Physical storage of a single key
The integration of a finite state machine and random number generator in integrated circuits secures encryption keys in non-volatile memory by limiting access, addressing vulnerabilities in existing circuit security.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-18
- Publication Date
- 2026-03-20
AI Technical Summary
Existing integrated circuit devices lack secure storage and protection mechanisms for encryption keys used in non-volatile memory, making them vulnerable to unauthorized access and exploitation.
A method involving a finite state machine connected to a random number generator via a dedicated bus, which generates and stores a random value in a secure memory area of a non-volatile fuse-type memory, accessible only by the finite state machine, ensuring the encryption key is inaccessible to unauthorized processors.
The solution provides secure storage and protection of encryption keys, preventing unauthorized access and ensuring confidentiality by limiting access to the encryption key to only the cryptographic processor, while utilizing existing circuit components without additional hardware.
Smart Images

Figure 00000011_0000 
Figure 00000012_0000 
Figure 00000013_0000
Abstract
Description
Title of the invention: Physical storage of a unique key technical field
[0001] This description relates generally to electronic circuits, and more particularly to integrated circuits comprising irreversibly programmable non-volatile memory (commonly referred to as fuse-type memory). This description relates, in particular, to the implementation of a method for protecting data stored in the fuse-type non-volatile memory of such a circuit. Previous technique
[0002] The operation of an integrated circuit electronic device requires the execution of proprietary software code or protocols used in the lifecycle of the circuit. The data representing the proprietary software code and protocols are linked to certain instances of the circuit but need to be stored in externally accessible, non-volatile memory. Such data is considered sensitive in terms of confidentiality and needs to be encrypted to prevent its exploitation in the event of an attack on the circuit.
[0003] The encryption and decryption of this data is performed by a cryptographic processor and requires one or more encryption keys stored in non-volatile memory of the device. Generally, the command to generate these encryption keys and to store them in non-volatile memory is executed by an unsecured processor.
[0004] However, these encryption keys must not be accessible to any potential attacker of the circuit. Any physical connection between the unsecured processor and the non-volatile memory containing these encryption keys can be exploited by attackers. Summary of the invention
[0005] There is a need to improve the security of data stored in irreversibly programmable non-volatile memories of integrated circuit devices.
[0006] An embodiment overcomes all or part of the disadvantages of known integrated circuit devices.
[0007] One embodiment provides a method in which a random value, generated by a random number generator, is stored, by a finite state machine connected to said generator by a first dedicated bus, in a memory area of a non-volatile fuse-type memory of an integrated circuit, the memory area being accessible only by said finite state machine.
[0008] One embodiment provides for an integrated circuit comprising a random number generator, a finite state machine connected to said generator by a first dedicated bus, and a non-volatile memory, in which a random value generated by said generator is stored by said state machine in a memory area of said non-volatile memory, the memory area being accessible only by said finite state machine.
[0009] According to one embodiment, the memory area can only be programmed by the finite state machine.
[0010] According to one embodiment, the first dedicated bus exclusively connects the finite state machine to the random number generator.
[0011] According to one embodiment, at each reset phase of said circuit, the contents of the memory area are loaded by the finite state machine into volatile memory elements.
[0012] According to one embodiment, a second dedicated bus exclusively connects the volatile memory elements to a first processor.
[0013] According to one embodiment, the first processor is a cryptographic processor.
[0014] According to one embodiment, the finite state machine and the volatile storage elements are contained in an adapter.
[0015] According to one embodiment, a transition of the circuit to or from a state allowing the execution of a scan-test results in the erasure of the content stored in the volatile memory elements.
[0016] According to one embodiment, the non-volatile memory is disconnected from the circuit when said circuit is in the state allowing a scan-test.
[0017] According to one embodiment, the finite state machine locks the memory area after storing the random value if the stored random value corresponds to the random value generated by the generator. Brief description of the drawings
[0018] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the accompanying figures, among which:
[0019] [Fig.1] represents, in a very schematic way and in block form, an embodiment of an integrated circuit device of the type to which, by way of example, described embodiments apply;
[0020] [Fig.2] represents, schematically and in block form, in more detail than in [Fig.1], an embodiment of an integrated circuit of the type to which, by way of example, described embodiments apply;
[0021] [Fig. 3] is a flowchart representing the steps in a method of implementing the creation and storage of an encryption key; and
[0022] [Fig.4] is a flowchart representing the steps followed by the circuit during a start-up or reset. Description of the implementation methods
[0023] The same elements have been designated by the same reference numerals in the different figures. In particular, structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.
