Qrng with prng use and vertical entropy source

EP4599325A1Pending Publication Date: 2025-08-13ELMOS SEMICON AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2023797650
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-09-20
Filing Date
2023-09-26
Publication Date
2025-08-13

AI Technical Summary

Technical Problem

Current random number generators, particularly in the automotive and industrial sectors, face challenges with inadequate entropy properties, making them vulnerable to piracy attacks and data transmission security issues. Quantum Random Number Generators (QRNGs) are difficult to integrate and have poor quantum yield, while existing solutions are complex, costly, and susceptible to external influences.

Method used

A microcontroller with a quantum process-based generator that includes a vertical entropy source with a photon source and detector integrated on a semiconductor substrate, using a time-to-pseudo-random number converter to generate random bits, and incorporating a watchdog and voltage monitor for security and robustness, ensuring high entropy and resistance to manipulation.

Benefits of technology

The solution provides a compact, robust, and secure true random number generator with high entropy rates, capable of passing NIST statistical tests, achieving a higher bit rate and enhanced security against attacks, while being more economical and integrated into a monolithic semiconductor circuit.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 1.1
    Figure 1.1
Patent Text Reader

Abstract

The quantum process-based generator (28) for real random numbers (411, 418) has an entropy source (401), and the quantum process-based generator (28) for real random numbers (411, 418) evaluates a signal (405) of the entropy source (401) using a time-to-pseudo random number converter (TPRC) (404.3) and generates one or more random bits (411) and optionally random numbers (418).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] QRNG with PRNG usage and vertical entropy source

[0002] Priorities

[0003] This patent application takes the priorities of the German patent application

[0004] DE 10 2022 125574.3 of October 4, 2022 and German patent application DE 10 2023 126 115.0 of September 26, 2023 and German patent application DE 10 2023 125543.6 of September 20, 2023.

[0005] Field of invention

[0006] The invention is directed to a microcontroller comprising at least one quantum-process-based true random number generator (QRGN) as a random number generator, particularly for encryption. The present invention particularly comprises a random number generator (RNG), in particular an improved true random number generator (TRNG) based on quantum processes, and the evaluation of the entropy source signal using pseudorandom number generators (PRNGs) located within the entropy extraction.

[0007] The present invention thus relates to a data processing device with a quantum technology-based random number generator.

[0008] Background of the invention

[0009] The automotive industry and other industries are increasingly facing a variety of

[0010] Exposed to piracy attacks. Counterfeiters copy the spare parts and products of the affected industrial manufacturers and usually use their brand names. Another point of attack is data transmission within the products and / or data transmission to and from the product.

[0011] The entropy properties of common random number generators for such systems are typically inadequate. Quantum-process-based generators for truly random numbers (QRNGs) are known from the state of the art, but they are difficult to integrate or exhibit poor quantum yield. Random number generators are currently used in many applications, ranging from science to cryptography.

[0012] The technical teaching of EP 3 529 694 B1 is known from the prior art, in which the time duration between pulses of an entropy source consisting of two SPAD diodes is used. The disadvantage of the technical teaching of EP 3 529 694 B1 is the low quantum efficiency in the transfer of photons from the first SPAD diode, which operates as a silicon diode, to the second SPAD diode, which operates as a photodiode. The document presented here therefore quotes statements by the authors and inventors in EP 3 529 694 B1 in sections. The document presented here uses the technical teaching of EP 3 529 694 B1 and builds on the technical teaching of

[0013] WO 2023 072 956 A1, the technical teaching of which is repeated in the document presented here in connection with the solution to the problem.

[0014] “A typical example of the first case is computer science, which requires the generation of a certain number of random initial states that serve as a description of the initial state of the simulation.

[0015] For these types of applications, it is generally required that the initial configurations are not strictly correlated but can be reproduced deterministically, for example, to verify the effects of variations on the codes that perform the simulations. For this reason, these sequences are more accurately called pseudorandom numbers (PRNs), as they are defined by complex algorithms that start from an initial value. In other words, given an initial random number, known in technical jargon as a "seed," a formula, no matter how complex, will always reproduce the same sequence of random numbers. The corresponding generators are called pseudorandom number generators (PRNGs).

[0016] In the second case, however, when random numbers are used in cryptography techniques to perform banking operations, for example, the approach described above appears weak, since it is necessary to ensure that the generated sequences are completely unpredictable in order to guarantee the security of highly sensitive information. In this case, the most secure approach is to generate random numbers from a generation process that must be truly random and must not allow any prediction of the generated sequence. These generators are called True Random Number Generators (TRNG).

[0017] In particular, quantum mechanisms, such as the generation of photons by a light source, are among the best-studied methods for obtaining the said sequences of true random numbers and are based on the uncertainty of the measured event, which is one of the properties of the quantum system itself.

[0018] From the point of view of information theory, the degree of unpredictability of the random numbers generated using the two techniques mentioned above can be expressed by the parameter "entropy", which is known as the uncertainty or information present in a random variable.

[0019] In addition, it is important to emphasize that the National Institute of Standards and Technology (NIST), in its guideline NIST SP800-22, specifies about fifteen statistical tests that can be used to determine whether or not a given random number generator has a sufficient level of entropy.

[0020] As mentioned above, the use of PRNGs for cryptographic purposes is dangerous, not only because certain algorithms have weaknesses that may not become apparent until some time after their introduction, but also because a malicious person who could recover the seed from which all random sequences are generated could predict all subsequent outputs based on the same seed with absolute certainty.

[0021] A solution based on physical phenomena, and in particular quantum phenomena, is therefore much more suitable, given the inherent unpredictability of these events, even for people with in-depth knowledge of the algorithms used and high computing power. However, while pseudorandom number generation algorithms can be chosen to produce sequences with certain statistical properties that can be determined with absolute certainty due to their deterministic nature, random numbers derived from physical phenomena are subject to practical limitations due, for example, to variations in the production quality of equipment, fluctuations in the power supply, and environmental factors such as external fields and temperature variations.These deviations from the ideal case generally result in a deviation from a statistically uniform distribution, which is independent of the events that can be measured in a sample space. As a result, it is even possible to observe a reduction in the entropy of the true random number generators mentioned.

[0022] To overcome this drawback, these true random number generators require an additional step, called post-processing, which is performed after the random code sequence has been extracted based on the specific physical phenomenon. This post-processing step indeed improves the uniformity of the probability distribution of the random code sequence. However, the disadvantage is that this post-processing step impacts the bit rate that the generator can guarantee.

[0023] As mentioned above, it is also known that one of the physical phenomena most widely used for generating truly random numbers is quantum photonics. For this reason, these generators, which belong to the macro category of TRNGs, are also referred to by the acronym QRNG (Quantum Random Number Generator). In these generators, an attenuated light source generates a few photons (a low value of the detected photon flux X), which are detected by one or more single-photon detectors, each of which is known by the acronym SPAD (Single Photon Avalanche Diode).In addition, the system includes corresponding electronic circuits downstream of the above-mentioned SPADs, consisting of auxiliary circuits and usually one or more TDCs (Time to Digital Converters) or counters capable of extracting a random bit sequence from each of the SPADs by measuring the arrival time of the detected photons or by counting them.

[0024] In these generators, the light source and the detector(s) are separate devices that must be appropriately coupled and shielded. A disadvantage, however, is that this design is not immune to the influence of uncontrolled external environmental factors. Furthermore, the fact that the light source and the detector(s) are separate devices that are coupled together one after the other makes the entire random number generator highly vulnerable to any kind of interference or manipulation.

[0025] Another disadvantage is that this implementation entails high costs for the device because the two devices must be optically aligned.

[0026] Having discussed the above, it should be noted that various types of random number generators based on the QRNG concept are available on the market. These generators cover a wide range of applications, from portable USB devices delivering only a few hundred kbit / s to large electronic systems capable of guaranteeing bit rates of hundreds of Mbps. Furthermore, several logics and architectures designed to determine sequences of truly random numbers starting from a physical phenomenon, in particular photon detection, have been proposed in the existing literature on this topic. Most of them record the "arrival time," or the number of photons impinging on the sensitive surface of the SPAD detector(s).An example of a known arrival-time-based quantum random number generator can be found in the international publication WO 2016016741 Al. In particular, the so-called arrival-time-based technique has been proposed to measure the time elapsed between the moment a photon comes into contact with a single SPAD and the moment the subsequent photon comes into contact with the same SPAD. While this technique allows for a high bit rate, it suffers from significant distortion because, as already explained, the photon source obeys the Poisson process.

[0027] To overcome this disadvantage, the state of the art proposes directly acting on the photon source to control the flux of photons generated by it. This process involves, in particular, varying the pilot current of the photon source to make its statistical distribution over time as uniform as possible.

[0028] A disadvantage of this approach, however, is that a special electronic circuit must be built into the random number generator that can control the photon source, as explained above, which increases the complexity and size of the generator itself."

[0029] Random events and the determination of probabilities play a particularly prominent role in many areas of science and technology. For example, Monte Carlo simulations and secure encryption methods rely heavily on the provision of random numbers. A general distinction is made between so-called pseudo-random numbers and true random numbers. While the former are generated using deterministic formulas by pseudo-random number generators (PRNGs), and are therefore not absolutely random, non-deterministic random number generators (TRNGs) for the provision of true random numbers are generally based on real, unpredictable processes such as thermal or atmospheric noise, rather than on artificially generated patterns of deterministic algorithms.However, even the results of such non-deterministic random number generators based on external parameters can, depending on the underlying random element, still tend slightly towards higher or even numbers due to weak correlations, for example, and thus enable at least a partial predictability of the random numbers generated in this way.

[0030] So-called quantum random number generators (QRNGs), a special subgroup of TRNGs, are based on fundamental quantum processes for random number generation and are therefore, at least theoretically, not dependent on other external factors and effects that influence statistics. Quantum random number generators thus represent the currently best available source of true random numbers. Current digital QNRGs can deliver entropy rates (i.e., a sequence of bit values ​​with maximum randomness or entropy) of up to several hundred Mbps. The generated random numbers are required in both classical encryption methods and a variety of quantum computing and quantum cryptography methods to ensure secure key exchange (Secure / Quantum Key Distribution, SKD / QKD).Therefore, non-manipulable and fast QRNGs are essential for generating secure keys in cryptography.

[0031] Due to their particularly easy implementation, many QRNGs are realized as photonic QRNGs using the random properties of photons. A simple concept for generating random numbers is the behavior of a photon, which is either reflected or transmitted at a semitransparent beam splitter independently of other photons. Another approach is to utilize the random arrival times of photons at a single-photon detector. This distribution effect, based on intrinsic, fundamentally non-deterministically calculable photon statistics of the photons of a corresponding photon source, can also be used to generate truly random numbers. The arrival times of photons at a single-photon detector generally exhibit an exponential distribution.

[0032] Typically, a single-photon detector (SPD) initially generates a detector pulse from a single incident photon, which is then converted into a time-stamped digital representation of the detection event in a time-to-digital converter (TDC) and can be further processed accordingly. Laser diodes (LDs) or simple light-emitting diodes (LEDs) that are strongly attenuated to the single-photon level are usually used as the photon or entropy source in QRNGs. Their emitted photons can then be recorded in a time-resolved manner as SPDs using one or more particularly sensitive single-photon avalanche diodes (SPADs).Such photon sources that simultaneously provide only single photons or only a few photons are also referred to as single-photon sources (SPS) in this application. However, they do not necessarily have to be true single-photon emitters, for example, based on a single isolated two-level system.

[0033] SPADs are a type of photodetector similar to photodiodes (PDs) and avalanche photodiodes (APDs), but with significantly increased sensitivity. SPADs can be read and evaluated digitally - even within a common integrated circuit. If such an integrated detector circuit is excited by individual photons, only one electron-hole pair is generated per exciting photon in the sensor-active region (absorption region). The excited electrons are drawn to the cathode by electric fields, and the excited holes are drawn to the anode. In a SPAD, the charge carriers drift through a so-called avalanche region, within which a charge avalanche is generated by intensified impact ionization. These are therefore highly sensitive photon receiver elements that, when activated, store a high amount of charge (approx.105 - 106 electrons) with high temporal resolution.

[0034] A SPAD is typically operated in Geiger mode above its breakdown voltage, where a single photon is detected via the generated charge avalanche and subsequently registered as a single event. To reduce the dead time during registration, active or passive suppression or quenching of further charge carrier amplification can occur immediately after the onset of the avalanche formation. In addition to the SPAD, the integrated circuit can also include a so-called single-photon counter (SPC). In this case, instead of directly outputting a single detector pulse, an immediate statistical evaluation of the temporal distribution of the individual detected single-photon events is generally performed.

[0035] Statistical analysis performed in parallel with random number generation can, for example, be used to further secure the random number generation process against potential attacks. Particularly in the case of non-integrated photonic QRNGs constructed from individual components, the required transmission paths within the system offer a wide range of attack possibilities. Therefore, to increase security, such systems are implemented as compactly as possible and isolated from their external environment. In addition to avoiding potential attack scenarios, another advantage of such compact QRNGs is that natural influences from outside the system that might impair random number generation can also be minimized to the greatest extent possible. Accordingly, compact QRNGs based on photon noise have typically been provided as hybrid integrated systems.

[0036] From EP 3 529 694 B1, an integrated quantum random number generator (iQRNG) with a PLC and one or more SPDs is also known, in which the PLC and the SPD(s) are completely integrated in CMOS technology in a single semiconductor substrate such that they are arranged directly next to each other (see FIG. 1 with the associated figure description). The PLC is provided by a suitably doped pn junction so that it generates a photon current to be detected when the photon source is suitably biased in the forward or reverse direction.

[0037] SPDs are particularly intended to be SPADs, which are preferably formed by joint

[0038] manufacturing processes with the PLCs and have the same chemical structure.

[0039] The joint integration ensures that the photon flux generated by the SPS can flow directly to an adjacent SPAD through optical crosstalk within one and the same semiconductor material. Unlike other hybrid-integrated QRNGs known from the state of the art, it does not first have to overcome or tunnel through a possibly empty coupling gap that physically separates the two components. The integrated "side-by-side" configuration makes the QRNG presented in the publication more compact and structurally less complex than hybrid QRNGs of the same functional type. Furthermore, thanks to the integration of all components, the random number generator is significantly more robust and immune to external environmental influences as well as attempts at manipulation by external attackers.

[0040] However, it is still possible, at significantly increased expense, to interfere with, influence, and / or monitor the random number generation process during the QRNG's operation. Since the iQRNG disclosed in the publication essentially has a planar structure, individual photons could certainly be tapped or additionally introduced from above or below the plane of the substrate.

[0041] The horizontal juxtaposition of the structures is also not ideal in terms of efficiency and required space consumption. Efficiency is particularly limited by the required lateral distance between the SPS and the SPAD and the associated high absorption of the photons in the semiconductor material. Furthermore, without special precautions, the photons emitted by the SPS are largely scattered into the material surrounding the SPS, meaning that only a portion of the generated photons can be detected by an associated SPAD. While multiple SPADs can be arranged around a single SPS, increasing efficiency and thus the digital entropy rate through joint evaluation of the connected SPADs, this significantly increases the space consumption of such an iQRNG.On the other hand, even with a single emitter-detector pair, it must be ensured that undetectable photons cannot propagate uncontrollably within the substrate and cause interference elsewhere in the substrate. The associated lateral blocking regions therefore also increase the effective area consumption of the iQRNG. An iQRNG, also implemented in CMOS technology (HV-CMOS), with a corresponding arrangement of a photon source and a single-photon detector next to each other is also known from Khanmohammadi et al. (Khanmohammadi, Abbas, et al. "A monolithic silicon quantum random number generator based on measurement of photon detection time." IEEE Photonics Journal 7.5 (2015): 1-13).A Si-LED, formed as a photon source in a circular n-well near the surface between a central n++ region as the cathode and several p++ regions arranged in a ring around it as the anode, is enclosed in a circular ring by a SPAD as a single-photon detector (see FIG. 2 with the associated figure description). The photons emitted by the SPS are thus detected from all sides in the plane, which allows for increased efficiency compared to the iQRNG known from EP 352694 B1 while requiring less space. The SPS is thus directly integrated into the SPAD. However, individual photons can also be emitted into the substrate or extracted from its surface. Likewise, the injection of corresponding photons by an attacker to influence the statistics is also possible in this way.

[0042] Therefore, to further increase security and reduce space consumption, there is a need for further miniaturization of integrated QRNGs compared to the state of the art. The iQRNG should be largely protected against external attacks while exhibiting the highest possible efficiency and the lowest possible substrate losses. To avoid being limited by manufacturing technology constraints in the design of SoCs (System on Chip, SoC), the underlying manufacturing process should be as technology-open as possible or be based on the most widely applicable technology platform for semiconductor structuring.

[0043] Task

[0044] The present invention aims to overcome all of the above-mentioned disadvantages. In particular, it is an object of the invention to provide a true random number generator that guarantees a high degree of entropy, allowing it to at least pass the statistical tests defined by NIST.

[0045] A further object of the invention is to provide a generator for true random numbers which makes it possible to achieve an even higher bit rate in the generation of random sequences of bits and to ensure the randomness of the measurement result even in the event of failure of the entropy source.

[0046] Another object of the invention is to provide a true random number generator having a more compact, robust and less complex structure than the random number generators known in the prior art, so that this random number generator can be accommodated in the pad edge of a monolithically integrated semiconductor circuit.

[0047] Another object of the invention is to provide a true random number generator that offers a high degree of security against any attempt to forcibly alter or tamper with its internal components.

[0048] Another object of the invention is to provide a true random number generator that offers a high level of security, detecting and reporting any attempt to forcibly alter or tamper with its internal components.

[0049] Another, but no less important, object of the invention is to provide a true random number generator that is more economical than the generators of the known prior art.

[0050] The device of the independent claim solves this problem. Further developments are the subject of the dependent claims.

[0051] The object of the invention to provide a compact entropy source 411 that goes beyond the prior art is achieved by the subject matter of independent patent claims. Preferred developments are the subject matter of further subclaims.

[0052] Solution to the task

[0053] The automotive industry and other industries are increasingly exposed to a variety of piracy attacks. Counterfeiters copy the spare parts and products of the affected industrial manufacturers and typically use their brand names. Another point of attack is data transmission within the products and / or data transmission to and from the product.

[0054] The entropy properties of common random number generators for such systems are typically inadequate. Quantum process-based generators for truly random numbers (QRNGs) are known from the state of the art, but they are difficult to integrate or exhibit poor quantum yield.

[0055] It is known from the prior art to provide an integrated circuit that includes, among other features, a processor. For some applications, it is necessary to ensure that the processed data, including the executable code, cannot be modified by unauthorized persons accessing data stored outside the integrated circuit, or, if such access occurs, that it cannot be undetected.

[0056] SUMMARY OF THE INVENTION The quantum process-based generator for true random numbers according to the invention has, in a first embodiment, an entropy source and is configured to evaluate a signal from the entropy source by means of at least one time-to-pseudo-random number converter and to generate one or more random bits as a function of the signal from the entropy source.

[0057] In a second independent embodiment, for which independent protection is claimed, the quantum process-based generator for true random numbers according to the invention is embodied in one piece on a semiconductor substrate with a surface and has a vertical entropy source with at least one photon source with at least one photon detector. The surface of the semiconductor substrate, within the meaning of the document presented here, is defined as a horizontal plane with a first direction in the plane (1st plane vector) and a second direction in the plane (2nd plane vector), which is different from the first direction in the plane. The photon source and the photon detector are arranged in a vertical direction relative to the first and second directions in the horizontal plane of the surface of the semiconductor substrate, relative to the first and second directions in the plane in the semiconductor substrate.In this wide independent embodiment of the invention, the quantum process-based generator for true random numbers is configured to generate one or more random bits depending on a signal from the entropy source.

[0058] The quantum process-based generator for true random numbers according to the invention comprises, in a third independent embodiment for which independent protection is claimed, an entropy source in a semiconductor substrate having a surface and a back side which is located opposite the surface on the other side of the semiconductor substrate, and means for detecting an attack on the entropy source by means of photons, wherein this attack can in particular be an attack from a back side of the semiconductor substrate.

[0059] In a variant of the third independent form, these means for detecting an attack on the entropy source by means of photons may comprise an observation diode.

[0060] In variants of the three independent forms, the quantum process-based generator can include a watchdog.

[0061] In variants of the three independent forms, the quantum process-based generator can comprise a voltage monitor (423).

[0062] In variants of the invention, the watchdog and / or the voltage monitor can be configured to monitor the quantum process-based generator for an attack or a disturbance by means of said means for detecting an attack on the entropy source by means of photons, in particular by means of the observation diode.

[0063] In variants of the invention, the at least two device parts of the quantum process-based generator for true random numbers can be designed in one piece on a common semiconductor substrate as a one-piece quantum process-based generator.

[0064] In variants of the invention, the quantum process-based generator for true random numbers can be configured to generate at least one random number from a plurality of random bits and to provide or use the at least one random number.

[0065] In variants of the invention, the logical values ​​in the temporal order of the pseudorandom bits of a time-to-pseudorandom number converter (TPRG), i.e. the actual pseudorandom bit sequence of the time-to-pseudorandom number converter (TPRG), of the quantum process-based generator depend on one or more quantum random bits and / or one or more quantum random numbers, which are typically operating parameters of the time-to-pseudorandom number converter (TPRG).

[0066] In variants of the invention, the watchdog is configured to monitor the correct functioning of the quantum process-based generator for true random numbers.

[0067] In variants of the invention, the watchdog is configured to measure the randomness of the generated quantum random bits in the form of one or more measured values ​​and to compare each of them with a respective tolerance interval or a respective threshold value, and to infer a respective error in the case of a respective deviation of the respective measured value from the respective tolerance interval or the respective threshold value.

[0068] In variants of the invention, the watchdog is configured to monitor the correct function of the time-to-pseudorandom number converter (TPRC) of the at least one time-to-pseudorandom number converter (TPRG) of the quantum process-based generator and / or to monitor a behavior in the form of the temporal statistics of the logical values ​​in the temporal sequence of the pseudorandom bits of the time-to-pseudorandom number converter (TPRC) and to record them in the form of statistical measured values ​​and to detect and / or signal an error in the event of deviations of the statistical measured values ​​from the expected behavior in the form of a departure from permitted measured value ranges for these measured values.

[0069] In variants of the invention, the quantum-process-based true random number generator with its at least two device parts is manufactured in one piece as part of an integrated circuit. In variants of the invention, the integrated circuit with the quantum-process-based true random number generator is manufactured using BCD technology.

[0070] In variants of the invention, the integrated circuit with the quantum process-based generator for true random numbers comprises a voltage converter for supplying the entropy source of the quantum process-based generator for true random numbers, wherein the voltage converter then comprises one or more DMOS transistors for increasing the voltage strength.

[0071] In variants of the invention, said integrated circuit comprises a circuit such as a microcontroller, a microprocessor, a memory, a DRAM, an SRAM, a RAM, a volatile memory, an OTP memory, an EEPROM, a flash memory, an MRAM, an FRAM, a sensor evaluation circuit, a control circuit for an automotive control circuit, a graphics controller, an evaluation circuit for a biometric sensor or an input device, a control circuit, a chip card circuit, an RFID circuit, a physical circuit of a mobile phone or a smartphone, a circuit of an access control system, a circuit with a coded recording of operating parameters, a circuit of an access control system, a circuit of an electronic security system, a radio system circuit, a communication circuit, a circuit of an encryption and / or decryption system,a circuit of an individualization system, a circuit of a gaming device, a circuit of a simulation system, a circuit of a computer system, a circuit of a noise source, a circuit with a device for generating and / or using a spreading code, a circuit with a device for generating and / or using a random number for individualizing the circuit, a circuit with a device for generating and / or using a random number for testing purposes, in particular for self-testing purposes and / or for testing an application circuit of which the circuit is a part. The document presented here thus discloses a microcontroller, a microprocessor, a memory, a DRAM, an SRAM, a RAM, a volatile memory, an OTP memory, an EEPROM, a flash memory, an MRAM, an FRAM, a sensor evaluation circuit,a control circuit for an automotive control circuit, a graphics controller, an evaluation circuit for a biometric sensor or an input device, a control circuit, a chip card circuit, an RFID circuit, a physical circuit of a mobile phone or a smartphone, a circuit of an access control system, a circuit with a coded recording of operating parameters, a circuit of an access control system, a circuit of a security system for electronic security devices, a radio system circuit, a communication circuit, a circuit of an encryption and / or decryption system, a circuit of an individualization system, a circuit of a gaming device, a circuit of a simulation system, a circuit of a computer system, a circuit of a noise source, a circuit with a device for generating and / or using a spreading code,a circuit with a device for generating and / or using a random number to individualize the circuit, a circuit with a device for generating and / or using a random number for testing purposes, in particular for self-testing purposes and / or for testing an application circuit of which the circuit is a part, with a quantum process-based generator for true random numbers according to the invention and / or the use of random bits and / or random numbers of the quantum process-based generator for true random numbers according to the invention in a microcontroller, a microprocessor, a memory, a DRAM, an SRAM, a RAM, a volatile memory, an OTP memory, an EEPROM, a flash memory, an MRAM, an FRAM, a sensor evaluation circuit, a control circuit for an automotive control circuit, a graphics controller,an evaluation circuit for a biometric sensor or an input device, a control circuit, a chip card circuit, an RFID circuit, a physical circuit of a mobile phone or a smartphone, a circuit of an access control system, a circuit with a coded recording of operating parameters, a circuit of an access control system, a circuit of a security system of electronic security devices, a radio system circuit, a communication circuit, a circuit of an encryption and / or,

[0072] Decryption system, a circuit of an individualization system, a circuit of a gaming device, a circuit of a simulation system, a circuit of a computer system, a circuit of a noise source, a circuit with a device for generating and / or using a spreading code, a circuit with a device for generating and / or using a random number for individualizing the circuit, a circuit with a device for generating and / or using a random number for testing purposes, in particular for self-testing purposes and / or for the purposes of testing an application circuit of which the circuit is a part.

[0073] In variants of the invention, the integrated circuit has (internal interfaces as special circuits) at a cryptographic boundary between a control device and other parts of the integrated microelectronic circuit that are classified as non-secure or less secure, and the quantum process-based generator for true random numbers is arranged within the cryptographic boundary between the control device and the other parts of the integrated microelectronic circuit. In variants of the invention, the entropy source comprises a photon source and a photon detector, wherein the photon source is configured to emit photons as a quantum signal when supplied with electrical energy, and wherein the photon source is optically coupled to the photon detector.In this variant of the invention, the photon detector is configured to at least partially receive the quantum signal of the photon source and to generate an output signal of the entropy source or a precursor signal thereof.

[0074] In a variant of the invention, the photon source comprises a silicon LED, in particular a Zener avLED or a SPAD diode.

[0075] In variants of the invention, the quantum process-based generator is placed entirely or in part in a pad frame between connection pads of the integrated circuit on the die of this integrated circuit, wherein at least the entropy source is placed in the pad frame between the connection pads of the integrated circuit on the die of this integrated circuit.

[0076] In variants of the invention, the entropy source of the quantum process-based generator is encapsulated, in particular by means of metal layers and / or silicide layers and vias, from at least one side, better at least from two sides, better at least from three sides, better at least from four sides, better at least from five sides, except for signal feedthroughs through this encapsulation.

[0077] According to one aspect of the present invention, a device is provided comprising: a preferably one-piece, preferably monolithic, microintegrated circuit comprising one or more processors (10-1, 10-2) and one or more non-volatile memories, preferably storing at least one security code; a first, preferably writable / readable memory external to or within the integrated circuit, which stores data, the data preferably being cryptographically protected in a first format; and preferably a second writable / readable memory external to or within the integrated circuit for storing data; wherein the device is arranged to transfer data from the first memory to the second memory via a device of the integrated circuit so that the processor can access it from the second memory;The integrated circuit is arranged to validate the data read from the first memory during transmission using a security code stored in the non-volatile memory and, once the data is validated, to apply cryptographic protection in a second format to the validated data using a security code stored in the non-volatile memory and to store the data protected in the second format in the second memory. The proposed device uses a quantum technology-based micro-integrated random number generator (Q.RNG 28) for;

[0078] Encryption. Such a random number generator produces a truly random number because the process of random number generation is based on an unpredictable quantum process.

[0079] By transmitting data across the integrated circuit devices and using the integrated circuit devices to validate data and protect the transmitted data, security is maintained because the validation is performed and the protection is applied within the integrated circuit.

[0080] The data is secured by cryptographically protecting the data in the first and second memories based on one or more security codes in the non-volatile memory of the integrated circuit.

[0081] In one embodiment, only validated data from the first memory is processed, and when data is read by the processor from the second memory, only validated data from the second memory is processed.

[0082] In one embodiment, the second memory is a random access memory (RAM) for the processor, which allows the processor to store and retrieve individual words that are individually protected, in contrast to the first memory, which is a read-only memory (ROM) and which only allows read access to a data set.

[0083] The invention also provides a data processing device comprising:

[0084] An integrated circuit comprising a processor, a non-volatile memory storing at least one security code, a hash calculator, and an interface at the boundary of the integrated circuit; and a memory inside or outside the integrated circuit for storing data for use by the processor, wherein the memory, when outside the integrated circuit, is preferably coupled to the processor via an interface at the boundary of the integrated circuit for receiving data, for example in the form of data words, from the processor and supplying data words to the processor. The processor and the hash calculator are arranged to perform the steps of: a. calculating the hash by means of a hash function for each data word in dependence on a security code stored in the non-volatile memory and storing the hash in association with the data word; b.Retrieving stored data words from memory, recalculating a hash function for each retrieved data word using the security code, and comparing the newly calculated hash value with the stored hash value, and c. allowing the data processing system to process the retrieved data word only if the newly calculated hashes and the stored hashes have a predetermined relationship.

