Tamper detection
The tamper detection system employs a strong-type PUF and CAM table to protect integrated circuits from physical tampering by ensuring that any alteration of the PUF response probabilities prevents the reconstruction of the cryptographic key, thereby maintaining the security of the integrated circuit.
Patent Information
- Application Number
- PCT/US2024/060388
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-12-16
- Publication Date
- 2025-06-26
AI Technical Summary
Integrated circuits with secure cryptographic keys and circuitry are vulnerable to tampering when physically accessed, allowing attackers to modify the chip and extract or circumvent the secure information.
A tamper detection system utilizing a strong-type physically unclonable function (PUF) circuit generates multiple fingerprint outputs in response to challenges, which are stored and used to populate a content-addressable memory (CAM) table. This system challenges the PUF with enrolled challenges and checks for responses in the CAM table to verify the integrity of the cryptographic key.
The system effectively prevents unauthorized access by ensuring that any tampering alters the PUF response probabilities, making it impossible to reconstruct the complete cryptographic key if the system has been tampered with, thus maintaining the security of the integrated circuit.
Smart Images

Figure US2024060388_26062025_PF_FP_ABST
Abstract
Description
TAMPER DETECTIONBRIEF DESCRIPTION OF THE DRAWINGS
[0001] Figure 1 is a block diagram illustrating a first example tamper detection system.
[0002] Figure 2 is a block diagram illustrating a second example tamper detection system.
[0003] Figure 3 is a diagram illustrating an example pre-tamper strong-type physically uncloneable function (PUF) response probability histogram..
[0004] Figure 4 is a diagram illustrating an example post- tamper strong -type physically uncloneable function (PUF) response probability histogram.
[0005] Figure 5 is a flowchart illustrating a method of enrolling a strong-type PUF.
[0006] Figure 6 is a flowchart illustrating a first example method of detecting tampering.
[0007] Figure 7 is a flowchart illustrating a second example method of detecting tampering.
[0008] Figure 8 is a flowchart illustrating a method of operating a tamper detecting system.
[0009] Figure 9 is a block diagram illustrating an example strong-type PUF.
[0010] Figure 10 is a block diagram of a processing system.DETAILED DESCRIPTION OF THE EMBODIMENTS
[0011] Many electronic devices (e.g., cell phones, tablets, set-top boxes, etc.) use integrated circuits ("ICs") that have secure cryptographic keys and secure cryptographic circuitry. These keys and circuitry may be used, for example, to secure data on the device, to secure communication, and / or to authenticate the device. It is desirable to protect the keys and / or other information used by the device from disclosure (thereby protecting the data on the device, preventing unauthorized use, etc.)
[0012] When an attacker has physical access to the integrated circuit (e.g., by purchasing a device, by stealing one, etc.), attacks designed to learn the secure cryptographic keys and / or circumvent the secure cryptographic circuitry can be carried out by modifying (i.e., tampering with) the chip in some manner. A chip may be modified for the purpose of these attacks using, for example, a focused ion beam (“FIB”) workstation. A FIB machine can cut tracks in a chip’s metallization layer, deposit new metal tracks, deposit new isolation layers, remove material (e.g., bulk silicon) to facilitate probing of circuits and signals, implant ions to change the doping of an area of silicon, and build conductors to structures in the lowerlayers of the chip. One or more of these types of modifications can be used to help learn the secure cryptographic keys and / or circumvent the secure circuitry.
[0013] A physically unclonable function circuit (“PUF”) may be used to generate a chipunique “digital fingerprint” based on the uniqueness of the physical characteristics (e.g., resistance, capacitance, connectivity, etc.) of a tamper prevention (i.e., shielding) structure realized on an integrated circuit. The physical characteristics include random physical factors (e.g., mismatch) introduced during manufacturing. This causes the chip-to-chip variations in these physical characteristics to be unpredictable and uncontrollable. In general, PUF circuits rely on unique physical variations which occur naturally and inevitably during integrated circuit manufacturing to provide one or more physically-defined digital fingerprints that may serve as a unique identifiers for a semiconductor device. In common nomenclature, a “weak PUF” is a circuit that generates a single, highly-reliable fingerprint output value in response to a first enrollment process and then subsequent regeneration process, whereas a “strongtype PUF” is a circuit that generates numerous fingerprint outputs, each in “response” to an input “challenge,” and each with varying reliability. In other words, while a weak PUF typically utilizes one enrollment process to achieve highly reliable digital fingerprints, the enrollment of a strong-type PUF typically requires the assertion of a large number of challenges. In an embodiment, these challenges which generate the most reliable responses are stored for future use (e.g., in on-chip non-volatile memory). In an embodiment that achieves tamper resistance (i.e., a “tamper-evident PUF”), not only are the enrolled challenges stored for future use, but the enrolled responses are stored as well, where the responses selected have a relatively low probability of occurring. Thus, when the system is to determine whether it has been tampered with, the PUF is challenged with each stored challenge value. To determine if tampering has occurred, the enrolled responses are used to populate a searchable memory table (a.k.a., content-addressable memory function - CAM function) where each enrolled response is associated with a key portion or key portion indicator. The system then iteratively challenges the PUF multiple times for each of the stored challenges and uses the responses by the PUF as a search key for the CAM function. If a response is found in the populated CAM function, the key portion or key portion indicator associated with that CAM entry is used to provide part of a larger cryptographic key. If all of the stored enrolled challenges result in at least one response that is a CAM “hit”, then the complete cryptographic key can be assembled. If any one of the challenges does not result in a CAM “hit”, the cryptographic key will be incomplete thereby preventing any functions that depend upon the cryptographic key from being accessed and / or performed.
[0014] Figure 1 is a block diagram illustrating a first example tamper detection system. In Figure 1, tamper detection system 100 comprises control circuitry 101, physically unclonable function (PUF) circuitry 110, searchable memory table function (a.k.a., content addressable memory function) 120, nonvolatile memory 130, key source 140, and key register 150. Control circuitry 101 is operatively coupled to PUF circuitry 110, CAM function 120, nonvolatile memory 130, key source 140, and key register 150. However, for the sake of clarity in Figure 1, some of the operational couplings are not illustrated in Figure 1.
[0015] In an embodiment, PUF circuitry 110 is configured as a strong-type PUF function. A strong-type PUF function generates different response values when provided with different challenge values. Strong-type PUF function responses may be probabilistic in nature. In other words, providing (or applying) the same challenge value results in multiple response values being generated. The multiple response values generated by a strong-type PUF have likelihoods of occurrence that follow a distribution that may be unique to each challenge value. For example, a first challenge value may result in the top four generated responses occurring, in order, 50%, 30%, 10%, and 5% of the time, while a second challenge value may result in the top four generated responses occurring, in order, 80%, 10%, 5%, and 1% of the time. In an embodiment, PUF circuitry 110 includes tamper detection structures that, when subject to tampering, may cause one or more of the probability distributions to changes. For example, after tampering, the likelihood of occurrence for the first challenge value for the top four generated responses may change from 50%, 30%, 10%, and 5% to, for example, 35%, 30%, 25%, and 20% (and / or, for example, a new response may now occur in the top four likelihoods).
