SRAM WITH PUF DEDICATED SECTOR SLEEP

The SRAM device addresses NBTI instability by placing a subset of cells in a metastable state to maintain long-term stability and security, while keeping others accessible, thus enhancing PUF reliability and reducing consumption.

FR3144403B1Active Publication Date: 2025-07-25COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022014117
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-21
Publication Date
2025-07-25
Estimated Expiration
2042-12-21

AI Technical Summary

Technical Problem

SRAM memory cells are susceptible to NBTI (Negative-Bias Temperature Instability) which affects the VTP1/VTP2 ratio, leading to instability in stored data and potential data retrieval, especially when used for PUF functions, and existing solutions like bit inversion techniques increase consumption and time access.

Method used

A static random access memory device with a control circuit that puts a first set of cells into a metastable state by equalizing or disconnecting their storage nodes, preventing logical state distinction and protecting against NBTI effects, while a second set remains freely accessible.

Benefits of technology

The metastable state prevents NBTI-induced drift in initialization, maintaining long-term stability and security of PUF cells, reducing consumption, and minimizing data falsification risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000017_0000
    Figure 00000017_0000
  • Figure 00000017_0001
    Figure 00000017_0001
  • Figure 00000018_0000
    Figure 00000018_0000
Patent Text Reader

Abstract

Static random access memory device comprising a memory matrix (M) provided with SRAM memory cells, each of said cells of said set comprising a first storage node (NT) and a second storage node (NF), the device being further provided with a control circuit (160, 180, 120, T1) of said cells configured so that, after powering up the matrix (M),putting the matrix into a first operating mode in which a first set (E1) of cells located in a first zone (Z1) of the matrix in a so-called "metastable" state for which the first storage node (NT) and said second storage node (NF) are set to equal or substantially equal potentials while a second set (E2) of cells located in a second zone (Z2) of the matrix (M) distinct from the first zone (Z1) have their respective first node (NT) and second node (NT) at different respective potentials and corresponding to a given logic state between a low state and a high state and to a logic state complementary to said given state. Figure for the abstract: Figure 4C.,
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: SRAM WITH PUF-DEDICATED SECTOR SLEEP Technical field

[0001] The present invention relates to the field of memories, and in particular of the SRAM type (SRAM for "Static Random Access Memory"), and introduces means for controlling a memory to place at least one given sector of cells of this memory in a particular operating mode while in other sectors, the cells are freely accessible for reading. STATE OF THE PRIOR ART

[0002] Transistors in PMOS technology undergo a physical phenomenon called NBTI (in English "Negative-Bias Temperature Instability"), which has the effect of increasing their threshold voltage, all the more so when their dimensions are reduced. This phenomenon is also accelerated when the temperature and / or the negative voltage VGS applied between the gate and the source of the transistor increase.

[0003] An SRAM memory cell is commonly provided with two inverters connected in a head-to-tail cross-connection, each being formed in particular of a first P-type transistor and a second N-type transistor.

[0004] The value stored in an SRAM memory cell will influence the PMOS transistors of a memory cell differently and the VTP1 / VTP2 ratio of the respective threshold voltages of the two PMOS will change over time in one direction or the other depending on the stored value.

[0005] Thus, the NBTI phenomenon influences the probability of an SRAM cell to spontaneously initialize upon power-up to logic level '1' or its opposite level '0', since the initialization logic level is related to the VTP1 / VTP2 ratio.

[0006] However, memory data from the initialization of SRAM cells can be used to generate encryption keys or a hardware identifier or a unique digital fingerprint. They can be used to thus constitute a physical unclonable function (PUF for “Physical Unclonable Function”).