[0085] Embodiments of the proposal will now be described by way of example with reference to the accompanying drawings.

[0086] In particular, the true random number generator (quantum random number generator 28) according to the invention comprises a photon source 54 with a flux of detected photons of light 58 transported horizontally in an optical fiber 44, one or more photon detectors 55, preferably single photon detectors (SPADs), and electronic sampling means (403, 2022, 402, 403, 404.2) operatively connected to the one or more photon detectors 55 to generate a bit sequence of quantum random bits 411 (random bit sequence) based on the number of photons detected in the photon detectors 55.

[0087] The said generator for true random numbers, hereinafter referred to as quantum random number generator 28 (QRNG), is characterized in particular in that the photon source 54 and the photon detector(s) 55 are arranged as close to one another as possible and are optically directly or indirectly coupled and are integrated in a single semiconductor substrate 49. Preferably, the photon source 54 and the photon detector(s) 55 are manufactured in a common semiconductor substrate 49 using CMOS technology, preferably BCD technology. Preferably, the photon source 54 comprises a silicon LED and / or a silicon laser. For example, the photon source 54 can comprise a first SPAD diode 54. For example, the photon detector 55 can comprise a photodiode. For example, the photon detector 55 can comprise a second SPAD diode 55.

[0088] The quantum random number generator 28 according to the invention preferably comprises a photon source 54 with a detected photon flux equal to A

[0089] It cannot be ruled out that the quantum random number generator 28, in an alternative embodiment, comprises more than one photon source 54. However, this has the disadvantage of requiring a larger chip area.

[0090] According to the preferred embodiment of the proposal, the proposed

[0091] Quantum random number generator 28 preferably also comprises an arrangement of one or more

[0092] Photon detectors 55. Preferably, but not necessarily, each of these photon detectors 55 is a single-photon detector 55. When one or more photon detectors 55 are implemented as reverse-biased PN diodes in a semiconductor substrate 49 with a bias voltage close to the breakdown voltage of the PN diode in question and a limitation of the breakdown current of the PN diode in question, they are generally referred to as single-photon avalanche photo diodes, which the document presented here also refers to by the acronym SPAD.

[0093] As already mentioned, a single photon detector 55 is capable of detecting and providing as output information about the incidence of a single photon in its sensitive volume and possibly about the arrival time of the latter within an observation window of a predetermined duration.

[0094] Between two consecutive observation windows, each photon detector 55 (every second SPAD diode 55) undergoes a recovery phase, which this document hereinafter refers to as the dead time. During the dead time of a second SPAD diode 55, this second SPAD 55 can no longer reliably detect any subsequent photon.

[0095] Typically, in the SPAD-type photon detector array 54, each respective SPAD diode 55 operates independently and in parallel with the other SPAD diodes 55. Typically, the array of SPAD diodes 55 has a single common output for reading the respective signal generated externally by the same array of SPAD diodes 55.

[0096] The typical advantage of an arrangement of closely spaced SPAD diodes 55 is that the solid angle of the photons 58 generated by the photon source 55 is increased and that any dead times are reduced, thereby increasing the generation rate of the quantum random bits 411 of the quantum random number generator 28 and thus the rate of the quantum random data words 418 themselves. This, in turn, enables the encryption of larger amounts of data.

[0097] While the technical teaching of EP 3 529 694 B1 still assumes a coupling via the semiconductor substrate 49, the technical teaching presented here proposes a first improved coupling of the photon source, i.e., for example, the first SPAD diode 54 and / or the silicon LED, to the photon detector 55, i.e., here, for example, to the second SPAD diode 55, via a light-optical system, for example, an optical fiber 44, which should have a significantly lower absorption rate than the common semiconductor substrate 49 in which the photon source 54 and the photon detector 55 are fabricated. As a result, the generation rate of the quantum random bits 411 of the quantum random number generator 28 increases dramatically again compared to a device according to the technical teaching of EP 3 529 694 B1.

[0098] However, it cannot be ruled out that, according to an alternative embodiment of the proposal, the quantum random number generator 28 always comprises an array of second SPAD diodes 55 as an array of photon detectors 55, wherein each SPAD diode 55 or each photon detector 55 is independent of the others, which means that these device parts can each individually generate a respective signal to the outside, which is typically independent of the signals of the other SPAD diodes 55 or of the other photon detectors 55. According to another embodiment of the proposed quantum random number generator 28, the arrangement can be divided into subgroups of SPAD diodes 55 or subgroups of photon detectors 55, wherein each subgroup has a predetermined number of SPAD diodes 55 orPhoton detectors 55, which are preferably each connected in parallel such that they each generate a single signal outwardly relative to the entropy source 401 of the quantum random number generator 28.

[0099] In the latter case, each of the subgroups of SPAD diodes 55 or photon detectors 55 can be connected to the outside world of the entropy source 401 of the quantum random number generator 28 independently of the other subgroups of SPAD diodes or photon detectors.

[0100] This independence has the advantage that the extraction of the binary random sequences from quantum random bits 411 from the quantum random number generator 28 can be parallelized, whereby the bit rate of the quantum random number generator 28 is further increased by spatial multiplexing.

[0101] According to another embodiment, the quantum random number generator 28 of the proposal may also comprise only exactly one second SPAD diode 55 or only exactly one photon detector 55.

[0102] Again, a further embodiment of the quantum random number generator 28, as already mentioned, can comprise a plurality of photon sources 54 or silicon LEDs 54 or first SPAD diodes 54, respectively, which are each optically connected to an array of photon detectors 55 or second SPAD diodes 55 via an optical system (44) outside the semiconductor substrate 49. This optical system 44 preferably comprises micro-optical device parts. Preferably, these micro-optical device parts comprise one or more optical waveguides 44 and / or one or more reflective layers 53 and / or reflective and / or optically refractive structures 53. Preferably, the optical waveguide 44 is fabricated in the metallization stack on the semiconductor substrate 49 of the microelectronic circuit, which typically comprises the photon source or the silicon LED 54 or the first SPAD diode 54 and the photon detector 55 or the second SPAD diode 55.The optical system - for example the optical waveguide 44 - the photon sources 54 and the photon detectors 55 are therefore preferably part of the integral quantum random number generator 28.

[0103] In other words, if the combination of a photon source 55 or a silicon LED 54 or a SPAD diode 54 on the one hand with one or more photon detectors 55 or one or more SPAD diodes 55 on the other hand defines pixels within the meaning of the document presented here, one embodiment of the entropy source 401 of the proposed quantum random number generator 28 can be regarded, for example, as a pixel matrix which makes it possible to parallelize the process of extracting random numbers.

[0104] As for the photon source 54 or the silicon LED 54 or the first SPAD diode 54, according to a preferred embodiment, this also preferably comprises one or more SPAD diodes 54. In this case, both the arrangement of the photon detectors 54 or the second SPAD diodes 54, which serve as receivers, and the photon sources 54 or the silicon LEDs 54, which preferably comprise one or more SPAD diodes 54, are configured and polarized such that they operate in the so-called Geiger mode with the same polarization voltage.

[0105] As already mentioned above, the quantum random number generator 28 of the proposal preferably also comprises electronic sampling means (403, 2022, 402, 403, 404.2) which are preferably functionally connected to the common output 417 in order to read the signal 405 generated by the arrangement of the photon detectors 54 or the second SPAD diodes 54.

[0106] It is conceivable that, in another embodiment, one or more of the respective electronic sampling means (2022, 402, 403, 404.2) are provided for each respective photon detector 54 or each respective second SPAD diode 54 belonging to the array, respectively, while individual electronic sampling means of the electronic sampling means (2022, 402, 403, 404.2) are provided for the respective individual photon detector 54 or for the respective individual second SPAD diode 54. Finally, in one embodiment, one or more respective sampling means of the electronic sampling means (2022, 402, 403, 404.2) can be provided for each pixel, the sampling signals (407, 407) of which are combined into a common quantum random bit data stream 411 by means of electronic post-processing.

[0107] The document presented here proposes to use these electronic scanning means (403, 2022, 402, 403,

[0108] 404.2) together or at least in large parts with the photon sources 54 or silicon LEDs

[0109] 54 or first SPAD diodes 54 and together with the photon detectors 55 or the second SPAD diodes 55 in a common semiconductor substrate 49 as a one-piece microintegrated circuit. The document presented here proposes electrically connecting these electronic scanning means (403, 2022, 402, 403, 404.2) together with the photon sources 54 or silicon LEDs 54 or first SPAD diodes 54 and together with the photon detectors 55 or the second SPAD diodes 55 via the metallization stack of the thus manufactured one-piece microintegrated circuit on the surface of the semiconductor substrate 49 by means of metallic electrical conductors. The document presented here proposes to combine these photon sources 54 or silicon LEDs 54 or first SPAD diodes 54 and with the photon detectors 55 orto optically interconnect the second SPAD diodes 55 via the metallization stack of the thus-fabricated one-piece microintegrated circuit on the surface of the semiconductor substrate 49 by means of dielectric optical waveguides 44. The metallization stack of the thus-fabricated one-piece microintegrated circuit on the surface of the semiconductor substrate 49 typically comprises structured metal layers that form the electrical conductor tracks (141, 142), typically in different levels of the metallization stack.The metallization stack of the thus-fabricated one-piece microintegrated circuit on the surface of the semiconductor substrate 49 typically comprises electrical insulation layers between these structured metallization layers (141, 142), which electrically insulate the electrical lines (141, 142) formed in the structured metallization layers between different metallization levels. The electrical insulation layers of the metallization stack of the thus-fabricated one-piece microintegrated circuit on the surface of the semiconductor substrate typically comprise electrical vias 140 between the electrical lines (141, 142) of the structured metallization layers, which electrically connect (via-connect) the electrical lines (141, 142) formed in the structured metallization layers between these different metallization levels.The metallization stack of the thus manufactured one-piece microintegrated circuit on the surface of the semiconductor substrate 49 typically comprises optically transparent electrical insulation layers between these structured metallization layers. As a result, one or more electrical insulation layers can assume the function of an optical waveguide 44 for the photons from the first SPAD diode 54 or the photon source 54 or the silicon LED 54 during their transport to the second SPAD diode 55 or the photon detector 55. For this purpose, the insulation layers in question are preferably structured.

[0110] In any case, the electronic sampling means (403, 2022, 402, 403, 404.2) of such a one-piece microelectronic circuit are preferably configured to implement a predefined logical method or a computer- or hardware-implemented algorithm for extracting a binary sequence of quantum random bits 411 based on the arrival times of the photons at the level of the respective photon detectors 55 or SPAD diodes 55. Some preferred examples of the logical extraction method are described in detail below in the document presented here.

[0111] According to the proposal, in the quantum random number generator 28, the photon source 54 or the silicon LED 54 or the first SPAD diode 54 and the array of photon detectors 55 or of second SPAD diodes 55 or the individual SPAD detector 54 are arranged next to one another or one below the other and preferably close to one another with a short optical connection for optical coupling via the shortest possible optical path and integrated into a single semiconductor substrate 49 as a micro-electro-optical system.

[0112] This results in the photon current generated by the photon source 54 or the silicon LED 54 or the first SPAD diode 54 flowing, for example, through the optical waveguide 44 in the metallization stack of the microelectronic circuit towards the photon detectors 55 or second SPAD diodes 55, which are preferably arranged nearby (a phenomenon actually known as "optical crosstalk"), unlike in the known random number generators, in which the same photons flow through the empty coupling gap between the two components, which are physically separated from each other, i.e., are typically not manufactured integrally with the scanning means on a semiconductor substrate 49.

[0113] Advantageously, this integrated configuration makes the quantum random number generator 28 proposed in this document more compact and structurally less complex than the random number generators of the known type.

[0114] Thanks to the integral integration of all components of the quantum random number generator 28, it is also more robust and immune to external environmental influences and to any attempts at manipulation by malicious persons.

[0115] A metal cover 142 made of a preferably soft metallic and / or electrically highly conductive material, for example, a gold layer on an iron layer, can shield the entropy source. Preferably, an electrical connection, which may also include vias (e.g., 140), connects the metal cover 142 to a defined electrical potential, for example, a ground line or a supply voltage line.

[0116] This integrated configuration and thus the direct and / or indirect coupling between the photon source 54 or the silicon LED 54 or the first SPAD diode 54 on the one hand and the photon detector(s) 55 or the second SPAD diodes 55 on the other hand are advantageous compared to solutions that use, for example, discrete beam splitters, since they enable uniform illumination of the photon detectors 55 or the second SPAD diodes 55 without having to ensure that the beam splitter is always perfectly aligned.

[0117] According to the preferred embodiment of the invention, the photon source 54, or the silicon LED 54, or the first SPAD diode 54, and the array of photon detectors 55, or the second SPAD diodes 55, are manufactured on the semiconductor substrate 49 in the same manufacturing steps, so that the elements have the same chemical-physical structure with respect to the doping profiles. More specifically, as mentioned above, even the photon source 54, or the silicon LED 54, or the first SPAD diode 54, can be manufactured with the same chemical-physical structure as another photon detector 55, or another second SPAD diode 55. The photon source 54 or the silicon LED 54 or the first SPAD diode 54 is, in terms of design and implementation, completely identical to the photon detectors 55 or the second SPAD detectors 55 belonging to the array, in certain embodiments of the proposal, except for usual variations of components on a wafer.

[0118] This has the advantage that the manufacturing costs of the various components of the proposed quantum random number generator 28 can be drastically reduced, since it is possible to manufacture one or more photon sources 54 or silicon LEDs 54 or first SPAD diodes 54 and / or one or more photon detectors 55 or SPAD diodes 55 on the same semiconductor substrate 49 without having to change, or in particular increase, the number of manufacturing steps. Thus, the manufacturing costs remain approximately the same.

[0119] According to the preferred embodiments of the proposal, the semiconductor substrate 49 is a silicon substrate 49.

[0120] However, it cannot be ruled out that, in various embodiments of the invention, the semiconductor substrate 49 may be made of a semiconductor material other than silicon to increase the efficiency of the emitter-source coupling. In this context, the document presented here specifically mentions the use of direct semiconductors with a direct transition for the electrons without lattice collision for momentum change.

[0121] Regarding the arrangement of the photon detectors 55 or the second SPAD diodes 55, it is known that preferably each of them primarily comprises a favorably doped pn junction, so that the phenomenon known in technical terms as "avalanche formation" can occur when the same photon detector 55 or SPAD diode 55, which is favorably polarized, is subjected to the impact of a photon in its photon-sensitive volume. The photon source 54, or silicon LED 54, or first SPAD diode 54, is also defined by a suitably doped pn junction such that the detected photon flux is generated when the photon source 54, or silicon LED 54, or first SPAD diode 54, is suitably forward-biased or (better) reverse-biased.When a first SPAD diode 54 is reverse-biased, a pulsed dark current of the diode current, the so-called dark current, is produced, which is associated with a pulsed emission of photons that can be detected by the photon detector 54 or the second SPAD diode 55.

[0122] In particular, according to the preferred embodiment of the invention, the photon source 54, or silicon LED 54, or first SPAD diode 54, is configured to obtain an emission spectrum of the detected photon flux X that lies primarily between 800 nm and 1000 nm. Within this spectrum, the efficiency of each photon detector 55, or each second SPAD diode 55, can be considered not to be excessively high, being less than 10%. Therefore, it is estimated that to achieve a detection rate of, for example, approximately 500,000 counts / sec. a usable photon rate (photon flux that reaches the sensitive volume of the photon detector 55 or the second SPAD diode 55 or the photon detectors 55 or the second SPAD diodes 55 from the photon source 54 or silicon LED 54 or first SPAD diode 54) of more than 5,000,000 ph / sec. is required.

[0123] Returning to the fabrication of the quantum random number generator 28: The fact that the structures of the photon source 54, the silicon LED 54, and the first SPAD diode 54 both have a pn junction as their main feature confirms the advantage described above, i.e., the possibility of performing the same fabrication steps for the photon source 54, the silicon LED 54, and the first SPAD diode 54 and the photon detectors 55 and the second SPAD diodes 55, respectively.

[0124] Preferably, but not necessarily, according to the preferred embodiment of the invention, the photon source 54 or the silicon LED 54 or the first SPAD diode 54 and the photon detectors 55 or the second SPAD diodes 55, which are obtained through the same manufacturing steps, have the same chemical-physical structure. However, it cannot be ruled out that in different embodiments of the quantum random number generator 28 according to the invention, the photon source 54 or the silicon LED 54 or the first SPAD diode 54 and the photon detectors 55 or the second SPAD diodes 55 can be manufactured with different chemical-physical structures, in particular with different sizes and / or different doping levels, even if they are obtained through the same manufacturing steps.As for the technology for integrating these components into the semiconductor substrate 49, according to the preferred embodiment of the invention, this involves CMOS or CMOS-compatible microfabrication technology for microintegrated circuits. So-called BCD technologies are also particularly preferred for the production of the proposed one-piece microelectronic circuit of the quantum random number generator 28.

[0125] BCT technologies are key technologies for integrated power circuits. BCD technology is characterized by the combination of bipolar electronic components (e.g., bipolar transistors and / or PN diodes) with CMOS components (e.g., CMOS transistors or CCD arrays) with DMOS components (e.g., a DMOS transistor).

[0126] The DMOS transistor typically comprises a double-diffused structure, with the p-type region and the n-type region serving as lines. It is a type of DMOS power transistor developed for radio-frequency (RF) applications. It can operate with relatively high supply voltages of 50 to 100 V and is characterized by high reliability, peak performance, and robustness. A DMOS transistor (double-diffused metal-oxide-semiconductor transistor) is a crucial element in integrated microelectronic circuits. Unlike conventional CMOS transistors, a DMOS transistor is characterized by specific features that define its function and areas of application.

[0127] A DMOS transistor has a special structure. In this structure, doping regions with different electrical charge carrier concentrations are present in the semiconductor material. These doping regions enable the DMOS transistor to switch higher power levels and offer a lower on-state resistance compared to CMOS transistors. These properties are particularly advantageous in high-performance applications. In this case, DMOS transistors are suitable for use in the voltage converters 91 of the monolithic integrated circuit. At the same time, BCD technologies enable the compact production of the first SPAD diodes for the photon sources 54 and the second SPAD diodes 55 for the photon detectors 55.Since the first SPAD diodes 54 typically require a higher supply voltage when used as photon sources 54, the voltage converters 91 very often comprise a charge pump or the like to supply the first SPAD diodes 54 with the required high supply voltage. The aforementioned DMOS transistors are particularly suitable for these charge pumps in the voltage converters 91 of the one-piece micro-integrated circuit of the quantum random number generator 28. Therefore, co-integration of the entropy source 401 with at least one DMOS transistor or several DMOS transistors on a common semiconductor substrate 49 is particularly advantageous. Therefore, a voltage converter 91 of a one-piece microelectronic integrated circuit of a quantum random number generator 28 preferably comprises at least one, preferably several, DMOS transistors.Preferably, the DMOS transistors of a respective voltage converter 91 of a one-piece microelectronic integrated circuit of a quantum random number generator 28 are located in a half-bridge or an H-bridge circuit within this voltage converter 91. In the case of a half-bridge, an energy storage device, for example a capacitor, is preferably connected by one terminal to the output node of this half-bridge and can then be recharged thereby. In the case of an H-bridge, an energy storage device, for example a capacitor, is preferably connected by a first terminal to the output node of the first half-bridge of the H-bridge and by a second terminal to the output node of the second half-bridge of the H-bridge and can then be recharged thereby.Such a voltage converter 91 preferably comprises an electronically controlled transfer switch which, after switching up the voltage at one terminal of the capacitor, can connect the other terminal to a photon source 54 or a silicon LED 54 or a first SPAD diode 54. This step-up technology for the supply voltage can also be multi-stage in order to achieve larger voltage swings. A further voltage converter 91 and an energy storage device, for example a further capacitor, can be connected downstream and upstream of the entropy source 401 or the photon source 54 or the silicon LED 54 or the first SPAD diode 54 in order to stabilize the supply voltage of the photon source 54 or the silicon LED 54 or the first SPAD diode 54.Preferably, the half-bridge and / or the H-bridge and / or the transfer switches of the voltage converter 91 comprise DMOS transistors in order to be able to provide higher supply voltages and thus increase the quantum random bit data rate of the quantum random bits 411, since the increase in the supply voltage leads to an increase in the pulse density of the entropy source.

[0128] Another distinguishing feature of a DMOS transistor is its ability to handle higher voltages, making it ideal for applications with high voltage ranges. This aspect distinguishes it from CMOS transistors, which are typically designed for lower voltages.

[0129] The term "BCD technology" stands for bipolar CMOS-DMOS technology. BCD technology is a family of silicon processes that each combine the strengths of three different process technologies on a single chip, thus enabling compact, one-piece quantum random number generators in the form of a single microintegrated circuit 2. The advantage of CMOS microfabrication technology, or more precisely BCD microfabrication technology, is that it is possible to integrate the sampling means (403, 2022, 402, 403, 404.2) for the output signals of the array of photon detectors 55 or the second SPAD diodes 55 into the semiconductor substrate 49.

[0130] An example of a possible quantum random number generator 28 of the proposal, obtained using the BCD microfabrication technique, preferably uses a p-type 100 doped substrate / epitaxial structure. The manufacturing process typically creates a deep n-well in the p-type 100 doped substrate / epitaxial structure, and the connections defining the photon source 54, the silicon LED 54, and the first SPAD diode 54 are made with a p+ type 102 implant. To avoid electric fields that are higher at the edges of the sensitive area than in its center, "guard ring" structures are preferably provided, forming a p-well ring around the p+ implant 47.

[0131] However, it cannot be ruled out that, in various embodiments of the invention, the technology used to manufacture the photon source 54, the silicon LED, or the first SPAD diode 54, may be a custom-made technology. The advantage of this latter solution is that the manufacturing steps of the quantum random number generator 28 according to the invention can be optimized to obtain the photon source 55 and / or the silicon LED 55, or the second SPAD diode 55.

[0132] According to an example of implementing a quantum random number generator 28 using a custom manufacturing technique, the photon detectors 55 or the second SPAD diodes 55 and the photon source 54 or the silicon LED 54 or the first SPAD diode 54 can be integrated into a doped p-type epitaxial structure / substrate, wherein a so-called "flat" implant and an enhancement implant are defined in the epitaxial structure, wherein the "flat" implant is more superficial, of the n+ type, and concentric with the epitaxial structure, but has a smaller extension, and the enhancement implant is of the p- type and has a lower doping, but in any case a higher doping than that of the epitaxial structure.

[0133] In this way, a so-called "virtual guard ring" structure is created. To avoid problems related to "charge crosstalk" or "charge injection" caused by the shared epitaxial structure of the two implants, it is possible to either separate the photon source 55, or the silicon LED 55, or the SPAD diodes 55, and the photon detector(s) 54, or silicon LED 54, or first SPAD diode 54 by arranging them at appropriate distances, or to create deep trenches surrounding both the region of the photon source 54, or silicon LED 54, or first SPAD diode 54, and the region of the photon detector(s) 55, or second SPAD 55. Finally, it is possible to create an auxiliary connection which, with a suitable bias voltage, absorbs the excess charge generated by the photon source 54 or the silicon LED 54 orThe first SPAD diode 54 can be transferred to the photon detector(s) 55 or the second SPAD diode(s) 55. The creation of trenches would also reduce optical crosstalk, which is again a desirable property. However, this reduction does not exceed a percentage in the range of 30-50%, so it is acceptable if it has the advantage of completely eliminating the problem.

[0134] As already explained above, the proposed quantum random number generator 28 is configured such that the photon source 54 or the silicon LED 54 or the first SPAD diode 54 can be biased selectively in the forward direction or in the reverse direction to generate the detected photon flux.

[0135] In the case of reverse bias, photoluminescence is used in the avalanche formation in the photon source 54, here the silicon LED 54 or the first SPAD diode 54, which occurs in a controlled manner but at quantum-mechanically random time intervals.

[0136] At a forward bias, the photons generated behave very similarly to a reverse bias, and the generation efficiency (photons per passed electric charge) is relatively similar or higher, but at a forward bias, the power dissipation can be reduced compared to a reverse bias because a lower voltage is applied.

[0137] To give an order of magnitude, a forward-facing photon source 54 or silicon LED 54 or first SPAD diode 54 requires a voltage of several volts, while a backward-facing photon source requires a voltage of several tens of volts. During the development of the technical teaching of this document, it was recognized that the use of DMOS transistors is particularly advantageous for the co-integrability of preferably all relevant electronic components of a quantum random number generator 28. Such DMOS transistors enable the provision of a voltage of several tens of volts to operate the backward-facing photon sources 54, i.e., in this case, the reverse-biased silicon LEDs 54 orfirst SPAD diodes 54, by a voltage converter 91, which, within the meaning of the document presented here, can comprise any form of suitable voltage converter 91 and which is preferably located in the semiconductor substrate 49 of the one-piece microelectronic integrated circuit of the quantum random number generator 28 presented here. In developing the technical teaching of this document, it was thus recognized that, for the co-integrability of these DMOS transistors with the other relevant electronic components of the quantum random number generator 28 presented here, the use of a BCD semiconductor technology for the production of the quantum random number generator 28 presented here is particularly advantageous.The document presented here thus proposes a quantum random number generator 28 which may comprise a voltage converter 91 with one or more DMOS transistors and an entropy source 401 with one or more photon sources 54 and / or silicon LEDs 54 and / or first SPAD diodes 54 and one or more photon detectors 55 and / or second SPAD diodes 55 and preferably one or more processors (10-1, 10-2) and / or one or more data bus interfaces 64 and / or one or more volatile and / or non-volatile memories (30, 6, 16, 8) and / or a test interface 12.

[0138] A forward-biased photon source 54 or silicon LED 54 or first SPAD diode 54 in a device variant would therefore advantageously make it possible to also reduce the space required to electrically isolate the photon source 54 or silicon LED 54 or first SPAD diode 54 itself from the arrangement of photon detectors 55 or second SPAD diodes 54. As a result, the forward-biased photon source 54 or silicon LED 54 or first SPAD diode 54 advantageously enables a more compact design of the quantum random number generator 28 and lower costs due to the smaller amount of semiconductor material used to manufacture the generator itself. However, since the structure and manufacturing technology of the photon source 54 or silicon LED 54 or first SPAD diode 54 and the photon detectors 55 orsecond SPAD diodes 55 are similar or even identical, the advantage of reverse bias is that the same voltage can be used to bias both components.

[0139] This last device variant, in particular, makes it possible to reduce the complexity and overall dimensions of both the structure and the potentially still required external circuitry: the photon source 54, or silicon LED 54, or first SPAD diode 54, and the photon detectors 55, or second SPAD diodes 55, can share the same semiconductor substrate 49 because they have a common terminal. This allows them to be arranged close to each other (on top of each other and / or side by side) in the semiconductor substrate 49, reducing the space occupied while simultaneously improving their optical coupling. In any case, the low efficiency of the photoluminescence process in generating a few photons argues for "quantum detection," since the photon detector(s) 55, or second SPAD diode(s) 55, is / are, by definition, sensitive to a single photon.

[0140] As already mentioned, in the preferred embodiment of the proposal, the electronic scanning means (403, 2022, 402, 403, 404.2) together with the photon source 54 or silicon LED 54 or first SPAD diode 54 and the arrangement of photon detectors 55 or second SPAD diodes 55 are also integrally integrated into the semiconductor substrate 49.

[0141] In this case, the electronic scanning means (403, 2022, 402, 403, 404.2) can be configured not only to read the signal(s) 405 generated by the array of photon detectors 55 or second SPAD diodes 55, but also to directly and simply control the operating conditions of one or more photon sources 54 or one or more silicon LEDs 54 or one or more first SPAD diodes 54, and to correct any bias parameters by changing the parameters of one of said voltage converters 91 for supplying energy to one or more photon sources 54 or one or more silicon LEDs 54 or one or more first SPAD diodes 54, or to activate or deactivate one or more photon sources 54 or one or more silicon LEDs 54 or one or more first SPAD diodes 54, in order to achieve the desired photon flux or the desired Random bit rate of the quantum random bits 411.

[0142] In this case, the electronic sampling means (403, 2022, 402, 403, 404.2) can be configured to directly and simply control the operating conditions of one or more photon detectors 55 or one or more second SPAD diodes 54, respectively, and to correct any bias parameters by changing the parameters of one of said voltage converters 91 for supplying energy to one or more photon detectors 55 or one or more second SPAD diodes 55, respectively, or to activate or deactivate one or more photon detectors 55 or one or more second SPAD diodes 55, respectively, in order to obtain the desired receivable portion of the photon flux or the desired random bit rate of the quantum random bits 411.