[0016] Nonvolatile memory 130 is operatively coupled with PUF circuitry 110 to provide PUF circuitry 110 with challenges 132 determined during an enrollment process. Nonvolatile memory 130 is also operatively coupled with CAM function 120 to provide CAM function 120 with responses 131 associated with challenges 132. The output of PUF circuitry 110 is operatively coupled with CAM function 120 to query CAM function 120 with responses by PUF circuitry 110 to challenges 132. Key source 140 is operatively coupled with CAM function 120 to provide CAM function 120 with key portions 14 la- 141c.
[0017] CAM function 120 is operatively coupled with key register 150 and control circuitry 101. CAM function 120 is operatively coupled with control circuitry 101 to provide an indication that CAM function 120, when queried, has determined that a given response 131 a- 131c generated by PUF circuitry 110 has or has not been detected to be present in CAMfunction 120. CAM function 120 is operatively coupled with key register 150 to, when a given response 131 a- 131c has been determined to be present in CAM function 120, provide a key indicator 141a-141c to key register 150. The reconstruction of a correct and complete cryptographic key value in key register 150 assembled from key indicators 141 a- 141c received from CAM function 120 in response to PUF circuitry 110 responses 131 a- 131c querying CAM function 120 is an indicator that tamper detection system 100 has not been tampered with. In other words, even if the adversary were to obtain the full contents of NVM 130 and the key source 140, they would not be able to reassemble the correct key if the system 100 had been tampered with. The lack of a reconstruction of a correct and complete cryptographic key value in key register 150 assembled from key indicators 141 a- 141c received from CAM function 120 in response to PUF circuitry 110 responses 131 a- 131c querying CAM function 120 is an indicator that tamper detection system 100 has been tampered with.
[0018] Nonvolatile memory (NVM) 130 stores challenges 132 and associated responses 131. In particular, nonvolatile memory 130 stores challenges 132a- 132c that respectively are associated with responses 13 la-131c. In an embodiment, NVM 130 also stores the values used by key source 140 (e.g., key source 140 may be a tamper-resistant key derivation function that is operative coupled to NVM 130). In an embodiment, challenges 132a-132c were provided to PUF circuitry 110 during an enrollment process (e.g., during manufacturing and / or test of tamper detection system 100) and respectively resulted in the associated response 131 a- 131c by PUF circuitry 110. In an embodiment, the storage arrangement and / or other information (e.g., identifying information, labels, tags, etc.) stored or provided by nonvolatile memory 130 about challenges 132a- 132c and responses 13 la-131c are organized in a way that does not associate individual challenges 132a- 132c with the respective responses 131 a- 131c that resulted from PUF circuitry 110 being challenged with that challenge 132a- 132c. For example, the locations and / or storage order of the challenges 132a- 132c may be in sequential order (e.g., the first through thirty-second challenges in sequential order), while the associated responses 131 a- 131c may be randomized (e.g., a randomized sequence of the first through thirty-second responses) when stored in nonvolatile memory 130.
[0019] PUF circuitry 110 includes tamper detection structures 111. During initialization, CAM function 120 may be populated (e.g., by control circuitry 101) with responses 13 la- 131c stored by nonvolatile memory 130. CAM function 120 may store responses 13 la-131cin a manner that associates each response 131 a- 131c with a key indicator 141 a- 141c. Key indicators 141 a- 141c may be provided by key source 140.
[0020] During the regeneration phase, challenges 132a- 132c are applied to PUF circuitry 110, and the output response is provided as an input to the CAM function 120. CAM function 120 is populated with responses 131-131c (stored by nonvolatile memory 130) and respective associations with key indicators 14 la- 141c. CAM function 120 may be populated (e.g., by control circuitry 101) with responses 131-131c and respective associations with key indicators 141 a- 141c during or in response to a reset and / or power-up process.
[0021] Key indicators 141a-141c are generated by key source 140. Key source 140 may be or comprise, for example, one or more of PUF circuitry (e.g., a traditional “weak PUF” relying on error-correction for long-term stability), a fixed value in secure non-volatile memory, the output of a key derivation function, and so on. In an embodiment, key indicator 14 la- 141c are reproducibly generated each time system 100 is reset and / or powered up. In an embodiment, key indicators 14 la- 141c are stored in the same non-volatile memory 130 as are the responses 13 la-131c. In an embodiment, key indicator 141a-141c are provided to the protected IC during a manufacturing process (e.g., during final test of the IC).
[0022] In an embodiment, key indicators 141a-141c are portions (e.g., a byte) of a larger cryptographic key (e.g., a 32-byte cryptographic key). In an embodiment, key indicator 14 la- 141c are pointers to values that are reproducibly generated each time system 100 is reset and / or powered up. In an embodiment, key indicators 141a-141c or the values pointed to by key indicators 141a-141c are portions (e.g., a byte) of a larger cryptographic key (e.g., a 32-byte cryptographic key). Thus, key source 140 may generate a larger cryptographic key and then provide key indicators 141 a- 141c to CAM function 120 to be used to assemble a complete and correct version of this larger cryptographic key in association with position information (e.g., first- in-time first- in-location / address, position ordinal, key index, etc.) for each respective key indicator’s 141a-141c position in the larger cryptographic key. In an embodiment, each respective key indicator’s 141a-141c position indicator is determined by its location (e.g., address) in CAM function 120.
[0023] Based on response values generated by PUF circuitry 110 in response to a provided challenge, CAM function 120 determines whether the response value provided as an input query to the CAM function 120 is present in CAM function 120 (i.e., whether the response value has been populated within the CAM memory). If a given response value is not present in CAM function 120, CAM function 120 provides an indicator (e.g., a “miss” indicator) that the given response value is not present in CAM function 120 to controlcircuitry 110. If a given response 131 a- 131c value is present in CAM function 120, CAM function 120 provides an indicator (e.g., a “hit” indicator) that the given response 131 a- 131c value is present in CAM function 120 to control circuitry 110. When a response 131 a- 131c value is determined to be present in CAM function 120, CAM function 120 provides the key indicator 141a-141c associated with the queried response 13 la-131c to key register 150. CAM function 120 also indicates for each key indicator 141 a- 141c provided to key register 150, location information (e.g., byte location, etc.) that allows key register 150 to assemble the key indicators 141 a- 141c into a complete and correct version of the larger cryptographic key.