[0007] Certain cells having a high VTP1 / VTP2 ratio can in particular be identified as cells sufficiently stable to be used to constitute a PUF function during a so-called enrollment phase. However, due to the effects of the aforementioned NBTI phenomenon, the ratio VTP1 / VTP2 may be modified over time, making the cells less suitable for use in a PUF, one of the prerequisites of which is long-term temporal stability. To limit such degradation over time of SRAM cells, one technique consists of inverting the contents of horizontal rows of memory cells on a regular basis. Such a technique induces an increase in consumption and is penalizing in terms of the time the system can access the memory cells. Bit inversion techniques are presented in the document "Impact ofNBTI on SRAM Read Stability and Design for Reliability A Secure Data-Toggling SRAM for Confidential Data Protection", by W.-G. Ho et al., IEEE TCAS-I 2019. In this last document, the proposed solution has the disadvantage of modifying the cell structure by adding additional transistors.In any case, the periodic inversion of bits causes a loss of time and energy in the memory user circuit.

[0008] A problem related to the effects of NBTI is the so-called "data imprint effect". Such an effect is described in the document: “Challenging On-Chip SRAM Security with Boot-State Statistics", by J. McMahan et al., HOST 2017. When data stored in memory remains there for a long time, and moreover in a state of electrical oversupply, the threshold voltage VTP of the PMOS transistor passing changes, due to the same physical effect that causes NBTI. A harmful remanence effect or "data imprint" then makes it possible to retrieve data that has been previously stored even when the memory is reset.

[0009] The problem arises of producing an improved memory device with respect to at least one of the problems mentioned above. Statement of the invention

[0010] An embodiment of the present invention provides a static random access memory device comprising a memory array provided with SRAM memory cells, each of said cells of said set comprising a first storage node and a second storage node, the device being further provided with a circuit for controlling said cells configured to, after powering up the array, put the array into a first operating mode in which a first set of cells located in a first area of the array is in an indeterminate state called "metastable" for which their respective first storage node and second storage node are set to equal or substantially equal potentials while a second set of cells located in a second area of the array distinct from the first area are in a determined state in which, following an initialization or writing operation,their first node and second node, respective are at different respective potentials between a low state, corresponding in particular to a given logic state '0', and a high state, corresponding to a complementary logic state '1', allowing in particular the memorization of a value by the cells of this second zone.

[0011] By putting the cells in a metastable state, we protect ourselves from the harmful effects of NB TI.

[0012] Such an operating mode is particularly advantageous when the first set of cells contains a non-clonable physical function (PUF). By putting the cells dedicated to the PUFs in a metastable state, any possible drift in their initialization state is avoided, thus avoiding falsifying a key or digital signature associated with these cells.

[0013] Advantageously, following the powering up of the matrix at least one grid or conductive line is brought to a supply potential.

[0014] The control circuit may be provided with at least one switch element capable, alternatively, of connecting or disconnecting a supply line of cells of said first set to said grid or conductive line, and the cells are put into the metastable state by disconnecting the supply line from said grid or conductive line.

[0015] Thus, in addition to not being able to read their logical data, it is avoided here that the cells placed in a metastable state do not consume in an inappropriate manner.

[0016] Advantageously, the cells of the first set can be put into said “metastable” state by connecting their respective first storage node and second storage node to each other.

[0017] According to one possible implementation, each cell of said first set can be provided with:

[0018] - of a first inverter and a second inverter connected crosswise between said first storage node and said second storage node, the first inverter and / or the second inverter being connected to a so-called “high” supply line which can be brought to a supply potential,

[0019] - of a first access transistor to the first storage node and of a second access transistor to the second storage node, the first access transistor and the second access transistor being respectively connected to a first bit line and a second line,

[0020] the control circuit is provided with at least one switching element capable of alternately connecting to each other or disconnecting from each other the first bit line and the second bit line, the cells of the first set being put into said metastable state by said control circuit by activating the access transistors and connecting to each other the first bit line with the second bit line.

[0021] According to one embodiment, the device may further comprise a module intended to produce a digital signature and / or an encryption key from data stored in cells of said first set of cells, said module being capable of producing an access request signal to the first set of cells, the control circuit being configured to, following receipt of said access request signal, put the cells of said first set of cells in a read accessibility state or in a state allowing an operation of storing a value after an initialization operation and in a read accessibility state, by:

[0022] - disconnecting or isolating from each other the first node of the second node of each cell of the second set or,

[0023] - applying a supply potential to the cells of the first set, or

[0024] - isolating the first node from the second node of each cell of the first set while applying a supply potential to the cells of the first set.

