Automatic authentication IC chip
The proposed system automatically detects and excludes impersonated electronic devices in IoT networks by using a response function based on unique random numbers from IC chips, effectively addressing the limitations of existing technologies in this area.
Patent Information
- Application Number
- JP2021017877
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-09-22
- Filing Date
- 2021-02-06
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2041-02-06
AI Technical Summary
Existing technologies are ineffective in automatically detecting and excluding impersonated electronic devices within IoT networks, even when using advanced cybersecurity tools like blockchain.
A network of electronic devices employs a system where M peripheral devices are inspected, and at least one device serves as an inspection subject. The system uses a response function to generate unique responses based on challenges and unique random numbers from IC chips, enabling automatic detection and exclusion of impersonated devices.
This solution effectively prevents impersonation attacks by ensuring that each electronic device responds uniquely to challenges, allowing for the automatic identification and exclusion of impersonated devices within the IoT network, thereby enhancing network security.
Smart Images

Figure 0007683857000001 
Figure 0007683857000002 
Figure 0007683857000003
Abstract
Description
Technical Field
[0001] The present invention relates to the technology of a memory chip with an automatic authentication function.
Background Art
[0002] As a result of the spread of the Internet in the 20th century, the scope of application of network technology has rapidly expanded. Entering the 21st century, the trend is expected to re-accelerate as the Internet of Things (IoT). On the other hand, IoT networks across national borders are at risk of being remotely operated by hackers abroad (especially illegal hackers when engaging in illegal activities).
[0003] An IoT network is a network of electronic devices. However, the difference from the ordinary Internet has remained ambiguous so far.
[0004] When it comes to a cyber network, it is a network between virtual accounts. Whether it is an IoT network or a cyber network, modern networks are information communication infrastructures for exchanging electronic data. A virtual account is a logical address on the network, which is essentially different from the electronic device itself. On the Internet, a physical address exists as part of the protocol that links this electronic device and the logical address.
[0005] A protocol is a routine process for processing the communication of code information, and the routine process itself can also be encoded and treated as code information. That is, a protocol is software and does not originate from a specific electronic device. As long as it meets a predetermined standard, it will operate in the same way when installed on any electronic device. That is, a physical address does not necessarily originate from a specific electronic device. It is only artificially (on the protocol) regarded as being linked to a certain electronic device. Hackers can modify this physical address at any time.
[0006] Nevertheless, it is certain that electronic devices on the Internet are physically connected to each other and electronic information is flowing between them. This connection is sometimes wired and sometimes wireless. The fact that the physical address is forged means that even if there is no problem with information communication between logical addresses, that is, even if there is no problem on the cyber network, the Internet protocol is deceived.
[0007] Figure 1 is a drawing for explaining this situation. There is a network consisting of electronic devices A to C (a network of electronic devices, or an IoT network, or a physical network) above, and a network consisting of logical addresses A to C (a logical network or a cyber network) below. The dashed line connecting the upper and lower networks indicates that electronic devices A to C are respectively linked to logical addresses A to C. That is, this dashed line is the physical address, and the Internet protocol (hereinafter simply referred to as the protocol) controls the information communication between logical addresses including this physical address.
[0008] There is a reason why the physical address can be forged at any time. It is due to the very definition of software.
[0009] Tracing back to the concept of a Turing machine, it can be seen that all possible processes of an electronic device can be encoded. If it is required that a block of encoded processes (software) operates in the same way for electronic devices (hardware) designed according to the same standard, the development of hardware and software can be carried out independently. When hardware and software independently improve their performance, sometimes software is required to switch from old hardware to new hardware (reinstall software). At this time, the logical address for using the software to be reinstalled on the Internet will break the link with the old hardware (electronic device 1) once and newly establish a link with the new hardware (electronic device 2). The reverse operation of this is the software update.
[0010] Thus, editing the physical address (the link between the electronic device and the logical address) is a necessary function for system maintenance. If an illegal hacker performs this editing, it will result in illegal tampering.
[0011] Thus, when considering the overall body that the Internet protocol controls information communication as the Internet, it can be seen that it includes the cyber network and the physical address in Figure 1 and does not include electronic devices A to C. That is, as shown in Figure 2, the Internet consists of a network (logical network or cyber network) composed of logical addresses A to C and a dashed line (physical address) that links each logical address to something. It is particularly important that the Internet protocol has no concern about what this something is. If it did, it might negate the very structure of the software.
[0012] On the contrary, what remains after removing all the elements from Figure 1 to Figure 2 is the IoT network (network of electronic devices, or physical network). See Figure 3. It has become clear above that the IoT network (physical network, or network of electronic devices) does not match what is currently called the Internet. However, as it is in Figure 3, there is no application, so the IoT network cannot do much work.
[0013] (Impersonation) If Figure 1 is regarded as the IoT network, an illegal hacker can easily break any security (cybersecurity) on the cyber network by using the method of impersonation. Figures 4 to 6 are diagrams explaining an example of impersonation.
[0014] First, as shown in Figure 4, an illegal hacker arbitrarily selects one legitimate logical address. For example, let's call it logical address B. Next, this logical address B is exchanged with the logical address (logical address B') assigned to the electronic device (a laptop as an example) that the hacker himself owns. This is, as shown in Figure 5, to tamper with the link between electronic device B and logical address B and link it to the device (for example, the laptop in the figure) owned by this illegal hacker. The result is as shown in Figure 6.
[0015] Assuming that the link between the electronic device and the logical address by the physical address (that is, the protocol of the Internet) is complete, the information communication between the logical addresses corresponding to the information communication between the electronic devices will always match. Therefore, as long as the cyber security is strong enough, the network of the electronic devices will be safe. That this is a misunderstanding is self-evident when looking at Figure 6.
[0016] In Figure 6, there is a laptop owned by illegal hacker B that has copied logical address B by tampering with the link (physical address) between electronic device B and logical address B between the electronic device A assigned logical address A and the electronic device C assigned logical address C. In this way, the illegal hacker can act as a middleman between electronic device A and electronic device C using the copied logical address B.
[0017] Thus, since spoofing is an attack that utilizes the very definition of software itself, any software-based defense is powerless.
[0018] (Man-in-the-Middle Attack) An illegal hacker can tamper with the information communication between electronic device A and electronic device C. Such an attack is called a man-in-the-middle attack. Even if the information communication between logical address A and logical address C is encrypted, a man-in-the-middle attack cannot be prevented. This is because the purpose of a man-in-the-middle attack is not necessarily limited to eavesdropping on the information communication between electronic device A and electronic device C. Even if it cannot be peeked at, it is possible to disrupt the cooperation between electronic device A and electronic device C by flowing false information between them.
[0019] One of the main application cases of IoT is that multiple electronic devices actively cooperate to jointly perform complex and large-scale operations. The main purpose of a man-in-the-middle attack is to disrupt such an IoT network (cooperation of electronic devices) that performs complex and large-scale operations through remote control. As IoT becomes more popular, the potential damage caused by man-in-the-middle attacks will become enormous.
[0020] For example, the electronic devices (IoT devices) that make up an IoT network are information terminals such as smartphones, tablets, laptops, and PCs, smart meters, sensors, surveillance cameras, or drones and vehicles equipped with multiple sensors, etc. As shown in Figure 7, these IoT devices spread to the bottom layer of the business model with artificial intelligence (AI) at the apex. The mass of various information collected by these IoT devices flooding the city is the big data in the middle layer. It is expected that the artificial intelligence (AI) in the upper layer will utilize it to solve various problems.
[0021] However, if there are disguised IoT devices (electronic devices) hidden here, information tampered with by a man-in-the-middle attack may be mixed in, casting doubt on the reliability of big data. This may lead to malfunctions of artificial intelligence (AI). In a smart factory, machines connected by high-speed communication such as 5G cooperate to perform operations. If these machines, control boards, etc. are disguised, the smart factory may be stopped. A connected car, which is connected to the Internet and equipped with multiple electronic devices, may malfunction in its autonomous driving or, in the worst case, be hijacked if some of them are disguised.
[0022] As described above, the damage caused by disguising electronic devices extends to property damage, factory shutdowns, human lives, etc., and it is obvious that this poses a threat of a different dimension from conventional cyberattacks.
[0023] Figure 8 briefly shows an example of a protocol in which electronic device A authenticates electronic device B.
[0024] First, electronic device A requests an authentication response from electronic device B. In the example of this figure, for clarity, it is written as "Mr. B, who are you?", but actually, some digital code (challenge) is sent from electronic device A to electronic device B. In response, electronic device B replies "I am logical address B". Of course, actually, some electronic code (response) is sent from electronic device B to electronic device A.
[0025] If this exchange of challenge and response (authentication communication) is properly protected by some cybersecurity tool, it may seem that a seemingly secure authentication is being performed.
[0026] Figure 9 is an example of the response of the challenge and response when electronic device B is disguised.
[0027] When the same challenge “Mr. B, who are you?” as shown in Fig. 8 is sent from the electronic device A to the hacker's laptop that has spoofed the logical address B, the hacker's laptop replies “I am the logical address B”. That is, even if there is spoofing, the combination of the challenge and the response is not changed.
[0028] If this exchange of challenge and response (authentication communication) is securely protected by some cyber security tool, it may seem that a seemingly secure authentication is being performed. However, this would mean protecting the communication with the hacker's laptop as well. That is, even if one tries to detect and eliminate the spoofed communication device, cyber security will protect the hacker's laptop (the spoofed communication device).
[0029] As described above, it can be seen that no matter how powerful the cyber security tool is, anti-spoofing measures are difficult. The same is true when using the latest cyber security tools such as blockchain.
[0030] (Real) Next, let's see how information is transferred between information devices. First, information is converted into digital data (or simply data) and transferred from one information device to another. Therefore, it is necessary to know how data is handled within a single information device.
[0031] Almost all information devices currently used on the network can be considered to be Neumann-type computers (or Neumann computers, or simply computers). Fig. 10 outlines the flow of data entering and leaving a computer.
[0032] The computer receives input from the input / output device (I / O) and passes it to the arithmetic unit. Each time the arithmetic unit performs an operation, it accesses the memory. Traditionally, this memory has a multi-level hierarchy, starting from the top with registers, cache memory (such as SRAM), main memory (such as DRAM), and further down, there is storage memory (such as flash memory) that does not lose data even when the computer is powered off. The higher the level, the faster the operating speed, and the lower the level, the higher the bit capacity.
[0033] As an example, the arithmetic unit includes a processor core, registers, and cache. Combine this with a stand-alone DRAM as the main memory, and add flash memory or the like as needed to form a rough configuration of an information device (or computer). Information devices that do not include DRAM have a severely limited amount of data that can be handled.
[0034] To exchange data between information devices, consider an example where the first information device outputs data through the I / O, and this data is input to the second information device through the I / O. As an example, consider the case where data is transferred from the first information device (upper part) to the second information device (middle part) as shown in FIG. 11.
[0035] First, the data read from the memory chip in the upper part (or an IC chip) is passed to the arithmetic unit in the upper part. After appropriate processing there, it is output from the I / O in the upper part. The output data is exposed on the network, and when it finds the I / O in the middle part, which is the transfer destination, it is taken in (input) by the information device in the middle part. This data is further written (stored) to the memory chip in the middle part after appropriate processing by the arithmetic unit in the middle part.
[0036] Subsequently, the data read from the memory chip in the middle layer is passed to the arithmetic unit in the middle layer, where appropriate processing is performed and then output from the I / O in the middle layer. The output data is exposed on the network and, when the destination I / O in the lower layer is found, it is taken in (input) by the information device in the lower layer. This data is further written (stored) to the memory chip in the lower layer after appropriate processing is performed by the arithmetic unit in the lower layer.
[0037] Thus, it can be seen that data is transferred between the upper, middle, and lower layers and the memory chips. That is, monitoring the flow of information between information devices is equivalent to monitoring the transfer of data between memory chips. At this time, it is necessary to note that no logical addresses (such as IP addresses) assigned to the cyber space appear at all.
[0038] Let's consider again the information exchange between the electronic devices A, B, and C described in FIG. 1.
[0039] The electronic devices A, B, and C in FIG. 1 each incorporate the information device (computer) units in the upper, middle, and lower layers of FIG. 11. Alternatively, the electronic devices A, B, and C in FIG. 1 are the information devices (computers) in the upper, middle, and lower layers of FIG. 11, respectively. That is, all the information exchanges between the electronic devices in FIGS. 1-6 and FIGS. 8 and 9 described so far are equivalent to data being transferred between the memory chips in the upper, middle, and lower layers of FIG. 11.
[0040] However, there is no information regarding logical addresses in FIG. 11. That is, there has been no well-defined relationship between information exchange in the cyber space and real data communication in the IoT network until now.
[0041] (Cyber) Next, let's roughly look at how information is transferred in the cyber space (logical network). FIG. 12 is an example of an information transfer method also adopted in blockchain and the like.
[0042] Use the end point of the information (hash value (N - 1)) at the current time as the logical account (N). The logical account (N - 1) is the one that last transferred the information (hash value (N - 1)) to this logical account (N). In the logical account (N - 1), this hash value (N - 1) is generated from the hash value (N - 2). The logical account (N - 2) is the one that last transferred the information (hash value (N - 2)) to this logical account (N - 1). In the logical account (N - 2), the hash value (N - 2) is generated from the hash value (N - 3).
[0043] Each has the public keys (N), (N - 1), and (N - 2) corresponding to the logical addresses. The public keys (N), (N - 1), and (N - 2) are one-to-one associated with the private keys (N), (N - 1), and (N - 2) respectively by public key cryptography (PKI).
[0044] The logical account (N - 2) obtains the public key (N - 1), which is the logical address of the logical account (N - 1) publicly available on the network, and uses the private key (N - 2) to encrypt the combination of the public key (N - 1) and the hash value (N - 2 ) to generate an electronic signature (N - 2). Furthermore, the logical account (N - 2) hashes together the public key (N - 2), the hash value (N - 3), and the electronic signature (N - 3) to generate the hash value (N - 2). Then the logical account (N - 2) transfers the hash value (N - 2) with the electronic signature (N - 2) attached to the logical account (N - 1).