[0143] According to a preferred embodiment of the proposal of the document presented here, the quantum random number generator 28 is preferably provided with a light protection filter or a cover, for example a metal layer (53, 142), at the level of the top side of the semiconductor substrate 49. In particular, preferably, but not necessarily, the light protection filter comprises a metallization layer (53, 142), which can be produced directly during the production process, for example, by the process steps of a BCD technology, for example, as the last metallization level. This metal layer (53, 142) does not necessarily have to be produced last. It is typically sufficient if the relevant device parts of the entropy source 401 are covered.Preferably, further device parts of the one-piece, micro-integrated circuit of the quantum random number generator 28 are covered with this metal cover (53, 142), so that it also protects these circuit parts from manipulation by means of electromagnetic radiation and / or thermal, local stress and / or by means of magnetic fields and / or other interventions by influencing physical parameters of such other circuit parts of the quantum random number generator 28. This protection should preferably in particular protect the memories (e.g. 404.9, 30, 6, 8, 16, 22, 20) and / or the processor (10-1, 10-2) and / or the monitoring devices - such as watchdog 404.5, ADC 403, voltage monitor 413, - amplifier 402, finite state machine 404.8 This solution has the function of protecting the photon detector(s) 55 or second SPAD diodes 55 or.to shield the other circuit components of the quantum random number generator 28 from external light and other physical interference signals. This solution thus also has the function of making the photon detector(s) 55 or second SPAD diode(s) 55 sensitive only to the photons that, due to crosstalk, pass from the photon source 54 or silicon LED 54 or first SPAD diode 54 through the semiconductor substrate 49 to the photon detectors 55 or second SPAD diodes 55. In addition, the metallization layer (53, 142) also has the function of improving the coupling of the photons emitted by the semiconductor substrate 49, in particular the silicon substrate. For this purpose, the metallization layer 53 reflects the photons emitted by the same photon source 54 or silicon LED 54 orThe electromagnetic radiation generated by the first SPAD diode 54, after exiting the semiconductor material of the semiconductor substrate 49, returns to the insulation layers of the metallization stack on the semiconductor substrate 49, so that these photons cannot leave the micro-optical system of the one-piece microelectronic circuit of the quantum random number generator 28. This increases the number of photons reaching the photon detector(s) 55 or the second SPAD diode(s) 55. This, in turn, increases the random bit data rate of the quantum random bits 411 of the quantum random number generator 28. This thus strengthens the optical coupling between the photon source 54 or silicon LED 54 or first SPAD diode 54, on the one hand, and the array of photon detectors 55 or second SPAD diodes 55, on the other hand.

[0144] Furthermore, the metal cover 53 of the optical waveguide 44 in the metallization stack of the microelectronic circuit on the semiconductor substrate 49 advantageously also serves to protect the quantum random number generator 28 from any attempts by malicious persons to tamper with the functionality of the system of the proposed device. Consequently, the presence of the metallization in the form of a metal cover (53, 143) makes it possible to ensure greater security and reliability of the random numbers generated by the quantum random number generator 28 according to the invention.

[0145] Finally, the proposed quantum random number generator 28 may optionally also comprise electronic post-processing means (404.3, 404.4, 404.8) configured to receive as input the binary sequences extracted by the electronic sampling means (403, 4022, 402, 403, 404.2), which in turn are connected to the array of photon detectors 55 and second SPAD diodes 55, respectively.

[0146] Said electronic post-processing means (404.3, 404.4, 404.8) are preferably configured to process said binary sequences 409, 415 in such a way that a so-called "whitening" operation is performed. This last term refers to a plurality of compression operations that serve to improve the statistical properties of the generated binary sequences (415, 409). Consequently, it is advantageous that this further post-processing step makes it possible to increase the entropy level of the proposed quantum random number generator 28.

[0147] As already mentioned above, the sampling means (403, 2022, 402, 403, 404.2), which according to the preferred embodiment are directly or indirectly connected to the array of photon detectors 55 or second SPAD diodes 55 or alternatively to a subset of the photon detectors 55 or second SPAD diodes 55 or even to a single pixel, are configured to implement a logical extraction method designed to extract a binary sequence of random bits (409, 415) based on the number of photons detected in the array of photon detectors 55 or second SPAD diodes 55, in the subset, in the single photon detector 55 or in the single second SPAD diode 55 or even in the single pixel. According to the proposal, a first logical extraction method, which is carried out by the sampling means (2022, 402, 403, 404.2) of the proposed quantum random number generator 28, the subdivision of the observation window of each photon detector 55 or each second SPAD diode 55 into a plurality of successive observation subwindows Tw, typically of the same duration. If the entropy extraction generates a pulse on its output line 405, a synchronization stage (403, 2022) synchronizes the pulse with the system clock 2106 of the quantum random number generator 28. An observation subwindow Tw typically corresponds to the temporal period of the system clock 2106. According to the methods commonly used in the prior art, the post-processing means would typically have to determine the arrival times of the photons at the photon detectors 55 or the second SPAD diodes 55, respectively, relative to a reference time, as a digital numerical value using a time counter.However, this has the disadvantage that an attacker could potentially manipulate this time point via a so-called side channel, without any specification as to how this might be done. For the purposes of the document presented here, it is assumed that the attacker succeeds in carrying out this manipulation through an unknown means. The attacker would then be able to manipulate the supposed "random bits," giving them a deterministic character that would potentially allow the breaking of encryption and / or locks. The proposal presented here prevents this.

[0148] The one-piece, integrated microelectronic circuit of the quantum random number generator 28 typically generates these successive observation subwindows Tw starting from the system clock 2106. An observation window Tw within the meaning of the document presented here can, for example, begin with a first edge of the system clock 2106 in a first edge direction, which can be rising or falling, and end with the next directly following edge of the system clock 2106 with the same edge direction (rising or falling). The duty cycle of this system clock 2106 typically defines the time during which the photon detector 55 or the second SPAD diode 55 is at the dead time level (system clock 2106 = H [= high level]).

[0149] The special feature of the method proposed here for entropy extraction at the level of each sub-window Tw is the generation of a first pseudorandom number which corresponds to the arrival time of a second photon from the photon source 54 or the silicon LED 54 or the first SPAD diode 54 at a photon detector 55 or a second SPAD diode 55, respectively, relative to the arrival time of a preferably immediately preceding first photon from the photon source 54 or the silicon LED 54 or the first SPAD diode 54 at a photon detector 55 or a second SPAD diode 55. The device proposed here of the one-piece integrated microelectronic circuit of the proposed quantum random number generator 28 generates this first pseudorandom number by means of a time-to-random number converter (Time to Pseudo-Random-Number Converter, TPRC). Such a time-to-pseudo-random-number converter (TPRC) can also be composed of several stages.For example, the time-to-pseudo-random number converter (TPRC, 404.3) may comprise an analog instrument, a time-to-analog converter (TAC), which would then be followed by an analog-to-pseudo-random number converter (APRC) in the data path to again result in a time-to-pseudo-random number converter (TPRC, 404.3). The diagram shown in Figure 22 represents the detection of the pulses (2201, 2202, 2203, 2204) on the voltage signal 405 of the entropy source 401. The entropy source 401 preferably comprises the one or more photon sources 54, the one or more silicon LEDs 54, or the one or more SPAD diodes 54, and the light transmission path 44 between them. The entropy source 401 is preferably manufactured in or on the semiconductor substrate 49 and is thus preferably part of the microintegrated circuit of the quantum random number generator 28.The output signal 405 of the entropy source 401 is typically the aforementioned voltage signal 405 of the entropy source 401. The voltage signal 405 of the entropy source 401 is preferably the signal of one or more photon detectors 55 or one or more second SPAD diodes 55 of the entropy source 401.

[0150] The voltage signal 405 shows exemplary pulses 2201, 2202, 2203, 2104 for random events of the voltage signal 405. These can be spontaneous voltage pulses of the photon detector 55 or the second SPAD diode 55 of the entropy source 401, which are not related to the activity of the photon source 54 or the silicon LED 54 or the first SPAD diode 54 of the entropy source 401. However, the pulses 2201, 2202, 2203, 2204 of the photon detector 55 or the second SPAD diode 55 of the entropy source 401 can also be based on stimulated emission, which causes the detection of a photon of the one or more photon sources 54 or the one or more silicon LEDs 54 or the one or more SPAD diodes 54 by the photon detector 55 or by the second SPAD diode 55 of the entropy source 401.

[0151] The time interval is random. However, after the photon detector 55 or the second SPAD diode 55 of the entropy source 401 receives a photon, a dead time occurs during which the photon detector 55 or the second SPAD diode 55 of the entropy source 401 is no longer capable of receiving. If the magnitude of the voltage signal 405 of the entropy source 401 exceeds a threshold value 2105, an analog-to-digital converter (ADC, 403), here an exemplary one-bit analog-to-digital converter 403, generates

[0152] Pulse extension circuit, which is preferably part of the integral microelectronic circuit, on a synchronized voltage signal 415 a pulse with a minimum length of n clock cycles of a system clock 2106 of the quantum random number generator 28, which is preferably one of the system clock cycles of the integral microintegrated circuit.

[0153] In the example shown in Figure 21, this pulse extension circuit is designed to reach a first logic level for at least three subsequent clock pulses and then fall back to the second logic level until the next event, here, for example, with the falling edge of the third clock pulse. Instead of three clock pulses, a to n clock pulses can be used, where a is a positive integer.

[0154] In the example of Figure 21, the falling edges of the pulses 2211, 2212, 2213, 2214 of the synchronized voltage signal 415 represent the synchronized signals of the entropy source 401.

[0155] With a falling edge of a first pulse 2211 of the synchronized voltage signal 415, the time-to-pseudorandom number converter (TPRC) resets a pseudorandom number generator, for example, to a predefined seed value. For example, the pseudorandom number generator of the time-to-pseudorandom number converter (TPRC) can be a feedback shift register that shifts its values ​​one place to the left or right, depending on the design, with each clock pulse of the system clock 2106 and feeds the feedback value of the feedback polynomial back into the released bit.

[0156] It is important that, starting with the starting value of the pseudorandom number generator (seed value), each clock pulse of the system clock 2106 is bijectively assigned exactly one pseudorandom number from the pseudorandom number generator starting from the falling edge. This means that the value of the pseudorandom number must be able to determine the temporal position of the respective clock pulse of the system clock 2106 after the falling edge of the synchronized voltage signal 415.

[0157] With the next falling edge of the second pulse 2212 synchronized voltage signal 415, a first pseudorandom number register takes over the last state of the pseudorandom number generator and the time-to-pseudorandom number converter (TPRC) preferably resets the pseudorandom number generator to the predefined seed value.

[0158] With the next falling edge of the third pulse 2213 synchronized voltage signal 415, a second pseudorandom number register takes over the last state of the pseudorandom number generator, and the time-to-pseudorandom number converter (TPRC) preferably resets the pseudorandom number generator to the predefined seed value. The entropy extraction 401 compares the value in the first pseudorandom number register with the value in the second pseudorandom number register. If the first value in the first pseudorandom number register is greater than the second value in the second pseudorandom number register, the entropy extraction 404.4 can, for example, generate a quantum random bit 411 with a first logical level. If the second value in the first pseudorandom number register is greater than the second value in the second pseudorandom number register, the entropy extraction 404.4 can, for example,4 generate a quantum random bit 411 with a second logic level that is different from the first level. With the next falling edge of the fourth pulse 2214 of the synchronized voltage signal 415, the first pseudorandom number register takes over the previous value of a second pseudorandom number register, and the second pseudorandom number register instead takes over the last state of the pseudorandom number generator, and the time-to-pseudorandom number converter (TPRC) preferably resets the pseudorandom number generator to the predefined seed value. The entropy extraction 401 then compares the value in the first pseudorandom number register with the value in the second pseudorandom number register. If the first value in the first pseudorandom number register is greater than the second value in the second pseudorandom number register, the entropy extraction 404 can, for example,4 generate another new, and in this case second, quantum random bit 411 with a first logic level. If the second value in the first pseudorandom number register is greater than the second value in the second.

[0159] Pseudorandom number registers, for example, the entropy extraction 404.4 can generate another new and here second quantum random bit 411 with a second logic level that is different from the first level.

[0160] In this way, the quantum random number generator 28 can continue this process of quantum random bit generation and thus generate a continuous stream of quantum random bits 411, albeit with phase noise.

[0161] The key idea here is to use a pseudorandom number generator, which generates the first and second values, instead of a digital counter as in the prior art. The advantage is that even if a disturbance is successfully introduced into the synchronized voltage signal 415, the randomness of the quantum random bit 411 is only marginally disturbed, since the attacker would also have to know the feedback polynomial.

[0162] To prevent this, it is useful if, for example, the quantum random number generator 28 changes the feedback polynomial of the linearly feedback shift register of the pseudorandom number generator of the time-to-pseudorandom number converter 404.3 (TPRC) after the complete determination of a number m of random quantum bits 411 as a function of one or more previously determined random quantum bits 411.

[0163] To prevent this, it is also useful if, for example, the quantum random number generator 28 changes the shift register length n of the linearly feedback shift register of the pseudorandom number generator of the time-to-pseudorandom number converter 404.3 (TPRC) after the complete determination of a number k of quantum random bits 411 depending on one or more previously determined quantum random bits 411. For this purpose, it is useful if the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or a processor (10-1, 10-2) rewrites the value of the feedback polynomial selection register 2112 for this purpose. The value stored in the feedback polynomial selection register 2112 preferably controls the feedback multiplexer 2102 of the time-to-pseudorandom number converter 404.3 (TPRC). Thus, the value stored in the feedback polynomial selection register 2112 preferably selects which of the m feedback polynomial circuits RKNi to RKNmdetermines the logical value of the shift register reload value line 2104 of the time-to-pseudorandom number converter 404.3 (TPRC). Preferably, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or one of the processors (10-1, 10-2) or another device prevents the forwarding of a generated quantum random bit 411 by the finite state machine (finite automaton) 404.8 by means of a line 2022 for preventing the use of a quantum random bit 411 by the finite state machine (finite automaton) 404.8 when this quantum random bit 411 is used for the feedback polynomial selection register 2112. This prevents double use and thus increases security. Instead, preferably use the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) or the processor (10-1, 10-2) or the other device uses this quantum random bit 411 to generate a random data word for storage in the feedback polynomial selection register 2112. This has the advantage that the feedback polynomial selected by the feedback polynomial selection register 2112 is one of the m feedback polynomial circuits RKNi to RKN. m is completely random. This makes it impossible for an attacker to feed a deterministic bit data stream instead of the data bit stream of quantum random bits 411, even if an attack on the entropy source 401 is successful.

[0164] In order to further harden the proposed micro-integrated quantum random number generator 28, it is also useful if, for example, the quantum random number generator 28 changes the starting value (seed value) of the linear feedback shift register of the pseudorandom number generator of the time-to-pseudorandom number converter 404.3 (TPRC) after the complete determination of a number p of random quantum bits 411 depending on one or more previously determined quantum random bits 411. For this purpose, it is useful for the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or a processor (10-1, 10-2) to rewrite the value of a seed reload register in the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) with quantum random bits 411. The bit width of a seed reload register in the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) preferably corresponds to the number n of shift register bits SBi to SB. n of the time-to-pseudorandom number converter 404.3 (TPRC). The shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) preferably counts the number of successfully generated quantum random bits 411. For this purpose, the finite-state machine 404.8 preferably signals the generation of a valid quantum random bit 411 to the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC). Instead of counting the valid quantum random bits 411, the finite-state machine 404.8 can also count the successfully generated random data words 418. The shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) preferentially loads the new seed value of a seed reload register in the shift register controller 2103 into the shift register bits SBi to SB on one or more of the following events nthe Time-to-Pseudo-Random Number Converter 404.3 (TPRC)

[0165] • upon reaching a predetermined number of successfully generated quantum random bits 411 and / or

[0166] • upon reaching a predetermined number of successfully generated random data words 418 and / or

[0167] • when changing the value of the feedback polynomial selection register 2112 of the time-to-pseudorandom number converter 404.3 (TPRC) and thus the selected feedback polynomial of the m feedback polynomials RKNi to RKN m the Time-to-Pseudo-Random Number Converter 404.3 (TPRC).

[0168] This reliably prevents any kind of predictability.

[0169] Preferably, the circuit components of the quantum random number generator 28 are covered with a metal layer 142, 53 to protect against any influences caused by temperature, electromagnetic radiation, electrostatic fields, or magnetic fields. Preferably, the metal layer also includes a soft magnetic layer to protect against attempted attacks using magnetic fields.

[0170] Preferably, by means of a line 2022 for preventing the use of a quantum random bit 411 by the finite state machine (finite automaton) 404.8, the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) or one of the processors (10-1, 10-2) or another device prevents the forwarding of a generated quantum random bit 411 by the finite state machine (finite automaton) 404.8 if this quantum random bit 411 is used for the seed reload register in the shift register controller 2103 in the time-to-pseudo-random number converter 404.3 (TPRC). This prevents double use and thus increases security. Instead, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or the processor (10-1, 10-2) or the other device preferably uses this quantum random bit 411 to generate a random data word for

[0171] Storage in the seed reload register in the shift register controller 2103. This has the advantage that the seed value of the linear feedback shift register of the n shift register bits SBi to SB selected by the seed reload register in the shift register controller 2103 nis completely random. Since a linear feedback shift register has two cycles when using simple primitive feedback polynomials, one of which contains only one shift register value, this single-cycle shift register value must be prevented. If the random reload value of the seed reload register in the shift register controller 2103 corresponds to the single-cycle seed value of the linear feedback shift register with the current feedback polynomial or the next intended feedback polynomial, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or one of the processors (10-1, 10-2) or another device generates a new random reload value in the seed reload register of the shift register controller 2103.

[0172] The m feedback polynomials RKNi to RKN are preferred mselected so that the one-cycle seed values ​​are equal. This reduces the effort for detecting the one-cycle shift register value, since it is then no longer dependent on the selected feedback polynomial of the feedback polynomials RKNi to RKN m In any case, it is recommended that the time-to-pseudorandom number converter 404.3 (TPRC) in the case of using linear feedback shift registers has a detection circuit 2113 for detecting an illegal value of the state vector of the n shift register bits SBi to SB n If the state vector of the n shift register bits SBi to SB nin such an illegal state, the detector 2113 preferably signals this illegal state to the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or one of the processors (10-1, 10-2) or another device. The detector 2113 or the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) or the processor (10-1, 10-2) or the other device then sets the value of the state value of the state vector of the n shift register bits SBi to SB nto a predetermined value and / or the value of the seed reload register in the shift register controller 2103. These reload values ​​are preferably different from the one-cycle shift register value. This preferably also occurs when the watchdog 404.5 and / or the voltage monitor 413 detect a disturbance or a suspected or possible attack. The shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) preferably counts the number of these disturbances. The shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) preferably reduces this counter value again depending on the number of random quantum bits 411 and / or random data words 418 successfully generated, in particular since the last disturbance.If this number and / or the event density of such events exceeds a certain predetermined temporal density and / or a certain numerical value, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) signals, preferably to the watchdog 404.5 and / or a processor (10-1, 10-2), a defect in the quantum random number generator 28 or a successful attack on the quantum random number generator 28. Typically, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) then signals to the finite state machine 404.8 that no more random numbers may be generated. Preferably, a processor (10-1, 10-2) must then reactivate the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) by means of a predetermined reactivation code word.The processor (10-1, 10-2) then writes this reactivation code word via the internal data bus 419 of the quantum random number generator 28 into a special reactivation register of the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC), which reactivates the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) and the quantum random number generator 28 and preferably resets all error counters. Preferably, the number of possible reactivations is limited. If the maximum number of reactivations is exceeded, the quantum random number generator 28 can preferably no longer be reactivated. Preferably, the counter for the reactivations of the quantum random number generator 28 can be reset using a special reset command before this maximum value is reached. Preferably, the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) of the quantum random number generator 28 or another device of the quantum random number generator 28 issues a warning before reaching this blocking limit.

[0173] When the quantum random number generator 28 is started, the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) first ensures that the shift register controller 2103 of the time-to-pseudo-random number converter 404.3 (TPRC) first determines a new seed value based on quantum random numbers 411 and a new value of the feedback polynomial selection register 2112 based on quantum random numbers from quantum random bits 411 using a predetermined seed value and a predetermined value of the feedback polynomial selection register 2112. Only when the seed value and the value of the feedback polynomial selection register 2112 are based on quantum random numbers is the initialization phase of the quantum random number generator 28 completed and the shift register controller 2103 of the time-to-pseudorandom number converter 404.3 (TPRC) signals the finite state machine 404.8, that it may use and forward the quantum random bits 411 and the quantum random data words 418 (quantum random numbers). Preferably, the finite state machine 404.8 signals this fact to one or more processors (10-1, 10-2). This has the advantage that the device only generates quantum random numbers 418 generated with full protection. By using a time-to-pseudorandom number generator 404.3 (TPRC), it is no longer possible for an attacker to feed a deterministic bit data stream instead of the data bit stream of the quantum random bits 411, even if an attack on the entropy source 401 is actually successful for whatever reason.

[0174] To prevent this, it is also useful if, for example, the quantum random number generator 28 changes this number m after the complete determination of a number m of quantum random bits 411 depending on one or more previously determined quantum random bits 411.

[0175] Preferably, the finite state machine 404.8 of the quantum random number generator 28 does not output these already used quantum random bits 411 and does not use them for generating quantum random data words 418.

[0176] The logic extraction method also includes three borderline cases, which are described below.

[0177] Typically, the time-to-pseudorandom number generator 404.3 (TPRC) uses the logical value of the shift register reload value line 2104 of the time-to-pseudorandom number converter 404.3 (TPRC) as the value of the output 410 of the time-to-pseudorandom number converter 404.3 (TPRC). A buffer amplifier may optionally be provided that detects the logical value of the shift register reload value line 2104 of the time-to-pseudorandom number converter 404.3 (TPRC) and outputs it as the value of the output 410 of the time-to-pseudorandom number converter 404.3 (TPRC).

[0178] The entropy extraction 404.4 now compares two different pseudorandom numbers generated by the time-to-pseudorandom number converter 404.3 (TPRC) from the output 410 of the time-to-pseudorandom number converter 404.3, a first pseudorandom number 410.1 and a second pseudorandom number 410.2.

[0179] If the first pseudorandom number 410.1 and the second pseudorandom number 410.2 are equal, the entropy extraction 404.4 discards one of the two pseudorandom numbers, the first pseudorandom number 410.1 or the second quantum random number 410.2, and replaces it with a new pseudorandom number 410.3 from the time-to-pseudorandom number converter 404.3 (TPRC). Preferably, the entropy extraction 404.4 uses a counter to count the events in which the two pseudorandom numbers, the first pseudorandom number 410.1 and the second pseudorandom number 410.2, are equal, and increments the counter by a first counter step with each such event. Preferably, the entropy extraction 404.4 also counts the events using this counter in which the two pseudorandom numbers, the first pseudorandom number 410.1 and the second pseudorandom number 410.2, are unequal, and decrements the counter by a second counter increment with each such event, preferably not falling below 0. The second counter increment is preferably smaller in magnitude than the first counter increment of the counter in the entropy extraction 404.4. If the value of this counter exceeds a predetermined value, the control device of the entropy extraction 404.4 assumes a defect in the time-to-pseudorandom number converter 404.3 (TPRC). Preferably, the control device of the entropy extraction 404.4 then signals to a processor (10-1, 10-2) a defect in the quantum random number generator 28 or a successful attack on the quantum random number generator 28. Preferably, the entropy extraction 404.4 then no longer signals to the finite-state machine a successful generation of a quantum random bit 411, so that the finite-state machine 404.8 can no longer report successful quantum random number generation to a processor (10-1, 10-2) and no longer generates quantum random numbers 1018.

[0180] If the first pseudorandom number 410.1 is smaller than the second pseudorandom number 410.2, the entropy extraction 404.4 generates a quantum random bit of a first logical value, for example a logical '1', and signals the successful generation to the finite state machine 404.8.

[0181] If the first pseudorandom number 410.1 is greater than the second pseudorandom number 410.2, the entropy extraction 404.4 generates a quantum random bit of a second logical value, for example a logical '0', which is different from the first logical value, and signals the successful generation to the finite state machine 404.8.

[0182] The finite-state machine converts the successfully generated quantum random bits 411 into quantum random data words 418, each representing a quantum random number, and makes them available to the processors (10-1, 10-2) via a RAM or a FIFO 404.9 via the internal data bus 419. The finite-state machine 404.8 preferably signals the provision of one or more quantum random numbers to one or more processors (10-1, 10-2).

[0183] One problem can be jitter in the system clock 2106. By using a time-to-random number generator 404.3 (TPRC), a monofrequency or otherwise systematic disturbance in the system clock 2106 is spread in the spectrum with a random spreading code, making detection difficult, if not impossible, for an attacker.

[0184] This further complicates the vulnerability of the quantum random number generator 28.

[0185] By using quantum random numbers for the seed value of the linear feedback shift register of the time-to-pseudorandom number converter and a quantum random number for the selection of the simple primitive feedback polynomial, the behavior of the time-to-pseudorandom number converter 404.3 (TPRC) itself is at the random level of a quantum random number. The regular change of these values ​​further complicates the ability of an attacker to manipulate the generated quantum random numbers.

[0186] Accordingly, the proposed quantum random number generator 28 achieves all of the stated goals.

[0187] In particular, the proposal achieves the objective of providing a one-piece, micro-integrated quantum random number generator 28 that makes it possible to guarantee a high level of entropy, so that it at least passes the statistical tests defined by NIST.

[0188] It is a further object of the proposal to provide a one-piece, micro-integrated quantum random number generator 28 which makes it possible to achieve a high bit rate in the generation of random sequences of quantum random bits 411 and / or quantum random data words 418.

[0189] It is a further object of the proposal to provide a one-piece, micro-integrated quantum random number generator 28 which, compared to the quantum random number generators of the prior art, has a more compact, more robust and less complex and, above all, a micro-integrated and CMOS compatible structure, which allows for one-piece manufacturing and co-integration into conventional systems such as memories (such as DRAMs, SRAMs, flash memories and the like) or processors (microprocessors and / or microcontrollers and / or SoCs with a processor on the IC).

[0190] Here, too, the proposal achieves the goal of providing a quantum random number generator 28 with a high degree of security against any attempt to manipulate its internal components. In particular, the use of a time-to-time pseudorandom number generator 1004.3 (TRNG) prevents the exploitation of successful attacks on the entropy source 401. Furthermore, the numerous tests enable reliable detection of an attack on the quantum random number generator 28, thus preventing the use of manipulated numbers as supposedly secure quantum random numbers.

[0191] Finally, the proposal also achieves the objective of providing a quantum random number generator 28 which is more economical than the generators of the known state of the art, in particular due to its ability to be co-integrated into CMOS circuits.

[0192] A further aspect of the present disclosure relates to an integrated quantum random number generator, 28, with an entropy source 401 comprising a photon source 54 and a single-photon detector 55, wherein the photon source 54 and the single-photon detector 55 are arranged one above the other in a common substrate made of a semiconductor material to further compact the device in the vertical direction relative to the surface of the semiconductor substrate 49, which marks the horizontal direction in the sense of the present document. An entropy source 401 according to the invention can also comprise a plurality of photon sources 54 coupled to a single single-photon detector 55 (e.g., to increase the photon rate or reliability) or a plurality of single-photon detectors 55 coupled to a single photon source 54 (e.g., for monitoring purposes) or a plurality of single-photon detectors 55 coupled to a plurality of photon sources 54 (e.g.,for monitoring purposes) 55. It is also possible to combine several photon sources 54 and single-photon detectors 55 into a single entropy source 401.

[0193] In contrast to the prior art, the photon sources 54 and photon detectors 55 are therefore not arranged side by side, but rather a compact arrangement of a photon source 54 and a single-photon detector 55 one above the other. This thus represents a particularly compact monolithic 3D integration with minimal space requirements for the entropy source 401. In particular, an arrangement is preferred in which the single-photon detector 55 is arranged lower than the photon source 54 in the semiconductor material (i.e., photon source 54 on top, single-photon detector 55 on the bottom) for improved shielding against external influences. In an alternative embodiment, however, the single-photon detector 55 can also be arranged higher than the photon source 54 in the semiconductor material (i.e., photon source 54 on the bottom, single-photon detector 55 on the top).For example, in addition to an inversion of the basic structural design during processing from the surface of the semiconductor substrate 49, an inverse arrangement of the elements can also be achieved by appropriate structuring from the back of the semiconductor substrate 49. In particular, structuring can be performed on both sides, from both the front and the back of the semiconductor substrate 49.

[0194] Preferably, the photon source 54 is a single-photon source (SPS) configured to simultaneously provide only single photons or a few photons at random time intervals. Such photon sources 54 that simultaneously provide only single photons or a few photons are also referred to as single-photon sources 54 in this application. However, they do not have to be true single-photon emitters, for example, based on a single isolated two-level system; rather, conventional light sources can also be configured as SPS 54 by appropriately attenuating the emission or the supplied current.

[0195] In the context of the present disclosure, a semiconductor substrate 54 is understood to mean the entire

[0196] A semiconductor chip is understood as a body in which, for example, a specific element structure is structured by means of bipolar, BiCMOS, CMOS or other semiconductor technologies, for example by forming differently doped wells or regions in the semiconductor material 49. However, the structure formation can also be carried out additively by applying further layers and structures or by a sequence of etching and application steps for such further layers and structures, preferably with the formation of the analog and digital circuits for evaluating and processing the output signal 404 of the entropy source 401. A corresponding semiconductor substrate 49 can therefore be used in addition to a so-called carrier or base substrate (e.g.An unstructured single-crystal semiconductor substrate 49 as the basis for the epitaxial growth of further semiconductor layers) may also comprise a plurality of such epitaxially grown layers 48 as well as other coatings. The semiconductor substrate 49 is therefore understood in this application as a material carrier for the semiconductor structures of an entropy source 401 according to the invention and not in the sense of a simple carrier or base substrate for applying these structures. In this respect, the formation of an entropy source 401 according to the invention one above the other in a common semiconductor substrate 49 made of a semiconductor material represents a distinction, in particular from hybrid-integrated combinations (e.g., by means of flip-chip assembly) comprising at least one photon source 54 and at least one single-photon detector 55, for example, on a common submount as a carrier structure.

