Random number generation circuit

A metastability management circuit in random number generation circuits addresses flip-flop metastabilities, ensuring accurate and compliant random number generation by filtering out erroneous outputs and stabilizing the Beat signal.

FR3163753A1Pending Publication Date: 2025-12-26COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
FR2024006833
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing random number generation circuits based on coherent sampling ring oscillators fail to account for metastabilities in flip-flops, leading to incorrect output values and deviations from stochastic models.

Method used

Incorporate a metastability management circuit to remove counter output values resulting from metastabilities in flip-flops and reset the counter on each rising or falling edge, or generate a metastability-free Beat signal using a majority vote among delayed flip-flop samples.

Benefits of technology

Ensures accurate random number generation by eliminating metastability-induced errors, maintaining compliance with stochastic models, and enhancing measurement accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Random Number Generation Circuit. This description concerns a circuit (3). Identical first and second ring oscillators (R1, R0) provide first and second periodic signals (S1, S0). A flip-flop (102) samples the first signal (S1) at the beginning of each period of the second signal (S0). A counter (COUNTER) is clocked by the second signal (S0). A metastability management circuit (GM) removes output values ​​(N) from the counter resulting from metastabilities of the first flip-flop (102), and resets the counter (COUNTER) on each rising and / or falling edge of an output (Beat) of the first flip-flop (102). Figure for the abstract: Fig. 3
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Random number generation circuit technical field

[0001] This description relates generally to electronic circuits, and, more particularly, to the random number generation circuit. Previous technique

[0002] A random number generation circuit uses an entropy source to generate random numbers, for example to generate a bit of a random number.

[0003] Known sources of entropy are based on metastabilities that can occur in a flip-flop, for example a D flip-flop, when a signal sampled by the flip-flop has an edge, that is to say a change in binary value, which is too close to an edge of a timing signal that triggers sampling.

[0004] Other known sources of entropy are based on the jitter of ring oscillators. This is the case, for example, with coherently sampling ring oscillator random number generation circuits designated by the acronym "COSO TRNG" (from the English "COherent Sampling ring Oscillator based True Random Number Generation").

[0005] Figure 1 shows an example of a coherent sampling ring oscillator random number generation circuit. Figure 1 more particularly shows a portion of a COSO-type random number generation circuit; the elements for producing a random bit from the output value N of a counter are not shown.

[0006] Circuit 1 comprises two identical ring oscillators RI and R0. Oscillator RI, respectively R0, provides a periodic output signal SI, respectively S0. Signal SI, respectively S0, has a period T1, respectively T0. In particular, since oscillators R0 and RI are identical, the periods T1 and T2 are similar, or, in other words, the ratio between the frequencies of the two oscillators R0 and RI is, for example, less than 1.5.

[0007] Circuit 1 further includes a synchronous flip-flop 102 (FF), for example of type D (D flip-flop). The flip-flop 102 is configured to sample the signal S1 at the frequency of the signal S0.

[0008] In other words, the flip-flop 102 is configured to update a Beat output signal at each period beginning of the signal S0 with the binary value of the signal SI, each period beginning of the signal S0 corresponding to an active edge of the signal S0, by example a rising edge. Between two successive updates of the Beat signal, the Beat signal is maintained at its current value, that is to say the value taken by the Beat signal during the first of the two successive updates.

[0009] For example, the flip-flop 102 includes a data input D configured to receive the signal SI, a synchronization (timing) input CK of the Beat signal updates configured to receive the signal S0, and an output Q configured to provide the Beat signal.

[0010] The two oscillators RI and R0 and the flip-flop 102 form an entropy source 100. The randomness extracted from the entropy source 100 is generated from the value of the period T of the Beat signal. The Beat signal is a periodic signal having an average period Tm whose average duration Nm, expressed in periods of the signal S0, is inversely proportional to the difference between the periods Tl and T0, according to the formula Nm = Tl / (Tl-T0). The Beat signal has an instantaneous period T that varies with the jitter of the signal SL. Thus, the measurement of the period T, that is to say, the duration of the period T, is representative of the jitter of the signal SL.

[0011] The Beat signal is said to be representative of the phase between the signals SI and S0 for example because it takes a first binary value, respectively a second binary value, as long as the phase between the signals S1 and S0 is such that each active edge of the signal S0 occurs while the signal SI is at a first binary level, respectively at a second binary level.

[0012] To measure the period T of the Beat signal, circuit 1 includes a COUNTER circuit. The COUNTER circuit is configured to provide, for each period T of the Beat signal, a value N, for example in the form of a numeric word, equal to the number of periods T0 of the S0 signal counted during the period T of the Beat signal. In other words, the COUNTER circuit is configured to measure the duration of each period T of the Beat signal as a number N of periods T0 of the S0 signal.

[0013] By way of example, the COUNTER circuit includes a reset input R receiving the Beat signal, a synchronization input C receiving the S0 signal, and an output O providing the counted values ​​N. At the beginning of each period T0 of the S0 signal, for example, at each rising edge of the S0 signal, the COUNTER circuit increments the current count value by one. At the beginning of each period T of the Beat signal, for example, at each rising edge of the Beat signal, the COUNTER circuit resets the current count value to zero. Preferably, the value N available at the output of the COUNTER circuit, at output O, is updated from the current count value at each reset of the COUNTER by the Beat signal, just before this current count value is reset to zero. In other words, the value N available at the output of the COUNTER circuit is updated at each reset of the COUNTER by the Beat signal, with the value The number of TO periods of the SO signal counted since the previous reset is stored, and the current output value N of the COUNTER is maintained until the next reset of the COUNTER. In other words, preferably, the COUNTER includes a register that receives the current count value as the input signal and the Beat signal as the timing signal, and provides the value N as the output signal. This register is configured to update the value N at each reset of the current count value, just before the current count value is reset to zero.