[0024] In an embodiment, operation of tamper detection system 100 may comprise populating CAM function 120 with responses 13 la-131c stored by nonvolatile memory 130. The responses 13 la- 131c are respectively associated by CAM function 120 with key indicators 14 la- 141c. In an embodiment, responses 13 la- 131c are associated by CAM function 120 with key indicators 141a-141c in a randomized fashion. In an embodiment, responses 13 la-131c are associated by CAM function 120 with key indicators 141a-141c in a randomized fashion by virtue of having been stored in nonvolatile memory 130 in a randomized order. In an embodiment, responses 131 a- 131c may be associated by CAM function 120 with key indicators 141a-141c in a randomized fashion by further being accessed from nonvolatile memory 130 and / or stored in CAM function 120 in a randomized order and / or fashion.
[0025] Once CAM function 120 is populated with responses 13 la- 131c, system 100 (e.g., in response to control circuitry 101) successively iterates through each of challenges 132a- 132c and provides challenges 132a- 132c to PUF circuitry 110. In an embodiment, each challenge 132a- 132c is provided to PUF circuitry 110 a relatively large number of times (e.g., 128). Based on each provision of each challenge 132a- 132c, PUF circuitry 110 generates a corresponding response value that is used to query CAM function 120. If one of PUF circuitry’s 110 responses to one the provisions of a challenge value “hits” in CAM function 120 (i.e., the response value generated by PUF circuitry 110 in response to that provision of that challenge 132a- 132c is found to be present in CAM function 120), further challenges of PUF circuitry 110 using that challenge 132a- 132c value may, in some embodiments, be discontinued and a new challenge 132a- 132c value be selected to be challenge PUF circuitry 110 (for the relatively large number of iterations). If all of the provisions of challenge 132a- 132c values for the relatively large number of iterations fails to “hit” in CAM function 120 (i.e., none of response values generated by PUF circuitry 110 in response to all of theprovisions of that challenge 132a- 132c value is found to be present in CAM function 120), an alarm indicator may, in some embodiments, be set to indicate that system 100 has been subject to tampering.
[0026] Based on (at least) one of the provisions of a challenge 132a- 132c value resulting in a response 131 a- 131c value “hitting” in CAM function 120 (i.e., a response 131 a- 131c value generated by PUF circuitry 110 in response to a given challenge 132a- 132c is found to be present in CAM function 120), CAM function 120 provides the key indicator 141 a- 141c associated with that response 13 la-131c value to key register 150. Based on the provided key indicator 141a-141c, key register 150 stores a key portion (e.g., byte) in the appropriate key portion location in key register 150. For example, in an embodiment, if the system 100 has iterated to the eleventh challenge in the list of sequential challenges 132a- 132c, the “hit” at some random location within the CAM (in this example, responses 13 la-131c are stored in randomize order) provides key indicator 14 la- 141c, which would be loaded into the eleventh position within key register 150. Thus, in an embodiment, if all (or a sufficient number — if redundant challenges / responses are stored in nonvolatile memory 130) of challenges 132a- 132c have resulted in the provision of a key portion to key register 150, key register 150 will be fully populated with a complete and correct set of key portions that, when assembled in correct order, form a complete cryptographic key that may be used to verify that system 100 has not been subject to tampering. If not all of challenges 132a- 132c have resulted in the provision of a key portion to key register 150, key register 150 will not be fully populated with a complete and correct set of key portions. Because key register 150 is not fully populated with a complete and correct set of key portions, the contents of key register 150 do not form a complete cryptographic key that may be used to verify that system 100 has not been subject to tampering.
[0027] Figure 2 is a block diagram illustrating a second example tamper detection system. In Figure 2, tamper detection system 200 comprises control circuitry 201, physically unclonable function (PUF) circuitry 210, searchable memory table function (e.g., content addressable memory function) 220, nonvolatile memory 230, key index source 240, key register 250, and stable PUF circuitry 260. Control circuitry 201 is operatively coupled to PUF circuitry 210, CAM function 220, nonvolatile memory 230, key index source 240, key register 250, and “stable PUF” (i.e., a traditional weak-PUF circuit utilizing robust errorcorrection to achieve long-term stability of the fingerprint output) circuitry 260. However, for the sake of clarity in Figure 2, some of the operational couplings are not illustrated in Figure 2.
[0028] Nonvolatile memory 230 is operatively coupled with PUF circuitry 210 to provide PUF circuitry 210 with challenges 232. The output of PUF circuitry 210 is operatively coupled with CAM function 220 to query CAM function 220 with responses generated by PUF circuitry 210 in response to challenges 232. Key index source 240 is operatively coupled with CAM function 220 to provide CAM function 220 with key indicators 24 la- 241c. In an embodiment, PUF circuitry 210 is configured as a strong-type PUF function. In an embodiment, key indicators 241a-241c are indexes and / or addresses to locations in stable PUF circuitry 260 that are accessed to provide key portions 251a-251c to key register 250.
[0029] CAM function 220 is operatively coupled with stable PUF circuitry 260 and control circuitry 201. CAM function 220 is operatively coupled with control circuitry 201 to provide an indication that CAM function 220, when queried, has determined that a given response 231a-231c generated by PUF circuitry 210 has or has not been detected to be present in CAM function 220. CAM function 220 is operatively coupled with stable PUF circuitry 260 to, when a given response 231a-231c has been determined to be present in CAM function 220, provide a key indicator 241a-241c that is used to access stable PUF circuitry 260 for a key portion 25 la-251c. The reconstruction of a correct and complete cryptographic key value in key register 250 assembled from key portions 251a-251c received from stable PUF circuitry 260 in response to PUF circuitry 210 responses 231a-231c querying CAM function 220 is an indicator that tamper detection system 200 has not been tampered with. The lack of a reconstruction of a correct and complete cryptographic key value in key register 250 assembled from key portions 251a-251c received from CAM function 220 in response to PUF circuitry 210 responses 231a-231c querying CAM function 220 is an indicator that tamper detection system 200 has been tampered with.
[0030] Nonvolatile memory 230 stores challenges 232 and associated responses 231. In particular, nonvolatile memory 230 stores challenges 232a-232c that respectively are associated with responses 23 la-231c. In an embodiment, challenges 232a-232c were provided to PUF circuitry 210 during an enrollment process (e.g., during manufacturing and / or test of tamper detection system 200) and respectively resulted in the associated response 231a-231c by PUF circuitry 210. In an embodiment, the storage arrangement and / or other information (e.g., identifying information, labels, tags, etc.) stored or provided by nonvolatile memory 230 about challenges 232a-232c and responses 23 la-231c do not associate individual challenges 232a-232c with the respective responses 231a-231c that resulted from PUF circuitry 210 being challenged with that challenge 232a-232c. For example, the locations and / or storage order of the challenges 232a-232c may be in sequentialorder (e.g., the first through thirty-second challenges in sequential order), while the associated responses 231a-231c may be randomized (e.g., a randomized sequence of the first through thirty-second responses) when stored in nonvolatile memory 230.