[0025] Advantageously, to put the cells of said first set of cells in a read-accessible state, the cells of the first set can be initialized beforehand by deactivating their first access transistor and second access transistor while putting the high supply line at the supply potential in order to power their first inverter and their second inverter.

[0026] According to a possible implementation, the control circuit can be configured so that when the cells of said first set of cells are in a read accessibility state, following detection of a fraudulent access signal, putting the first set of cells located in a first zone of the matrix in said “metastable” state. Brief description of the drawings

[0027] The present invention will be better understood upon reading the description of exemplary embodiments given, for purely indicative and non-limiting purposes, with reference to the appended drawings in which:

[0028] [Fig. 1] serves to illustrate an SRAM memory plane having an area formed by a set of cells capable of being put into sleep mode by placing them in a metastable state while other areas of the memory are freely accessible for reading;

[0029] [Fig.2] serves to illustrate a particular structure of SRAM cell to put it in a metastable state by equalizing its internal nodes;

[0030] [Fig.3] serves to illustrate an SRAM memory cell capable of being integrated into a memory device according to the invention;

[0031] [Fig.4A] serves to illustrate a way of placing a conventionally structured SRAM cell into a metastable state by disconnecting its power supply from a power supply. memory plan management;

[0032] [Fig.4B] serves to illustrate a way of placing an SRAM cell in a metastable state by equalizing its internal nodes by connecting together bit lines to which this cell is linked;

[0033] [Fig.4C] serves to illustrate a preferred variant in which the metastable state is obtained by equalizing its internal nodes and disconnecting its power supply from a power supply of the memory plane;

[0034] [Fig.5] gives an example of a timing diagram illustrating an example of operation of different areas of memory and a mode of operation in which a particular sector of memory contains cells put into a metastable state in order to limit the influence of the NBTI phenomenon while other sectors are accessible for reading.

[0035] Identical, similar or equivalent parts of the different figures bear the same numerical references so as to facilitate the transition from one figure to another.

[0036] The different parts represented in the figures are not necessarily on a uniform scale, in order to make the figures more readable.

[0037] DETAILED DESCRIPTION OF PARTICULAR EMBODIMENTS

[0038] A memory array is schematically represented in [Fig. 1] and comprises an array M of memory cells. The array is typically formed from a plurality of rows and columns of SRAM cells (not shown in this figure).

[0039] Here we distinguish two zones Z1, Z2 in the matrix M, each formed from a set of cells.

[0040] The memory comprises in particular a first set E1 of cells located in a first zone Z1 of the matrix and which it is particularly desired to protect from the NBTI phenomena mentioned previously.

[0041] According to a particular embodiment, the first zone Z1 contains cells intended to carry out a non-clonable physical function (PUF) and whose logical state, in particular the initialization logical state, is capable of being used to form a digital signature or a digital fingerprint of the memory.

[0042] To overcome the phenomena of NBTI and aging, the memory device is provided with a control circuit 10 configured to, after powering up the matrix or while the matrix is powered up and connected to a so-called “general” power supply (represented schematically by a block 3), place the first set E1 of the first zone of the matrix M1 in a particular state called “metastable” in which the respective logic state of the cells of this set cannot be distinguished.

[0043] The memory also comprises a second set E2 located in a second zone Z2 of the matrix which, when the first set El of the first zone of the matrix Ml is put into a metastable state, can be put into an operating mode where the cells are freely accessible for reading and writing. The second set E2 occupies a second zone Z2 of the matrix typically larger in terms of size than the first zone Zl.

[0044] The second set E2 can be formed from several subsets E21, E22 and advantageously include a subset E22 of cells capable of storing sensitive CSP data (for “Critical Security Parameters”).

[0045] One way of placing a memory cell in said metastable state consists, for example, of connecting its internal nodes NT, NF together.