[0197] In the case of the vertical arrangement of photon source 54 and photon detector 55, the photon source 54 is preferably a light-emitting silicon LED 54 operated at an operating point below or close to the breakdown voltage, better an avalanche Zener diode (Zener-avLED) 54. Preferably, the Zener-avLED 54 has a breakdown voltage of < 10 V, more preferably a breakdown voltage of < 8 V and even more preferably a breakdown voltage of < 7 V. The advantages of using a Zener-avLED as single-photon source 54 are explained in more detail below.This new type of single-photon source 54 allows a high single-photon rate of photons emitted by the single-photon source 54 at a relatively low operating voltage, even below and in the range of the Zener breakdown voltage. With the desired design, the generated photons are preferably radiated in a directed manner into the interior of the semiconductor substrate 49 and thus toward the single-photon detector 54. The close proximity of the single-photon detector 55 to the single-photon source 54 outweighs the disadvantage of increased attenuation in the semiconductor substrate 49. This makes Zener avLEDs particularly suitable for use as a single-photon source 54 in an entropy source 401. The single-photon detector 55 is preferably a single-photon avalanche diode (SPAD), i.e., a second SPAD 55.In the context of this document, these are detectors which, due to their particularly high sensitivity with high amplification and low (dark) noise, are in principle capable of detecting and proving individual photons.

[0198] A main idea of ​​the inventive entropy source 401 of the present invention is thus to provide a particularly compact and safe integrated entropy source 401 by arranging a Zener avLED as photon source 54 and a second SPAD 55 as single photon detector 55 vertically one above the other in a common semiconductor substrate 49.

[0199] One approach to improving the entropy sources 401 known from the state of the art is to select a correspondingly broad technology platform. For SoC designs with the broadest possible spectrum of potential applications, integrated circuits based on bipolar CMOS-DMOS (BCD) technology on silicon offer great potential. Silicon LEDs are well-known for this technology. Highly efficient SPADs have already been successfully demonstrated and implemented using BCD technology. BCD technology allows for particularly effective and optimized integration of these SPADs with a variety of other functional groups, such as digital and analog circuit components, particularly energy-efficient digital memory and switching elements, general power and driver electronics, as well as detector and sensor components.The document presented here particularly points out the advantage of the availability of DMOS transistors for the necessary voltage-stable voltage converters for generating the increased supply voltages for operating the entropy source 401 in such a way that the photon sources 54 and / or the photon detectors 55 can be operated near their breakdown voltages, e.g. in Geiger mode.

[0200] The silicon-based PLCs known in the state of the art can, in principle, also be implemented in BCD technologies. However, due to the undirected radiation of photons and their typically near-surface implementation, such silicon LEDs are not optimal for the realization of particularly efficient and attack-protected entropy sources 401. The near-surface implementation also usually results in degradation in the case of a silicon LED used in avalanche operation. Since silicon, as an indirect semiconductor, is poorly suited for photon generation, and these can generally only be generated through further processes via additional interaction with the crystal lattice, the selection of possible alternative silicon-based photon sources is severely limited.During the investigation of Zener diodes provided in a BCD technology in different layers by corresponding pn junctions, which are optimized for a permanent operating point even in the breakdown region, with a near-surface Zener diode as the emitter and an underlying simple pn diode without bias (English "zero bias") as the photon detector 55, it was shown that in this configuration, contrary to the general expectation of the skilled person, strong electroluminescence with an efficiency of at least 0.03% can be observed at the Zener diode in avalanche operation at the breakdown voltage. Such Zener diodes are not usually intended for operation as optoelectronic components (LEDs) in the prior art.

[0201] In particular, the generated photons are preferentially emitted toward the lower pn diode, which can thus detect almost all emitted photons, which can also be demonstrated via a photocurrent in the inventive structure (see FIGS. 29 to 32 with the associated figure description). It was thus shown that the investigated Zener diode exhibits a low, but nevertheless significant efficiency in the breakdown / Zener voltage range (approximately one detected photon per 3000 electrons of the Zener diode current) and therefore appears to be eminently suitable as single-photon sources for the realization of entropy sources 401 in silicon-based BCD technology. Above all, the preferential radiation toward the photon detector offers significant advantages over the isotropic radiation of conventional photon sources 54 used in entropy sources 401.The silicide commonly used in CMOS technology to reduce contact resistance between the metal contacts and the semiconductor silicide is both light-tight and mirror-smooth, so that even photons originally emitted upwards can be reflected back into the interior of the semiconductor substrate 49 by the silicide mirror thus formed. Accordingly designed Zener diodes operated as SPS in avalanche mode are therefore also referred to below as light-emitting avalanche Zener diodes (Avalanche Light Emitting Zener diodes, Zener-avLED) 54, in contrast to the silicon LEDs 54 known from the prior art.

[0202] The Zener avLEDs provided in the BCD technology used emit photons with wavelengths from the visible spectral range when used as a photon source 54 and have a relatively low Zener operating voltage of usually less than 8 V. This simplifies the design of the charge pumps in the voltage regulators 91 for supplying the entropy sources 401 with electrical energy. Since the radiation of a Zener avLED when used as a photon source 54 is also typically directed such that the photons are preferably emitted in the vertical direction, ieFurthermore, when used in an entropy source 401, a significantly stronger isolation of the SPS and the generated photons from the environment of the semiconductor material 49 can be achieved, and tapping or injecting photons at the surface of the photon detector 55 is made significantly more difficult. With a suitable design of the second SPAD diode 55 belonging to an entropy source 401, the efficiency of the random number generation of the quantum random number generator 28 can be significantly increased, and uncontrolled photon propagation in the semiconductor material 49 with corresponding crosstalk to other circuit components of the microintegrated circuit 2 can be largely prevented.The document presented here thus also discloses the idea of ​​minimizing the optical crosstalk between the entropy source 401 and other device parts of the microintegrated circuit 2 by a vertical arrangement of the photon source 54 and the photon detector 55 in a common substrate with the other device parts of the microintegrated circuit 2.

[0203] The second essential component for constructing a compact entropy source 401 is therefore the selection of a correspondingly adapted SPAD design for the second PSPAD diode of the photon detector 55. Typically, the second SPAD diodes 55 in BCD technologies are also implemented near the surface by appropriately forming p- or n-wells. Such near-surface SPADs as second SPAD diodes 55 are quite comparable to the SPADs implemented in CMOS technology in the prior art. In principle, the entropy source known from EP 3 529 694 B1 could thus also be implemented in BCD technologies with the Zener avLEDs described above. However, the Zener avLEDs as photon source 54, as already described above, advantageously emit the photons preferably in the direction into the semiconductor substrate 49.A prior art juxtaposition of a Zener avLED as the SPS and, when used as the photon source 54, with a near-surface SPAD as the second SPAD diode 55 and as the photon detector 55 could, in principle, be implemented, but not necessarily effectively. When using Zener avLEDs as photon sources 54, it is therefore expedient to arrange the associated second SPAD diode 55 below the Zener avLED, which serves as the photon source 54.

[0204] In addition to the implementation of conventional n-SPADs and p-SPADs, BCD technology also enables the implementation of completely new SPAD concepts, including the use of deep n- or p-doped layers in a BCD substrate.

[0205] In this case, a method for generating deep pn junctions in a BCD process, also recently developed by the applicant, made it possible to realize a particularly efficient, deep-lying single-photon avalanche diode ("deepSPAD") based thereon, which can be easily arranged directly below a Zener avLED configured to provide single photons as a photon source 54. The combination of a Zener avLED as a photon source 54 in combination with a deep-lying second SPAD diode 55 as a photon detector 55 thus provides the essential components of an entropy source 401 that is completely vertically integrated in BCD technology, in contrast to a horizontal integration of an entropy source 401 based on CMOS technology according to the prior art.

[0206] By vertically arranging a Zener avLED as photon source 54 and a deepSPAD realized by means of extremely deep pn junctions as a second SPAD diode 55 and thus as a photon detector 55, a miniaturized quantum random number generator 28 based on a monolithic silicon die as semiconductor substrate 49 can be realized in BCD technologies. It includes an entropy source 401 with highly efficient optical coupling of the photon source 54 and the photon detector 55, high attack security, a relatively low operating voltage, and thus reduced voltage converter complexity. Thus, the BCD-based design presented here, with a photon detector 55 arranged vertically to a photon source 54 in a one-piece microintegrated circuit 2, represents an optimal solution to the inventive problem.In particular, vertical 3D integration can further increase the compactness of an entropy source 401 and reduce the chip area consumption compared to conventional lateral 2D designs while simultaneously increasing efficiency. This makes it possible to place the entropy source 401 in the pad edge 2403 of a microintegrated circuit 2. This effectively reduces the chip area consumption for the proposed entropy source 401 to virtually zero, resulting in a massive economic advantage.

[0207] Preferably, an entropy source 401 according to the invention and the associated quantum random number generator 28 are therefore formed in a BCD substrate as a semiconductor substrate 49, which was manufactured using BCD technology.

[0208] The BCD substrate preferably comprises a carrier substrate 49 of the proposed vertical entropy source 401 and an epitaxial layer 48 grown on the carrier substrate 49 of the proposed vertical entropy source 401. A deep pn junction in the epitaxial layer 48 is created between the carrier substrate 49 of the proposed vertical entropy source 401 and the epitaxial layer 48 by diffusion of dopants introduced into a surface of the carrier substrate 49 of the proposed vertical entropy source 401 below the epitaxial layer 48. The carrier substrate 49 of the proposed vertical entropy source 401 can preferably be a p-substrate. However, n-substrates or intrinsic substrates can also be used. The substrate material of the carrier substrate 49 of the proposed vertical entropy source 401 may in particular be silicon.However, the processes can in principle also be adapted for other semiconductor materials. A typical dopant for forming a p-type region is boron. For example, phosphorus (P), arsenic (As), or antimony (Sb) can be used to form an n-type region. In silicon, for example, boron diffuses significantly further as a dopant than the heavy donors (P, As, or Sb). It can also be seen that the n-type regions created are largely dominant due to the higher doses used, i.e. an n-type region already doped with phosphorus can retain its existing conductivity type even after additional boron is added. To create the deep pn junctions, additional masking, lithography, and epitaxy steps in the conventional BCD process can sometimes be dispensed with.

[0209] The first and second dopant preferably have different diffusion properties in the carrier substrate and / or in the epitaxial layer. The second dopant preferably has greater mobility in the carrier substrate and / or in the epitaxial layer than the first dopant. The first dopant and / or the second dopant are preferably introduced masklessly or using a mask process. For maskless introduction, a direct ion beam writing process, for example using focused ion beams, can be used. In a mask process, the introduction is carried out using a previously provided and / or preferably photolithographically produced mask, wherein the introduction is carried out, for example, using a chemical or physical deposition process or likewise using an ion beam writing process.Preferably, immediately after the introduction of the second dopant, the first region or the second region completely overlies the other region in a plan view of the surface of the carrier substrate. Preferably, the first region is a deep n-type layer (NBL layer) and the second region is a deep p-type layer (PBL layer).

[0210] Preferably, the single-photon detector 55 forms an avalanche region in a region around the deep pn junction and comprises an absorption region for converting photons into electron-hole pairs, wherein the absorption region is directly adjacent to the deep pn junction.

[0211] It is preferred that the deep pn junction is formed at least partially between a deep n-layer as the cathode and a deep p-layer directly adjacent to the deep n-layer. It is also preferred that the absorption region directly adjoins the deep p-layer and is essentially formed as a p-region. "Essentially" means that the absorption region can also be partially formed as an intrinsic region. It is further preferred that an anode formed as a p+ region directly adjoins the absorption region.

[0212] Preferably, a second deep pn junction formed below the deep pn junction of the single-photon detector 55 located in the epitaxial layer 48 (e.g., in the carrier substrate 49) is used as an additional photon detector 55 for monitoring for external attacks. The aforementioned method for generating deep pn junctions in a BCD process results in a second pn junction (see FIG. 27 with the associated figure description) (observation diode 28040) located below the first pn junction in some embodiments. Due to its largely identical electronic properties, this second pn junction can also be configured as a photon detector 55 or single-photon avalanche diode 55.Since this additional photon detector 55 is thus arranged below the actual arrangement of the entropy source 401, deeply buried in the semiconductor material 49, it can provide an additional protective function, unknown in the prior art, against photons injected from the back of the semiconductor substrate 49. Preferably, the proposed watchdog 404.5 and / or the proposed voltage monitor 423 use this second pn junction as a light-sensitive observation diode 28040. Preferably, the proposed watchdog 404.5 and / or the proposed voltage monitor 423 evaluate the diode voltage of the observation diode 28040 (observation diode voltage) in the form of this second pn junction, record the diode voltage of this observation diode 28040 as an observation diode voltage value, and compare this observation diode voltage value with a permitted observation diode voltage value interval.If the observation diode voltage value lies outside the observation diode voltage value interval, the proposed watchdog 404.5 and / or the proposed voltage monitor 423 conclude that there is a defect or a photonic attack on the entropy source 401. In this case, after detecting such an incident, they signal the presence of such an incident to one of the processors 10-1, 10-2 and / or provide such information. Preferably, the watchdog 404.5 signals such an incident to the designated processor 10-1, 10-2 by means of an interrupt signal via an interrupt line. Preferably, the watchdog 404.5 checks whether there is a correlation between a photon detection of the observation diode 28020 and a signal at the output 405 of the entropy source 401. If this is the case, the photons do not originate externally, but from the entropy source 401. Such events are ignored by the watchdog 404.5 and the voltage monitor 413 preferably. Typically, other circuit components of the microintegrated circuit 2 and / or the quantum random number generator 28 also emit parasitic photons that can hit the observation diode 28020. Typically, the observation diode 28020 also detects some of these parasitic normal operation photons. The watchdog 404.3 can detect the level of these normal operation photons and make them available to the processor 10-1, 10-2, for example, via the data bus 419, as a measured value for other purposes. If necessary, the processor 10-1, 10-2 or another device component of the microintegrated circuit 2 can infer an operating state of the microintegrated circuit 2 depending on a transmitted or provided measured value of the level of the normal operation photons.The permitted observation diode voltage value interval is preferably set such that a photonic attack is only detected if the measured value of the level of the normal operating photons is significantly outside the expected measured values ​​of the level of the normal operating photons.

[0213] Using the 28040 observation diode and typically with the aid of the voltage monitor 413, the watchdog 404.3 can detect attack photons in close proximity to the entropy source 401 over a wide angular range. This allows the processor 10-1, 10-2 to detect external attacks with a high degree of probability.

[0214] Preferably, the top and / or bottom of the semiconductor substrate 49 in the region of the entropy source 401 is mirrored on one surface. Preferably, the top and / or bottom of the semiconductor substrate 49 in the region of the entropy source 401 can also comprise a light-blocking layer—which can also be mirrored—on one surface. Mirroring the surfaces of a semiconductor substrate 49 (e.g., by means of metallization 142, 53 or the application of dichroic layers) as well as the application of a light-blocking layer are known in the art and have already been discussed above. These approaches can also be used in a proposed entropy source 401 to shield against external photons ("shadowing") and to increase efficiency by backreflecting the photons generated by the associated photon source 54.Alternatively or additionally, a corresponding encapsulation can be carried out in the area of ​​the entropy source 401 or this area can be surrounded by a metal box.

[0215] Preferably, the surface of the semiconductor substrate 49 is covered with a silicide layer in the region of the entropy source 401 and with a metallization 142, 53 above it. Preferably, the metallization 142, 53 is closed in the region of the entropy source 401. The metallization 142, 53 can act as a mirror coating for the interior and / or as a wavelength-independent shading for external photons. The same applies to a formed silicide layer. Preferably, the escape of photons provided by the single-photon source 54 at the surface of the semiconductor substrate 49 and / or the rear side of the semiconductor substrate 49 is prevented by a combination of at least one element each consisting of metal covers, sidewall contacts, and vias. This prevents the signal generation from being observable by microscopes or the like. The aforementioned elements can provide largely complete shielding orEncapsulation of the entropy source 401 can be achieved, which, in addition to external shielding, also ensures high immunity to external interference. This encapsulation preferably also encompasses other device components of the quantum random number generator 28. A second corresponding encapsulation can also encompass the other device components of the quantum random number generator 28 and the already encapsulated entropy source 401 through additional layers and vias.

[0216] Preferably, several entropy sources 401 according to the invention or a multi-channel entropy source 401 are implemented as a QRNG system in a system of several quantum random number generators 28. Such a QRNG system preferably comprises a plurality of proposed entropy sources 401, which are preferably implemented jointly on the same semiconductor substrate 49 of a preferably one-piece microintegrated circuit 2. Together with compact shielding of the individual entropy sources 401, very high integration densities can be achieved with a large number of densely packed entropy sources 401, decoupled from one another due to the shielding by means of the aforementioned layers and vias, and thus overall high effective random number rates.Preferably, such a QRNG system comprises, in addition to the required plurality of shielded entropy sources 401, the required plurality of analog-to-digital converters 403, the required plurality of time-to-pseudo-random number converters 404.3, and the plurality of entropy extractors 404.4, a device that combines the plurality of generated quantum random bits 411 into a sequence of quantum random numbers. This is typically a modified FSM 404.8. In prior art entropy sources 401, the integration density is limited primarily by the structural juxtaposition of the individual components.

[0217] Preferably, a proposed quantum random number generator 28 comprises an electronic circuit for generating and outputting a digital quantum random number sequence based on the statistical evaluation of the temporal sequence of signals 405 of the single-photon detector 55 of the entropy source 401.

[0218] Another aspect of the present proposal concerns the integrated microelectronic

[0219] Integrated circuit (IC) comprising at least one proposed entropy source 401. In particular, these can be ICs 2 for applications based on safety-relevant chip-based systems (System on Chip, SoC).

[0220] The advantages of a proposed vertical entropy source 401 with a photon source 54 arranged vertically to the photon detector 55 compared to the known horizontal implementations in the prior art are primarily based on the further miniaturization of the entire random number generator structure and the resulting high degree of integration or miniaturization of the generated structures and the resulting increase in the quantum random bit rate. Due to the complete isolation of the SPS (photon source 54) and the associated second SPAD diode 55 from the environment through the proposed shielding using layers and vias, the security of the quantum random number generation can be significantly further increased.The directed vertical radiation from the Zener avLED 54 used as SPS (photon source 54) in the proposed vertical entropy source 401 also contributes to increasing the security as well as to a significant increase in the efficiency of the quantum random number generation of the quantum random number generator 28.

[0221] A second deep pn junction, formed below the pn junction of the second SPAD 55 of the vertical entropy source 401 using a novel BCD technology, can be used as an additional photon detector, such as observation diode 28020, for monitoring attacks, particularly from the backside of the semiconductor substrate 49. In the example discussed here, observation diode 28040 is connected between the substrate 49 and the cathode 26132 of the second SPAD diode 55, which operates as a photon detector and is buried in the semiconductor substrate 49 of the vertical entropy source 401. The watchdog 404.5 and / or the voltage monitor 413 preferably detect the observation diode voltage value of the voltage of the observation diode 28020. The watchdog 404.5 preferably compares the synchronized voltage signal 415 with a likewise synchronized signal of the observation diode voltage value of the observation diode 28020.If the synchronized signal of the observation diode voltage value of the observation diode 28020 shows a positive signal that is synchronous with a pulse of the synchronized voltage signal 415, the watchdog 404.5 assumes that this is not an attack but a regular signal and typically does not trigger an alarm. However, from time to time, the watchdog 404.5 and / or the processor 10-1, 10-2 can interrupt the power supply to the entropy source 401, so that the synchronized voltage signal 415 of the observation diode voltage value should no longer show any pulses. In this case, the synchronized signal of the observation diode voltage value of the observation diode 28020 should also no longer show any pulses. However, if the synchronized signal of the observation diode voltage value of the observation diode 28020 continues to show a pulse, the watchdog 404.5 typically concludes that an attack or a malfunction has occurred.Preferably, the watchdog 404.5 reports such an attack or such a disturbance to the processor 10-1, 10-2 via the data bus 419 and / or by means of an interrupt signal via an interrupt line. The watchdog 404.3 can also keep the information about such a suspected attack available in a register or memory of the quantum random number generator 28. Typically, the watchdog 404.5 then prevents the generation of random numbers 418 by the FSM 404.8 at least until the processor 10-1, 10-2 explicitly permits this generation again by sending a corresponding command to the watchdog 404.5, preferably using a password, via the data bus 419.

[0222] The voltage monitor 413 preferably monitors the voltage level of the observation diode voltage value of the voltage of the observation diode 28020. If the observation diode voltage value of the voltage of the observation diode 28020 is outside the predefined observation diode voltage value interval, the voltage monitor 413 preferably reports this to the watchdog 404.5. In the case of such an out-of-spec message from the voltage monitor 413 for the observation diode voltage value of the observation diode 28040, the watchdog 404.5 typically concludes that an attack or a fault has occurred. The watchdog 404.5 preferably reports such an attack or a fault to the processor 10-1, 10-2 via the data bus 419 and / or by means of an interrupt signal via an interrupt line. The watchdog 404.3 can also keep the information about such a suspected attack in a register or memory of the quantum random number generator 28.Typically, the watchdog 404.5 then prevents the generation of random numbers 418 by the FSM 404.8 at least until the processor 10-1, 10-2 explicitly permits this generation again by sending a corresponding command to the watchdog 404.5, preferably by means of a password via the data bus 419.

[0223] The efficiency of the optical coupling into the associated second SPAD diodes 55, as well as the isolation and safety, can be further increased through the use of internal metal and silicide mirrors. Compared to the prior art, the Zener avLED used as the photon source 54 requires only a relatively low operating voltage of <8 V. This further simplifies the voltage converters 91 required to generate the operating voltages of the entropy source 401. Furthermore, since the absorption length of the emitted visible light in silicon is small (i.e., the associated absorption coefficient is high), very good optical isolation between neighboring elements can be achieved. The close proximity of the photon source 54 to the photon detector 55 in the vertical entropy source 401 prevents this disadvantage of the small absorption length of the emitted visible light in silicon from becoming effective with regard to the efficiency of photon transport.This enables the arrangement of the vertical entropy sources 401 in an array with high cell density and a resulting correspondingly high generation or entropy rate of the quantum random number generator 28. Further aspects of the present invention are disclosed in the dependent claims or in the following description of the drawings.

[0224] Features of the invention

[0225] The features of the invention summarize these once again. Applications of the technical teaching may combine the features with one another, provided these combinations do not cause factual contradictions. Therefore, the dependencies and relationships presented here represent only particularly preferred, exemplary embodiments.

[0226] Feature 1: Quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG), wherein the quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG) has an entropy source (401) and wherein the quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG) evaluates a signal (405) of the entropy source (401) by means of a time-to-pseudo-random number converter (TPRC) (404.3) and generates one or more random bits (411).

[0227] Feature 2: Quantum process-based generator (28) for true random numbers (411, 418) according to feature 1, wherein the quantum process-based generator (28) for true random numbers (411, 418) generates one or more random numbers (418) from a plurality of random bits (411) and makes them available or uses them.

[0228] Feature 3: Quantum process-based generator (28) for true random numbers (411, 418) according to feature 1 or 2, wherein the behavior of the P of a time-to-pseudo-random number converter (TPRG) (404.3) depends on one or more quantum random bits (411) and / or one or more quantum random numbers (418).

[0229] Feature 4: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 3, wherein the quantum process-based generator (28) for true random numbers (411, 418) comprises a watchdog (404.5) which monitors the correct function of the quantum process-based generator (28) for true random numbers (411, 418).

[0230] Feature 5: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 4, wherein the quantum process-based generator (28) for true random numbers (411, 418) comprises a watchdog (404.5) which monitors the correct function of the quantum process-based generator (28) for true random numbers (411, 418) by measuring the randomness of the generated quantum random bits (411) in the form of a measured value and comparing it with a tolerance interval or a threshold value and inferring an error in the event of a deviation.

[0231] Feature 6: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 5, wherein the quantum process-based generator (28) for true random numbers (411, 418) comprises a watchdog (404.5) which monitors the correct function of a time-to-pseudorandom number converter (TPRC) (404.3) and detects and / or signals an error in the event of deviations from an expected behavior.

[0232] Feature 7: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 6, wherein the quantum process-based generator (28) for true random numbers (411, 418) is manufactured in one piece as part of an integrated circuit (2), and wherein the integrated circuit (2) comprises a voltage converter (91) for supplying the entropy source (401) of the quantum process-based generator (28) for true random numbers (411, 418), and wherein the voltage converter (91) comprises one or more DMOS transistors.

[0233] Feature 8: Quantum process-based generator (28) for true random numbers (411, 418) according to feature 7, wherein the integrated circuit (2) is manufactured using BCD technology. Feature 9: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 8, wherein the quantum process-based generator (28) for true random numbers (411, 418) is manufactured in one piece as part of an integrated circuit (2), and wherein the integrated circuit (2) is one of the following circuits or comprises one of the following circuits:

[0234] A microcontroller, a microprocessor, a memory, a DRAM, an SRAM, a RAM, a volatile memory, an OTP memory,

[0235] - an EEPROM, a flash memory, an MRAM, an FRAM, a sensor evaluation circuit, a control circuit for an automotive control circuit, a graphics controller, an evaluation circuit for a biometric sensor or an input device, a control circuit, a chip card circuit, a physical circuit of a mobile phone or a smartphone, a circuit of an access control system, a circuit with a coded recording of operating parameters, a circuit of an access control system, a circuit of an electronic security system, a radio system circuit, a communication circuit, a circuit of an encryption and / or decryption system, a circuit of an individualization system, a circuit of a gaming device, a circuit of a simulation system, a circuit of a computer system, a circuit of a noise source,a circuit with a device for generating and / or using a spreading code.,

[0236] Feature 10: Quantum process-based generator (28) for true random numbers (411, 418) according to one of features 1 to 9, wherein the entropy source (401) comprises a photon source (54) and wherein the entropy source (401) comprises a photon detector (55) and wherein the photon source (54) emits photons as a quantum signal when supplied with electrical energy and wherein the photon source (54) is optically coupled to the photon detector (55) and wherein the photon detector (55) at least partially receives the quantum signal of the photon source (54) and generates the output signal (405) of the entropy source (401) or a precursor signal thereof.

[0237] Feature 11: Secure microcontroller for controlling devices, in particular in automobiles, comprising a semiconductor crystal and memory elements and at least one internal bus (419) and at least one processor (10-1), in particular an 8 / 16 / 32 / 15-bit microcontroller core, and one or more data interfaces and at least one quantum process-based generator (28) for true random numbers (411, 418) (Quantum Random Number Generator: QRNG) according to one of features 1 to 9, and wherein the memory elements are connected to the internal bus (419) and wherein the data interface is connected to the internal bus (419), and wherein in particular the quantum process-based generator for true random numbers (QRNG) (28) can be connected to the internal bus (419), and wherein the processor (10-1) is connected to the internal bus (419), and wherein the quantum process-based generator for true random numbers (QRNG) (28),in particular upon request of the processor (10-1), generates or makes available a random number (418), and wherein the processor (10-1) generates a key with the aid of a program from one or more of its memory elements and with the aid of the random number, and wherein the processor (10-1) encrypts and decrypts data with the aid of a program from one or more of its memory elements and with the aid of the key, which data it exchanges via the data interface with devices outside the secure microcontroller, and wherein the semiconductor crystal integrally comprises these sub-devices of the secure microcontroller, wherein these sub-devices of the secure microcontroller comprise the memory elements, the internal bus (419), the at least one processor (10-1), the data interfaces, and the quantum process-based generator for true random numbers (English: Quantum Random Number Generator: QRNG) (28),

[0238] Feature 12: Secure microcontroller according to feature 11, wherein the memory elements comprise one or more read / write memories RAM and / or one or more writable non-volatile memories, in particular EEPROM memories and / or flash memories and / or OTP memories, and / or one or more read-only memories and / or one or more non-volatile manufacturer memories, in particular one or more manufacturer ROMs and / or one or more manufacturer EEPROMs and / or one or more manufacturer flash memories.

[0239] Feature 13: A secure microcontroller as defined in Feature 12, wherein the manufacturer's ROM includes the boot software.

[0240] Feature 14: A secure microcontroller according to feature 12 or 13, wherein a manufacturer memory firewall is provided between the manufacturer memory and the internal bus (419).

[0241] Feature 15: Secure microcontroller according to one or more of features 11 to 14, comprising one or more of the following components: a clock generator (92) (among othersfor the system clock 2106), a reset circuit (83) and / or one or more voltage converters (91) which provide the operating voltages, and / or a ground circuit in the negative supply voltage line (GND), in particular for defending against attacks via ground offset, and / or an input / output circuit and / or one or more processing modules, wherein the processing modules are configured to communicate with the internal bus (419), and wherein the processing modules comprise one or more of the following modules: a CRC module (Cyclic Redundancy Check), a clock generator module, with a DES accelerator and / or an AES accelerator, one or more timer modules, a security monitoring and control circuit, a data interface, in particular a Universal Asynchronous Receiver Transmitter (UART).

[0242] Feature 16: Secure microcontroller according to one or more of features 11 to 15, with at least one photon source (54), in particular a silicon LED (54) or a first SPAD diode (54), and with at least one photon detector (54), in particular a second SPAD diode (55), and with at least one processing circuit and with at least one operating circuit, wherein the quantum process-based generator for true random numbers (Q.RNG) (28) comprises at least the photon source (54) as a light source for the optical quantum signal, and wherein the quantum process-based true random number generator (QRNG) (28) comprises at least the photon detector (55) as a photodetector for the optical quantum signal, and wherein the quantum process-based true random number generator (QRNG) (28) comprises at least the processing circuit, and wherein the at least one photon source (54) is optically coupled to the at least one photon detector (55), and wherein the operating circuit supplies the photon source (54) with electrical energy such that the photon source (54) emits light, and wherein the processing circuit detects the signal from the photon detector (55) and forms the random number therefrom and makes it available to the processor (10-1).

[0243] Feature 17: Secure microcontroller 11 according to feature 16, comprising at least one optical waveguide (44), wherein the quantum process-based true random number generator (Q.RNG) (28) comprises at least the optical waveguide (44) and wherein the at least one optical waveguide (44) optically couples the at least one photon source (54) to the at least one photon detector (55).