[0031] PUF circuitry 210 includes tamper detection structures 211. CAM function 220 may be populated (e.g., by control circuitry 201) with responses 231a-231c stored by nonvolatile 230. CAM function 220 may store responses 23 la-231c in a manner that associates each response 231a-231c with an index 271a-271c and a key indicator 241a-241c. Key indicators 241a-241c may be provided by key index source 240. Index 271a-271c may, in some embodiments, correspond to the location in key register 250 that the key portion 251a-251c associated (by stable PUF circuitry 260) with the key indicator 241a-241c that is further associated with the response 231a-231c is to be stored in.
[0032] Responses 23 la-231c are provided as inputs to CAM function 220 by PUF circuitry 210. Responses 23 la-231c are respectively associated by CAM function 220 with indexes 271a-271c and key indicators 241a-241c. CAM function 220 is populated with responses 231 -231c and respective associations with indexes 271a-271c and key indicators 241a-241c. CAM function 220 may be populated (e.g., by control circuitry 201) with responses 231a-231c and respective associations with indexes 271a-271c and key indicators 241a-241c during or in response to a reset and / or power-up process.
[0033] Key indicators 241 a-241 c are generated and associated with indexes 271 a-271 c by key index source 240. Key index source 240 may be or comprise, for example, one or more of PUF circuitry (e.g., another stable PUF), a fixed value in secure non-volatile memory, the output of a key derivation function, and so on. In an embodiment, key indicators 241 a-241c are reproducibly generated and associated with indexes 271 a-271c each time system 200 is reset and / or powered up.
[0034] In an embodiment, key indicators 241 a-241c comprise address information pointing to key portions 251a-251c of a larger cryptographic key (e.g., a 32-byte cryptographic key). In an embodiment, key indicator 241 a-241c are pointers to values accessed from stable PUF circuitry 260 that are reproducibly generated each time system 200 is reset and / or powered up. In an embodiment, the values pointed to by key indicators 24 la- 2410 are portions (e.g., a byte) of a larger cryptographic key (e.g., a 32-byte cryptographic key). Thus, key index source 240 may generate a larger cryptographic key from values accessed in stable PUF circuitry 260 and then provide key indicators 241 a-241c to CAM function 220 to be used to assemble a complete and correct version of this larger cryptographic key where indexes 271 a-271c provide position information (e.g., positionordinal, key index, etc.) for each respective key portion 25 la-25 Ic’s position in the larger cryptographic key. In an embodiment, each respective index 271a-271c position information is determined by its location (e.g., address) in CAM function 220.
[0035] Based on response values provided by PUF circuitry 210, CAM function 220 determines whether each of the response values provided as an input query to CAM function 220 is present in CAM function 220 (i.e., whether the response value has been populated within the CAM memory). If a given response value is not present in CAM function 220, CAM function 220 provides an indicator (e.g., a “miss” indicator) that the given response value is not present in CAM function 220 to control circuitry 201. If a given response 23 la- 2310 value is present in CAM function 220, CAM function 220 provides an indicator (e.g., a “hit” indicator) that the given response 231a-231c value is present in CAM function 220 to control circuitry 201. When a response 231a-231c value is determined to be present in CAM function 220, CAM function 220 provides the key indicator 241a-241c associated with the queried response 231a-231c to stable PUF circuitry 260 and a position indicator (e.g., one of index 271a-271c) to key register 250. Based on the provided key indicator 241a-241c, stable PUF circuitry 260, in turn, provides a key portion 25 la-251c to key register 250.
[0036] In an embodiment, operation of tamper detection system 200 may comprise populating CAM function 220 with responses 231a-231c stored by nonvolatile memory 230. The responses 231a-231c are respectively associated by CAM function 220 with indexes 271 a-271 c and key indicators 241 a-241 c. In an embodiment, responses 231 a-231 c are associated by CAM function 220 with key indicators 241 a-241c in a randomized fashion. In an embodiment, responses 231 a-231c are associated by CAM function 220 with key indicators 241 a-241c in a randomized fashion by virtue of having been stored in nonvolatile memory 230 in a randomized order. In an embodiment, responses 23 la-231c may be associated by CAM function 220 with key indicators 241 a-241c in a randomized fashion by further being accessed from nonvolatile memory 230 and / or stored in CAM function 220 in a randomized order and / or fashion.
[0037] Once CAM function 220 is populated with responses 231 a-231c, system 200 (e.g., in response to control circuitry 201) successively iterates through each of challenges 232a- 232c and provides challenges 232a-232c to PUF circuitry 210. In an embodiment, each challenge 232a-232c is provided to PUF circuitry 210 a relatively large number of times (e.g., 128). Based on each provision of each challenge 232a-232c, PUF circuitry 210 generates a corresponding response value that is used to query CAM function 220. If one of PUF circuitry’s 210 responses to one of the provisions of a challenge value “hits” in CAMfunction 220 (i.e., the response value generated by PUF circuitry 210 in response to that provision of that challenge 232a-232c is found to be present in CAM function 220), further challenges of PUF circuitry 210 using that challenge 232a-232c value may, in some embodiments, be discontinued and a new challenge 232a-232c value be selected to be challenge PUF circuitry 210 (for the relatively large number of iterations). If all of the provisions of challenge 232a-232c values for the relatively large number of iterations fails to “hit” in CAM function 220 (i.e., none of response values generated by PUF circuitry 210 in response to all of the provisions of that challenge 232a-232c value is found to be present in CAM function 220), an alarm indicator may, in some embodiments, be set to indicate that system 200 has been subject to tampering.
[0038] Based on (at least) one of the provisions of a challenge 232a-232c value resulting in a response 23 la-231c value “hitting” in CAM function 220 (i.e., a response 23 la-231c value generated by PUF circuitry 210 in response to a given challenge 232a-232c is found to be present in CAM function 220), CAM function 220 provides the key indicator 241a-241c associated with that response 23 la-231c value to stable PUF circuitry 260. Based on the provided key indicator 241a-241c, stable PUF circuitry 260, in turn, provides a key portion 25 la-251c to key register 250. Based on the provided key portion 25 la-251c, key register 250 stores the key portion 251a-251c in the appropriate key portion location in key register 250. For example, in an embodiment, if the system 200 has iterated to the eleventh challenge in the list of sequential challenges 232a-232c, the “hit” at some random location within the CAM (in this example, responses 23 la-231c are stored in randomize order) provides key indicator 241a-241c, which causes the selected byte of stable PUF circuitry 260 be loaded into the eleventh position within key register 250. Thus, in an embodiment, if all (or a sufficient number — if redundant challenges / responses are stored in nonvolatile memory 230) of challenges 232a-232c have resulted in the provision of a key portion 25 la-251c to key register 250, key register 250 will be fully populated with a complete and correct set of key portions that, when assembled, form a complete cryptographic key that may be used to verify that system 200 has not been subject to tampering. If not all of challenges 232a-232c have resulted in the provision of a key portion 251a-251c to key register 250, key register 250 will not be fully populated with a complete and correct set of key portions. Because key register 250 is not fully populated with a complete and correct set of key portions, the contents of key register 250 do not form a complete cryptographic key that may be used to verify that system 200 has not been subject to tampering.
