Authentication device, authenticatee device, authentication system, authentication method, authentication key generation device, and authentication key generation method
By leveraging the unique DNL of ADCs in IoT sensor devices, authentication is achieved with a simple and cost-effective method that maintains data integrity and enhances security.
Patent Information
- Application Number
- JP2024117552
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-07-23
- Publication Date
- 2026-01-08
- Estimated Expiration
- 2040-04-06
AI Technical Summary
Existing authentication methods for IoT sensor devices are complex, costly, and degrade the purity of measurement data, or require additional information processing that increases computational load.
Utilize the inherent differential nonlinearity (DNL) of analog-to-digital converters (ADCs) present in sensor devices to generate authentication keys without altering the measurement data, using a simple configuration and low calculation cost.
Authenticates IoT devices with a simple configuration and low computational cost, preserving the purity of measurement data and enhancing security against spoofing attacks.
Smart Images

Figure 0007795817000002 
Figure 0007795817000003 
Figure 0007795817000004
Abstract
Description
[Technical Field]
[0001] The present invention relates to an authentication device that authenticates a device to be authenticated, a device to be authenticated that is authenticated by the authentication device, an authentication system including the authentication device and the device to be authenticated, an authentication method for authenticating a device to be authenticated, an authentication key generation device that generates an authentication key, and an authentication key generation method that generates an authentication key. [Background technology]
[0002] With the rapid expansion of IoT (Internet of Things) networks around the world today, security is becoming more important than ever. The key to security in IoT networks is the sensor devices that input information. However, sensor devices at the edge of the network are often subject to strict cost constraints and are vulnerable to attacks such as spoofing and tampering.
[0003] For example, Patent Document 1 proposes an on-chip monitor circuit according to the following prior art example 1, which uses an on-chip monitor circuit in a semiconductor chip requiring security to test the semiconductor chip so as to prevent security attacks, such as embedding malicious circuits, such as Trojan horses, during the manufacturing stage of a semiconductor chip equipped with a cryptographic module.
[0004] An on-chip monitor circuit according to Prior Art 1 is an on-chip monitor circuit mounted on a semiconductor chip having a security function module that performs security function processing on an input signal and outputs a security function signal, and includes a monitor circuit that monitors a signal waveform of the semiconductor chip. The on-chip monitor circuit is characterized by including: storage means for storing data specifying a window period for testing the semiconductor chip; and control means for controlling the monitor circuit to operate during the window period when a predetermined test signal is input to the security function module.
[0005] Furthermore, for example, Patent Document 2 proposes a solid-state imaging device according to the following prior art example 2, which can ensure the tamper resistance of the unique key and thereby prevent the falsification and fabrication of images.
[0006] The solid-state imaging device according to Conventional Example 2 includes a pixel section in which a plurality of pixels, each including a photodiode, are arranged in a matrix, a readout section that reads pixel signals from the pixel section, and a key generation section that generates a unique key using at least one of pixel variation information and variation information from the readout section. This configuration ensures the tamper resistance of the unique key, thereby making it possible to prevent image tampering and fabrication. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Patent No. 6555486 [Patent Document 2] Patent No. 6606659 Summary of the Invention [Problem to be solved by the invention]
[0008] However, the on-chip monitor circuit according to the above-mentioned conventional example 1 has a problem in that the configuration becomes complicated because it needs to include a security function module that performs security function processing on an input signal and outputs a security function signal.
[0009] Furthermore, in the solid-state imaging device according to the above-mentioned conventional example 2, a special mode for generating an authentication key is added to generate the authentication key independently. Specifically, the variation in the leakage current value of each pixel is measured when the camera, which is the solid-state imaging device, is not exposed to light, and this is used as the authentication key. However, in order to pair this authentication key with the measurement data, it is necessary to insert a digital watermark or digitally sign the data using the generated authentication key, which poses the problem of either modifying the measurement data itself (so-called "digital watermark") or adding other information (so-called "digital signature").
[0010] The former, which uses "digital watermarking," significantly reduces the purity of the measurement data, which is unacceptable for photographers and filmmakers who place importance on the expression of images and videos. The latter, which uses "digital signatures," has the problem of increasing the amount of redundant information and extending loading times, and while it protects the purity of the image, it also has the problem of increasing the amount of information or requiring encryption and decryption calculations to sign.
[0011] The object of the present invention is to solve the above problems and to provide an authentication system and authentication method in which an authentication device can authenticate a device to be authenticated with an extremely simple configuration and low calculation cost compared to conventional techniques, and without degrading the purity of measurement data, as well as an authentication device and a device to be authenticated of said authentication system.