[0014] Although not illustrated in [Fig. 1], by way of example, circuit 1 further includes a circuit configured to control or modify the period of at least one of the two oscillators RI and RO so that the difference between periods T1 and TO is equal to a target difference. The modification of the period T1 of the RI oscillator and / or the period TO of the RO oscillator by this circuit is, for example, implemented based on the output values ​​N of the COUNTER circuit. For example, for a target value Nmt of the average number of TO periods Nm per period T of the Beat signal, if the output value N is less than Nmt, the difference between periods T1 and TO is reduced, and if the output value N is greater than Nmt, the difference between periods T1 and TO is increased.

[0015] For example, when the two oscillators RI and RO are implemented in complementary metal-oxide-semiconductor (CMOS) technology on semiconductor-on-insulator (SOI), preferably on fully depleted silicon-on-insulator, the modification of the period T1 of the RI oscillator, or of the period T0 of the RO oscillator respectively, can be implemented by controlling the back gates of at least one delay element, for example an inverter, of the RI oscillator, or of RO respectively. An example of such control of the gap between the periods of two ring oscillators of a COSO-type random number generator circuit is described in more detail in French application FR 3 140 968, European patent application EP 4 354 279 A1, and US patent application 2024-0128957 Al.

[0016] By way of further example, whether or not the RI and R0 oscillators are implemented in CMOS on SOI or FDSOI, the modification of the period T1 of the RI oscillator, and of the period T0 of the R0 oscillator respectively, is implemented differently, for example by selecting one propagation path of an oscillation from among several possible ones, or by modifying the oscillator's supply conditions. For example, see the paper by A. Peetermans, V. Rozic, and I. Verbauwheden entitled "A Highly-Portable True Random Number Generator Based on Coherent Sampling", published in 2019 in the 29th International Conference on Field Programmable Logic and Applications (FPL) another example of adjusting the relative periods of two ring oscillators.

[0017] However, the use of the back grids to modulate the period of at least one of the RI and RO oscillators when these are implemented in CMOS on SOI or FDSOI allows for greater tuning dynamics and better tuning accuracy of the gap between the periods T1 and T0.

[0018] As yet another example, circuit 1 may be devoid of a circuit for adjusting the difference between periods T1 and T0.

[0019] In circuit 1, in each of the oscillators R0 and RI, the ratio R between the oscillator period and its jitter is determinable and depends on the oscillator implementation technology. When the oscillators are implemented in CMOS on FDSOI, this ratio R is, for example, on the order of 1000. In practice, for a given technology, this ratio can be obtained through a characterization phase, for example, of a plurality of circuits.

[0020] Furthermore, in circuit 1, the measurement accuracy is determined by the difference between the periods T1 and T0. More specifically, the measurement accuracy is equal to 1 / Nm.

[0021] Sufficient measurement accuracy is obtained, for example, when Nm is substantially equal to R. However, in other examples, a measurement accuracy where Nm is less than R may be sufficient. A person skilled in the art is able to determine a target measurement accuracy based on the application.

[0022] There are known stochastic models of the entropy source 100 of circuit 1, for example, models that mathematically define entropy based on phase noise. These stochastic models are used to characterize the entropy source 100, and therefore the random number generation device 1. Such characterization is, for example, necessary for obtaining certification of the device 1, for example, according to the AIS20 / 31 standard.

[0023] However, in [Fig. 1], when a rising edge of the SI signal occurs during a setup time preceding a rising edge of the S0 signal that triggers sampling of the SI signal by flip-flop 102, or during a hold time following a rising edge of the S0 signal that triggers sampling of the SI signal by flip-flop 102, flip-flop 102 can enter a metastable state, and the Beat output of flip-flop 102, i.e., the sample provided by flip-flop 102, can then take on an incorrect value that does not correspond to the value of the SI signal at the time of the rising edge of the S0 signal that triggered sampling. This metastability phenomenon, although it serves as a source of entropy in random number generation devices, is not taken into account in known stochastic models of the entropy source 100.

[0024] It follows that a hardware implementation of the entropy source 100, which expresses metastability noise in addition to phase noise, has an operation which deviates from its stochastic model, which is not desirable. Summary of the invention

[0025] There is a need to take into account, in a random number generation circuit of the coherent sampling type of ring oscillator, metastabilities that may occur in the flip-flop sampling an output signal from a first ring oscillator at the beginning of each rising or falling edge of an output signal from a second oscillator identical to the first oscillator.

[0026] An embodiment overcomes all or part of the disadvantages of known random number generation circuits of the coherent sampling type of ring oscillator.

[0027] One embodiment provides a random number generation circuit comprising: a first ring oscillator and a second ring oscillator identical to the first, configured to provide respectively a first periodic signal and a second periodic signal; a first flip-flop configured to sample the first signal at the beginning of each period of the second signal; a counter timed by the second signal; and a metastability management circuit configured to: - remove counter output values ​​resulting from metastabilities of the first flip-flop, and to reset the counter on each rising edge and / or each falling edge of an output of the first flip-flop, or - generate a third signal devoid of metastability from at least the output of the first flip-flop, and to reset the counter at each rising edge and / or each falling edge of the third signal.

[0028] According to one embodiment, the metastability management circuit is configured to: to reset the counter on each rising edge and / or each falling edge of the output of the first flip-flop; and remove counter output values ​​resulting from first flip-flop metastabilities by removing counter output values ​​below a threshold determined at least in part by a first flip-flop setup time, a first flip-flop hold time, and a difference between an average value of the first signal period and an average value of the second signal period.

[0029] According to one embodiment, the threshold is determined by the following formula: Nmin = (ts + th) / DT, with Nmin the threshold, ts the setup time, th the maintenance time and DT the difference between the average value of the period of the first signal and the average value of the period of the second signal.

[0030] According to one embodiment, the threshold is determined by the time of setting up the first flip-flop, the time of holding the first flip-flop, the difference between the average value of the period of the first signal and the average value of the period of the second signal, a standard deviation on the jitter of the first signal and a standard deviation on the jitter of the second signal.