[0039] Figure 3 is a diagram illustrating an example pre-tamper strong-PUF response probability histogram. Figure 3 illustrates a pre-tampering probability of each of response values A-D occurring in response to repeated applications (e.g., to PUF circuitry 110 and / or PUF circuitry 210) of the same challenge value to a strong-type PUF function. In Figure 3, a pre-tampering distribution response value “A” is illustrated as occurring the most with around 66% occurrence rate, response value “B” is illustrated as occurring around 20% of the time, response value C occurring 6% of the time, and response value “D” occurring 2% of the time. In an embodiment, during enrollment, the response value to this challenge value selected to be stored in nonvolatile memory 130 and / or nonvolatile memory 230 may not be the value with a highest degree of certainty (e.g., response value “A”). Rather, in an embodiment, a response value with a good, but not highest, degree of certainty would be selected (e.g., response value “C”).
[0040] Figure 4 is a diagram illustrating an example post-tamper strong-type PUF response probability histogram. Figure 4 illustrates a post-tampering probability of each of response values A-D occurring in response to repeated applications (e.g., to PUF circuitry 110 and / or PUF circuitry 210) of the same challenge value (which is also same challenge value as illustrated in Figure 3) to a strong-type PUF function. In Figure 4, a post-tampering distribution response value “A” is illustrated as still occurring the most but now with only around 56% occurrence rate, response value “B” is illustrated as not occurring, response value D is illustrated as occurring around 20% of the time, response value C occurring 1% of the time, and a new response value “E” occurring 6% of the time. Thus, it should be understood from Figure 3 and Figure 4, that tampering with system 100 and / or system 200 may change the probability of a response 131 a- 131c 23 la-231c to that challenge value that is required for a “hit” in CAM function 120 or CAM function 220 to a low enough rate of occurrence that it is unlikely (or not possible) that this response will occur as one of the relatively large number (e.g., 128) of challenges made using that value.
[0041] Figure 5 is a flowchart illustrating a method of enrolling a strong-type PUF. One or more steps illustrated in Figure 5 may be performed by, for example, system 100, system 200, and / or their components. A challenge value is selected (502). For example, a candidate challenge value may be selected at random during a manufacturing and / or test process for application to PUF circuitry 110 in order to characterize PUF circuitry 110’s response to the candidate challenge value.
[0042] The challenge value is applied to a PUF a large number of times to characterize response occurrence probabilities (504). For example, during a manufacturing and / or testprocess, control circuitry 101 may apply the selected challenge value to PUF circuitry 110 a very large number of times (e.g., 1024) in order to characterize the probability of occurrence of a set of responses to the challenge value by PUF circuitry 110. In box 506, if a suitable response is found, flow proceeds to box 508. If a suitable response is not found, flow proceeds back to box 502 where another candidate challenge value is selected (506). For example, during the manufacturing and / or test process, the responses to the candidate challenge value may be sorted by frequency of occurrence to determine whether at least one of the observed responses has characteristics (e.g., probability of occurrence) that make it suitable for tamper detection. An example of an unsuitable response might be one where the same response is seen 100% of the time for all 1024 applications of the same challenge - this would be useful for a stable PUF, but is unsuitable for a tamper-evident PUF where some amount of non-uniform response probability is beneficial.
[0043] The challenge and associated response are stored in nonvolatile memory (508). For example, during the manufacturing and / or test process, control circuitry 101 may store the candidate challenge value and associated suitable response in nonvolatile memory 130. In an embodiment, specific key indicator values associated with each suitable response are also stored in nonvolatile memory 130. If the enrollment is not complete, flow proceeds back to box 502 for the selection of another candidate challenge value. If enrollment is complete, flow proceeds to box 512 (510). In box 512, the process ends (512). For example, candidate challenge value may continue to be selected, characterized, and suitable challenge value and responses stored in nonvolatile memory 130 until enough responses that can be associated with key indicators 141 a- 141c have been found. In an embodiment, the suitable challenges discovered during enrollment may be stored in sequential order within nonvolatile memory 130 (e.g., the first through thirty-second challenges in sequential order), while the associated suitable responses may be randomized (e.g., a randomized sequence of the first through thirty-second responses, along with their associated key indicator values).
[0044] Figure 6 is a flowchart illustrating a first example method of detecting tampering. One or more steps illustrated in Figure 6 may be performed by, for example, system 100, system 200, and / or their components. A CAM is populated with response values and key indicator values (602). For example, control circuitry 101 may cause CAM function 120 to be populated with response 13 la-131c values from nonvolatile memory 130 and key indicator 141a-141c values generated by key source 140.
[0045] A challenge value is selected and applied to a PUF a large number of times (604). For example, control circuitry 101 may select a one of challenge 132a-132c values fromnonvolatile memory 130 and apply it to PUF circuitry 110 a large (e.g., 128) number of times to generate a corresponding number of PUF circuitry 110 responses that are used to query CAM function 120. If a response is found in a CAM, flow proceeds to box 608. If a response is not found in the CAM, flow proceeds to box 612 (606). In box 612, a tamper alarm indicator is set to indicate a tampered with condition (612).
[0046] An associated key portion is copied to a key register (608). For example, if response 131b occurs and produces a CAM function 120 hit, CAM function 120 may provide an associated (e.g., by CAM function 120) key indicator 141b that may be used as, used to derive, or points to, a key portion value that is copied to key register 150. For example, if the system is working on the eleventh challenge value, the resulting key portion value is copied to the eleventh position within key register 150.
[0047] If there are more untried challenges, flow proceeds to box 604. If there are no more untried challenges, flow proceeds to box 614 where the process ends. For example, if there are challenges 132a-132c stored by nonvolatile memory 130 that remain untried, control circuitry 101 may select another challenge 132a- 132c and repeat the process of determining whether a response to that challenge is present in CAM function 120.
[0048] Figure 7 is a flowchart illustrating a second example method of detecting tampering. One or more steps illustrated in Figure 7 may be performed by, for example, system 100, system 200, and / or their components. A CAM is populated with response values and key indicator values (702). For example, control circuitry 201 may cause CAM function 220 to be populated with response 23 la-231c values from nonvolatile memory 230, index 271a-271c, and key indicator 241a-241c values generated by key index source 240.
[0049] A challenge value is selected and applied to a PUF a large number of times. For example, control circuitry 201 may select a one of challenge 232a-232c values from nonvolatile memory 230 and apply it to PUF circuitry 210 a large (e.g., 128) number of times to generate a corresponding number of PUF circuitry 210 responses that are used to query CAM function 220. If a response is found in a CAM, flow proceeds to box 708. If a response is not found in the CAM, flow proceeds to box 714. In box 714, a tamper alarm indicator is set to indicate a tampered with condition (714).