[0045] The logical account (N - 1) obtains the public key (N), which is the logical address of the logical account (N) publicly available on the network, and uses the private key (N - 1) to encrypt the combination of the public key (N) and the hash value (N - 1Encrypt them together to generate an electronic signature (N - 1). Further, the logical account (N - 1) collectively hashes the public key (N - 1), the hash value (N - 2), and the electronic signature (N - 2) to generate a hash value (N - 1). Then, the logical account (N - 1) transfers the hash value (N - 1) with the electronic signature (N - 1) attached to the logical account (N).
[0046] However, there is no information about the memory chip of the information device in FIG. 12. That is, there has been no well - defined relationship between information exchange in the cyber - space and real - data communication in the IoT network until now.
Disclosure of the Invention
Problems to be Solved by the Invention
[0047] The present invention has been made in view of the above circumstances, A technology for automatically detecting the impersonation of an electronic device and automatically excluding the impersonated electronic device even when using the latest cyber - security tools that employ blockchain or the like, is provided as an object.
Means for Solving the Problems
[0048] To solve the above problems, the present invention employs the following means.
[0049] The solution proposed by the present invention is, A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, Among the other plurality of electronic devices, at least one electronic device serves as an inspection subject, The first to Mth devices to be inspected are the first to Mth peripheral devices respectively, The inspection subject inputs a first challenge to the first to Mth peripheral devices, The first to Mth peripheral devices, in response to the first challenge, based on a response function, return first to Mth responses to the inspection subject respectively, The first to Mth responses form a first response set with the first to Mth responses as elements, The inspection subject saves the first challenge and the first response set, At least one of the first to Mth peripheral devices receives a second challenge sent from the inspection subject, generates an M + 1th response, and generates a pair of an M + 1th private key and an M + 1th public key from the M + 1th response, The first to Mth peripheral devices each have the first to Mth IC chips as components, The response function generates the first to Mth responses respectively, taking the first challenge and unique random numbers unique to the first to Mth IC chips as arguments, The response function generates the M + 1th response, taking the second challenge and a unique random number unique to the IC chip that input the second challenge as arguments, characterized in that or A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, Among the other plurality of electronic devices, at least two electronic devices serve as the first and second inspection subjects, The first to Mth devices to be inspected are the first to Mth peripheral devices respectively, The inspection subject inputs a first challenge to the first to Mth peripheral devices, The first to Mth peripheral devices, in response to the first challenge, based on a response function, return first to Mth responses to the inspection subject respectively, The first to Mth responses form a first response set with the first to Mth responses as elements, The inspection subject saves the first challenge and the first response set, At least one of the first to M-th peripheral devices receives a second challenge sent from the second inspection subject, generates an (M + 1)-th response, and generates a pair of an (M + 1)-th private key and an (M + 1)-th public key from the (M + 1)-th response. The first to M-th peripheral devices each include a first to M-th IC chip as a component. The response function generates the first to M-th responses respectively, taking the first challenge and a unique random number unique to the first to M-th IC chips as arguments. The response function generates the (M + 1)-th response, taking the second challenge and a unique random number unique to the IC chip that inputs the second challenge as arguments. characterized by.
[0050] The solution proposed by the present invention further has the following characteristics. The IC chip has a cell array, a row decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives a redundancy mode acquisition code and a challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, acquires the unique random number from access to the first and second cell arrays based on the redundancy code stored in the special internal memory, and passes the unique random number to the code generation device. The code generation device uses the response function to generate the response from the challenge and the unique random number, and passes it to the External input / output device. The external input / output can receive the input of the redundancy mode acquisition code and the challenge from the outside, receive the response from the code generation device, and output the response outside the IC chip.
[0051] The solution proposed by the present invention further has the following features. It is a network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, a first electronic device serves as an inspection subject, and a second electronic device serves as a device to be inspected. The inspection subject inputs a challenge to the second electronic device. The second electronic device generates a response according to the challenge based on a response function. The second electronic device has at least one IC chip. The IC chip has a cell array, a row decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, and obtains a unique random number unique to the IC chip from the access to the first and second cell arrays based on the redundancy code stored in the special internal memory, and passes the unique random number to the code generation device. The code generation device generates the response from the challenge and the unique random number. The external input / output receives the redundancy mode acquisition code and the input of the challenge from the outside, receives the response from the code generation device, and outputs the response outside the IC chip. The redundant mode acquisition code includes authentication setting options, dedicated bit specification mode, access options, and operation options, The cell array is divided into a plurality of small blocks, The IC chip further has a cell block address table, The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-small-block address, The dedicated bit specification mode has a specified bit address as an argument, The specified bit address is an authentication-dedicated bit within the small block, The authentication setting options consist of an authentication mode or a non-authentication mode. When the authentication mode is selected, the authentication-dedicated bit is selected as the selected bit address of the in-small-block address. When the non-authentication mode is selected, one bit other than the authentication-dedicated bit is selected as the selected bit address within the small block, The access options control the combination of the column decoder, the first and second row decoders, and instruct access to each bit address on the cell array, The operation options include writing, erasing, and reading to / from each bit address, When the authentication mode is selected, the peripheral circuit reads the unique random number from the cell array based on the redundancy code by switching the combination of the access options and the operation options, The response function generates the response with the challenge and the unique random number unique to the IC chip as arguments, which is characterized by or a network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, the first electronic device is the inspection subject, and the second electronic device is the device to be inspected, The inspection subject inputs a challenge to the second electronic device, The second electronic device generates a response according to the challenge based on the response function, The second electronic device has at least one IC chip, The IC chip has a cell array, a row decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output, The cell array is divided into a first and a second cell array, The row decoder is divided into a first and a second row decoder, The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, obtains a unique random number specific to the IC chip from access to the first and second cell arrays based on the redundancy code stored in the special internal memory, and passes the unique random number to the code generation device. The code generation device generates the response from the challenge and the unique random number. The external input / output receives the input of the redundancy mode acquisition code and the challenge from the outside, receives the response from the code generation device, and outputs the response outside the IC chip. The redundancy mode acquisition code includes authentication setting options, dedicated column designation modes, access options, and operation options. The dedicated column designation mode has a designated column number as an argument. The authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication dedicated column, and the authentication dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column. The access option selects a combination of the first and second row decoders and instructs access to the address defined by the combination of the row decoders and the selected column. The operation option includes writing, erasing, and reading to / from the address. When the authentication mode is selected, the peripheral circuit reads the unique random number from the cell array based on the redundancy code by switching the combination of the access option and the operation option. The response function generates the response with the challenge and the unique random number specific to the IC chip as arguments. A digital information communication system, characterized in that... Characterized in that... Digital information communication system.
[0052] The best mode for carrying out the invention will be specifically described below.
Best Mode for Carrying Out the Invention
[0053] As described above, in the present invention, authentication of an electronic device is performed using a first response obtained from a unique random number unique to an IC chip included in the electronic device and a first challenge to the electronic device, and a physical firewall composed of authenticated electronic devices is created. Further, a pair of a secret key and a public key is generated using a second response obtained by inputting a second challenge to the IC chip, the public key, or code information generated from the public key is used as the logical address of the electronic device, and an electronic signature generated using the secret key is used for data transmission and reception between electronic devices within the physical firewall. A communication system for digital information, is proposed.
[0054] This will be specifically described below with reference to the drawings.
[0055] (Cyber and Real Fusion) FIG. 13 conceptually shows a method of associating the electronic devices A, B, and C in FIG. 1 with the logical addresses A, B, and C, respectively.
[0056] A secret key and a public key are linked one-to-one by PKI. The public key is equivalent to, or corresponds to, a logical address in the cyber space. The logical address is equivalent to, or corresponds to, an account of software (application, or simply app) operating in the cyber space. However, it is practically difficult to generate a secret key from a public key.
[0057] The electronic device B is the device under test and is inspected by the electronic device A which is the inspection entity. If the inspection of the inspection entity passes, the device under test is authenticated. The electronic device B incorporates one or more semiconductor chips (IC chips, or simply chips). As an example, assume it incorporates the memory chips of FIGS. 10 and 11. The electronic device A sends a challenge (C) to the electronic device B. As an example, "Mr. B, who are you?" in FIGS. 8 and 9 is fine.
[0058] In the chips incorporated in the electronic device B, there exists a random number unique to that chip (unique random number). A response (R) is generated from the said challenge (C) and this unique random number. As long as the unique random number is unique to the chip, this response (R) can be regarded as a response unique to the said chip and the challenge (C). As an example, it may be regarded as "I am chip B" in FIGS. 8 and 9.
[0059] Here, the relationship between the response, the challenge (C) input to the chip under test, and the unique random number unique to the chip under test can be described using the function Res.
[0060] Response (R) = Res(C, unique random number (chip))
[0061] If a hacker accesses the device under test (for example, the electronic device B), it is possible to read and copy this unique random number. However, if it is not known what challenge (C) the inspection entity (electronic device A) inputs, it is difficult for the hacker to predict the response (R). The inspection entity (electronic device A) saves the pair of the challenge (C) and the response (R) and can use it at any time for the authentication of the device under test. The important thing here is that in practice, the unique random number is not used for the authentication test.
[0062] As long as the unique random number is unique to the chip, that is, when the unique random number can be regarded as having a one-to-one relationship with the chip, the relationship in paragraph 0060 can be rewritten as follows.
[0063] Response (R) = Res (C, chip)
[0064] As long as this relationship is satisfied, the relationship between the unique random number and the chip can be anything. As an example, the unique random number can be generated by utilizing the randomness generated during the chip manufacturing process. However, data that can be rewritten from the outside by some means cannot be regarded as unique to the chip.
[0065] For example, consider N×M electronic elements arranged in N rows and M columns on a chip as shown in FIG. 14. Here, N is a natural number of 1 or more, and M is a natural number of 1 or more. In this application, such electronic elements will be referred to as authentication elements. The characteristics of the authentication elements vary due to manufacturing variations during the chip manufacturing process. In mass production, it is required to control this variation as much as possible, but it is impossible to completely eliminate it. By quantifying the variation for each such authentication element and distributing it on the cell array of FIG. 14, it is possible to convert it into a physical random number.
[0066] For example, measure a certain electrical property of the authentication element. If the value is higher than a certain level, it is set to 1, and conversely, if it is lower, it is set to 0. That is, the authentication elements with values of 1 and 0 will be distributed on the cell array of FIG. 14. If 0 is set to white and 1 is set to black, for example, a pattern of white and black can be formed as shown in FIG. 15. If both M and N are sufficiently larger than 1, this pattern will be a checkerboard-like two-dimensional pattern. If either M or N is 1, this pattern will be a one-dimensional pattern. In any case, if the generation of 0 and 1 for each authentication element is due to manufacturing variations, this pattern of white and black will be physically random and different for each chip. The probability that two chips accidentally have the same pattern will decrease as M or N increases. Since M and N can be controlled by the design of the cell array, it is possible to control the probability that two chips accidentally have the same pattern to be below the allowable range by the design of the cell array. In this way, what represents the unique random number as an array of a plurality of values (as an example, 0 and 1) is called a unique random number code (or simply a random number code).
[0067] The authentication element is, for example, a resistor (Figure 16), a capacitor (Figure 17), a PN junction (Figure 18), a Schottky junction (Figure 19), a transistor (Figures 20 and 21), a memory element (Figures 22 - 26), etc. In particular, Figure 22 shows an example in which a DRAM element composed of a combination of a transistor and a capacitor is used as the authentication element. Figure 23 shows an example in which a non-volatile memory element using a variable resistor is used as the authentication element. When the resistance is changed by an applied voltage, the authentication element is a resistance change memory (such as ReRAM) cell. When the resistance is changed by utilizing the phase change between crystal and amorphous generated by heating or the like, the authentication element is a phase change memory (PCRAM) cell. Figure 24 shows a non-volatile memory element using magnetoresistance as the authentication element. When magnetoresistance is changed using the giant magnetoresistance effect (GMR), the authentication element is an MRAM cell. When magnetoresistance is changed using the spin torque transfer effect (STT), the authentication element is an STT-MRAM cell. The examples in Figures 25 and 26 use a non-volatile memory element with a charge storage layer as the authentication element. If the charge storage layer is a charge trap, the authentication element is a charge trap type non-volatile memory element. If the charge storage layer is a floating gate (FG), the authentication element is an FG type memory element. Generally, it is possible to configure an authentication element from one or more of the above elements (resistors, capacitors, PN junctions, Schottky junctions, transistors, memory elements, etc.). Therefore, although not particularly illustrated as it is obvious, it is also possible to configure one authentication element by combining two or more of the above elements (resistors, capacitors, PN junctions, Schottky junctions, transistors, memory elements, etc.). When configuring one authentication element by combining any two or more of the above elements (resistors, capacitors, PN junctions, Schottky junctions, transistors, memory elements, etc.), it is obvious that at least two of the elements to be combined are connected in series or in parallel with each other.
[0068] Alternatively, as another example, after chip manufacturing, it is also possible to convert a separately generated unique random number into a code of 0 and 1 (random number code) and write it into the cell array of Figure 14. At this time, it is desirable that the authentication element constituting the cell array of Figure 14 is a memory element of a one-time programmable memory (OTP). Since OTP utilizes the intentional destruction of memory elements or the intentional short circuit of wiring elements (the intentional destruction of resistance elements), as a result, any of the authentication elements from Figure 16 to Figure 26 can be utilized as the memory element of OTP.
[0069] Although multiple methods can be applied as random number generators, the one using qubits has the highest degree of unpredictability. In a qubit, both 0 and 1 information exists simultaneously. When read out according to the principle of the observation problem in quantum mechanics, it is probabilistically determined to be either 0 or 1, and it is theoretically impossible to predict the readout result in advance. Repeatedly reading 0 and 1 from qubits and arranging the results in a row becomes a random number code. With current technology, it is difficult to mix a large number of qubits on a semiconductor chip. Of course, as long as it does not deviate from the gist of this application, a random number generation method based on other physical principles may be used.
