Random number generation circuit
Patent Information
- Application Number
- JP2022050403
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-25
- Publication Date
- 2025-06-02
- Estimated Expiration
- 2042-03-25
AI Technical Summary
Existing random number generators using ring oscillators (ROs) face challenges in generating high-entropy random numbers stably due to periodicity issues and sensitivity to environmental factors like heat generation, leading to errors in randomness tests.
A random number generation circuit that includes a sampling circuit, periodicity detection circuit, randomness test circuit, and control circuit to divide random numbers, adjust RO oscillation periods, and perform randomness tests, ensuring high entropy and stability through feedback loops and redundancy.
The circuit effectively reduces errors in randomness tests by limiting changes in RO oscillation cycles and regenerating erroneous random numbers, ensuring high-entropy outputs with improved reliability and efficiency.
Smart Images

Figure 00000016_0000 
Figure 00000017_0000 
Figure 00000017_0001
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to a random number generation circuit.
Background Art
[0002] With the development of information and communication technologies, the requirements for information security have been increasing. Random numbers are used in key generation, authentication, etc., which are essential for information security technology, and the quality of random numbers is extremely important for security. Generally, in a random number generator composed of digital circuits, a ring oscillator (hereinafter also referred to as RO) is often used as a noise source. RO is required to have high reliability as a source of high-entropy data.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] An embodiment aims to provide a random number generation circuit that can stably generate random numbers with high entropy.
Means for Solving the Problems
[0005] The random number generation circuit of the embodiment includes a sampling circuit that captures the oscillation output of a ring oscillator using a first clock to generate a random number value, a periodicity detection circuit that detects the periodicity of the output of the sampling circuit, a randomness test circuit that performs a randomness test on the output of the sampling circuit, and a control circuit that changes the oscillation period of the oscillation output based on the detection result of the periodicity detection circuit, divides the random number output into a plurality of divided random numbers, performs random number generation for each of the divided random numbers, and executes the randomness test for each generation of the divided random numbers.
Brief Description of the Drawings
[0006] [Figure 1] A block diagram showing a random number generation circuit according to one embodiment of the present invention. [Figure 2] Figure 1 shows a circuit diagram illustrating a specific example of the configuration of an FF42 with enabler. [Figure 3] Figure 1 shows a circuit diagram illustrating a specific example of the configuration of an FF42 with enabler. [Figure 4] A circuit diagram showing an example of a specific configuration for the RO21 with a variable oscillation period. [Figure 5] A circuit diagram showing an example of the circuit configuration of the periodicity detection circuit 25 and the randomness test circuit 26. [Figure 6] A circuit diagram showing an example of the circuit configuration of the randomness test circuit 26. [Figure 7] A circuit diagram showing an example of the circuit configuration of part of the periodicity detection circuit 25 and the randomness test circuit 26. [Figure 8] A circuit diagram showing an example of the circuit configuration of part of the periodicity detection circuit 25 and the randomness test circuit 26. [Figure 9] A flowchart illustrating the operation of this embodiment. [Figure 10] A timing chart showing the operating timing of this embodiment. [Figure 11] Timing chart during periodicity detection. [Figure 12] Timing chart during randomness testing. [Figure 13] A timing chart illustrating the enable signal SHIFTENy_p3 supplied to the shift register group 40. [Figure 14] A timing chart illustrating a specific example of the operation of the embodiment. [Figure 15] A timing chart illustrating a specific example of the operation of the embodiment. [Modes for carrying out the invention]
[0007] Embodiments of the present invention will be described in detail below with reference to the drawings.
[0008] (Embodiment) Figure 1 is a block diagram showing a random number generation circuit according to one embodiment of the present invention. In this embodiment, a randomness test circuit is provided in an RO unit including a ring oscillator (RO), and random numbers of a predetermined number of bits are divided and generated into multiple parts. A randomness test is performed for each divided random number (hereinafter referred to as a divided random number), thereby reducing the amount of drift in the oscillation period change of the RO due to heat generation such as RO oscillation, reducing the number of errors in the randomness test, and enabling the stable acquisition of high-entropy random numbers.
[0009] In Figure 1, the random number generation circuit 1 is composed of a control circuit 10, a plurality of RO units 20_0, 20_1…, 20_n (hereinafter, these RO units are collectively referred to as RO unit 20), a post-processing circuit 30, a shift register group 40, a retry counter 50, and a comparator 60. The control circuit 10 controls the operation of the RO units 20, the shift register group 40, and the retry counter 50. The random number generation circuit 1 is composed of logic circuits such as NAND gates, NOR gates, and flip-flops. Logic circuits are generally functionally described as source code in a hardware description language based on input and output signal specifications, flowcharts, and timing charts, and are realized by converting the source code into logic circuits using a logic synthesis tool. The random number generation circuit 1 receives instructions for random number generation from a higher-level system such as a host device (not shown) and generates random numbers. The random number generation circuit 1 is also input to a system clock CK (not shown) and an asynchronous reset RESETN. The flip-flops (FFs) used in the random number generation circuit 1 are fed the system clock CK. The FFs take the input on the rising edge of the system clock CK and use it as their output. With an asynchronous reset RESETN=0, all FFs in the random number generation circuit 1 are initialized to 0.
[0010] The configurations of RO units 20_0 to 20_n are identical to each other. RO unit 20 has two ring oscillators (RO) 21a and 21b. RO 21a and 21b have identical configurations and oscillate with a period that depends on the operating temperature, voltage, circuit configuration, wiring length, manufacturing variations, etc., and alternately output a logic value of "1" or "0". RO 21a is the main oscillator circuit, and RO 21b is the backup oscillator circuit for RO 21a.
[0011] The oscillation output of RO21a is supplied to FF22a. FF22a takes the oscillation output of RO21a in synchronization with the system clock CK (not shown) input to the random number generation circuit 1 and outputs it to FF23a. FF23a takes the output of FF22a in synchronization with the system clock CK and outputs it to the input terminal (0) of selector 24. The oscillation output of RO21b is supplied to FF22b. FF22b takes the oscillation output of RO21b in synchronization with the system clock CK and outputs it to FF23b. FF23b takes the output of FF22b in synchronization with the system clock CK and outputs it to the input terminal (1) of selector 24. Selector 24 is controlled by a selection signal (Select) from the control circuit 10 and selects either input terminal (0) or input terminal (1) to output either the output of FF23a or the output of FF23b.