[0244] Feature 18: Secure microcontroller according to feature 17, wherein the semiconductor crystal has a surface (56) and wherein the semiconductor crystal has a semiconducting material below its surface (56), and wherein the surface (56) of the semiconductor crystal has a metallization stack, and wherein the metallization stack has a typically structured and optically transparent and electrically insulating layer (44), and wherein at least a part of this typically structured, transparent and electrically insulating layer (44) of the surface (56) forms the optical waveguide (44), and wherein the photon source (54) from the semiconducting material of the semiconductor substrate radiates into this optical waveguide (44), and wherein the optical waveguide (44) irradiates the photon detector (54) in such a way thatthat the light from within the optical waveguide (44) penetrates back into the semiconducting material of the semiconductor substrate from the surface and there strikes device parts of the photon detector (55).

[0245] Feature 19: Secure microcontroller according to feature 17 and / or 18, wherein the at least one operating circuit supplies the at least one photon source (54) at least temporarily with electrical energy and wherein the at least one photon source (54) feeds photons into the at least one optical waveguide (44) when supplied with sufficient electrical energy and wherein the at least one optical waveguide (44) radiates such photons into the photon detector (55).

[0246] Feature 20: Secure microcontroller according to one or more of the preceding features 11 to 19, wherein a data interface of the one or more data interfaces is a wired automotive data bus interface, and wherein the wired automotive data bus interface comprises in particular a CAN data bus interface and / or a CAN FD data bus interface and / or a Flexray data bus interface and / or a PSI5 data bus interface and / or a DSI3 data bus interface and / or a LIN data bus interface and / or an Ethernet data bus interface and / or a LIN data bus interface and / or a MELIBUS data bus interface

[0247] Feature 21: Secure microcontroller according to one or more of the preceding features 11 to 20, wherein a data interface of the one or more data interfaces is a wireless data bus interface and wherein the wireless data bus interface comprises in particular a WLAN interface and / or a Bluetooth interface.

[0248] Feature 22: Secure microcontroller according to one or more of the preceding features 11 to 21, wherein a data interface of the one or more data interfaces is a wired data bus interface and wherein the wireless data bus interface is in particular a KNX data bus interface and / or an EIB data bus interface and / or a DALI data bus interface and / or a PROFIBUS data bus interface.

[0249] Feature 23: A device, wherein the device comprises an integrated circuit (4) with a first processor (10-1) and a non-volatile memory (16), and wherein the device comprises a first memory, wherein the non-volatile memory stores at least one security code; wherein the first memory stores data, and wherein the data in the first memory is cryptographically protected in a first format, and wherein the integrated circuit is configured to validate the data read from the first memory during a transfer of data from the first memory, andwherein the device comprises a quantum random number generator (28) according to one of features 1 to 9, and wherein the integrated circuit and the quantum random number generator (28) are manufactured in a semiconductor crystal, and wherein the semiconductor crystal has a surface (56), and wherein the semiconductor crystal has a semiconducting material below its surface (56), and wherein the surface (56) of the semiconductor crystal has a metallization stack, and wherein the metallization stack has a typically structured and optically transparent and electrically insulating layer (44), and wherein at least a part of this typically structured,transparent and electrically insulating layer (44) of the surface (56) forms the optical waveguide 44, and wherein the first SPAD diode (54) radiates photons (57) from the semiconducting material of the semiconductor substrate into this optical waveguide (44), and wherein the at least one optical waveguide (44) transports such photons (58) to the second SPAD diode (55), and wherein the optical waveguide (44) irradiates the second SPAD diode (55) such that the light (59) from within the optical waveguide (44) penetrates back into the semiconducting material of the semiconductor substrate from the surface (56) and there strikes device parts of the second SPAD diode (55), and wherein the first SPAD diode (54), the second SPAD diode (55), and the optical waveguide (44) are part of the quantum random number generator (28). are.,

[0250] Feature 24: Device according to feature 23, wherein the device has at least one operating circuit and wherein the at least one operating circuit supplies the at least one first SPAD diode (54) at least temporarily with electrical energy and wherein the at least one first SPAD diode (54) feeds photons (57) into the at least one optical waveguide (44) when supplied with sufficient electrical energy and wherein the at least one optical waveguide (44) transports such photons (58) to the second SPAD diode (55) and wherein the at least one optical waveguide (44) radiates such photons (59) into the second SPAD diode (55).

[0251] Feature 25: Device according to feature 24, wherein the quantum random number generator (28) comprises at least the first SPAD diode (54) as a light source for the optical quantum signal, and wherein the quantum random number generator (28) comprises at least the second SPAD diode (55) as a photodetector for the optical quantum signal, and wherein the quantum random number generator (28) comprises at least one processing circuit, and wherein the quantum random number generator (28) comprises at least the optical waveguide (44), and wherein the at least one optical waveguide (44) optically couples the at least one first SPAD diode (54) to the at least one second SPAD diode (55), and wherein the operating circuit supplies the first SPAD diode (54) with electrical energy,that the first SPAD diode emits light (54) and wherein the processing circuit detects the signal of the second SPAD diode (55) and forms the random number therefrom and makes it available to the processor (10) or another part of the device.,

[0252] Feature 26: Device according to one of features 23 to 24, wherein the first memory is located inside or outside the integrated circuit and wherein the device has a second memory for storing data and wherein the second memory is located inside or outside the integrated circuit;wherein the device is configured to transfer data from the first memory via the integrated circuit to the second memory so that the processor can access it from the second memory, and wherein the integrated circuit is configured, during a transfer of data from the first memory to the second memory, to validate the data read from the first memory using a security code stored in the non-volatile memory and, if the data is validated, to apply cryptographic protection in a second format to the validated data using a security code stored in the non-volatile memory, and to store the data protected in the second format in the second memory.;

[0253] Feature 27: Apparatus according to any one of features 23 to 26, wherein the first memory comprises a read-only memory.

[0254] Feature 28: Apparatus according to any one of features 26 to 27, wherein the second memory comprises a random access memory.

[0255] Feature 29: Apparatus according to any one of features 26 to 28, wherein the cryptographic protection applied to the data in the first memory is different from the cryptographic protection applied to the data in the second memory.

[0256] Feature 30: Apparatus according to any one of features 23 to 29, wherein the integrated circuit includes a memory for storing data to be processed by the processor, and wherein the device is arranged to store some data of the validated data set in the memory and the remainder in the second memory.

[0257] Feature 31: Apparatus according to any one of features 26 to 30, wherein the first memory stores data in a first data format and the second memory is arranged to store data in a second, different data format. Feature 32: Apparatus according to feature 31, wherein the data stored in the first memory is protected by a first authentication technique, and wherein the apparatus is arranged to protect the data in the second memory by a second, different authentication technique.

[0258] Feature 33: Apparatus according to any one of features 26 to 32, wherein the data is stored in the first memory in at least one data set and the or each data set is cryptographically protected as a set, and wherein the apparatus is arranged to store in the second memory words or groups of words of a validated data set, each word or group of words being separately cryptographically protected.

[0259] Feature 34: Apparatus according to feature 33, arranged to read the words or groups of words from the second memory, to validate the read words or groups of words using a security code stored in the non-volatile memory, and to process the read and validated words or groups of words in the processor.

[0260] Feature 35: Apparatus according to feature 34, wherein the integrated circuit comprises a hash calculator, and wherein the processor and the hash calculator (hash engine) are arranged to: a) calculate a hash function for each word or group of words in dependence on a security code stored in the non-volatile memory and store the hash in association with the word or group in the second memory, b) retrieve a stored word or group from the second memory, recalculate a hash function for the retrieved word or group using the security code and compare the newly calculated hash with the stored hash, and c) allow the data processing system to process the retrieved word or group only if the newly calculated and stored hashes have a specific relationship to one another.

[0261] Feature 36: Apparatus according to feature 35, wherein the hash calculator is a circuit in the integrated circuit.

[0262] Feature 37 The device according to any one of features 23 to 36, wherein the non-volatile memory of the integrated circuit is a one-time programmable memory.

[0263] Feature 38 Apparatus according to any one of features 23 to 37, wherein the or each data set stored in the first memory is cryptographically protected by a corresponding digital signature.

[0264] Feature 39: Device according to one of features 23 to 38, wherein the or each data set stored in the first memory is cryptographically protected by a corresponding digital signature with the aid of at least one random number of the quantum random number generator.

[0265] Feature 40: Device according to feature 38 or 39, wherein a security code is stored in the non-volatile memory of the integrated circuit, which security code the device has generated at least partially by means of at least one random number of the quantum random number generator (28).

[0266] Feature 41: Apparatus according to any one of features 38 to 39, wherein the apparatus is arranged to validate a digital signature of the data set by reference to a security code stored in the non-volatile memory of the integrated circuit.

[0267] Feature 42: A data processing device, wherein the data processing device comprises an integrated circuit, and wherein the integrated circuit comprises a processor, and wherein the integrated circuit comprises a non-volatile memory, and wherein the non-volatile memory stores at least one security code, and wherein the integrated circuit comprises a hash calculator, and wherein the integrated circuit comprises an interface at the boundary of the integrated circuit, and wherein the integrated circuit comprises a quantum random number generator according to any one of features 1 to 9, and wherein the integrated circuit and the quantum random number generator are fabricated in a semiconductor crystal, and wherein the semiconductor crystal has a surface (56), and wherein the semiconductor crystal has a semiconducting material below its surface (56), and wherein the surface (56) of the semiconductor crystal has a metallization stack, and wherein theMetallization stack has a typically structured and optically transparent and electrically insulating layer (44), and wherein at least a part of this typically structured, transparent and electrically insulating layer (44) of the surface (46) forms the optical waveguide (44), and wherein the first SPAD diode (54) radiates photons (57) from the semiconducting material of the semiconductor substrate into this optical waveguide (44), and wherein the at least one optical waveguide (44) transports such photons (58) to the second SPAD diode 55, and wherein the optical waveguide (44) irradiates the second SPAD diode (55) such that the light (59) from within the optical waveguide (44) penetrates back into the semiconducting material of the semiconductor substrate from the surface (56) and there strikes device parts of the second SPAD diode (55), and wherein the first SPAD diode (54) and the second SPAD diode (55) and the optical fiber(44) are part of the quantum random number generator (28).

[0268] Feature 43: Data processing device according to claim 42, wherein the processor and / or another device part of the data processing device encrypts or decrypts data with the aid of at least one random number of the quantum random number generator.

[0269] Feature 44: A data processing device according to feature 42 or 43, wherein the data processing device comprises a memory, and wherein the memory is for storing data when used by the processor, and wherein the memory is coupled to the processor to receive words from the processor and to provide words to the processor.

[0270] Feature 45: A data processing device according to any one of features 42 to 44, wherein the memory is external to the integrated circuit and wherein the memory is coupled to the processor via the interface at the boundary of the integrated circuit to receive words from the processor and to supply words to the processor.

[0271] Feature 46 Data processing apparatus according to one of claims 42 to 45, wherein the processor and the hash calculator are arranged to a) calculate a hash function for each word in dependence on a security code stored in the non-volatile memory and store the hash in association with the word, b) retrieve stored words from the memory, recalculate a hash function for each retrieved word using the security code and compare the newly calculated hash value with the stored hash value, and c) permit processing of the retrieved word by the data processing system only if the newly calculated and stored hashes have a predetermined relationship.

[0272] Feature 47: A device comprising: an integrated circuit including data processing means and non-volatile storage means storing at least one security code; a first means storing data, the data being cryptographically protected in a first format by at least one authentication code;and a quantum random number generator (28) according to one of features 1 to 9 as part of the integrated circuit, wherein the quantum random number generator comprises a photon source (54) and a photon detector (55) which are or can be coupled to one another, in particular via an optical waveguide (44) which is manufactured in particular outside the semiconductor substrate of the integrated circuit on the surface of the integrated circuit, and wherein the device uses at least one random number of the quantum random number generator (28) for encrypting or decrypting a date or the authentication code, at least temporarily.

[0273] Feature 48 A device according to feature 47, wherein the device comprises a second device, in particular external to the integrated circuit, for storing data, and wherein the device comprises means for transferring data from the first memory via the integrated circuit to the second memory so that the processor can access it from the second memory, and wherein the device comprises means for validating the data read from the first memory during transfer using a security code stored in the non-volatile memory, and wherein the device comprises means for applying cryptographic protection comprising at least one authentication code to the validated data in a second format using a security code stored in the non-volatile memory when the data is validated,and wherein the device comprises means for storing the protected data in the second memory in the second format.,

[0274] Feature 49: Device, in particular according to one of features 23 to 48, wherein the device comprises a quantum random number generator (28) according to one of features 1 to 9, and wherein the quantum random number generator comprises the following device parts: a photon source (54), a photon detector (55), wherein the photon detector (55) is optically coupled to the photon source (55), an optional optical waveguide (44) for this optical coupling, an optional amplifier (404) and / or filter, an analog-to-digital converter (403), an optional comparator (404.2), a time-to-pseudo-random number converter (404.3), an entropy extraction device (404.4) which converts output values ​​of the time-to-pseudo-random number converter (403) into first and second values ​​and generates quantum random bits 411 therefrom. generated.

[0275] Feature 50: Apparatus according to feature 49, wherein the apparatus comprises a watchdog (404.5) that monitors apparatus parts of the quantum random number generator (28).

[0276] Feature 51: Device according to one of features 49 to 50, wherein the device comprises a voltage monitor (413) which detects and monitors analog values ​​of analog signals of the quantum random number generator (28) and / or for the operation of the quantum random number generator (28).

[0277] Feature 52: Device according to one of features 49 to 51, wherein the device comprises a further pseudorandom number generator (404.6), in particular in the form of a linear feedback shift register (404.6).

[0278] Feature 53: Device according to one of features 49 to 52, wherein the device comprises a signal multiplexer (404.7) which, in the event of an error, switches from the signal of the output (411) of the entropy extraction device to a signal of a replacement random number generator or a replacement pseudorandom number generator (404.6).

[0279] Feature 54: Device according to one of features 49 to 53, wherein the starting value of the additional pseudorandom number generator 404.6 in the event of an error depends on previously correctly generated quantum random bits 411 of the quantum random number generator (28).

[0280] Feature 55: Method for generating a random bit

[0281] Generating a pulse sequence with random intervals by means of a photon source (54), in particular a silicon LED (54) and / or in particular a first SPAD diode (54), and a photon detector (55), in particular a second SPAD diode (55),

[0282] Generating (501) a first value in the form of a first pseudorandom number as a function of the time interval between a first pulse and a second pulse that is different from the first pulse; generating (501) a second value in the form of a second pseudorandom number as a function of the time interval between a third pulse that is different from the first pulse and a fourth pulse that is different from the first pulse and the second pulse and the third pulse.

[0283] Comparing (502) the first value with the second value and

[0284] Outputting (503) a first logical value as a quantum random bit (411) if the first value is greater than the second value, and

[0285] Outputting (503) a second logical value different from the first logical value as the random bit if the first value is less than the second value.

[0286] Feature 56: Method (3700) for generating a quantum random number QZ (418) with m quantum random bits (411) comprising the steps;

[0287] Generation (3710) of a random single photon stream 57, 58, 59, 44 from single photons by means of one or more photon sources, in particular one or more silicon LEDs (54) and / or one or more first SPAD diodes (54);

[0288] Transmission (3720) of the random single photon stream (57, 58, 59, 44), in particular by means of an optical waveguide 44 different from the semiconductor substrate (49, 48) and / or the semiconductor substrate or by direct transmission, to one or more photon detectors (55), in particular one or more second SPAD diodes (55);

[0289] Conversion (3730) of the random single photon stream (57, 58, 59, 44) into a detection signal by means of the one or more photon detectors (55);

[0290] Processing (3740) the detection signal into a processed detection signal;

[0291] Determining (3760) a first pseudorandom number as a function of a first time interval between a first pulse and a second pulse of a first pair of two successive pulses of the processed detection signal produced by coupling the emissions of the photon source (54) and the photon detector (55), and

[0292] Determining (3765) a second pseudorandom number as a function of a second time interval between a third pulse and a fourth pulse of a second pair of two successive pulses of the conditioned detection signal produced by coupling the emissions of the photon source (54) and the photon detector (55);

[0293] Determining (3770) the bit value of a quantum random bit (411) by comparing the value of the first pseudorandom number and the value of the second pseudorandom number; if the number (3780) n of the determined random bits is less than the desired number m of the random bits of the quantum random number QZ (418) to be generated, repeating the above steps (3710 to 3770) and terminating the process for generating a quantum random number if the number (3780) n of the determined random bits is greater than or equal to the desired number m of the random bits of the quantum random number to be generated

[0294] (418) QZ is.

[0295] Advantage

[0296] The monolithically integrable quantum random number generator 28 presented here is particularly robust against external attacks. Even in the event of a successful attack on the entropy source 401, the quantum random numbers 411 are not affected to such an extent that the attacker can break an encryption without considerable additional effort. The secure microcontroller presented here thus exhibits improved entropy of its random number generator. As a result, the encryption of this secure microcontroller is post-quantum secure, unlike the state of the art. However, the advantages are not limited to this.

[0297] List of characters

[0298] The above objects and the advantages described below will be highlighted in the description of a preferred embodiment of the invention, presented as a non-limiting example with reference to the accompanying drawings, in which:

[0299] Figure 1 shows a schematic block diagram of a data processing device in combination with a controlled system;

[0300] Figure 2 shows a schematic block diagram of a circuit for deactivating a test interface of the device of Figure 1;

[0301] Figure 3 shows a diagram illustrating the verification of digital signatures;

[0302] Figure 4 shows a flowchart illustrating the use of HASH functions in storing and retrieving data from a DRAM of the device of FIG. 1.

[0303] Figure 5 shows a proposed SPAD diode in cross section.

[0304] Figure 6 shows the combination of two proposed SPAD diodes in cross section.

[0305] Figure 7 shows the combination of two proposed SPAD diodes in cross section, with several insulation layers now forming the optical waveguide 44.

[0306] Figure 8 shows the integration of the SPAD diodes and the optical fiber into an evaluation and operating circuit

[0307] Figure 9 corresponds to Figure 8, which is now supplemented by monitoring circuits.

[0308] Figure 10 shows a typical output signal of the second SPAD diode. Figure 11 shows an example oscillogram of the voltage signal 404 of the entropy source 401.

[0309] Figure 12 shows the schematic flow of a server-client communication using a proposed quantum random number generator.

[0310] Figure 13 shows the schematic flow of the functions KeyExchangeServer() and KeyExchangeClient().

[0311] Figure 14 shows the schematic flow of the setPrimes() function.

[0312] Figure 15 shows the schematic flow of the function setE() 3400.

[0313] Figure 16 shows the schematic flow of the findD() function.

[0314] Figure 17 shows the schematic sequence of a secure transmission of quantum-based random numbers between a first processor 10-1 of the computer, in particular in the form of a proposed integrated circuit 2, a server 3600, and a first processor 10-1 of the computer, in particular in the form of another proposed integrated circuit 2, a client 3610.

[0315] Figure 18 shows schematically the proposed method 3700 for generating a quantum random number.

[0316] Figure 19 shows another exemplary proposal for a one-piece, monolithic integrated circuit 2.

[0317] Figure 20 shows a device similar to the device of Figures 8 and 9.

[0318] Figure 21 shows an example of a time-to-pseudorandom number converter 404.3. Figure 22 shows a diagram illustrating the detection of the pulses (2201, 2202, 2203, 2204) on the voltage signal 405 of the entropy source 401.

[0319] Figure 23 shows an exemplary voltage converter 91 for supplying the entropy source 411 with a sufficient operating voltage of the supply voltage line VENT of the entropy source 411 relative to the reference potential line GND at the reference potential.

[0320] Figure 24 shows, by way of example, a rough layout of an imaginary integrated circuit 2, for example a microcontroller, with a proposed quantum random number generator 28 in plan view to illustrate the placement of a quantum random number generator 28 in whole or in part in the pad frame 2403 or of a proposed entropy source 401 in the pad frame 2403.

[0321] ###########

[0322] Figure 25 shows a schematic representation of a first embodiment of a quantum random number generator according to the prior art in plan view;

[0323] Figure 26 shows a schematic representation of a second embodiment of a horizontal entropy source 401 according to the prior art in a side view;

[0324] Figure 1 shows a schematic representation of a BCD substrate provided by a method for providing deep pn junctions in a BCD process and a TCAD representation of the resulting dopant distribution;

[0325] Figure 28 shows a schematic representation of an exemplary first embodiment of an entropy source 401 according to the invention;

[0326] Figure 29 shows a schematic representation of an exemplary second embodiment of an entropy source 401 according to the invention; Figure 30 shows a schematic representation of an exemplary third embodiment of an entropy source 401 according to the invention;

[0327] Figure 31 shows a graphical representation of the dependence of the SPAD current (SPAD Current (A)) on the Zener reverse voltage (Zener Reverse Voltage (V)) at different SPAD reverse voltages (less than, equal to, greater than the breakdown voltage VBD) within an entropy source 401 according to the invention.

[0328] Figure 32 shows a graphical representation of the dependence of the ratio between

[0329] SPAD current and Zener current as a function of the Zener reverse voltage (V) at different SPAD reverse voltages (less than, equal to, greater than the breakdown voltage VBD) within an entropy source 401 according to the invention.

[0330] Description of the characters

[0331] The figures show, by way of example and in simplified form, essential parts of the proposed devices and methods. For illustrative purposes, specific examples constructed in accordance with the teachings of this disclosure will now be described with reference to the accompanying drawings, in which:

[0332] Detailed embodiments will now be described, which are illustrated by way of example in the accompanying drawings. The effects and features of these embodiments will be described with reference to the accompanying drawings. In the drawings, like reference numerals designate like elements, and redundant descriptions are omitted. The present disclosure may be embodied in various forms and should not be construed as limited only to the embodiments shown herein. Rather, these embodiments are examples so that this disclosure will be thorough and complete, and will fully convey the aspects and features of the present disclosure to those skilled in the art. Therefore, methods, elements, and techniques that are not necessary for a full understanding of the aspects and features of the present disclosure may not be described.In the drawings, the relative sizes of elements, layers and regions may be exaggerated for clarity.

[0333] As used herein, the term "and / or" includes all combinations of one or more of the listed elements. Furthermore, the use of "may" in describing embodiments of the present disclosure refers to "one or more embodiments of the present disclosure." In the following description of embodiments, the terms in the singular may also include the plural, unless the context clearly indicates otherwise.

[0334] Although the terms "first" and "second" are used to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the present disclosure. Terms such as "at least one of," when preceded by a list of elements, modify the entire list, not just the individual elements of the list.

[0335] Terms such as "substantially," "approximately," and similar terms are used as terms of approximation rather than degrees and are intended to take into account the inherent variations in measured or calculated values ​​that will be recognized by those skilled in the art. When the term "substantially" is used in connection with a characteristic that can be expressed by a numerical value, the term "substantially" means a range of at least + / - 5% of the value centered on the value.

[0336] DETAILED DESCRIPTION OF THE EMBODIMENTS OF THE INVENTION

[0337] In this example, the data processing device is a computer in the form of a monolithic, micro-integrated circuit 2, for example the microcontroller, for controlling a controlled system 26.

[0338] The following description first describes the configuration of an exemplary microcontroller as an example of a monolithic, microintegrated circuit 2 with a proposed quantum random number generator 28 and the exemplary contents of its various memories as they would be used after manufacture.

[0339] The computer in the form of the monolithic, microintegrated circuit 2, for example, the microcontroller, is connected to a controlled system 26 via a connector 3. The controlled system can be, for example, a backup tape drive. With a backup tape drive, it is important that the integrity of the backed-up data is maintained. It is therefore important that the integrity of the data and programs used by the computer in the form of the monolithic, microintegrated circuit 2, for example, the microcontroller, is maintained.

[0340] Figure 1

[0341] The computer in the form of the monolithic, microintegrated circuit 2, for example the microcontroller, comprises in the example of Figure 1, for example, the monolithic integrated circuit 2 of an exemplary microcontroller, which comprises, for example, a control device 4, a non-volatile memory 6 and a random access memory 8, hereinafter also referred to as RAM (Random Access Memory). The non-volatile memory 6 can comprise any suitable type, e.g., a flash memory and other types. In this example, it is a read-only memory, e.g., an EEPROM. The microcontroller here is only an exemplary embodiment of a one-piece and monolithic integrated circuit 2 with a monolithic integrated quantum random number generator 28. Other microelectronic integrated circuits 2 are expressly encompassed by the technical teaching of the document presented here.When this document refers to an "integrated circuit 2 of a microcontroller" or an "integrated circuit 2 of the microcontroller," the technically knowledgeable person automatically reads other microelectronic integrated circuits and devices. For the purposes of this document, these microelectronic integrated circuits and devices expressly include MEMS (micro-electro-mechanical system), MOEMS (also: MOMS) (micro-optical-electro-mechanical system), optical MEMS, optical microsystems, BioMEMS (standing for the application of MEMS to, for example, cell biology or related fields), micromachines, MEFS (micro-electro-fluidic systems), NEMS (nano-electro-mechanical system), pMEMS (piezo-electric micro-electro-mechanical resonators), and RF-MEMS (radio-frequency MEMS).

[0342] The document presented here therefore considers the term "microcontroller" to be used only as an example. The person skilled in the art will immediately understand the use of a quantum random number generator 28 with a time-to-pseudo-random number converter 404.3, as proposed here, in a monolithic co-integration with conventional micro-integrated circuits when referring to "integrated circuit 2 of the microcontroller," and expressly does not limit the technical teaching of this document to the co-integration of the proposed quantum random number generator 28 with a microcontroller.

[0343] Such other conventional integrated circuits 2 may include, for example:

[0344] - Microcontrollers, microprocessors, memories, DRAMs, SRAMs, RAMs, volatile memories, OTP memories, EEPROMs, flash memories, MRAMs, FRAM, bus transceivers, sensor evaluation circuits, motor driver circuits, control circuits for automotive control circuits, graphics controllers, communication circuits, evaluation circuits for biometric sensors, evaluation circuits for input devices, control circuits, chip card circuits, circuits for mobile phones or smartphones, circuits for servers.Circuits for PCs, circuits for laptops, circuits for access and / or access control systems, circuits for the coded recording of operating parameters, circuits for electronic security devices, radio system circuits, communication circuits, circuits for encryption and / or decryption systems, circuits for individualization and identification purposes and / or identification systems, circuits for gaming devices, circuits for simulation systems, circuits for computer systems, circuits for noise and / or signal sources, circuits for modulation systems and / or devices, circuits with a device for generating and / or using spreading codes. This list is certainly incomplete.

[0345] The random access memory 8 can be any suitable memory, e.g., an SRAM, but in this case, it is a DRAM. The non-volatile memory 6 and the random access memory 8 are located outside the control device 4 in the example of Figure 1. A further non-volatile memory 30 can optionally be provided within the microintegrated circuit outside the control device 4 and connected to it via an internal interface 301.

[0346] The microintegrated circuit 2 with the exemplary control device 4 is preferably a monolithic integrated circuit, which comprises, for example, one or more processors 10-1, 10-2; a tightly coupled memory 14, which may be, for example, an SRAM; a non-volatile boot ROM 16 containing a preferably non-modifiable code; a hashing engine 18, which may be present, for example; one or more one-time programmable memories (OTP) 20 and 22; a JTAG test interface 12; an interface 32; internal interfaces 63, 81, and 301 coupled to the memories 6, 8, and 30; a quantum random number generator 28, which the document presented here also refers to as QRNG (English abbreviation for Quantum Random Number Generator); and a hard-wired test deactivation circuit 24.The OTP memories 20 and 22 may be separate memories or portions of a memory within the exemplary integrated circuit 2. In this example, they are portions of a single memory. The test disabling circuit 24 is preferably located between the test port 12, which in this example is a JTAG port, and the processor(s) 10. The preferably present disabling circuit 24 responds to the data in the OTP memory portion 22. The optional hashing engine 18 uses data (one or more keys) in the OTP memory portion 20. The OTP memory portion 20 preferably stores critical security parameters (CSPs) including a secret key and at least one public key. Additional keys may be stored in the OTP memory portion 20.In one embodiment of the proposal of this example application of a quantum random number generator 28, the secret key is preferably unique for each instance of the exemplary microintegrated circuit 2 proposed here.

[0347] The processor(s) 10 preferably execute(s) instructions only from the tightly coupled memory 14 and from the DRAM 8 in the example presented here in Figure 1. The boundary of the control device 4 is a cryptographic virtual boundary, and the data and program execution within this boundary are considered secure in this first proposal for the application of a proposed quantum random number generator 28, as explained further below. The EEPROM 6 and the DRAM 8 (and the memory 30, if present) are located outside the cryptographic boundary, and without security measures, the contents of these memories would not be secure within the meaning of the document presented here. The interfaces 12, 63, 301, 32, and 81 are located at the physical and cryptographic boundary of the control device 4 within the microintegrated circuit 2.The document presented here thus discloses a microintegrated circuit 2 having internal interfaces 63, 301, 32, and 81 at a cryptographic boundary between a control device 4 and other parts (8, 30, 6) of the integrated microelectronic circuit 2 that are classified as non-secure or less secure. The essential purpose of these internal interfaces 63, 301, 32, and 81 is thus the secure shielding of an internal control device 4 within the microintegrated microelectronic circuit 2.

[0348] The contents of DRAM 8 and EEPROM 6 are preferably cryptographically protected by authentication codes. In this example, the authentication codes used in DRAM 8 are preferably of a different type than those used in EEPROM 6. In this example, the contents of EEPROM 6 are protected from undetected malicious modification at least through the use of digital signatures. The format of the data in EEPROM 6 is also preferably different from that in DRAM 8.