[0046] In the particular embodiment illustrated in [Fig.2] this technique uses the addition of a transistor Ti at the memory cell level which allows the internal nodes NT, NF to be alternately connected to each other or disconnected from each other depending on the state of a signal Smet- When the internal nodes NT, NF are equalized (transistor Ti turned on), the equivalent of an erase operation of the memory cell is carried out. If a read operation were to be carried out with the nodes thus connected, there would be approximately a 50% probability of reading a value "1" and a 50% probability of reading a value "0", and in any case the value read no longer corresponds at all to that which could have been memorized prior to the equalization operation.The transistor Ti will be made non-conducting after “erasing” the nodes NT, NF to be able to “reset” the cell and put it back in a configuration allowing it to be accessible again in “normal” writing and reading mode.

[0047] It may be preferable to maintain a conventional arrangement of the cells, without modification of their internal structure, in particular in order to limit the size. In this case, the “metastable” state can be achieved by other means as specified below.

[0048] Thus, in [Fig.3], a cell of conventional structure SRAM Cy is represented with its two storage nodes NT and NF, provided to store a first logical information, and a logical information complementary to the first information. The maintenance of the logical information in the nodes is ensured by transistors forming inverters INV1, INV2 looped on themselves. For example, when the SRAM cell is of the type commonly called "6T" and thus formed of 6 transistors. The two inverters INV1, INV2, are typically made by two load transistors and two conduction transistors. The inverters INV1, INV2 are connected to a first power supply line, in particular a VirVDD power supply line called "high", and to a second LGND power supply line, in particular a so-called "low" power supply line.

[0049] Cell Cy receives power through the high power line VirVDD when connected to a general power supply of the memory plane, for example set to a potential VDD. Access to the storage nodes NT and NF is achieved by means of two access transistors TAt and TAF connected respectively to bit lines BLT and BLF generally shared by the SRAM cells of the same column of cells of the matrix plane. This access to the storage nodes NT and NF is controlled by a word line WL generally shared by the SRAM cells of the same row of cells of the matrix plane. The access transistors TAt and TAF are thus designed to allow, when they are activated (i.e. turned on), access to the first NT node and the second NF node, and when they are deactivated, to block access to the first NT node and the second NF node from the bit lines BLT and BLF.

[0050] Different ways of placing in a “metastable state” a first set E1 of cells whose internal structure is conventional and as previously described in connection with [Fig.3] are illustrated in Figures 4A-4C.

[0051] In order not to overload these figures, only one column of cells Cin-i,.. .Ci0 of the first set El is shown. The cells Cin_i,.. .Ci0 are here put into a metastable state by disconnecting or leaving disconnected a high supply line VirVDD of the memory cells.

[0052] In the example illustrated in [Fig.4A], a switch element 160, typically in the form of a transistor, in this example of PMOS type, is arranged between the high supply line VirVDD and the general supply of the memory plane, for example carried by a gate or a supply line 170 set to a potential VDD.

[0053] Depending on the state of a control signal (not shown) emitted by a control circuit 120, the switch element 160 is configured to connect or disconnect the high supply line virVDD from the power supply 170. The disconnection is carried out here when the transistor 160 is made blocked. The first inverter INV1 and the second inverter INV2 are then not powered. The internal nodes NT and NF of the cells Cin.i,.. .Ci0 are then typically established at the same potential or substantially at the same potential, here typically corresponding to ground. By substantially at the same potential is meant which differs by less than 10 mV.

[0054] In this case, the cells are also in a metastable state so that no logical state can be distinguished by accessing the nodes of the cells.

[0055] Another way to place the cells in a metastable state is to equalize the internal nodes NF, NT of the memory cells.

[0056] In the particular embodiment illustrated in [Fig.4B], the equalization of the nodes NF, NT of the cells of the i-th column is carried out by connecting together the bit lines BLTi and BLFi and by coupling the bit lines BLTi and BLFi to these nodes NF, Nt through the access transistors TAt and TAF. The access transistors are thus in this example activated (ie made passing) via the word lines WL0 .. .WLni to allow the equalization of the nodes NF, NT.

[0057] A switching element 180, formed for example by a transistor 180, here of type N, can be provided between the bit lines BLTi and BLFi.