[0012] The oscillation output of RO21a and 21b (hereinafter referred to as the RO oscillation output) is asynchronous with the system clock CK. FF22a and 22b (hereinafter referred to as FF22 for representing these FFs) sample the RO oscillation output respectively with the system clock CK that is asynchronous with the RO oscillation output. When the period of the RO oscillation output (hereinafter referred to as the RO oscillation period) and the clock period of the system clock CK are close to a multiple relationship, the phase relationship between the RO oscillation output and the system clock CK is difficult to change, the value of the RO oscillation output captured at the rising edge of the system clock CK is likely to be the same, and the output of FF22 is likely to be a fixed value continuously. When the RO oscillation period and the clock period of the system clock CK are exactly in a multiple relationship, the output of FF22 is a fixed value continuously. When the system clock CK period is not a multiple of the RO oscillation period, the output of FF22 becomes data with periodicity determined by the least common multiple of the system clock CK period and the RO oscillation period. Also, there may be a timing when the rising edge of the system clock CK overlaps with the rising edge or falling edge of the RO oscillation output. Due to the jitter (fluctuation) of the RO oscillation output and the metastable state of FF22, the output of FF22 becomes an irregular value. This irregular value leads to entropy and becomes the source of randomness.
[0013] In addition, when a metastable state occurs in FF22, the output of FF22 becomes temporarily unstable. By capturing the outputs of FF22a and FF22b respectively with the second-stage FFs 23a and 23b (hereinafter referred to as FF23 for representing these FFs), it is possible to obtain the determined data after the metastable state subsides. Thus, a sampling circuit for the RO oscillation output is constituted by FF22 and 23. Due to the jitter of the RO oscillation output and the metastable state of FF22, irregular values can be obtained from FF23. This irregularity is entropy, and as described above, the greater the entropy, the more the security strength in authentication using random numbers can be improved. Since the entropy obtained from FF23 is small, the post-processing circuit 30 accumulates the entropy.
[0014] Selector 24 outputs the output of FF23 selected based on the selection signal (Select) from the control circuit 10 to the post-processing circuit 30. The post-processing circuit 30 accumulates the entropy of the output (RO unit output) of the selector 24 and increases the entropy input to the shift register group 40.
[0015] The post-processing circuit 30 includes FFs 31_0, 31_1, …, 31_n (hereinafter collectively referred to as FF31 for the sake of simplicity) and exclusive OR circuits (hereinafter referred to as EXOR) 32_0, 32_1, …, 32_n (hereinafter collectively referred to as EXOR32 for the sake of simplicity). One input terminal of each of EXOR32_0, 32_1, …, 32_n is supplied with the output data of RO units 20_0, 20_1, …, 20_n, respectively. FFs 31_0, 31_1, …, 31_n each receive the output of EXOR32_0, 32_1, …, 32_n, capture the input data in synchronization with the system clock CK, and output it to the other input terminal of each of RO units 20_0, 20_1, …, 20_n.
[0016] EXOR32_0, 32_1, …, 32_n perform a two-input exclusive OR operation, output to FFs 31_0, 31_1, …, 31_n, and also output to EXOR33. EXOR33 receives the outputs of EXOR32_0, 32_1, …, 32_n, performs an exclusive OR operation on these inputs, and outputs the result as the output of the post-processing circuit 30 to the shift register group 40.
[0017] Due to the self-feedback loop formed by FF31 and EXOR32, the RO unit output is added, and entropy is accumulated in FF31. Also, the outputs of each EXOR32 are added by EXOR33. By adding the entropy of the RO unit outputs of each RO unit 20 by EXOR33, it becomes possible to output data with increased entropy to the shift register group 40. That is, even when the entropy of the FF23 output is relatively low, it is possible to obtain high-entropy data by the post-processing circuit 30.
[0018] In the feedback loop between FF31 and EXOR32, for example, the output of the RO unit is repeatedly added, for example, four times. In this case, since the RO unit 20 outputs 1 bit of data per system clock CK, the loop between FF31 and EXOR32 outputs 1 bit of data once every 4 system clock CK. This 1 bit of data is output to the shift register group 40 via EXOR33.
[0019] In this embodiment, random number generation is divided as described later. For example, random number generation is divided into four parts to generate four divided random numbers, and the shift register group 40 has four stages of shift registers 41_0, 41_1, 41_2, and 41_3 (hereinafter, these shift registers are collectively referred to as shift register 41) corresponding to these four divided random numbers. Note that the number of bits in the random number and the number of divided random numbers are not limited to four, and can be set to an appropriate number.
[0020] Each shift register 41 has the same configuration and has m stages (e.g., 256 stages) of enable-enabled FF42s. The output of EXOR33 is input to the first stage enable-enabled FF42 of the shift register 41. The enable-enabled FF42 is allowed to take data from its input terminal by the enable signal SHIFTENy_p3 (y is 0 to 3), and outputs the data from its input terminal to its output terminal in synchronization with the system clock CK. Each enable-enabled FF42 outputs its output to the input terminal of the next stage enable-enabled FF42. The outputs of the enable-enabled FF42s from the first stage to the last stage become the bit values of the output (random number output) of the random number generation circuit 1.
[0021] Figures 2 and 3 are circuit diagrams showing specific examples of configurations for the enable-enabled FF42 in Figure 1. The example in Figure 2 uses a selector 42a and FF42b to configure the enable-enabled FF42. The example in Figure 3 uses a D-latch 43a, an AND circuit 43b, and FF43c to configure the enable-enabled FF42.
[0022] In Figure 2, selector 42a receives the input signal DIN to the enabled FF42 at input terminal (1) and the output of FF42b at input terminal (0). Selector 42a selects either the input signal DIN or the output of FF42b and outputs it to FF42b based on the enable signal SHIFTENy_p3. When input terminal (1) of selector 42a is selected by the enable signal SHIFTENy_p3, the enabled FF42 functions as a normal flip-flop. When input terminal (0) of selector 42a is selected by the enable signal SHIFTENy_p3, the enabled FF42 retains its output.