[0012] Another object of the present invention is to solve the above problems and provide an authentication key generation device and authentication key generation method that can generate an authentication key with an extremely simple configuration and low calculation cost compared to conventional techniques, and without degrading the purity of measurement data. [Means for solving the problem]
[0013] The authentication device according to the present invention comprises: An authentication device for authenticating an authenticated device that includes a conversion device that converts a predetermined input signal into conversion characteristic data using a nonlinear characteristic, a storage means for storing, in advance as an authentication key, characteristic information generated based on conversion characteristic data of a conversion device provided in the device to be authenticated and including a nonlinear characteristic inherent to the conversion device; a control means for (A) generating the characteristic information as an authenticated key based on conversion characteristic data measured by a conversion device of the authenticated device, which is input when authenticating the authenticated device, or (B) receiving the characteristic information as an authenticated key based on conversion characteristic data measured by a conversion device of the authenticated device, which is input when authenticating the authenticated device, comparing the generated or received authenticated key with the stored authentication key, and performing authentication judgment of the authenticated device based on the comparison result; Equipped with. [Effects of the Invention]
[0014] Therefore, according to the authentication device etc. of the present invention, the authentication device can authenticate the device to be authenticated with an extremely simple configuration and low calculation cost compared to conventional technology, and without degrading the purity of the measurement data, and the authentication device can easily generate an authentication key with which the authentication device can authenticate the device to be authenticated. [Brief explanation of the drawings]
[0015] [Figure 1] 1 is a block diagram illustrating a configuration example of an authentication system according to an embodiment. [Figure 2] 1. FIG. 4 is a flowchart showing an authentication key registration request process by a device to be authenticated 1 and an authentication key registration process by an authentication device 2 in the authentication system of FIG. [Figure 3] 2 is a flowchart showing an authentication request process by the authenticated device 1 and an authentication verification process by the authenticating device 2 in the authentication system of FIG. [Figure 4] 2 is a block diagram showing an example of the configuration of an AD conversion unit 15 of a sensor 30 used in the embodiment. FIG. [Figure 5A] 5 is a graph showing an example of an ideal conversion function of an AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 5B]5 is a graph showing an example of an actual conversion function of an AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 6] 6(a) is a waveform diagram showing an example of a ramp signal input to the AD converter (ADC) of the AD conversion unit 15 of FIG. 4, and FIG. 6(b) is an enlarged view of the digital output data D[N:1] in a portion of FIG. 6(a). [Figure 7A] 5 is a graph showing histogram frequencies HD for digital output data D[N:1] for actual and ideal values of AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 7B] 7B is a graph showing the frequency DNLD of the differential histogram of the least significant bit (LSB) for the digital output data D[N:1] calculated based on the graph of FIG. 7A. [Figure 8] FIG. 4 is a waveform diagram showing an example of Gaussian noise used in the embodiment. [Figure 9A] 5 is a graph showing an actual histogram distribution relating to the AD conversion characteristics of an AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 9B] 5 is a graph showing an ideal histogram distribution relating to the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 10A] 5 is a graph showing a differential histogram DNLD[LSB] for digital output data D[12:1], relating to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15-1 of FIG. 4. [Figure 10B] 5 is a graph showing a differential histogram DNLD[LSB] for digital output data D[12:1], relating to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15-2 of FIG. 4. [Figure 11] 5 is a graph showing a differential histogram DNLD[LSB] for digital output data D[12:1], relating to the LSB of the AD conversion characteristics of the AD converters (ADCs) of the four AD conversion units 15-1 to 15-4 in FIG. [Figure 12A]5 is a graph showing typical values (at 5 V and 24° C.) of a differential histogram DNLD[LSB] for digital output data D[12:1] relating to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. [Figure 12B] 5 is a graph showing a differential histogram DNLD[LSB] for digital output data D[12:1] when there is a supply voltage variation, relating to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 12C] 5 is a graph showing a differential histogram DNLD[LSB] for digital output data D[12:1] when there is temperature variation, relating to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. 4. [Figure 13A] 5 is a graph showing histogram frequencies for brightness values for the camera 50-1 of FIG. 4. [Figure 13B] 5 is a graph showing histogram frequencies for brightness values for the camera 50-2 of FIG. 4. [Figure 14A] 5 is a graph showing the differential frequency of a differential histogram with respect to brightness value, for the camera 50-1 of FIG. 4. [Figure 14B] 5 is a graph showing the differential frequency of a differential histogram with respect to brightness value, for the camera 50-2 of FIG. 4. [Figure 15] 10 is a graph showing the accuracy of clustering versus the number of training photos for five cameras clustered on 100 photos according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0016] Hereinafter, embodiments of the present invention will be described with reference to the drawings, in which the same or similar components are designated by the same reference numerals.
[0017] (Inventor's Knowledge) As mentioned above, the rapid spread of IoT networks around the world today has made security more important than ever. The key to security in IoT networks is the sensor devices that input information. However, sensor devices at the edge of the network are often subject to strict cost constraints and are vulnerable to attacks such as spoofing and tampering.
[0018] Therefore, in an embodiment of the present invention, a method for extracting the inherent characteristics of a sensor device potentially present in the data is disclosed as a method for linking digital data acquired by a sensor with the sensor device from which it originated. Such inherent characteristics can be found in the non-ideal characteristics of the device. To achieve this function without significant additional hardware costs, we considered using an analog-to-digital converter (hereinafter referred to as ADC), which is always present in any sensor device. In particular, the differential nonlinearity error (DNL) of an ADC is an important candidate for efficiently classifying the unique characteristics of a device. Furthermore, because the DNL of an ADC is difficult to physically replicate, it can also enhance the security level against spoofing attacks using physically counterfeit sensors.