[0050] Based on an associated key indicator, a key portion is provided (708). For example, if response 23 lb occurs and produces a CAM function 220 hit, CAM function 220 may provide an associated (e.g., by CAM function 220) key indicator 241b that may be, for example: key material stored in on-chip NVM, a input “key seed” value for an on-chip key derivation function, a key index used to access stable PUF circuitry, or a combination thereofthat result in key portion value 25 lb. The associated key portion is copied to a key register (710). For example, the key portion value 251b associated with key indicator 241b may be provided by stable PUF circuitry 260 to key register 250.
[0051] If there are more untried challenges, flow proceeds to box 704. If there are no more untried challenges, flow proceeds to box 716 where the process ends (712). For example, if there are challenges 232a-232c stored by nonvolatile memory 230 that remain untried, control circuitry 201 may select another challenge 232a-232c and repeat the process of determining whether a response to that challenge is present in CAM function 220.
[0052] Figure 8 is a flowchart illustrating a method of operating a tamper detecting system. One or more steps illustrated in Figure 8 may be performed by, for example, system 100, system 200, and / or their components. From a nonvolatile memory and associated with a physically uncloneable function (PUF) circuit, a set of challenge values each associated with a one of a first set of PUF response value is received (802). For example, control circuitry 101 may iteratively read challenges 132a-132c from nonvolatile memory 130.
[0053] Each of the set of challenge values are provided to the PUF circuit multiple time to generate sets of second sets of PUF response values, each of the second sets of PUF response values resulting from corresponding ones of the set of challenge values being provided to the PUF circuitry (804). For example, control circuitry 101 may iteratively select each challenge 132a-132c value from nonvolatile memory 130 and apply each one to PUF circuitry 110 a large (e.g., 128) number of times to generate a corresponding set of PUF circuitry 110 responses for each challenge 132a-132c value. At least a portion of each of the sets of second sets of PUF response values are provided to a searchable memory table function populated with the first set of PUF response values in association with respective ones of a plurality of key portion indicators to generate a set of query result indicator each corresponding to one of the set of challenge values, the set of query result indicators comprising all of the plurality of key portion indicators (806). For example, at least a portion of each set of PUF circuitry 110 responses from each challenge 132a- 132c value may be used to query CAM function 120. If at least one of each set of PUF circuitry 110 responses from each challenge 132a-132c value produces a “hit” and a associated key portion indicator 141a- 141c, then a complete and correct cryptographic key can be assembled in key register 150.
[0054] Based on the set of query result indicators comprising all of the plurality of key portion indicators, it is determined that a tampering condition has not occurred (808). For example, based on a complete and correct cryptographic key being assembled in key register 150, system 100 may determine that system 100 has not been tampered with (i.e., altered).
[0055] Figure 9 is a block diagram illustrating an example strong-type PUF. PUF 900 illustrated in Figure 9 may be, or comprise, for example, PUF circuitry 110 and / or PUF circuitry 210. In Figure 9, strong-type PUF circuitry 900 comprises M number of semiindependent delay lines each outputting a single bit of response that comprise and / or are routed via protective shield layers. Collectively, the M number of semi-independent delay lines each outputting a single bit of response produce a M-bit response (RSPNS[0:M-l]). In Figure 9, a representative one of the M semi-independent delay lines is shown in detail. Delay line 901 comprises routing switches 91 la-911c, buffers 912a-912c, buffers 913a-913c, shield structures 915a-915b, and set-reset (SR) latch 920. A signal (e.g., rising edge, falling edge) to the inputs of buffer 912a and buffer 913a. Routing switch 911a, under the control of a first challenge bit (CHLG[0]), either passes the outputs of buffer 912a and buffer 913a directly to shield structures 915a or swaps the routing. The output of shield structures 915a are received by the inputs of buffer 912b and buffer 913b. Routing switch 911a, under the control of a second challenge bit (CHLGfl]), either passes the outputs of buffer 912b and buffer 913b directly to shield structures 915b or swaps the routing. This proceeds for N number of routing switches 91 la-911c until the outputs of routing switch 911c is applied to SR latch 920. The output of SR latch 920 is used as one of the M-bits of response produced by PUF 900. Thus, it should be understood that the M output bits of PUF 900 depend upon the challenge value (CHLG[0:N-l]) and manufacturing variances between routing switches 91 la-911c, buffers 912a-912c, buffers 913a-913c, shield structures 915a-915b, and set-reset (SR) latch 920 of the M number of semi -independent delay lines. Furthermore, it should be understood that if one or more of routing switches 91 la-911c, buffers 912a-912c, buffers 913a-913c, shield structures 915a-915b, and set-reset (SR) latch 920 of the M number of semi-independent delay lines have been altered (i.e., tampered with) the probability of a given response (RSPNS[0:M-l]) value occurring may change.
[0056] The methods, systems and devices described above may be implemented in computer systems, or stored by computer systems. The methods described above may also be stored on a non-transitory computer readable medium. Devices, circuits, and systems described herein may be implemented using computer-aided design tools available in the art, and embodied by computer-readable files containing software descriptions of such circuits. This includes, but is not limited to one or more elements of system 100, system 200, and their components. These software descriptions may be: behavioral, register transfer, logic component, transistor, and layout geometry -level descriptions. Moreover, the software descriptions may be stored on storage media or communicated by carrier waves.
[0057] Data formats in which such descriptions may be implemented include, but are not limited to: formats supporting behavioral languages like C, formats supporting register transfer level (RTL) languages like Verilog and VHDL, formats supporting geometry description languages (such as GDSII, GDSIII, GDSIV, CIF, and MEBES), and other suitable formats and languages. Moreover, data transfers of such files on machine-readable media may be done electronically over the diverse media on the Internet or, for example, via email. Note that physical files may be implemented on machine-readable media such as: 4 mm magnetic tape, 8 mm magnetic tape, 3-1 / 2 inch floppy media, CDs, DVDs, and so on.
[0058] Figure 10 is a block diagram illustrating one embodiment of a processing system 1000 for including, processing, or generating, a representation of a circuit component 1020. Processing system 1000 includes one or more processors 1002, a memory 1004, and one or more communications devices 1006. Processors 1002, memory 1004, and communications devices 1006 communicate using any suitable type, number, and / or configuration of wired and / or wireless connections 1008.
[0059] Processors 1002 execute instructions of one or more processes 1012 stored in a memory 1004 to process and / or generate circuit component 1020 responsive to user inputs 1014 and parameters 1016. Processes 1012 may be any suitable electronic design automation (EDA) tool or portion thereof used to design, simulate, analyze, and / or verify electronic circuitry and / or generate photomasks for electronic circuitry. Representation 1020 includes data that describes all or portions of system 100, system 200, and their components, as shown in the Figures.
[0060] Representation 1020 may include one or more of behavioral, register transfer, logic component, transistor, and layout geometry-level descriptions. Moreover, representation 1020 may be stored on storage media or communicated by carrier waves.