[0023] The post-processing circuit 30 outputs, for example, one bit of data every four clock cycles of the system clock CK. The enable signal SHIFTENy_p3 causes the selector 42a to take in the output of the post-processing circuit 30 at a timing corresponding to the output of the post-processing circuit 30. As a result, the output of the post-processing circuit 30 every four clock cycles of the system clock CK is sequentially input to each shift register 41 and transferred to each enable FF42. In this way, for example, 256 bits of output can be obtained from one 256-stage shift register 41 every 1024 clock cycles of the system clock CK. By sequentially switching the shift register 41 that takes in the output from the post-processing circuit 30 using shift registers 41_0, 41_1, 41_2, and 41_3, a random number output of 256 × 4 = 1024 bits can be obtained from each shift register 41.
[0024] In Figure 3, a gated clock module is formed by the D latch 43a and the AND circuit 43b. This gated clock module receives the enable signal SHIFTENy_p3 when the system clock CK is "0", and if the received enable signal is "1", the AND circuit 43b provides the system clock CK to the FF43c when the system clock CK next becomes "1". As a result, the FF43c outputs the input signal DIN based on the system clock CK for the period specified by the enable signal SHIFTENy_p3. In this way, the circuit in Figure 3 can also be configured to have an enable function similar to that in Figure 2.
[0025] In this embodiment, each RO unit 20 is provided with a periodicity detection circuit 25 and a randomness test circuit 26. As described above, when the clock period of the system clock CK is close to a multiple, the RO unit output tends to remain at a fixed value, and the entropy becomes small. The periodicity detection circuit 25 detects the periodicity of the RO unit output, and based on the detection result, the control circuit 10 controls the oscillation period of RO 21.
[0026] Figure 4 is a circuit diagram showing an example of a specific configuration for the RO21 with a variable oscillation period.
[0027] In Figure 4, RO21 is composed of a NOR circuit N1, an EXOR27, delay elements IN1, IN2, IN3, and a selector SE1. The output of EXOR27 is input to terminal (00) of selector SE1, the output of delay element IN1 is input to terminal (01), the output of delay element IN2 is input to terminal (10), and the output of delay element IN3 is input to terminal (11). Selector SE1 selects and outputs the inputs of terminals (00), (01), (10), or (11) respectively, based on, for example, a 2-bit selection signal SEL[1:0] from the control circuit 10 (00), (01), (10), or (11). The output of selector SE1 is supplied to one input terminal of the NOR circuit N1 and also supplied to FF22 as the output of RO21. The signal INIT from the control circuit 10 is input to the other input terminal of the NOR circuit N1. EXOR27 has the output of the NOR circuit N1 as input to one input terminal and the STOP signal from the control circuit 10 as input to the other input terminal.
[0028] The NOR gate N1 functions as an inverter when the INIT signal is "0", and when the INIT signal is "1", its output is fixed at "0". The EXOR gate 27 outputs the input as is when the STOP signal is "0", and functions as an inverter when the STOP signal is "1".
[0029] Let's assume that the INIT signal is "0" and the STOP signal is "0". In this case, EXOR27 outputs the output of NOR circuit N1 as is. If selector SE1 is selected to terminal (00), the output of NOR circuit N1 is supplied to one input terminal of NOR circuit N1 via EXOR27 and selector SE1, and RO21 is configured as a single-stage inverter and oscillates at a specific period. Here, the oscillation period depends not only on the operating temperature and voltage, but also on the circuit's manufacturing process, the driving capability of the circuit used, the wiring width and length used for circuit connection, and other manufacturing variations. If the STOP signal is "1", EXOR27 functions as an inverter, so RO21 is configured as a two-stage inverter and stops oscillating. Also, if the INIT signal becomes "1", NOR circuit N1 outputs a fixed value, and RO21 stops oscillating.
[0030] In other words, the STOP signal controls oscillation when set to "1" to stop oscillation and when set to "0" to control oscillation. The INIT signal controls the initialization and stopping of the RO oscillation output when set to "1", and is "0" during normal operation.
[0031] When selector SE1 selects terminal (01), one delay element is inserted into the loop of NOR circuit N1, EXOR27, and SE1, lengthening the oscillation period of RO21. When selector SE1 selects terminal (10), two delay elements are inserted into the loop of NOR circuit N1, EXOR27, and SE1, further lengthening the oscillation period of RO21. Furthermore, when selector SE1 selects terminal (11), three delay elements are inserted into the loop of NOR circuit N1, EXOR27, and SE1, resulting in the longest oscillation period of RO21.
[0032] For example, suppose the period of the system clock CK (hereinafter referred to as the system clock period) is 120 ns, and the RO oscillation period is 10 ns when the selection signal SEL[1:0]=(00) is applied to selector SE1. Also, suppose that changing the selection signal SEL by one step increases the number of delay elements in the loop of NOR circuit N1, EXOR27, and SE1 by one, and the RO oscillation period becomes 2 ns longer. That is, in this case, when the selection signal SEL[1:0]=(01) is applied to selector SE1, the RO oscillation period becomes 12 ns, when the selection signal SEL[1:0]=(10) is applied to selector SE1, the RO oscillation period becomes 14 ns, and when the selection signal SEL[1:0]=(11) is applied to selector SE1, the RO oscillation period becomes 16 ns.
[0033] In other words, when the selection signal SEL[1:0]=(00),(01), the system clock period and the RO oscillation period are multiples, but when the selection signal SEL[1:0]=(10),(11), the system clock period and the RO oscillation period are not multiples. That is, by changing the selection signal SEL, it is possible to prevent the system clock period and the RO oscillation period from being multiples.
[0034] Although Figure 4 shows an example in which RO21 can generate four RO oscillation periods, the number of periods that RO21 can generate is not limited to four, and it may be configured to generate an appropriate number of RO oscillation periods.
[0035] (Periodic detection circuit / Randomness test circuit) The periodicity detection circuit 25 performs periodicity detection on the RO unit output, for example, by determining the following two conditions: (a1) and (b1). If either condition (a1) or (b1) is met, the periodicity detection circuit 25 outputs a warning to the control circuit 10.
[0036] (a1) When the same logic bit appears 10 times in a row (b1) When 3 bits or 4 bits of the same logic continue for 24 consecutive clock cycles When a warning is output from the periodicity detection circuit 25, the control circuit 10 changes the oscillation period of RO21. This can sometimes resolve the warning.