[0019] (Purpose of the embodiment) Much of the security of IoT networks lies in protecting the input. Significant cost constraints at the sensor layer make implementing security measures difficult and make sensors vulnerable to spoofing and manipulation attacks. A good way to protect input is to link captured data to the device that measured it. This individual device can be identified by a physically unclonable ID registered during circuit manufacturing (Reference 1). Linking measurement data to pre-registered trusted devices ensures data origin and builds a trusted data supply chain. To extract sensor identity from measurement data without additional hardware, we can use the analog-to-digital converter (ADC) present in every sensor. ADCs exhibit a unique characteristic for each device, called differential nonlinearity (DNL), which can be used as a determinant for sensor identification. This invention focuses on extracting the ADC identity from the digital output of sensor measurement data. The goal is to use this characteristic to classify the data and the sensor that measured it.
[0020] (ADC specificity: DNL) DNL is unique to each ADC because it is the result of random and unpredictable variations in device manufacturing. Therefore, it is difficult to create a perfect physical copy of the DNL, making it safe to use against spoofing attacks that physically imitate specific sensors. In addition, all digital data output through an ADC contains (imprinted with) DNL information that is unique to each ADC and does not depend on the input.
[0021] DNL refers to the error in the transfer function between the ideal value of the least significant bit (LSB) in a binary digital code and the actual value required for the ADC to carry the code by one bit. If the output range of a certain code is greater than the ideal 1 LSB, it means that the input voltage range resulting in this code value is wider than the ideal value (Reference 2). In this invention, the measured DNL for each code can be used to create profiles for different ADCs and to create clusters of DNL characteristics for different devices.
[0022] DNL can be measured by applying a signal with a known distribution (e.g., Gaussian noise, ramp, or sine wave) to the ADC input and analyzing the histogram of the output codes (References 3, 4). When the code value is D, the histogram of the actual output codes, H, D,Actual and an ideal histogram H based on a known distribution D,Ideal By comparing the histogram with the ideal value, it is possible to determine which code values occur more or less frequently than the ideal value. The difference between the ideal and actual values in this histogram is the DNL. The formula used to calculate the DNL from the histogram is:
[0023]
number
[0024] where D is the code value.
[0025] (Embodiment) Fig. 4 is a block diagram showing an example of the configuration of the AD conversion unit 15 of the sensor 30 used in the embodiment. In Fig. 4, the sensor 30 includes a sensor front-end circuit (sensor FE circuit) 31, the AD conversion unit 15, and a processor 32. Here, the AD conversion unit 15 is, for example, a successive approximation type AD converter, and includes a subtractor 41, a nonlinear amplifier 42, a logic circuit 43, and a DA converter 44.
[0026] For example, an authentication device is important for verifying the authenticity of information handled by an authenticated device, which is an information terminal device such as a personal computer, smartphone, or tablet. By verifying which terminal device the information was obtained from, the origin can be guaranteed, and pairing is performed between the authenticated device, which is an information terminal device, and the authentication device. Most information terminal devices consist of an information input unit, an analog-to-digital conversion circuit (ADC), and a unit that manages and processes the digital data.
[0027] A typical example is the sensor 30 in Fig. 4, which is particularly configured with a sensor FE circuit 31 that converts an external physical quantity into an analog signal such as an analog voltage or analog current, an AD conversion unit 15 including an ADC, and a processor 32. Since all sensors 30 that output digital signals are equipped with an ADC, data measured by the sensor 30 always passes through the ADC. The ADC is the gateway for all sensors.
[0028] This is not limited to the sensor 30; for example, all general-purpose computing terminal devices such as personal computers that are equipped with interface devices such as keyboards and mice that come into contact with people or physical space have an ADC within the interface, and the data handled by the interface also passes through the ADC, and since this data is stored within the personal computer, the method proposed here can be used in many electronic devices such as information terminal devices.
[0029] The ADC of the AD conversion unit 15 is a circuit that converts an input analog voltage or current into, for example, a multi-bit digital code. The most common circuit configuration is an architecture represented by a successive approximation register (SAR) ADC based on binary search. The SAR ADC sequentially subtracts reference signals (reference voltages or reference currents) such as 1 / 2, 1 / 4, and 1 / 8 of the full-scale signal from an analog signal, such as an input analog voltage or current, and repeatedly determines whether the residual is positive or negative using a comparator, converting it into a binary 0-1 digital code. The reference signal is generated by a matching capacitor array or the like within the ADC. The reference signal for binary search can be generated by configuring a capacitor array in a binary format, such as C, 2C, 4C, or 8C.
[0030] By standardizing the unit capacitance and lining up the same capacitance and doubling it by two, four, eight, etc., it is possible to achieve high consistency in the reference signal and improve the linearity of the conversion characteristics. However, in reality, unpredictable and uncontrollable variations during manufacturing cause capacitance mismatch. The impact of such non-ideal variations results in variations in the conversion characteristics known as the non-linearity of the ADC, and the effects of this variation remain (are inevitably imprinted) in the resulting digital data. By extracting this non-ideal characteristic of the ADC's conversion characteristics from the data and authenticating the data with the ADC that obtained it, pairing of the data with the device that measured it is achieved.