[0024] For the sake of clarity, only the steps and elements necessary for understanding the described embodiments have been shown and are detailed. In particular, integrated circuit design is well known to those skilled in the art, and some components have not been described further.
[0025] Unless otherwise specified, when referring to two elements connected together, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") together, this means that these two elements can be connected or linked through one or more other elements.
[0026] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made, unless otherwise specified, to the orientation of the figures.
[0027] Unless otherwise specified, the expressions "approximately", "roughly", and "in the order of" mean within 10%, preferably within 5%.
[0028] Fig. 1 represents, in a very schematic way and in block form, an embodiment of an electronic device 100 comprising an integrated circuit 102 of the type to which, by way of example, described embodiments apply.
[0029] The electronic device 100 is, for example, an electronic card such as a microcircuit board, computer hardware, a microprocessor circuit, etc.
[0030] In the applications covered by this description, the integrated circuit 102 includes a non-volatile, non-rewritable, fuse-type memory 104. By default, that is, as manufactured, all the fuse-type bits of the memory 104 are in the same state, arbitrarily 0. This state corresponds, depending on the native state of the fuse bits, for example, to a non-conductive or "blocked" state of the memory elements defining the bits. data are stored on non-volatile memory 104 by switching the states of certain bits of memory (memory words) to the inverse state 1, corresponding for example to a conducting or "passing" state of the corresponding memory elements.
[0031] The designation "0" or "1" of the respective non-conducting and conducting states of the memory bits is arbitrary and another convention, for example reverse: 0 for conducting and 1 for non-conducting, may be taken depending on the application.
[0032] The storage capacity of the fuse-type memory 104 was limited; other data is stored in an external non-volatile memory 120 (NV MEM), for example, a flash memory. This data corresponds, for example, to software code or proprietary protocols ensuring the functionality of the electronic device. This data is used throughout the life of the electronic device and is considered critical in terms of confidentiality.
[0033] In order to protect the contents of the external non-volatile memory 120 and ensure its confidentiality in the event of a circuit hack, sensitive data is encrypted by a cryptographic processor 112 (CRYPTO) of the circuit 102. An encryption key, used for this purpose, is stored in the non-volatile memory 104 of the circuit 102, which corresponds to a safe and secure environment. The encryption key must be accessible from outside the circuit.
[0034] To this end, and according to the embodiments described, the integrated circuit 102 comprises a finite state machine 106 (FSM) connected to a random number generator 110 (RNG) by a bus 118. The random number generator 110 may be a pseudo-random number generator, for example, a linear congruential generator, using recursive arithmetic sequences with disordered behavior and a sufficiently long period to appear random. The quality of such a generator depends entirely on the arithmetic parameters used. The generator 110 may also be a purely random number generator using a physical source of randomness based, for example, on intrinsic properties of the material on which it is embedded.
[0035] According to the described embodiments, the bus 118 exclusively connects the finite state machine 106 to the random number generator 110. The finite state machine 106 is also connected, typically via a data bus, to the non-volatile memory 104. To ensure compatibility between data that can be provided by the random number generator and the data stored in the non-rewritable non-volatile memory 104, the circuit 102 contains an adapter 108 (WRAPPER). The adapter 108 itself contains the finite state machine 106.
[0036] The cryptographic processor 112 is configured to decrypt, using the encryption key contained in the non-volatile memory 104, the data sensitive so that they can be used for the operation of the electronic device. The cryptographic processor 112 is connected to a part (not detailed in [Fig. 1]) of the adapter 108 by a data bus 116. The data bus 116 exclusively connects the cryptographic processor 112 to the adapter 106.
[0037] The circuit further contains, a generic processor 114 (CPU), unsecured, typically connected by a data bus, to a part (not shown) of the adapter 108.
[0038] The external non-volatile memory 120 is connected to the generic non-secure processor 114 and to the adapter part 108. For example, the memory 120 is coupled via an external bus to the data bus coupling the generic non-secure processor 114 to the adapter part 108.
