Automatic authentication IC chip

The solution addresses the challenge of spoofed devices in IoT networks by using IC chips with unique random numbers for authentication, creating a physical firewall and enhancing IoT security.

JP7683858B2Active Publication Date: 2025-05-27渡辺 浩志
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021018502
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-02-08
Publication Date
2025-05-27
Estimated Expiration
2041-02-08

AI Technical Summary

Technical Problem

Existing cybersecurity measures, even those employing blockchain, are ineffective in automatically detecting and excluding spoofed electronic devices in IoT networks, leading to vulnerabilities in IoT security.

Method used

A network of electronic devices with M inspection devices and at least one inspection entity, where each inspection device has an IC chip with a unique random number, and the inspection entity authenticates devices by inputting a challenge and generating a response using the IC chip's unique random number.

Benefits of technology

The proposed solution effectively authenticates electronic devices and creates a physical firewall, enhancing the security of IoT networks by automatically detecting and excluding spoofed devices, thereby improving the reliability of data flow and preventing man-in-the-middle attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007683858000001
    Figure 0007683858000001
  • Figure 0007683858000002
    Figure 0007683858000002
  • Figure 0007683858000003
    Figure 0007683858000003
Patent Text Reader

Abstract

To provide a technology that automatically searches for a spoofing electronic device and automatically eliminates the spoofed electronic device even when using the latest cybersecurity tool that employs a block chain or the like.SOLUTION: A unique random number unique to an IC chip included in an electronic device and a response obtained from a challenge to the electronic device are used to authenticate the electronic device and create a physical firewall composed of the authenticated electronic devices. Further, the response is used to generate a pair of a private key and a public key, the public key or code information generated from the public key is used as the logical address of the electronic device, and the electronic signature generated using the private key is used for sending and receiving data between electronic devices inside physical firewall.SELECTED DRAWING: Figure 30
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technology of a memory chip with an automatic authentication function.

Background Art

[0002] As a result of the spread of the Internet in the 20th century, the scope of utilization of network technology has rapidly expanded. Entering the 21st century, the trend is expected to re-accelerate as the Internet of Things (IoT). On the other hand, IoT networks across national borders are at risk of being remotely operated by hackers abroad (especially illegal hackers when engaging in illegal activities).

[0003] An IoT network is a network of electronic devices. However, the difference from the ordinary Internet has so far remained ambiguous.

[0004] Speaking of a cyber network, it is a network between virtual accounts. Whether it is an IoT network or a cyber network, modern networks are information communication infrastructures for exchanging electronic data. A virtual account is a logical address on the network and is essentially different from the electronic device itself. On the Internet, a physical address exists as part of the protocol that links this electronic device and the logical address.

[0005] A protocol is a routine process for processing the communication of code information, and the routine process itself can also be encoded and treated as code information. That is, a protocol is software and does not originate from a specific electronic device. As long as it meets a predetermined standard, it operates in the same way when installed on any electronic device. That is, the physical address does not necessarily originate from a specific electronic device. It is only artificially (on the protocol) regarded as being linked to a certain electronic device. Hackers can modify this physical address at any time.

[0006] Nevertheless, it is certain that electronic devices on the Internet are physically connected to each other and electronic information is flowing between them. This connection is sometimes wired and sometimes wireless. The fact that the physical address is forged means that even if there is no problem with information communication between logical addresses, that is, even if there is no problem on the cyber network, the Internet protocol is deceived.

[0007] Figure 1 is a drawing explaining this situation. There is a network consisting of electronic devices A to C (a network of electronic devices, or an IoT network, or a physical network) above, and a network consisting of logical addresses A to C (a logical network or a cyber network) below. The dashed line connecting the upper and lower networks indicates that electronic devices A to C are respectively linked to logical addresses A to C. That is, this dashed line is the physical address, and the Internet protocol (hereinafter simply referred to as the protocol) controls the information communication between logical addresses including this physical address.

[0008] There is a reason why the physical address can be forged at any time. It is due to the very definition of software.

[0009] Tracing back to the concept of a Turing machine, it can be seen that all possible processes of an electronic device can be encoded. If it is required that a block of encoded processes (software) operates in the same way for electronic devices (hardware) designed according to the same standard, the development of hardware and software can be carried out independently. When hardware and software independently improve their performance, sometimes software is required to switch from old hardware to new hardware (reinstall software). At this time, the logical address for using the software to be reinstalled on the Internet will unlink from the old hardware (electronic device 1) once and newly link to the new hardware (electronic device 2). The reverse operation of this is the software update.

[0010] Thus, editing the physical address (the link between the electronic device and the logical address) is a necessary function for system maintenance. If an illegal hacker performs this editing, it will result in illegal tampering.

[0011] Thus, when considering the overall body that the Internet protocol controls information communication as the Internet, it can be seen that it includes the cyber network and the physical address in Figure 1 and does not include electronic devices A to C. That is, as shown in Figure 2, the Internet consists of a network (logical network or cyber network) composed of logical addresses A to C and a dashed line (physical address) that links each logical address to something. It is particularly important that the Internet protocol has no concern about what this something is. If it did, it might negate the very composition of the software.

[0012] On the contrary, what remains after removing all the elements from Figure 1 to Figure 2 is the IoT network (a network of electronic devices, or a physical network). See Figure 3. It has become clear that the IoT network (physical network, or a network of electronic devices) does not currently match what is called the Internet. However, as it is in Figure 3, there is no application, so the IoT network cannot do much work.

[0013] (Impersonation) If Figure 1 is regarded as the IoT network, an illegal hacker can easily break any security (cybersecurity) on the cyber network by using the method of impersonation. Figures 4 to 6 are diagrams explaining an example of impersonation.

[0014] First, as shown in Figure 4, an illegal hacker arbitrarily selects one legitimate logical address. For example, let's call it logical address B. Next, this logical address B is exchanged with the logical address (logical address B') assigned to the electronic device (a laptop as an example) that the hacker owns. This is, as shown in Figure 5, to tamper with the link between electronic device B and logical address B and link it to the device (for example, the laptop in the figure) owned by this illegal hacker. The result is as shown in Figure 6.

[0015] Assuming that the link between the electronic device and the logical address by the physical address (that is, the protocol of the Internet) is complete, the information communication between the corresponding logical addresses corresponding to the information communication between the electronic devices will always be consistent. Therefore, as long as the cyber security is strong enough, the network of the electronic devices will be safe. That this is a misunderstanding is self-evident by looking at Figure 6.

[0016] In Figure 6, there is a laptop owned by illegal hacker B that has tampered with the link (physical address) between electronic device B and logical address B and copied logical address B between electronic device A assigned logical address A and electronic device C assigned logical address C. In this way, the illegal hacker can act as a man-in-the-middle between electronic device A and electronic device C using the copied logical address B.

[0017] Thus, since impersonation is an attack that utilizes the very definition of software, any software-based defense is powerless.

[0018] (Man-in-the-Middle Attack) A malicious hacker can tamper with the information communication between electronic device A and electronic device C. Such an attack is called a man-in-the-middle attack. Even if the information communication between logical address A and logical address C is encrypted, a man-in-the-middle attack cannot be prevented. This is because the purpose of a man-in-the-middle attack is not necessarily limited to intercepting the information communication between electronic device A and electronic device C. Even if it cannot be snooped, it is possible to disrupt the cooperation between electronic device A and electronic device C by injecting false information between them.

[0019] One of the main application cases of IoT is that multiple electronic devices actively cooperate to jointly perform complex and large-scale operations. The main purpose of a man-in-the-middle attack is to disrupt such an IoT network (cooperation of electronic devices) that performs complex and large-scale operations through remote control. The more IoT spreads, the greater the potential damage caused by man-in-the-middle attacks.

[0020] For example, the electronic devices (IoT devices) that make up an IoT network are information terminals such as smartphones, tablets, laptops, and PCs, smart meters, sensors, surveillance cameras, or drones and vehicles equipped with multiple sensors, etc. As shown in Figure 7, these IoT devices spread to the bottom layer of the business model with artificial intelligence (AI) at the apex. The collection of various information collected by these IoT devices flooding the city is the big data in the middle layer. It is expected that the artificial intelligence (AI) in the upper layer will utilize it to solve various problems.

[0021] However, if there is a disguised IoT device (electronic device) hidden here, information modified by a man-in-the-middle attack may be mixed in, casting doubt on the reliability of big data. This may lead to malfunction of artificial intelligence (AI). In a smart factory, machines connected by high-speed communication such as 5G cooperate to perform tasks. If these machines, control boards, etc. are disguised, the smart factory may be stopped. A connected car, which is connected to the Internet and equipped with multiple electronic devices, may malfunction in its autonomous driving or, in the worst case, be hijacked if some of its components are disguised.

[0022] As described above, the damage caused by disguising electronic devices extends to property damage, factory shutdowns, human lives, etc., and it is obvious that this poses a threat of a different dimension from conventional cyberattacks.

[0023] Figure 8 briefly shows an example of a protocol in which electronic device A authenticates electronic device B.

[0024] First, electronic device A requests an authentication response from electronic device B. In the example of this figure, it is written clearly as "Mr. B, who are you?" for easy understanding, but actually, some digital code (challenge) is sent from electronic device A to electronic device B. In response, electronic device B replies "I am logical address B". Of course, actually, some electronic code (response) is sent from electronic device B to electronic device A.

[0025] If this exchange of challenge and response (authentication communication) is properly protected by some cyber security tool, it may seem that a seemingly secure authentication is being performed.

[0026] Figure 9 shows an example of the challenge and response when electronic device B is disguised.

[0027] When the same challenge as shown in Fig. 8, "Mr. B, who are you?", is sent from the electronic device A to the hacker's laptop that has spoofed the logical address B, the hacker's laptop replies, "I am the logical address B." That is, even if there is spoofing, the combination of the challenge and the response is not changed.

[0028] If this exchange of challenge and response (authentication communication) is securely protected by some cyber security tool, it may seem that a seemingly secure authentication is being performed. However, this would mean protecting the communication with the hacker's laptop as well. That is, even if one tries to detect and eliminate the spoofed communication device, cyber security will protect the hacker's laptop (the spoofed communication device).

[0029] As described above, it can be seen that no matter how powerful the cyber security tool is, anti-spoofing measures are difficult. The same is true even when using the latest cyber security tools such as blockchain.

[0030] (Real) Next, let's see how information is transferred between information devices. First, information is converted into digital data (or simply data) and transferred from one information device to another. Therefore, it is necessary to know how data is handled within a single information device.

[0031] Almost all information devices currently used on the network can be considered Neumann-type computers (or Neumann computers, or simply computers). Fig. 10 outlines the flow of data entering and leaving a computer.

[0032] The computer receives input from the input / output device (I / O) and passes it to the arithmetic unit. Each time the arithmetic unit performs an operation, it accesses the memory. Traditionally, this memory has a multi-layer hierarchy. From the top, there are registers, cache memory (such as SRAM), main memory (such as DRAM), and further down, there is storage memory (such as flash memory) that does not lose data even when the computer is powered off. The higher the level, the faster the operating speed, and the lower the level, the higher the bit capacity.

[0033] As an example, the arithmetic unit includes a processor core, registers, and cache. Combine this with a stand-alone DRAM as the main memory, and add flash memory or the like as needed to form a rough configuration of an information device (or computer). Information devices without DRAM have a severely limited amount of data that can be handled.

[0034] To enable data exchange between information devices, consider an example where the first information device outputs data through the I / O, and this data is input to the second information device through the I / O. As an example, consider the case where data is transferred from the first information device (upper section) to the second information device (middle section) as shown in FIG. 11.

[0035] First, the data read from the memory chip in the upper section is passed to the arithmetic unit in the upper section. After appropriate processing there, it is output from the I / O in the upper section. The output data is exposed on the network and, when it finds the I / O in the middle section, which is the transfer destination, it is taken in (input) by the information device in the middle section. This data is further processed by the arithmetic unit in the middle section and then written (stored) to the memory chip in the middle section.

[0036] Subsequently, the data read from the memory chip in the middle layer is passed to the arithmetic unit in the middle layer, where appropriate processing is performed and then output from the I / O in the middle layer. The output data is exposed on the network and, when the destination I / O in the lower layer is found, it is taken in (input) by the information device in the lower layer. This data is further written (stored) to the memory chip in the lower layer after appropriate processing is performed by the arithmetic unit in the lower layer.

[0037] Thus, it can be seen that data is transferred between the upper, middle, and lower layers and the memory chips. That is, monitoring the flow of information between information devices is equivalent to monitoring the transfer of data between memory chips. At this time, it is necessary to note that no logical addresses (such as IP addresses) assigned to the cyber space appear at all.

[0038] Let's consider once again the information exchange between the electronic devices A, B, and C described in Figure 1.

[0039] The electronic devices A, B, and C in Figure 1 each incorporate the information device (computer) units in the upper, middle, and lower layers of Figure 11. Alternatively, the electronic devices A, B, and C in Figure 1 are the information devices (computers) in the upper, middle, and lower layers of Figure 11, respectively. That is, all the information exchanges between the electronic devices in Figures 1 - 6 and Figures 8, 9 described so far are equivalent to the transfer of data between the memory chips in the upper, middle, and lower layers of Figure 11.

[0040] However, there is no information regarding logical addresses in Figure 11. That is, there has been no clearly defined relationship between information exchange in the cyber space and real - data communication in the IoT network until now.

[0041] (Cyber) Next, let's roughly look at how information is transferred in the cyber space (logical network). Figure 12 is an example of an information - transfer method also adopted in blockchain and the like.

[0042] Set the end point of the current information (hash value (N-1)) as the logical account (N). The logical account (N-1) is the one that last transferred the information (hash value (N-1)) to this logical account (N). In the logical account (N-1), this hash value (N-1) is generated from the hash value (N-2). The logical account (N-2) is the one that last transferred the information (hash value (N-2)) to this logical account (N-1). In the logical account (N-2), the hash value (N-2) is generated from the hash value (N-3).

[0043] Each has the public keys (N), (N-1), and (N-2) corresponding to the logical addresses. The public keys (N), (N-1), and (N-2) are respectively and one-to-one associated with the private keys (N), (N-1), and (N-2) by public key cryptography (PKI).

[0044] The logical account (N-2) obtains the public key (N-1), which is the logical address of the logical account (N-1) publicly available on the network, and uses the private key (N-2) to encrypt the combination of the public key (N-1) and the hash value (N-3) to generate an electronic signature (N-2). Furthermore, the logical account (N-2) collectively hashes the public key (N-2), the hash value (N-3), and the electronic signature (N-3) to generate the hash value (N-2). Then the logical account (N-2) transfers the hash value (N-2) with the electronic signature (N-2) attached to the logical account (N-1).

[0045] The logical account (N-1) obtains the public key (N), which is the logical address of the logical account (N) publicly available on the network, and uses the private key (N-1) to encrypt the combination of the public key (N) and the hash value (N-2) to generate an electronic signature (N-1). Furthermore, the logical account (N-1) collectively hashes the public key (N-1), the hash value (N-2), and the electronic signature (N-2) to generate the hash value (N-1). Then the logical account (N-1) transfers the hash value (N-1) with the electronic signature (N-1) attached to the logical account (N).