[0031] Fig. 5A is a graph showing an example of an ideal conversion function of the AD converter (ADC) of the AD conversion unit 15 of Fig. 4. Also, Fig. 5B is a graph showing an example of an actual conversion function of the AD converter (ADC) of the AD conversion unit 15 of Fig. 4.
[0032] The ideal characteristic of an ADC is the perfectly linear staircase characteristic shown in Figure 5A (analog input voltage V IN (The conversion characteristic data is obtained by changing the input analog voltage V INWhen converting into digital code D, if the width of the analog input voltage that gives a digital code of 1 LSB, which indicates the size of the smallest bit, is all constant, then ideally, a perfectly linear characteristic will result. However, as mentioned above, due to circuit variations, the step width of this staircase characteristic will not be constant. Some widths will become larger and smaller, so an actual ADC will have nonlinear characteristics. Such nonlinear characteristics can be quantified using an index called differential nonlinearity (DNL).
[0033] (Authentication System) Next, an authentication system according to an embodiment when the DNL characteristic is used as an authentication key will be described below.
[0034] Fig. 1 is a block diagram showing an example of the configuration of an authentication system according to an embodiment. In Fig. 1, the authentication system includes a device to be authenticated 1, which is an information terminal device or electronic device such as a personal computer, smartphone, or tablet, and an authenticating device 2 having the authority and function to authenticate the device to be authenticated 1. Here, a communication unit 17 of the device to be authenticated 1 and a communication unit 24 of the authenticating device 2 are connected via a wired communication line such as a LAN or a wireless communication line such as a wireless LAN.
[0035] The device to be authenticated 1 includes a control unit 10, a read-only memory (ROM) 11, a random access memory (RAM) 12, and a solid-state drive (SSD) 13.
[0036] The control unit 10 is composed of a processor and the like that controls the operations of the processing units 11 to 17. The ROM 11 stores an operating system (OS) and the data required for executing the basic operations of the control unit 10. The RAM 12 temporarily stores programs and data required for the operation of the control unit 10. The SSD 13 stores programs (processing in FIGS. 2 and 3) and the data required for executing applied operations of the control unit 10.
[0037] The device to be authenticated 1 further includes an analog signal generating section 14 , an AD converting section 15 , a data memory 16 , and a communication section 17 .
[0038] The analog signal generating unit 14 generates a predetermined analog signal while changing it based on a control signal from the control unit 10, and outputs the signal to the AD converting unit 15. The AD converting unit 15 converts the analog signal from the analog signal generating unit 14 into digital data and outputs the digital data to the communication unit 17 via the data memory 16. The data memory 16 temporarily stores AD conversion characteristic data including the AD converted digital signal (including a large number of AD conversion characteristic data, a number sufficient for calculating a histogram and a differential histogram for generating an authentication key in the authentication device 2, for example, 1000 pieces, by repeating AD conversion using an analog signal such as an input analog voltage or an input analog current, or a signal that changes in a stepwise manner, a ramp signal, a triangular wave signal, a sine wave signal, a cosine wave signal, a Gaussian noise signal, a signal with a known signal intensity distribution, a signal with a continuous signal intensity distribution, or a signal with a partially continuous signal intensity distribution, such as a measurement data signal such as image data captured by a digital camera). The communication unit 17 is a so-called communication interface circuit, and as shown in Figures 2 and 3, transmits an authentication key registration request signal Srr or an authentication request signal Sar including AD conversion characteristic data to the communication unit 24 of the authentication device 2, or receives an authentication key registration completion signal Src or an authentication result signal Sat from the communication unit 24 of the authentication device 2.
[0039] The authentication device 2 includes a control unit 20, a ROM 21, a RAM 22, and an SSD 23 having a table memory 23m.
[0040] The control unit 20 is composed of a processor and the like that controls the operations of the processing units 21 to 26. The ROM 21 stores an operating system (OS) and the data required for executing the basic operations of the control unit 20. The RAM 22 temporarily stores programs and data required for the operation of the control unit 20. The SSD 23 stores programs (processing in FIGS. 2 and 3) and the data required for executing the applied operations of the control unit 20 (for example, table memory 23m).
[0041] The authentication device 2 further includes a communication unit 24, an authentication key generation unit 25, and an authentication unit .
[0042] 2 and 3 , the communication unit 24 is a so-called communication interface circuit, and receives an authentication key registration request signal Srr or an authentication request signal Sar including AD conversion characteristic data from the communication unit 17 of the device to be authenticated 1, or transmits an authentication key registration completion signal Src or an authentication result signal Sat to the communication unit 17 of the device to be authenticated 1. The authentication key generation unit 25 generates characteristic information including nonlinear characteristics unique to the AD conversion unit 15, which is generated based on the AD conversion characteristic data in the received authentication key registration request signal (here, characteristic information refers to nonlinear characteristic data, or an output digital data bit string of an ADC, a histogram generated based on output digital data bit strings of multiple ADCs, or a differential histogram generated based on a histogram, etc.), as an authentication key, and stores it in the table memory 23m in the SSD 23 in association with the device number of the device to be authenticated 1. Alternatively, the communication unit 24 generates characteristic information including nonlinear characteristics unique to the AD conversion unit 15, which is generated based on the AD conversion characteristic data in the received authentication request signal, as an authentication key, and outputs it to the authenticating unit 26. The authentication unit 26 compares the generated authenticated key with the authentication key stored in the table memory 23m of the SSD 23 corresponding to the device number to determine whether they substantially match, and generates an authentication signal if they substantially match, or generates a non-authentication signal if they do not substantially match and outputs it to the communication unit 24 via the control unit 20.
