the third functions are one-way functions, wherein the first function is selected by the second function (551) from said family of one-way functions by using: a parameter (P) provided to the logic circuits (53) by an enabling function (555) of the circuit (5') to configure the third functions, and / or the previous result (R) injected into the logic circuits (53) by the second function (551) to have an influence on the configuration of the third functions.
2. The method according to claim 1, wherein a previous result of the first function has an influence on a result of the third functions.
3. The method according to claim 1 or 2, wherein said result (R) is further used to modify clock signals (CLK) of the circuit (5').
4. The method according to claim 3, wherein said result (R) is further used to modify the clock signals (CLK) having an influence on the third functions.
5. A method of authentication of a first electronic device by a second electronic device, using the method according to any one of claims 1 to 4.
6. A cipher method using the method according to any one of claims 1 to 4.
7. A hash method using the method according to any one of claims 1 to 4.
8. An electronic device (3) comprising a circuit (5') suitable to implement the method according to any one of claims 1 to 4.
9. The device according to claim 8, being a consumable.
10. The device according to claim 8 or 9, being suitable to implement the method according to claim 5.
11. The device according to claim 8 or 9, being suitable to implement the method according to claim 6.
12. The device according to claim 8 or 9, being suitable to implement the method according to claim 7.