[0037] The randomness test circuit 26 performs a randomness test on the RO unit output, for example, by determining the following three conditions (a2) to (c2). If any one of the conditions (a2) to (c2) is met, the randomness test circuit 26 outputs an error to the control circuit 10.
[0038] (a2) When the same logic bit appears 21 times in a row (b2) If the same value as the leading bit appears 589 or more times, or 435 or less times, within the 1024 bits. (c2) When 10 bits, 12 bits, 14 bits, and 16 bits of the same logic continue for 152 consecutive clock cycles. The control circuit 10 controls each part to generate divided random numbers by dividing a random number, and the randomness test circuit 26 performs a randomness test on the RO unit output that is the source of the divided random numbers. If an error is detected by the randomness test circuit 26 on the RO unit output that is the source of the divided random numbers, the control circuit 10 regenerates the divided random number that had the error.
[0039] Jitter generated in RO21 of RO unit 20 (fluctuations in the RO oscillation period and timing fluctuations in the rising and falling edges of the RO oscillation output) and metastable generated in FF22 are sources of entropy. However, the RO oscillation period changes due to heat generated during RO oscillation. If the amount of change in the RO oscillation period is large, the opportunities for the RO oscillation period and the system clock CK clock period to be multiples increase. When the RO oscillation period and the system clock CK clock period are close to being multiples, a fixed value follows the output of FF23, making it difficult to obtain entropy from FF23, and errors are more likely to occur in the randomness test circuit 26. In this embodiment, by dividing the random number generation and shortening the randomness test period, the amount of change in the RO oscillation period due to the effects of heat generation etc. is reduced, making it less likely for errors to occur in the randomness test. Even if an error occurs, the divided random number that caused the error is regenerated to obtain a high-entropy random number.
[0040] Figure 5 is a circuit diagram showing an example of the circuit configuration of a periodicity detection circuit 25 and a randomness test circuit 26 that enables periodicity detection and randomness testing based on the above condition (a1) or (a2) (one bit of the same logic occurring C times consecutively).
[0041] In Figure 5, x is the output of the RO unit, en1st is a signal that is "1" for only one clock cycle at the start of the periodicity detection / randomness test, and en2nd_to_last is a signal that is "1" from the next clock cycle after the start of periodicity detection / randomness until the end of periodicity detection / randomness. Also, a is the value obtained by capturing x with EN="1" (en1st="1" or x_a_not_equal="1"), and x_a_not_equal is a signal that is "1" when x and a are different.
[0042] When en1st becomes "1" at the start of the periodicity detection / randomness test, the input x is taken into FF71 by the output of the OR circuit 70 and output as a to the comparator 72. The comparator 72 compares x and a and outputs the comparison result of whether they match or not to the AND circuit 73. The AND circuit 73 also has en2nd_to_last as input, and when x=a, the AND circuit 73 outputs "1" for each system clock CK. When "1" is input to UP, the synchronous counter 75 adds 1 to the value it holds and outputs the addition result to the comparator 76.
[0043] The output of comparator 72 is also supplied to inverter 74, which outputs x_a_not_equal, which becomes "1", as the logical value of x changes sequentially as it is input. Because x_a_not_equal is "1", FF71 takes x and outputs a to comparator 72. Furthermore, when x_a_not_equal, which is "1", is input to SET1, the synchronous counter 75 initializes its held value to 1. In this way, the count value of the synchronous counter 75 increases until the logic of x is reversed.
[0044] The comparator 76 is given a set value C, and outputs "1" when the count value of the synchronous counter 75, i.e., the number of consecutive identical logic sequences, reaches the set value. The set value C is, for example, 10 in the periodicity detection circuit 25 and 21 in the randomness test circuit 26.
[0045] The "1" output of comparator 76 is supplied to one input terminal of AND circuit 78 via OR circuit 77. The inverted signal of en1st is input to the other input terminal of AND circuit 78 via inverter 80, and AND circuit 78 outputs the "1" output from OR circuit 77 to FF79 after the start of the periodicity detection / randomness test. FF79 outputs the "1" output from AND circuit 78 as an error or warning at the timing of the rising edge of the system clock CK. The output of FF79 is held until en1st becomes "1". That is, the output of FF79 indicates a warning or error output according to the conditions of (a1) or (a2) above.
[0046] Figure 6 is a circuit diagram showing an example of the circuit configuration of the randomness test circuit 26 that enables the randomness test under the conditions of (b2) above. In Figure 6, the same components and signals as in Figure 5 are denoted by the same reference numerals and their explanations are omitted.
[0047] In Figure 6, enlast_p1 is a signal that is "1" for only one clock cycle after the periodicity detection / randomness test is completed. When en1st becomes "1" at the start of the periodicity detection / randomness test, the input x is taken up by FF71 and output to comparator 72 as a (the value of the leading bit). Comparator 72 compares a (the value of the leading bit) with the input x, and outputs "1" to the synchronous counter 75 via AND gate 73 if x has the same logic as the leading bit.
[0048] When "1" is input to UP, the synchronous counter 75 adds 1 to its current value and outputs the result to the comparator 76. When "1" is input to SET1, the synchronous counter 75 initializes its current value to 1. In this way, the count value of the synchronous counter 75 represents the same number of bits as the logical value of the leading bit at the start of the periodicity detection / randomness test.
[0049] The output of the synchronous counter 75 is supplied to comparators 82 and 83. Comparator 82 compares the count value of the synchronous counter 75 with the set value C1, and outputs "1" to the OR circuit 77 if the count value is greater than or equal to the set value C1. Comparator 83 also compares the count value of the synchronous counter 75 with the set value C2, and outputs "1" to the OR circuit 77 if the count value is less than or equal to the set value C2. The OR circuit 77 outputs "1" to the FF84 when at least one of its two inputs is "1". The set value C1 is set to 589, and the set value C2 is set to 435. The FF84 outputs the "1" output from the OR circuit 77 as an error at the timing of the rising edge of the system clock CK during the period when enlast_p1 is "1". That is, the output of the FF84 indicates an error output under the conditions of (b2) above.
[0050] Figures 7 and 8 are circuit diagrams showing an example of the circuit configuration of a periodicity detection circuit 25 and a randomness test circuit 26 that enable periodicity detection and randomness testing under the conditions (b1) or (c2) above (n bits of the same logic are continuous for T clocks). In Figures 7 and 8, the same components and signals as in Figure 5 are denoted by the same reference numerals and their explanations are omitted. The circuits of the periodicity detection circuit 25 and the randomness test circuit 26 include the circuits shown in Figures 7 and 8.