[0070] Regardless of the method for generating the random number code outside the chip, it is necessary to avoid storing the same code as the random number code stored in the cell array of a certain chip in the cell array of another chip. To achieve this, first, the authority to write the random number code generated outside the chip into the cell array inside the chip must be limited only to those who are formally involved in chip manufacturing, distribution, use, etc. That is, when generating a random number code outside the chip, an operation method is required to control the risk of human error within an acceptable range.
[0071] To avoid accidentally leaving the same random number code in the cell arrays of two chips, the number of bits of the random number code to be generated must be large enough. Let this number of bits be Q and the number of chips including the cell array into which the random number code is written be U. It is desirable that 2 to the power of Q divided by U is a sufficiently large number. As an example, to achieve a specification that can withstand even trillions of nodes, if U is 1 trillion, when Q is 40, the number of cases of the random number code is exactly about 1 trillion. Therefore, Q must be a number much larger than at least 44. If Q is 50, the probability that two of the random number codes written in the chips distributed worldwide accidentally match is less than 1 in a million. That is, it is desirable that the information amount of the random number code is 50 bits or more.
[0072] That is, as an example, readout can be repeated 50 times from one qubit per chip, or 25 times from two qubits, or at least 50 / M times from M qubits, and the results can be written into an area of 50 bits or more anywhere within the chip.
[0073] In order to prevent forgery of the separately generated random number code once it is properly written, the cell array for storing the separately generated random number code must be made non-rewritable. It is desirable to use a one-time programmable (OTP) memory for such a cell array.
[0074] The most promising example of OTP is mask ROM. FIG. 20 is also an example of the bit cell structure of a typical mask ROM. That is, the transistor is the bit cell of the mask ROM. First, an address in the cell array is selected according to the bit representation of the random number code separately generated by an external random number generator. Next, methods such as cutting off the PN junction of the transistor of the bit cell located at the selected address with a laser or applying a large current to the bit line for a long time to surely break the PN junction can be considered. In any method, the bit cell having a once-broken PN junction loses its rectifying action and current flows even when a reverse voltage is applied. For example, if the broken bit cell is made to correspond to data 1 and the unbroken bit cell is made to correspond to data 0, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing the separately generated random number code, the PN junction of the transistor at the selected address must be surely broken.
[0075] Alternatively, it is possible to utilize all bit cells (such as FIGS. 18, 20-26, etc.) including PN junctions as OTP. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, the PN junction of the transistor of the bit cell located at the selected address is cut by a laser or the like. Alternatively, a method of surely destroying the PN junction by flowing a large current through the bit line for a sufficiently long time can be considered. In any method, the bit cell having a once-destroyed PN junction loses the rectifying action, and current flows even when a reverse voltage is applied. For example, if the destroyed bit cell is made to correspond to data 1 and the non-destroyed bit cell is made to correspond to data 0, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the PN junction of the selected address must be surely destroyed.
[0076] Alternatively, it is possible to utilize all bit cells (such as FIGS. 17, 20-26, etc.) including capacitors as OTP. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, a method of hard-destroying the insulating film of the capacitor of the bit cell located at the selected address by flowing a large current through the capacitor for a sufficiently long time can be considered. The capacitor of the bit cell having a destroyed insulating film loses its insulation property, and current flows even when a DC voltage is applied. For example, if the destroyed bit cell is made to correspond to data 1 and the non-destroyed bit cell is made to correspond to data 0, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the insulating film of the capacitor of the selected address must be surely hard-destroyed.
[0077] Alternatively, it is possible to utilize all bit cells (such as in FIG. 16) including resistors or resistor wirings as OTP. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, the resistor or resistor wiring of the bit cell located at the selected address is cut with a laser. Alternatively, a method of causing disconnection (short circuit) by flowing a large current for a sufficiently long time can be considered. Such a property is generally called a fuse. That is, the example of FIG. 16 is generally a fuse memory. For the selected bit cell, no current flows even when an appropriate voltage is applied due to the disconnection. For example, if the disconnected bit cell is made to correspond to data 0 and the non-disconnected bit cell is made to correspond to data 1, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the resistor or resistor line at the selected address must surely be disconnected.
[0078] Thus, there are various examples of OTP. It is possible to regard a random number code separately generated outside the chip as a unique random number sharing the concept of the present application regardless of which OTP is used. However, as a condition of the OTP, it is desirable to make the unique random number once normally written electrically unrewritable.
[0079] The random number code to be the unique random number of the present application may be written in the entire cell array constituting the chip of the present application, or may be written in a part of the cell array. Alternatively, it may be written in an area (such as a peripheral area) different from the cell array on the chip.
[0080] Nevertheless, it is also possible to use a pseudo-random number generator as the random number generator. To put it simply, a pseudo-random number generator is random number generation software. As long as it is software, since a random number code is generated according to some algorithm, if a combination of responses (R) to a plurality of challenges (C) is obtained, it is possible to decode and predict the response to an unknown challenge.
[0081] Nevertheless, if the possibility of decryption can be kept low within an acceptable range, it can be used as the unique random number of the present application. In this case, the equation in the 0063th row is satisfied pseudo-satisfied. Even if it is pseudo-satisfied, if the possibility of decryption can be controlled to within an acceptable range, it can be used as the unique random number of the present application.
[0082] From the above, there are two methods for generating unique random numbers for a chip: generating them at the time of chip manufacture and generating them on the chip itself. The former is a method in which the semiconductor is produced separately from the chip manufacturing process, and the latter is a method in which the semiconductor is produced separately from the chip manufacturing process. The first method uses the chip's random number code (unique random number) for authentication, and the second method writes a unique random number generated separately to a memory cell array (OTP, etc.) included in the chip. Another example of the second method is to randomly destroy the authentication element array. After deciding the area to write the unique random number, area A destructive pulse that is just at the limit of whether or not the authentication element present at the address in the region is destroyed may be applied. The authentication element to which the destructive pulse is applied is probabilistically destroyed, and its address is physically distributed randomly, so that it becomes a unique random number. Regardless of which generation method is used, it does not deviate from the concept of the present application as long as the unique random number of the chip to be tested is combined with the input (challenge) to the chip to be tested to obtain an output (response). Therefore, either generation method can be used equally in all embodiments of the present application.
[0083] FIG. 27 shows what happens when the same challenge (C) is input to two different devices under test (1 and 2).
[0084] The device under test 1 incorporates chip 1 and outputs response R1 from challenge (C) and the unique random number 1 of chip 1. The device under test 2 incorporates chip 2 and outputs response R2 from the same challenge (C) and the unique random number 2 of chip 2. Here, the two responses R1 and R2 are both different. This means that when the device under test 1 is replaced with another device under test 2, the response changes from R1. That is, if someone impersonates an information device, the change in the response will be noticed by the inspection entity.
[0085] Figure 28 shows an example of applying this concept to the authentication of an IoT network (a network of electronic devices).
[0086] The inspection entity (electronic device A) challenges the device under test (electronic device B) with "Mr. B, who are you?". The electronic device B returns the response "I am chip B" from this challenge and the unique random number in the built-in chip.
[0087] Figure 29 shows what happens when the electronic device B is impersonating a hacker's laptop (however, having logical address B).
[0088] The inspection entity (electronic device A) challenges the device under test (electronic device B) with "Mr. B, who are you?". The hacker's laptop impersonating the logical address B returns the response "I am the hacker's chip" from this challenge and the unique random number in the built-in chip.
[0089] In this way, as shown in Figure 27, by using the property of the authentication of the device under test according to the present application that different responses are made if the chips are different even though the challenges are the same, it is possible to search for whether there is an electronic device impersonated within the IoT network.
[0090] It is possible to search for spoofing in an electronic device. If a spoofed electronic device (illegal electronic device) is found, it can be excluded from the IoT network. For example, it can be easily realized by using a smart contract on a blockchain. Although it is self-evident and will not be particularly explained, the search and exclusion of spoofing can be performed automatically.
[0091] (When using an ElGamal type key generation device) Figure 30 shows an example of a method for generating a private key (n) and a public key (n) from a response R(n) output from an electronic device B(n) which is the n-th subject to be inspected.
[0092] The ElGamal algorithm is one of the important algorithms in public key cryptography. One of its features is to generate a public key paired with a private key. In this specification, regardless of the details of the algorithm, a key generation device that generates a public key paired with a private key is generically called an ElGamal type key generation device.
[0093] First, a challenge (C) is input from a hardware (electronic device A) which is the inspection subject to the electronic device B(n). The electronic device B(n) outputs a response R(n) from the unique random number (n) of the built-in chip (n) and this challenge (C).
[0094] The response R(n) is used as a private key (n) after performing code conversion for the purpose of adjusting the format, etc. By inputting this private key (n) into an ElGamal type key generation device, a public key (n) paired with the private key can be obtained. This public key (n) is a logical address corresponding to the logical account (n).
[0095] It is desirable to erase the private key (n) after it has been used. It can be generated at any time by the method in Figure 30 when needed. Alternatively, it is desirable to securely confine it within the electronic device B(n). Confining it securely within the electronic device B(n) means that, from the outside of the electronic device B(n), it is the same as if the private key (n) has disappeared.
[0096] It is desirable to install the key generation device as software in the electronic device B(n). Alternatively, it is desirable to install the key generation device in the chip (n) built into the electronic device B(n) as an embedded module. Alternatively, it is desirable to install the key generation device in another chip built into the electronic device B(n) as an embedded module. Alternatively, the key generation device may exist in another electronic device that is securely connected to the electronic device B(n).
[0097] Figures 31 and 32 show examples of a method of additionally using a second input in the embodiment of Figure 30.
[0098] In Figure 31, the second input is input in the process of generating the secret key (n) by code conversion from the response R(n). That is, this code conversion includes the second input. In Figure 32, the second input is input in the process of generating the public key (n) from the secret key (n). That is, this key generation device includes the second input.
[0099] Basically, the second input is used to increase the degree of freedom and strength of the authentication of the device under test related to this application.
[0100] For example, to strengthen the management of the IoT network, additional security servers are added to support the inspection entity. This security server can independently input (distribute) a second input to the device under inspection B(n) and change the response R(n) to the challenge (C). This helps prevent hackers from predicting combinations of unknown challenges and responses from multiple known pairs of challenges and responses. However, it is desirable for this security server to be pre-authenticated by the inspection entity before distributing the second input to the device under inspection. Also, the security server can inspect the authentication of the device under inspection in the same way as the inspection entity. In this sense, the security server is also an inspection entity. That is, the inspection entity is not necessarily limited to one. It is desirable for the first inspection entity to manage pairs of CRs, further search for devices under inspection and eliminate unauthorized electronic devices, and for the second inspection entity to manage pairs of CRs and further distribute a second input to the device under inspection as a security server.
[0101] (When using an RSA-type key generation device) Figures 33 - 35 show examples when using an RSA-type key generation device. Other than replacing the Elgamal-type key generation device in Figures 30 - 32 with an RSA-type key generation device, everything else is the same.
[0102] RSA consists of the initials of the inventors Rivest, Shamir, and Adleman. The RSA algorithm is one of the most important algorithms in public-key cryptography. One of its features is generating a pair of a private key and a public key from an external input. In this specification, regardless of the details of the algorithm, a key generation device that generates a pair of a private key and a public key from an external input is generically called an RSA type.
[0103] Figure 33 shows an example of a method for generating a private key (n) and a public key (n) from the response R(n) output from the electronic device B(n) which is the nth entity under inspection.
[0104] First, a challenge (C) is input from the hardware (electronic device A) which is the inspection subject to the electronic device B(n). The electronic device B(n) outputs a response R(n) from the built-in chip (n)'s unique random number (n) and this challenge (C).
[0105] The response R(n) is input directly or, after performing code conversion such as adjusting the format, into an RSA-type key generation device, and a secret key (n) and a public key (n) that form a pair with each other are generated. This public key (n) is the logical address corresponding to the logical account (n).
[0106] It is desirable to erase this secret key (n) after it has been used. Alternatively, it can be generated at any time by the method of FIG. 33 when necessary. Alternatively, it is desirable to securely confine it within the electronic device B(n). Confining it securely within the electronic device B(n) means that, from the outside of the electronic device B(n), it is the same as if the secret key (n) has disappeared.
[0107] It is desirable to install the key generation device as software in the electronic device B(n). Alternatively, it is desirable to install the key generation device as an embedded module in the chip (n) built into the electronic device B(n). Alternatively, it is desirable to install the key generation device as an embedded module in another chip built into the electronic device B(n). Alternatively, the key generation device may exist in another electronic device that is securely connected to the electronic device B(n).
[0108] FIG. 34 and FIG. 35 show examples of methods of additionally using a second input in the embodiment of FIG. 33.
[0109] In FIG. 34, the second input is input during the process of inputting the response R(n) into the key generation device. That is, this second input and the response R(n) are synthesized by some method. In FIG. 35, the second input is input during the process in which the key generation device generates the secret key (n) and the public key (n). That is, the key generation device includes the second input.
[0110] Basically, the use of the second input is to increase the degree of freedom and strength of the authentication of the device under test related to the present application.
[0111] For example, in order to strengthen the management of the IoT network, additional security servers that support the inspection entity are added. This security server can independently input (distribute) the second input to the device under test B(n) and change the response R(n) to the challenge (C). This helps prevent hackers from predicting combinations of unknown challenges and responses from multiple known pairs of challenges and responses. However, it is desirable that this security server be authenticated in advance by the inspection entity before distributing the second input to the device under test.
[0112] As described above, embodiments using the ElGamal-type and RSA-type key generation devices defined in this specification have been described. Next, a brief mention will be made of a key generation device that does not belong to either, that is, a key generation device that generates a private key from a public key. This corresponds to using an ElGamal-type input as the public key. The public key is publicly available on the network and can be freely obtained by an attacker. If this is input into a key generation device of the same algorithm, the private key can be obtained. In this way, the private key cannot be kept secret.