[0031] According to one embodiment, the threshold is determined by the following formula: Nmin = (ts + th + ol) / (DT + oO), with Nmin the threshold, ts the setup time, th the holding time, DT the difference between the average value of the period of the first signal and the average value of the period of the second signal, ol the standard deviation on the jitter of the first signal and oO the standard deviation on the jitter of the second signal.

[0032] According to one embodiment, the metastability management circuit is configured to reset the counter at each rising edge and at each falling edge of the output of the first flip-flop.

[0033] According to one embodiment, the metastability management circuit is configured to reset the counter at each rising edge and / or each falling edge of the third signal, and to generate the third signal by a majority vote between the output of the first flip-flop, P first samples obtained at each period of the second signal by sampling the first signal at P successive times delayed relative to the beginning of said period, and P second samples obtained at each period of the second signal by sampling at the beginning of said period P fourth signals delayed differently relative to the first signal, P being an integer greater than or equal to 2.

[0034] According to one embodiment, at each period of the second signal: the P successive instants are delayed relative to the beginning of said period by delays equal respectively to i*D, with D a time period and i an integer from 1 to P; and The fourth P signals are delayed relative to the first signal by delays equal respectively to j*D, with j an integer from 1 to P.

[0035] According to one embodiment, the time period D is at least partly determined by a time for setting up the first flip-flop and a time for maintaining the first flip-flop.

[0036] According to one embodiment, a value for the time period D is chosen such that: T01m / 2 > P*D > ts+th, with ts the setup time, th the maintenance time and TOlm an average value of the first and second signal periods.

[0037] According to one embodiment, a value for the time period D is chosen such that: T01m / 2 > P*D > ts+th+ol+oO, with ts the setup time, th the holding time, TOlm an average value of the first and second signal periods, o I a standard deviation on the jitter of the first signal and oO a standard deviation on the jitter of the second signal.

[0038] According to one embodiment, the metastability management circuit comprises: P first delay circuits configured to each receive the first signal and to respectively provide the P fourth signals; P second flip-flops identical to the first flip-flop and configured to sample respectively the P fourth signals at the beginning of each period of the second signal so as to provide respectively the P second samples; P second delay circuits identical respectively to the first P delay circuits, and configured to each receive the second signal and provide respectively P fifth signals delayed differently with respect to the second signal; and P third flip-flops identical to the first flip-flop and configured to sample the first signal at the beginning of each period of the P fifth signals respectively and provide the first P samples; and an arbitration circuit configured to receive the first P samples, the second P samples and the output of the first flip-flop and to provide the third signal from the first P samples, the second P samples and the output of the first flip-flop. Brief description of the drawings

[0039] These features and advantages, as well as others, will be described in detail in the following description of particular embodiments, given by way of non-limiting example, in relation to the accompanying figures, among which:

[0040] The [Fig.1], described above, represents an example of a coherent sampling type random number generation circuit of ring oscillator;

[0041] [Fig.2] represents timing diagrams of two signals from the circuit of [Fig.1];

[0042] Figure 3 represents an embodiment of a number generation circuit random type with coherent sampling of ring oscillator;

[0043] [Fig.4] represents an example of output value distribution of a counter in the circuit of [Fig.1];

[0044] Figure 5 represents an example of an embodiment of a coherently sampling ring oscillator random number generation circuit; and

[0045] [Fig. 6] illustrates, by means of timing diagrams, the operation of the circuit of [Fig. 5]; and

[0046] [Fig.7] represents another example of an embodiment of a coherent sampling type random number generation circuit of ring oscillator. Description of the implementation methods

[0047] The same elements have been designated by the same reference numerals in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same reference numerals and may have identical structural, dimensional and material properties.

[0048] For the sake of clarity, only the steps and elements useful for understanding the described embodiments have been shown and are detailed. In particular, the known circuits used in a COSO-type random number generator to generate a random bit from an output N of a counter configured to count the number of periods of a first oscillator during one or half a period of a Beat signal output from a flip-flop sampling a second oscillator identical to the first at the frequency of the first oscillator, have not been described. Indeed, the embodiments and variants described here are compatible with these known circuits.

[0049] Unless otherwise specified, when referring to two elements connected together, this means directly connected without intermediate elements other than conductors, and when referring to two elements coupled together, this means that these two elements can be connected or linked through one or more other elements.

[0050] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "superior", "inferior", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made, unless otherwise specified, to the orientation of the figures.

[0051] Unless otherwise specified, the expressions "approximately", "roughly", and "on the order of" mean to within 10% or 10°, preferably to within 5% or 5°.

[0052] It is proposed here to modify device 1 of [Fig. 1] to add a circuit for managing metastabilities in flip-flop 102. This circuit is configured to: control the resets of the COUNTER, and remove the N values ​​which are from metastabilities in the 102 flip-flop, or directly generate a Beat signal free of metastability from at least the output of the 102 flip-flop.

[0053] The Beat signal is said to be devoid of metastability, for example, when the effects of a metastable state of the flip-flop 102 on the value of the Beat signal have been removed.

[0054] For example, the Beat signal lacking metastability is generated from: samples of the SI signal obtained at the output of the flip-flop 102, samples of signals corresponding to delayed versions of the SI signal, these samplings being synchronous with the sampling of the SI signal by the flip-flop 102, other samples of the S1 signal obtained at sampling times offset in time with respect to the sampling times of the SI signal by the flip-flop 102, and a majority vote between these samples.

[0055] Preferably, the metastability management circuit is configured so as not to unbalance the load seen by the output of each of the oscillators R0 and RI compared to the case where this circuit is omitted. In other words, the metastability management circuit is configured so as not to introduce asymmetries between the load seen by oscillator R0 and that seen by oscillator RI compared to the case where this circuit is omitted. Thus, the stochastic models used to characterize the entropy source remain advantageously valid.