[0051] Figure 7 shows a shift register. The shift register in Figure 7 contains 2n flip-flops (FFs) connected in cascades. These FFs output their inputs to the next stage FF. The outputs of each FF are R1[X] and R2[X] (where X is 0 to n-1). The RO unit output x is input to the first stage FF. The first n FFs sequentially shift the RO unit output by n system clock CK, and the n FFs from the nth stage sequentially shift the output R1[n-1] of the (n-1)th stage by n system clock CK. Therefore, R1[X] and R2[X] represent RO unit outputs shifted by n bits.
[0052] Figure 8 includes multiple comparators 72_0, 72_1, ..., 72_n (hereinafter, these comparators will be collectively referred to as comparator 72). Comparator 72_0 is input to R1[0] and R2[0]. Similarly, comparator 72_1 is input to R1[1] and R1[2]. Likewise, comparator 72 is input to R1[X] and R2[X]. Each comparator 72 outputs "1" to the AND circuit 81 when the logic of its two inputs matches. The AND circuit 81 outputs "1" when the outputs of all comparators 72 are "1". That is, the AND circuit 81 outputs "1" when the n bits of consecutive RO unit outputs have the same logic, and when the n bits of consecutive RO unit outputs have the same logic. In other words, the output "1" of the AND circuit 81 indicates a state where n bits of the same logic are consecutive.
[0053] The output of the AND circuit 81 is provided as a det signal to the AND circuit 85 and inverter 86. The AND circuit 85 provides the output of the AND circuit 81 to the synchronous counter 75 after en2nd_to_last becomes "1". The inverter 86 inverts the output of the AND circuit 81 and outputs it to the OR circuit 87. The OR circuit 87 outputs the logical OR of the signal en1st, which is "1" for only one clock cycle at the start of the periodicity detection / randomness test, and the output of the inverter 86 to the SET1 terminal of the AND circuit 78. As a result, the synchronous counter 75 is initialized by the "1" output of the AND circuit 81 after the start of the periodicity detection / randomness test and counts up the "1" of the AND circuit 85.
[0054] Thus, the synchronous counter 75 outputs a count value indicating how many consecutive clock cycles the same n bits of logic in the RO unit output have continued. The output of the synchronous counter 75 is supplied to the comparator 76. The comparator 76 is given a set value T-2n, and when the count value of the synchronous counter 75, i.e., the number of consecutive clock cycles the same n bits of logic have continued, reaches the set value, it outputs "1". The output of the comparator 76 is output from the FF79 via the OR circuit 77 and the AND circuit 78. That is, the FF79 outputs a warning or error output according to the conditions of (b1) or (b3) above.
[0055] Furthermore, to detect 3 bits of the same logic continuing for 24 consecutive clock cycles, set n=3 and T=24; to detect 4 bits of the same logic continuing for 24 consecutive clock cycles, set n=4 and T=24; to detect 10 bits of the same logic continuing for 152 consecutive clock cycles, set n=10 and T=152; to detect 12 bits of the same logic continuing for 152 consecutive clock cycles, set n=12 and T=152; to detect 14 bits of the same logic continuing for 152 consecutive clock cycles, set n=14 and T=152; and to detect 16 bits of the same logic continuing for 152 consecutive clock cycles, set n=16 and T=152 to configure each part accordingly.
[0056] To perform all periodicity detection and randomness tests, it is simply necessary to implement six different configurations. However, if a configuration for n=16 (32 flip-flops) is available for the shift register, it can be shared. Similarly, the synchronous counter 75 can be shared by prioritizing the det signal, which becomes 1 first.
[0057] At the start of random number generation, the control circuit 10 first causes the selector 24 to select terminal (0). This enables periodicity detection by the periodicity detection circuit 25 for the RO unit output based on the output of RO21a. When a warning is issued by the periodicity detection circuit 25, the control circuit 10 increments the value of SEL[1:0] by 1. After four warnings are issued by the periodicity detection, the control circuit 10 sets the value of SEL[1:0] to "0" and causes the selector 24 to select terminal (1) using the selection signal Select. From this point onward, periodicity detection by the periodicity detection circuit 25 is performed for the RO unit output based on the output of RO21b. If the selection signal Select is SEL[2], the control circuit 10 will increment the value of SEL[2:0] by 1 when a warning is issued.
[0058] When an error occurs in the RO unit 20, the control circuit 10 causes the retry counter 50 to count the number of errors. The retry counter 50 counts the number of errors and outputs the count result to the comparator 60. When the count result of the retry counter 50 exceeds a predetermined threshold, the comparator 60 outputs an error output (error notification) indicating that an error has occurred in random number generation to a higher-level system such as a host device (not shown).
[0059] (action) Next, the operation of the embodiment configured in this way will be described with reference to Figures 9 to 15. Figure 9 is a flowchart illustrating the operation of this embodiment. Figure 10 is a timing chart showing the operation timing of this embodiment.
[0060] In this embodiment, an example is described in which a 1024-bit random number output is divided into four 256-bit partitioned random numbers. Since the post-processing circuit 30 outputs 1 bit every 4 clock cycles, a 1024-bit RO unit output is output from the RO unit 20, generating one partitioned random number.
[0061] (overview) Figure 10 shows the timing of operations until a 1024-bit random number output is obtained. Note that the example in Figure 10 shows the case where no errors are determined as a result of the randomness test. In Figure 10, the timing of each operation is indicated by the duration of the arrows, corresponding to the start signal (START) that instructs the start of random number generation supplied from a higher-level system such as a host device (not shown) and the busy signal (BUSY) output from the control circuit 10.
[0062] Random number generation begins with a pulse from the start signal. First, during a 256-clock (hereinafter, "clock" refers to the system clock CK) warm-up period, seven periodicity detections are performed. Once the warm-up period ends, a 256-bit partitioned random number is generated using the 1024-bit RO unit output, which is output over a period of 1024 clocks, and a randomness test is performed. Error checking and periodicity detection are performed for the randomness test over the next 34 clocks. Subsequently, the generation of partitioned random numbers and error checking are repeated three times to obtain a 1024-bit random number output.