[0046] However, there is no information about the memory chip of the information device in FIG. 12. That is, there has been no well-defined relationship between information exchange in the cyber space and real data communication in the IoT network until now. Disclosure of the Invention Problems to be Solved by the Invention

[0047] The present invention has been made in view of the above circumstances, even when using the latest cyber security tools employing blockchain or the like, a technology for automatically searching for spoofed electronic devices and automatically excluding the spoofed electronic devices, is provided. Means for Solving the Problems

[0048] To solve the above problems, the present invention employs the following means.

[0049] The solution proposed by the present invention is a network of electronic devices composed of a plurality of electronic devices, among the plurality of electronic devices, M electronic devices are the first to Mth inspection devices, among the other plurality of electronic devices, at least one electronic device serves as the first inspection entity, the first to Mth inspection devices are the first to Mth peripheral devices respectively, the first to Mth peripheral devices each have a response function and each have an IC chip as a component, the IC chips each have a unique random number, the first inspection entity selects one peripheral device as the selected peripheral device from among the first to Mth peripheral devices, and inputs a challenge to the selected peripheral device. The response function generates a response from the challenge and the unique random number of the IC chip of the selected peripheral device, and the selected peripheral device returns the response to the first inspection subject. The IC chip includes a cell array composed of a plurality of authentication elements respectively. The plurality of authentication elements are arranged on the intersections of a row line group and a column line group stretched in the row direction and the column direction of the cell array. The plurality of authentication elements each have first and second terminals. The first terminals are respectively connected to input lines. The second terminals are respectively connected to output lines. The output lines belong to the column line group. The input lines belong to the row line group or the column line group. The IC chip has a cell array control device for operating the cell array. The cell array control device selects a selected authentication element from among the plurality of authentication elements according to an instruction from outside the IC chip, selects an input line connected to the selected authentication element as a selected input line, selects an output line connected to the selected authentication element as a selected output line, applies a test voltage to the selected input line, reads an output voltage from the potential of the selected output line, It is characterized by the above.

[0050] The solution proposed by the present invention further has the following means. Define the address of the selected authentication element on the cell array from the combination of the number assigned to the selected input line and the number assigned to the selected output line. The cell array control device selects a plurality of selected authentication elements from among the plurality of authentication elements, sets an upper limit voltage and a lower limit voltage according to an instruction from outside the IC chip, acquires a frequency distribution of the output voltage from the plurality of selected authentication elements, generates the unique random number from an arrangement of addresses of the selected authentication elements for which the output voltage is between the upper limit voltage and the lower limit voltage, or sets first and second read temperatures according to an instruction from outside the IC chip, uses, as a first output voltage, an output read from the selected output line while applying the test voltage at the first read temperature, uses, as a second output voltage, an output read from the selected output line while applying the test voltage at the second read temperature, generates the unique random number from an arrangement of addresses of the selected authentication elements among the plurality of selected authentication elements for which the first and second output voltages are significantly different from each other by a predetermined error. characterized by this.

[0051] The solution means proposed by the present invention further has the following means. The authentication element has at least one inverter circuit, the inverter circuit has an input terminal and an output terminal, and when the input to the input terminal is a high voltage, the output is about Vss, and when the input is a low voltage, the output is about Vdd, and the Vdd is higher than the Vss, when the authentication element is the selected authentication element, the input terminal is connected to the selected input line, and the output terminal is connected to the selected output line, The test voltage is a voltage input to the input terminal such that the output becomes approximately in the middle between the Vdd and the Vss. Or The authentication element has first and second inverter circuits. The first and second inverter circuits each have first and second input terminals and first and second output terminals. The first input terminal is connected to the second output terminal and is connected to the output line via a second selection gate. The second input terminal is connected to the first output terminal and is connected to the input line via a first selection gate. The outputs of the first and second inverter circuits are each approximately at Vss when the inputs to the first and second input terminals are at high voltage, and are each approximately at Vdd when the inputs are at low voltage. The Vdd is higher than the Vss. The test voltage is a voltage applied to the input line such that the potential of the output line becomes approximately in the middle between the Vdd and the Vss. It is characterized by this.

[0052] Hereinafter, the best mode for carrying out the invention will be specifically described.

Best Mode for Carrying Out the Invention

[0053] As described above, in the present invention, Using a response obtained from a unique random number unique to an IC chip included in an electronic device and a challenge to the electronic device, authenticate the electronic device and create a physical firewall consisting of the authenticated electronic devices. Further, generate a pair of a private key and a public key using the response, use the public key, or code information generated from the public key, as the logical address of the electronic device, and use an electronic signature generated using the private key for data transmission and reception between electronic devices within the physical firewall. A communication system for digital information is proposed.

[0054] This will be specifically described below with reference to the drawings.

[0055] (Cyber and Real Fusion) FIG. 13 conceptually shows a method of associating the electronic devices A, B, and C of FIG. 1 with the logical addresses A, B, and C, respectively.

[0056] In PKI, a private key and a public key are associated one-to-one. The public key is equivalent to, or corresponds to, a logical address in the cyber space. The logical address is equivalent to, or corresponds to, an account of software (application, or simply app) operating in the cyber space. However, it is practically difficult to generate a private key from a public key.

[0057] The electronic device B is a device to be inspected, and is selected by the electronic device A which is the inspection subject, and is inspected as a selected electronic device (or a selected peripheral device). If the inspection by the inspection subject is passed, the device to be inspected is authenticated. The electronic device B incorporates one or more semiconductor chips (IC chips, or simply chips). As an example, assume that it incorporates the memory chips of FIGS. 10 and 11. The electronic device A sends a challenge (C) to the electronic device B. As an example, "Mr. B, who are you?" in FIGS. 8 and 9 is fine.

[0058] The chip built into the electronic device B has a random number unique to that chip (unique random number). A response (R) is generated from the challenge (C) and this unique random number. As long as the unique random number is unique to the chip, this response (R) can be regarded as a response unique to the chip and the challenge (C). As an example, it may be regarded as "I am chip B" in FIGS. 8 and 9.

[0059] Here, the relationship between the response, the challenge (C) input to the chip to be inspected, and the unique random number unique to the chip to be inspected can be described using the function Res.

[0060] Response (R) = Res(C, unique random number (chip))

[0061] If a hacker accesses the device under inspection (electronic device B as an example), it is possible to read and copy this unique random number. However, it is difficult for the hacker to predict the response (R) unless it is known what challenge (C) the inspection entity (electronic device A) inputs. The inspection entity (electronic device A) saves the pair of the challenge (C) and the response (R) and can use it for authenticating the device under inspection at any time. The important thing here is that, in fact, the unique random number is not used for the authentication test.

[0062] As long as the unique random number is unique to the chip, that is, when the unique random number can be regarded as having a one-to-one relationship with the chip, the relationship in paragraph 0060 can be rewritten as follows.

[0063] Response (R) = Res(C, chip)

[0064] As long as this relationship is satisfied, the relationship between the unique random number and the chip can be anything. As an example, the unique random number can be generated using the randomness generated at the chip manufacturing stage. However, data that can be rewritten from the outside by some method cannot be regarded as unique to the chip.

[0065] For example, consider N×M electronic elements arranged in N rows and M columns on a chip as shown in FIG. 14. Here, N is a natural number of 1 or more, and M is a natural number of 1 or more. In the present application, such an electronic element will be referred to as an authentication element. The authentication elements have variations in characteristics due to manufacturing variations during the chip manufacturing stage. In mass production, it is required to control such variations as much as possible, but it is impossible to completely eliminate them. By quantifying the variations for each such authentication element and distributing them on the cell array of FIG. 14, it is possible to convert them into physical random numbers.

[0066] For example, measure a certain electrical property of the authentication element. If the value is higher than a certain level, it is set to 1, and conversely, if it is lower, it is set to 0. That is, the authentication elements with values of 1 and 0 will be distributed on the cell array of FIG. 14. If 0 is set to white and 1 is set to black, for example, a pattern of white and black can be formed as shown in FIG. 15. If both M and N are sufficiently larger than 1, this pattern will be a checkered two-dimensional pattern. If either M or N is 1, this pattern will be a one-dimensional pattern. In any case, if the generation of 0 and 1 for each authentication element is due to manufacturing variations, this pattern of white and black will be physically random and different for each chip. The probability that two chips accidentally have the same pattern will decrease as M or N increases. Since M and N can be controlled by the design of the cell array, it is possible to control the probability that two chips accidentally have the same pattern to be below the allowable range by the design of the cell array. In this way, what represents a unique random number by an array of a plurality of values (as an example, 0 and 1) is called a unique random number code (or simply a random number code).

[0067] The authentication element is, for example, a resistor, a capacitor, a PN junction, a Schottky junction, a transistor, an inverter circuit, a memory element, etc. Memory elements that can be used for the authentication element include a DRAM (Dynamic Random Access Memory) element composed of a combination of a transistor and a capacitor, an SRAM (Static Random Access Memory) element composed of two inverters and two transistors, a non-volatile memory element using a variable resistor, a resistive change memory (such as ReRAM) that changes resistance by an applied voltage, a phase change memory (PCRAM) that changes resistance by utilizing the phase change between crystal and amorphous generated by heating, etc., a non-volatile memory element using magnetoresistance, an MRAM cell that changes magnetoresistance using the giant magnetoresistance effect (GMR), an STT-MRAM cell that changes magnetoresistance using the spin torque transfer effect (STT), a non-volatile memory element with a charge storage layer, a charge trap type non-volatile memory element in which the charge storage layer is a charge trap, an FG type memory element in which the charge storage layer is a floating gate (FG), etc. FIG. 16 is a simple equivalent circuit showing a part of examples of these authentication elements. (1) is a DRAM cell, (2) is a resistor element, (3) is a capacitor, (4) is a variable resistor (including PRAM, ReRAM, etc.) element, (5) is various junction (including Schottky junction, disconnection, etc.) elements, (6) is a PN junction, (7) is magnetoresistance (including GMR, MRAM, STT-MRAM, etc.), (8) is a transistor, (9) is a non-volatile memory (including FG type, charge trapping layer type, etc.) element.

[0068] Alternatively, as another example, after chip manufacturing, it is also possible to convert a separately generated unique random number into a code of 0 and 1 (random number code) and write it into the cell array of FIG. 14. At this time, it is desirable that the authentication element constituting the cell array of FIG. 14 is a memory element of a one-time programmable memory (OTP). Since OTP utilizes the intentional destruction of the memory element or the intentional short circuit of the wiring element (intentional destruction of the resistor element), as a result, any of the above authentication elements can be utilized as the memory element of OTP.

[0069] Although multiple methods can be applied as random number generators, the one using quantum bits has the highest degree of unpredictability. In a quantum bit, both the information of 0 and 1 exists simultaneously. When read out according to the principle of the observation problem in quantum mechanics, it is probabilistically determined to be either 0 or 1, and it is theoretically impossible to predict the readout result in advance. A random number code is formed by repeatedly reading out 0 and 1 from quantum bits and arranging the results in a row. With current technology, it is difficult to mix a large number of quantum bits on a semiconductor chip. Of course, as long as the gist of this application is not deviated from, a random number generation method based on other physical principles can also be used.

[0070] Regardless of the method of generating a random number code outside the chip, it is necessary to avoid storing the same code as the random number code stored in the cell array of a certain chip in the cell array of another chip. That is, when generating a random number code outside the chip, an operation method is required to control the risk of human error within an acceptable range.

[0071] To avoid accidentally leaving the same random number code in the cell arrays of two chips, the number of bits of the random number code to be generated must be large enough. Let this number of bits be Q and the number of chips including the cell array where the random number code is written be U. It is desirable that 2 to the power of Q divided by U is a sufficiently large number. As an example, to achieve a specification that can withstand one trillion nodes, if U is 10 trillion, when Q is 50, the probability that two of the random number codes written in the chips distributed worldwide accidentally match is less than one in a million. That is, it is desirable that the information amount of the random number code is 50 bits or more.

[0072] That is, as an example, read out 50 times repeatedly from one quantum bit per chip, or read out 25 times from two quantum bits, or read out from M quantum bits at least 50 / M times, and write the results in some area in the chip with 50 bits or more.

[0073] To prevent the forgery of the randomly generated code once it has been properly written, it is desirable to store the separately generated random code in an isolated area. Generally, the specifications of the isolated area vary. As an example, it is desirable to use, as the isolated area, a region on the chip that is physically, circuit-wise, or software-wise restricted in access. This isolated area is a non-volatile memory area. Alternatively, this isolated area is an OTP (One-Time Programmable). Physical or circuit access restrictions are possible by the physical layout and circuit pattern of the modules inside the IC chip. Software access restrictions are possible by cryptographic techniques.

[0074] OTP is a promising method for preventing forgery. As an example of OTP, a typical one is a mask ROM. Usually, in a ROM, a transistor is a bit cell. First, an address in the cell array is selected according to the bit representation of the random code separately generated by an external random number generator. Next, a method can be considered in which the PN junction of the transistor of the bit cell located at the selected address is cut off by a laser or the like, or a large current is passed through the bit line for a sufficiently long time to surely destroy the PN junction. In any method, the bit cell having a destroyed PN junction loses its rectifying action and current flows even when a reverse voltage is applied. For example, if the destroyed bit cell is made to correspond to data 1 and the non-destroyed bit cell is made to correspond to data 0, a random code in a checkerboard pattern as shown in FIG. 15 is obtained. In any case, when writing the separately generated random code, the PN junction of the transistor at the selected address must be surely destroyed.

[0075] Alternatively, it is possible to utilize all bit cells including PN junctions and Schottky junctions as OTP. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, the PN junction of the transistor of the bit cell located at the selected address is cut with a laser or the like. Alternatively, a method of surely destroying the PN junction by flowing a large current through the bit line for a sufficiently long time can be considered. In any method, a bit cell having a once-destroyed PN junction loses its rectifying action and current starts to flow even when a reverse voltage is applied. For example, if the destroyed bit cell is made to correspond to data 1 and the non-destroyed bit cell is made to correspond to data 0, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the PN junction of the selected address must be surely destroyed.

[0076] Alternatively, it is possible to utilize all bit cells including capacitors as OTP. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, a method of hard-destroying the insulating film of the capacitor of the bit cell located at the selected address by flowing a large current through the capacitor for a sufficiently long time can be considered. The capacitor of the bit cell having a destroyed insulating film loses its insulating property and current starts to flow even when a DC voltage is applied. For example, if the destroyed bit cell is made to correspond to data 1 and the non-destroyed bit cell is made to correspond to data 0, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the insulating film of the capacitor of the selected address must be surely hard-destroyed.