[0056] Figure 2 represents timing diagrams of two signals from the circuit of Figure 1. More particularly, Figure 2 represents the signals SI and S0 at a time when the signal SI is ahead in phase with respect to the signal S0 (on the left in Figure 2) and at a time when the signal S1 is behind in phase with respect to the signal S0 (on the right in Figure 2).

[0057] In the following description, the "active edge" of the signal S0 is defined as the type of edge among the rising type and the falling type, which causes sampling of the signal SI by the flip-flop 102. In the example of [Fig.2], the active edges of the signal S0 are the rising edges, although an example based on falling active edges is possible.

[0058] In [Fig. 2], the set-up time ts of the flip-flop 102 and the hold-up time th of the flip-flop 102 are shown. The time ts is the duration preceding each active edge of the signal S0 during which the signal S1 must have a stable value, and the time th is the duration following each active edge of the signal S0 during which the signal S1 must have a stable value. If the signal S1 has a stable value during the times ts and th, then the flip-flop 102 does not exhibit a metastable state.

[0059] These times ts and th define, for each active edge of the signal S0, a time window Tmeta during which a change in the value of the signal SI can leading to a metastable state of the 102 flip-flop, that is to say to a binary value of the Beat signal which does not correspond to the binary value of the SI signal at the time of the active edge of the S0 signal.

[0060] The difference between the average duration of periods T0 and T1 is denoted DT. This difference is, for example, fixed by an active control as described by way of example in relation to [Fig. 1]. As an alternative example, this difference is determined during a design phase of the oscillators R0 and RI. As another alternative example, this difference is determined during a post-fabrication characterization phase of circuit 1.

[0061] When the phase between signals SI and S0 is such that a wavefront of signal SI occurs at the beginning of the duration Tmeta of a corresponding active wavefront of signal S0, knowing DT, ts, and th, it is then possible to determine the number Nmin of periods T0 of the signal that must elapse before the phase between signals SI and S0 is such that a wavefront of signal SI no longer occurs during the duration Tmeta of a corresponding active wavefront of signal S0. Indeed, this number Nmin is determined at least in part from the difference DT and the times or durations ts and th of the flip-flop 102.

[0062] For example, the number Nmin is determined by the following relation: Nmin = (ts + th) / DT.

[0063] As an alternative example, the number Nmin is determined by further taking into account the jitter on the SI and S0 signals, i.e. the standard deviation 00 on the jitter of the SI signal and the standard deviation 00 on the jitter of the S0 signal. For example, in the case where the SI signal is in phase lead with the S0 signal (left in [Fig. 2]), for a given phase value where the edges of the SI signal would not occur in the periods Tmeta of the corresponding active edges of the S0 signal, because the jitter of the SI signal and the jitter of the S0 signal can reduce the phase difference between the SI and S0 signals, edges of the SI signal can in practice occur during the duration Tmeta of the corresponding active edges of the S0 signal. Symmetrically, in the case where the SI signal is in phase lag with the S0 signal (right in [Fig. 2]),2]), for a given phase value where the SI signal's edges would not occur in the Tmeta periods of the corresponding active edges of the S0 signal, because the jitter of the SI signal and the jitter of the S0 signal can reduce the phase difference between the SI and S0 signals, and SI signal edges can in practice occur during the Tmeta duration of the corresponding active edges of the S0 signal. In this case, to take into account the jitter of the SI and S0 signals, statistically characterized by the respective standard deviations oI and oO, the number Nmin is determined by the following relation: Nmin = (ts + th + ol) / (DT + oO). .

[0064] In practice, the counter values ​​N that are less than Nmin are values ​​N for which metastabilities in the flip-flop have given rise to unforeseen or undesired oscillations of the Beat signal, and therefore have unforeseen resets or unwanted values ​​of the COUNTER. These N values ​​less than Nmin are therefore not only representative of phase noise, or jitter, of the SO and SI signals, but also of metastability phenomena in the 102 flip-flop.

[0065] The metastability management circuit therefore suppresses N values ​​that are below the threshold Nmin. In this case, the COUNTER circuit remains reset by the Beat signal output of flip-flop 102, which is directly transmitted by the metastability management circuit to the R input of the COUNTER circuit. However, when metastability leads to unwanted oscillations of the Beat signal, and thus to an untimely reset of the COUNTER circuit and an N value below Nmin, this N value is suppressed by the metastability management circuit. The suppressed N values ​​are therefore not transmitted to the digital circuits that use the N output of the COUNTER to generate a random bit.

[0066] Figure 3 represents an embodiment of a number generation circuit 3 random of coherent sampling type of ring oscillator, in the case where this circuit 3 includes a GM metastability management circuit as described above.

[0067] Device 3 includes many elements in common with device 1 of [Fig. 1], and only the differences between these two devices are highlighted here. Thus, unless otherwise indicated, everything described in relation to [Fig. 1] applies to device 3 of [Fig. 3].

[0068] Device 3 includes the entropy source 100, which is unchanged from that of [Fig. 1]. Thus, the known stochastic models used to model the source 100 in order to characterize device 1 apply to the entropy source 100 of device 3 to characterize device 3.

[0069] Compared to device 1, device 3 further includes the GM circuit delimited by dotted lines in [Fig.3].

[0070] The GM circuit is configured to suppress (or filter) N values ​​that are below the threshold Nmin described previously. Thus, the GM circuit receives the output N values ​​from the COUNTER circuit and provides corresponding Nok values. The Nok values ​​are the N values ​​that are above the threshold Nmin. This function of the GM circuit is represented in [Fig. 3] as a block 300 ("N > Nmin" in [Fig. 3]). For example, this block 300 includes a digital circuit for comparing each received N value to the threshold Nmin, and a circuit configured to provide a Nok value equal to the received N value only if this received N value is strictly above the threshold Nmin. In other words, the block 300 corresponds, for example, to an ideal digital high-pass filter having a cutoff value Nmin.