[0063] (Preparation period) In Figure 9, when the start signal pulse is input to the control circuit 10, it first sets the enable signal SHIFTENy_p3, which controls the shift register group 40, to y=0 (S1). Next, the control circuit 10 performs a warm-up period (S2).
[0064] (Periodic detection) To obtain a high-entropy random number output, the system clock period and the RO oscillation period must not be multiples of each other. Therefore, a 256-clock warm-up period is provided before random number generation to adjust the RO oscillation period. In the example in Figure 4, RO21a and 21b can each be set to four different oscillation periods. Thus, by switching the RO oscillation period up to seven times, it is possible to perform a periodicity test of the RO unit output based on the RO oscillation output that can be generated by RO21. A 3-bit selection signal SEL[2:0] is used as the selection signal SEL for changing the RO oscillation period, with the lower two bits of the selection signal SEL[1:0] used to change the period of RO21 and the upper one bit of the selection signal SEL[2] used to switch selector 24.
[0065] Specifically, the control circuit 10 sequentially switches the selection signal SEL[1:0] for RO21a from (00) to (01), (10), and (11), and also sequentially switches the selection signal SEL[1:0] for RO21b from (00) to (01), (10), and (11). When the final selection signal SEL[1:0]=(11) for RO21b is set, there are no further periods to switch, so the RO oscillation output of the RO oscillation period based on this selection signal SEL[1:0]=(11) is used for subsequent generation of divided random numbers.
[0066] Figure 11 shows the timing chart during periodicity detection. Figure 11 shows the selection signal SEL[2:0], signal INIT, signal PDET_en1st, and signal PDET_en2nd_to_last. Note that in Figure 11, the signals en1st and en2nd_to_last from Figures 5 and 8, which are supplied to the periodicity detection circuit 25, are shown as signal PDET_en1st and signal PDET_en2nd_to_last, respectively.
[0067] The control circuit 10 initializes the RO oscillation output by changing the INIT signal from "0" to "1" upon input of the start signal pulse, and then returns the INIT signal to "0". The control circuit 10 waits for the first 4 clock cycles after this initialization as a warm-up period. Next, the control circuit 10 sets en1st, which indicates the start of periodic detection, to "1" for one clock cycle, and then sets the en2nd_to_last signal to "1" from the clock cycle following the start of periodic detection until the end of periodic detection. The periodic detection circuit 25 receives these signals and performs periodic detection. In the example in Figure 11, the periodic detection circuit 25 performs periodic detection in 24 clock cycles, and in the next 3 clock cycles, it determines whether the conditions are met and notifies the control circuit 11 of the determination result. In this way, the periodic detection circuit 25 performs one periodic detection in 32 clock cycles.
[0068] When a warning result from periodicity detection is supplied to the control circuit 10 from the periodicity detection circuit 25, the control circuit 10 increases the selection signal SEL[2:0] by +1. For example, immediately after the pulse input of the start signal, the selection signal SEL[2:0] = (000), and each time a warning occurs, the selection signal SEL[2:0] changes to (001), (010), (011), ... In this way, when a warning occurs, the RO oscillation period of RO21 is switched. For example, immediately after the pulse input of the start signal, the selector 24 is supplied with the selection signal Select (SEL[2] = (0)), and the FF23 output from RO21a is selected. However, when the fourth warning occurs, the control circuit 10 changes the selection signal SEL[2] = (1) and selects the FF23 output from RO21b. In this case, the selection signal Select[2] remains at (1) until random number generation is completed.
[0069] Regardless of whether a warning is issued, periodicity detection is performed seven times. Once the seven periodicity detections are complete, the control circuit 10 proceeds to random number generation and randomness testing after a 32-clock waiting period (S3).
[0070] (Partitioned random number generation and randomness testing) Figure 12 shows the timing chart during the randomness test. Figure 12 shows the signals RTEST_en1st, RTEST_en2nd_to_last, and RTEST_enlast_p1. Note that in Figure 12, the signals en1st, en2nd_to_last, and enlast_p1 from Figures 5, 6, and 8, which are supplied to the periodicity detection circuit 26, are shown as signals RTEST_en1st, RTEST_en2nd_to_last, and RTEST_enlast_p1, respectively.
[0071] At the start of the period for divided random number generation and randomness testing, the control circuit 10 first sets the enable signal SHIFTENy_p3, which controls the shift register group 40, to y=0. Every clock cycle, the RO unit output is output to the post-processing circuit 30 and the randomness test circuit 26. The FF31 and EXOR32 of the post-processing circuit 30 add the RO unit outputs for a period of 4 clock cycles and output the sum result to EXOR33. EXOR33 adds up the outputs of all EXOR32 and outputs the result. The output from EXOR33 is taken into the shift register group 40 as 1 bit of data once every 4 clock cycles. Therefore, a 256-bit divided random number is generated from the 1024-bit RO unit output. The data output from EXOR33 is first stored as a divided random number in the shift register 41_0.
[0072] Figure 13 is a timing chart illustrating the enable signal SHIFTENy_p3 supplied to the shift register group 40. The control circuit 10 generates the enable signal SHIFTENy_p3 during the period when the signal SHIFTENy is "1". The control circuit 10 generates SHIFTENy_p0 once every four clock cycles using the system clock CK from the signal SHIFTENy=1. Furthermore, it delays SHIFTENy_p0 by one clock cycle using the system clock CK to generate SHIFTENy_p1, SHIFTENy_p2, and SHIFTENy_p3, and supplies SHIFTENy_p3, which is generated once every four clock cycles, to the shift register group 40. As described above, each enable-enabled FF42 of shift registers 41_0~4 takes in and outputs input data when the enable signals SHIFTEN0_p3, SHIFTEN1_p3, SHIFTEN2_p3, and SHIFTEN3_p3 are "1", respectively.
[0073] At the start of the partitioned random number generation and randomness test period, the enable signal SHIFTEN0_P3 causes the data output from EXOR33 to be sequentially transferred to each enabled FF42 once every four clock cycles. In this way, a 256-bit partitioned random number is held in the shift register 41_0.