[0039] Fig. 2 represents schematically and in block form, in more detail than in Fig. 1, an embodiment of an integrated circuit of the type to which, by way of example, described embodiments apply.
[0040] At the end of manufacturing, the finite state machine 106 sends a request to the random number generator 110, via the bus 118. The generator 110 then generates a random value which it transmits, again via the bus 118, to the finite state machine 106. Since the bus 118 exclusively connects the finite state machine 106 to the generator 110, the generic processor 114 does not have access to the random value generated in this operation.
[0041] According to the embodiments described, the non-volatile fuse-type memory 104 is provided to comprise several distinct memory areas.
[0042] A first zone 202 is composed of a word of several bits (for example 16 or 32 bits) which can only be programmed by the finite state machine 106. Once the random value has been generated and transmitted to the finite state machine 106, the latter stores this value in a part of the zone 202 by programming the bits composing it.
[0043] A second area 204 of the non-volatile memory 104 is reserved for storing sensitive information. Its storage in the non-volatile memory is, for example, performed by the generic, unsecured processor 114. This operation is carried out, for example, by the end user of the circuit or by an intermediary entity between the manufacturer and this user.
[0044] The random value stored in memory area 202 acts as an encryption key and will be used by the cryptographic processor 112 for the encryption and / or decryption of data stored in an area 210 of the external non-volatile memory 120. This value must remain inaccessible to any processing unit other than the cryptographic processor 112.
[0045] To this end, the adapter 108 contains, in addition to the finite state machine 106, two separate volatile storage elements 206 and 208. Elements 206 and 208 are, for example, registers. At each reset or start-up of the circuit, the contents of area 202 are loaded into the volatile storage element 206, and other fusible-type values are loaded into register 208, before the generic, unsecured processor 114 exits the reset. The storage element 206 is connected by a dedicated data bus 116 to the cryptographic processor 112. The data bus 216 exclusively connects element 206 to the processor 112; thus, the data stored in the storage elements 206 is not accessible to any component of the circuit other than the cryptographic processor 112.
[0046] During the circuit's lifetime, scan tests can be performed, for example, in the event of a malfunction of the electronic device 100. However, the contents of word 202 and volatile memory element 206 must remain inaccessible to outside the circuit. To perform a scan test, the circuit 102 must be placed in scan mode. Scan tests can only be performed in scan mode; the non-volatile memory 104 is disconnected from the rest of the circuit so as to isolate the contents of areas 202 and 204. Any transition to or from scan mode triggers a reset of the chip. Consequently, the contents of volatile memory elements 206 and 208 are erased during the transition to or from scan mode.
[0047] Fig. 3 is a flowchart representing steps in an implementation method for generating and storing an encryption key.
[0048] When the circuit 102 is manufactured, the finite state machine 106 can be called upon to send a request to the random number generator 110. The random number generator 110 generates a random value (block 301 RN GENERATION). The generated value is transmitted to the finite state machine 106 via the dedicated data bus 118. The data bus 118 exclusively connects the random number generator 110 to the finite state machine 106. Therefore, the generic, unsecured processor does not have access to the random value during this operation.
[0049] The finite state machine then checks whether the random value is acceptable (for example, that it is not a value composed solely of 0s or solely of 1s in binary representation). If the quality is not deemed acceptable by the finite state machine, the process regenerates a new random value. If the quality of the random value is deemed acceptable, the finite state machine 106 stores it (block 303 STORAGE IN FUSE NV MEM) in the non-volatile memory 104 by programming a portion of the bits of word 202.
[0050] To ensure that the programming of the fuse bits has been carried out correctly, step 303 is immediately followed by step 304 (READ BACK) which reads the stored value and verifies it 305 (VALID?) against the generated value. These steps are performed by the finite state machine 106. If the two values are different (output N of block 305), there has been an error in the programming of the bits of word 202 by the finite state machine, and the process terminates (block 309 END). If the two values match (output Y of block 305), the finite state machine 106 programs additional bits of word 202 (block 307 FUSE WORD LOCKED). For example, if the word 202 has 32 bits and the random value storage occupies the 24 least significant bits of the word 202, the finite state machine will program the remaining 8 most significant bits, for example by switching them to state 1.This action locks the word 202 and validates the encryption key thus stored, and the process ends (block 309 END).