[0077] Alternatively, it is possible to utilize all bit cells including resistors or resistor wirings as OTPs. This is generally a fuse memory. First, an address in the cell array is selected according to the bit representation of a random number code separately generated by an external random number generator. Next, the resistor or resistor wiring of the bit cell located at the selected address is cut by a laser. Alternatively, a method of causing disconnection (short circuit) by flowing a large current for a sufficiently long time is conceivable. In the selected bit cell, no current flows even when an appropriate voltage is applied due to the disconnection. For example, if the disconnected bit cell is made to correspond to data 0 and the non-disconnected bit cell is made to correspond to data 1, a random number code in a checkered pattern as shown in FIG. 15 is obtained. In any case, when writing a separately generated random number code, the resistor or resistor line at the selected address must surely be disconnected.

[0078] Thus, there are various examples of OTPs. It is possible to regard a random number code separately generated outside the chip as a unique random number sharing the concept of the present application regardless of which OTP is used. However, as a condition of the OTP, it is desirable to make the unique random number once normally written electrically unrewritable. By doing so, it is possible to prevent forgery after the random number code is normally programmed.

[0079] The random number code serving as the unique random number of the present application may be written for the entire cell array constituting the chip of the present application or for a part of the cell array. Alternatively, a region (such as a peripheral region) different from the cell array on the chip may be written as an isolation region.

[0080] Nevertheless, it is also possible to use a pseudo-random number generator as the random number generator. To put it simply, a pseudo-random number generator is random number generation software. As long as it is software, since a random number code is generated according to some algorithm, if a combination of responses (R) to a plurality of challenges (C) is obtained, it is possible to decrypt and predict the response to an unknown challenge.

[0081] However, if the possibility of decryption can be kept extremely low within an acceptable range, it can be used as the unique random number of the present application. At this time, the equation in step 0063 is pseudo-satisfied. Even if it is pseudo, if the possibility of decryption can be controlled within an acceptable range, it can be used as the unique random number of the present application.

[0082] From the above, the method for generating a unique random number unique to a chip is mainly divided into two methods: a method of generating it together with chip manufacturing and a method of generating it separately from chip manufacturing. The former uses the manufactured chip itself as a random number code (unique random number) for authentication, and the latter writes a separately generated random number code into a memory cell array (isolated area) included in the chip. Another example of the latter is a method of randomly destroying an authentication element array. After determining the area (such as a part of the isolated area) where the unique random number is to be written, a critical destruction pulse may be applied to the authentication element existing at the address within that area to see if destruction occurs. The authentication element to which the destruction pulse is applied is probabilistically destroyed, and its address is physically randomly distributed, so it becomes a unique random number. Whichever generation method is used, as long as an output (response) is obtained by combining the unique random number of the chip to be inspected and the input (challenge) to the chip to be inspected, the concept of the present application is not deviated from. Therefore, in all embodiments of the present application, either generation method can be used equally.

[0083] Figure 17 shows what happens when the same challenge (C) is input to two different devices under test (1 and 2).

[0084] The device under test 1 incorporates chip 1 and outputs a response R1 from the challenge (C) and the unique random number 1 of chip 1. The device under test 2 incorporates chip 2 and outputs a response R2 from the same challenge (C) and the unique random number 2 of chip 2. Here, the two responses R1 and R2 are both different. This means that if the device under test 1 is replaced with another device under test 2, the response changes from R1. That is, if someone tries to impersonate an information device, it will be noticed by the inspection entity that the response changes.

[0085] Figure 18 shows an example of applying this concept to the authentication of an IoT network (a network of electronic devices).

[0086] The inspection entity (electronic device A) challenges the device under inspection (electronic device B) with "Mr. B, who are you?" Electronic device B returns a response "I am chip B" from this challenge and a unique random number in the built-in chip.

[0087] Figure 19 shows what happens when electronic device B is impersonating a hacker's laptop (which has logical address B).

[0088] The inspection entity (electronic device A) challenges the device under inspection (electronic device B) with "Mr. B, who are you?" The hacker's laptop impersonating logical address B returns a response "I am the hacker's chip" from this challenge and a unique random number in the built-in chip.

[0089] Thus, as shown in Figure 17, by using the nature of the authentication of the device under inspection according to the present application, that is, different responses are given even if the challenges are the same but the chips are different, it is possible to search for whether there is an electronic device impersonating within the IoT network.

[0090] It is possible to search for whether there is an impersonation of an electronic device. If an impersonated electronic device (illegal electronic device) is found, it can be excluded from the IoT network. For example, it can be easily realized by using a smart contract of blockchain. Although it is self-evident and will not be particularly described, the search and exclusion of impersonation can be performed automatically.

[0091] (When using an ElGamal type key generation device) Figure 20 shows an example of a method for generating a secret key (n) and a public key (n) from a response R(n) output from the nth device under inspection, electronic device B(n).

[0092] The ElGamal algorithm is one of the important algorithms in public-key cryptography. One of its features is to generate a public key paired with a private key. In this specification, regardless of the details of the algorithm, a key generation device that generates a public key paired with a private key is generically called an ElGamal-type key generation device.

[0093] First, a challenge (C) is input from the hardware (electronic device A) which is the inspection subject to the electronic device B(n). The electronic device B(n) outputs a response R(n) from the built-in chip (n)'s unique random number (n) and this challenge (C).

[0094] The response R(n) is used as the private key (n) after performing code conversion for the purpose of adjusting the format or the like. By inputting this private key (n) into the ElGamal-type key generation device, a public key (n) paired with the private key can be obtained. This public key (n) is the logical address corresponding to the logical account (n).

[0095] It is desirable to erase the private key (n) after it has been used. It can be generated at any time by the method in FIG. 20 when necessary. Alternatively, it is desirable to securely confine it within the electronic device B(n). Confining it securely within the electronic device B(n) means that, from the outside of the electronic device B(n), it is the same as if the private key (n) has disappeared.

[0096] It is desirable to install the key generation device as software in the electronic device B(n). Alternatively, it is desirable to install the key generation device as an embedded module in the chip (n) built into the electronic device B(n). Alternatively, it is desirable to install the key generation device as an embedded module in another chip built into the electronic device B(n). Alternatively, the key generation device may exist in another electronic device that is securely connected to the electronic device B(n).

[0097] FIGS. 21 and 22 show examples of methods of additionally using a second input in the embodiment of FIG. 20.

[0098] In FIG. 21, the second input is input during the process of generating the secret key (n) by code conversion from the response R(n). That is, this code conversion includes the second input. In FIG. 22, the second input is input during the process of generating the public key (n) from the secret key (n). That is, this key generation device includes the second input.

[0099] Basically, the use of the second input is to increase the degree of freedom and strength of the authentication of the device under test related to this application.

[0100] For example, in order to strengthen the management of the IoT network, additional security servers that support the inspection entity are added. This security server can independently input (distribute) the second input to the device under test B(n) and change the response R(n) to the challenge (C). This helps prevent hackers from predicting combinations of unknown challenges and responses from multiple known pairs of challenges and responses. However, it is desirable that this security server be authenticated by the inspection entity in advance before distributing the second input to the device under test. Also, the security server can inspect the authentication of the device under test in the same way as the inspection entity. In this sense, the security server is also an inspection entity. That is, the inspection entity is not necessarily one. It is desirable that the first inspection entity manages the pair (CR) of C and R, further searches for the device under test and eliminates illegal electronic devices, and the second inspection entity distributes the second input to the device under test as a security server.

[0101] (When using an RSA type key generation device) FIG. 23 - 3 2 5 shows an example when using an RSA type key generation device. Each of FIGS. 20 - 3 2 is the same except that the Elgamal type key generation device in FIG. 2 is replaced with an RSA type key generation device. is the same.

[0102] RSA is composed of the initials of Rivest, Shamir, and Adleman, the inventors. The RSA algorithm is one of the most important algorithms in public-key cryptography. One of its features is to generate a pair of a private key and a public key from an external input. In this specification, regardless of the details of the algorithm, a key generation device that generates a pair of a private key and a public key from an external input is generically called an RSA type.

[0103] Figure 23 shows an example of a method for generating a private key (n) and a public key (n) from a response R(n) output from an electronic device B(n) that is the nth subject to be inspected.

[0104] First, a challenge (C) is input from a hardware (electronic device A) that is the inspection subject to the electronic device B(n). The electronic device B(n) outputs a response R(n) from the unique random number (n) of the built-in chip (n) and this challenge (C).

[0105] The response R(n) is input into an RSA type key generation device directly or after performing code conversion such as adjusting the format, and a private key (n) and a public key (n) that form a pair with each other are generated. This public key (n) is a logical address corresponding to the logical account (n).

[0106] It is desirable to erase this private key (n) after it has been used. Or it can be generated at any time by the method of Figure 23 when necessary. Or it is desirable to safely confine it within the electronic device B(n). To safely confine it within the electronic device B(n) means that, from the outside of the electronic device B(n), it is the same as if the private key (n) has disappeared.

[0107] It is desirable to install the key generation device as software in the electronic device B(n). Alternatively, it is desirable to install the key generation device on the chip (n) built into the electronic device B(n) as an embedded module. Alternatively, it is desirable to install the key generation device on another chip built into the electronic device B(n) as an embedded module. Alternatively, the key generation device may exist in another electronic device that is securely connected to the electronic device B(n).

[0108] Figures 24 and 25 show examples of methods for additionally using a second input in the embodiment of Figure 23.

[0109] In Figure 24, the second input is input during the process of inputting the response R(n) to the key generation device. That is, this second input and the response R(n) will be synthesized in some way. In Figure 25, the second input is input during the process in which the key generation device generates the private key (n) and the public key (n). That is, the key generation device includes the second input.

[0110] Basically, the use of the second input is to increase the degree of freedom and strength of the authentication of the device under test related to this application.

[0111] For example, in order to strengthen the management of the IoT network, additional security servers that support the inspection entity are added. This security server can input (distribute) a second input to the device under test B(n) independently of the inspection entity and change the response R(n) to the challenge (C). This helps prevent hackers from predicting combinations of unknown challenges and responses from multiple known pairs of challenges and responses. However, it is desirable that this security server be authenticated in advance by the inspection entity before distributing the second input to the device under test.

[0112] As described above, embodiments using the ElGamal-type and RSA-type key generation devices defined in this specification have been explained. Next, a key generation device that does not belong to either of them, that is, a key generation device that generates a private key from a public key, will be briefly mentioned. This corresponds to using the input of the ElGamal type as the public key. The public key is publicly available on the network and can be freely obtained by an attacker. If this is input into a key generation device of the same algorithm, the private key can be obtained. In this way, the private key cannot be kept secret.

[0113] When using the ElGamal-type key generation device, according to the usage method of the present application, as shown in FIG. 20-3 2 As shown in 2, the private key is generated from the response (R) output from the electronic device. It is possible to input the response (R) directly into the ElGamal-type key generation device as the private key without conversion. It is also possible to perform appropriate code conversion on the response (R) to adjust the data format and then input it into the ElGamal-type key generation device as the private key. Alternatively, it is possible to perform code conversion including some intention on the response (R) and then input it into the ElGamal-type key generation device as the private key. In any case, the ElGamal-type key generation device generates a pair of private and public keys from the response (R). On the other hand, in the RSA-type key generation device, as shown in FIG. 23-3 2 As shown in 5, the response (R) is input to generate a pair of private and public keys. Thus, according to the usage method of the present application, regardless of whether an ElGamal-type or RSA-type key generation device is adopted, "a pair of private and public keys unique to the electronic device is generated from the response (R) obtained by inputting the challenge (C) into the electronic device". Furthermore, if the challenge (C) is changed, it is possible to automatically update the pair of private and public keys. Note that the key generation device only needs to be in a state where the electronic device can use it at any time. In particular, it does not have to be installed in a specific part of the electronic device. That is, the key generation device may be installed inside the IC chip constituting the electronic device, or may be installed outside the IC chip. Alternatively, the key generation device may be installed in the electronic device as software.

[0114] (Blockchain of things) Figures 26 and 27 conceptually show how to construct a blockchain of things using ElGamal and RSA type key generation devices, respectively.

[0115] Physical node (N-2), physical node (N-1), and physical node (N) are logical nodes, Logical Account (N-2), Logical Account (N-1), and Logical Account (N) and In particular, the electronic device B shown in Figure 20-3 2 In Figure 5, this refers to electronic device B(n), where n = N - 2, N-1, and N. Here, the private key (n) and the public key (n) are paired by the public key cryptography (PKI) in Figure 13, so the logical account (n) and the physical node (n) are paired.

[0116] According to the concept of FIG. 13, the responses output by electronic device B(N-2), electronic device B(N-1), and electronic device B(N) to challenge (C) are R(N-2), R(N-1), and R(N), respectively.

[0117] If the key generating device and responses R(N-2), R(N-1), and R(N) and the key generating device are removed from each electronic device in Figures 26 and 27, it completely coincides with Figure 12. This shows that the method of pairing a physical node and a logical node according to the concept of Figure 13 is completely compatible with existing blockchains.

[0118] In the examples of Figures 26 and 27, the memory of physical node (N) stores the latest data. That is the chip (i.e., the memory chip) in Figure 13. In Figures 20-35, that is chip (N).

[0119] As shown in Figure 11, in an IoT network, data is transferred from memory chip to memory chip.

[0120] By the way, the chip that transfers data to the chip (chip (N)) including the memory storing this latest data is one is not necessarily so. In the example of FIG. 28, data is transferred from three chips to the chip (N) that holds the latest data. It is considered that data is also transferred to each of these three chips from a plurality of chips. Nevertheless, the history of this transfer ends at the last chip (N) that holds the latest data.

[0121] In this way, as shown in FIG. 28, the Merkle tree form of the chips is completed. The last chip (N) becomes the root of the Merkle of the Merkle tree of the present application.

[0122] Generally, the root of the Merkle is a candidate for a block in the blockchain. When the root of the Merkle satisfies a condition called Proof of Consensus (PoC), this root of the Merkle is recorded in the distributed ledger, certified as a new block, and linked to the end of the blockchain. The blockchain is thus extended.

[0123] There are multiple methods for PoC. As an example, there is a method of adding a nonce and hashing. If this hash value (block hash) satisfies a predetermined condition, this root of the Merkle is newly blocked and added to the blockchain as a new block.

[0124] As an example, the predetermined condition that the block hash should satisfy is that the first 16 digits of the block hash generated by adding a nonce are all zero. Searching for the root of the Merkle that is still unblocked and exposed on the network and finding a nonce that satisfies the predetermined condition is called mining. There is also a mechanism to reward miners who succeed in mining. An example of this is Bitcoin.

[0125] FIG. 29 conceptually shows the process of block generation by this mining.

[0126] Assume that the Merkle root (L-3) has already been blocked and the block hash (L-2) has been generated. That is, the Merkle root (L-3) is the latest block connected to the end of the blockchain at this point ( L -3). Further, from the left of the drawing, there are the Merkle root (L-2), the Merkle root (L-1), and the Merkle root (L). However, as described above, in this application, all these Merkle roots are chips (or IC chips including the cell array in FIG. 14).