[0074] At the start of the divided random number generation and randomness test period, as shown in Figure 12, the control circuit 10 sets the signal en1st, which indicates the start of the randomness test, to "1" for one clock cycle, and then sets the signal en2nd_to_last to "1" from the clock cycle following the start of the randomness test until the end of the randomness test. Every clock cycle, the RO unit output is input to the randomness test circuit 26. The randomness test circuit 26 receives each of the signals shown in Figure 12 and performs the randomness test.
[0075] Specifically, the randomness test circuit 26 performs a randomness test on the 1024-bit RO unit output that generates the divided random numbers. As shown in Figure 10, the randomness test circuit 26 checks the result of the randomness test in the next two clock cycles after the randomness test on the 1024-bit RO unit output (S4). If the result of the randomness test is error-free (NO judgment in S4), the control circuit 10 determines the termination condition, which is whether or not a random number output of the number of bits requested by the host device, etc., has been generated (S7). If there are no errors in the randomness test and the divided random numbers have been stored in all the shift registers 41 of the shift register group 40, that is, if y=3, a 1024-bit random number output has been generated and the termination condition is satisfied (YES judgment in S7), so the control circuit 10 terminates the process (normal termination).
[0076] If there are no errors in the randomness test and the termination condition is not satisfied (NO judgment in S7), the control circuit 10 increments y in the next S8 and then performs periodicity detection once. In this case, as shown in Figure 10, the periodicity detection shown in Figure 11 is performed once at 32 clock cycles after the 2-clock period of error checking. If no warning occurs in the periodicity detection (NO judgment in S9), the control circuit 10 returns to S3, sets the enable signal SHIFTENy_p3 (y=1) to "1" once every 4 clock cycles, and transfers the next generated divided random number to the shift register 41_1. Thereafter, the divided random numbers are transferred to all shift registers 41 in the same manner to obtain a 1024-bit random number output. On the other hand, if a warning occurs in the periodicity detection (YES judgment in S9), the control circuit 10 moves to S2 to perform a warm-up period and then performs the next random number generation. Note that the RO unit output during the 2-clock period for checking the results of the randomness test and the subsequent 32-clock periodicity detection period or run-up period is not used for the randomness test or random number output.
[0077] On the other hand, if the randomness test result is found to have an error (YES judgment in S4), the randomness test circuit 26 outputs the error to the control circuit 10. In this case, the control circuit 10 instructs the retry counter 50 to count up (S5). The comparator 60 determines whether the count value of the retry counter 50 has reached its upper limit (S6). If the count value of the retry counter 50 has not reached its upper limit (NO judgment in S6), the control circuit 10 proceeds to S2 to perform a warm-up period, and then repeats the generation of partitioned random numbers and the randomness test. In this case, the partitioned random numbers that were determined to have an error in the previous randomness test are discarded, and the newly generated partitioned random numbers are used for random number output. If the count value of the retry counter 50 reaches its upper limit (YES judgment in S6), the comparator 60 generates an error output (error notification) based on the output of the retry counter 50 and terminates the random number generation process. The error output is supplied to the host device, etc.
[0078] (Specific examples of actions) Next, specific examples of operation will be explained with reference to the timing charts in Figures 14 and 15. Figure 14 is a timing chart showing random number generation when a warning occurs during the second periodicity detection in the pre-run period. Figure 15 is a timing chart showing random number generation when a warning occurs during the second periodicity detection in the pre-run period, and an error occurs in the randomness test on the RO unit output that generates the first divided random number. The signal names in Figures 14 and 15 are the same as the signal names in the explanation above. The enable signal SHIFTENy_p3 will be denoted as the enable signal SHIFTENy(y=0~3). The warning from the periodicity detection circuit 25 will be denoted as PDET_warning, and the error from the randomness test circuit 26 will be denoted as RTEST_error. The error from the comparator 60 when the count value of the retry counter 50 exceeds the upper limit will be denoted as RNG_ERROR, and the random number output including the divided random number will be denoted as RNG_OUT[1023:0].
[0079] In Figure 14, after the pulse input of the start signal (START), the RO oscillation output is initialized by the INIT signal, and the RO oscillation period of RO21a is set by the selection signal SEL[2:0]=(000). Periodicity detection is started by PDET_en1st, and periodicity detection is performed during the "1" period of PDET_en2nd_to_last. As shown in Figure 14, regardless of whether a warning occurs or not, seven periodicity detections are performed during the 32 × 7 clock run-up period.
[0080] In the example in Figure 14, a warning (PDET_warnning) is issued from the periodicity detection circuit 25 after the second periodicity detection. This causes the selection signal SEL[2:0] to change to (001), and the RO oscillation period of RO21a is changed. Subsequently, during the pre-cycle period, no warnings are issued from the periodicity detection circuit 25, and the RO oscillation output with an RO oscillation period based on the selection signal SEL[2:0]=(001) is used for random number generation.
[0081] 32 clock cycles after the warm-up period, the randomness test is initiated by RTEST_en1st, and during the "1" period of RTEST_en2nd_to_last, until the end of the randomness test by RTEST_enlast_p1, the division random number generation and the randomness test of the RO unit output that generates these division random numbers are performed.
[0082] In the example in Figure 14, no errors occurred in the randomness test circuit 26, and after the division random number generation and randomness test, one periodicity detection was performed using PDET_en1st and PDET_en2nd_to_last. Thereafter, division random number generation, randomness test, and periodicity detection were repeated. Since no errors occurred during the randomness test on the fourth division random number generation, random number generation ended in the example in Figure 14, and the busy signal (BUSY) became "0". Thus, in the example in Figure 14, four 256-bit division random numbers were generated, and a 1024-bit random number output was obtained.
[0083] In Figure 15, the operation during the warm-up period is the same as in Figure 14. Also, similar to Figure 14, 32 clock cycles after the warm-up period, the randomness test is started by RTEST_en1st, and during the period of "1" in RTEST_en2nd_to_last, until the end of the randomness test by RTEST_enlast_p1, partitioned random number generation and randomness testing of the RO unit output that generates these partitioned random numbers are performed.
[0084] In the example in Figure 15, the error check of the randomness test during the first division random number generation results in an RTEST_error from the randomness test circuit 26. When the control circuit 10 receives this RTEST_error, it sets the run-up period again. That is, as shown in Figure 15, the control circuit 10 initializes the RO oscillation output with the INIT signal, selects terminal (0) of the selector 24 with the selection signal SEL[2:0]=(000), and returns the RO oscillation period of RO21a to its initial state. The control circuit 10 starts periodicity detection with PDET_en1st and performs periodicity detection during the "1" period of PDET_en2nd_to_last. As shown in Figure 15, regardless of whether a warning occurs or not, seven periodicity detections are performed during the 32 × 7 clock run-up period.