[0043] Here, the table memory 23m of the authentication device 2 stores, for each different device to be authenticated 1, an authentication key which is characteristic information generated based on the AD conversion characteristic data in the authentication key registration process of Figure 2, corresponding to its device number.
[0044] FIG. 2 is a flowchart showing an authentication key registration request process by the device to be authenticated 1 and an authentication key registration process by the authenticating device 2 in the authentication system of FIG.
[0045] 2, in step S1, the analog signal from the analog signal generating unit 14 is changed to generate an AD conversion characteristic for the AD converting unit 15, and this is repeated, or multiple AD conversion characteristics are generated by inputting an analog signal that depends on Gaussian noise or light intensity from a sensor front end such as a photodiode in a digital camera. Next, in step S2, an authentication key registration request signal Srr, which includes the device number of the device to be authenticated 1 and multiple AD conversion characteristic data, is transmitted from the communication unit 17 to the authenticating device 2.
[0046] In step S3, the communication unit 24 receives an authentication key registration request signal Srr from the device to be authenticated 1. Next, in step S4, characteristic information including a nonlinear characteristic unique to the AD conversion unit 15, which is generated based on the plurality of AD conversion characteristic data in the received authentication key registration request signal Srr, is generated as an authentication key and stored in the table memory 23m in the SSD 23 in association with the device number. Furthermore, in step S5, an authentication key registration completion signal Src is transmitted to the device to be authenticated 1. This completes the authentication key registration process by the authentication device 2.
[0047] In step S6, an authentication key registration completion signal Src is received from the authenticator 2, and the authentication key registration request process by the device to be authenticated 1 is terminated. Thus, the initial setting process for authenticating the device to be authenticated 1 is completed.
[0048] Fig. 3 is a flowchart showing an authentication request process by the authenticated device 1 and an authentication matching process by the authenticating device 2 in the authentication system of Fig. 1. Fig. 3 shows the authentication process for providing authentication to the authenticated device 1 after the initial setting process of Fig. 2 has been completed.
[0049] 3, the analog signal from the analog signal generating unit 14 is changed to generate an AD conversion characteristic for the AD converting unit 15, and this is repeated, or multiple AD conversion characteristics are generated by inputting an analog signal that depends on Gaussian noise or light intensity from a sensor front end () such as a photodiode in a digital camera. Next, in step S12, an authentication request signal Sar including the device number and multiple AD conversion characteristic data is transmitted from the communication unit 17 to the communication unit 24 of the authentication device 2.
[0050] In step S13, the communication unit 24 receives the authentication request signal Sar from the communication unit 17 of the device to be authenticated 1. Next, in step S14, characteristic information including a nonlinear characteristic unique to the AD conversion unit 15, which is generated based on a plurality of AD conversion characteristic data in the received authentication request signal Sar, is generated as an authenticated key, and the authenticated key is compared with the authentication key in the table memory 23m of the SSD 23 corresponding to the device number, and the authentication unit 26 determines whether they substantially match. Furthermore, in step S15, an authentication result signal Sat indicating an authentication signal is transmitted to the authentication device 1 when there is a substantial match, and an authentication result signal Sat indicating a non-authentication signal is transmitted when there is no substantial match. The authentication comparison process by the authentication device 2 is then terminated.
[0051] In step S16, an authentication result signal Sat indicating authentication or non-authentication is received from the communication unit 24 of the authentication device 2, and the authentication request process is terminated.
[0052] As described above, according to this embodiment, by executing the authentication request process and authentication key registration process of Fig. 2, characteristic information including the nonlinear characteristic inherent to the AD conversion unit 15, which is generated based on a plurality of AD conversion characteristic data of the device to be authenticated 1, which is, for example, an information terminal device, can be stored as an authentication key in the table memory 23m in association with the device number of the device to be authenticated 1. Next, by executing the authentication request process and authentication comparison process of Fig. 3, when authenticating the device to be authenticated 1, characteristic information including the nonlinear characteristic inherent to the AD conversion unit 15, which is generated based on a plurality of AD conversion characteristic data measured in the device to be authenticated 1, is generated, and this is used as the authentication key to be compared with the stored authentication key, so that if they substantially match, the device to be authenticated 1 can be authenticated, but if they do not substantially match, the device to be authenticated 1 cannot be authenticated.
[0053] In this embodiment, there is no need to use a "digital watermark" as in the conventional technology, so the purity of the measurement data does not deteriorate. Furthermore, compared to the conventional technology that uses a "digital signature," the calculation cost is extremely low because all that is required is to calculate the derivative using the frequency of the digital data bit string output by the ADC as a coefficient. Therefore, according to the authentication system of this embodiment, the authenticator 2 can authenticate the device to be authenticated 1 with an extremely simple configuration and low calculation cost compared to the conventional technology, and without deteriorating the purity of the measurement data, and the authenticator 2 can easily generate an authentication key that can authenticate the device to be authenticated 1.