[0127] First, find a nonce (L-2) that satisfies the conditions of a predetermined PoC as the nonce value, and hash it together with the block hash (L-3) and the Merkle root (L-2) to generate the block hash (L-2). In this way, block (L-2) is recognized as the latest block and connected to the end of the blockchain.

[0128] Subsequently, find a nonce (L-1) that satisfies the conditions of a predetermined PoC as the nonce value, and hash it together with the block hash (L-2) and the Merkle root (L-1) to generate the block hash (L-1). In this way, block (L-1) is generated as the latest block and connected to the end of the blockchain.

[0129] Subsequently, find a nonce (L) that satisfies the conditions of a predetermined PoC as the nonce value, and hash it together with the block hash (L-1) and the Merkle root (L) to generate the block hash (L). In this way, block (L) is generated as the latest block and connected to the end of the blockchain.

[0130] When generating the block hash (n), the Merkle root (n) that is hashed together with the nonce (n) and the block hash (n-1) is, in the network of the electronic device of the present application (or the IoT network), the Merkle root (n) is substantially the data (n) unique to the chip (n). However, n is any integer including the above L-3, L-2, L-1, L.

[0131] The chip (n) is an IC chip including the cell array of FIG. 14, or a memory chip. Since the said unique data (n) is also unique to the Merkle root (n), it is considered to represent the Merkle root (n). Therefore, the Merkle root (n) of the present application is, for example, the unique random number (n) of the chip (n).

[0132] (Physical firewall) The number of devices to be inspected is not necessarily one. If the inspection entity is regarded as a test server, as shown in FIG. 30, the concept of FIG. 13 can be extended to a network consisting of multiple devices to be inspected and a test server. FIG. 31 shows the state where one test server conducts authentication tests on N devices to be inspected. As shown in the figure, generally, the devices to be inspected are not necessarily uniform electronic devices. It refers to all devices equipped with IC chips connected to the IoT network. For example, personal computers, routers, vehicles, smartphones, servers, tag readers, printers ters, machine tools, tablets, and so on. When all the authentications are completed, these N electronic devices (devices to be inspected) constitute a physical firewall centered on this test server. However, the method by which the test server conducts authentication tests on each device to be inspected is the same as the electronic device in FIG. 13. The method by which device A authenticates electronic device B is the same. Let n be a natural number from 1 to N. Then, the test server inputs a challenge (C) to electronic device (n), and electronic device (n) generates a response (R(n)) from the unique random number (n) of chip (n) contained therein and this C. Electronic device (n) generates a pair of private key (n) and public key (n) from R(n) as shown in Figure 20-3 2 As shown in 5, the public key (n) becomes a logical address (n), or the logical address (n) can be generated from the public key (n). Figure 31 depicts the case where the test server is integrated, but the number of test servers is not necessarily integrated. Although not particularly illustrated as it is obvious, just as there may be multiple inspection devices, there may be multiple test servers in the network of integrated electronic devices. The network of integrated electronic devices is a network that includes all other electronic devices to which the electronic devices that are elements of this network can be directly or indirectly connected. However, the number (N) of peripheral devices must logically be 1 or greater than 1.

[0133] On the other hand, since the conventional firewall is composed of logical addresses, it can be called a logical firewall. When a logical firewall is applied to an IoT network, as shown in Figure 32, it becomes a target of spoofing attacks. The spoofing attack method is as already described in Figures 4-6 and 9. As shown in Figure 33, a hacker's electronic device (with a built-in chip) that has copied the logical address enters inside the logical firewall. Figure 34 shows an attempt to perform the same spoofing attack on a physical firewall. As already described in Figure 19, the present application can block this spoofing attack.

[0134] As shown in Figure 35, if the communication within the physical firewall composed only of electronic devices that have passed the authentication test by the method of the present application is protected by the latest cyber security techniques, the network of electronic devices can be protected. - The reliability of data flow on the Internet of Things (IoT) network is significantly improved. There are currently various cyber security techniques, and new techniques will continue to be developed in the future. The most advanced technique at present is blockchain. As already explained in Figure 26-4 0, the authentication method of the electronic device of the present application can realize the Merkle tree of the memory chip. Therefore, by matching the authentication of the memory chip with the logical address as shown in Figure 20-3 5, complete compatibility with the existing blockchain can be ensured. 3 2

[0135] What Figure 35 means is that by using the authentication method of the electronic device of the present application, a physical firewall can be configured by the central management of the test server, and a distributed system can be constructed using blockchain among the authenticated electronic devices that are its components. This means that the coexistence of central management and distributed management, which was difficult in the cyber space, can be realized in the network (IoT network) of the electronic device of the present application. Also, since the test server can arbitrarily change the challenge (C), it is possible to update the pair of the private key and public key of the authenticated electronic device at any time. If a hacker breaks the security of some authenticated electronic devices, the security of other authenticated electronic devices may also be broken in the same way. At this time, the fact that the public key and private key of the authenticated electronic device can be automatically changed by the central management helps to restore the network security to a sound state in an instant. It is because the private key, or the pair of the private key and public key, is generated from the response as in the present application that such a response is possible.

[0136] ​​When the physical firewall of the present application is created within the network of an electronic device, the electronic device can be divided into what is included in and what is not included in this physical firewall. The physical firewall of the present application does not prohibit its constituent electronic devices from communicating with the outside of the physical firewall. When communicating with the outside of the physical firewall, it is desirable to inform the electronic devices inside the physical firewall that the authentication of the communication partner by the test server has not been performed. Alternatively, it is desirable that the test server does not allow the communication.

[0137] If it is informed that the authentication of the communication partner has not been performed or the communication is not allowed by the test server, it will be found that the communication partner is outside the physical firewall. In such a case, it will be up to the user or system administrator of the electronic device to decide how to handle it. For example, when a test server (the first inspection entity) that authenticates the first electronic device and another test server (the second inspection entity) that authenticates the second electronic device, which is the communication partner of the first electronic device, can communicate with each other, the first and second electronic devices can communicate indirectly via the first and second inspection entities. At this time, the communication content will be managed by the first and second inspection entities.

[0138] (Row line redundancy) FIG. 36 conceptually shows a cell array included in a chip (or memory chip) built into the electronic device to be inspected, and it is desirable that it is part of or all of the isolation region described above. Either the bit line or the word line runs horizontally, and the other runs vertically. There are bit cells (memory cells) represented by squares at the intersection points of the row lines and column lines (the intersection points of the word lines and bit lines). The position of the intersection point of the nth bit line and the mth word line is represented by a pair of two integers (n, m), and this is called the address on the cell array. However, n is an integer from 1 to N in FIG. 14, and m is an integer from 1 to M in FIG. 14.

[0139] In this specification, this bit cell will be deliberately referred to as an authentication element. That is, the type of chip is determined by what kind of electronic element is adopted as this authentication element.

[0140] Since the chip (or memory chip) is a mass-produced product, accidental inclusion of defective products cannot be avoided no matter how the manufacturing process is optimized. On the cell array of FIG. 36, it occurs as defective bits. The number of defective bits and their arrangement on the cell array are random. If the amount of information in the arrangement pattern is large enough, this randomness is different for each chip, that is, it can be regarded as a unique random number unique to the chip. Alternatively, if some bits are deliberately destroyed and the number and address arrangement of the destroyed bits become physically chaotic, the bits deliberately destroyed in this way can also be treated in the same way as the defective bits described above. Alternatively, the number and address of the bits to be deliberately destroyed are specified from a separately generated random number code, and the bits deliberately destroyed can also be treated in the same way as the defective bits described above.

[0141] A method of dividing the cell array of FIG. 36 by row line groups will be described. FIG. 37 shows an example of dividing this row line group into two upper and lower row line groups A and B. The upper end is the top and the lower end is the bottom. As an example, the row lines are bit lines and the column lines are word lines. As another example, the row lines are word lines and the column lines are bit lines.

[0142] FIG. 38 shows another example of dividing this row line group into row line groups A and B. The row line groups A and B are alternately arranged in the column direction, and the upper top of the row line group A and the lower bottom of the row line group B are alternately repeated. The bottom of the row line group B and the top of the row line group A are adjacent in the column direction.

[0143] Anyway, a group of row lines A and a group of row lines B are arranged in the column direction between the top and the bottom, and as shown in FIG. 39, a row decoder A and a row decoder B are required respectively. The number of rows of the group of row lines A is LA, and the number of rows of the group of row lines B is LB. There is a boundary line between the group of row lines A and the group of row lines B. However, the boundary line is drawn between the bottom of the group of row lines A (the row line at the lower end) and the top of the group of row lines B (the row line at the upper end), and is not a row line corresponding to a word line or a bit line. Both the row decoder A and the row decoder B are controlled by a peripheral control device. The peripheral control device accesses a special internal memory and controls the operations of the row decoder A and the row decoder B using the data (Fi, Ri) stored in the special internal memory.

[0144] The group of row lines A is utilized as a redundant row line group with respect to the group of row lines B which is a normal cell array. If the row lines are bit lines, the group of row lines A is a bit line redundant area. If the row lines are word lines, the group of row lines A is a word line redundant area. Generally, the number of row lines belonging to one group of row lines is 1 or more. Also, the number of column lines belonging to one group of column lines is 1 or more.

[0145] As long as the chip is a mass-produced product, as shown in FIG. 36, the inclusion of defective bits cannot be avoided. For example, consider the case where a defective bit is included in the cell array as shown in FIG. 40. However, let the number of row lines (defective row lines) in which defective bits occur in the group of row lines A be mA. Let the number of row lines in which defective bits occur in the group of row lines B be mB. Consider the row lines without defective bits as normal row lines. At this time, the number of cases due to defective bit distribution is given by the product of C(LA, mA) and C(LB, mB). However, C(S, T) is the combination of selecting T elements from S elements. In terms of information amount, it is log(C(LA, mA)) + log(C(LB, mB)). Generally, as the number of rows of the cell array increases, the number of defective bits included also increases, so it is expected that the information amount due to defective bit distribution will increase as the bit capacity of the chip increases. In the example of the figure, mA = 1 and mB = 2. Also, when the division by row line groups as in this embodiment is adopted, the information amount increases as the number of row lines (N in FIG. 14), or LA and LB increase.

[0146] To access the row line group B (regular cell array), as shown in Fig. 41, first select an appropriate column, and then specify "normal access" in the access mode of the peripheral control device (see Fig. 39). Then, access the row lines below the boundary line sequentially along the selected column. Although it is self-evident and not particularly shown here, a column decoder is required to select a column in this way.

[0147] When reaching a row line with a defective bit in the middle, read the row number (F1) and save it in the special internal memory (see Fig. 39). Instead of accessing the bit cells in this F1 row, access the bit cells in the R1 row that does not contain defective bits in the row line group A (redundant row line group). R1 is also recorded in the special internal memory (see Fig. 39). This is called a swap. After the first swap is completed, return to the row line group B (regular cell array) and resume access from the next row after the F1 row. If reaching a row line with a defective bit again, read the row number (F2) and save it in the special internal memory. Instead of accessing the bit cells in this F2 row, access the bit cells in the R2 row that does not contain defective bits in the row line group A (redundant row line group). R2 is also recorded in the special internal memory (see Fig. 39). This is called the second swap.

[0148] In this way, the combination of {Fi, Ri} is stored as data in the special internal memory. However, i is a natural number from 1 to mA. The number of cases when performing mA swaps is given by the product of C(LA, mA) and P(LB, mB). Here, P(S, T) is the number of cases (permutations) of selecting and arranging T elements from S elements. In terms of information quantity, it becomes log(C(LA, mB)) + log(P(LB, mB)). This is the information quantity of the data stored in the special internal memory.

[0149] In order to always be able to read and rewrite, LA must be greater than the sum of mA and mB. Furthermore, in order for the regular cell array to be acceptable as a mass-produced product, LB must be much larger than mB. Even in that case, if the bit capacity is large enough, the information amount log(C(LA,mB)) + log(P(LB,mB)) will be large, and the possibility that the data stored in the special internal memories of two mass-produced chips accidentally match becomes negligibly low. Moreover, since its generation mechanism does not depend on any algorithm, it is physically random. Thus, the combination code of {Fi,Ri} stored in the special internal memory can be regarded as a random number code unique to the chip (an example of a unique random number).

[0150] Figure 42 is a diagram for explaining Test Mode 1. First, select an appropriate column. Next, specify "Test Mode 1" in the access mode of the peripheral control device (see Figure 39), and sequentially access from the top to the bottom row lines across the boundary line along the selected column. This is a mode of accessing all row lines along the selected column from row line group A to row line group B.

[0151] Figure 43 is a diagram for explaining Test Mode 2. First, select an appropriate column. Next, specify "Test Mode 2" in the access mode of the peripheral control device (see Figure 39), and sequentially access the row lines from the top to the boundary line along the selected column. This is a mode of accessing only the row lines belonging to row line group A.

[0152] Figure 44 shows the state of selecting Test Mode 1 and writing 0. First, select an appropriate column. Next, specify "Test Mode 1" in the access mode of the peripheral control device (see Figure 39), and sequentially access from the top to the bottom row lines across the boundary line along the selected column to write 0. Thus, all 0s are written along the selected column from row line group A to row line group B.

[0153] Subsequently, while the same selection sequence is specified, Fig. 45 shows the state after selecting test mode 2 and performing one write operation. First, specify "test mode 2" in the access mode of the peripheral control device (see Fig. 39). Sequentially access from the top to the boundary line along the selection sequence and write 1. In this way, only 1 is written to the row line group A along the selection sequence, and the row line group B remains 0.

[0154] Subsequently, specify "normal mode" in the access mode of the peripheral control device (see Fig. 39), and Fig. 46 shows the result of sequentially accessing and reading from the top to the boundary line along the selection sequence. Among the LB rows, the mB rows where the reading has been changed are inverted to 1. In this way, a random pattern of 0 and 1 is formed. Since the number of cases is given by C(LB, mB), the amount of information ultimately becomes log(C(LB, mB)).

[0155] Since 0 and 1 are arranged along the selection sequence, it becomes a random number code like a barcode. Write this random number code as {d(i)}. As described above, if the bit capacity of the chip is large enough, this random number code can be regarded as unique to the chip. That is, {d(i)} is a unique random number unique to the chip and is the root of Merkle in Figs. 28 and 29.

[0156] However, compared with the original amount of information log(P(LA - mA, mB)) + log(P(LB, mB)), the amount of information of this {d(i)} will decrease to log(C(LB, mB)).

[0157] Note that when using the argument (n) to identify multiple chips, an example of the unique random number (n) of chip (n) is {dn(i)}.

[0158] Also, in the description of this embodiment, the 0 write and the 1 write can be exchanged. The key point is that it is sufficient to be able to handle at least binary data.