[0071] The GM circuit is further configured to control the resets of the COUNTER.

[0072] According to one embodiment, the GM circuit is configured to reset the COUNTER circuit on each rising edge of the Beat signal, or on each falling edge of the Beat signal. In this case, the output values ​​N of the COUNTER that do not result from metastability correspond to the number of periods T0 of the signal S0 during a period of the Beat signal that has not been affected by metastabilities in the flip-flop 102. By way of example, the GM circuit is configured to directly supply the Beat signal to the input R of the COUNTER circuit, this input R being active on rising edges when the rising edges of the Beat signal cause a reset of the COUNTER circuit, and on falling edges when the falling edges of the Beat signal cause a reset of the COUNTER circuit.

[0073] According to one embodiment, the GM circuit is configured to reset the COUNTER circuit on each rising edge of the Beat signal and on each falling edge of the Beat signal. In this case, the output values ​​N of the COUNTER that do not result from metastability correspond to the number of periods T0 of the signal S0 during a half-period of the Beat signal that has not been affected by metastabilities in the flip-flop 102. By way of example, the GM circuit is configured to directly supply the Beat signal to the input R of the COUNTER circuit, this input R being active on both rising and falling edges, from which it follows that each rising and falling edge of the Beat signal causes a reset of the COUNTER circuit.

[0074] Figure 4 shows an example of the distribution of the output N values ​​of the COUNTER circuit 100 of Figure 1. In this example, one of the oscillators RI and R0 operates with an average frequency of 500 MHz, and the other of the oscillators RI and R0 operates with an average frequency of 503 MHz. As an example, the threshold Nmin is equal to 25 when calculated using the formula Nmin = (ts + th) / DT, and to 39 when calculated using the formula Nmin = (ts + th + ol) / (DT + 00). In the example in Figure 4, the COUNTER circuit is reset only on the rising edges of the Beat signal, or, alternatively, only on the falling edges of the Beat signal.

[0075] The numerical values ​​of the output N of the counter COUNTER are represented on the abscissa, and the number NB of outputs N equal to each numerical value N on the abscissa is indicated on a logarithmic scale on the ordinate.

[0076] A peak of 400 represents the values ​​N for which the Beat signal has undergone unwanted binary value changes at the beginning of a period of the Beat signal due to metastability in flip-flop 102. These unwanted oscillations of the Beat signal at the beginning of a period of the Beat signal cause closely spaced resets of the COUNTER circuit, which are a result of metastabilities in flip-flop 102. N outputs corresponding to peak 400 are indeed suppressed by the GM circuit because they correspond to values ​​less than Nmin.

[0077] A peak 402 represents the N values ​​for which the Beat signal has not undergone metastability from the beginning to the end of a period of the Beat signal. These N values ​​are therefore well representative of the number of periods T1 of the S0 signal during a period of the Beat signal in the absence of metastabilities in the flip-flop 102, and their distributions around an average value are solely the result of jitter on the S0 and SI signals.

[0078] An additional peak 404 represents values ​​N for which the Beat signal did not undergo any unwanted binary value changes at the beginning of a period of the Beat signal, but did undergo unwanted binary value changes in the middle of that period due to metastabilities in the flip-flop 102, whereas, in the absence of metastability, the Beat signal should have switched only once. These unwanted oscillations of the Beat signal at the midpoint of a period of the Beat signal cause resets of the COUNTER circuit, which are a result of metastabilities in the flip-flop 102.

[0079] Preferably, to prevent the output Nok values ​​of the GM circuit in [Fig. 4] from representing not only the duration of one period of the Beat signal but also the duration of half a period of the Beat signal, the GM circuit and the COUNTER circuit are configured so that the COUNTER circuit resets on each rising and falling edge of the Beat signal. In this case, the COUNTER circuit together with the GM circuit provide Nok values ​​that are indeed equal to the number of periods T0 of the S0 signal during half a period of the Beat signal in the absence of metastability in the flip-flop 102. As an example, by adding two successive Nok values, which correspond to the number of periods T0 of the S0 signal in two successive half periods of one period of the S0 signal, respectively, we obtain a value representative of the number of periods T0 of the S0 signal in that period of the Beat signal.

[0080] The GM circuit described in relation to Figures 2, 3 and 4 is configured to control the resets of the COUNTER and to remove the N values ​​which are from metastabilities in the flip-flop 102.

[0081] A GM circuit configured to control the resets of the COUNTER and to directly generate a Beat signal devoid of metastability will now be presented in relation to Figures 5, 6 and 7.

[0082] Figure 5 represents an example of an embodiment of a coherently sampling ring oscillator random number generation circuit 5, in the case where this circuit 5 includes a metastability management circuit. GM as described above. The GM circuit is delimited by dashed lines in [Fig.5].

[0083] Device 5 includes many elements in common with device 1 of [Fig. 1], and only the differences between these two devices are highlighted here. Thus, unless otherwise indicated, everything described in relation to [Fig. 1] applies to device 5 of [Fig. 5].

[0084] Device 5, like Device 1 in [Fig. 1], comprises the two oscillators RO and RI and the flip-flop 102 receiving the signal SI on its input D and the signal S0 on its input C. However, in [Fig. 5], the Beat signal representing the phase between the signals SI and S0 is not the output signal of the flip-flop 102, which is referenced as Q0 in [Fig. 5], but is generated by the GM circuit from this output Q0 so that the Beat signal is devoid of metastability. The GM circuit therefore receives the output Q0 of the flip-flop 102.

[0085] Circuit 5 includes the COUNTER. Input D of the COUNTER receives the signal S0, and input R of the COUNTER receives the Beat signal provided by the GM circuit. This input R can be active on rising edges only, on falling edges only, or on both rising and falling edges. The output O of the COUNTER circuit provides the value N equal to the number of periods T0 of the signal S0 counted during each period of the Beat signal if input R is active only on rising edges, or only on falling edges, and to the number of periods T0 of the signal S0 counted during each half-period of the Beat signal if input R is active on both rising and falling edges.