[0054] (Variation) The authentication device 2 can use the following various authentication methods.
[0055] Matching can be performed simply by using pre-registered characteristic information as an authentication key and calculating the cross-correlation with the characteristic information sent at the time of authentication. Alternatively, pre-registering characteristic information using k-shape clustering and matching based on whether it can be classified into the same class as the characteristic information may be performed. For example, if the authentication unit 26 is configured with a neural network trained with the authentication key stored in the table memory 23m for matching, the parameter set of the neural network trained with multiple pieces of characteristic information at the time of pre-registration becomes the authentication key. A neural network may be configured for each identified device to be authenticated 1, and the neural network may output a Yes / No result indicating whether the device is an authenticable target device.
[0056] 1 that generates characteristic information is included in the authentication device 2, but this process may be executed in the device to be authenticated 1, and only the characteristic information may be communicated. That is, in the authentication systems of FIGS. 1 to 3, a plurality of AD conversion characteristic data are inserted into the authentication key registration request signal, but the characteristic information may be inserted instead of the plurality of AD conversion characteristic data.
[0057] In the above embodiment, measurement data of AD conversion characteristic data measured by the device to be authenticated 1 was used to pair the measurement data with the information terminal device that measures it. The primary objective was to have the authenticity of the data confirmed by the authentication device 2 and to handle the data safely. However, it may also be applied to, for example, an electronic key. It may also be configured so that the lock can be opened by verifying the ADC characteristics and authenticating the user.
[0058] In the above embodiments, measurement data that is AD conversion characteristic data, which is the nonlinear characteristic of the ADC, is used. However, the present invention is not limited to this, and a measurement device that measures measurement data that is a nonlinear characteristic, or a conversion device that converts a predetermined input signal into conversion data using a nonlinear characteristic may also be used.
[0059] The authentication device 2 includes the authentication key generation unit 25, but the authentication key generation unit 25 may be provided together with the table memory 23m in the SSD 23 and the control unit 20 to configure the authentication key generation device.
[0060] In this embodiment, the input signal input to the AD conversion unit 15 may be a signal that changes in a stepwise manner, a ramp signal, a triangular wave signal, a sine wave signal, a cosine wave signal, a Gaussian noise signal, a signal whose intensity distribution is known, a signal whose intensity distribution is continuous, or a signal whose intensity distribution is partially continuous. [Example]
[0061] (ramp signal or sawtooth wave) 6(a) is a waveform diagram showing an example of a "ramp signal" or "sawtooth wave" input to the AD converter (ADC) of the AD conversion unit 15 of FIG. 4, and FIG. 6(b) is an enlarged view of the digital output data D[N:1] in a part of FIG. 6(a). Also, FIG. 7A is a histogram frequency H of the digital output data D[N:1] for the actual value and ideal value of the AD conversion characteristic of the AD converter (ADC) of the AD conversion unit 15 of FIG. D 7B is a graph showing the frequency DNL of the differential histogram of LSB for the digital output data D[N:1] calculated based on the graph of FIG. 7A. D 1 is a graph showing
[0062] The simplest way to measure the DNL of an ADC is to input an ideal "ramp signal" or "sawtooth wave" to the input of the ADC and measure the error of the resulting digital code from an ideal straight line, as shown in Figure 6(a). However, considering that the conversion characteristics of an ADC have variations in the step width of the staircase as mentioned above, as shown in Figure 6(b), it can be seen that the DNL can also be found from a histogram analysis of the output digital code.
[0063] If the "ramp signal" or "sawtooth wave" is an ideal straight line, and the ADC also has ideal linear characteristics, the frequency of occurrence of the output digital code will be constant for all codes. This is because the step width of the conversion characteristic is constant. However, in reality, there is nonlinearity and the step width is not constant, so as shown in Figures 7A and 7B, where the width is wide, the frequency of the output digital code increases, and where the width is narrow, the frequency decreases. In other words, if you measure the difference in frequency between the actual output code and the ideal output code, it will match the DNL.
[0064] (Gaussian noise) Fig. 8 is a waveform diagram showing an example of Gaussian noise used in the embodiment. Fig. 9A is a graph showing an actual histogram distribution related to the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of Fig. 4, and Fig. 9B is a graph showing an ideal histogram distribution related to the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of Fig. 4.
[0065] If the frequency distribution of the input signal is known, not limited to the "ramp signal" or "sawtooth wave" in Figure 6, the DNL can be found according to the above formula by analyzing the error between the ideal histogram and the actual histogram. For example, if the frequency distribution of the input signal follows a Gaussian distribution as shown in Figure 8, the DNL can also be measured by taking the difference between the actual histogram of the ADC output digital code and the ideal Gaussian distribution as shown in Figures 9A and 9B.