[0085] In the example shown in Figure 15, no warning (PDET_warnning) was issued by the periodicity detection circuit 25 during the 7th periodicity detection period, and the RO oscillation period of RO21a remained unchanged. Therefore, the RO oscillation output with an RO oscillation period based on the selection signal SEL[2:0]=(000) is used for random number generation.
[0086] After 32 clock cycles from the warm-up period, the randomness test is initiated by RTEST_en1st. During the "1" period of RTEST_en2nd_to_last, until the end of the randomness test by RTEST_enlast_p1, a randomness test is performed on the output of the RO unit that generates these partitioned random numbers. In this case, the first partitioned random number that previously resulted in an error is discarded, and a new first partitioned random number is generated, and a randomness test is performed on the 1024-bit RO unit output that generates this new partitioned random number.
[0087] In the example in Figure 15, no further errors occur from the randomness test circuit 26. After the division random number generation and randomness test, one periodicity detection is performed using PDET_en1st and PDET_en2nd_to_last. Then, the division random number generation, randomness test, and periodicity detection are repeated. Since no errors occur during the randomness test on the fourth division random number generation, random number generation ends in the example in Figure 15, and the busy signal (BUSY) becomes "0". Thus, in the example in Figure 15 as well, 256-bit division random numbers are generated four times, and a 1024-bit random number output is obtained.
[0088] In the example in Figure 15, an error occurred during the randomness test when generating the first partitioned random number, so the generation restarted from the first partitioned random number generation. However, if an error occurred in the randomness test for a partitioned random number, the generation should be restarted for that partitioned random number. For example, if an error occurs during the randomness test when generating the third partitioned random number, the generation should be restarted from the third partitioned random number generation. Note that each time an error occurs in the randomness test, the retry counter 50 counts up, and when the count reaches the upper limit, an RNG_ERROR is generated indicating that an error occurred in random number generation, and random number generation terminates.
[0089] In this embodiment, random numbers are generated by dividing them into a predetermined number of divided random numbers, and a randomness test circuit is provided within the RO unit to perform a randomness test on the output of the RO unit that generates the divided random numbers. Since the divided random numbers are generated in a shorter time than the random number generation time when the numbers are not divided, the amount of change in the RO oscillation period due to the effects of heat generation etc. can be limited, reducing the occurrence of errors in the randomness test and enabling the acquisition of random numbers with high entropy values. Furthermore, since periodicity detection is performed for each generation of divided random numbers, the RO oscillation period can be changed to one that is more likely to yield high entropy. In addition, even if an error occurs in the randomness test, it is possible to set the RO oscillation period to avoid the error, so if an error in the randomness test occurs accidentally due to a change in the RO oscillation period due to the effects of heat generation etc., the error notification to the higher system is notified until the error count of the randomness test reaches the upper limit, thereby improving the efficiency of random number generation. Furthermore, if the error count of the randomness test reaches the upper limit, it is possible to notify the higher system of a failure. Furthermore, since it has two RO (Reverse Oscillator) systems, one for the main oscillator circuit and one for the backup oscillator circuit, it also has the effect of being highly reliable against failures and degradation.
[0090] The present invention is not limited to the embodiments described above, and can be modified in various ways during implementation without departing from its essence. Furthermore, the embodiments described above include inventions at various stages, and various inventions can be extracted by appropriate combinations of the multiple constituent elements disclosed. For example, if some constituent elements are deleted from all the constituent elements shown in the embodiments, and the problem described in the section on the problem the invention aims to solve is solved and the effect described in the section on the effect of the invention is obtained, then the configuration with these constituent elements deleted can be extracted as an invention. [Explanation of symbols]
[0091] 1...Random number generation circuit, 10...Control circuit, 20...RO unit, 21, 21a, 21b...RO, 22, 22a, 22b, 23, 23a, 23b, 31...FF, 24...Selector, 25...Periodicity detection circuit, 26...Randomness test circuit, 27, 32, 33...EXOR, 30...Post-processing circuit, 40...Shift register group, 41...Shift register, 42...FF with enable, 50...Retry counter, 60...Comparator.
Claims
1. a sampling circuit that captures an oscillation output of the ring oscillator using a first clock and generates a random number value; a periodicity detection circuit for detecting the periodicity of the output of the sampling circuit; a randomness test circuit for testing the randomness of the output of the sampling circuit; a control circuit that changes the oscillation period of the oscillation output based on the detection result of the periodicity detection circuit, divides the random number output into a plurality of divided random numbers, generates a random number for each of the divided random numbers, and executes the randomness test for each divided random number generated; A random number generation circuit comprising:
2. The control circuit When an error is detected as a result of executing the randomness test for each generation of the divided random numbers, the oscillation period is changed based on the detection result of the periodicity detection circuit, the divided random numbers that are the subject of the error are discarded, and new divided random numbers are generated and the randomness test is executed. The random number generating circuit according to claim 1 .
3. The control circuit performing one or more detections of the periodicity prior to the randomness test, and varying the oscillation period based on the detection results; 3. The random number generating circuit according to claim 1.
4. When an error is detected as a result of executing the randomness test for each generation of the divided random numbers, the control circuit counts the number of times the error has occurred, and when the count value reaches an upper limit, issues an error notification.
3. The random number generating circuit according to claim 2.
5. a first ring oscillator; a second ring oscillator; and a selector that selects one of the oscillation outputs of the first and second ring oscillators; a sampling circuit that captures the oscillation output from the selector using a first clock and generates a random number; a periodicity detection circuit for detecting the periodicity of the output of the sampling circuit; a randomness test circuit for testing the randomness of the output of the sampling circuit; a control circuit that changes the oscillation period of the oscillation output based on the detection result of the periodicity detection circuit, divides the random number output into a plurality of divided random numbers, generates a random number for each of the divided random numbers, and executes the randomness test for each divided random number generated; A random number generating circuit comprising:
6. the control circuit controls the selector based on the detection result of the periodicity detection circuit; 6. The random number generating circuit according to claim 5.