[0086] The GM circuit is configured here to generate the Beat signal by implementing a majority vote between: - the Q0 output of flip-flop 102, that is, the sample available at output Q of flip-flop 102; and - P samples QOi, with P an integer strictly greater than 2 and i an integer index from 1 to P, obtained at each period of the signal S0 by sampling the signal at P successive times delayed relative to the beginning of the period of the signal S0, that is to say delayed relative to the sampling time of the signal SI by the flip-flop 102.

[0087] In [Fig.5], P is equal to 2, and the GM circuit therefore generates, at each period of the signal S0, a sample Q01 and a sample Q02, corresponding to two successive sampling instants delayed relative to the sampling instant of the signal SI by the flip-flop 102.

[0088] According to one embodiment, at each period of the signal S0, the flip-flop 102 samples the signal S1 at the beginning of the period, and the P successive sampling instants are delayed relative to the beginning of the period by delays equal respectively to i*D, with D a time period.

[0089] For example, in [Fig.5], at each period of the signal S0, the flip-flop 102 samples the signal SI at the beginning of the period, and the P=2 successive sampling instants corresponding to the samples Q01 and Q02 are delayed relative to the beginning of the period by delays equal respectively to 1*D and to 2*D.

[0090] For example, the duration D is at least partly determined by the time ts and the time th of the flip-flop 102. For example, the largest delay equal to P*D is strictly greater than the duration of a time window in which metastabilities can occur, this window being at least partly determined by the time ts and the time th of the flip-flop 102, for example at least partly determined by ts+th. Furthermore, this largest delay equal to P*D is preferably less than the average half-period of the oscillators R0 and RI. P.

[0091] For example, when the time window during which metastabilities can occur is equal to ts+th, the duration D is determined solely by the times ts and th, and is chosen so that T01m / 2 > P*D > ts+th, with TOlm the average value of the periods T0 and Tl.

[0092] As an alternative example, the value D is determined by the times th and ts and, furthermore, by the jitter on the signal S0 and the jitter on the signal SI. For example, the time window during which metastabilities can occur is then equal to ts+th+ol+oO, the duration D is determined by the sum ts+th+ol+oO, and the duration D is chosen such that T01m / 2 > P*D > ts+th+ol+oO.

[0093] By way of example, the GM circuit comprises P 5020i delay circuits (50201 and 50202 in the example in [Fig. 5] where P equals 2) and P 1020i flip-flops (10201 and 10202 in the example in [Fig. 5] where P equals 2), the 1020i flip-flops all being identical to the 102 flip-flop. Each 5020i delay circuit receives the signal S0 and provides a corresponding delayed version SOdi of this signal S0. For example, each SOdi signal has a delay equal to i*D with respect to the signal S0. Each 1020i flip-flop is configured to sample the signal SI at the beginning of each period of the corresponding SOdi signal. For example, the 1020A flip-flop, respectively 10202, is configured to sample the SI signal at each period start of the SOdi signal, respectively S0d2, so as to provide the QOdl sample, respectively Q0d2.For example, each 1020i flip-flop receives the SI signal on its D input, the SOdi signal on its C input and provides the QOdi signal or sample on its Q output.

[0094] The GM circuit includes an ARB arbitration circuit configured to receive the Q0 and QOi samples, and to provide the Beat signal corresponding to the result of a majority vote between these samples.

[0095] Fig. 6 illustrates, by means of timing diagrams, the operation of circuit 5 of Fig. 5.

[0096] In particular, [Fig.6] represents the timing diagrams of the signals SI, SO, SOdl, and S0d2.

[0097] In this example, the active edges of the SO signal are the rising edges, meaning that each period of the SO signal corresponds to a rising edge of this signal. Thus, in this example, the active edges of the SOdl and S0d2 signals causing the sampling of the SI signal by the respective flip-flops 10201 and 10202 are also the rising edges of these signals, and each period of the SOdl signal, respectively S0d2, therefore begins with a rising edge of this SOdl signal, respectively S0d2.

[0098] Fig. 6 shows the delay 601, for example equal to 1*D, of the SOdl signal with respect to the S0 signal, and the delay 602, for example equal to 2*D, of the S0d2 signal with respect to the S0 signal.

[0099] In addition, in [Fig.6], the times ts and th of the flip-flop 102 around each active edge of the signal S0 are shown, the times ts and th of the flip-flop 10201 around each active edge of the signal SOdl are shown, and the times ts and th of the flip-flop 10202 around each active edge of the signal S0d2 are shown.

[0100] As can be seen in [Fig.6], a front of the signal S0 which occurs during the time ts or th of an active front of one of the signals SOdi and S0, namely the signal SOdl in the example of [Fig.6], does not occur during the times ts or th of a corresponding front of the other signals SdOi and S0, namely signals S0d2 and S0 in the example of [Fig.6].

[0101] Thus, even if one of the samples Q0 and QOi is unstable due to a metastable state of the flip-flop that provided that sample, the value of the Beat signal resulting from the majority vote between the samples Q0 and QOdi will be stable and free from the effects of that metastable state.

[0102] Table 1 below gives, for all combinations of values ​​of samples Q0 and Qdi, the corresponding value of the Beat signal.

[0103] [Tables] Q0 Q01 Q02 Beat 0 0 0 0 0 0 1 0 0 1 0 X 0 1 1 1 1 0 0 0 1 0 1 X 1 1 0 1 1111

[0104] It should be noted that, in practice, the combination Q0=0, Qdl=l and Qd2=0 cannot occur, nor can the combination Q0=l, Qdl=0 and Qd2=l.