[0159] A method of obtaining a unique random number by utilizing test mode 1 or test mode 2, and the normal access mode requires power consumption. When there is a need to save power as much as possible, although not particularly illustrated as it is obvious, wiring for accessing a special internal memory is required. A power-saving mode is possible as a mode of directly accessing the special internal memory using such wiring. In this case, when reading is performed with the power-saving mode selected as the access mode, {Fi, Ri}, which is an example of a unique random number, can be obtained. In this case, it is also possible to prevent the loss of information amount due to code conversion.

[0160] If the number of rows (LA) of the row line group A (redundant row line group) is too small, it may become impossible to perform rereading. In order to avoid such a situation, LA must be larger than the sum of mA and mB. It is possible to confirm whether this condition is satisfied.

[0161] Subsequently, the address space check mode will be described. First, a combination of any plurality of addresses is selected, writing is performed to the corresponding authentication elements, then reading is performed, and it is confirmed whether the read data matches the written data. If a sufficient number of cells match, this chip can be certified (passed) as having a sufficient address space as an authentication chip. If they do not match, the certification is failed.

[0162] Fig. 47 summarizes the relationship between the above-described access mode and operation mode. A redundant mode acquisition code is given from an external input to the subject to be inspected. This can be included in the challenge (C) or can be given separately from the challenge (C). The redundant mode acquisition code has as arguments an access option for selecting an access mode, and an operation option for setting an operation mode (writing, erasing, reading), etc.

[0163] As described above, the access mode consists of test mode 1, test mode 2, normal access mode, power-saving mode, address space check mode, etc.

[0164] In the normal access mode, access is made only to the bits belonging to the row line group B (normal cell array) along the selection column, and when the row number matches the element with the row number Fi, the row number is replaced with Ri. However, Fi and Ri are stored as redundancy data {Fi, Ri} in a special internal memory (see FIG. 39). The subscript i is a natural number from 1 to mB. It is desirable that the redundancy data be obtained during the pre-shipment inspection of the chip and stored in the special internal memory.

[0165] In this embodiment, test mode 1 is an access mode that uses both row decoder A and row decoder B. In test mode 2, it is an access mode that uses only row decoder A.

[0166] Even if test mode 1 is changed to an access mode that uses only row decoder B as shown in FIG. 48, a unique random number {d(i)} specific to the chip can be obtained. As an example, if a write of 0 is performed in test mode 1 and a write of 1 is performed in test mode 2, FIG. 45 can be obtained. Subsequently, a read can be performed in the normal access mode. Of course, 0 and 1 can be exchanged in this case as well.

[0167] Even if test mode 2 is changed to an access mode that uses only row decoder B as shown in FIG. 49, a unique random number {d(i)} specific to the chip can be obtained. As an example, if a write of 0 is performed in test mode 1 and a write of 1 is performed in test mode 2, FIG. 45 can be obtained. Subsequently, a read can be performed in the normal access mode. Of course, 0 and 1 can be exchanged in this case as well.

[0168] The access option is an option for switching the selection of row decoders A and B. In FIGS. 47 - 59, an example is shown where different binary data (0 or 1) can be written to row line groups A and B by sequentially selecting test modes 1 and 2.

[0169] Generally, the area other than the cell array within the chip is called the peripheral area. FIG. 50 shows the module configuration of the peripheral area that operates row decoders A and B. The cell array is divided into row line groups A and B as described above, and is controlled by row decoders A and B respectively. The peripheral control device cooperates with the external input / output, and receives the above-mentioned challenge (C) and the redundancy mode acquisition code as external inputs. The redundancy mode acquisition code is distributed to row decoders A and B, and is used for the control of row decoders A and B as shown in FIGS. 47 to 59.

[0170] As an example, a unique random number {d(i)} is obtained from the redundancy data {Fi, Ri} stored in the special internal memory as in the result of FIG. 46 described above. That is, as shown in FIG. 51, d(i) can be obtained by converting (Fi, Ri) with the function f. When f is a dummy function that does nothing, the redundancy data itself is the unique random number. This unique random number {d(i)} is a set of d(i), and is distributed to the code generation device together with the challenge (C) received as an external input, and returns a set of {R(i)} as the response (R) according to an appropriate response function Res (see below). However, the challenge is a set of {C(i)} of C(i).

[0171] R(i)=Res (C(i), d(i))

[0172] As long as the set {d(i)} is unique to the chip, the Res function satisfies the relational expressions in paragraph 0060 and paragraph 0063.

[0173] Finally, {R(i)} is externally output as the response (R) via the external input / output.

[0174] In this way, it is possible to realize the concepts of FIGS. 13 and 30 by using the unique random numbers retrieved from the special internal memory. By adopting this embodiment, the unique random numbers of FIGS. 13, 30 - 35 and 40 can be obtained from the redundancy data {(Fi, Ri)}. However, it is the special internal memory within the electronic device B that stores the redundancy data {(Fi, Ri)} related to the unique random numbers. The unique random numbers may use this redundancy data {(Fi, Ri)} as it is, or may be used after code conversion from this data. The special internal memory may be installed within the electronic device B together with the chip related to the unique random numbers, or may be installed inside this chip. In any case, it is desirable that this special internal memory be unique to the electronic device B.

[0175] (Dedicated column for authentication) The cell array of the chip may be randomly accessed for purposes other than authentication during chip operation. In such a case, it is necessary to prevent inconsistencies from occurring between the access to the cell array by the authentication operation of this application and the access to the cell array by another operation of the chip. In this embodiment, this problem is addressed by providing a dedicated column for authentication. FIG. 52 shows the case where the dedicated column for authentication is at the right end. FIG. 53 shows the case where the dedicated column for authentication is located slightly to the right of the center.

[0176] When the chip performs operations other than authentication, it is necessary to set restrictions on access so that the dedicated column for authentication is not accessed. At this time, an authentication setting option for selecting either the authentication mode or the non - authentication mode as an argument of the redundancy mode acquisition code will be newly added. FIGS. 47 to 59 are examples when the authentication mode is selected.

[0177] Furthermore, a mode (dedicated column specification mode) for specifying the dedicated column for authentication can be added as one of the arguments of the redundancy mode acquisition code. In this case, the number of columns of the dedicated column for authentication is used as the argument of the dedicated column specification mode. For example, it can be specified as dedicated column specification (column number). FIG. 52 is an example when the column number at the right end is selected in the dedicated column specification. FIG. 53 is an example when the column number slightly to the right of the center is selected in the dedicated column specification.

[0178] When the authentication mode is selected as an argument for the authentication setting mode, the dedicated authentication column with the column number selected in the dedicated column specification mode is selected. Subsequently, select any one of test mode 1, test mode 2, and normal access mode in the access mode. Then, it is desirable to perform authentication according to the specifications in FIGS. 47 to 59.

[0179] When the non-authentication mode is selected in the dedicated column specification mode, the column numbers not selected in the dedicated column specification mode are selected. Subsequently, the normal access mode is selected.

[0180] (Block redundancy) As described above, when the cell array is divided by the row line group, the amount of information of the unique random number decreases from log(P(LA - mA, mB)) + log(P(LB, mB)) to log(C(LB, mB)). In order to control the decrease in the amount of information, a method of dividing the cell array in FIG. 14 into small blocks instead of the row line group can be expected.

[0181] FIG. 54 shows an example of dividing the cell array in FIG. 14 into small blocks. The number of small blocks in the row direction is MB, and the number of small blocks in the column direction is NB. Each small block is assigned a small block address of (iB, jB). However, iB is a natural number from 1 to MB. jB is a natural number from 1 to NB. This is called a block array.

[0182] FIG. 55 shows an example of the element arrangement within a small block. The number of rows within each small block is BM and the number of columns is BN, and each bit cell is assigned a small block internal address of (i’, j’). However, i’ is a natural number from 1 to BM, and j’ is a natural number from 1 to BN. The row lines are bit lines or word lines. The column lines are word lines or bit lines. For example, when BN is 1, this embodiment is the same as the division by the row line group. Therefore, the division by blocks (block division) can be regarded as a generalization of the division using the row line group (row line group division).

[0183] If the small block address and the address within the small block are specified, the address (bit address) of the bit cell (authentication element) can be specified. FIG. 56 shows an example of a method for converting the bit address (i, j) into the address of the present embodiment. That is, a cell block address table is required. The cell block address table is a correspondence table between an arbitrary address on the cell array and a combination of the small block address and the address within the small block.

[0184] First, a cell block address table is created according to FIGS. 54 and 55. The bit address (i, j) is converted into (iB, jB; i’, j’) using this cell block address table. However, the first half (iB, jB) consists of the small block address. The second half (i’, j’) consists of the address within the small block.

[0185] FIG. 57 shows an example in the case where there is a defective bit in the small block. Such a small block containing a defective bit is called a defective small block. In this way, defective small blocks are arranged in the block array.

[0186] FIGS. 58 to 70 show an example in the case where two defective small blocks are distributed in the block array. In FIG. 58, the small block address (sB, tB) is assigned to one of the defective small blocks. There is a defective bit at the address within the small block (s’, t’), and the bit address of this defective bit is represented by (sB, tB; s’, t’).

[0187] On the other hand, FIG. 59 shows the case where there is no defective bit at the address within the small block (v’, w’) in the defective small block assigned with the small block address (sB, tB).

[0188] On the one hand, in FIG. 60, it shows a case where there is no defective bit in the small block at the small block address (pB, qB). At this time, no matter which coordinates are selected for the in-block address (i’, j’) of the bit address (pB, qB; i’, j’), there is no defective bit. Such a small block is called a regular small block.

[0189] In mass-produced products, it is impossible to make the number of defective products zero. Even if there are defective products, it is important to manage them and suppress their effects. Since it is impossible to completely remove the defective bits from the cell array in FIG. 14, the set of small blocks in FIG. 54 is divided into redundant blocks and regular blocks. FIG. 61 shows an example where two defective small blocks are distributed within a regular block.

[0190] FIG. 62 shows an example of a method for searching for defective small blocks in a block array divided into redundant blocks and regular blocks.

[0191] First, select each small block within the regular block and search whether there is a defective bit inside. However, for the sake of simplicity in explanation, the small block address assigned to the upper-left small block to be examined first is set as (1, 1). To check whether there is a defective bit in that small block, check whether there is a defective bit at the in-block address (i’, j’). That is, search (1, 1; i’, j’). However, i’ scans from 1 to BM, and j’ scans from 1 to BN. If no defective bit is found after scanning from (1, 1; 1, 1) to (1, 1; BM, BN), this small block is a regular small block. Otherwise, this small block is a defective small block. Update the small block address (as an example, (1, 2; I’, j’)), and repeat the same process until all small blocks within the regular block are operated on.

[0192] In the example of FIG. 62, the small block address at the upper left of the regular block is set as (1, 1), and the small blocks are scanned in the row direction from there. When reaching the right end, the column is lowered by one step and the search is restarted from the left end (2, 1) in the row direction. The same method can be used for scanning the small blocks within the redundant block.

[0193] In this way, the set of small block addresses of defective small blocks {defective small block (iB, jB)} and the set of addresses of defective bits {(iB, jB; i’, j’)} are obtained. Both are random data unique to the chip (unique random numbers), but the set of small block addresses of defective small blocks {(iB, jB)} has less information content than the set {(iB, jB; i’, j’)}. However, it is possible to suppress the loss of information content by reducing the number of bits within the small block.

[0194] In this embodiment, the set of small block addresses of defective small blocks {defective small block (iB, jB)} is redundancy data. Generally, redundancy data is associated with unique random numbers, so the set {defective small block (iB, jB)} can be regarded as unique random numbers. For example, FIG. 63 shows the addresses of defective small blocks displayed and arranged in binary. In this way, the set {defective small block (iB, jB)} is obtained as a unique random number code unique to the chip, which is displayed in binary of 0 and 1. This redundancy data is acquired during the pre-shipment inspection of the chip and stored in a special internal memory.

[0195] FIG. 64 shows an example of the method for re-reading small blocks. In this example, the scanning is performed in the row direction, but it is also possible to perform the scanning in the column direction as shown in FIG. 42. In particular, if power saving is not a particular issue, it is desirable to generate unique random numbers from the set {defective small block (iB, jB)} by this method. Although not particularly shown as it is obvious, various scanning methods can be adopted in the present application.

[0196] First, scan each small block within the regular block one by one using the above-described method or another appropriate method. If the first defective small block is found, move to the redundant block and start scanning the small blocks within the redundant block. Replace the first regular small block that appears in the redundant block with the defective small block found in the regular block. This is referred to as replacement 1 in FIG. 63. After replacement 1, update the small block addresses within the redundant block, return to the regular block, update the small block addresses within the regular block, and resume scanning within the regular block. If the next defective small block is found, move to the redundant block and start scanning the small blocks within the redundant block. Replace the first regular small block that appears in the redundant block with the defective small block found in the regular block. This is referred to as replacement 2 in FIG. 63. After replacement 2, update the small block addresses within the redundant block, return to the regular block, update the small block addresses within the regular block, and resume scanning within the regular block.

[0197] Repeat this operation until all small blocks within the regular block have been scanned.

[0198] However, the redundant block and the regular block must be divided such that the number of regular small blocks within the redundant block is greater than the number of defective small blocks found within the regular block. This is determined by the chip design specification, but if only chips that meet this condition in the adopted design specification are shipped as good products, all the shipped chips will satisfy the condition that "the number of regular small blocks within the redundant block is greater than the number of defective small blocks found within the regular block."

[0199] The division by small blocks is a generalization of the division using the row line group as described above. That is, the relationships corresponding to the access option and operation option selection methods in FIGS. 47 to 59 also exist in this embodiment. They are shown in FIGS. 65 to 77, respectively corresponding to FIGS. 47 to 59.

[0200] First, a redundancy mode acquisition code is given to the subject under test from an external input. This can be included in the challenge (C) or can be given separately from the challenge (C). The redundancy mode acquisition code has, as arguments, access options for selecting an access mode, operation options for setting an operation mode (write, erase, read), and the like.

[0201] As described above, the access mode consists of test mode 1, test mode 2, normal access mode, power saving mode, address space check mode, and the like. So far, it is the same as FIG. 47.

[0202] However, in FIGS. 65 to 77, the information stored in the special internal memory is replaced by a set {small blocks (iB, jB)} that generalizes the row line group division. Further, for bit address conversion, it is necessary to read the cell block address table of FIG. 56 from the normal access mode.

[0203] It is also necessary to explain again about the generalization to the block division of test modes 1 and 2.

[0204] FIG. 68 shows a method of controlling access to redundant blocks and normal blocks using a row decoder A, a row decoder B, and a column decoder.

[0205] The peripheral control device receives a challenge (C) and a redundancy mode acquisition code through external input / output. In accordance with the access option of the redundancy mode acquisition code, row decoder A controls access to the redundant block together with the column decoder. Row decoder B controls access to the normal block together with the column decoder. Further, by manipulating the operation option, a set of addresses of defective bits {(i,j)} is obtained. This is converted into a set of addresses of defective sub-blocks {(iB,jB)} using the cell block address table. This results in data where 0s and 1s are distributed in a checkered pattern as shown in, for example, FIG. 69. This can be converted to binary representation to obtain a unique random number {d(i)}. This is stored in a special internal memory. The unique random number and the challenge (C) obtained from external input / output are input into the response function (Res) of paragraph 0171 to obtain a response {R(i)}. Finally, {R(i)} is externally output as a response (R) through external input / output.