[0113] When using an ElGamal-type key generation device, according to the usage method of the present application, as shown in FIGS. 30-32, the private key is generated from the response (R) output from the electronic device. It is possible to input the response (R) directly into the ElGamal-type key generation device as the private key without conversion. It is also possible to perform appropriate code conversion on the response (R) to adjust the data format and then input it into the ElGamal-type key generation device as the private key. Alternatively, it is possible to perform code conversion including some intention on the response (R) and then input it into the ElGamal-type key generation device as the private key. In any case, the ElGamal-type key generation device generates a pair of private and public keys from the response (R). On the other hand, in the RSA-type key generation device, as shown in FIGS. 33-35, the response (R) is input to generate a pair of private and public keys. Thus, according to the usage method of the present application, regardless of whether an ElGamal-type or RSA-type key generation device is adopted, "a pair of private and public keys unique to the electronic device is generated from the response (R) obtained by inputting the challenge (C) to the electronic device". Furthermore, if the challenge (C) is changed, it is possible to automatically update the pair of private and public keys. Note that it is sufficient if the key generation device is in a state where the electronic device can use it at any time. In particular, it is not necessary to be installed in a specific part of the electronic device. That is, the key generation device may be installed in the IC chip constituting the electronic device, or may be installed outside the IC chip. Alternatively, the key generation device may be installed in the electronic device as software.
[0114] (Blockchain of things) FIGS. 36 and 37 conceptually show methods of constructing a blockchain of things using an ElGamal-type and an RSA-type key generation device, respectively.
[0115] The physical nodes (N-2), (N-1), and (N) are the electronic device B that pairs with the logical accounts (N-2), (N-1), and (N), respectively. In particular, in FIGS. 30-35, it is the electronic device B(n), where n corresponds to the cases of n = N-2, N-1, and N. Here, since the secret key (n) and the public key (n) are paired by the public key cryptography (PKI) of FIG. 13, the logical account (n) and the physical node (n) are paired.
[0116] According to the concept of FIG. 13, the responses output by the electronic device B(N-2), the electronic device B(N-1), and the electronic device B(N) to the challenge (C) are R(N-2), R(N-1), and R(N), respectively.
[0117] Removing the key generation device and the responses R(N-2), R(N-1), and R(N) and the key generation device from each electronic device in FIGS. 36 and 37 completely matches FIG. 12. This shows that the method of pairing physical nodes and logical nodes according to the concept of FIG. 13 is completely compatible with the existing blockchain.
[0118] In the examples of FIGS. 36 and 37, the memory of the physical node (N) stores the latest data. It is the chip (i.e., the memory chip) of FIG. 13. In terms of FIGS. 30-35, it is the chip (N).
[0119] As shown in FIG. 11, in the IoT network, data is transferred from memory chip to memory chip.
[0120] By the way, the chip that transfers data to the chip (chip (N)) including the memory storing this latest data is not necessarily one. In the example of FIG. 38, data is transferred to the chip (N) that holds the latest data from three chips. It is considered that data is also transferred to these three chips from a plurality of chips respectively. Nevertheless, the history of this transfer ends at the last chip (N) that holds the latest data.
[0121] In this way, as shown in FIG. 38, the Merkle tree of the chip is completed. The last chip (N) becomes the root of the Merkle of the Merkle tree of the present application.
[0122] Generally, the root of the Merkle is a candidate for a block in the blockchain. When the root of the Merkle satisfies a condition called Proof of Consensus (PoC), this root of the Merkle is recorded in the distributed ledger, recognized as a new block, and linked to the end of the blockchain. The blockchain is thus extended.
[0123] There are multiple methods for PoC. As an example, there is a method of adding a nonce value and hashing. If this hash value (block hash) satisfies a predetermined condition, this root of the Merkle is newly blocked and added to the blockchain as a new block.
[0124] As an example, the predetermined condition that the block hash should satisfy is that the first 16 digits of the block hash generated by adding a nonce value are all zero. Searching for the root of the Merkle that is still unblocked and exposed on the network and finding a nonce value that satisfies the predetermined condition is called mining. There is also a mechanism to reward miners who succeed in mining. An example of this is Bitcoin.
[0125] FIG. 39 conceptually shows the process of block generation by this mining.
[0126] Assume that the root of the Merkle (L-3) has already been blocked and the block hash (L-2) has been generated. That is, the root of the Merkle (L-3) is the latest block (Ⅼ-3) connected to the end of the blockchain at this point. Further, from the left of the drawing, there are the root of the Merkle (L-2), the root of the Merkle (L-1), and the root of the Merkle (L). However, as described above, in the present application, all these roots of the Merkle are chips (or IC chips including the cell array of FIG. 14).
[0127] First, find a nonce (L-2) that satisfies the conditions of a predetermined PoC as a nonce value, and hash it together with the block hash (L-3) and the Merkle root (L-2) to generate a block hash (L-2). In this way, the block (L-2) is recognized as the latest block and connected to the end of the blockchain.
[0128] Subsequently, find a nonce (L-1) that satisfies the conditions of a predetermined PoC as a nonce value, and hash it together with the block hash (L-2) and the Merkle root (L-1) to generate a block hash (L-1). In this way, the block (L-1) is generated as the latest block and connected to the end of the blockchain.
[0129] Subsequently, find a nonce (L) that satisfies the conditions of a predetermined PoC as a nonce value, and hash it together with the block hash (L-1) and the Merkle root (L) to generate a block hash (L). In this way, the block (L) is generated as the latest block and connected to the end of the blockchain.
[0130] When generating the block hash (n), the Merkle root (n) that is hashed together with the nonce (n) and the block hash (n-1) is the unique data (n) of the chip (n) that becomes the Merkle root (n) in the network of the electronic device of the present application (or the IoT network). However, n is any integer including the above L-3, L-2, L-1, L.
[0131] The chip (n) is an IC chip including the cell array of FIG. 14, or a memory chip. Since the unique data (n) is also unique to the Merkle root (n), it can be considered to represent the Merkle root (n). Therefore, the Merkle root (n) of the present application is, for example, the unique random number (n) of the chip (n).
[0132] The number of devices under test is not necessarily one. If the test entity is regarded as a test server, as shown in Fig. 40, the concept of Fig. 13 can be extended to a network consisting of multiple devices under test and a test server. Fig. 41 shows the situation where one test server conducts authentication tests on N devices under test. Generally, a device under test as shown in FIG. 41 is not necessarily a uniform electronic device. It refers to all devices equipped with an IC chip that are connected to the IoT network. For example, personal computers, routers, vehicles, smartphones, servers, tag readers, printers, machine tools, tablets, and so on. An example is shown in FIG. 85. However, FIG. 85 is equivalent to FIG. 41 in terms of explaining the essence of the present application. When all authentications are completed, these N electronic devices (devices under test) form a physical firewall centered around this test server. However, the method by which the test server conducts authentication tests on each device under test is the same as the method by which electronic device A authenticates electronic device B in Fig. 13. Let n be a natural number from 1 to N. The test server inputs a challenge (C) to electronic device (n), and electronic device (n) generates a response (R(n)) from the unique random number (n) of chip (n) contained therein and this C. As shown in Figs. 30 - 35, electronic device (n) generates a pair of private key (n) and public key (n) from R(n). Furthermore, the public key (n) becomes the logical address (n), or the logical address (n) can be generated from the public key (n). Fig. 41 depicts the case where the test server is integrated, but the number of test servers is not necessarily one. Although not particularly illustrated as it is obvious, similar to the case where there can be multiple inspection devices, there can also be multiple test servers within a network of integrated electronic devices. A network of integrated electronic devices is a network that includes all other electronic devices to which the electronic devices that are elements of this network can be directly or indirectly connected. However, the number (N) of peripheral devices must logically be 1 or greater than 1.
[0133] On the other hand, since the conventional firewall is composed of logical addresses, it can be called a logical firewall. When applying the logical firewall to the IoT network, as shown in FIG. 42, it becomes a target of spoofing attacks. The spoofing attack method has already been described as shown in FIGS. 4-6 and 9. As shown in FIG. 43, a hacker's electronic device (with a chip built-in) that has copied the logical address enters inside the logical firewall. FIG. 44 shows an attempt to perform the same spoofing attack on the physical firewall. As already described in FIG. 29, the present application can block this spoofing attack.
[0134] As shown in FIG. 45, if the communication within the physical firewall composed only of the electronic devices that have passed the authentication test by the method of the present application is protected by the latest cyber security methods, the reliability of the data flow on the network (IoT network) of the electronic devices will be greatly improved. There are various cyber security methods even at present, and new methods will continue to be solved in the future. The most advanced one at present is blockchain. As already described in FIGS. 36-40, the authentication method of the electronic device of the present application can realize the Merkle tree of the memory chip. Therefore, by matching the authentication of the memory chip with the logical address as shown in FIGS. 30-35, complete compatibility with the existing blockchain can be ensured. Generally, the device under test is not necessarily a uniform electronic device. It is all devices equipped with IC chips that are connected to the IoT network. For example, personal computers, routers, vehicles, smartphones, servers, tag readers, printers, machine tools, tablets, and so on. An example is shown in FIG. 86. However, FIG. 86 is equivalent to FIG. 45 in terms of explaining the essence of the present application.
[0135] Figure 45 or FIG. 86What is important is that by using the authentication method of the electronic device of the present application, a physical firewall can be configured by the central management of the test server, and a distributed system can be constructed using a blockchain among the authenticated electronic devices that are its components. This means that the coexistence of central management and distributed management, which was difficult in the cyber space, can be realized in the network (IoT network) of the electronic device of the present application. Also, since the test server can arbitrarily change the challenge (C), it is possible to update the pair of the private key and the public key of the authenticated electronic device at any time. If a hacker breaks the security of some of the authenticated electronic devices, the security of other authenticated electronic devices may also be broken in the same way. At this time, the fact that the public key and the private key of the authenticated electronic device can be automatically changed by the central management helps to instantly restore the network security to a sound state. It is because the private key, or the pair of the private key and the public key, is generated from the response as in the present application that such a countermeasure becomes possible.
[0136] When the physical firewall of the present application is created in the network of the electronic device, the electronic devices can be divided into those included in this physical firewall and those not included. The physical firewall of the present application does not prohibit the components, i.e., the electronic devices, from communicating with the outside of the physical firewall. When communicating with the outside of the physical firewall, it is desirable to inform the electronic devices inside the physical firewall that the test server has not authenticated the communication partner. Alternatively, it is desirable that the test server does not permit the communication.
[0137] If authentication of the communication partner is not performed by the test server or it is notified that communication is not permitted, it will be found that the communication partner is outside the physical firewall. In such a case, it will be up to the user or system administrator of the electronic device to decide how to handle it. For example, when a test server (first inspection entity) that authenticates a first electronic device and another test server (second inspection entity) that authenticates a second electronic device, which is the communication partner of the first electronic device, can communicate with each other, the first and second electronic devices can communicate indirectly via the first and second inspection entities. At this time, the communication content will be managed by the first and second inspection entities.
[0138] (Line redundancy) Figure 46 conceptually shows a cell array included in a chip (or memory chip) incorporated in an electronic device to be inspected. Either bit lines or word lines run horizontally, and the other runs vertically. There are bit cells (memory cells) represented by squares at the intersection points of the row lines and column lines (the intersection points of the word lines and bit lines). The position of the intersection point of the n-th bit line and the m-th word line is represented by a pair of two integers (n, m), which is called an address on the cell array. However, n is an integer from 1 to N in FIG. 14, and m is an integer from 1 to M in FIG. 14.
[0139] In this specification, this bit cell will be deliberately called an authentication element. That is, the type of the chip is determined by what kind of electronic element is adopted as this authentication element.
[0140] Since the chip (or memory chip) is a mass-produced product, accidental inclusion of defective products cannot be avoided no matter how the manufacturing process is optimized. On the cell array of FIG. 46, it occurs as defective bits. The number of defective bits and their arrangement on the cell array are random. If the amount of information of the arrangement pattern is large enough, this randomness is different for each chip, that is, it can be regarded as a unique random number unique to the chip.
[0141] A method for dividing the cell array of FIG. 46 by row line groups will be described. FIG. 47 shows an example of dividing this row line group into two upper and lower row line groups A and B. The top is the top end and the bottom is the bottom end. As an example, the row lines are bit lines and the column lines are word lines. As another example, the row lines are word lines and the column lines are bit lines.
[0142] FIG. 48 shows another example of dividing this row line group into row line group A and row line group B. Row line group A and row line group B are alternately arranged in the column direction, and the top of row line group A and the bottom of row line group B are alternately repeated. The bottom of row line group B and the top of row line group A are adjacent in the column direction.
[0143] In any case, row line groups A and B are arranged in the column direction between the top and the bottom, and as shown in FIG. 49, a row decoder A and a row decoder B are required for each. The number of rows of row line group A is LA, and the number of rows of row line group B is LB. There is a boundary line between row line group A and row line group B. However, the boundary line is drawn between the bottom of row line group A (the row line at the lower end) and the top of row line group B (the row line at the upper end), and is not a row line corresponding to a word line or a bit line. Both row decoder A and row decoder B are controlled by a peripheral control device. The peripheral control device accesses a special internal memory and controls the operations of row decoder A and row decoder B using the data (Fi, Ri) stored in the special internal memory.
[0144] Row line group A is utilized as a redundant row line group for row line group B which is a normal cell array. If the row lines are bit lines, row line group A is a bit line redundant region. If the row lines are word lines, row line group A is a word line redundant region.
[0145] As long as the chip is a mass-produced product, as shown in Fig. 46, the inclusion of defective bits is inevitable. For example, consider the case where defective bits are included in the cell array as shown in Fig. 50. However, let mA be the number of row lines (defective row lines) in which defective bits have occurred among the row line group A. Let mB be the number of row lines in which defective bits have occurred among the row line group B. Let the row lines without defective bits be normal row lines. At this time, the number of cases due to defective bit distribution is given by the product of C(LA, mA) and C(LB, mB). Here, C(S, T) is the combination of selecting T elements from S elements. In terms of information amount, it is log(C(LA, mA)) + log(C(LB, mB)). Generally, as the number of rows of the cell array increases, the number of included defective bits also increases, so it is expected that the information amount due to defective bit distribution will increase as the bit capacity of the chip increases. In the example of the figure, mA = 1 and mB = 2. Also, when the division by row line groups as in this embodiment is adopted, the information amount increases as the number of row lines (N in Fig. 14), or LA and LB increase.