[0066] (different ADC) To study the feasibility of using DNL for ADC characteristic extraction, the inventors measured the DNL of seven samples of the same ADC product, a commercially available 12-bit, 1 MSample / s ADC evaluation board: Analog Devices' EVALAD7091RSDZ (Reference 5). This ADC uses a switched-capacitor-based successive approximation register (SAR) architecture (Reference 6), which is the most commonly used architecture for IoT applications due to its low power and small area. DNL is primarily caused by random mismatches between element capacitors. DNL was measured multiple times using Gaussian noise, ramp waveforms, and sinusoidal waveforms generated by a Keysight 33210A 10 MHz function arbitrary waveform generator (FAWG). In all cases, the DNL was successfully measured. A Gaussian-distributed signal (so-called Gaussian noise signal) was generated from the arbitrary waveform generator and input to multiple ADCs of the same model number. The DNL for each was calculated and the results were compared. FIG. 10A shows a differential nonlinearity error DNL for digital output data D[12:1], which is related to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15-1 of FIG. D 10B is a graph showing the differential nonlinearity error DNL [LSB] for the digital output data D[12:1], which is related to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15-2 in FIG. D 10A and 10B, which relate to two different AD conversion units 15-1 and 15-2, it was found that the DNL characteristics differ for each ADC, even if they have the same model number, as can be seen visually.
[0067] FIG. 11 shows a differential nonlinearity error DNL for digital output data D[12:1], which is related to the LSB of the AD conversion characteristics of the AD converters (ADCs) of four AD conversion units 15-1 to 15-4 that have the same model number but are different. D11 is a graph showing the LSB. As is clear from Fig. 11, we measured the DNL multiple times for four ADCs of the same model number and clustered them using the well-known k-Shape clustering method, and found that they could be correctly classified. In the experiment, we used the k-Shape algorithm to successfully classify the measured DNLs for all seven ADC samples.
[0068] FIG. 12A shows a differential nonlinearity error DNL for digital output data D[12:1], which is related to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. D 12B is a graph showing typical values of [LSB] (at 5 V, 24° C.) for the differential nonlinearity error DNL for the digital output data D[12:1] when there is a supply voltage variation, which is related to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. D 12C is a graph showing the differential nonlinearity error DNL [LSB] for the digital output data D[12:1] when there is a temperature variation, which is related to the LSB of the AD conversion characteristics of the AD converter (ADC) of the AD conversion unit 15 of FIG. D 10 is a graph showing [LSB].
[0069] 12A to 12C, it was also confirmed that these DNLs hardly changed even when the temperature or operating power supply voltage changed within the range expected in everyday environments, thereby confirming the reproducibility of the results.
[0070] (different camera) It is possible to measure ADC characteristics caused by DNL even when the input signal distribution is not completely known. Generally, the distribution of the object to be measured in nature is smooth (continuous), even if it is unknown. DNL causes discontinuities in this ideally continuous distribution. In other words, by differentiating the output histogram, it is possible to highlight the inherent variation information caused by the ADC's DNL from the output digital data.
[0071] The inventors conducted experiments using a number of actual commercially available digital cameras.
[0072] A digital camera is also an information terminal device equipped with a sensor 30 represented by the model in Figure 4. A photodiode array is located in the sensor FE circuit (31 in Figure 4), and converts light into an analog voltage. Next, the analog voltage is converted into a digital code in the AD conversion unit 15, and the signal is processed and output as image data. The luminance value of the image data is the output digital code, and the characteristics of the ADC can be extracted by analyzing the frequency of this luminance value.
[0073] Fig. 13A is a graph showing the histogram frequency versus brightness value for camera 50-1 in Fig. 4, and Fig. 13B is a graph showing the histogram frequency versus brightness value for camera 50-2 in Fig. 4. Also, Fig. 14A is a graph showing the differential frequency of the differential histogram versus brightness value for camera 50-1 in Fig. 4, and Fig. 14B is a graph showing the differential frequency of the differential histogram versus brightness value for camera 50-2 in Fig. 4.
[0074] As is clear from FIGS. 13A to 14B, various everyday scenes were photographed with digital cameras, and it was confirmed whether ADC features could be extracted with each digital camera.
[0075] FIG. 15 is a graph showing the accuracy of clustering versus the number of training photos for five cameras clustered for 100 photos according to the example.
[0076] The experiment was conducted using five commercially available Canon EOS Kiss X9i digital cameras. Nearly 1,000 standard images were displayed on the display in sequence and photographed. It was found that there were differences in the frequency of brightness values even when the same image was photographed with different cameras, and that these differences were emphasized by differentiating the histogram.
[0077] As is clear from Figure 15, we experimentally verified how accurately authentication could be performed using image data obtained from five digital cameras. Using the image histogram and its differentiated histogram as input, we conducted a classification experiment using a fully connected neural network. The output of the neural network is the digital camera number, which is a number between 1 and 5. We performed training with the neural network while varying the number of images used for training, and measured the probability of correctly authenticating 100 images from each of the five cameras.
[0078] When this process was performed using only a simple histogram, the authentication accuracy did not improve even when training with 100 images. However, by training with a differentiated histogram, authentication accuracy approaching 100% was achieved even when training with only a few dozen images.