[0206] Return to FIG. 65. First, select test mode 1 with the access option and write 0 to all sub-block addresses accessible in combination with the column decoder. Subsequently, select test mode 2 and write 1 to all sub-block addresses accessible. Subsequently, select the normal access mode and sequentially scan all accessible sub-blocks, and while reading the data in the special internal memory, determine whether it is a defective sub-block. If it is a defective sub-block, a read replacement to the redundant sub-block is performed, and the read result will be 1. If it is a normal sub-block, the read result will be 0. In this way, as an example, data where 0s and 1s are distributed in a checkered pattern as shown in FIG. 69 is obtained. It is also possible to do the same by exchanging 0s and 1s. As described above, this becomes a unique random number.

[0207] Return to FIG. 66. First, select Test Mode 1 in the access option and write 0 to all small block addresses accessible in combination with the column decoder. Subsequently, select Test Mode 2 and write 1 to all small block addresses accessible. Then, select the normal access mode and sequentially scan all accessible small blocks, determining whether there are defective small blocks while reading the data in the special internal memory. If it is a defective small block, read substitution to the redundant small block is performed, and the read result will be 1. If it is a normal small block, the read result will be 0. In this way, as an example, data distributed in a checkered pattern of 0s and 1s as shown in FIG. 69 is obtained. It is also okay to do the same thing by exchanging 0 and 1. As described above, this becomes a unique random number.

[0208] Return to FIG. 67. First, select Test Mode 1 in the access option and write 1 to all small block addresses accessible in combination with the column decoder. Subsequently, select Test Mode 2 and write 0 to all small block addresses accessible. Then, select the normal access mode and sequentially scan all accessible small blocks, determining whether there are defective small blocks while reading the data in the special internal memory. If it is a defective small block, read substitution to the redundant small block is performed, and the read result will be 1. If it is a normal small block, the read result will be 0. In this way, as an example, data distributed in a checkered pattern of 0s and 1s as shown in FIG. 69 is obtained. It is also okay to do the same thing by exchanging 0 and 1. As described above, this becomes a unique random number.

[0209] What conceptualizes the above-described operation is FIG. 70. Compared with FIG. 51, the unique random number stored in the special internal memory is the set of addresses of defective small blocks, and it is only different in this point. Since the rest is the same, detailed description is omitted.

[0210] (Authentication-only bit) As described above, the cell array of the chip may be randomly accessed for purposes other than authentication during chip operation. In such a case, it is necessary to ensure that there is no inconsistency between the access to the cell array by the authentication operation of the present application and the access to the cell array by another operation of the chip.

[0211] In this embodiment, this problem is addressed by providing an authentication - dedicated bit in the small - block - internal address. FIG. 71 shows the case where the authentication - dedicated bit is at the upper - left corner of the small block. FIG. 72 shows the case where the authentication - dedicated bit is at a position slightly to the center from the upper - left corner.

[0212] When the chip performs operations other than authentication, it is necessary to select the non - authentication mode in the authentication setting option and set a restriction so as not to access this authentication - dedicated bit within each small block. FIGS. 65 to 77 are examples when the authentication mode is selected.

[0213] Furthermore, a mode (dedicated - bit - specifying mode) for specifying the authentication - dedicated bit as one of the arguments of the redundant - mode acquisition code can be added. In this case, the row number and column number of the authentication - dedicated bit are used as the arguments (specified - bit address) of the dedicated - bit - specifying mode. For example, dedicated - bit - specifying (row number, column number), etc. However, the address selected by the dedicated - bit - specifying is the address within the small block. FIG. 71 shows an example when the bit at the upper - left corner within the small block is selected by the dedicated - bit - specifying. FIG. 72 shows an example when the bit from the upper - left corner to the right of the center is selected by the dedicated - bit - specifying.

[0214] When the authentication mode is selected as an argument of the authentication setting mode, the authentication - dedicated bit of the bit selected in the dedicated - column - specifying mode is selected. Subsequently, one of test mode 1, test mode 2, and normal access mode is specified in the access mode. Then, authentication can be performed according to the specifications of FIGS. 65 to 77.

[0215] When the non-authentication mode is selected in the dedicated bit specification mode, bits not selected by the dedicated bit specification are selected within each small block. Subsequently, the normal access mode is selected.

[0216] Figures 13 and 30 illustrate the concept of the present application. If the present embodiment (block redundancy) is adopted, the redundancy code {defective small block (iB, jB)} can be used as data related to the random numbers unique to Figures 13, 30 - 35, and 40. Alternatively, if the embodiment of (row line redundancy) is adopted, the redundancy code {(Fi, Ri)} can be used as data related to the random numbers unique to Figures 13, 30 - 35, and 40.

[0217] In any case, generally according to the concepts of Figures 13 and 30, the inspection entity inputs the data (code information) {C(i)} that is the challenge to the device under test. Also, if BM = 1 and BN = N in Figure 55, it can be seen that (block redundancy) generalizes (row line redundancy).

[0218] Inside the chip included in the device under test, data (defective code information) related to the defective bit distribution unique to that chip is stored as data related to the random number unique to the chip.

[0219] Generating the response (R) from the challenge (C) together with this defective code information according to the formula in paragraph 0060 ultimately agrees with the generation of the response (R) using the random number and the challenge (C). As long as the random number is unique to the chip, that is, as long as the random number can be regarded as having a one-to-one relationship with the chip, this response (R) can be regarded as being determined by the challenge (C) and the chip.

[0220] The inspection entity receives this response (R) output from the device under test and authenticates the device under test from the combination of C and R. At this time, it is desirable for the inspection entity to play the role of the test server in Figure 31.

[0221] Note that it is possible to generate a pair of a private key and a public key according to the PKI algorithm using the response (R) and the method shown in FIG. 20-35. The pair of the private key and the public key thus generated is utilized for data transmission and reception using the methods shown in FIGS. 26 and 27.

[0222] As shown in FIGS. 13 and 30, this private key is associated with the unique random number unique to the chip constituting the device under test in an inseparable manner. Moreover, as shown in the equations in paragraphs 0060 and 0063, the challenge (C) is also included as an argument. Therefore, even if a hacker steals the unique random number, since the inspection entity uses the pair (C, R) for the authentication of the device under test, it is impossible to forge the authentication of the device under test unless the inspection entity itself is hacked.

[0223] The special internal memory in the device under test stores data (such as defective code information) related to the unique random number. It is desirable to install the special internal memory inside the chip related to the unique random number. Alternatively, it is also possible to install it inside the device under test together with the chip related to the unique random number. In any case, it is desirable that this special internal memory is unique to the device under test. Also, it is desirable that the special internal memory is not directly connected to the external input / output of the chip.

[0224] As shown in FIG. 31, there is a test server (core device) as the central position of the physical firewall. The test server manages other electronic devices (peripheral devices), and the peripheral devices can communicate with each other using the public key or the code information generated from the public key as a logical address. The difference between the case of communicating with another electronic device inside the physical firewall and the case of communicating with an external electronic device is whether the test server can be authenticated. Since an external electronic device cannot be authenticated by the test server, whether to communicate with an external electronic device or what kind of communication to perform is left to the judgment of the administrator. As an example, it is desirable to communicate with an electronic device outside the physical firewall via the test server.

[0225] The test server performs authentication management of the peripheral devices using a set of combinations of inputs (challenges, C) and responses (R) from the peripheral devices under its management. When the test server inputs the same challenge (C) to the peripheral devices under its management all at once, each peripheral device returns a different response (R), so the test server will obtain the set of Rs {R}. The test server can change the challenge (C) at any time and send it to the peripheral devices under its management each time. This is a change in the challenge (C). The set of responses (R) from each peripheral device also changes corresponding to the changed challenge (C). That is, the test server can manage the authentication of the peripheral devices within the physical firewall using the appropriately updatable combination of C and {R}.

[0226] Figure 20-3 2 In 5, the private key and the public key are generated from the response (R(n)), but it is also possible to generate the private key and the public key from the unique random number (n). In this case, the inspection entity (test server) is as shown in FIGS. 73 and 8 7 4, as an example, inputs the challenge (C) to the key generation device. In the key generation device, it is desirable to synthesize the unique random number (n) and this challenge (C) by some method and generate a pair of private key and public key based on it using a predetermined algorithm (RSA type or Elgamal type). FIGS. 73 and 74 respectively correspond to the case where the Elgamal type and RSA type algorithms are used in the key generation device. The method of synthesizing the unique random number (n) and the challenge (C) can be realized, for example, using a logic gate with two inputs and one output such as logical AND, logical NAND, logical XOR, logical OR, logical NOR. Although not particularly illustrated as it is obvious, in the embodiments of FIGS. 73 and 8 7 4, it is also possible to use the second input as in FIGS. 21 and 3 2 2, or FIGS. 24 and 3 2 5. Also, in the case of this embodiment, FIGS. 50, 6 5 1, 7 6 8, 8 7The code generation device of 0 is not necessarily used. Further, in FIGS. 50 and 7 6 8, it is also possible to install a key generation device in the peripheral control device. At this time, the key generation device may be installed as software or may be incorporated as an embedded circuit.

[0227] Describe the conditions that the device under test, or the peripheral device of the present application under the management of the test server, should satisfy.

[0228] For an input (C) from the outside to the device under test, the device under test generates a response (R) from the physical characteristics of the device under test or its internal part and the input (C). However, the device under test does not store C or R internally. After the generation of R is completed, the data related to C inside the device under test is discarded, encrypted, hashed, or made inaccessible from the outside by another method. After the generated R is output outside the inspection device, the data related to R inside the device under test is also discarded, encrypted, hashed, or made inaccessible from the outside by another method.

[0229] The device under test of the present application has an authentication device inside. The authentication device needs to satisfy conditions such as input independence, output independence, output unpredictability, input / output reliability, output practical infinity, chip uniqueness, and physical non-rewritability with respect to the combination of C and R.

[0230] Input independence means that when two different challenges (C1 and C2) are input to one authentication device, different responses (R1 and R2) are output from the one authentication device.

[0231] Output independence means that when one same challenge (C) is input to two different authentication devices, the two different authentication devices output different responses (R1 and R2).

[0232] The unpredictability of the output means that, even if the combinations {(C1R1), (C2R2), … (CSRS)} of the outputs for each of S challenges {C1, C2, … CS} input to the same authentication device are known, the output RS+1 when an unknown challenge (CS+1) different from any of the S challenges is input to the one authentication device is realistically unpredictable. However, S is 2 or more. When the authentication device generates an output by some algorithm, that is, when authentication is returned by software, this condition is almost always violated. Therefore, the authentication device of the present application must utilize physical randomness to generate an output signal.

[0233] Next, the meaning of being realistically unpredictable will be explained.

[0234] Prepare a first input set consisting of a plurality of input signals and a first output set consisting of a set of output signals obtained by inputting these plurality of input signals to the authentication device respectively. Further, prepare a second input set consisting of a plurality of input signals not belonging to the first input set. However, let the number of elements of the second input set be M. Even if any combination of the first input signal and the first output signal is known, it is probabilistically difficult to predict the M output signals that the authentication device outputs respectively according to the M input sets before inputting the M input signals belonging to the second input set to the authentication device. For example, when M input signals are selected M N time predictions will be made. Here, being able to predict means that a considerable number of the M predictions are successful. On the other hand, if the probability of successful prediction is on average 1 / (M + 1) or less, it is considered realistically unpredictable.

[0235] The reliability of input / output means that due to uncontrollable noise related to the circuit that controls the challenge signal C to be input, a signal error (ΔC) is mixed into the challenge signal C. On the other hand, due to uncontrollable noise related to the circuit that controls the challenge signal error (ΔC) and the output response signal, a signal error (ΔR) is mixed into the response signal R. At this time, the absolute value of the difference between two different challenge signals (for example, C1 and C2) shall be greater than the maximum value of the absolute value of the challenge signal error (ΔC). Here, the absolute value of the difference between the response signal R1 for the challenge signal C1 and the response signal R2 for the challenge signal C2 must always be greater than the absolute value of the response signal error (ΔR).

[0236] The practical infinity of output is closely related to the independence of output. The authentication device of the present application generates a response (R) from the unique random number (RN) caused by the electronic device serving as the device under test and the challenge (C) input to the authentication device. However, the information entropy of this unique random number (RN) is generally not infinite. Therefore, when the number of authentication devices becomes very large, there is a possibility that two different authentication devices output the same response for the same challenge due to accidental coincidence.

[0237] If such an accidental coincidence occurs, the outputs from two different chip authentication devices for the same input will match, which will impair (the independence of output). The only way to deal with this problem is to consider it probabilistically.

[0238] For example, let X be the number of cases of the randomness (random) unique to the IC chip, and Y be the number of all physical nodes connected to the network. At this time, the probability that the outputs from two different authentication devices for the same input accidentally match increases as Y increases and decreases as X increases. Therefore, it is considered to be proportional to Y / X. It is necessary that Y / X is small enough that this probability is almost zero in reality. That is, at least X is larger than Y. Furthermore, considering along the six sigma often used in quality control, the realistically acceptable error is 3.4 in one million. Therefore, it is necessary that X is larger than one million times Y.

[0239] The chip uniqueness (or IC chip uniqueness) is deeply related to the output of the authentication device of the present application being unique to the authentication device. When the authentication device of the present application includes an IC chip as a component, the output from the authentication device must be an electronic signal unique to this IC chip. In particular, the said unique random number is generated from the physical randomness unique to the IC chip.

[0240] The physical non-rewritability is related to the durability against external environment changes.

[0241] For example, it must be impossible to rewrite the physical randomness specific to the chip by applying some physical stimulus from the outside. In other words, even if some physical stimulus is applied from the outside, the physical randomness specific to the chip remains unchanged, or is stable. Alternatively, the physical randomness specific to the chip is resistant to external stimuli or changes in the external environment. As a result, it is required that the output from the authentication device of the present application be stable. If it were possible to rewrite the physical randomness specific to the chip to the randomness caused by separately prepared random numbers, then on the network, that chip would be replaced by another one. It is obvious that such forgery creates a situation advantageous to the attacker. Here, some physical stimulus from the outside refers to an electric field, an electromagnetic field, heating, a temperature change, a humidity change, a shock, a vibration, etc., and in the normal case, it is of a degree that does not destroy the package of the IC chip. Conversely, it is desirable that if the package is destroyed, the data stored in the isolated area is also destroyed. This is to satisfy the tamper resistance.

[0242] As described above, the unique random number of the present application is stored in a stable state against changes in external environmental factors such as temperature, has a lifespan longer than the product lifespan of the electronic device (device under test) in this stored state, has a sufficiently large information entropy, and is preferably generated from physical species caused by the IC chip.