[0105] In the example in Figures 5 and 6 above, P is equal to 2. However, the higher the value of P, the higher the confidence in the vote will be. Thus, preferably, P is chosen to be greater than or equal to 3.

[0106] In [Fig.5], the set of the two oscillators RI and R0, the flip-flop 102 and the GM circuit implement an entropy source 500 in which the effects of the metastability of the flip-flop 102, and, in practice, of the other flip-flops 1020i, are suppressed in the Beat signal provided by this entropy source 500. In this case, the variation in the duration of each half-period or each period of the Beat signal is then only related to the jitter of the signals S1 and S0.

[0107] However, to characterize the source 500, the known stochastic models are no longer completely valid. Indeed, the prediction of the GM circuit as described in [Fig. 5] introduces an additional load on the output of oscillator R0, without correspondingly modifying the load on the output of oscillator RI. As a result, the operation of the two oscillators R0 and RI is no longer entirely identical, contrary to what is generally predicted by the known stochastic models.

[0108] This problem can be addressed by a GM circuit of the type described below in relation to [Fig.7].

[0109] Fig. 7 represents another example of an embodiment of the coherent sampling ring oscillator type random number generation circuit 5.

[0110] Device 5 of [Fig. 7] includes many elements in common with Device 5 of [Fig. 5], and only the differences between these two devices are highlighted here. Thus, unless otherwise indicated, everything described in relation to [Fig. 5] applies to Device 5 of [Fig. 7].

[0111] Device 5 of [Fig.7] differs from device 5 of [Fig.5] by its GM circuit.

[0112] The GM circuit is configured here to generate the Beat signal by implementing a majority vote between: - the Q0 output of the flip-flop 102, that is to say the sample available at the Q output of the flip-flop 102; - P samples QOi (Q01 and Q0P in [Fig.7]), with P an integer strictly greater than 2 and i an integer index from 1 to P, obtained at each period of the signal S0 by sampling the signal at P successive instants delayed relative to the beginning of the period of the signal S0, that is to say delayed relative to the sampling instant of the signal SI by the flip-flop 102; and P samples Qlj (Qldl and QldP in [Fig.7]) obtained at each period of the SO signal by sampling, at the beginning of this period, P signals Sldj (Sldl and SldP in [Fig.7]) delayed differently with respect to the SI signal, with j an integer from 1 to P.

[0113] Thus, the GM circuit can be implemented symmetrically, that is, so that the load seen by the RO oscillator at its output is the same as the load seen by the RI oscillator at its output. The known stochastic models used to characterize the entropy source 100 ([Fig. 1] or 2) can be reused to characterize the entropy source 500 comprising the R0 and RI oscillators, the flip-flop 102, and the GM circuit.

[0114] According to one embodiment, at each period of the signal S0, the flip-flop 102 samples the signal SI at the beginning of the period, and the P signals Sli are delayed relative to the signal SI by delays equal respectively to j*D.

[0115] For example, in [Fig.7], at each period of the signal S0, the flip-flop 102 samples the signal SI at the beginning of the period, and at this same sampling instant, each of the signals S ldi is sampled by the GM circuit.

[0116] By way of example, the GM circuit of [Fig.7] comprises, like the GM circuit of [Fig.5], P 5020i delay circuits (50201 and 5020P in the example of [Fig.7]), P 1020i flip-flops (10201 and 1020P in the example of [Fig.7]), P 502Ij delay circuits (50211 and 5021P in the example of [Fig.7]), and P 1021j flip-flops (10211 and 1021P in the example of [Fig.7]), the 1020i and 102Ij flip-flops being all identical to the 102 flip-flop. Each 5020i delay circuit receives the signal S0 and provides a corresponding delayed version SOdi of this signal S0. Each 502Ij circuit receives the SI signal and provides a corresponding delayed version Sldj (Sldl and SldP in [Fig. 7]) of this signal. For example, each SOdi signal has a delay of i*D relative to the S0 signal, and each Sldj signal has a delay of j*D relative to the SI signal. In other words, the P 502Ij circuits are, for example, identical to the P 5020i circuits.Each 1020i flip-flop is configured to sample the SI signal at the beginning of each period of the corresponding SOdi signal. For example, each 1020i flip-flop receives the SI signal on its D input, the SOdi signal on its C input, and provides the QOdi signal or sample on its Q output. Each 102Ij flip-flop is configured to sample the Sldj signal corresponding to the beginning of each period of the S0 signal. For example, each 102Ij flip-flop receives the Sldj signal on its D input, the S0 signal on its C input, and provides the Qldj signal or sample on its Q output.

[0117] The GM circuit includes the ARB arbitration circuit, except that, in the example of [Fig.7], the ARB circuit is configured to receive the samples Q0, QOi and Qlj, and to provide the Beat signal corresponding to the result of a majority vote between these samples.

[0118] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will become apparent to them. For example, although not described, those skilled in the art may foresee another example of a GM circuit of the type described in relation to Figures 5 to 7, by providing that the Beat signal is the result of a majority vote only between the Q0 sample and the Qldj samples, i.e., for example, by removing the 5020i and 1020i circuits in the GM circuit of [Fig. 7] and adapting the ARB circuit of that GM circuit. As another example, in devices 5 of figures 5 and 7, the delay circuits 5020i and / or 502Ij can be omitted, the respective signals SOdi and Sldj then corresponding to internal signals of the respective oscillators RO and / or RI.However, although such an example is functionally identical to the device examples 5 described in relation to Figures 5 and 7, its implementation requires connecting the inputs of the 1020i and / or 102 Ij flip-flops directly to internal nodes of the respective RO and / or RI oscillators, from which it follows that the stochastic model of the entropy source will have to be adapted with respect to known models.

[0119] Finally, the practical implementation of the embodiments and variants described is within the reach of a person skilled in the art, based on the functional indications given above.