[0146] To access the row line group B (normal cell array), as shown in Fig. 51, first select an appropriate column, and then specify "normal access" in the access mode of the peripheral control device (see Fig. 49). Then, sequentially access the row lines below the boundary line along the selected column. Although it is obvious and not particularly shown here, a column decoder is required to select the column in this way.
[0147] It reaches a row line where there is a defective bit on the way. In that case, read the row number (F1) and save it in the special internal memory (see Fig. 49). Without accessing the bit cell in this F1 row, instead access the bit cell of row R1 that does not contain the defective bit in row line group A (redundant row line group). Record R1 in the special internal memory (see Fig. 49) as well. This is called swapping. After swapping 1 is completed, return to row line group B (regular cell array) and resume access from the next row of F1 row. If it reaches a row line with a defective bit again, read the row number (F2) and save it in the special internal memory. Without accessing the bit cell in this F2 row, instead access the bit cell of row R2 that does not contain the defective bit in row line group A (redundant row line group). Record R2 in the special internal memory (see Fig. 49) as well. This is called swapping 2.
[0148] In this way, the combination {Fi, Ri} is stored as data in the special internal memory. However, i is a natural number from 1 to mA. The number of cases when performing mA swaps is given by the product of C(LA, mA) and P(LB, mB). Here, P(S, T) is the number of cases (permutations) of selecting and arranging T elements from S elements. In terms of information amount, it becomes log(C(LA, mB)) + log(P(LB, mB)). This is the information amount of the data stored in the special internal memory.
[0149] In order to always be able to swap, LA must be larger than the sum of mA and mB. Furthermore, in order for the regular cell array to be acceptable as a mass-produced product, LB must be much larger than mB. Even in that case, if the bit capacity is large enough, the information amount log(C(LA, mB)) + log(P(LB, mB)) will be large, and the possibility that the data stored in the special internal memories of two mass-produced chips accidentally coincide becomes negligibly low. Moreover, since its generation mechanism does not depend on any algorithm, it is physically random. Thus, the combination code {Fi, Ri} stored in the special internal memory can be regarded as a random code unique to the chip (an example of a unique random number).
[0150] Figure 52 is a diagram for explaining Test Mode 1. First, select an appropriate column. Next, specify "Test Mode 1" in the access mode of the peripheral control device (see Fig. 49), and sequentially access along the selected column from the top to the bottom row line across the boundary line. This is a mode of accessing all the row lines along the selected column from row line group A to row line group B.
[0151] Figure 53 is a diagram for explaining Test Mode 2. First, select an appropriate column. Next, specify "Test Mode 2" in the access mode of the peripheral control device (see Fig. 49), and sequentially access the row lines from the top to the boundary line along the selected column. This is a mode of accessing only the row lines belonging to row line group A.
[0152] Figure 54 shows the state of writing 0 with Test Mode 1 selected. First, select an appropriate column. Next, specify "Test Mode 1" in the access mode of the peripheral control device (see Fig. 49), and sequentially access from the top to the bottom row line across the boundary line along the selected column to write 0. In this way, all 0s are written along the selected column from row line group A to row line group B.
[0153] Subsequently, Fig. 55 shows the state of writing 1 with Test Mode 2 selected while keeping the same selected column specified. First, specify "Test Mode 2" in the access mode of the peripheral control device (see Fig. 49). Sequentially access from the top to the boundary line along the selected column and write 1. In this way, only 1 is written to row line group A along the selected column, and row line group B remains 0.
[0154] Subsequently, specify "Normal Mode" in the access mode of the peripheral control device (see Fig. 49), and Fig. 56 shows the result of sequentially accessing from the top to the boundary line along the selected column and reading. The mB row where the reading has been changed in the LB row is inverted to 1. In this way, a random pattern of 0s and 1s is formed. Since the number of cases is given by C(LB, mB), the amount of information ultimately becomes log(C(LB, mB)).
[0155] Since 0s and 1s are arranged along the selection column, it becomes a random number code like a barcode. This random number code is denoted as {d(i)}. If the bit capacity of the chip is large enough as described above, this random number code can be regarded as unique to the chip. That is, {d(i)} is a unique random number unique to the chip and is the Merkle root in FIGS. 38 and 39.
[0156] However, compared with the original information amount log(P(LA - mA,mB)) + log(P(LB,mB)), the information amount of this {d(i)} will decrease to log(C(LB, mB)).
[0157] Note that when using the argument (n) to identify multiple chips, an example of the unique random number (n) of chip (n) is {dn(i)}.
[0158] Also, in the description of this embodiment, 0 writing and 1 writing may be exchanged. The key point is that it is sufficient to be able to handle at least binary data.
[0159] The method of obtaining a unique random number by utilizing test mode 1 or test mode 2 and the normal access mode requires power consumption. If there is a need to save power even a little, although it is obvious and not particularly illustrated, wiring for accessing a special internal memory is required. A power-saving mode is possible as a mode of directly accessing the special internal memory using such wiring. In this case, when reading is performed with the power-saving mode selected as the access mode, {Fi,Ri}, which is an example of a unique random number, can be obtained. In this case, it is also possible to prevent the loss of information amount due to code conversion.
[0160] If the number of rows (LA) of the row line group A (redundant row line group) is too small, rereading may become impossible. To avoid such a situation, LA must be greater than the sum of mA and mB. It is possible to confirm whether this condition is satisfied.
[0161] Next, the address space check mode will be described. First, select any combination of a plurality of addresses, write to the corresponding authentication elements, then read, and check whether the read data matches the written data. If a sufficient number of cells match, this chip can be certified (passed) as having a sufficient address space as an authentication chip. If they do not match, the certification fails.
[0162] Figure 57 summarizes the relationship between the access mode and the operation mode described above. A redundancy mode acquisition code is given to the subject under test from an external input. This can be included in the challenge (C), or can be given separately from the challenge (C). The redundancy mode acquisition code has, as arguments, an access option for selecting an access mode, and an operation option for setting an operation mode (write, erase, read), etc.
[0163] As described above, the access mode consists of test mode 1, test mode 2, normal access mode, power saving mode, address space check mode, etc.
[0164] In the normal access mode, access is made only to the bits belonging to the row line group B (normal cell array) along the selection column, and when the row number matches the element of Fi, the row number is replaced with Ri. However, Fi and Ri are stored as redundancy data {Fi, Ri} in a special internal memory (see Fig. 49). The subscript i is a natural number from 1 to mB. It is desirable that the redundancy data be acquired during the pre-shipment inspection of the chip and stored in the special internal memory.
[0165] In this embodiment, test mode 1 is an access mode that uses both row decoder A and row decoder B. Test mode 2 is an access mode that uses only row decoder A.
[0166] Test mode 1 can obtain a unique random number {d(i)} specific to the chip even when changed to an access mode using only row decoder B as shown in Fig. 58. As an example, when writing 0 in test mode 1 and writing 1 in test mode 2, Fig. 55 is obtained. Subsequently, reading can be performed in the normal access mode. Of course, 0 and 1 can be exchanged in this case as well.
[0167] Test mode 2 can obtain a unique random number {d(i)} specific to the chip even when changed to an access mode using only row decoder B as shown in Fig. 59. As an example, when writing 0 in test mode 1 and writing 1 in test mode 2, Fig. 55 is obtained. Subsequently, reading can be performed in the normal access mode. Of course, 0 and 1 can be exchanged in this case as well.
[0168] The access option is an option for switching the selection of row decoders A and B. In Figs. 57 - 59, it is exemplified that different binary data (0 or 1) can be written to row line groups A and B by sequentially selecting test modes 1 and 2.
[0169] Generally, the area other than the cell array in the chip is called the peripheral area. Fig. 60 shows the module configuration of the peripheral area that controls row decoders A and B. The cell array is divided into row line groups A and B as described above and is controlled by row decoders A and B respectively. The peripheral control device cooperates with external input / outputs and receives the above-mentioned challenge (C) and redundant mode acquisition code as external inputs. The redundant mode acquisition code is distributed to row decoders A and B and is used for the control of row decoders A and B as shown in Figs. 57 to 59.
[0170] As an example, a unique random number {d(i)} is obtained from the redundancy data {Fi, Ri} stored in the special internal memory as in the result of FIG. 56 described above. That is, as shown in FIG. 61, d(i) can be obtained by converting (Fi, Ri) with a function f. When f is a dummy function that does nothing, the redundancy data itself is the unique random number. This unique random number {d(i)} is a set of d(i), and is distributed to the code generation device together with the challenge (C) received as an external input, and according to an appropriate response function Res (see below), returns a set of R(i), {R(i)}, as a response (R). However, the challenge is a set of C(i), {C(i)}.
[0171] R(i)=Res (C(i), d(i))
[0172] As long as the set {d(i)} is unique to the chip, the Res function satisfies the relational expressions in paragraphs 0060 and 0063.
[0173] Finally, {R(i)} is externally output as a response (R) via external input / output.
[0174] In this way, it is possible to realize the concepts of FIGS. 13 and 40 using the unique random number extracted from the special internal memory. By adopting this embodiment, the unique random numbers of FIGS. 13, 30-35, and 40 can be obtained from the redundancy data {(Fi, Ri)}. However, it is the special internal memory in the electronic device B that stores the redundancy data {(Fi, Ri)} related to the unique random number. For the unique random number, this redundancy data {(Fi, Ri)} may be used as it is, or may be used after code conversion from this data. The special internal memory may be installed in the electronic device B together with the chip related to the unique random number, or may be installed inside this chip. In any case, it is desirable that this special internal memory be unique to the electronic device B.
[0175] (Dedicated column for authentication) The cell array of the chip may be randomly accessed for purposes other than authentication during chip operation. In such a case, it is necessary to prevent inconsistencies between access to the cell array by the authentication operation of this application and access to the cell array by another operation of the chip. In this embodiment, this problem is addressed by providing a dedicated column for authentication. FIG. 62 shows the case where the dedicated authentication column is at the right end. FIG. 63 shows the case where the dedicated authentication column is located slightly to the right of the center.
[0176] When the chip performs an operation other than authentication, it is necessary to provide access restrictions so that the dedicated authentication column is not accessed. At this time, an authentication setting option for selecting either the authentication mode or the non - authentication mode as an argument of the redundant mode acquisition code will be newly added. FIGS. 57 to 59 are examples when the authentication mode is selected.
[0177] Furthermore, a mode (dedicated column specification mode) for specifying the dedicated authentication column as one of the arguments of the redundant mode acquisition code can be added. In this case, the number of columns of the dedicated authentication column is used as the argument of the dedicated column specification mode. For example, it can be specified as dedicated column specification (column number). FIG. 62 is an example when the right - most column number is selected by dedicated column specification. FIG. 63 is an example when a column number slightly to the right of the center is selected by dedicated column specification.
[0178] When the authentication mode is selected as an argument of the authentication setting mode, the dedicated authentication column with the column number selected in the dedicated column specification mode is selected. Subsequently, one of test mode 1, test mode 2, and normal access mode is specified in the access mode. Then, it is desirable to perform authentication according to the specifications of FIGS. 57 to 59.
[0179] When the non - authentication mode is selected in the dedicated column specification mode, the column numbers not selected in the dedicated column specification mode are selected. Subsequently, the normal access mode is selected.
[0180] (Block redundancy) As described above, when the cell array is divided by the row line group, the amount of information of the unique random number decreases from log(P(LA - mA, mB)) + log(P(LB, mB)) to log(C(LB, mB)). In order to control the decrease in the amount of information, a method of dividing the cell array of FIG. 14 by small blocks instead of the row line group can be expected.
[0181] FIG. 64 shows an example of dividing the cell array of FIG. 14 into small blocks. The number of small blocks in the row direction is MB, and the number of small blocks in the column direction is NB. Each small block is assigned a small block address (iB, jB). Here, iB is a natural number from 1 to MB, and jB is a natural number from 1 to NB. This is called a block array.
[0182] FIG. 65 shows an example of the element arrangement within a small block. The number of rows within each small block is BM, and the number of columns is BN. Each bit cell is assigned an address (i’, j’) within the small block. Here, i’ is a natural number from 1 to BM, and j’ is a natural number from 1 to BN. The row lines are bit lines or word lines, and the column lines are word lines or bit lines. For example, when BN is 1, this embodiment is the same as the division by the row line group. Therefore, the division by blocks (block division) can be regarded as a generalization of the division using the row line group (row line group division).
[0183] By indicating the small block address and the address within the small block, the address (bit address) of the bit cell (authentication element) can be indicated. FIG. 66 shows an example of a method for converting the bit address (i, j) into the address of this embodiment. That is, a cell block address table is required. The cell block address table is a correspondence table between any address on the cell array and the combination of the small block address and the address within the small block.
[0184] First, create a cell block address table according to FIGS. 64 and 65. The bit address (i, j) is converted to (iB, jB; i’, j’) using this cell block address table. Here, the first half (iB, jB) consists of small block addresses. The second half (i’, j’) consists of addresses within the small block.
[0185] FIG. 67 shows an example where there is a defective bit in a small block. A small block containing such a defective bit is called a defective small block. In this way, defective small blocks are arranged in the block array.
[0186] FIGS. 68 to 70 show an example where two defective small blocks are distributed in the block array. In FIG. 68, a small block address (sB, tB) is assigned to one defective small block. There is a defective bit at the address within the small block (s’, t’), and the bit address of this defective bit is represented by (sB, tB; s’, t’).
[0187] On the other hand, FIG. 69 shows a case where there is no defective bit at the address within the small block (v’, w’) in the defective small block assigned to the small block address (sB, tB).
[0188] On the other hand, FIG. 70 shows a case where there is no defective bit in the small block at the small block address (pB, qB). At this time, no matter which coordinates are selected for the address within the small block (i’, j’) of the bit address (pB, qB; i’, j’), there is no defective bit. Such a small block is called a regular small block.
[0189] In mass-produced products, it is impossible to make the defective products zero. Even if defective products are included, a method of managing them and suppressing their influence becomes important. Since it is impossible to completely remove the defective bits from the cell array in FIG. 14, the set of small blocks in FIG. 64 is divided into redundant blocks and regular blocks. FIG. 71 shows an example where two defective small blocks are distributed within a regular block.