[0079] (Conclusion) As described above, we investigated the possibility of using the ADC's DNL as a unique identification parameter imprinted on digital data captured by IoT sensors. We actually measured the DNL of seven commercially available ADC samples and successfully classified each corresponding ADC sample using a well-known k-shape clustering algorithm. We also confirmed the unique effect that the built-in ADC's characteristics can be extracted from the differential histogram of measured digital data in sensors such as digital cameras, even if the input signal distribution is not completely known, and that the unique information device that measured the data can be correctly identified and classified using a well-known machine learning algorithm.
[0080] (References) References 1 to 7 used in this specification are as follows:
[0081] (Reference 1) N. Miura et al., "Chip-Package-Board Interactive PUF Utilizing Coupled Chaos Oscillators with Inductor," IEEE Journal of Solid-State Circuits, Vol. 53, No. 10, pp. 2889-2897, July 2018. (Reference 2) IEEE, "IEEE Standard for Terminology and Test Methods for Analog-to-Digital Converters," IEEE Standard 1241-2010 (Revision of IEEE Standard 1241-2000) pp. 1-139, January 2011. (Reference 3) J. Blair, "Histogram Measurement of ADC Nonlinearities Using Sine Waves," Instrumentation and Measurement, IEEE Transactions, Vol.43, No.3, pp. 373-383, June 1994. (Reference 4) R. Carneiro Martins et al, "The use of Noise stimulus in ADC characterization," Proceedings of IEEE International conference on Electron Circuits System," pp. 457-460, 1998. (Reference 5) Analog Devices, Inc. "AD7091R User Guide, UG-409, Evaluation Board for the AD7091R Analog-to-Digital Converter," [online], 2012, [Retrieved March 30, 2020], Internet<URL: https: / / www.analog.com / media / en / technicaldocumentation / user-guides / UG-409.pdf.> . (Reference 6) BP Ginsburg et al., "An Energy-Efficient Charge Recycling Approach for a SAR Converter with Capacitive DAC," Proceedings of ISCAS, July 2005. (Reference 7) J. Paparrizos, et al., "k-Shape: Efficient and Accurate Clustering of Time Series," Proceedings of the 2015 ACM SIGMOD International Conference on Management of Data, pp1855-1870, June 2015. [Industrial Applicability]
[0082] As described above in detail, the authentication system etc. according to the present invention allows the authenticating device to authenticate the device to be authenticated with an extremely simple configuration and low calculation cost compared to the prior art, and without degrading the purity of the measurement data, and also allows the authenticating device to generate an authentication key with which it can authenticate the device to be authenticated.
[0083] An authentication system can be configured using the authenticator and the authenticated device, and an authentication method for the authenticator can be used.Furthermore, an authentication key generating device and an authentication key generating method can be configured using the authentication key generating unit of the authenticator. [Explanation of symbols]
[0084] 1. Device to be authenticated 2. Authentication Device 10 Control Unit 11 ROM 12 RAM 13 SSD 14 Analog signal generator 15, 15-1 to 15-4 AD converter 16 data memories 17 Communications Department 20 Control Unit 21 ROM 22 RAM 23 SSD 23m table memory 24 Communications Department 25 Authentication key generation unit 26 Authentication Section 30 sensors 31 Sensor front-end circuit (sensor FE) 32 processors 41 Subtractor 42 Nonlinear Amplifier 43 Logic Circuits 44 DA converter 50, 50-1, 50-2 Camera
Claims
1. an analog-to-digital converter that converts a predetermined analog signal into an analog-to-digital conversion characteristic including a differential nonlinearity error; a measuring means for measuring a differential nonlinearity error of the analog-to-digital conversion characteristic; a control means for transmitting an authentication key registration signal including the differential nonlinear error to an authentication device in order to register the differential nonlinear error of the measured analog-to-digital conversion characteristic as an authentication key for the device to be authenticated, and for transmitting an authentication request signal including the differential nonlinear error to the authentication device in order to request authentication of the device to be authenticated; An authenticated device comprising:
2. The present invention further comprises an authentication key generation means for calculating a histogram of a differential nonlinear error of the analog-to-digital conversion characteristic and generating the histogram of the differential nonlinear error as the authentication key. The authenticatee device according to claim 1 .
3. The authenticated device according to claim 1 or 2; an authentication device including a control means for performing authentication by comparing an authentication key generated using the differential nonlinear error of the measured analog-to-digital conversion characteristic with an authentication key of the authenticated device stored in advance in a storage means; An authentication system comprising:
4. an analog-to-digital converter converting a predetermined analog signal into an analog-to-digital conversion characteristic including a differential nonlinearity error; a measuring means for measuring a differential nonlinearity error of the analog-to-digital conversion characteristic; a control means for transmitting an authentication key registration signal including the differential nonlinear error to an authentication device in order to register the differential nonlinear error of the measured analog-to-digital conversion characteristic as an authentication key for the device to be authenticated, and transmitting an authentication request signal including the differential nonlinear error to the authentication device in order to request authentication of the device to be authenticated; An authenticated method including:
Citation Information
Patent Citations
Physical anti-duplication function circuit using resistive memory device
JP2017514190A
PUF (physically unclonable function) code generation device and PUF code authentication system
JP2018142816A
PUF device, PUF identification device, and PUF device identification method
JP2019047323A
Data generation device, authentication device, and authentication system
JP2019220869A
On-chip monitor circuit and semiconductor chip
JP6555486B2