[0349] For example, the EEPROM 6 preferably stores the firmware arranged in one or more data records 61, each with a digital signature 62. The digital signatures used in this example of the proposal use public and private keys. Therefore, the details of the digital signatures will not be described further, as they are known to those skilled in the art. When a processor (10-1, 10-2) reads a data record from the EEPROM 6, the processor 10 checks its digital signature. If the digital signature is valid, the data record is processed by the processor(s) 10 using computer-implemented methods of the firmware. The processor(s) 10 thus preferably only executes validly signed firmware. For signing, the processors 10 preferably use keys and authentication codes that depend on quantum random numbers 418 from one or more quantum random number generators 28.

[0350] As shown in Figure 1, in one example, the boot ROM 16 contains code that the processor 10 uses to read a loader program S2 from the EEPROM 6 in order to read further data records from the EEPROM 6. Logic in the processor 10 loads a program counter (not shown) in the processor 10 with the starting address 15 of the boot ROM 16. The processor 10 then executes the code in the boot ROM 15. This boot ROM 15 code can read a computer-implemented loader program from the EEPROM 6. The boot code in the boot ROM 15 is considered secure because it is within the cryptographic boundary 4. The loader program is protected by a digital signature, which the processor 10 verifies when executing the boot ROM code S4 in the boot ROM 15 using the public key stored in the first OTP memory 20. Subsequent data records are read using the loader program S6.The loading program in EEPROM 6 and the subsequent data records are each provided with a digital signature and have one or more public keys embedded. When executing the loading code of the loading program in EEPROM 6, the processor 10 checks the signature of the data record newly read from EEPROM 6 in step S8 using a public key embedded in a previously loaded data record or a data record stored in OTP memory 20.

[0351] A data set read from EEPROM 6 may contain too much firmware code / data to be stored in the small, tightly coupled memory TCM 14 of the controller 4 within the microelectronic circuit 2. The TCM 14 preferably stores firmware code / data that is immediately required by the processor(s) 10. The remainder of the firmware data set is transferred to DRAM 8. Since DRAM 8 lies outside the cryptographic boundary 4, the code / data stored there is cryptographically protected by authentication codes generated by the processor 10, preferably using quantum random numbers from the quantum random number generator 28.

[0352] Figure 3

[0353] As shown in Figure 3, the processor 10 reads the data as a record from the EEPROM 6 and writes it as words into the DRAM 8 or reads these words from this DRAM 8. In this example, when the processor 10 reads a record from the EEPROM in step S20, the processor 10 validates it as described in Figure 4 and the associated description. The processor 10 stores at least part of the data of the record in the TCM 14 in step S21. The processor 10 processes the remaining data of the record, for example, as follows and stores it in the DRAM 8. The processor(s) 10 cooperates (work) with the optional hash engine 18 to calculate a hash value for each word of the remaining data, for example, in step S22 and to store the hash value in the DRAM 8 at a location associated with the stored word in step S24. The word size is selected according to the system constraints.It can be as small as one byte. In practice, it may be 32 bits. When the processor 10 reads a word from the DRAM 8 in step S26, the processor 10 and the hash engine 18 preferably recalculate the hash value and compare the recalculated hash value with the corresponding hash value stored in the DRAM 8 in step S30. If the hash values ​​have a predetermined relationship, which is checked in step S34, e.g., they are equal, the processor 10 processes the read data in a step S38. If the hash values ​​do not have the predetermined relationship, the processor 10 interrupts processing in step S36 and / or the processor 10 generates an error message and / or the processor 10 ignores the data / code.Storing words in DRAM 8 with corresponding authentication codes, preferably based on quantum random numbers from quantum random number generator 28, facilitates random access to the words by processor(s) 10.

[0354] The hash function can be any suitable hash function. An example is the well-known HMAC function. In this example, the HASH function uses the secret key stored in the OTP memory 20. It could also use a different key stored in the OTP memory. Preferably, the secret key is based on a quantum random number from the quantum random number generator 28. An example of the hash value is HMAC (address | | data | | secret key), where the character string " | | " stands for the concatenation. Taking into account the number of bytes that the DRAM 8 can store, the HASH value preferably comprises at least enough bits to avoid or at least reduce duplication of HASH values ​​in the DRAM 8. The number of bits of the HASH value is preferably at least 96 bits and can also be significantly larger.The industry standard is 160 bits, which reduces the probability of duplicate hash values ​​to a sufficiently low level.

[0355] By providing the cryptographic boundary 4 and protecting the data stored in DRAM 8 and EEPROM 6, the integrated circuit 2, particularly that of the microcontroller, is protected from unauthorized access to the programs and data used by the processor(s) 10 of the computer during normal operation. This is particularly important in the automotive sector to prevent counterfeiting and unauthorized spare parts, which typically require knowledge of the firmware of the illegally copied spare parts. However, the JTAG test interface 12 could allow access to the processor(s) 10 in a test mode using known EMULATE and TRACE routines and still permit illegal program modifications. The JTAG test port 12 is required for testing at least during the manufacturing process of the integrated circuit 2, for example, that of a microcontroller, and can be used for fault diagnosis after production.Such analysis capability of an integrated automotive circuit 2, for example an automotive microcontroller, is an indispensable prerequisite to meet the quality requirements of T16491.

[0356] In order to prevent unauthorized and in particular illegal use of the JTAG interface 12, the OTP memory 22 can, for example, comprise at least one security bit which, together with the blocking circuit 24, blocks the JTAG interface 12.

[0357] In one example, the OTP memory 22 contains only one bit. The OTP memory 22 allows a bit to change only once from one state, e.g., "0," to the opposite state, "1." During manufacture of the integrated circuit 2, e.g., the microcontroller, the bit is, for example, "0," enabling testing. In a final testing step, the manufacturer of the exemplary integrated circuit 2, e.g., the microcontroller, sets the bit to "1" before releasing the integrated circuit 2, e.g., the microcontroller, for delivery and use. The JTAG connector 12 typically has a serial input and a serial output (see Figure 2).The deactivation circuit, which is part of the circuit of the control device 4 within the integrated circuit 2, for example, the microcontroller, preferably comprises a gate 241, which is located, for example, between the serial output of the JTAG interface 10 and the processor(s) 10, and a gate 242, which is located between the serial input of the JTAG interface 10 and the processor(s) 10. The security bit "1" in the OTP memory 22 deactivates gates 241 and 242. Since the security bit cannot be changed, the test port is then protected against use after the manufacture and delivery of the integrated circuit 2, for example, the microcontroller.

[0358] In another example, the OTP memory 22 has a two-bit security code, initially "00." This allows for verification during manufacturing, after which the code is set to "01," meaning one of the two bits is set to "1." This "01" code disables gates 241 and 242. If an error occurs, the integrated circuit 2, for example, of the microcontroller, is returned to its manufacturer, who sets the other bit to "1," resulting in the code "11," which allows verification via port 12. Such verification is preferably destructive, as it does not allow resetting to the original value.Access to the OTP memory 22 to change the security code can be achieved using a suitable access code, preferably generated by a quantum random number generator 28, which is provided with a digital signature that can be verified by a quantum random number-based key stored in the OTP memory 20. The key can, for example, be the standard public key stored in the memory 20. This allows the security code to be changed to "11," which enables verification via the JTAG interface 12. The original integrated circuit 2, for example, the microcontroller, is preferably retained and preferably destroyed by the manufacturer, and the user receives a new integrated circuit 2, for example, a microcontroller.

[0359] In another example, the security code may consist of three or more bits that change when the signed access code is used. During manufacture, the code is "000" and when released to a user, it is "001." If an error occurs, the manufacturer changes the code to "011" to enable testing. After testing, the code is changed to "111," which secures the JTAG interface 12 against use and allows the integrated circuit 2, for example, of the microcontroller, to be returned to the user. Only a signed access code, provided with a digital signature verified by a key in the OTP memory 20, can be used to change the code stored in the OTP memory 22.

[0360] Security codes of two or more bits provide an audit trail for testing (or any unauthorized testing attempts) after manufacturing.

[0361] Additional interface and additional EEPROM

[0362] As shown in Figure 1, the control device 4 of the integrated circuit 2, for example, the microcontroller, can optionally have at least one further interface 32 in addition to the ports 3 and 12. This further interface 32 can be, for example, an Ethernet port or a Fibre Channel port or an automotive data bus port for data buses such as CAN, LIN, DSI3, or PSI5. A Fibre Channel port, as defined in the document presented here, is a data port that uses an optical fiber or other waveguide for electromagnetic radiation.

[0363] The integrated circuit 2, for example, the microcontroller, may additionally have another non-volatile memory 30 outside the control device 4 of the integrated circuit 2, for example, a microcontroller, which stores data cryptographically protected by a security parameter stored in the OTP memory 20. The other non-volatile memory 30 is coupled to the control device 4 via the internal interface 301 of the integrated circuit 2, for example, the microcontroller.

[0364] The additional non-volatile memory 30 can be an EEPROM, for example. The additional memory 30 can store additional critical security parameters outside of the control device 4. The additional parameters are preferably encrypted and provided with digital signatures to make them secure. The additional parameters are preferably encrypted with the secret key that is valid only for the control device 4 and stored in the OTP memory 20. The secret key is preferably based on a quantum random number from a quantum random number generator 28. The digital signatures of the additional parameters are created using the unique secret key stored in the OTP memory 20. This secret key is used to decrypt the additional security parameters and to verify the digital signatures read from the additional memory 30.

[0365] The additional non-volatile memory 30 can contain other encrypted and / or digitally signed data. Additional security parameters outside the control device 4 of the integrated circuit 2, for example, the microcontroller, can be used to secure the data and codes transmitted via the interface(s) 32.

[0366] Manufacturing of the integrated circuit 2, for example the microcontroller.

[0367] During the manufacture of the integrated circuit 2, for example the microcontroller, the boot code is preferably hard-coded in the boot ROM 16; the loader program and other codes / data are stored in the EEPROM 6 with digital signatures based on the public and private keys, preferably generated using quantum random numbers from a quantum random number generator 28; and preferably, at least one public key is generated using a quantum random number from a quantum random number generator and stored in the OTP memory 20.

[0368] The secret key is preferably only stored in the OTP 20 once the security code, which is preferably based on a quantum random number from a quantum random number generator 28, has been set in the OTP 22 and the test port of the exemplary JTAG interface 12 has been blocked. In the example presented here, the control device 4 of the integrated circuit 2, for example the microcontroller, contains the necessary quantum random number generator QRNG 28. The firmware stored in the tightly coupled memory 14 or in the DRAM 8 reads one or more quantum random numbers of, for example, 256 bits from the quantum random number generator 28 and stores them in the OTP 20 as a secret key, without this data leaving the control device 4, preferably within the integrated circuit 2, for example the microcontroller.This preferably occurs only after the test connection 12 has been deactivated, in order to prevent access to the secret key even for persons who have access to the manufacturing process. Preferably, the logic gates of the integrated circuit 2, for example, the microcontroller, or at least those of the control device 4 of the integrated circuit 2, for example, the microcontroller, are designed such that the current peaks occurring during changes in logical states within the circuits of the logic gates do not allow any conclusions to be drawn about the processes and / or the data and / or the quantum random numbers and / or the circuit states of the device. This avoids so-called side channels. For this purpose, the proposed device can comprise current sources, complementary switching, complementary dummy circuits, energy reserves (e.g., capacitors), etc.

[0369] The hash function of the hashing engine 18 can be any suitable hash function and is not limited to the HMAC example described above. The on-chip quantum random number generator 28 QRNG could be omitted from the integrated circuit 2, for example, the microcontroller, and instead an off-chip quantum random number generator QRNG could be used to generate the secret key during the manufacturing process. However, an on-chip quantum random number generator QRNG is significantly more secure.

[0370] The firmware stored in EEPROM 6 is preferably cryptographically protected, in this example by digital signatures. During production, the firmware is first compiled. It is then digitally signed with a secret private key of a private-public key system. The secret private key of the private-public key system is preferably based on a quantum random number from a quantum random number generator 28. The public key is preferably stored in the OTP memory 20 so that the signature can be verified. The signed firmware is stored in EEPROM 6. The digital signatures can be created by transmitting the compiled firmware to a secure signature generator during the production process. The secure signature generator can be the integrated circuit 2, for example of the microcontroller, specifically the control device 4 in cooperation with the quantum random number generator 28 itself.The signed firmware can be downloaded to EEPROM 6 via a communications connection, e.g., the Internet, if the signing is performed externally. However, processor 10 can remove the firmware signature before saving it to EEPROM 6 and replace it with its own quantum random number-based signature based on a quantum random number from its quantum random number generator 28, which then makes it impossible for anyone to read the firmware without exception.

[0371] Instead of an EEPROM, the non-volatile memory 6 may be any other suitable memory, for example a FLASH memory.

[0372] The further non-volatile memory 30 can be, for example, a serial EEPROM memory.

[0373] The one-time programmable OTP 22 memory, which contains the security code, can be replaced with another reprogrammable, non-volatile memory, and the security code can be changed using signed firmware. However, a memory 22 that can only be programmed once is more secure because its programming is irreversible.

[0374] The DRAM 8 can be further protected by making access to the DRAM 8 physically very difficult and detectable in the event of an attempt. For example, the connections between the DRAM 8 and the control device 4 can be buried in layers of the metallization stack of the integrated circuit 2, for example, the microcontroller, or protected in some other way against physical sensing (e.g., by e-beam). Preferably, the device parts of the control device 4 also comprise such sensing protection. In particular, it is advantageous if the quantum random number generator 28 has such sensing protection, for example, in the form of a metal layer 53, 142 at a predefined potential.

[0375] The entire integrated circuit 2, for example of the microcontroller, can be provided with such scanning protection, for example in the form of a metal layer 53, 142 at a predefined potential. The entire integrated circuit 2, for example of the microcontroller, can also be housed in a tamper-evident housing with tamper-evident seals.

[0376] The secure integrated circuit 2, for example of the microcontroller, preferably has at least one photon source 54 or a silicon LED 54 or a first SPAD diode 54 as a photon source for photons from the quantum random number generator 28. The secure integrated circuit 2, for example of the microcontroller, preferably has at least one photon detector 55 or a second SPAD diode 55. An optical system preferably optically couples the at least one photon source 54 or the silicon LED 54 or the first SPAD diode 54 to the photon detector 55 or the second SPAD diode 55 using these photons. The optical system can comprise an optical fiber 44. The quantum random number generator 28 is preferably a quantum process-based true random number generator (QRNG) 28. The quantum process-based true random number generator (QRNG) 28 preferably comprises a photon source 54 or a silicon LED 54 or.a first SPAD diode 54 as a light source for an optical quantum signal and a photon detector 55 or a second SPAD diode 55 as a photodetector for this optical quantum signal. Furthermore, the quantum process-based true random number generator (QRNG) 28 preferably comprises at least the processing circuit and, if applicable, the optical waveguide 44. Preferably, the optical waveguide 44, if present, optically couples the photon source 54 or the silicon LED 54 or the first SPAD diode 54 to the photon detector 55 or a second SPAD diode 55. An operating circuit supplies the photon source 54 or the silicon LED 54 or the first SPAD diode 54 with electrical energy such that the photon source 54 or the silicon LED 54 or the first SPAD diode 54 emit light. The emission of light requires that the operating voltage provides sufficient electrical bias for the photon source 54 or the silicon LED 54 or.the first SPAD diode 54. A processing circuit (402, 403, 404) detects the signal from the photon detector 55 or the second SPAD diode 55 and forms the quantum random number 418 therefrom. The processing circuit then preferably makes the quantum random number 418 thus formed available to one or more of the one or more processors 10 via a data bus 419. The semiconductor crystal of the integrated circuit 2, for example of the microcontroller, preferably has a surface 56. Typically, the semiconductor crystal has a semiconducting material below its surface 56. In particular, when using conventional semiconductor circuit manufacturing processes, such as CMOS processes, bipolar processes, BiCMOS processes, and BCD processes, the surface 56 of the semiconductor crystal typically has a metallization stack as structured metal layers and electrical insulation layers.The structured metal layers typically form the electrically conductive traces, which are electrically separated from one another by the insulation layers. Thus, the metallization stack typically has a structured, optically transparent, and electrically insulating layer 44. At least a portion of this typically structured, transparent, and electrically insulating layer 44 of the surface 56 preferably forms the optical waveguide 44.

[0377] The examples presented here in Figures 6 and 7 use a first SPAD diode 54 as photon source 54. In the examples in Figures 6 and 7, the first SPAD diode 54 radiates light 57 from the semiconducting material of the semiconductor substrate 49 into this optical waveguide 44. This means that, as a rule, the first SPAD diode 54 radiates perpendicular to the surface 56, essentially upwards, and not sideways into the semiconductor substrate 49 of the semiconductor crystal 49. The material of the semiconductor crystal 49 has a high attenuation for this light. Nevertheless, the emission of the photons 57 from the first SPAD diode 54 is not directed in the optical waveguide 44. In particular, the emission via the substrate 48, 49 is very attenuated, since visible light has a very high absorption.This arrangement allows the device to couple more photons from the first SPAD diode 54 directly to the second SPAD diode 55, which here serves as the photon detector 54 in the examples of Figures 6 and 7. In the examples of Figures 6 and 7, the optical waveguide 44 transports these photons 57, 58, 59 of the first SPAD diode 54 in the optical waveguide 44 to the second SPAD diode 55 with virtually no loss compared to other prior art solutions. In the examples of Figures 6 and 7, the optical waveguide 44 irradiates the second SPAD diode 55 with these photons 57, 58, 59 of the first SPAD diode 54 in such a way that the light 59 penetrates from within the optical waveguide 44 back into the semiconducting material of the semiconductor substrate 49 from the surface 56 and there strikes device parts of the second SPAD diode 55. The second SPAD diode 55 then generates a received signal depending on the irradiation with these photons 59.

[0378] Typically, at least one operating circuit in the examples of Figures 6 and 7 supplies the at least one first SPAD diode 54 with electrical energy, at least temporarily. When supplied with sufficient electrical energy, the at least one first SPAD diode 54 then feeds photons 57 into the optical waveguide 44 provided in Figures 6 and 7. The optical waveguide 44 then transports these photons 57, 58, 59 further. The optical waveguide 44 provided in the examples of Figures 6 and 7 then radiates the transported photons 58 as essentially vertically moving photons 59 into the second SPAD diode 55. Since this transport of photons from the first SPAD diode 54 to the second SPAD diode 55 loses significantly fewer photons than in other prior art designs that use the highly absorbing semiconductor substrate 49, 49 due to the low attenuation in the optical waveguide 44, the quantum efficiency is massively higher.This increases the bit rate of the quantum random bits 411 with which the device can generate quantum random numbers 418. Therefore, in the design presented here, a pair consisting of a single first SPAD diode 54 and a single second SPAD diode 55 is sufficient. Other prior art devices typically use multiple SPAD diodes.

[0379] In a further development of the proposed secure integrated circuit 2, for example of the microcontroller, at least one data interface of the one or more data interfaces 64 is a wired automotive data bus interface 64. In this case, the wired automotive data bus interface 64 can be, for example, a CAN data bus interface or a CAN-FD data bus interface or a Flexray data bus interface or a PSI5 data bus interface or a DSI3 data bus interface or a LIN data bus interface or an Ethernet data bus interface or an SPI data bus interface or a MELIBUS data bus interface.

[0380] In a further development of the proposed secure integrated circuit 2, for example, the microcontroller, at least one data interface 64 of the one or more data interfaces 64 is a wireless data bus interface. The wireless data bus interface 64 can be, for example, a WLAN interface or a Bluetooth interface.

[0381] In a further development of the proposed secure integrated circuit 2, for example of the microcontroller, at least one data interface 64 of the one or more data interfaces 64 is a wired data bus interface 64. The wireless data bus interface 64 can be, for example, a KNX data bus interface or an E1 B data bus interface or a DALI data bus interface or a PROFIBUS data bus interface.

[0382] Although the proposed device is described by way of example with reference to a

[0383] Although the control device 4 and the integrated circuit 2, for example, of the microcontroller, have been described, it is not limited to a control device 4 or the integrated circuit 2, for example, of the microcontroller. The proposed device can also be applied to other types of integrated circuit processors and other integrated circuits. A microprocessor is only a particularly advantageous, because complex, example of a proposed exemplary integrated circuit 2.

[0384] The embodiments of the proposed device store data inside and, if necessary, also outside the integrated circuit 2, for example, the microcontroller. The embodiments of the proposal ensure that the data to be processed, including the executable code, cannot be modified by unauthorized persons accessing the data stored outside the integrated circuit 2, for example, the microcontroller, or, if such access occurs, ensure that this access and / or attempted access does not go unnoticed and that the data and / or program codes and / or keys and / or authentication data, etc., cannot be modified unnoticed.Security is ensured by security data, and the security data itself is secure because it is stored within the integrated circuit 2, for example the microcontroller, in a protected area 4 and protected from unauthorized access.

[0385] The description presented here is not exhaustive and does not limit this disclosure to the examples shown. Other variations to the disclosed examples can be understood and practiced by those having ordinary skill in the art, based on the drawings, the disclosure, and the claims. The indefinite articles "a" or "an" and their inflections do not exclude a plurality, while the mention of a certain number of elements does not exclude the possibility of more or fewer elements being present. A single unit may perform the functions of several elements mentioned in the disclosure, and conversely, several elements may perform the function of a unit. Numerous alternatives, equivalents, variations, and combinations are possible without departing from the scope of the present disclosure.

[0386] Unless otherwise stated, all features of the present invention can be freely combined with one another. This applies to the entire document presented here. The features described in the description of the figures can also be freely combined with the other features as features of the invention, unless otherwise stated. A restriction of individual features of the exemplary embodiments to combination with other features of the exemplary embodiments is expressly not intended. Furthermore, physical features of the device can also be reformulated as method features, and method features can be reformulated as physical features of the device. Such a reformulation is therefore automatically disclosed.

[0387] In the foregoing detailed description, reference is made to the accompanying drawings. The examples in the description and drawings should be considered illustrative and not limiting of the specific example or element described. Multiple examples may be derived from the foregoing description and / or drawings and / or the claims by modifying, combining, or varying certain elements. Furthermore, examples or elements not described verbatim may be derived from the description and / or drawings by a person skilled in the art.

[0388] Figure 6

[0389] The secure integrated circuit 2, for example of the microcontroller, has, in the example of Figure 6, at least one first SPAD diode 54 and at least one second SPAD diode 55, and at least one optical waveguide 44. The quantum random number generator 28 is preferably a quantum process-based true random number generator (QRNG) 28. In the example of Figure 6, the quantum process-based true random number generator (QRNG) 28 comprises a first SPAD diode 54 as a light source for an optical quantum signal and a second SPAD diode 55 as a photodetector for the optical quantum signal. Furthermore, the quantum process-based true random number generator (QRNG) 28 in the example of Figure 6 comprises at least the processing circuit and the optical waveguide 44.In the example of Figure 6, the optical waveguide 44 preferably optically couples the at least one first SPAD diode 54 to the at least one second SPAD diode 55. In the example of Figure 6, an operating circuit supplies the first SPAD diode 54 with electrical energy such that the first SPAD diode 54 emits light 57. In the example of Figure 6, the emission of light 57 requires that the operating voltage provides a sufficient electrical bias to the first SPAD diode 54 (404.1). In the example of Figure 6, a processing circuit (402, 403, 404) detects the signal of the second SPAD diode 55 (404.3) and forms the quantum random number 418 therefrom. The processing circuit then preferably makes the quantum random number 418 thus formed available to one or more of the one or more processors 10 via a data bus 419.

[0390] Preferably, the semiconductor crystal 49 of the control device 4 of the integrated circuit 2, for example, the microcontroller, has a surface 56. Typically, the semiconductor crystal 49 has a semiconducting material beneath its surface 56. Particularly when using conventional semiconductor circuit manufacturing processes, such as CMOS processes, bipolar processes, BiCMOS processes, and BCD processes, the surface 56 of the semiconductor crystal 49 typically has a metallization stack as structured metal layers and electrical insulation layers. The structured metal layers typically form the electrically conductive traces, which are electrically separated from one another by the insulation layers. Thus, the metallization stack typically has a structured and optically transparent and electrically insulating layer 44.At least a portion of this typically structured, transparent and electrically insulating layer 44 of the surface 56 preferably forms the optical waveguide 44.

[0391] In the example of Figure 6, the first SPAD diode 54 radiates light 57, for example, from the semiconducting material of the semiconductor substrate 49 into this optical waveguide 44. This means that in the example of Figure 6, the first SPAD diode 54, in contrast to other prior art devices, radiates perpendicular to the surface 56, essentially upwards, and not sideways into the semiconductor substrate 49 of the semiconductor crystal, which has high attenuation. Nevertheless, the emission of the photons 57 from the first SPAD diode 54 is not directed in the optical waveguide 44. In particular, the emission via the substrate 48, 49 is very attenuated, since visible light has a very high absorption. As a result, the device of Figure 6 can couple more photons from the first SPAD diode 54 directly to the second SPAD diode 55 compared to prior art devices.The optical waveguide 44 transports these photons 57, 58, 59 from the first SPAD diode 54 in the example of Figure 6 in the optical waveguide 44 to the second SPAD diode 55 with virtually no loss compared to other prior art devices. The optical waveguide 44 irradiates the second SPAD diode 55 with these photons 57, 58, 59 from the first SPAD diode 54 in the example of Figure 6 in such a way that the light 59 penetrates from within the optical waveguide 44 back into the semiconducting material of the semiconductor substrate 49 from the surface 56 and there strikes device parts of the second SPAD diode 55. The second SPAD diode 55 then generates a received signal in the example of Figure 6 as a function of the irradiation with these photons 59.

[0392] Typically, in the example of Figure 6, at least one operating circuit supplies the at least one first SPAD diode 54 with electrical energy at least temporarily. In the example of Figure 6, the at least one first SPAD diode 54 then feeds photons 57 into the at least one optical waveguide 44 when supplied with sufficient electrical energy. In the example of Figure 6, the optical waveguide 44 then transports these photons 57, 58, 59 further. In the example of Figure 6, the at least one optical waveguide 44 then radiates the transported photons 58 as essentially perpendicularly moving photons 59 into the second SPAD diode 55.Since this transport of photons from the first SPAD diode 54 to the second SPAD diode 55 in the example of Figure 6 loses significantly fewer photons than in other prior art designs that use the highly absorbing semiconductor substrate 48, 49 due to the low attenuation in the optical waveguide 44, the quantum efficiency is massively higher. Thus, in a device according to the example of Figure 6, the quantum random bit rate that can be generated, with which the device can in turn generate quantum random numbers, increases. Therefore, in the design presented here in Figure 6, a pair consisting of a single first SPAD diode 54 and a single second SPAD diode 55 is typically sufficient. Prior art devices typically use multiple SPAD diodes.

[0393] Figure 7 Figure 7 essentially corresponds to Figure 6. In contrast to Figure 6, the semiconductor crystal 49 and the epitaxial layer 48 are now covered with a first optically transparent insulator layer, for example an oxide layer 143. In the example of Figure 7, the vias 140 are filled with electrically conductive metal. In the example of Figure 7, the metallization level 1 with the electrical lines of the first wiring level 141 contact these vias 140. In the example of Figure 7, a second optically transparent insulation layer 144, preferably likewise in the form of an oxide layer, is applied to this first insulation layer 142 and the first metallization layer with the first wiring level 141.This layer can also be plated through vias (not shown in Figure 7), so that lines of the first metallization level can be connected to lines of the second metallization level in the example of Figure 7. The interface 145, shown in dashed lines, between the first optically transparent insulation layer 143 and the second optically transparent insulation layer 144 is also essentially optically transparent in the example of Figure 7 and preferably does not reflect and / or absorb the light of the first SPAD diode 55. In the example of Figure 7, the first optically transparent insulation layer 143 and the second optically transparent insulation layer 144 essentially form the optical waveguide in the region of the first SPAD diode 54 and the second SPAD diode 55.In the example of Figure 7, there are preferably no vias 140 and no metal lines 141 in the optical path between the first SPAD diode 54 and the second SPAD diode 55, so that the light from the first SPAD diode 54 can reach the second SPAD diode 55 unhindered. A metal cover 142 prevents photons from escaping upwards in the example of Figure 7 and preferably reflects them back into the optical waveguide 44 in the example of Figure 7. The vias 140 and the metal lines of the first metallization level 141 similarly prevent light from the optical waveguide 44 from being lost horizontally in the metallization stack in the example of Figure 7. Figure 8.

[0394] Figure 8 shows schematically the simplified block diagram of a quantum-based random generator

[0395] (Quantum Random Number Generator 28) as proposed in this document.

[0396] A preferably common system clock 2106 preferably clocks the digital circuits of the device illustrated by way of example in Figure 8. The quantum random number generator 28 of Figure 8 is preferably part of the control device 4 and thus of the integrated circuit 2, for example, the microcontroller. The structure of the quantum random number generator 28 includes an entropy source 401, in the example of Figure 8, a broadband 40 dB high-frequency amplifier 402 or the like, and an analog-to-digital converter 403, which may also be just an inverter or the like. In experiments, an analog-to-digital converter 403 with a resolution of 14 bits and a sampling rate of 125 MS / s and with an evaluation device 404 was successfully used.