[0190] FIG. 72 shows an example of a method for searching for defective small blocks in a block array divided into redundant blocks and regular blocks.
[0191] First, select small blocks within a regular block one by one and search whether there are any defective bits inside. However, for the sake of simplicity of explanation, the small block address assigned to the upper left small block to be examined first is set as (1, 1). To check whether there is a defective bit in that small block, check whether there is a defective bit at the in-block address (i’, j’). That is, search (1, 1; i’, j’). However, i’ scans from 1 to BM, and j’ scans from 1 to BN. If no defective bit is found after scanning from (1, 1; 1, 1) to (1, 1; BM, BN), this small block is a regular small block. Otherwise, this small block is a defective small block. Update the small block address (as an example, (1, 2; I’, j’)) and repeat the same process until all small blocks within the regular block are operated on.
[0192] In the example of FIG. 72, the upper left small block address of the regular block is set as (1, 1), and small blocks are scanned in the row direction from there. When reaching the right end, lower the column by one and search again in the row direction from the left end (2, 1). The same method can be used for scanning small blocks within the redundant block.
[0193] In this way, a set of small block addresses of defective small blocks {defective small block (iB, jB)} and a set of addresses of defective bits {(iB, jB; i’, j’)} are obtained. Both are random data unique to the chip (unique random numbers), but the set of small block addresses of defective small blocks {(iB, jB)} has less information volume than the set {(iB, jB; i’, j’)}. However, it is possible to suppress the loss of information volume by reducing the number of bits within the small block.
[0194] In this embodiment, the set of small block addresses of defective small blocks {defective small blocks (iB, jB)} is redundancy data. Generally, redundancy data is associated with a unique random number, so the set {defective small blocks (iB, jB)} can be regarded as a unique random number. For example, FIG. 73 shows the addresses of defective small blocks displayed and arranged in binary. In this way, the set {defective small blocks (iB, jB)} is obtained as a random number code unique to the chip displayed in binary of 0 and 1. This redundancy data is acquired during the pre-shipment inspection of the chip and stored in a special internal memory.
[0195] FIG. 74 shows an example of a method for rereading small blocks. In this example, scanning is performed in the row direction, but it is also possible to scan in the column direction as shown in FIG. 52. In particular, if power saving is not a particular issue, it is desirable to generate a unique random number from the set {defective small blocks (iB, jB)} by this method. Although not particularly illustrated as it is obvious, various scanning methods can be adopted in the present application.
[0196] First, scan the small blocks in the normal block one by one by the method described above or another appropriate method. If the first defective small block is found, move to the redundant block and start scanning the small blocks in the redundant block. Replace the first normal small block that appears in the redundant block with the defective small block found in the normal block. This is referred to as rereading 1 in FIG. 73. After rereading 1, update the small block addresses in the redundant block, return to the normal block, update the small block addresses in the normal block, and resume scanning in the normal block. If the next defective small block is found, move to the redundant block and start scanning the small blocks in the redundant block. Replace the first normal small block that appears in the redundant block with the defective small block found in the normal block. This is referred to as rereading 2 in FIG. 73. After rereading 2, update the small block addresses in the redundant block, return to the normal block, update the small block addresses in the normal block, and resume scanning in the normal block.
[0197] Repeat this operation until all small blocks in the normal block have been scanned.
[0198] However, the redundant block and the regular block must be divided so that the number of regular small blocks in the redundant block is larger than the number of defective small blocks found in the regular block. This is determined by the chip design specification. However, if only chips that meet this condition in the adopted design specification are shipped as non-defective products, all the shipped chips will meet the condition that "the number of regular small blocks in the redundant block is larger than the number of defective small blocks found in the regular block."
[0199] As described above, the division by small blocks is a generalization of the division using the row line group. That is, the relationship corresponding to the selection method of the access options and operation options in FIGS. 57 to 59 also exists in this embodiment. This is shown in FIGS. 75 to 77. Each corresponds to FIGS. 57 to 59 respectively.
[0200] First, a redundant mode acquisition code is given to the subject under inspection from an external input. This can be included in the challenge (C), or can be given separately from the challenge (C). The redundant mode acquisition code has, as arguments, access options for selecting an access mode, and operation options for setting an operation mode (write, erase, read), etc.
[0201] As described above, the access mode consists of test mode 1, test mode 2, normal access mode, power saving mode, address space check mode, etc. So far, it is the same as FIG. 57.
[0202] However, in FIGS. 75 to 77, the information stored in the special internal memory is replaced by the set {small blocks (iB, jB)} that generalizes the row line group division. Further, for bit address conversion, it is necessary to read the cell block address table in FIG. 66 from the normal access mode.
[0203] It is also necessary to explain again the generalization of the block division in test modes 1 and 2.
[0204] FIG. 78 shows a method of controlling access to redundant blocks and normal blocks using row decoder A, row decoder B, and a column decoder.
[0205] The peripheral control device receives a challenge (C) and a redundant mode acquisition code through an external input / output. According to the access option of the redundant mode acquisition code, row decoder A controls access to the redundant block together with the column decoder. Row decoder B controls access to the normal block together with the column decoder. Further, by manipulating the operation option, a set of addresses of defective bits {(i,j)} is obtained. This is converted into a set of addresses of defective sub-blocks {(iB,jB)} using a cell block address table. This results in data where 0s and 1s are distributed in a checkered pattern as shown in FIG. 79, for example. This can be converted to binary representation to obtain a unique random number {d(i)}. This is stored in a special internal memory. The unique random number and the challenge (C) obtained from the external input / output are input to the response function (Res) of paragraph 0171 to obtain a response {R(i)}. Finally, {R(i)} is output externally as a response (R) via the external input / output.
[0206] Return to FIG. 75. First, select test mode 1 in the access option and write 0 to all sub-block addresses accessible in combination with the column decoder. Subsequently, select test mode 2 and write 1 to all sub-block addresses accessible. Subsequently, select the normal access mode and sequentially scan all accessible sub-blocks, and determine whether they are defective sub-blocks while reading the data in the special internal memory. If it is a defective sub-block, a read replacement to the redundant sub-block is performed, and the read result will be 1. If it is a normal sub-block, the read result will be 0. Thus, as an example, data where 0s and 1s are distributed in a checkered pattern as shown in FIG. 79 is obtained. It is also possible to do the same by exchanging 0s and 1s. As described above, this becomes a unique random number.
[0207] Return to Fig. 76. First, select Test Mode 1 in the access option and write 0 to all small block addresses accessible in combination with the column decoder. Subsequently, select Test Mode 2 and write 1 to all small block addresses accessible. Then, select the normal access mode and sequentially scan all accessible small blocks, determining whether there are defective small blocks while reading the data in the special internal memory. If it is a defective small block, read it instead to the redundant small block, and the read result will be 1. If it is a normal small block, the read result will be 0. In this way, as an example, data distributed in a checkered pattern of 0 and 1 as shown in Fig. 79 is obtained. It is also okay to do the same thing after exchanging 0 and 1. As described above, this becomes a unique random number.
[0208] Return to Fig. 77. First, select Test Mode 1 in the access option and write 1 to all small block addresses accessible in combination with the column decoder. Subsequently, select Test Mode 2 and write 0 to all small block addresses accessible. Then, select the normal access mode and sequentially scan all accessible small blocks, determining whether there are defective small blocks while reading the data in the special internal memory. If it is a defective small block, read it instead to the redundant small block, and the read result will be 1. If it is a normal small block, the read result will be 0. In this way, as an example, data distributed in a checkered pattern of 0 and 1 as shown in Fig. 79 is obtained. It is also okay to do the same thing after exchanging 0 and 1. As described above, this becomes a unique random number.
[0209] Fig. 80 conceptualizes the above-described operation. Compared with Fig. 61, the unique random number stored in the special internal memory is the set of addresses of defective small blocks, and this is the only difference. Since the rest is the same, detailed explanations are omitted.
[0210] (Authentication - only bit) As described above, the cell array of the chip may be randomly accessed for purposes other than authentication during chip operation. In such a case, it is necessary to prevent inconsistencies from occurring between the access to the cell array by the authentication operation of the present application and the access to the cell array by another operation of the chip.
[0211] In this embodiment, this problem is addressed by providing an authentication - dedicated bit in the small - block - internal address. FIG. 81 shows the case where the authentication - dedicated bit is at the upper - left corner of the small block. FIG. 82 shows the case where the authentication - dedicated bit is at a position slightly to the center from the upper - left corner.
[0212] When the chip performs an operation other than authentication, it is necessary to select the non - authentication mode in the authentication setting option and provide a restriction so as not to access this authentication - dedicated bit within each small block. FIGS. 75 to 77 are examples when the authentication mode is selected.
[0213] Furthermore, a mode (dedicated - bit - specified mode) for specifying the authentication - dedicated bit as one of the arguments of the redundant - mode acquisition code can be added. In this case, the row number and column number of the authentication - dedicated bit are used as the arguments (designated - bit address) of the dedicated - bit - specified mode. For example, it can be designated as dedicated - bit - specified (row number, column number). However, the address selected by the dedicated - bit - specified mode is the address within the small block. FIG. 81 shows an example when the bit at the upper - left corner within the small block is selected by the dedicated - bit - specified mode. FIG. 82 shows an example when the bit from the upper - left corner to the right of the center is selected by the dedicated - bit - specified mode.
[0214] When the authentication mode is selected as an argument of the authentication setting mode, the authentication - dedicated bit of the bit selected in the dedicated - column - specified mode is selected. Subsequently, one of test mode 1, test mode 2, and normal access mode is specified in the access mode. Then, authentication can be performed according to the specifications of FIGS. 75 to 77.
[0215] When the non-authentication mode is selected in the dedicated bit specification mode, bits not selected by the dedicated bit specification are selected within each small block. Subsequently, the normal access mode is selected.
[0216] Figures 13 and 40 illustrate the concept of the present application. If the present embodiment (block redundancy) is adopted, the redundancy code {defective small block (iB, jB)} can be used as data related to the unique random numbers in Figures 13, 30 - 35, and 40. Alternatively, if the embodiment of (row line redundancy) is adopted, the redundancy code {(Fi, Ri)} can be used as data related to the unique random numbers in Figures 13, 30 - 35, and 40.
[0217] In any case, generally according to the concepts of Figures 13 and 40, the inspection entity inputs the data (code information) {C(i)} to be challenged into the device under test. Also, if BM = 1 and BN = N in Figure 65, it can be seen that (block redundancy) generalizes (row line redundancy).
[0218] Inside the chip included in the device under test, data (defective code information) related to the defective bit distribution unique to that chip is stored as data related to the unique random number unique to the chip.
[0219] Generating the response (R) from the challenge (C) together with this defective code information according to the formula in paragraph 0060 ultimately agrees with the generation of the response (R) using the unique random number and the challenge (C). As long as the unique random number is unique to the chip, that is, as long as the unique random number can be regarded as having a one-to-one relationship with the chip, this response (R) can be regarded as determined by the challenge (C) and the chip.
[0220] The inspection entity receives this response (R) output from the device under test and authenticates the device under test from the combination of C and R. At this time, it is desirable for the inspection entity to play the role of the test server in Figure 41.
[0221] Note that it is possible to generate a pair of a private key and a public key according to the PKI algorithm using the response (R) and the method shown in FIGS. 30 to 35. The pair of the private key and the public key thus generated is utilized for data transmission and reception using the method shown in FIGS. 36 and 37.
[0222] As shown in FIGS. 13 and 40, this private key is associated with a unique random number unique to the chip constituting the device under test in an inseparable manner. Moreover, as shown in the equations in paragraphs 0060 and 0063, the challenge (C) is also included as an argument. Therefore, even if a hacker steals the unique random number, since the inspection entity uses the pair of (C, R) for authentication of the device under test, it is impossible to forge the authentication of the device under test unless the inspection entity itself is hacked.
[0223] The special internal memory in the device under test stores data (such as defective code information) related to the unique random number. It is desirable to install the special internal memory inside the chip related to the unique random number. Alternatively, it is also possible to install it inside the device under test together with the chip related to the unique random number. In any case, it is desirable that this special internal memory is unique to the device under test. Also, it is desirable that the special internal memory is not directly connected to the external input / output of the chip.
[0224] As shown in FIG. 41, a test server (core device) exists as the central position of the physical firewall. The test server manages other electronic devices (peripheral devices), and the peripheral devices can communicate with each other using the public key or the code information generated from the public key as a logical address. The difference between the case of communicating with another electronic device within the physical firewall and the case of communicating with an external electronic device lies in whether the test server can be authenticated. Since an external electronic device cannot be authenticated by the test server, whether to communicate with the external electronic device or what kind of communication to perform is left to the judgment of the administrator. As an example, it is desirable to communicate with an electronic device outside the physical firewall via the test server.
[0225] The test server performs authentication management of peripheral devices using a set of combinations of inputs (challenges, C) and responses (R) from the peripheral devices under its management. When the same challenge (C) is input to the peripheral devices under the management of the test server all at once, each peripheral device returns a different response (R), so the test server will obtain the set of R, {R}. The test server can change the challenge (C) at any time and send it to the peripheral devices under its management each time. This is a change in the challenge (C). The set of responses (R) from each peripheral device also changes corresponding to the changed challenge (C). That is, the test server can manage the authentication of peripheral devices within the physical firewall using a combination of C and {R} that can be updated as appropriate.
[0226] Note that the technical scope of the present invention is not limited to the above embodiments, and various changes can be made without departing from the spirit of the present invention.
Industrial Applicability
[0227] Central management centered on the test server for chip authentication using a unique random number unique to the chip, and entrusting the communication between electronic devices having authenticated chips as components to distributed management such as blockchain, and complementing the central management and the distributed management with each other makes it possible to strengthen the security of the IoT network. Also, it is desirable that the redundancy data be unique to the chip like the unique random number.