[0061] Data formats in which representation 1020 may be implemented include, but are not limited to: formats supporting behavioral languages like C, formats supporting register transfer level (RTL) languages like Verilog and VHDL, formats supporting geometry description languages (such as GDSII, GDSIII, GDSIV, CIF, and MEBES), and other suitable formats and languages. Moreover, data transfers of such files on machine-readable media may be done electronically over the diverse media on the Internet or, for example, via email
[0062] User inputs 1014 may comprise input parameters from a keyboard, mouse, voice recognition interface, microphone and speakers, graphical display, touch screen, or other type of user interface device. This user interface may be distributed among multiple interfacedevices. Parameters 1016 may include specifications and / or characteristics that are input to help define representation 1020. For example, parameters 1016 may include information that defines device types (e.g., NFET, PFET, etc.), topology (e.g., block diagrams, circuit descriptions, schematics, etc.), and / or device descriptions (e.g., device properties, device dimensions, power supply voltages, simulation temperatures, simulation models, etc.).
[0063] Memory 1004 includes any suitable type, number, and / or configuration of non- transitory computer-readable storage media that stores processes 1012, user inputs 1014, parameters 1016, and circuit component 1020.
[0064] Communications devices 1006 include any suitable type, number, and / or configuration of wired and / or wireless devices that transmit information from processing system 1000 to another processing or storage system (not shown) and / or receive information from another processing or storage system (not shown). For example, communications devices 1006 may transmit circuit component 1020 to another system. Communications devices 1006 may receive processes 1012, user inputs 1014, parameters 1016, and / or circuit component 1020 and cause processes 1012, user inputs 1014, parameters 1016, and / or circuit component 1020 to be stored in memory 1004.
[0065] Implementations discussed herein include, but are not limited to, the following examples:
[0066] Example 1: An integrated circuit, comprising: tamper-evident physically unclonable function (PUF) circuitry configured to receive challenge values and produce corresponding PUF responses that are based on the received challenge values; a nonvolatile memory to store a plurality of PUF challenge values in sequential order and a plurality of PUF response values in randomized order; and a searchable memory table populated with the plurality of PUF response values in association with respective ones of a plurality of key portion indicators each associated with respective key portions of a cryptographic key, the searchable memory table to receive a first plurality of candidate PUF response values generated by the PUF circuitry in response to a first PUF challenge value of the plurality of PUF challenge values, the searchable memory table to, based on receiving a first candidate PUF response value of the first plurality of candidate PUF response values, output a first key portion indicator associated with a first key portion of the cryptographic key, the first key portion indicator to be one of the plurality of key portion indicators.
[0067] Example 2: The integrated circuit of claim 1, wherein the searchable memory table is to, based on a second candidate PUF response value of the first plurality of candidatePUF response values, output a not-present indicator, the first candidate PUF response value and the second candidate PUF response value not being equal.
[0068] Example 3 : The integrated circuit of claim 2, the searchable memory table to receive a second plurality of candidate PUF response values generated by the PUF circuitry in response to a second PUF challenge value of the plurality of PUF challenge values, the searchable memory table to, based on receiving a third candidate PUF response value of second first plurality of candidate PUF response values, output a second key portion indicator associated with a second key portion of the cryptographic key, the second key portion indicator to be one of the plurality of key portion indicators, the second key portion to not be a same portion of the cryptographic key as the first key portion.
[0069] Example 4: The integrated circuit of claim 1, further comprising: key generation circuitry to generate the cryptographic key; and searchable memory table population circuitry to, based on the plurality of PUF response values, associate respective ones of the plurality of PUF response values with respective ones of the plurality of key portion indicators.
[0070] Example 5: The integrated circuit of claim 1, wherein the cryptographic key includes the first key portion indicator.
[0071] Example 6: The integrated circuit of claim 1, wherein the first key portion indicator is associated with a first key portion value, and the cryptographic key includes the first key portion value.
[0072] Example 7: The integrated circuit of claim 1, wherein associations between the plurality of PUF response values and respective ones of the plurality of key portion indicators have been randomized.
[0073] Example 8: An integrated circuit, comprising: strong-type tamper-evident physically unclonable function (PUF) circuitry configured to, based on challenge values, generate corresponding PUF response values; nonvolatile memory storing a set of challenge values and a set of PUF response values generated by the PUF circuitry in response to the set of challenge values; content addressable memory (CAM) function, populated with the set of PUF response values and associations to the set of key portion indicators, to receive candidate response values as CAM function query values to the CAM function and to output, in response to the CAM function query values, indicators of query value presence and key portion indicators; a control function to generate a plurality of sets of candidate PUF response values respectively corresponding to each of the set of challenge values by providing the PUF circuitry with each of the set of challenge values at least a first number of times, the control function also to iteratively provide the CAM function with each of the plurality of sets ofcandidate PUF response values to generate corresponding sets of query result indicators; and tamper condition detection function to, based on at least one of the sets of query result indicators, determine a tamper indicator.
[0074] Example 9: The integrated circuit of claim 8, wherein each query result indicator in the sets of query result indicators comprise a presence indicator.
[0075] Example 10: The integrated circuit of claim 9, wherein the tamper condition detection function indicates a no tampering condition based on each of the sets of query result indicators indicating that at least one candidate PUF response value in each of the plurality of sets of candidate PUF response values indicating that at least one candidate PUF response value in that set of candidate PUF response values is present in the CAM function.
[0076] Example 11 : The integrated circuit of claim 8, wherein the sets of query result indicators include a set of key portion indicators.
[0077] Example 12: The integrated circuit of claim 11, wherein the set of key portion indicators are associated with a complete cryptographic key.
[0078] Example 13: The integrated circuit of claim 11, wherein the tamper condition detection function is to indicate a tampered condition based on the set of key portion indicators not being associated with a complete cryptographic key.
[0079] Example 14: The integrated circuit of claim 12, further comprising: key generation function to generate the complete cryptographic key; and CAM function population circuitry to associate each of the set of PUF response values and to respective ones of the set of key portion indicators in a randomized manner.
[0080] Example 15: A method, comprising: receiving, from a nonvolatile memory and associated with a physically unclonable function (PUF) circuit, a set of challenge values each associated with a one of a first set of PUF response values; providing each of the set of challenge values to the PUF circuit multiple times to generate sets of second sets of PUF response values, each of the second sets of PUF response values resulting from corresponding ones of the set of challenge values being provided to the PUF circuit; providing at least a portion of each of the sets of second sets of PUF response values to a searchable memory table function populated with the first set of PUF response values in association with respective ones of a plurality of key portion indicators to generate a set of query result indicators each corresponding to one of the set of challenge value, the set of query result indicators comprising all of the plurality of key portion indicators; and determining, based on the set of query result indicators comprising all of the plurality of key portion indicators, that a tampering condition has not occurred.