[0051] The length of word 202 can vary depending on the embodiment, as can the length of the generated encryption key. When using the circuit, only the portion of word 202 corresponding to the encryption key (with a random value) is read and used.
[0052] Figure 4 is a flowchart representing the steps followed by the circuit during a startup or a reset.
[0053] After the encryption key has been correctly stored (for example, according to the steps illustrated in [Fig. 3]) in the non-volatile memory 104, the circuit 102 is reset (block 401, RESET). Once the adapter 108 emerges from the reset, the word 202, or the part of the word 202 corresponding to the random value generated in step 301, is, for example, loaded (block 403, LOADING OF KEY IN V MEM) into the volatile memory elements 206. It should be noted that these volatile memory elements 206 are not accessible by the generic processor 114 and are accessible only to the cryptographic processor 112. The process ends in a step 405 (END OF CPU RESET) when the generic processor 114 exits the reset.
[0054] The content of the volatile memory elements 206 is loaded by the cryptographic processor 112 via a dedicated data bus 116. Thus, the generic processor 114 and more generally, any component of the circuit 102 other than the cryptographic processor 112, never has access to the encryption key stored in the volatile memory elements 206.
[0055] One advantage of the described embodiments is that no processing unit other than the cryptographic processor has access to the memories containing the encryption key. This access restriction considerably limits the possibilities of reading sensitive data from outside the circuit.
[0056] Another advantage of the described embodiments is that they do not require additional components to generate the encryption key. Indeed, a random number generator is generally present in such a circuit for other security purposes.
[0057] The fact that the random word is never visible allows only one random word (one value) to be used and therefore has the advantage (compared to solutions where several random values must be used and stored) that the random word can be larger and therefore safer.
[0058] Another advantage of the described embodiments is that the implementation of the finite state machine requires simple combinational logic that can be implemented in a robust manner.
[0059] Various embodiments and variations have been described. A person skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will become apparent to a person skilled in the art.
[0060] Finally, the practical implementation of the described embodiments and variants is within the reach of a person skilled in the art, based on the functional specifications given above. In particular, the size of the encryption key and / or the word 202 may vary.
Claims
Demands
1. A method in which a random value, generated by a random number generator (110), is stored, by a finite state machine (106) connected to said generator (110) by a first dedicated bus (118), in a memory area (202) of a non-volatile fuse-type memory (104) of an integrated circuit (102), the memory area (202) being accessible only by said finite state machine, the random value being loaded, by the finite state machine, into a volatile memory element (206) at each reset phase of the circuit, the volatile memory element being accessible only by a first processor (112) of the integrated circuit (102).
2. Method according to claim 1, wherein the memory area (202) can only be programmed by the finite state machine (106).
3. Method according to claim 1 or 2, wherein the first dedicated bus (118) exclusively connects the finite state machine (106) to the random number generator (110).
4. A method according to any one of claims 1 to 3, wherein a second dedicated bus (116) exclusively links the volatile storage elements (206) to the first processor (112).
5. A method according to any one of claims 1 to 4, wherein the first processor (112) is a cryptographic processor.
6. A method according to any one of claims 1 to 5, wherein the loading of the contents of the memory area (202) into the volatile storage element (206) takes place before the reset exit of a second processor (114), the second processor (114) being a generic, unsecured processor.
7. A method according to claim 6, wherein the finite state machine (106) is configured, at each reset phase of the integrated circuit (102), to load into other volatile memory elements (208) other fuse-type values stored in another area (204) of the fuse-type memory (104).
8. A method according to any one of claims 1 to 7, wherein the finite state machine (106) and the volatile storage elements (206) are contained in an adapter (108).
9. A method according to any one of claims 1 to 8, wherein a circuit transition to or from a state allowing The execution of a scan-test results in the erasure of the content stored in the volatile memory elements (206).
10. Method according to claim 9 wherein the non-volatile memory (104) is disconnected from the circuit when said circuit is in the state permitting a scan-test.
11. A method according to any one of claims 1 to 10, wherein the finite state machine (106) locks the memory area (202) after storing the random value if the stored random value corresponds to the random value generated by the generator (110).
12. Integrated circuit configured for implementing the method according to any one of claims 1 to 11.