[0228] Finally, in FIGS. 30 - 35, the private key and the public key are generated from the response (R(n)), but it is also possible to generate the private key and the public key from the unique random number (n). In this case, the inspection entity (test server) inputs a challenge (C) into the key generation device as an example, as shown in FIGS. 83 and 84. In the key generation device, it is desirable to synthesize the unique random number (n) and this challenge (C) in some way and generate a pair of private key and public key based on it using a predetermined algorithm (RSA type or Elgamal type). FIGS. 83 and 84 correspond to the cases where the Elgamal type and RSA type algorithms are used in the key generation device respectively. The method of synthesizing the unique random number (n) and the challenge (C) can be realized, for example, using a logic gate with two inputs and one output such as logical AND, logical NAND, logical XOR, logical OR, logical NOR, etc. Although not particularly illustrated as it is obvious, in the embodiments of FIGS. 83 and 84, it is also possible to use a second input as in FIGS. 31 and 32, or FIGS. 34 and 35. Also, in the case of this embodiment, the code generation devices in FIGS. 60, 61, 78, 80 are not necessarily used. Further, in FIGS. 60 and 78, it is also possible to install a key generation device in the peripheral control device. At this time, the key generation device may be installed as software or may be incorporated as an embedded circuit.
[0229] More specifically, it is about the proper use of FIGS. 41 and 45. For example, in FIG. 41, it is central management that the test server authenticates each node (peripheral device) belonging to the network. On the contrary, in FIG. 45, it is distributed management that each node communicates with each other without going through the test server.
[0230] In the central management of FIG. 41, first, registration of N peripheral devices (devices under test) to be placed under management is performed. For example, the test server (inspection subject) sends a first challenge (CA) to these N peripheral devices. These N peripheral devices each generate a response (R1, R2... RN) to C using an internal unique random number and send it back to the test server. The test server saves this pair of challenge and response (CAR1, CAR2, CAR3... CARN). Let this saved data be {CAR}. Such registration can be performed at any time for the convenience of central management. For example, when a cyber attack occurs, all nodes can be disconnected by removing temporary authentication, and after safety confirmation, it can be appropriately performed for network recovery.
[0231] Subsequently, the test server checks whether any node on the network is a peripheral device under its management. For example, the test server sends a first challenge (CA) to any selected node. Suppose this node replies with a response (RA) to the test server. The test server checks it against the stored {CAR}. If the pair of CA and RA is found in this stored {CAR}, it is determined that this node is a registered node. Otherwise, the connection is not permitted. In this way, it can be excluded outside the physical firewall as shown in FIG. 44.
[0232] Nodes that are known to belong to the physical firewall by the method described above can communicate freely with each other. As shown in FIG. 45, this communication is protected by cyber security technology and is subject to distributed management. As an example, the cyber security technology proposed in this application is the one described in FIGS. 27-35, 40, 83, 84. Note that the cyber security technology of this application is in good consistency with the blockchain as shown in FIGS. 36-39. For example, R(N) in FIGS. 36 and 37 is the response R(n) in FIGS. 27-35. When using a unique random number as the response R as shown in FIGS. 83 and 84, R(N) in FIGS. 36 and 37 may be replaced with the unique random number (N). Since it is self-evident, the drawings are omitted.
[0233] Here, the important thing is that in FIGS. 27-35, 40, it is desirable to use a second challenge (CB) different from the first challenge (CA) for the challenge input to the IC chip to obtain a response using a unique random number. Because the first challenge (CA) has been exposed to the network once, there is a non-zero possibility of being exploited by hackers. However, if the first challenge can be prevented from being exploited by another method, the first and second challenges may be the same. It does not matter whether the test server distributes the second challenge to each peripheral device or not. When the test server does not distribute the second challenge, it becomes a network with two inspection entities. In this case, it is desirable because the separation and cooperation between central management and distributed management are likely to be clear.
Brief Description of the Drawings
[0234]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
Figure 19
Figure 20
Figure 21
Figure 22
Figure 23
Figure 24
Figure 25
Figure 26
Figure 27
Figure 28
Figure 29
Figure 30
Figure 31
Figure 32
Figure 33
Figure 34
Figure 35
Figure 36
Figure 37
Figure 38
Figure 39
Figure 40
Figure 41
Figure 42
Figure 43
Figure 44
Figure 45
Figure 46
Figure 47
Figure 48
Figure 49
Figure 50
Figure 51
Figure 52
Figure 53
Figure 54
Figure 55
Figure 56
Figure 57
Figure 58
Figure 59
Figure 60
Figure 61
Figure 62
Figure 63
Figure 64
Figure 65
Figure 66
Figure 67
Figure 68
Figure 69
Figure 70
Figure 71
Figure 72
Figure 73
Figure 74
Figure 75
Figure 76
Figure 77
Figure 78
Figure 79
Figure 80
Figure 81
Figure 82
Figure 83
Figure 84
Figure 85
Figure 86
Claims
1. A network of electronic devices consisting of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, At least one of the other electronic devices among the plurality of electronic devices serves as the inspection subject, The first to Mth devices to be inspected are the first to Mth peripheral devices respectively, The inspection subject inputs a first challenge to the first to Mth peripheral devices, The first to Mth peripheral devices, based on the response function, according to the first challenge, Each return a first to Mth response to the inspection subject, The first to Mth responses form a first response set with the first to Mth responses as elements, The inspection subject saves the first challenge and the first response set, The first to Mth peripheral devices generate a pair of a first to Mth private key and a first to Mth public key respectively from the first to Mth responses, The first to Mth peripheral devices each have a first to Mth IC chip as a component, The response function takes the first challenge and the unique random numbers unique to the first to Mth IC chips as arguments, and generates the first to Mth responses respectively, Select one of the first to Mth IC chips as the nth IC chip, The nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output device, The cell array is divided into a first and a second cell array, The row decoder is divided into a first and a second row decoder, The first and second row decoders respectively control access to the first and second cell arrays, The peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output device, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, and acquires an nth unique random number from the access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, and passes the nth unique random number to the code generation device, The code generation device uses the response function to generate an nth response from the first challenge and the nth unique random number, and passes it to the external input / output device, The external input / output device receives the redundant mode acquisition code and the input of the first challenge from the outside, receives the nth response from the code generation device, and outputs the nth response to the outside of the nth IC chip. The redundant mode acquisition code includes an authentication setting option, a dedicated bit designation mode, an access option, and an operation option. The cell array is divided into a plurality of small blocks, and the IC chip further has a cell block address table. The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-block address. The dedicated bit designation mode has a designated bit address as an argument. The designated bit address is an authentication dedicated bit within the small block. The authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the authentication dedicated bit is selected as the selected bit address of the in-block address within the small block. When the non-authentication mode is selected, one bit other than the authentication dedicated bit is selected as the selected bit address within the small block. The access option controls a combination of the column decoder, the first and second row decoders, and instructs access to each bit address on the cell array. The operation option includes writing, erasing, and reading to each bit address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching a combination of the access option and the operation option. A digital information communication system, characterized in that.
2. Among the plurality of small blocks, a small block including an address of a defective bit distributed on the cell array is defined as a defective small block, and a small block not including the address of the defective bit is defined as a normal small block. The nth redundancy code is related to the distribution of the defective small blocks. The digital information communication system according to claim 1, characterized in that.
3. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to the Mth devices to be inspected. At least one of the plurality of other electronic devices serves as an inspection subject, the first to Mth devices to be inspected are the first to Mth peripheral devices respectively, the inspection subject inputs a first challenge to the first to Mth peripheral devices, the first to Mth peripheral devices, based on the response function, in response to the first challenge, each return a first to Mth response to the inspection subject, the first to Mth responses form a first response set with the first to Mth responses as elements, the inspection subject saves the first challenge and the first response set, the first to Mth peripheral devices generate, respectively, a pair of a first to Mth private key and a first to Mth public key from the first to Mth responses, the first to Mth peripheral devices each have a first to Mth IC chip as a component, the response function generates the first to Mth responses respectively, taking the first challenge and the unique random numbers inherent in the first to Mth IC chips as arguments, select one of the first to Mth IC chips as the nth IC chip, the nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output device, the cell array is divided into a first and a second cell array, the row decoder is divided into a first and a second row decoder, the first and second row decoders respectively control access to the first and second cell arrays, the peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output device, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, obtains the nth unique random number from access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, and passes the nth unique random number to the code generation device, the code generation device uses the response function to generate the nth response from the first challenge and the nth unique random number and passes it to the external input / output device, The external input / output device receives the redundant mode acquisition code and the input of the first challenge from the outside, receives the nth response from the code generation device, and outputs the nth response to the outside of the nth IC chip. The redundant mode acquisition code includes authentication setting options, dedicated column designation mode, access options and operation options. The dedicated column designation mode has a designated column number as an argument. The authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication dedicated column, and the authentication dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column. The access option selects a combination of the first and second row decoders and instructs access to the address defined by the combination of the row decoders and the selected column. The operation option includes writing, erasing, and reading to the address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching the combination of the access option and the operation option. A digital information communication system characterized by the above.
4. A row line including the address of a defective bit distributed on the cell array is defined as a defective row line, and a row line not including the address of the defective bit is defined as a normal row line. The nth redundancy code is related to the distribution of the defective row lines. The digital information communication system according to claim 3, characterized by the above.
5. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to the Mth devices to be inspected. At least one of the other plurality of electronic devices serves as an inspection subject. The first to the Mth devices to be inspected are the first to the Mth peripheral devices respectively. The inspection subject inputs a first challenge to the first to the Mth peripheral devices. The first to the Mth peripheral devices return the first to the Mth responses to the inspection subject respectively according to the first challenge based on the response function. The first to the Mth responses form a first response set with the first to the Mth responses as elements. The inspection entity stores the first challenge and the first response set, The first to Mth peripheral devices respectively generate first to Mth secret keys from the first to Mth responses, and respectively generate pairs of first to Mth public keys from the first to Mth secret keys. The first to Mth peripheral devices each have the first to Mth IC chips as components. The response function generates the first to Mth responses respectively, taking the first challenge and the unique random numbers inherent in the first to Mth IC chips as arguments. Select one of the first to Mth IC chips as the nth IC chip. The nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into first and second cell arrays. The row decoder is divided into first and second row decoders. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, and acquires the nth unique random number from access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, and passes the nth unique random number to the code generation device. The code generation device generates the nth response from the challenge passed to the peripheral device and the nth unique random number using the response function. The external input / output receives the input of the redundancy mode acquisition code and the first challenge from the outside, receives the nth response from the code generation device, and outputs the nth response outside the nth IC chip. The redundancy mode acquisition code includes authentication setting options, dedicated bit designation modes, access options, and operation options. The cell array is divided into a plurality of small blocks. The IC chip further has a cell block address table. The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-block address. The dedicated bit specification mode has a specified bit address as an argument, wherein the specified bit address is an authentication dedicated bit within the small block, the authentication setting option consists of an authentication mode or a non - authentication mode. When the authentication mode is selected, the authentication dedicated bit is selected as the selected bit address of the address within the small block, and when the non - authentication mode is selected, one bit other than the authentication dedicated bit is selected as the selected bit address within the small block. The access option controls the combination of the column decoder, the first and second row decoders, and instructs access to each bit address on the cell array. The operation option includes writing, erasing, and reading to each bit address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching the combination of the access option and the operation option. A digital information communication system characterized by the above.
6. Among the plurality of small blocks, a small block containing the address of a defective bit distributed on the cell array is defined as a defective small block, and a small block not containing the address of the defective bit is defined as a normal small block. The nth redundancy code is related to the distribution of the defective small blocks. The digital information communication system according to claim 5, characterized by the above.
7. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to the Mth devices to be inspected. At least one of the other plurality of electronic devices serves as an inspection subject. The first to the Mth devices to be inspected are respectively the first to the Mth peripheral devices. The inspection subject inputs a first challenge to the first to the Mth peripheral devices. The first to the Mth peripheral devices respectively return first to Mth responses to the inspection subject according to the first challenge based on a response function. The first to the Mth responses form a first response set with the first to the Mth responses as elements. The inspection subject stores the first challenge and the first response set. The first to Mth peripheral devices generate first to Mth secret keys respectively from the first to Mth responses, and generate pairs of first to Mth public keys respectively from the first to Mth secret keys. The first to Mth peripheral devices each include the first to Mth IC chips as components. The response function generates the first to Mth responses respectively using the first challenge and the unique random numbers inherent in the first to Mth IC chips as arguments. One of the first to Mth IC chips is selected as the nth IC chip. The nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, obtains the nth unique random number from access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, and passes the nth unique random number to the code generation device. The code generation device generates the nth response using the response function from the challenge passed to the peripheral device and the nth unique random number. The external input / output receives the input of the redundancy mode acquisition code and the first challenge from the outside, receives the nth response from the code generation device, and outputs the nth response outside the nth IC chip. The redundancy mode acquisition code includes an authentication setting option, a dedicated column designation mode, an access option, and an operation option. The dedicated column designation mode has a designated column number as an argument. The authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication dedicated column, and the authentication dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column. The access option selects a combination of the first and second row decoders and instructs access to an address defined by the combination of the row decoders and the selection column. The operation option includes writing, erasing, and reading to / from the address. When the authentication mode is selected, the peripheral control device reads the n-th unique random number from the cell array based on the n-th redundancy code by switching the combination of the access option and the operation option. A digital information communication system characterized by the above.
8. A row line including an address of a defective bit distributed on the cell array is defined as a defective row line, and a row line not including the address of the defective bit is defined as a normal row line. The n-th redundancy code is related to the distribution of the defective row lines. The digital information communication system according to claim 7, characterized by the above.
9. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to M-th devices to be inspected. At least one of the other electronic devices among the plurality of electronic devices serves as an inspection subject. The first to M-th devices to be inspected are the first to M-th peripheral devices, respectively. The inspection subject inputs a first challenge to the first to M-th peripheral devices. The first to M-th peripheral devices each include the first to M-th IC chips as components. The first to M-th IC chips each have unique first to M-th unique random numbers. The first to M-th peripheral devices each generate a pair of a first to M-th secret key and a first to M-th public key from the first challenge and the first to M-th unique random numbers. One of the first to M-th IC chips is selected as the n-th IC chip. The n-th IC chip includes a cell array, a row decoder, a column decoder, a peripheral control device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders each control access to the first and second cell arrays, respectively. The external input / output receives an input of a redundancy mode acquisition code and the first challenge from the outside. The peripheral control device receives the redundant mode acquisition code and the challenge from the external input / output, operates the first and second decoders based on the redundant mode acquisition code, and acquires the nth unique random number from the access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory. The redundant mode acquisition code includes authentication setting options, dedicated bit designation modes, access options, and operation options. The cell array is divided into a plurality of small blocks. The IC chip further has a cell block address table. The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-small-block address. The dedicated bit designation mode has a designated bit address as an argument. The designated bit address is an authentication-dedicated bit within the small block. The authentication setting options consist of an authentication mode or a non-authentication mode. When the authentication mode is selected, the authentication-dedicated bit is selected as the selected bit address of the in-small-block address. When the non-authentication mode is selected, one bit other than the authentication-dedicated bit is selected as the selected bit address within the small block. The access options operate a combination of the column decoder, the first and second row decoders, and instruct access to each bit address on the cell array. The operation options include writing, erasing, and reading to each bit address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching a combination of the access options and the operation options. A digital information communication system characterized by the above.
10. Among the plurality of small blocks, a small block including an address of a defective bit distributed on the cell array is defined as a defective small block, and a small block not including the address of the defective bit is defined as a regular small block. The nth redundancy code is related to the distribution of the defective small blocks. The digital information communication system according to claim 9, characterized by the above.
11. A network of electronic devices consisting of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, and at least one of the other electronic devices among the plurality of electronic devices serves as an inspection subject, the first to Mth devices to be inspected are the first to Mth peripheral devices respectively, the inspection subject inputs a first challenge to the first to Mth peripheral devices, the first to Mth peripheral devices each have the first to Mth IC chips as components, the first to Mth IC chips have first to Mth unique random numbers respectively unique to the first to Mth IC chips, the first to Mth peripheral devices respectively generate a pair of first to Mth secret keys and first to Mth public keys from the first challenge and the first to Mth unique random numbers, select one of the first to Mth IC chips as the nth IC chip, the nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a special internal memory, and an external input / output, the cell array is divided into a first and a second cell array, the row decoder is divided into a first and a second row decoder, the first and second row decoders respectively control access to the first and second cell arrays, the external input / output receives a redundancy mode acquisition code and an input of the first challenge from the outside, the peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, and acquires the nth unique random number from access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, the redundancy mode acquisition code includes authentication setting options, a dedicated column designation mode, access options, and operation options, the dedicated column designation mode has a designated column number as an argument, the authentication setting options consist of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication-dedicated column, and the authentication-dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column, the access options select a combination of the first and second row decoders and instruct access to an address defined by the combination of the row decoders and the selected column, The operation options include writing to, erasing from, and reading from the address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching the combination of the access option and the operation option. A digital information communication system characterized by the above.
12. A row line including the address of a defective bit distributed on the cell array is defined as a defective row line, and a row line not including the address of the defective bit is defined as a normal row line. The nth redundancy code is related to the distribution of the defective row lines. The digital information communication system according to claim 11, characterized by the above.
13. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to the Mth devices to be inspected. At least one of the other electronic devices among the plurality of electronic devices serves as an inspection subject. The first to the Mth devices to be inspected are the first to the Mth peripheral devices respectively. The inspection subject inputs a first challenge to the first to the Mth peripheral devices. The first to the Mth peripheral devices each include the first to the Mth IC chips as components. The first to the Mth IC chips each have unique first to the Mth unique random numbers respectively. The first to the Mth peripheral devices each generate first to the Mth secret keys from the first challenge and the first to the Mth unique random numbers, and each generate a pair of first to the Mth public keys from the first to the Mth secret keys. One of the first to the Mth IC chips is selected as the nth IC chip. The nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders each control access to the first and second cell arrays. The external input / output receives an input of a redundancy mode acquisition code and the first challenge from the outside. The peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, operates the first and second decoders based on the redundancy mode acquisition code, and acquires an nth unique random number from accesses to the first and second cell arrays based on the nth redundancy code stored in the special internal memory. The redundancy mode acquisition code includes authentication setting options, dedicated bit designation modes, access options, and operation options. The access options include operation options. The cell array is divided into a plurality of small blocks. The IC chip further has a cell block address table. The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-small-block address. The dedicated bit designation mode has a designated bit address as an argument. The designated bit address is an authentication-dedicated bit within the small block. The authentication setting options consist of an authentication mode or a non-authentication mode. When the authentication mode is selected, the authentication-dedicated bit is selected as the selected bit address of the in-small-block address. When the non-authentication mode is selected, one bit other than the authentication-dedicated bit is selected as the selected bit address within the small block. The access options operate a combination of the column decoder, the first and second row decoders, and instruct access to each bit address on the cell array. The operation options include writing, erasing, and reading to / from each bit address. When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching a combination of the access options and the operation options. A digital information communication system, characterized in that.
14. Among the plurality of small blocks, a small block including an address of a defective bit distributed on the cell array is defined as a defective small block, and a small block not including the address of the defective bit is defined as a normal small block. The nth redundancy code is related to the distribution of the defective small blocks. The digital information communication system according to claim 13, characterized in that.
15. A network of electronic devices composed of a plurality of electronic devices. Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, and at least one of the other electronic devices among the plurality of electronic devices serves as an inspection subject, the first to Mth devices to be inspected are the first to Mth peripheral devices respectively, the inspection subject inputs a first challenge to the first to Mth peripheral devices, the first to Mth peripheral devices each have the first to Mth IC chips as components, the first to Mth IC chips each have unique first to Mth random numbers unique to the first to Mth IC chips, the first to Mth peripheral devices respectively generate first to Mth secret keys from the first challenge and the first to Mth random numbers, and respectively generate pairs of first to Mth public keys from the first to Mth secret keys, select one of the first to Mth IC chips as the nth IC chip, the nth IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a special internal memory, and an external input / output, the cell array is divided into first and second cell arrays, the row decoder is divided into first and second row decoders, the first and second row decoders respectively control access to the first and second cell arrays, the external input / output receives a redundancy mode acquisition code and an input of the first challenge from the outside, the peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, and acquires the nth random number from access to the first and second cell arrays based on the nth redundancy code stored in the special internal memory, the redundancy mode acquisition code includes an authentication setting option, a dedicated column designation mode, an access option, and an operation option, the dedicated column designation mode has a designated column number as an argument, the authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication dedicated column, and the authentication dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column, the access option selects a combination of the first and second row decoders, Instruct access to the combination of the row decoder and the address defined by the selection column, The operation options include writing, erasing, and reading to the address, When the authentication mode is selected, the peripheral control device reads the nth unique random number from the cell array based on the nth redundancy code by switching the combination of the access option and the operation option. A digital information communication system characterized by the above.
16. The row line including the address of the defective bit distributed on the cell array is defined as a defective row line, and the row line that does not include the address of the defective bit is defined as a normal row line. The row line that does not include the address of the defective bit is defined as a normal row line. The nth redundancy code is related to the distribution of the defective row lines. The digital information communication system according to claim 15, characterized by the above.
17. A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, the first electronic device is the inspection subject, and the second electronic device is the device to be inspected. The second electronic device is the device to be inspected. The inspection subject inputs a challenge to the second electronic device. The second electronic device generates a response according to the challenge based on the response function. The second electronic device generates a response. The second electronic device has at least one IC chip. The IC chip has a cell array, a row decoder, a column decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into a first and a second cell array. The row decoder is divided into a first and a second row decoder. The first and second row decoders respectively control access to the first and second cell arrays. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, and based on the redundancy code stored in the special internal memory, obtains the unique random number unique to the IC chip from the access to the first and second cell arrays, and passes the unique random number to the code generation device. The peripheral control device receives the redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, and based on the redundancy code stored in the special internal memory, obtains the unique random number unique to the IC chip from the access to the first and second cell arrays, and passes the unique random number to the code generation device. The code generation device generates the response from the challenge and the unique random number. The code generation device generates the response from the challenge and the unique random number. The code generation device generates the response. The external input / output receives the input of the redundancy mode acquisition code and the challenge from the outside. Receive the response from the code generation device, and output the response outside the IC chip. The redundancy mode acquisition code includes authentication setting options, dedicated bit designation modes, access options, and operation options. The cell array is divided into a plurality of small blocks. The IC chip further has a cell block address table. The cell block address table is a correspondence table between any address on the cell array and a combination of a small block address and an in-block address. The dedicated bit designation mode has a designated bit address as an argument. The designated bit address is an authentication dedicated bit within the small block. The authentication setting option consists of an authentication mode or a non-authentication mode. When the authentication mode is selected, the authentication dedicated bit is selected as the selected bit address of the in-block address. When the non-authentication mode is selected, one bit other than the authentication dedicated bit is selected as the selected bit address within the small block. The access option controls a combination of the column decoder, the first and second row decoders, and instructs access to each bit address on the cell array. The operation option includes writing, erasing, and reading to each bit address. When the authentication mode is selected, the peripheral control device reads the unique random number from the cell array based on the redundancy code by switching a combination of the access option and the operation option. The response function generates the response with the challenge and a unique random number unique to the IC chip as arguments. A digital information communication system characterized by the above.
18. Among the plurality of small blocks, a small block including an address of a defective bit distributed on the cell array is defined as a defective small block, and a small block not including the address of the defective bit is defined as a normal small block. The redundancy code is related to the distribution of the defective small blocks. The digital information communication system according to claim 17, characterized by the above.
19. A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, the first electronic device is the inspection subject, and the second electronic device is the inspected device. The inspection entity inputs a challenge to the second electronic device, and based on a response function, the second electronic device generates a response in response to the challenge. The second electronic device has at least one IC chip. The IC chip has a cell array, a row decoder, a peripheral control device, a code generation device, a special internal memory, and an external input / output. The cell array is divided into first and second cell arrays. The row decoder is divided into first and second row decoders. The first and second row decoders respectively control access to the first and second cell arrays. The peripheral control device receives a redundancy mode acquisition code and the challenge from the external input / output, controls the first and second decoders based on the redundancy mode acquisition code, passes the challenge to the code generation device, obtains a unique random number specific to the IC chip from access to the first and second cell arrays based on a redundancy code stored in the special internal memory, and passes the unique random number to the code generation device. The code generation device generates the response from the challenge and the unique random number. The external input / output receives the input of the redundancy mode acquisition code and the challenge from the outside, receives the response from the code generation device, and outputs the response outside the IC chip. The redundancy mode acquisition code includes authentication setting options, a dedicated column designation mode, access options, and operation options. The dedicated column designation mode has a designated column number as an argument. The authentication setting options consist of an authentication mode or a non-authentication mode. When the authentication mode is selected, the designated column number designates an authentication dedicated column, and the authentication dedicated column is selected as the selected column. When the non-authentication mode is selected, one of the columns other than the designated column number is selected as the selected column. The access options select a combination of the first and second row decoders and instruct access to an address defined by the combination of the row decoders and the selected column. The operation options include writing, erasing, and reading to / from the address. When the authentication mode is selected, the peripheral control device reads the unique random number from the cell array based on the redundancy code by switching the combination of the access option and the operation option. The response function generates the response using the challenge and a unique random number unique to the IC chip as arguments. A digital information communication system characterized by the above.
20. A row line including the address of a defective bit distributed on the cell array is defined as a defective row line, and a row line not including the address of the defective bit is defined as a normal row line. The redundancy code is related to the distribution of the defective row lines. The digital information communication system according to claim 19, characterized by the above.
21. A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, At least one of the other plurality of electronic devices serves as an inspection entity, The first to Mth devices to be inspected are the first to Mth peripheral devices respectively, The inspection entity inputs a first challenge to the first to Mth peripheral devices, The first to Mth peripheral devices respectively return first to Mth responses to the inspection entity based on a response function in response to the first challenge, The first to Mth responses form a first response set having the first to Mth responses as elements, The inspection entity stores the first challenge and the first response set, and centrally manages the first to Mth peripheral devices, At least one of the first to Mth peripheral devices receives a second challenge sent from the inspection entity, generates an (M + 1)th response, and generates a pair of an (M + 1)th private key and an (M + 1)th public key from the (M + 1)th response. The first to Mth peripheral devices respectively include the first to Mth IC chips as components, The response function generates the first to Mth responses respectively using the first challenge and unique random numbers unique to the first to Mth IC chips as arguments, The response function generates the (M + 1)th response using the second challenge and a unique random number unique to the IC chip that received the second challenge as arguments. The first to Mth inspection devices form a distributed system by using the pair of the (M + 1)th private key and the (M + 1)th public key. A digital information communication system characterized by the above. **Claim 22** A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth inspection devices, Among the other plurality of electronic devices, at least two electronic devices serve as the first and second inspection entities and The first to Mth inspection devices are respectively the first to Mth peripheral devices, The inspection entity inputs a first challenge to the first to Mth peripheral devices, In response to the first challenge, the first to Mth peripheral devices respectively return first to Mth responses to the inspection entity based on a response function, The first to Mth responses form a first response set with the first to Mth responses as elements, The first inspection entity stores the first challenge and the first response set, and centrally manages the first to Mth peripheral devices, At least one of the first to Mth peripheral devices receives a second challenge sent from the second inspection entity, generates an (M + 1)th response, and generates a pair of an (M + 1)th private key and an (M + 1)th public key from the (M + 1)th response, The first to Mth peripheral devices respectively have the first to Mth IC chips as components, The response function generates the first to Mth responses respectively with the first challenge and unique random numbers unique to the first to Mth IC chips as arguments, The response function generates the (M + 1)th response with the second challenge and a unique random number unique to the IC chip that received the second challenge as arguments, The second inspection entity uses the pair of the (M + 1)th private key and the (M + 1)th public key, The first to Mth inspection devices form a distributed system. A digital information communication system characterized by the above.
Citation Information
Patent Citations
Authentication method and equipment based on PUF (Physically Unclonable Function)
CN105323069A
Method and system for arranging communication between a user device and a server
JP2016513899A
Physical-chip-identification (PCID) of chip authentication using redundant address of semiconductor chip
JP2017139757A
Electronic device network, electronic device and inspection process thereof
JP2018011298A
Method and System for Electronically Securing an Electronic Biometric Device Using Physically Unclonable Functions
US20110002461A1