[0081] Example 16: The method of claim 15, further comprising: based on the plurality of key portion indicators, generating a complete cryptographic key.
[0082] Example 17: The method of claim 16, wherein the complete cryptographic key is generated from the plurality of key portion indicators.
[0083] Example 18: The method of claim 16, wherein the complete cryptographic key is generated from key portions associated with the key portion indicators.
[0084] Example 19: The method of claim 15, wherein the PUF circuit, for each of a majority of the set of challenge values and in response to processing a single time, has a probability of generating a corresponding one of the first set of PUF response values of less than 25%.
[0085] Example 20: The method of claim 15, wherein tampering with the PUF circuit will, for at least one of the set of challenge values and in response to processing a single time, change a probability of generating a corresponding one of the first set of PUF response values.
[0086] The foregoing description of the invention has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the invention to the precise form disclosed, and other modifications and variations may be possible in light of the above teachings. The embodiment was chosen and described in order to best explain the principles of the invention and its practical application to thereby enable others skilled in the art to best utilize the invention in various embodiments and various modifications as are suited to the particular use contemplated. It is intended that the appended claims be construed to include other alternative embodiments of the invention except insofar as limited by the prior art.
Claims
CLAIMSWhat is claimed is:
1. An integrated circuit, comprising: tamper-evident physically unclonable function (PUF) circuitry configured to receive challenge values and produce corresponding PUF responses that are based on the received challenge values; a nonvolatile memory to store a plurality of PUF challenge values in sequential order and a plurality of PUF response values in randomized order; and a searchable memory table populated with the plurality of PUF response values in association with respective ones of a plurality of key portion indicators each associated with respective key portions of a cryptographic key, the searchable memory table to receive a first plurality of candidate PUF response values generated by the PUF circuitry in response to a first PUF challenge value of the plurality of PUF challenge values, the searchable memory table to, based on receiving a first candidate PUF response value of the first plurality of candidate PUF response values, output a first key portion indicator associated with a first key portion of the cryptographic key, the first key portion indicator to be one of the plurality of key portion indicators.
2. The integrated circuit of claim 1, wherein the searchable memory table is to, based on a second candidate PUF response value of the first plurality of candidate PUF response values, output a not-present indicator, the first candidate PUF response value and the second candidate PUF response value not being equal.
3. The integrated circuit of claim 2, the searchable memory table to receive a second plurality of candidate PUF response values generated by the PUF circuitry in response to a second PUF challenge value of the plurality of PUF challenge values, the searchable memory table to, based on receiving a third candidate PUF response value of second first plurality of candidate PUF response values, output a second key portion indicator associated with a second key portion of the cryptographic key, the second key portion indicator to be one of the plurality of key portion indicators, the second key portion to not be a same portion of the cryptographic key as the first key portion.
4. The integrated circuit of claim 1, further comprising: key generation circuitry to generate the cryptographic key; and searchable memory table population circuitry to, based on the plurality of PUF response values, associate respective ones of the plurality of PUF response values with respective ones of the plurality of key portion indicators.
5. The integrated circuit of claim 1, wherein the cryptographic key includes the first key portion indicator.
6. The integrated circuit of claim 1, wherein the first key portion indicator is associated with a first key portion value, and the cryptographic key includes the first key portion value.
7. The integrated circuit of claim 1, wherein associations between the plurality of PUF response values and respective ones of the plurality of key portion indicators have been randomized.
8. An integrated circuit, comprising: strong-type tamper-evident physically unclonable function (PUF) circuitry configured to, based on challenge values, generate corresponding PUF response values; nonvolatile memory storing a set of challenge values and a set of PUF response values generated by the PUF circuitry in response to the set of challenge values; content addressable memory (CAM) function, populated with the set of PUF response values and associations to the set of key portion indicators, to receive candidate response values as CAM function query values to the CAM function and to output, in response to the CAM function query values, indicators of query value presence and key portion indicators; a control function to generate a plurality of sets of candidate PUF response values respectively corresponding to each of the set of challenge values by providing the PUF circuitry with each of the set of challenge values at least a first number of times, the control function also to iteratively provide the CAM function with each of the plurality of sets of candidate PUF response values to generate corresponding sets of query result indicators; and tamper condition detection function to, based on at least one of the sets of query result indicators, determine a tamper indicator.
9. The integrated circuit of claim 8, wherein each query result indicator in the sets of query result indicators comprise a presence indicator.
10. The integrated circuit of claim 9, wherein the tamper condition detection function indicates a no tampering condition based on each of the sets of query result indicators indicating that at least one candidate PUF response value in each of the plurality of sets of candidate PUF response values indicating that at least one candidate PUF response value in that set of candidate PUF response values is present in the CAM function.
11. The integrated circuit of claim 8, wherein the sets of query result indicators include a set of key portion indicators.
12. The integrated circuit of claim 11, wherein the set of key portion indicators are associated with a complete cryptographic key.
13. The integrated circuit of claim 11, wherein the tamper condition detection function is to indicate a tampered condition based on the set of key portion indicators not being associated with a complete cryptographic key.
14. The integrated circuit of claim 12, further comprising: key generation function to generate the complete cryptographic key; andCAM function population circuitry to associate each of the set of PUF response values and to respective ones of the set of key portion indicators in a randomized manner.
15. A method, comprising: receiving, from a nonvolatile memory and associated with a physically unclonable function (PUF) circuit, a set of challenge values each associated with a one of a first set of PUF response values; providing each of the set of challenge values to the PUF circuit multiple times to generate sets of second sets of PUF response values, each of the second sets of PUF response values resulting from corresponding ones of the set of challenge values being provided to the PUF circuit;providing at least a portion of each of the sets of second sets of PUF response values to a searchable memory table function populated with the first set of PUF response values in association with respective ones of a plurality of key portion indicators to generate a set of query result indicators each corresponding to one of the set of challenge value, the set of query result indicators comprising all of the plurality of key portion indicators; and determining, based on the set of query result indicators comprising all of the plurality of key portion indicators, that a tampering condition has not occurred.
16. The method of claim 15, further comprising: based on the plurality of key portion indicators, generating a complete cryptographic key.
17. The method of claim 16, wherein the complete cryptographic key is generated from the plurality of key portion indicators.
18. The method of claim 16, wherein the complete cryptographic key is generated from key portions associated with the key portion indicators.
19. The method of claim 15, wherein the PUF circuit, for each of a majority of the set of challenge values and in response to processing a single time, has a probability of generating a corresponding one of the first set of PUF response values of less than 25%.
20. The method of claim 15, wherein tampering with the PUF circuit will, for at least one of the set of challenge values and in response to processing a single time, change a probability of generating a corresponding one of the first set of PUF response values.
Citation Information
Patent Citations
Cryptographic device having physical unclonable function
US11218306B2
Providing a Cryptographic Key
US20150188718A1
Physically unclonable function generating systems and related methods
US9985791B2