[0058] Thus, depending on the state of a signal applied to the gate of this transistor 180, the bit lines BLTi and BLFi can be alternately connected together when it is desired to put the cells into an operating mode in which they are placed in a metastable state or else the bit lines BLTi and BLFi can be disconnected from each other to allow the nodes NF, NT to be set to respective values different from each other in another operating mode, for example where it is desired to read the data stored by the cells of the first set.

[0059] When the bit lines BLTi and BLFi are connected to each other, these bit lines BLTi and BLFi can also be isolated from bias lines 193, 194 placed for example at the potential VDD of a circuit peripheral to the memory plane and which can be located at one end of the column of cells, generally at the bottom of the column. A switch element 191 is thus provided to alternately ensure coupling or decoupling between the first bit line BLTi and a first bias line 193. Similarly, a switch element 192 is provided to alternately ensure coupling or decoupling between the second bit line BLF and the second bias line 194. In the example illustrated, these switch elements are in the form of coupling transistors 191, 192 for example of the PMOS type.The switch elements 191 and 192 can be used and possibly activated during an initialization operation.

[0060] A preferred embodiment for placing cells in a metastable state while limiting matrix consumption is illustrated in [Fig.4C].

[0061] To put the cells in a metastable state, it provides both an equalization of the internal nodes NF, NT (here when the switch element 180 is made conducting) and a maintenance of the cells without power supply (here when the switch element 160 is made blocking). The device thus differs from that described previously with [Fig.4B] by the additional control of the switch element 160 to no longer power the cells when they are put in the metastable state.

[0062] A control circuit 120 producing in particular the control signals for the switches 160, 180 and for activating the transistors applied to the word lines WL0,...,WLn i is shown schematically in FIGS. 4A-4C. It may be formed from a set of logic gates and may also comprise one or more flip-flop(s), and / or multiplexer(s), and / or delay stage(s).

[0063] In the example illustrated in [Fig.4C] the circuit 120 is intended in particular to receive as input one or more signals coming from a controller module 210 of PUF. The PUF controller module 210 may be in the form of a dedicated digital circuit or in the form of a digital function performed by a processor. The transition from an operating mode in which the cells are in a meta-tastable state to an operating mode in which the cells can be accessed for reading, and possibly for other operations, may be triggered in particular by an SPUF signal requesting access to the first set El of cells.

[0064] Thus, when one wishes to access identification or authentication data of the memory relating to the PUF (“Physically Unclonable Function”) serving as a digital signature or digital fingerprint of the memory, the PUF controller module 210 transmits to the control circuit the signal SPUFC. This signal SPUF makes it possible to trigger the performance of various operations including in particular at least one free initialization operation of the internal nodes of the cells of the first set E1 and possibly a biased initialization as described below. During these initialization operations, the internal nodes NT, NF of the cells are established at respective distinct potentials, from which it follows that values are stored in memory in the PUF zone and that it is possible to read them.

[0065] An initialization phase therefore consists of changing a memory cell from an “undetermined” (and undeterminable by reading) or “metastable” state to a state with a “determined” stored value (and therefore determinable by reading). An initialization phase can be carried out when the memory device is powered up or following an erasure operation having, for example, been triggered following detection of fraudulent access to the memory. Thus, reference can be made to a first patent application FR, No. 1761692, filed on December 6, 2017 in which a fast erasure mechanism is described.

[0066] Reference may also be made to a second French patent application No. 2111286 filed by the applicant on October 25, 2021 before the National Institute of Intellectual Property in which different initialization mechanisms are described.

[0067] A so-called "free" initialization mode consists of letting each memory cell initialize to a specific value during the progressive power-up of the elements constituting the memory cell, in particular the two looped inverters (see above in connection with figures 2 and 3), without seeking to impose a value "0" or "1" on the internal nodes NT and NF of the cell. In the free initialization mode, the access transistors TAt and TAF are first of all not conducting, and the high supply line VirVdd is set to the supply potential Vdd in order to supply the first inverter and the second inverter.