[0397] In the example of Figure 8, the entropy source 401 of the quantum random number generator 28 comprises an array 54 of single photon avalanche diodes (SPAD) 54 as photon sources 54 and an array 55 of single photon avalanche diodes (SPAD) 55 as photon detectors 55. It may also be a single common array. The voltage converters 91 of the integrated circuit 2, for example, the microcontroller, supply the first SPADs 54 of the array 54 of single-photon avalanche diodes (SPADs) of the quantum random number generator 28, which serve as photon sources 54, and the second SPADs 55 of the array 55 of single-photon avalanche diodes (SPADs) of the quantum random number generator 28, which serve as photon detectors 55, preferably with an operating voltage such that they are preferably in the so-called Geiger mode. The operating voltage of these SPAD diodes 54, 55 is then above the breakdown voltage.The SPAD diodes 54, 55 are then preferably connected in reverse direction. Additionally, a quenching resistor 401.4 is preferably connected in series with each SPAD diode 54, 55. The quenching resistor 401.4 prevents thermal destruction of the respective SPAD diode 54, 55 in the event of a triggered charge carrier avalanche. The respective quenching resistor 401.4 of Figure 8 simultaneously serves as a shunt resistor for detecting the electrical diode current through the SPAD diodes 54, 55. The current signal of the second single-photon avalanche diode 55 of the array 55 of single-photon avalanche diodes (SPAD) is measured via a shunt resistor 401.4 for these second SPAD diodes 55. In the example shown in Figure 8, the series resistor for limiting the current through the respective SPAD diodes forms the shunt resistor 401.4. However, the shunt resistor 401.4 can be inserted into the supply line of the respective SPAD diodes 54, 55 independently of the quenching resistor 401.4.An exemplary common array of SPAD diodes in the example of Figure 8 comprises, for example, four active first SPAD diodes 54 and twelve passive second SPAD diodes 55. The exemplary four active first SPAD diodes 54 and twelve passive second SPAD diodes 55 are preferably coupled via an optical waveguide (optical waveguide 44). The active first SPAD diodes 54 spontaneously and randomly emit individual light pulses 57. They correspond to the first SPAD diode 54 in Figures 6 and 7. The active first SPAD diodes 54 are preferably located inside the array of first and second SPAD diodes 54 and 55. The proposed device supplies the active first SPAD diodes 54 with an increased supply voltage by means of its voltage converters. For this purpose, the proposed device preferably uses particularly voltage-stable DMOS transistors in these voltage converters.It is therefore particularly advantageous if the one-piece, micro-integrated quantum random number generator 28 is manufactured using BCD semiconductor technology, which typically allows the production of CMOS circuits, SPADs, and DMOS transistors simultaneously in a cost-effective and chip-area-effective manner. The proposed device therefore preferably operates the active, first SPAD diodes 54 in the example of Figure 8 well above the breakdown voltage of the first SPAD diodes 54. This operation at an increased supply voltage of the first SPAD diodes 54 increases the dark count rate of these first SPAD diodes 54, which leads to a higher number of spontaneously emitted photons 57. The optical waveguide 44 transmits some photons 58 of the emitted photons 57 to the passive, second SPAD diodes 55 in the example of Figure 8. The optical waveguide 44 corresponds to the optical waveguide 44 of Figures 6 and 7.The passive, second SPAD diodes 55 correspond to the second SPAD diode 55 in Figures 6 and 7. One or more voltage converters of the proposed device supply the passive, second SPAD diodes 55 in the example of Figure 8 with an increased supply voltage. For this purpose, the proposed device also preferably uses particularly voltage-resistant DMOS transistors in these voltage converters. Therefore, it is particularly advantageous if the one-piece, micro-integrated quantum random number generator 28 is manufactured using BCD semiconductor technology, which typically allows the simultaneous production of CMOS circuits, SPADs, and DMOS transistors in a cost-effective and chip-area-effective manner. The proposed device operates the passive, second SPAD diodes 55 only just above the breakdown voltage. Preferably, the passive, second SPAD diodes 55 are arranged as a ring around the active, first SPAD diodes 54 in the example of Figure 8.Other arrangements are conceivable. In particular, it is conceivable to replace the first SPAD diodes 54 with other silicon LEDs and to use an arrangement of such other silicon LEDs and second SPAD diodes 55 close to one another, in which case the light transmission takes place directly through the semiconductor substrate 49 as an optical waveguide 44 with an extremely short light transmission path of only a few pm. In the example of Figure 8, the passive, second SPAD diodes 55 detect at least a portion of the photons 59 arriving via the optical waveguide 44. The passive, second SPAD diodes 55 generate a current flow via a shunt resistor associated with the second SPAD diodes 55 depending on the incoming photons 59. In the example of Figure 8, the entropy source 401 preferably comprises the shunt resistors, the operating device of the SPAD diodes, the SPAD diodes 54 and 55, and the optical fiber 44.A voltage signal 405 from the entropy source 401 preferably connects the entropy source 401 to a preferred, exemplary, broadband 40 dB high-frequency amplifier 402. In other embodiments of the proposal, this 40 dB high-frequency amplifier 402 is not required. Therefore, the 40 dB high-frequency amplifier 402 is optional. The voltage signal preferably corresponds to the voltage drop across the quenching resistor 401.4, which in the example of the figure functions as a shunt resistor 401.4. It is conceivable to supply the first SPAD diodes 54 and the second SPAD diodes 55 via a common quenching resistor 401.4, which then also functions as a common shunt resistor. The proposed exemplary radio frequency amplifier 402 preferably and exemplarily has a bandwidth of 30 to 4000 MHz and preferably a 1 dB compression point of 20 dBm.In tests conducted in connection with the development of the technical teachings of the document presented here, the voltage swing of the voltage signal 405 of the entropy source 401 was in the sub-millivolt range. The exemplary high-frequency amplifier 402, for example, amplifies the voltage swing of this voltage signal 405 of the entropy source 401 to an exemplary range of 50 to 150 mV.

[0398] An amplifier output signal 406 of the high-frequency amplifier 402 connects, for example, the exemplary high-frequency amplifier 402 to an exemplary evaluation device 404, which essentially comprises subdevices of the control device 4. The evaluation device 404 of Figure 8 is only one of many different implementation options of the technical teaching presented in this document. The evaluation device 404 is preferably part of the integrated circuit 2, for example, the microcontroller. The integrated circuit 2, for example, the microcontroller, preferably comprises one or more processors 10-1, 10-2. In the examples of Figures 8 and 9, the evaluation circuit 404 has an exemplary 14-bit analog-to-digital converter (ADC) 403 with an exemplary sampling rate of 125 megasamples / s and an exemplary bandwidth of 50 MHz.During development, it has been shown that smaller bit widths and lower sampling rates are possible. If necessary, analog preprocessing prior to digitization by the analog-to-digital converter 403 using pulse broadening circuits 2022 may be appropriate. The amplified voltage signal of the exemplary high-frequency amplifier 402 is the amplifier output signal 406 of the high-frequency amplifier 402. The analog-to-digital converter 403 samples the amplifier output signal 406 of the high-frequency amplifier 402 at a sampling rate of the analog-to-digital converter 403. The sampling rate preferably depends on the system clock 2106. Typically, the sampling rate of the analog-to-digital converter 403 is equal to the frequency of the system clock 2106.The analog-to-digital converter 403, for example, digitally transmits the determined sample values ​​of the amplifier output signal 406 of the high-frequency amplifier 402 with a bus width of, for example, 14 bits to the evaluation device 404. A proposal is also described below that operates without the high-frequency amplifier 402 and provides an analog-to-digital converter 403 with a bit width of 1.

[0399] The device shown in simplified form in Figure 8 includes, by way of example, a comparator 404.2, a time-to-pseudo-random number converter (TPRC) 404.3, an entropy extraction device 404.4 and a finite state machine 404.8.

[0400] In the example of Figure 8, the comparator 404.2 compares the exemplary digital 14-bit value 407 of the analog-to-digital converter 403 with a constant 404.1, which represents a threshold value, and generates a two-clock-long 1-bit output pulse on its output signal 409 of the comparator 404.2 if the output value of the analog-to-digital converter 403 is greater than the constant 404.1. In the case of a device without a high-frequency amplifier 402 and with an analog-to-digital converter 403 with a bit width of 1, the comparator 404.2 and the constant 404.1 are omitted, and the analog-to-digital converter 403 immediately generates the output signal 409 of the comparator, since the analog-to-digital converter 403 then also fulfills the function of the comparator 404.2. The disadvantages of such a design include its reduced flexibility and increased design and production requirements. The output signal 409 of comparator 404.2 connects to comparator 404.2 with the time-to-pseudorandom number converter 404.3 (TPRC). The time-to-pseudorandom number converter 404.3 (TPRC) preferably comprises, for example, a linear feedback 32-bit shift register that counts up with the system clock 2106 of the integrated circuit 2, for example, the microcontroller. The oscillator 30 and the clock system of the control device 4 typically provide this clock. The bit width of this linear feedback shift register can vary depending on the application. This bit width is preferably adjustable via a register of the control device 4 of the integrated circuit 2, for example, the microcontroller. The feedback polynomial of the linear feedback shift register of the time-to-pseudorandom number converter 404.3 (TPRC) is preferably adjustable via a register of the control device 4 of the integrated circuit 2, for example, the microcontroller. For example, the system clock 2106 can have a frequency of 125 MHz.A pulse on the 1-bit output signal of comparator 404.2 preferably causes time-to-pseudorandom number converter 404.3 (TPRC) to output the current shift register value of the linear feedback shift register of time-to-pseudorandom number converter 404.3 (TPRC) as a pseudorandom number at output 410 of time-to-pseudorandom number converter 404.3 (TPRC). The pseudorandom numbers typically change with the clock period of system clock 2106, resulting in a time resolution with respect to the pulses on the 1-bit output signal of comparator 404.2. For an exemplary 125 MHz system clock 2106, this results in a time resolution of 1 / (125 MHz)=8 ns. The output 410 of the time-to-pseudorandom number converter.

[0401] 404.3 (TPRC) passes the exemplary 32-bit shift register value, also called raw data, of the time-to-pseudorandom number converter 404.3 (TPRC) to the entropy extraction following in the signal path

[0402] 404.4 continues. Entropy extraction 404.4 converts the random raw data RD of the time-to-pseudorandom number converter 404.3 (TPRC) on the signal at output 410 of the time-to-pseudorandom number converter 404.3 (TPRC) into a 1-bit random number 411 RN. The raw data at the signal at output 410 of the time-to-pseudorandom number converter 404.3 (TPRC) typically represents the last shift register value at which the output signal 409 of the comparator 404.2 exhibited a pulse. The output 411 of entropy extraction 404.4 is connected to the input of the finite state machine FSM 404.8.

[0403] The finite state machine 404.8 typically has the task of receiving data in the form of a serial stream of quantum random bits 411 from the entropy extraction 404.4, converting the serial stream of random data bits into random data words, and storing these in the RAM block 404.9 of the evaluation device 404, which is typically the volatile memory. The finite state machine 404.8 preferably communicates with the processor 404.11 (10-1, 10-2) via an internal data bus 419. After a successful write operation, the finite state machine 404.8 sets a finish flag 404.10. The processor 404.11 can preferably write and / or read the finish flag 404.10 via the internal data bus 419. The finish flag 404.10 may be part of RAM 404.9 or a register of processor 404.11. Processor 404.11 preferably controls and monitors finite state machine 404.8 via internal data bus 419. The finish flag 404.10 is preferably not set at system startup.The processor 404.11 can then access the RAM block 414.9, for example, using a C program started on the embedded processor 404.11, for example, a dual-core Arm Cortex-A9 MPCore, and read the random number from the RAM 404.9. The processor 404.11 is preferably identical to the first processor 10-1 of Figure 1. The processor 404.11 can, for example, be a dual-core Arm Cortex-A9 MPCore. The processor 404.11 can also execute some of the functions of the sub-devices of the evaluation device 404 using a suitable program and thus replace these device components if necessary.

[0404] Preferably, the processor 404.11 controls a watchdog 404.5. In the sense of the document presented here, the watchdog 404.5 is not only a watchdog timer, but also comprises a timer that is clocked with the system clock of the quantum random number generator 28 or the system clock 2106 of the processor 404.11 and that must be reset to a starting value by the processor 404.11 at regular intervals to prevent the program execution of the processor 404.11 from being interrupted when a watchdog counter reading threshold is reached and / or crossed by the counter reading of the timer of the watchdog 405.5. The watchdog 405.5 also performs further monitoring tasks within the quantum random number generator 28. For example, the watchdog 404.5 preferably monitors the entropy of the quantum random bits 411. In particular, the watchdog 404.5 preferably ensures that the quantum random bits 411 preferably do not have more than q consecutive random bits of the same logical value. If this is the case, the watchdog 404.5 preferably inserts other bits instead of the quantum random bits 411 into this serial bit data stream from the entropy extraction 404.5 to the finite state machine 407.8. More on this in the following Figure 9. In this case, the watchdog 404.5 preferably inserts random bits from another true random number generator and / or another quantum random number generator and / or pseudorandom bits from a pseudorandom number generator whose starting value is determined by valid random bits from a quantum random number generator (QRNG) or a true random number generator (TRNG). Since the time-to-pseudorandom number converter 404.3 (TPRC) already ensures by design that this case should not occur, the watchdog returns 404.5 preferably issues an error message to processor 404.11 in such a case. Preferably, watchdog 404.5 is also simultaneously a watchdog for the first processor 10-1. Furthermore, watchdog 404.5, as defined in the document presented here, monitors other variables, such as the agreement of voltage values ​​within quantum random number generator 28 and / or within the device by means of one or more analog-to-digital converters and / or by means of one or more voltage monitoring devices such as voltage monitors 413, etc.

[0405] Figure 9

[0406] Figure 9 shows the expanded exemplary evaluation device 404, which now includes monitoring of the random number 411 RN and has an additional backup system for the event of a fault, in order to ensure the security of the application circuit by means of an emergency operation procedure even in the event of a failure of the quantum random number generator. For better clarity, the components processor 404.11, RAM 404.9, and finish flag 404.10 have been omitted. The reader should still consider these device parts or functions to be present in Figure 9. However, the person skilled in the art can easily copy the connection to the finite state machine 404.8 from Figure 8 into Figure 9 and then arrive at the disclosed technical teaching. The watchdog 404.5, an optional additional linear feedback shift register 404.6 as backup pseudorandom number generator PRNG and a signal multiplexer 404.7 extend the device of Figure 8 to the device of Figure 9.The output 411 of the entropy extraction 404.4 is now connected to the watchdog 404.5 and the signal multiplexer 404.7, as an example. The watchdog 404.5 monitors the quantum random number RN at the output 411 of the entropy extraction 404.4. According to the proposed method, the watchdog 404.5 detects at least three defined error cases. For this purpose, the watchdog 404.5, for example, passes valid quantum random bits 411 to the optional additional linear feedback shift register 404.6, generating a seed value S 412. Preferably, the watchdog 404.5 prevents the finite state machine 404.8 from using these valid quantum random bits. If an error occurs, the watchdog 404.5 sets error bits in a non-drawn error register ER of the processor 404.11. Which error bit Watchdog 404.5 sets in the error register of processor 404.11 preferably depends on the specific error detected by Watchdog 404.5. Watchdog 404 is also5 is connected to a voltage monitor 413 via one or more, preferably digital, input / output signal lines 414 in the example of Figure 9. Preferably, the watchdog circuit 404.5 monitors the voltage values ​​determined by the voltage monitor 413. It has proven useful for the voltage monitor 413 to determine and monitor not only the voltages in the quantum random number generator 28, but also other voltages within the respective application circuit. The voltage monitor 413 can be the aforementioned analog-to-digital converter.

[0407] In the example of Figure 9, the voltage monitor 413 preferably monitors the operating voltages of the entropy source 401 and / or other voltages generated by voltage converters within the application circuit. For example, if one of the operating voltages of a photon source 54 and / or a silicon LED 54 and / or a first SPAD diode 54 and / or a photon detector 55 and / or a second SPAD diode 55 is too low, i.e., if the voltage value is below a lower operating voltage threshold for these components, or too high, i.e., if the voltage value is above an upper operating voltage threshold for these components, the voltage monitor 413 detects this voltage deviation and reports it to the watchdog 404.5 and / or the processor 10-1, 404.11. Preferably, the processor 404.11 reads the values ​​of the voltage monitor 413 via the internal data bus 419 of the control device 4 of the integrated circuit 2, for example, the microcontroller. In the event of such a voltage deviation, the voltage monitor 413 signals such a deviation to the watchdog 404.5 or directly to the processor 404.11. In the event of a signal to the watchdog 404.5, the watchdog 404.5 can, for example, generate an interrupt signal 420 for the processor 404.11. The watchdog 404.5 can, for example, trigger such an interrupt 420 of the microcontroller 404.11 or another sub-device of an application system if the supply voltage of the entropy source 401 or the high-frequency amplifier 402 or another device part of the quantum random number generator QRNG 28 and / or the integrated circuit 2, for example, the microcontroller, and / or the application device is faulty. The watchdog has 404.5 detects an error in the quantum random number generator 28, it preferably causes the quantum random number generator 28 to switch to an emergency operating state. To do so, the watchdog 404.5 preferably sets the selection signal 416 of a signal multiplexer 404.7, so that the signal multiplexer 404.7, instead of the output 411 of the entropy extraction 404.4, applies the pseudorandom number PRN of the optional additional linear feedback shift register 404.6 in the form of a stream of pseudorandom bits via a pseudorandom signal line 417 to the input of the finite state machine 404.8 as a replacement for the at least potentially faulty random number RN of the output 411 of the entropy extraction 404.4.

[0408] In the example of Figure 9, the optional additional linear feedback shift register 404.6 is connected to the output Seed S 412 of the watchdog 404.5. In the event of an error, the watchdog 404.5 activates the optional additional linear feedback shift register 404.6. The optional additional linear feedback shift register 404.6 then generates pseudorandom numbers PRN as the pseudorandom number generator PRNG. The Seed S 412 preferably contains the last valid quantum random bits. The watchdog 404.5 preferably applies these last valid quantum random bits 411 to the input of the optional additional linear feedback shift register 404.6. The seed S thus serves as a random PQC secure starting value for the generator polynomial of the feedback of the optional, further linear feedback shift register 404.6 for the generation of the pseudorandom number PRN and its signaling via the pseudorandom signal line 417.The generator polynomial and the degree of the generator polynomial can preferably be freely selected.

[0409] The signal of output 411 of entropy extraction 404.4 with the 1-bit random number RN of entropy extraction 404.4, or the signal of pseudorandom signal line 417 with the pseudorandom number PRN of linear feedback shift register 404.6, are connected to the inputs of signal multiplexer 404.7. Depending on the value of selection signal 416 SEL, signal multiplexer 404.7 forwards one of the two inputs to finite state machine 404.8. Of course, it is conceivable to use a multiplexer with more than two inputs and a more complex control signal if the application requires it. The number of inputs of signal multiplexer 404.7 is therefore typically greater than or equal to two.

[0410] Here, too, the finite state machine 404.8 is tasked with receiving the random data RN or the pseudorandom number PRN at the output of the signal multiplexer 404.7 and writing it to the RAM block 404.9, 15 of the evaluation device 404 within the control device 4. If the write operation is successful, the finite state machine 404.8 again sets the finish flag 404.10. The processor 404.11 can then access the RAM block 404.9, for example, using a C program, which preferably runs on the embedded processor 404.11, and read the random number and use it, for example, for encryption.

[0411] Preferably, the time-to-pseudo-random number converter 404.3 records the time between two pulses on the output signal 409 of the comparator 404.2 as a time value. If a time value at the output 410 of the time-to-pseudo-random number converter 404.3 is less than a minimum value, this is a value that lies within the dead time of the second SPAD diodes 55. The evaluation device 404 preferably discards the generated pseudo-random numbers upon occurrence of such a value and preferably increments the error counter by the first error step size, which can also be negative. In this case, the entropy extraction 404.4 waits for the next random number to be determined by the time-to-pseudo-random number converter 404.3. Once the random bit has been extracted in this way, the quantum random number generator 28 starts the process again.

[0412] If the error counter crosses or reaches the error counter threshold, an error may occur, for example, in which the time-to-pseudorandom number converter 404.3, for example, delivers constant numerical values ​​due to an error.

[0413] This device is thus capable of detecting a failure of the voltage supply 5 of the entropy source 401 or other parts of the device (e.g., 4, 28). The processor 404.11 can also use the analog-to-digital converter 403 to detect voltages and currents in the quantum random number generator 28 and / or within the control device 4 of the integrated circuit of a microcontroller and / or within the integrated circuit 2, e.g., the microcontroller, for testing purposes and compare the values ​​thus determined with expected value ranges within which these values ​​must lie. The processor 404.11 can also detect digital values ​​within the quantum random number generator 28 and / or within the control device 4 of the integrated circuit of a microcontroller and / or within the integrated circuit 2, e.g., the microcontroller.

[0414] For example, processor 404.11 can set constant Const 404.1 so low for testing purposes that the noise floor essentially controls time-to-pseudorandom number converter 404.3. For this purpose, processor 404.11 preferably sets an operating state of time-to-pseudorandom number converter 404.3 in which time-to-pseudorandom number converter 404.3 restarts with the last seed value after generating a pseudorandom number. The values ​​of time-to-pseudorandom number converter 404.3 should then satisfy an expected statistic within a tolerance band. If this is not the case, an error is present. Processor 404.11 can create this statistic and, if necessary, infer this error if the determined statistical values ​​do not lie within an expected value interval. Watchdog 404.5 can monitor the entropy of the supplied quantum random bits 411.If the mean entropy of the quantum random bits 411 deviates significantly more than a permissible entropy deviation value from the expected random mean of 50% over an entropy measurement period, the watchdog 404.5 preferably concludes an error in the quantum random number generator 28 and preferably increments the error counter by the said error counter increment. The watchdog 404.5 then preferably stops the use of these quantum random bits of the output 411 of the entropy extraction 404.4 to prevent the device from sending plaintext over the data bus. Plaintext, in the sense of the document presented here, means that the sent and / or stored data is in a form that allows a third party to gain unauthorized access to the content of a data message and / or stored data and / or program code directly and / or through the application of statistical or other methods.It is conceivable that even with functioning sub-devices, a virtual permanent one or a virtual permanent zero is randomly generated. Randomness also includes the permanent zero and the permanent one. It is therefore sensible for the maximum length of a bit sequence without changing the logical state at the output 411 of the entropy extraction 404.4 to be limited by the watchdog 404.5 to a value programmable by the processor 404.11.

[0415] Essentially, the quantum random number generator 28 described above can thus detect the following errors and, by means of an emergency run using an optional, further pseudorandom number generator

[0416] 404.6, for example by means of an optional additional linear feedback shift register

[0417] 4104.6, with a lower level of safety:

[0418] • Disturbance of supply voltages

[0419] • Faulty signal generation of the photon sources 54 and / or the silicon LEDs 54 and / or the first SPAD diodes 54,

[0420] • Faulty signal generation of the photon detectors 55 and / or the second SPAD diodes 55,

[0421] • Fault in the optional optical fiber 44,

[0422] • Disturbance of the coupling of the photon sources 54 and / or the silicon LEDs 54 and / or the first SPAD diodes 54 to the optical waveguide 44,

[0423] • Disturbance of the coupling of the photon detectors 55 and / or the second SPAD diodes 55 to the optical waveguide 44,

[0424] • Circuit failures in the digital part 404 of the quantum random number generator 28,

[0425] • Incorrect entropy of the supplied quantum random bits 411. It is conceivable to use a second complete quantum random number generator 28 instead of the optional, additional linear feedback shift register 404.6 or the optional, additional pseudorandom number generator 404.6, the output 411 of which is the entropy extraction

[0426] 404.4, the multiplexer 404.7 is then used instead of the signal from the optional additional pseudorandom signal line 417 for the emergency operation of the quantum random number generator 28. In the event that the output of the optional, additional pseudorandom number generator 404.6 depends on one or more genuine quantum random bits 411 as seed 412, it is again a quantum random number, as long as the number of inserted bits is limited. Preferably, the watchdog 405.5 determines the number q of the permitted, maximum consecutive quantum random bits 411 using a quantum random number. If this quantum random number, which the watchdog 404.5 uses to determine q, only comprises quantum random bits 411 with a single logical value, there is a possibility that an error is present. The number q should not be maximal to avoid sending or storing plaintext. Instead, the watchdog should return 404.5 then choose the number q very small, preferably minimal.

[0427] Figure 10

[0428] Fig. 10 shows the flowchart 500 of the entropy extraction method, which, for example, executes entropy extraction 404.4. The method provides for, in a first step 501, two values ​​of the output 410 of the time-to-pseudo-random number converter 404.3 to be determined and stored in a shift register of entropy extraction 404.4. If two values ​​are stored in the shift register of entropy extraction 404.4, entropy extraction 404.4 compares these two values ​​in a second step 502. The two values ​​in the shift register of entropy extraction

[0429] 404.4 thus comprise a first value and a second value, both of which the time-to-pseudorandom number converter 404.3 has determined by means of two different pseudorandom number determinations depending on the respective time period between two signal pulses of the output signal 409 of the comparator 404.2. In a third step 503, the entropy extraction 404.4 evaluates the two values. If the first value is smaller than the second value and the difference between value 1 and value 2 is greater than a minimum difference e, the entropy extraction sets

[0430] 404.4 sets the value of its output 411 to a first logical value. If the first value is greater than the second value and the difference between the first value and the second value is greater than the minimum difference e, the entropy extraction 404.4 sets its output to a second logical value that is different from the first logical value. If the difference between the first value and the second value is less than the minimum difference e, the entropy extraction discards the first value and the second value. In such a case, the entropy extraction preferably causes the watchdog 404.5 to increment an error counter by a first error counter increment. The first error counter increment can be negative. Conversely, the entropy extraction 404.4 can decrement the error counter of the watchdog 404.5 by a second error counter increment if the difference between the first value and the second value is greater than the minimum difference e.The second error counter step size can be equal to the first error counter step size. Typically, the signs of the first error counter step size and the second error counter step size are the same. Preferably, the processor 404.11 can set the error counter step sizes and the starting value of the error counter and an error counter threshold. If the count of the error counter crosses the error counter threshold, the watchdog 404.5 signals the presence of a critical error state to the processor 404.11, preferably by means of an interrupt 420 or other signaling. The processor 404.11 then typically starts a self-test program to test the various parts of the quantum random number generator 28. Preferably, the processor 404.11 can, for example, set the analog-to-digital converter 403 to a state in which the processor 404.11 can write test values ​​to an output register of the analog-to-digital converter 403, which the subsequent signal chain then processes like real sample values. Since the test values ​​are known in advance, the processor 404.11 can observe and evaluate the correct response of the rest of the system, for example, the incrementing of the error counter in the watchdog 404.5. Therefore, the microcontroller 404.11 can preferably monitor all memory nodes of the evaluation circuit 404 or the control device 4 and read their logical state.

[0431] Figure 11

[0432] Figure 11 shows an example oscillogram of the voltage signal 404 of the entropy source 401. As can easily be seen, first spikes 601 occur with a first height and second spikes 602 with a second height. The scatter of the first height of the first spikes 601 and the scatter of the second height of the second spikes 602 are each so small that a clear separation of these events 601, 602 is possible using an example cutting level 603 via the selection of the constant 404.1. The cutting level 603 corresponds to the value that the processor location 404.11 sets using the constant 404.1, which is preferably implemented as a register of the processor 404.11.

[0433] Figure 12

[0434] Figure 12 shows the schematic sequence of server-client communication using a proposed quantum random number generator. A first device, such as the one in Figure 1, as the server, is intended to communicate in an encrypted manner via a data bus with a second device, such as the one in Figure 1, as the client. In a first example, both the first device and the second device are intended to each comprise a quantum random number generator 28, which the respective first processor 10-1 of the computer III

[0435] (here the exemplary microintegrated circuit 2) for encryption. The quantum random number generator 28 preferably corresponds entirely or partially to a construction according to one of Figures 5 to 9. Very particularly preferably, the quantum random number generators of the first device and the second device each comprise a quantum random number generator 28, which in each case has at least one photon source 54 or a silicon LED 54 or a first SPAD diode 54 and in each case, for example, an optical waveguide 44, for example in the form of the oxide stack 44 on the semiconductor surface of the semiconductor substrate 49 and preferably at least one photon detector 55 or a second SPAD diode 55 as a receiver.This increases the data rate of the generated quantum random bits 411 and enables the first processor 10-1 of the computer (here, the exemplary microintegrated circuit 2) of the respective device to generate and exchange keys very quickly. The respective first processors 10-1 of the respective computers (here, the exemplary microintegrated circuit 2) of the respective devices encrypt their mutual communication, preferably using an RSA encryption method. The exemplary RSA encryption method is known, for example, from RL Rivest, A. Shamir, and L. Adleman, "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems," Communications of the ACM, February 1978, Vol. 21, No. 2, pages 120 to 126.The prime numbers that the respective first processor 10-1 of the respective computer (here the respective exemplary microintegrated circuit 2) of the respective device preferably uses to generate the public and private keys are preferably randomly generated by the quantum random number generator 28 QRNG.The communication of the computer (here the exemplary micro-integrated circuit 2) of the server with the respective first processor 10-1 of the respective computer (here the exemplary micro-integrated circuit 2) of the client preferably comprises, firstly, the process "Server Process", which is started on the respective first processor 10-1 of the respective computer (here the exemplary micro-integrated circuit 2) of the server, i.e. the first device, and secondly, the process "Client Process", which is started on the respective first processor 10-1 of the respective computer (here the exemplary micro-integrated circuit 2) of the client, i.e. the second device.The respective first processor 10-1 of the respective computer (here, the exemplary micro-integrated circuit 2) of the client typically communicates with the respective first processor 10-1 of the respective computer (here, the exemplary micro-integrated circuit 2) of the server via so-called sockets. These are communication points provided by the respective operating system of the respective computer (here, the exemplary micro-integrated circuit 2). The functions required to establish communication preferably originate, for example, from the standard C library socket.h. The following explains the communication according to Figure 12 by way of example: At the beginning, the first processor 10-1 of the computer (here, the exemplary micro-integrated circuit 2) of the server generates a socket descriptor in step 3000.A socket descriptor, as defined in this document, is an integer-like file handle, generated, for example, by the Standard C Library function socket() of the socket.h library. The first processor 10-1 of the server's computer (here, the exemplary microintegrated circuit 2) can use this socket descriptor in subsequent function calls that use sockets.