[0243] Alternatively, the device under test of the present application preferably has an isolated area inside that is difficult to access realistically from the outside of the device under test or the IC chip included in the device under test, and stores a unique random number that satisfies all of the above conditions except for physical non-rewritability in the isolated area. At this time, it is desirable that the isolated area satisfies durability against external environmental changes.

[0244] Alternatively, it is desirable to store the ciphertext of the unique random number in an area inside the authentication device of the present application that has durability against external environmental changes.

[0245] In any case, it is desirable to enable the internal circuit to read the specific function only for generating a response. When encrypted, the plaintext of the specific random number can be read when accessing the specific random number inside the chip, but it is desirable to ensure that when accessing the specific function from outside the chip, the ciphertext of the specific function is read.

[0246] In order to securely generate a response (R) using the authentication device of the present application, it is desirable to generate it using a function that is practically irreversible from the challenge (C) input to the authentication device and the specific random number unique to the IC chip included in the authentication device.

[0247] Functions that are practically irreversible mainly include methods using hashing and methods using encryption.

[0248] A hash function is a function that converts an input of any bit length into a code of a fixed bit length using a predetermined algorithm. It is considered difficult to regenerate the input from the output. However, if the bit length of the output is too short, there is a risk of impairing the practical infinity of the output.

[0249] Another way to implement a function that is practically irreversible is encryption. In this case, the combination of the input (C) and the specific random number (RN) becomes the plaintext, and the encrypted result becomes the output (R). However, it is necessary to discard the encryption key after generating the output (R) by encryption. If the encryption algorithm is a symmetric encryption, the symmetric key can be discarded. In the case of an asymmetric or public key encryption (PKI) where the key consists of a pair of a decryption key and an encryption key, at least the decryption key should be discarded. However, the bit length of the output needs to be made sufficiently long so as not to impair the practical infinity of the output.

[0250] In particular, synthesizing the input (C) and the specific random number (RN) is important in embodying the basic concept of the present application.

[0251] The unique random number (RN) is generated from the IC chip that constitutes the authentication device, using physical randomness that is unique to that IC chip. Such physical randomness that is unique to the IC chip is called a physical random number seed.

[0252] The seed of the physical random number is, for example, the address of a destroyed or shorted authentication element that is physically randomly distributed on the cell array of the authentication element described in FIG. 14. Alternatively, as described in FIG. 36 to FIG. 72, the seed of the physical random number is the address of a defective bit (an authentication element that has become defective for some reason) that is physically randomly distributed on the cell array of the authentication element. The address of the authentication element on the cell array is defined by a pair of one word line (selected word line) and one bit line (selected bit line) selected from the word line group and bit line group stretched on the cell array as shown in FIG. 14. For example, if the number (for example, row number) assigned to the selected word line is m and the number (for example, column number) assigned to the selected bit line is n, the address (selected address) on the cell array of the selected authentication element (selected authentication element) is expressed by (m, n). Note that, in FIG. 14, the word line group is stretched in the row direction and the bit line group is stretched in the column direction, but the row direction and the column direction may be interchanged.

[0253] As mentioned above, a defective bit is a bit of poor quality that accidentally gets mixed into a cell array during the manufacturing process of an IC chip. Alternatively, it is a bit whose quality is intentionally made poor (destroyed, shorted, etc.) by applying an electric pulse after the cell array is manufactured. In either case, the number of defective bits and their address arrangement in the cell array are characterized by being uncontrollable and physically random.

[0254] In any case, it is possible to generate a unique random number that is unique to the IC chip including this cell array from the address arrangement of the defective bits by using the methods of Figures 37 to 72. It is desirable to store the unique random number in a separate area or to encrypt it as described above.

[0255] It is also possible to directly store a random number generated by some method outside the IC chip or outside the cell array in the isolation region. Alternatively, as described above, it is also possible to store it after encryption.

[0256] Some authentication elements include capacitors. There are those where the authentication element itself is a capacitor, and those where the transistors included in the authentication element have gate capacitors. In the case of a DRAM cell, it has both a capacitor and a transistor. In this way, for authentication elements containing capacitors, the capacitance of the capacitor changes due to parasitic capacitance and parasitic resistance parasitizing on the wiring (bit lines, word lines, etc.) connected to the authentication element. Parasitic capacitance and parasitic resistance vary from authentication element to authentication element, and it is practically impossible to control them. Therefore, the variation in the capacitors included in the authentication elements can be a source of physical random numbers. Among other authentication elements containing capacitors, of particular interest are the inverter in FIG. 75 and the SRAM (Static Random Access Memory) in FIG. 77, etc.

[0257] The IC chip has a peripheral control device that operates the cell array according to an external command. The peripheral control device (or cell array control device) selects one from a plurality of authentication elements arranged on the cell array and uses this (selected authentication element). The selection method is to select a pair of one row line (selected row line) and one column line (selected column line) from the row line group and column line group stretched vertically and horizontally on the cell array. Furthermore, the cell array control device can control the voltage input to the selected authentication element and read the output from the selected authentication element.

[0258] An explanation will be given based on the characteristics of the inverter in FIG. 75.

[0259] Both Vdd and Vss are the voltages of power lines, and Vdd is higher than Vss by a predetermined voltage. The difference between Vdd and Vss is generally on the same order as the potential difference applied between the source and drain of the transistors constituting the integrated circuit on the chip, and is set so that the integrated circuit can exhibit sufficient performance. If it is too small, it is likely to be affected by environmental factors (such as temperature changes). If it is too large, it is likely to increase power consumption or cause failures of internal elements and shorten the life of the circuit.

[0260] The right side of FIG. 76 illustrates typical inverter characteristics. Vin can be applied from the selection row line. As an example, the selection row line is one word line (selected word line), that is, the input terminal is connected to the selected word line (WL). Vout is the potential of the selection column line or the voltage read out as an output from the current. When the output is a current, a capacitor or a resistor element is further used to finally convert it into a voltage. As an example, the selection column line is one bit line (selected bit line), that is, the output terminal is connected to the selected bit line (BL). The upper transistor is of P-type (P-FET or PMOSFET), and the drain-side terminal (upper) is connected to the power line to which Vdd is applied. The opposite source side (lower) is connected to the drain side (upper) of the lower transistor. The lower transistor is of N-type (N-FET or NMOSFET), and its drain side (upper) is connected to the source of the P-FET. The input terminal is connected to the gates of the N-FET and the P-FET. The output terminal is connected to the source of the P-FET and the drain of the N-FET.

[0261] The P-FET turns off when Vin is at a high voltage and turns on when Vin is at a low voltage. Conversely, the N-FET turns on when Vin is at a high voltage and turns off when Vin is at a low voltage. Therefore, when Vin is at a high voltage, the upper gate turns off and the lower gate turns on, and Vout becomes about Vss (low voltage). Conversely, when Vin is at a low voltage, the upper gate turns on and the lower gate turns off, and Vout becomes about Vdd (high voltage). That is, it has the property that the high and low of the voltage are inverted between the input and the output. This is the inverter characteristic.

[0262] That is, when the input Vin applied from the selected word line is high, the output Vout to the selected bit line is low. Conversely, when Vin is low, Vout is high. However, what will happen when Vin is near the middle of high and low (the vertical dashed line in the figure)? It is possible to adjust the voltage applied to the selected word line and deliberately apply such a voltage (test voltage) to the inverter circuit.

[0263] What is important here is the threshold variation of the transistors constituting the inverter, or the capacitances and resistances parasitic in the circuit. Generally, such threshold variations, or parasitic capacitances and parasitic resistances, have large individual differences. By changing the pair of the selected word line and the selected bit line, or by selecting a plurality of pairs of word lines and bit lines simultaneously and reading Vout, as shown on the left in FIG. 76, it is possible to obtain the frequency distribution with respect to the read Vout. This distribution (frequency distribution) will vary above and below the distribution average value. A plurality of authentication elements (inverter circuits) with such a variation in Vout are distributed on the cell array.

[0264] This variation distribution is physically random and is considered to be different for each IC chip if the bit capacity of the cell array is large enough.

[0265] Set the value above the distribution average as VH (high voltage output) and the lower side as VL (constant voltage output). The variations due to the parasitic capacitance and parasitic resistance described above are susceptible to changes in the external environment (such as temperature changes). Therefore, the vicinity of the center of the distribution has strong temperature dependence, and the authentication elements (inverter circuits) included in this range are likely to fluctuate with Vout becoming VH or VL in response to temperature changes. On the other hand, the tail part of the distribution has weak temperature dependence is and the cells included in the tail part are less likely to fluctuate in response to temperature changes. Also, when the temperature rises, the width of the variation itself tends to increase.

[0266] Considering physical non-rewritability, that is, durability against external environment changes, it seems good to collect only the authentication elements included in the tail of the distribution. At this time, the data of the authentication elements included in the upper tail distribution is VH, and the data of the authentication elements included in the lower tail distribution is VL. If VH is represented in black and VL in white, the checkerboard-like random pattern of white and black in Fig. 15 is generated. That is, this has the potential to become a unique random number (RN).

[0267] On the other hand, considering the practical infinity of the output, it seems better to generate a unique random number (RN) from the VH and VL distributions of the authentication elements included in the vicinity of the center of the distribution with a large number of bits. However, the center of this distribution has strong temperature dependence, and VH and VL will be interchanged in response to changes in temperature and other external environmental factors. This means that the checkerboard pattern of white and black in Fig. 15 changes in response to changes in temperature and other external environmental factors.

[0268] Also, with increasing temperature, the distribution width increases, and the number of authentication elements that output a relatively stable output (VH or VL) with respect to temperature conversion tends to decrease.

[0269] From such a perspective, different utilization methods of the distribution on the left in Fig. 76 are required. In the next embodiment of the present application, the addresses of a group of authentication elements with strong temperature dependence are utilized to obtain a unique random number (RN).

[0270] That is, in order to generate a unique random number (RN) inside the authentication device, the cell array control device performs the following prescription in the environment where the authentication device is placed or at a given temperature.

[0271] (1) Designate a group of authentication elements on the cell array. (2) Set the upper limit voltage (VUB) and the lower limit voltage (VLB) of the output according to an instruction from outside the IC chip. (3) Apply a test voltage to the designated group of authentication elements (the group of selected authentication elements) using the row lines associated with each selected authentication element. However, the test voltage is near the middle of the high and low of Vin in FIG. 76 (the vertical dashed line in the figure). (4) Measure the output Vout from each of the designated group of authentication elements using the column lines associated with each selected authentication element. (5) Record the addresses of the authentication elements whose Vout is between VLB and VUB. (6) Perform appropriate code conversion on the arranged addresses of the corresponding authentication elements according to the measured Vout values of the authentication elements whose addresses are recorded to obtain a unique random number (RN). (The code conversion is, for example, simply arranging Vout in descending order.) (7) Save the unique random number (RN) in an isolated area.

[0272] However, the output that can be authenticated with the output between VUB and VLB cell includes the central peak in the frequency distribution of FIG. 76. The isolated area for storing the unique random number (RN) is preferably a predetermined storage of the electronic device including the IC chip having the cell array or a predetermined memory area in the IC chip. Also, the isolated area is such that only special access from inside the IC chip or the device under test is allowed by a circuit or a physical barrier, or such that plaintext information can be accessed only for special access from inside the chip by encryption technology, hashing technology, etc. For this, the decryption key needs to be safely protected inside the device under test. To realize a circuit barrier, for example, it may not be connected to external input / output.

[0273] Note that since the information entropy increases as the variation increases, it is desirable from the viewpoint of information entry entropy to perform the above prescription in a high-temperature environment and obtain a unique random number (RN) from the IC chip constituting the authentication device of the present application. Further, even if the output of the authentication element has temperature dependence, there is no problem as long as the data stored in the isolation region has sufficient resistance to changes in the external environment.

[0274] This method of using the distribution center (left in FIG. 76) with a relatively large number of bits becomes a particularly important technique when the cell array of the authentication element uses a small-capacity IC chip. SRAM, which has a bit capacity two to three orders of magnitude smaller than DRAM, is a typical example.

[0275] In the above example, only the authentication element belonging to the center of the frequency distribution is simply used to generate the unique random number. In a more detailed method, for example, the output voltages of the selected authentication element group are read twice at different temperatures (high temperature and low temperature), and the addresses of the selected authentication elements with different output voltages in the two readings may be arranged. In this case, the prescription in step 0271 is changed as follows.

[0276] (1) Designate a group of authentication elements on the cell array. (2) Designate the output reading temperature. (3) Apply a test voltage to the designated group of authentication elements (selected authentication element group) using the row lines associated with each selected authentication element. (4) Measure the output Vout from the designated group of authentication elements using the column lines associated with each selected authentication element. (5) Change the output reading temperature and repeat (3)-(4). (6) From the addresses of the authentication elements whose output Vout has changed more than a predetermined error (for example, the value obtained by dividing 1.5 times the temperature energy by the elementary charge) in the first and second readings, arranged according to the value of Vout, perform appropriate code conversion to generate a unique random number (RN). (The code conversion is, for example, simply arranging Vout in descending order.) (7) Store the intrinsic random number (RN) in the isolation region.

[0277] FIG. 77 shows an example of a circuit diagram of a typical 6-transistor type SRAM. Inverters each consisting of two transistors are arranged on the left and right, and selection gates are arranged on both sides thereof. Thus, a total of six transistors are used. The left and right selection gates are each connected to the outer bit line (BL) and the complementary bit line (BL).

[0278] When a high voltage is applied to the word line (WL) and the left and right selection gates are turned on, BL is connected to the input of the left inverter and the output of the right inverter. At the same time, complementary BL is connected to the input of the right inverter and the output of the left inverter. In the normal usage of SRAM, when BL is at a high voltage, complementary BL is always at a low voltage (data 1), and conversely, when BL is at a low voltage, complementary BL is always at a high voltage (data 0). This is the state of statically storing information.

[0279] In this embodiment, a test voltage is applied to BL and complementary BL is read out as output data. Here, the test voltage is a voltage such that the output of the inverter varies as shown in FIG. 76. Therefore, it is different from the static state which is the data holding state of normal SRAM. Conversely, when a test voltage is applied to complementary BL, the output comes out in the opposite way. BL comes out.

[0280] If BL and complementary BL are swapped in FIG. 77, only the left and right are inverted and there is no particular change in the circuit configuration. Therefore, in the present application, as shown in FIG. 78, a test voltage is applied from the right end, and the output data Vout is read out at the left end. Since it is the same even if it is reversed, the explanation in that case is omitted.

[0281] In FIG. 78, when a high voltage is applied to WL to turn on the select gate, the test voltage is applied to the input of the left inverter, and the output of the left inverter is output as Vout through the left output terminal. A voltage equivalent to this Vout is applied to the input of the right inverter, and depending on its value, the influence of Vdd and Vss may appear in the output of the right inverter. However, the external circuit adjusts the input voltage to BL so that the test voltage can maintain a predetermined value taking this influence into account. Alternatively, it is desirable to float at least one of the line connected to Vdd and the line connected to Vss.