[0068] In contrast, a so-called deterministic initialization mode consists of imposing or forcing a value to be memorized by the cell during its transition from an indeterminate state to a determined state. To impose a value during initialization, the memory device comprises at the bottom of the column means for imposing a value on the internal nodes of the cells being initialized, via the bit lines and by making the access transistors of the cells concerned conductive. In this second patent application, the initialization value that one wishes to impose may be “0” or “1”. The deterministic initialization means described in this second application, in particular in connection with Figure 4, make it possible to write all the memory cells either to “0” or to “1”. To do this, the device provides for controlling, for each column, one of the BLT or BLF bit lines by connecting it to a supply voltage by turning on a bit line selection transistor. The selected and powered bit line thus tends to impose a value “1” on one of the nodes of each memory cell connected to this bit line.

[0069] In this second patent application, a biased initialization mode is also described in connection with its figure 6. In this biased initialization mode, as for a deterministic initialization, a different polarization is ensured between the first bit line BLT and the second bit line BLF while activating the access transistors TAt and TAF of the initialized cells. Instead of applying a voltage Vdd or Gnd on the bit lines BLT and BLF to "force" an initialization value, a voltage Vdd is instead applied to one of the bit lines and Vdd-AV to the other bit line. Alternatively, a voltage Gnd can be applied to one of the bit lines and Gnd+AV to the other bit line.Thus, in the biased initialization mode, we only seek to "unbalance" the memory cells by favoring the switching of each memory cell towards a predefined stored value ("1" or "0"), but without forcing the switching of the memory cells towards this predefined state. The advantage of this biased initialization mode is that it allows to quickly detect the cells which are initialized naturally (during a free initialization) to "1" or to "0" with a high probability. In other words, if a cell has for example a high probability of being initialized to "1" during a free initialization, it will still be able to be initialized to "1" during a biased initialization favoring writing to "0", by "resisting" the imbalance more than another memory cell which would have a lower probability of being initialized to "1" during a free initialization.

[0070] [Fig. 5] gives an example of a timing diagram of the operation of a memory device as described previously. The time scale on this timing diagram is not represented in a linear manner, the ratio of the durations respectively between the instants t1 and t2 and between the instants t2 and 3 being typically much greater than on this schematic representation.

[0071] When the matrix is powered up, which results, for example, in a transition from 0 to VDD of a grid or conductive line 170 between an instant t0 and an instant t1, the cells of the first set El are preferably maintained in a meta-tastable state. To do this, their high supply line VirVdd is disconnected from this gate or conductive line 170 and / or their internal nodes NT and NF are connected to each other, for example by activating their access transistors TAt and TAF and by connecting the bit lines BLTi, ..., BLFi to each other via the switching element 180. The internal nodes NT and NF of the cells of the first set are then maintained at equal or substantially equal potentials (i.e. at values which differ by less than 10 mV). A reading circuit, for example equipped with a detection amplifier at the bottom of the column, is then not capable of detecting the difference in potentials between the internal nodes NT and NF of the cells of the first set.

[0072] It is noted that initialization of the cells making it possible to maintain a metastable state of the cells during power-up (between t0 and t1) requires providing a memory device control device ensuring the equivalent of a short circuit between the internal nodes NT and NF of each of the cells. To do this, the memory device control circuit can use all or part of the “short circuit” or “erasure” means described in relation to FIGS. 2 to 4.

[0073] Alternatively, it is possible to let the memory cells of the set El initialize freely, as is conventionally done. It is also possible, according to another variant, to provide that the memory cells of the set El are initialized, during this power-up phase (between t0 and t1), according to a deterministic initialization mode, for example to set all the cells to “0” or “1”.

[0074] Concomitantly, the cells of the second set E2 are powered, therefore with their high power supply line connected to the gate or conductive line 170. The cells of this set E2 will be initialized according to the initialization mode provided for powering up. Thus, it can for example be provided that the cells of the set E2 will have a free initialization by providing that the internal nodes of the cells of the second set are isolated from each other and then establish themselves at different potentials from each other, so that a reading circuit reading the cells after initialization (after t1) is capable of detecting the difference in potentials between the internal nodes NT and NF. Alternatively, it is possible that the initialization of the cells of the set E2 are initialized to predefined values using a deterministic initialization device for example such as that described in the second aforementioned application.