[0436] In step 3010, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably binds the socket descriptor to a port and an IP address. Binding, as defined in this document, means that the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) uses the standard C function bind() from the standard C library socket.h to logically link the port and IP address to the socket descriptor generated in step 3000. A port, as defined in this document, is a part of the network address that enables the assignment of data packets between server and client programs. An IP address, as defined in this document, is a network address that uniquely identifies a participant in a network.

[0437] In the next step 3020, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) enters a passive wait state 3020 and waits for connection requests from a first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) of a client. For the purposes of the document presented here, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably calls the standard C function I isten() of the socker.h library for this purpose. The function indicates that the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) is ready to accept connection requests from clients.The first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) creates a queue for incoming connection requests from the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the client in one of the memories of the computer (here of the exemplary micro-integrated circuit 2) or the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) or another device part of the computer (here of the exemplary micro-integrated circuit 2).If the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server detects a connection request from a first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of a client, the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server accepts this connection request from the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the client.

[0438] The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then establishes a connection to the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) in a subsequent step 3030. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) detects a connection request from the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) by the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) exiting the listen() function. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) accepts the connection request, preferably by calling the standard C function accept() of the socket.h standard C library.The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably extracts the first connection request from the queue of open connection requests for the server and then uses it to establish the connection to the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2). If successful, the accept() function returns a socket descriptor of the client to the first processor 10-1 of the computer (here, the exemplary micro-integrated circuit 2). A socket descriptor, as defined in this document, is an integer similar to a file handle of the standard C library socket.h. This then establishes the connection between the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) and the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2).

[0439] If such a connection exists, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably starts a keyExchangeServer() function in a subsequent step 3040. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then executes this keyExchange() function in this step 3040 to send its public key to the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2). However, this keyExchangeServer() function is not a standard C function. In this function, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) generates 28 quantum random numbers Q.RNG using a quantum random number generator. The quantum random number preferably has a bit width n.Here, n is a positive integer, including zero. These random numbers from the quantum random number generator 28 of the computer (here, the exemplary microintegrated circuit 2) of the server serve, in the example presented in this document, as indices for a look-up table of the first 2n prime numbers. This look-up table is preferably located in one of the memories of the computer (here, the exemplary microintegrated circuit 2) or in a memory of subdevices of the computer (here, the exemplary microintegrated circuit 2) of the server. The first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server then reads the prime number corresponding to this index of the quantum random number of the quantum random number generator 28 of the computer (here the exemplary micro-integrated circuit 2) from the memory of the computer (here the exemplary micro-integrated circuit 2) of the server.Using these prime numbers, the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) server generates both a public and a private key according to the aforementioned RSA encryption method.

[0440] The first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) then transmits a public key to the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the client via the data interface 64 of the computer (here of the exemplary micro-integrated circuit 2) of the server and the data bus 95 and the data interface 64 of the computer (here of the exemplary micro-integrated circuit 2) of the client.

[0441] The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then waits for a message from the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) via the data interface 64 of the client's computer (here, the exemplary micro-integrated circuit 2) and the data bus 65 and the data interface 64 of the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2). This message from the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) preferably includes a public key of the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2).Thus, the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the client typically transmits the private key of the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the client via the data interface 64 of the computer (here of the exemplary micro-integrated circuit 2) of the client and the data bus 95 and the data interface 64 of the computer (here of the exemplary micro-integrated circuit 2) of the server to the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the server.If the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server has received the public key of the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the client, the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server stores this public key in a memory of the computer (here the exemplary micro-integrated circuit 2) of the server.

[0442] Subsequently, the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the server sends, for example, its public key via its data bus interface 64 and the data bus 65 and the data bus interface 64 of the computer (here of the exemplary micro-integrated circuit 2) of the client to the first processor 10-1 of the computer (here of the exemplary micro-integrated circuit 2) of the client.

[0443] Thus, the server is typically prepared for the exchange of encrypted data between the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the client and the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server.

[0444] After the keys have been exchanged, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably executes the recv() function 3050 and waits for an encrypted message from the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2). If the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) receives a message, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably initially stores this encrypted message in a temporary buffer on the server's computer (here, the exemplary micro-integrated circuit 2). For the purposes of this document, the recv() function is preferably a standard C function of the standard C library socket. h.The recv() function typically reads incoming data from a socket descriptor, in this case the socket descriptor of the first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) from step 3030 of the method. The recv() function, which the first processor 10-1 of the server's computer (here, the exemplary microintegrated circuit 2) typically executes, typically stores the received data in the temporary cache of the client's computer (here, the exemplary microintegrated circuit 2).

[0445] Server. If the first processor 10-1 of the computer (here, the exemplary microintegrated circuit 2) of the server has received an encrypted message in this way, the first processor 10-1 of the computer (here, the exemplary microintegrated circuit 2) of the server preferably executes the Decrypt() function 3060 in a further step 3060. This Decrypt() function is not a standard C function. In this step 3060, the DecryptQ function, as defined in the document presented here, decrypts the message of the server's private key from step 3040 according to the RSA method using the server's private key temporarily stored in the memory of the computer (here, the exemplary microintegrated circuit 2).As a result, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) decrypts the received encrypted message from the client using the private key from step 3040, which is temporarily stored in the memory of the server's computer (here, the exemplary micro-integrated circuit 2), according to the RSA method. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably stores the then decrypted message in a temporary buffer of the server's computer (here, the exemplary micro-integrated circuit 2).

[0446] If the first processor 10-1 of the computer (here the exemplary microintegrated circuit 2) of the server does not receive a message from the first processor 10-1 of the computer (here the exemplary microintegrated circuit 2) of the client within a predetermined period of time, the first processor 10-1 of the computer (here the exemplary microintegrated circuit 2) of the server jumps to the step now described. The first processor 10-1 of the computer (here the exemplary microintegrated circuit 2) of the server checks whether a message should be sent to the first processor 10-1 of the computer (here the exemplary microintegrated circuit 2) of the client. Typically, such a message is stored in a memory of the computer (here the exemplary microintegrated circuit 2) of the server for transmission in such a case.The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) can also retrieve or receive such a message from another memory or system before sending it. Preferably, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then temporarily stores such a message in a buffer of the server's computer (here, the exemplary micro-integrated circuit 2). If such a message to be sent is pending in a memory or buffer of the server's computer (here, the exemplary micro-integrated circuit 2), the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably executes the Encrypt() function in a further step 3070.In this step 3070, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) encrypts its own message using the client's public key from 3040 according to the RSA algorithm. This Encrypt() function is not a standard C function. The server stores its now encrypted message in a temporary buffer of the server's computer (here, the exemplary micro-integrated circuit 2).

[0447] The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) now executes the send() function in a step 3080. In step 3080, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) sends its encrypted message, stored in the buffer of the computer (here, the exemplary micro-integrated circuit 2), to the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) via the data bus interface 64 of the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) and via the data bus 65 and via the data interface 64 of the first processor 10-1 of the computer (here, the exemplary micro-integrated circuit 2).For the purposes of this document, the send() function is a standard C function from the standard C library socket.h. The send() function sends data via a socket descriptor, in this case the client's socket descriptor from step 3030. The typical cycle ends with the end of the transfer.

[0448] Thereafter, the encrypted communication for the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server starts again at step 3040.

[0449] If the communication is terminated by the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) or the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2), the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) executes the close() function 3090. The close() function is a standard C function of the standard C library socket.h. By executing the close() function, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) closes the open connection to a socket, here, the client's socket, and thus terminates the communication.

[0450] In an analogous manner, the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the client executes a client process.

[0451] At the beginning of the "client process," the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) creates a socket descriptor in step 3100. A socket descriptor, as defined in this document, is again an integer similar to a file handle, such as the standard C library function socket() of the socket.h library, which the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) can use in subsequent function calls that utilize sockets. The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) sends a connection request to the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) using the port and IP address specified in step 3010.

[0452] To do this, the first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) preferably executes the standard C function connect() from the standard C library socket.h. This function establishes a connection between the server socket from step 3010 and the client socket from step 3100.

[0453] If the connection was accepted by the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) according to step 3030, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) executes the KeyExchangeClient() function in a step 3120. This function is not a standard C function. By executing this function, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) generates one or more QRNG quantum random numbers using the quantum random number generator 28. This quantum random number has a bit width n. Here, n is a positive integer, including zero. These random numbers from the quantum random number generator 28 of the client's computer (here, the exemplary micro-integrated circuit 2) preferably serve as indices for a look-up table of the first 2 nPrime numbers. Using these prime numbers or other prime numbers, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) generates both a public and a private key according to RSA encryption (ANGANG). The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) stores its thus generated public key and its thus generated private key, preferably in a memory of the client's computer (here, the exemplary micro-integrated circuit 2).The first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) then sends its public key to the first processor 10-1 of the server's computer (here, the exemplary microintegrated circuit 2) via the data interface 64 of the client's computer (here, the exemplary microintegrated circuit 2) and via the data bus 65 and via the data interface 54 of the server's computer (here, the exemplary microintegrated circuit 2). The first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) then waits for a message from the first processor 10-1 of the server's computer (here, the exemplary microintegrated circuit 2).This message from the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server typically contains the public key of the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server.

[0454] Subsequently, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) executes the Encrypt() function 3130. By executing the Encrypt() function in step 3130, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) encrypts its own message using the public key of the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) from step 3040 using the RSA method. This function is not a standard C function. The client stores the encrypted message in a temporary buffer.

[0455] The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) now executes the send() function in step 3140 and sends its encrypted message to the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2). For the purposes of this document, the send() function is a standard C function of the standard C library socket.h. By executing the send() function, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) sends data via a socket descriptor, in this case, the client's socket descriptor from 3100.

[0456] The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) then executes the recv() function 3150. In step 3150, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) waits for an encrypted message from the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2). If the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) receives a message, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) stores this received and typically encrypted message in a temporary buffer. For the purposes of this document, the recv() function is preferably a standard C function of the standard C library socket.h.The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) reads incoming data from a socket descriptor, in this case from the socket descriptor of the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) from step 3100, by executing the recv() function. The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) preferably stores the read data in a temporary buffer of the client's computer (here, the exemplary micro-integrated circuit 2).

[0457] If the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) has received an encrypted message in this way, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) preferably executes the DecryptQ function in a step 3160. This DeCryptQ function is not a standard C function.The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) decrypts an encrypted message received by the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) by executing the Decrypt() function, using the private key of the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) from step 3120 using the RSA method. The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) then stores the decrypted message in a temporary buffer of the client's computer (here, the exemplary micro-integrated circuit 2).

[0458] Thereafter, the communication between the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server and the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the client starts again at step 3120.

[0459] If the communication is terminated by the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) or the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2), the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) executes the close() function in step 3170. The close() function is a standard C function of the standard C library socket.h. By executing the close() function, the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) closes the open connection to a socket and thus terminates communication with the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2). Figure 13

[0460] Figure 13 shows the schematic flow of the functions KeyExchangeServer() and KeyExchangeClient().

[0461] When starting the KeyExchangeServer() function, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) first calls the setPrimes() function in step 3200. This KeyExchangeServer() function is not a standard C function. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) uses the KeyExchangeServer() function to generate two different prime numbers p and q, the product n=p*q, and the Euler phi function phi = (pl)(ql) in step 3200.

[0462] The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then calls the setE() function in step 3210. This setE() function in step 3210 is not a standard C function. When calling the setE() function in step 3210, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) generates a number e that is coprime to phi, where the number phi is the number from step 3200. Coprime in the sense of this document means that there is no natural number other than one that simultaneously divides the number e and phi.

[0463] Subsequently, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) executes the findD() function in step 3220. This findD() function is not a standard C function. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) uses the findD() function to calculate the multiplicative inverse of e, such that (e*d) mod phi = 1.

[0464] The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) now calls the recv() function in step 3230. The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) now waits for an incoming message from the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2), which should typically include the client's public key. For the purposes of this document, the recv() function is a standard C function of the standard C library socket.h. By calling the recv() function, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) reads the incoming data from a socket descriptor, in this case, the client's socket descriptor.The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) preferably stores the read data in a temporary buffer of the server's computer (here, the exemplary micro-integrated circuit 2). The first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) then calls the send() function in step 3240. In this step 3240, the first processor 10-1 of the server's computer (here, the exemplary micro-integrated circuit 2) sends its public key (d,n) from steps 3200 and 3220 to the first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2). For the purposes of this document, the send() function is a standard C function of the standard C library socket. h.The first processor 10-1 of the server's computer (here the exemplary micro-integrated circuit 2) sends data via a socket descriptor, in this case the client's socket descriptor from step 3030, using the send() function.

[0465] Subsequently, the first processor 10-1 of the computer (here the exemplary micro-integrated circuit 2) of the server leaves the KeyExchangeServer() function in step 3245.

[0466] When starting the KeyExchangeClient() function, the first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) first calls the setPrimes() function in step 3250. This function is not a standard C function. The first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) uses the KexExchangeClient() function to generate the prime number p and the prime number q that is different from q. The first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) uses the KexExchangeClient() function to generate the product n=p*q. The first processor 10-1 of the client's computer (here, the exemplary microintegrated circuit 2) uses the KexExchangeClient() function to generate the Euler phi function phi = (pl)(ql).

[0467] The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) then calls the setE() function in step 3260. This function is not a standard C function. The first processor 10-1 of the client's computer (here, the exemplary micro-integrated circuit 2) uses the setE() function to generate an integer e that is coprime to the number phi from step 3250. Coprime, as defined in this document, means that there is no natural number other than one that si...

Claims

Claims 1. Quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG), wherein the quantum process-based generator (28) for true random numbers (411, 418) has an entropy source (401), and wherein the quantum process-based generator (28) for true random numbers (411, 418) is configured to evaluate a signal (405) from the entropy source (401) by means of at least one time-to-pseudo-random number converter (TPRC) (404.3), and wherein the quantum process-based generator (28) is further configured to generate one or more random bits (411) as a function of the signal (405) from the entropy source (401).

2. Quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG), wherein the quantum process-based generator (28) for true random numbers (411, 418) is implemented in one piece on a semiconductor substrate (49) having a surface (O), and wherein the quantum process-based generator (28) for true random numbers (411, 418) has a vertical entropy source (401), and wherein the vertical entropy source (401) has a photon source (54), and wherein the vertical entropy source (401) has a photon detector (55), and wherein the surface (O) of the semiconductor substrate (49) has a horizontal plane with a first direction in the plane (1st plane vector) and a second direction in the plane (2nd plane vector).Plane vector) which is different from the first direction in the plane, and wherein the photon source (54) and the photon detector (55) are arranged in a vertical direction to the first and second direction in the plane in the semiconductor substrate (49) with respect to the first and second direction in the horizontal plane of the surface (O) of the semiconductor substrate (49), and wherein the quantum process-based generator (28) for true random numbers (411, 418) is configured to generate one or more random bits (411) in dependence on the signal (405) of the entropy source (401).

3. Quantum process-based generator (28) for true random numbers (411, 418) (English: Quantum Random Number Generator: QRNG), wherein the quantum process-based generator (28) for true random numbers (411, 418) comprises an entropy source (401) in a semiconductor substrate (49) having a surface (O) and a back side which lies opposite the surface (O) on the other side of the semiconductor substrate (49), and wherein the quantum process-based generator (28) for true random numbers (411, 418) comprises means for detecting an attack on the entropy source (401) by means of photons, wherein this attack can in particular be an attack from the back side of the semiconductor substrate (49).

4. Quantum process-based generator (28) for true random numbers (411, 418) according to claim 3, wherein said means for detecting an attack on the entropy source (401) by means of photons comprise an observation diode (28020).

5. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 4, wherein the quantum process-based generator (28) comprises a watchdog (404.5).

6. Quantum process-based generator (28) for true random numbers (411, 418) according to one of the Claims 1 to 5, wherein the quantum process-based generator (28) comprises a voltage monitor (423).

7. Quantum process-based generator (28) for true random numbers (411, 418) according to one of the Claims 5 to 6, wherein the watchdog (404.5) and / or the voltage monitor (413) are configured to monitor the quantum process-based generator (28) for an attack or a disturbance by means of the means for detecting an attack on the entropy source (401) by means of photons, in particular by means of the observation diode (28020).

8. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 7, wherein the at least two device parts of the quantum process-based generator (28) for true random numbers (411, 418) according to one of the said claims and optionally further circuit parts are designed in one piece on a common semiconductor substrate (49) as a one-piece quantum process-based generator (28), wherein the device parts of the quantum process-based generator (28) for true random numbers (411, 418) and the optionally further circuit parts comprise at least as device parts the entropy source (401) or the vertical entropy source (401) and the time-to-pseudo-random number converter (TPRC) (404.3) or at least the vertical entropy source (401) and the time-to-pseudo-random number converter (TPRC) (404.3) or a time-to-digital converter (TDC) (404.3) instead of the Time-to-pseudorandom number converter (TPRC) (404.3) or at least the entropy source (401) or the vertical entropy source (401) and Means for detecting an attack on the entropy source (401) by means of photons or at least the time-to-pseudo-random number converter (TPRC) (404.3) or a time-to-digital converter (TDC) (404.3) instead of the time-to-pseudo-random number converter (TPRC) (404.3) and Means for detecting an attack on the entropy source (401) by means of photons and wherein the device parts of the quantum process-based generator (28) for true random numbers (411, 418) can additionally comprise the following device parts: an integrated circuit (2) and / or one or more photon sources (54) and / or one or more photon detectors (55) and / or one or more optical functional elements (44) and / or one or more optical waveguides (44) and / or a time-to-pseudo-random number converter (TPRC) (404.3) and / or Means for detecting an attack on the entropy source (401) by means of photons and / or one or more observation diodes (28020) and / or a watchdog (404.5) and / or one or more voltage monitors (423) and / or one or more voltage converters (91) and / or one or more amplifiers (402) and / or one or more comparators (404.2) and / or an entropy extraction device (404.4) and / or a finite state machine (FSM) (404.8) and / or a signal multiplexer (404.7) and / or one or more RAMs and / or FIFOs (404.9) and / or one or more finish flags (404.10) and / or an internal data bus (419) and / or one or more signal lines and / or one or more interrupt signals (420) and / or a pulse extension circuit (2023) and / or a feedback multiplexer (2102) the time-to-pseudorandom number converter (404.3) (TPRC) and / or a control register (2111) of the feedback multiplexer (2102) and / or one or more feedback polynomial selection registers (2112) and / or a detection circuit (2113) and / or a shift register controller (2103) and / or one or more feedback networks (RKNi to RKN m ) of the time-to- Pseudorandom number converter (404.3) (TPRC) and / or one or more shift register bits (SBi to SB n ) and / or one or more second high-side transistors (2303), in particular in the form of DMOS transistors, and / or one or more transfer transistors (2305), in particular in the form of DMOS transistors, and / or one or more first energy storage devices (2306) and / or one or more second energy storage devices (2307) and / or one or more control devices (2330) of the voltage converters (91) and / or a pad frame (2401) of the microintegrated circuit (2) and / or Means (25145) for electronic post-processing and / or one or more observation diodes (28020) and / or an encapsulation with one or more metal layers (53, 142) and / or one or more silicide layers and vias (140) and / or one or more data bus interfaces (64) and / or a JTAG test interface (12) and / or another test interface and / or a control device (4) and / or one or more non-volatile memories (6) and / or one or more EEPROMs (6) and / or one or more random access memories (8) (volatile read / write memories) and / or one or more processors (10-1, 10-2) and / or one or more tightly coupled memories (TCM) (14) and / or a non-volatile boot memory (boot ROM) (16) and / or a hashing engine (18) and / or one or more one-time programmable memories (OTP) (20,22) (one-time programmable memory) and / or a deactivation circuit (24) and / or one or more further internal non-volatile memories (30) and / or one or more interfaces (32) to one or more controlled systems (26) and / or one or more clock generators (92) (including any necessary PLLs) and / or one or more voltage converters (91) and / or one or more reset circuits (83) and / or one or more data bus interfaces (64) and / or one or more internal interfaces (81, 63, 301) and / or one or more optical functional elements (44) and / or one or more analog input processing units (84) and / or one or more analog-to-digital converters (85) and / or one or more digital signal processing units (86) and / or one or more digital-to-analog converters (87) and / or one or more analog output processing units (88)., 9. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 8, wherein the quantum process-based generator (28) for true random numbers (411, 418) is configured to generate at least one random number (418) from a plurality of random bits (411), and wherein the quantum process-based generator (28) is further configured to provide or use the at least one random number (418).

10. Quantum process-based generator (28) for true random numbers (411, 418) according to claim 1 and claim 9, wherein the logical values ​​in the time sequence of the pseudorandom bits of a time-to-pseudorandom number converter (TPRG) (404.3) of the quantum process-based generator (28) depend on one or more quantum random bits (411) and / or one or more quantum random numbers (418).

11. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 5 to 10, wherein the watchdog (404.5) is configured to monitor correct functioning of the quantum process-based generator (28) for true random numbers (411, 418).

12. Quantum process-based generator (28) for true random numbers (411, 418) according to claim 11, wherein the watchdog (404.5) is configured to measure the randomness of the generated quantum random bits (411) in the form of one or more measured values ​​and to compare each with a respective tolerance interval or a respective threshold value, and wherein the watchdog (404.5) is configured to infer a respective error in the event of a respective deviation of the respective measured value from the respective tolerance interval or the respective threshold value.

13. Quantum process-based generator (28) for true random numbers (411, 418) according to one of the Claims 5 to 12, wherein the watchdog (404.5) is configured to to monitor a correct function of the time-to-pseudo-random number converter (TPRC) (404.3) of the at least one time-to-pseudo-random number converter (TPRG) (404.3) of the quantum process-based generator (28) and / or to monitor a behavior in the form of the temporal statistics of the logical values ​​in the temporal sequence of the pseudo-random bits of the time-to-pseudo-random number converter (TPRC) (404.3) and to record them in the form of statistical measured values ​​and to detect and / or signal an error in the event of deviations of the statistical measured values ​​from the expected behavior in the form of a departure from permitted measured value ranges for these measured values.

14. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 13, wherein the quantum process-based generator (28) for true random numbers (411, 418) with its at least two device parts is manufactured in one piece as part of an integrated circuit (2), and wherein the device parts of the quantum process-based generator (28) for true random numbers (411, 418) and the optionally further circuit parts comprise at least as device parts one or the entropy source (401) or one or the vertical entropy source (401) and one or the time-to-pseudo-random number converter (TPRC) (404.3), or at least one or the vertical entropy source (401) and one or the time-to-pseudo-random number converter (TPRC) (404.3) or in the case of claims 2 or 3, a time-to-digital converter (TDC) (404.3) instead of the time-to-pseudo-random number converter (TPRC) (404.3) or at least one or more.the entropy source (401) or a or the vertical entropy source (401) and. Means for detecting an attack on the entropy source (401) by means of photons or at least a time-to-pseudo-random number converter (TPRC) (404.3) or, in the case of claims 2 or 3, a time-to-digital converter (TDC) (404.3) instead of the time-to-pseudo-random number converter (TPRC) (404.3) and Means for detecting an attack on the entropy source (401) by means of photons, and wherein the device parts of the quantum process-based generator (28) for true random numbers (411, 418) can additionally comprise the following device parts: an integrated circuit (2) and / or one or more photon sources (54) and / or one or more photon detectors (55) and / or one or more optical functional elements (44) and / or one or more optical waveguides (44) and / or a time-to-pseudo-random number converter (TPRC) (404.3) and / or Means for detecting an attack on the entropy source (401) by means of photons and / or one or more observation diodes (28020) and / or a watchdog (404.5) and / or one or more voltage monitors (423) and / or one or more voltage converters (91) and / or one or more amplifiers (402) and / or one or more comparators (404.2) and / or an entropy extraction device (404.4) and / or a finite state machine (FSM) (404.8) and / or a signal multiplexer (404.7) and / or one or more RAMs and / or FIFOs (404.9) and / or one or more finish flags (404.10) and / or an internal data bus (419) and / or one or more signal lines and / or one or more interrupt signals (420) and / or a pulse extension circuit (2023) and / or a feedback multiplexer (2102) of the time-to-pseudo-random number converter (404.3) (TPRC) and / or a control register (2111) of the feedback multiplexer (2102) and / or one or more feedback polynomial selection registers (2112) and / or a detection circuit (2113) and / or a shift register controller (2103) and / or one or more feedback networks (RKNi to RKN m ) of the time-to- Pseudorandom number converter (404.3) (TPRC) and / or one or more shift register bits (SBi to SB n ) and / or one or more second high-side transistors (2303), in particular in the form of DMOS transistors, and / or one or more transfer transistors (2305), in particular in the form of DMOS transistors, and / or one or more first energy storage devices (2306) and / or one or more second energy storage devices (2307) and / or one or more control devices (2330) of the voltage converters (91) and / or a pad frame (2401) of the microintegrated circuit (2) and / or Means (25145) for electronic post-processing and / or one or more observation diodes (28020) and / or an encapsulation with one or more metal layers (53, 142) and / or one or more silicide layers and vias (140) and / or one or more data bus interfaces (64) and / or a JTAG test interface (12) and / or another test interface and / or a control device (4) and / or one or more non-volatile memories (6) and / or one or more EEPROMs (6) and / or one or more Random Access Memories (8) (volatile read / write memories) and / or one or more processors (10-1, 10-2) and / or one or more tightly coupled memories (TCM) (14) and / or a non-volatile boot memory (Boot-ROM) (16) and / or a hashing engine (18) and / or one or more one-time programmable memories (OTP) (20, 22) (One- Time-Programmable Memory) and / or a deactivation circuit (24) and / or one or more further internal non-volatile memories (30) and / or one or more interfaces (32) to one or more controlled systems (26) and / or one or more clock generators (92) (including any necessary PLLs) and / or one or more voltage converters (91) and / or one or more reset circuits (83) and / or one or more data bus interfaces (64) and / or one or more internal interfaces (81, 63, 301) and / or one or more optical functional elements (44) and / or one or more analog input processing units (84) and / or one or more analog-to-digital converters (85) and / or one or more digital signal processing units (86) and / or one or more digital-to-analog converters (87) and / or one or more analog output processing units (88).

15. Quantum process-based generator (28) for true random numbers (411, 418) according to claim 14, wherein the integrated circuit (2) is manufactured using BCD technology.

16. A quantum process-based true random number generator (28) according to claim 14 or claim 15, wherein the integrated circuit (2) comprises a voltage converter (91) for supplying the entropy source (401) of the quantum process-based true random number generator (28) (411, 418), and wherein the voltage converter (91) comprises one or more DMOS transistors.

17. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 14 to 16, wherein the integrated circuit (2) is one of the following circuits or comprises one of the following circuits: a microcontroller, a microprocessor, a memory, a DRAM, an SRAM, a RAM, a volatile memory, an OTP storage, - an EEPROM, a flash memory, an MRAM, an FRAM, a sensor evaluation circuit, a control circuit for an automotive control circuit, a graphics controller, an evaluation circuit for a biometric sensor or an input device, a control circuit, a chip card circuit, an RFID circuit; a physical circuit of a mobile phone or a smartphone, a circuit of an access control system, a circuit with a coded recording of operating parameters, a circuit of an access control system, a circuit of an electronic security system, a radio system circuit, a communication circuit, a circuit of an encryption and / or decryption system, a circuit of an individualization system, a circuit of a gaming device, a circuit of a simulation system, a circuit of a computer system, a circuit of a noise source,a circuit with a device for generating and / or using a spreading code, a circuit with a device for generating and / or using a random number to individualise the circuit, a circuit with a device for generating and / or using a random number for testing purposes, in particular for self-testing purposes and / or for testing an application circuit of which the circuit is a part.

18. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 14 to 17, wherein the integrated circuit (2) has internal interfaces (63, 301, 32 and 81) as special circuits at a cryptographic boundary between a control device (4) and other parts (8, 30, 6) of the integrated microelectronic circuit (2) which are classified as not secure or less secure, and wherein the quantum process-based generator (28) for true random numbers (411, 418) is arranged within the cryptographic boundary between the control device (4) and the other parts (8, 30, 6) of the integrated microelectronic circuit (2).

19. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 18, wherein the entropy source (401) comprises a photon source (54) and wherein the entropy source (401) comprises a photon detector (55) and wherein the photon source (54) is configured to emit photons as a quantum signal (57) when supplied with electrical energy and wherein the photon source (54) is optically coupled to the photon detector (55) and wherein the photon detector (55) is configured to at least partially receive the quantum signal (57) of the photon source (54) and to generate an output signal (405) of the entropy source (401) or a precursor signal thereof.

20. Quantum process-based generator (28) for true random numbers (411, 418) according to claim 19 and claim 2, wherein the photon source (54) comprises a silicon LED, in particular a Zener avLED.

21. A quantum process-based true random number generator (28) according to claim 19 or 20, wherein the photon source (55) comprises a SPAD diode.

22. Quantum process-based generator (28) for true random numbers (411, 418) according to one of claims 1 to 21, wherein the quantum process-based generator (28) is placed entirely or in part in a pad frame (2403) between connection pads (2402) of an integrated circuit (2) on a die (2401) of this integrated circuit (2), and wherein at least the entropy source (401) is placed in the pad frame (2403) between the connection pads (2402) of the integrated circuit (2) on the die (2401) of this integrated circuit (2).

23. Quantum process-based generator (28) for true random numbers (411, 418) according to one of Claims 5 to 24, wherein the entropy source (401) of the quantum process-based generator (28), in particular by means of metal layers (53, 142) and / or silicide layers and vias (140), except for signal feedthroughs through this encapsulation from at least one side, better at least from two sides, better at least from three sides, better at least four sides, better at least five sides.