[0282] That is, in the circuit of FIG. 78, instead of using it as SRAM, only the left inverter is used to obtain Vout with respect to the test voltage. Therefore, it becomes possible to obtain a unique random number (RN) from the SRAM chip according to the prescription in paragraph 0271.

[0283] FIG. 79 is an example of a layout when one authentication element straddles two column lines. FIGS. 77 and 78 are typical examples of such authentication elements, where the even columns correspond to bit lines and the odd columns correspond to anti-bit lines. FIG. 80 is another example of a layout when one authentication element straddles two column lines. FIGS. 77 and 78 are typical examples of such authentication elements, where the odd columns in the even rows correspond to bit lines and the even columns correspond to anti-bit lines. Conversely, the even columns in the odd rows correspond to bit lines and the odd columns correspond to anti-bit lines. In FIGS. 77 and 78 as well, it is possible to interchange rows and columns. Since the explanation is substantially the same, it is omitted.

[0284] In the examples of FIGS. 77 to 80, the line for inputting the test voltage and the line for reading the output are not necessarily divided into row lines and column lines. Therefore, it is possible to call the line for inputting the test voltage the input line and the line for reading the output the read line.

[0285] Note that the technical scope of the present invention is not limited to the above embodiments, and various modifications can be made without departing from the spirit of the present invention.

Industrial Applicability

[0286] Chip authentication using a unique random number unique to the IC chip (or chip) of the present application is managed centrally with a test server, and communication between electronic devices having the authenticated chips as components is entrusted to distributed management such as a blockchain, and the central management and the distributed management complement each other, thereby strengthening the security of the IoT network. Further, it is desirable that the redundancy data is unique to the chip as well as the unique random number.

[0287]

Brief Description of Drawings

[0288]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Figure 29

Figure 30

Figure 31

Figure 32

Figure 33

Figure 34

Figure 35

Figure 36

Figure 37

Figure 38

Figure 39

Figure 40

Figure 41

Figure 42

Figure 43

Figure 44

Figure 45

Figure 46

Figure 47

Figure 48

Figure 49

Figure 50

Figure 51

Figure 52

Figure 53

Figure 54

Figure 55

Figure 56

Figure 57

Figure 58

Figure 59

Figure 60

Figure 61

Figure 62

Figure 63

Figure 64

Figure 65

Figure 66

Figure 67

Figure 68

Figure 69

Figure 70

Figure 71

Figure 72

Figure 73

Figure 74

Figure 75

Figure 76

Figure 77

Figure 78

Figure 79

Figure 80

Claims

1. A network of electronic devices composed of a plurality of electronic devices, Among the plurality of electronic devices, M electronic devices are the first to Mth devices to be inspected, Among the other plurality of electronic devices, at least one electronic device serves as the first inspection subject, The first to Mth devices to be inspected are the first to Mth peripheral devices respectively, The first to Mth peripheral devices each have a response function and each have an IC chip as a component, Each of the IC chips has a unique random number, The first inspection subject selects one peripheral device as the selected peripheral device from among the first to Mth peripheral devices, and inputs a challenge to the selected peripheral device, The response function generates a response from the challenge and the unique random number of the IC chip of the selected peripheral device, and the selected peripheral device returns the response to the first inspection subject, Each of the IC chips includes a cell array composed of a plurality of authentication elements, The plurality of authentication elements are arranged at intersections of a row line group and a column line group stretched in the row direction and the column direction of the cell array, The plurality of authentication elements each have first and second terminals, The first terminal is connected to an input line respectively, The second terminal is connected to an output line respectively, The output line belongs to the column line group, The input line belongs to the row line group or the column line group, The IC chip has a cell array control device for operating the cell array, The cell array control device, Selects a selected authentication element from among the plurality of authentication elements according to a command from outside the IC chip, Selects an input line connected to the selected authentication element as a selected input line, Selects an output line connected to the selected authentication element as a selected output line, Applies a test voltage to the selected input line, Reads an output voltage from the potential of the selected output line, The unique random number is an array obtained by quantifying the electrical characteristics of the plurality of authentication elements distributed in part or all of the cell array, The method for generating the unique random number includes quantifying the variation of each of the plurality of authentication elements generated during mass production of the IC chip, Alternatively, the method for generating the unique random number includes writing a random number code generated separately from the manufacture of the IC chip into part or all of the cell array, Alternatively, the method for generating the unique random number includes randomly destroying a part or the whole of the cell array. Define the address of the selection authentication element on the cell array from the pair of numbers assigned to the selection input line and the number assigned to the selection output line. The cell array control device selects a plurality of selection authentication elements from the plurality of authentication elements, and sets an upper limit voltage and a lower limit voltage according to a command from outside the IC chip. Obtain the frequency distribution of the output voltage from the plurality of selection authentication elements. Generate the unique random number from the arranged addresses of the selection authentication elements for which the output voltage is between the upper limit voltage and the lower limit voltage. A digital information communication system characterized by the above.

2. The authentication element has at least one inverter circuit. The inverter circuit has an input terminal and an output terminal. When the input to the input terminal is a high voltage, the output is about Vss, and when the input is a low voltage, the output is about Vdd. The Vdd is Higher than the Vss. When the authentication element is the selection authentication element, the input terminal is connected to the selection input line. The output terminal is connected to the selection output line. The test voltage is a voltage input to the input terminal so that the output is about in the middle between the Vdd and the Vss. The digital information communication system according to claim 1, characterized by the above.

3. The authentication element has first and second inverter circuits. The first and second inverter circuits each have first and second input terminals and first and second output terminals. The first input terminal is connected to the second output terminal and is connected to the output line via a second selection gate. The second input terminal is connected to the first output terminal and is connected to the input line via a first selection gate. The outputs of the first and second inverter circuits are about Vss when the inputs to the first and second input terminals are high voltages, and about Vdd when the inputs are low voltages. The Vdd is higher than the Vss. The test voltage is a voltage applied to the input line so that the potential of the output line is about in the middle between the Vdd and the Vss. The digital information communication system according to claim 1, characterized by the above.

4. The device under test has an isolation region. The isolation area is such that access from the outside of the device under test is realistically difficult and has durability against external environmental changes. The external environmental changes are physical stimuli from the outside world such as electric fields, electromagnetic fields, heating, temperature changes, humidity changes, impacts, vibrations, with a strength that does not destroy the package of the IC chip. The isolation area stores the unique random number. The digital information communication system according to claim 1, characterized by the above.

5. The unique random number is encrypted. The device under test stores the ciphertext of the unique random number internally. From the outside of the device under test, only access to the ciphertext is possible. From the inside of the device under test, it is possible to access the plaintext of the unique random number. The digital information communication system according to claim 1, characterized by the above.

6. The first inspection entity inputs a first challenge to the first to Mth peripheral devices. The first to Mth peripheral devices, based on the response function, return first to Mth responses to the first inspection entity respectively in response to the first challenge. The first to Mth responses form a first response set having the first to Mth responses as elements. The first inspection entity stores the first challenge and the first response set internally. The first to Mth peripheral devices generate a pair of a first to Mth secret key and a first to Mth public key respectively from the first to Mth responses. The digital information communication system according to claim 1, characterized by the above.

7. The first inspection entity inputs a first challenge to the first to Mth peripheral devices. The first to Mth peripheral devices, based on the response function, return first to Mth responses to the first inspection entity respectively in response to the first challenge. The first to Mth responses form a first response set having the first to Mth responses as elements. The first inspection entity stores the first challenge and the first response set internally. The first inspection entity inputs a second challenge to the selected peripheral device. The selected peripheral device generates an (M + 1)th response and generates a pair of an (M + 1)th secret key and an (M + 1)th public key from the (M + 1)th response. The digital information communication system according to claim 1, characterized by the above.

8. Among the network of electronic devices composed of the plurality of electronic devices, at least one electronic device different from the first to Mth peripheral devices and the first inspection entity is a second inspection entity, the first inspection entity inputs a first challenge to the first to Mth peripheral devices, the first to Mth peripheral devices, based on the response function, return first to Mth responses to the inspection entity respectively in response to the first challenge, the first to Mth responses form a first response set having the first to Mth responses as elements, the first inspection entity internally stores the first challenge and the first response set, the second inspection entity inputs a second challenge to the selected peripheral device, the selected peripheral device generates an (M + 1)th response, and generates a pair of an (M + 1)th private key and an (M + 1)th public key from the (M + 1)th response, The digital information communication system according to claim 1, characterized in that.

9. A network of electronic devices composed of a plurality of electronic devices, among the plurality of electronic devices, M electronic devices are first to Mth devices to be inspected, among the other plurality of electronic devices, at least one electronic device serves as a first inspection entity, the first to Mth devices to be inspected are first to Mth peripheral devices respectively, the first to Mth peripheral devices each have a response function and each have an IC chip as a component, the IC chip each has a unique random number, the first inspection entity selects one peripheral device as a selected peripheral device from among the first to Mth peripheral devices, and inputs a challenge to the selected peripheral device, the response function generates a response from the challenge and the unique random number of the IC chip of the selected peripheral device, and the selected peripheral device returns the response to the first inspection entity, the IC chip each includes a cell array composed of a plurality of authentication elements, the plurality of authentication elements are arranged on the intersections of a row line group and a column line group stretched in the row direction and the column direction of the cell array, the plurality of authentication elements each have first and second terminals, the first terminal is connected to an input line respectively, the second terminal is connected to an output line respectively, the output line belongs to the column line group, the input line belongs to the row line group or the column line group, The IC chip has a cell array control device for operating the cell array, The cell array control device, in accordance with an instruction from outside the IC chip, selects a selected authentication element from among the plurality of authentication elements, selects an input line connected to the selected authentication element, and sets it as a selected input line, selects an output line connected to the selected authentication element, and sets it as a selected output line, applies a test voltage to the selected input line, reads an output voltage from the potential of the selected output line, The unique random number is an array obtained by quantifying and arranging the electrical characteristics of the plurality of authentication elements distributed in part or in whole of the cell array, The method for generating the unique random number includes quantifying the variation of each of the plurality of authentication elements that occurs when the IC chip is mass-produced, alternatively, the method for generating the unique random number includes writing a random number code generated separately from the manufacture of the IC chip into part or in whole of the cell array, alternatively, the method for generating the unique random number includes randomly destroying part or in whole of the cell array, defines the address of the selected authentication element on the cell array from the pair of the number assigned to the selected input line and the number assigned to the selected output line, The cell array control device selects a plurality of selected authentication elements from among the plurality of authentication elements, and sets first and second read temperatures in accordance with an instruction from outside the IC chip, with the test voltage applied, the output read from the selected output line at the first read temperature is set as a first output voltage, with the test voltage applied, the output read from the selected output line at the second read temperature is set as a second output voltage, generates the unique random number from an arrangement of the addresses of the selected authentication elements among the plurality of selected authentication elements, for which the first and second output voltages differ by more than a predetermined error, A digital information communication system characterized by the above.

10. The authentication element has at least one inverter circuit, The inverter circuit has an input terminal and an output terminal. When the input to the input terminal is a high voltage, the output is about Vss, and when the input is a low voltage, the output is about Vdd. The Vdd is, higher than the Vss. When the authentication element is the selected authentication element, the input terminal is connected to the selected input line, the output terminal is connected to the selected output line, The test voltage is a voltage input to the input terminal such that the output is at a level approximately midway between the Vdd and the Vss. The digital information communication system according to claim 9, characterized in that.

11. The authentication element has first and second inverter circuits. The first and second inverter circuits each have first and second input terminals and first and second output terminals. The first input terminal is connected to the second output terminal and is connected to the output line via a second selection gate. The second input terminal is connected to the first output terminal and is connected to the input line via a first selection gate. When the inputs to the first and second input terminals of the first and second inverter circuits are high voltages, the outputs are at about Vss, and when the inputs are low voltages, the outputs are at about Vdd. The Vdd is higher than the Vss. The test voltage is a voltage applied to the input line such that the potential of the output line is at a level approximately midway between the Vdd and the Vss. The digital information communication system according to claim 9, characterized in that.

12. The device under test has an isolation region. The isolation region is practically inaccessible from outside the device under test and has durability against external environmental changes. The external environmental changes are physical stimuli from the outside world such as electric fields, electromagnetic fields, heating, temperature changes, humidity changes, impacts, vibrations, and of a strength that does not destroy the package of the IC chip. The isolation region stores the unique random number. The digital information communication system according to claim 9, characterized in that.

13. The unique random number is encrypted. The device under test stores the ciphertext of the unique random number internally. From outside the device under test, only the ciphertext can be accessed. From inside the device under test, it is possible to access the plaintext of the unique random number. The digital information communication system according to claim 9, characterized in that.

14. The first inspection entity inputs a first challenge to the first to Mth peripheral devices. The first to Mth peripheral devices each return a first to Mth response to the first inspection entity in response to the first challenge based on the response function. The first to Mth responses form a first response set having the first to Mth responses as elements. The first inspection entity stores the first challenge and the first response set internally. The first to Mth peripheral devices generate a pair of a first to Mth private key and a first to Mth public key respectively from the first to Mth responses. The digital information communication system according to claim 9, characterized in that.

15. The first inspection entity inputs a first challenge to the first to Mth peripheral devices. The first to Mth peripheral devices return first to Mth responses to the first inspection entity respectively according to the first challenge based on the response function. The first to Mth responses form a first response set having the first to Mth responses as elements. The first inspection entity stores the first challenge and the first response set internally. The first inspection entity inputs a second challenge to the selected peripheral device. The selected peripheral device generates an M+1th response and generates a pair of an M+1th private key and an M+1th public key from the M+1th response. The digital information communication system according to claim 9, characterized in that.

16. Among the network of electronic devices composed of the plurality of electronic devices, at least one electronic device different from the first to Mth peripheral devices and the first inspection entity is a second inspection entity. The first inspection entity inputs a first challenge to the first to Mth peripheral devices. The first to Mth peripheral devices return first to Mth responses to the inspection entity respectively according to the first challenge based on the response function. The first to Mth responses form a first response set having the first to Mth responses as elements. The first inspection entity stores the first challenge and the first response set internally. The second inspection entity inputs a second challenge to the selected peripheral device. The selected peripheral device generates an M+1th response and generates a pair of an M+1th private key and an M+1th public key from the M+1th response. The digital information communication system according to claim 9, characterized in that.

Citation Information

Patent Citations

  • Electronic signature device, electronic signature system, electronic signature method, and program

    JP2016052102A

  • Nonvolatile memory device and integrated circuit card that have resistance to protein, authentication method for nonvolatile memory device and individual identification information generating method

    JP2017011678A

  • Physical-chip-identification (PCID) of chip authentication using redundant address of semiconductor chip

    JP2017139757A

  • Electronic device network, electronic device and inspection process thereof

    JP2018011298A

  • Integrated circuit, control device, information distribution method, and information distribution system

    JP2019121884A