[0075] During a phase between an instant t1 and an instant t2, the device is in a so-called “normal” operating mode, which corresponds to a majority of the overall operating time of the matrix when it is powered, for example at least 99% and in this example 99.9% of the time when the power supply conductive grid is powered and thus brought to the supply voltage VDD. In this operating mode, the cells of the first set El are maintained in their meta-tastable state while the cells of the second set E2 are kept accessible in read / write mode, in particular as long as no fraudulent access is detected.

[0076] Then, from time t2, another phase called “PUF access” is triggered. The triggering of this phase can be initiated by the PUF controller module 210 which, by means of the SPUF signal which changes state, makes it possible to trigger the transition to a second operating mode of the cells of the first set E1.

[0077] This second operating mode may in particular be an operating mode in which one wishes to access the cells of the first set in order to carry out an enrollment procedure to determine the cells that one wishes to use to create a digital signature and / or an encryption key (PUF), or in order to read a digital signature and / or an encryption key contained in certain cells of this first set E1 (the enrollment procedure having already been carried out).

[0078] It is noted, as is known to those skilled in the art, that an enrollment procedure for searching for PUFs typically requires performing a large number of free initializations of the PUF area E1 in order to establish a statistic for each cell establishing a probability of free initialization at “1” or “0”. Following the production of this statistic, a choice of cells is made to form the PUF by retaining the cells having the highest probabilities of being freely initialized at “1” or at “0”.

[0079] As described in the second patent application mentioned above, the use of biased initialization makes it possible to speed up this search and to limit the number of initializations to be carried out to establish the statistics.

[0080] Once the PUF has been established, after an enrollment procedure, it is possible to provide a single interrogation of the PUF zone or to request a “challenge” consisting, as is known to those skilled in the art, of performing a free initialization of the PUF zone and recovering the values of the cells previously identified to form the response to the challenge and deliver a secret value.

[0081] An example of a sequence of operations during an authorized PUF access, between times t2 and t3, is described below in relation to [Fig. 5]. During this PUF access, in this example, an attempt is made to perform a PUF enrollment procedure.

[0082] For this access to the PUF, the cells of the first set El are initialized (phase ¢1), for example by performing a “free” initialization. For this, the access transistors are then non-conducting and the bit lines BLTi, ..., BLFi are disconnected from each other by means of the switching element 180 which is made blocked. The switch element 160 is made conductive so as to connect the high supply line VirVdd to the supply gate. Alternatively, it can be provided that the first initialization memory cells during a PUF access are performed according to a deterministic access for security reasons.

[0083] During a phase ¢2, we will seek to define the cells that we retain to form the PUF in fine. We thus carry out successive initialization operations, free or biased as explained previously. Between two initializations, it is necessary to carry out an erasure operation using one of the erasure methods described previously.

[0084] During the PUF access phase, an attempt at fraudulent access to the memory may possibly be detected. A fraudulent access detection module may then be provided to transmit to the control circuit a fraudulent access detection signal making it possible to trigger the passage of the cells into a metastable state again.

[0085] Such a fraudulent access detection module can be equipped with functions similar to those of a TAMP module present in an STM32GO microcontroller marketed by the company STMicroelectronics and described in the notice “STM32GO -TAMP, tamper and back-up registers, revision 1.0”. Thus, between the times tB and tc, the cells of the first set El can be placed again in a metastable state by equalizing its internal nodes and / or switching off their power supply.

[0086] If the signature search operation is not completed and must continue, the search process is resumed, comprising operations for initializing and erasing the cells of the first set E1 (phase ¢3).

[0087] A new change of state of the signal transmitted SPUF by the PUF controller module 210 can, from a time t3, make it possible to return to a “normal” operating mode in which the cells of the first set are put back into the metastable state. This change of state of the signal SPUF occurs in particular at the end of an enrollment operation or at the end of an “interrogation” or “challenge” operation of the PUF zone.