Claims

Demands

1. Random number generation circuit (3; 5) comprising: a first ring oscillator (RI) and a second ring oscillator (RO) identical to the first, configured to provide respectively a first periodic signal (SI) and a second periodic signal (S0); a first flip-flop (102) configured to sample the first signal (SI) at the beginning of each period of the second signal (S0); a counter (COUNTER) clocked by the second signal (S0);and a metastability management circuit (GM) configured to: - remove output values ​​(N) from the counter resulting from metastabilities of the first flip-flop (102), and to reset the counter (COUNTER) on each rising edge and / or each falling edge of an output (Beat) of the first flip-flop (102), or - generate a third signal (Beat) devoid of metastability from at least the output (Q0) of the first flip-flop (102), and to reset the counter (COUNTER) on each rising edge and / or each falling edge of the third signal (Beat).

2. Circuit (3) according to claim 1, wherein the metastability management circuit (GM) is configured to: reset the counter at each rising edge and / or each falling edge of the output (Beat) of the first flip-flop (102); and remove the output values ​​(N) of the counter (COUNTER) resulting from metastabilities of the first flip-flop (102) by removing the output values ​​(N) of the counter below a threshold (Nmin) determined at least in part by a setup time (ts) of the first flip-flop (102), a hold time (th) of the first flip-flop (102) and a difference between an average value of the period of the first signal (SI) and an average value of the period of the second signal (S0).

3. Circuit (3) according to claim 2, wherein the threshold (Nmin) is determined by the following formula: Nmin = (ts + th) / DT, with Nmin the threshold, ts the setup time, th the holding time and DT the difference between the average value of the period of the first signal (SI) and the average value of the period of the second signal (S0).

4. Circuit (3) according to claim 2, wherein the threshold is determined by the set time (ts) of the first flip-flop (102), the hold time (th) of the first flip-flop (102), the difference between the average value of the period of the first signal (SI) and the average value of the period of the second signal (S0), a standard deviation (ol) on the jitter of the first signal and a standard deviation (oO) on the jitter of the second signal.

5. Circuit (3) according to claim 4, wherein the threshold is determined by the following formula: Nmin = (ts + th + ol) / (DT + oO), with Nmin the threshold, ts the setup time, th the holding time, DT the difference between the average value of the period of the first signal (SI) and the average value of the period of the second signal (S2), ol the standard deviation on the jitter of the first signal and oO the standard deviation on the jitter of the second signal.

6. Circuit (3) according to any one of claims 2 to 5, wherein the metastability management circuit (GM) is configured to reset the counter (COUNTER) at each rising edge and at each falling edge of the output (Beat) of the first flip-flop (102).

7. Circuit (5) according to claim 1, wherein the metastability management circuit (GM) is configured to reset the counter (COUNTER) at each rising edge and / or each falling edge of the third signal (Beat), and to generate the third signal (Beat) by a majority vote between the output (Q0) of the first flip-flop (102), P first samples (Q01, Q02, QOP) obtained at each period of the second signal (S0) by sampling the first signal (SI) at P successive times delayed relative to the beginning of said period, and P second samples (Q11, Q1P) obtained at each period of the second signal (S0) by sampling at the beginning of said period P fourth signals (Sld1, SldP) delayed differently relative to the first signal (SI), P being an integer greater than or equal to 2.

8. Circuit (5) according to claim 7, wherein, at each period of the second signal (S0): the P successive instants are delayed relative to the beginning of said period by delays equal respectively to i*D, with D a time period and i an integer from 1 to P; and The fourth P signals are delayed relative to the first signal (SI) by delays equal respectively to j*D, with j an integer from 1 to P.

9. Circuit (5) according to claim 8, wherein the time period D is at least partly determined by a setup time (ts) of the first flip-flop (102) and a holding time (th) of the first flip-flop (102).

10. Circuit (5) according to claim 9, wherein a value of the time period D is chosen such that: T01m / 2 > P*D > ts+th, with ts the setup time, th the holding time and TOlm an average value of the first and second signal periods (S0, SI).

11. Circuit (5) according to claim 9, wherein a value of the time period D is chosen such that: T01m / 2 > P*D > ts+th+ol+oO, with ts the setup time, th the holding time, TOlm an average value of the periods of the first and second signals (S0, SI), ol a standard deviation on the jitter of the first signal (SI) and oO a standard deviation on the jitter of the second signal (S0).

12. Circuit (5) according to any one of claims 8 to 11, wherein the metastability management circuit (GM) comprises: P first delay circuits (50211, 5021P) configured to each receive the first signal (SI) and to respectively provide the P fourth signals (Sldl, SldP); P second flip-flops (10211, 1021P) identical to the first flip-flop and configured to respectively sample the P fourth signals at the beginning of each period of the second signal (S0) so as to respectively provide the P second samples (Q11, Q1P); P second delay circuits (50201, 5020P) identical respectively to the P first delay circuits (50211, 5021P), and configured to each receive the second signal (S0) and to respectively provide P fifth signals (SOdl, SOdP) delayed differently with respect to the second signal (S0);and P third flip-flops (10201, 1020P) identical to the first flip-flop and configured to sample the first signal (SI) at the beginning of each period of the P fifth signals (SOdl, SOdP); respectively and provide the first P samples (QOdl, QOdP); and an arbitration circuit (ARB) configured to receive the first P samples (QOdl, QOdP), the second P samples (Qldl, QldP) and the output (QO) of the first flip-flop (102) and to provide the third signal (Beat) from the first P samples, the second P samples and the output of the first flip-flop.

Citation Information

Patent Citations

  • Generation of true random numbers with coherent sampling in fd-soi technology

    EP4354279A1

  • Generation of truly random numbers with consistent sampling using FD-SOI technology

    FR3140968A1

  • Coherent sampling true random number generation in fd-soi technology

    US20240128957A1

  • Ring oscillator based true random number generator and a method for generating a random number

    US20220399883A1

  • Entropy source with embedded computing method for true random number generation

    US20240201954A1