[0088] Outside of the times of authorized access to the PUF area, the cells of the PUF memory are therefore maintained in a metastable state in the present invention. The interest of maintaining the cells in a metastable state is to eliminate, at the very least to greatly reduce, the NBTI phenomenon described previously. Thus, the PUF area is protected against the effects of aging and its reliability is much greater and maintained over time.

Claims

Claims

1. Static random access memory device comprising a memory matrix (M) provided with SRAM memory cells, each of said cells of said set comprising a first storage node (NT) and a second storage node (NF), the device being further provided with a control circuit (160, 180, 120, Ti) of said cells configured to, after powering up the matrix (M), put the matrix into a first operating mode in which a first set (El) of cells located in a first zone (Zl) of the matrix is in an indeterminate state called "metastable" for which their respective first storage node (NT) and second storage node (NF) are set and maintained at equal or substantially equal potentials while a second set (E2) of cells located in a second zone (Z2) of the matrix (M) distinct from the first zone (Zl) are in a determined state in which,following an initialization or writing operation, their respective first node (NT) and second node (Nt) are maintained at respective different potentials between a low state, corresponding in particular to a given logic state '0', and a high state, corresponding to a complementary logic state '1', allowing the memorization of a value by the cells of this second zone.,

2. A static random access memory device according to claim 1, wherein the first set (El) of cells contains a physical unclonable function (PUF).

3. Static random access memory device according to one of claims 1 or 2, wherein following the powering up of the matrix (M) at least one gate or conductive line (170) is set to a supply potential (Vdd) and in which the control circuit is provided with at least one switch element (160) capable, alternately, of connecting or disconnecting a supply line (VirVdd) of cells of said first set to said gate or conductive line (170), and in which the cells are put into the metastable state by disconnecting the supply line (VirVdd) from said gate or conductive line (170).

4. Static random access memory device according to one of claims 1 to 3, in which the cells of the first set (El) are put into said “metastable” state by connecting one to the other. of their respective first and second storage nodes.

5. A static random access memory device according to one of claims 1 to 4, wherein each cell of said first set is provided with: - a first inverter (INV1) and a second inverter (INV2) connected crosswise between said first storage node and said second storage node, the first inverter and / or the second inverter being connected to a so-called "high" supply line (VirVdd) which can be set to a supply potential (VDD), - a first access transistor (TAt) to the first storage node (NT) and a second access transistor (TAF) to the second storage node (Nf), the first access transistor and the second access transistor being respectively connected to a first bit line (BLT) and to a second line (BLF), the control circuit is provided with at least one switching element (180) capable of alternately connecting the first bit line and the second bit line to each other or disconnecting one from the other,the cells of the first set being put into the so-called “metastable” state by said control circuit by activating the access transistors and connecting the first bit line to the second bit line.,

6. Static random access memory device according to one of claims 1 to 5, further comprising a module (210) intended to produce a digital signature and / or an encryption key from data stored in cells of said first set of cells, said module (210) being capable of producing a signal (SPUF) requesting access to the first set of cells, the control circuit being configured to, following the reception of said access request signal (SPUF), put the cells of said first set of cells in a state allowing an operation of storing a value after an initialization operation and in a state of accessibility in reading, in - by isolating from each other the first node (NT) of the second node (NT) of each cell of the second set or, - applying a supply potential (Vdd) to the cells of the first set, or - isolating the first node (NT) from the second node (NT) of each cell of the first set while applying a supply potential (Vdd) to the cells of the first set.

7. A static random access memory device according to claim 6 when attached to claim 5, wherein to set the cells of said first set of cells are initialized freely by turning off their first access transistor (TAt) and second access transistor (TAf) while setting the high supply line (VirVdd) to the supply potential (VDD) in order to power their first inverter and their second inverter.

8. A static random access memory device according to claim 7, wherein the control circuit (160, 180, 120, Ti) is configured to, following detection of a fraudulent access signal, put the first set (El) of cells located in a first zone (Zl) of the matrix into said metastable state.