Method for enrolling a physically unclonable function, PUF, circuit for cryptographic applications

The temperature-compensated PUF system with embedded PCM cells and helper bits stabilizes cryptographic key generation, addressing temperature-induced inconsistencies and enhancing security in IoT systems.

WO2025149827A1PCT designated stage expired Publication Date: 2025-07-17POLITECNICO DI MILANO
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/063201
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-09
Filing Date
2024-12-27
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Existing PUF systems for cryptographic key generation in IoT systems are unreliable due to temperature variations, leading to inconsistent key outputs, and existing solutions like error correction codes and digitalization of memory cells either incur high overhead or increase security risks.

Method used

A temperature-compensated PUF system using embedded Phase-Change Memory (PCM) cells with helper bits to stabilize key generation, ensuring consistent outputs across temperature changes by identifying and adjusting helper bits based on resistive ratios of cell pairs.

Benefits of technology

Generates reliable, temperature-stable, and non-explicit cryptographic keys with minimal energy consumption, suitable for high-security IoT applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024063201_17072025_PF_FP_ABST
    Figure IB2024063201_17072025_PF_FP_ABST
Patent Text Reader

Abstract

Method for enrolling a Physically Unclonable Function, PUF, circuit for cryptographic applications, comprising: providing a plurality of modules (11), each module (11) comprising at least three embedded PUF cells y, z), each cell y, z) being configured to give an output upon application of an input. For each module (11), the following operations are executed : defining a reference temperature; for each cell pair (x-y, x-z, y-z) belonging to said module (11), initializing a respective helper bit (HDA, HDB, HDC) to a default value; bringing said module (11) to said reference temperature; applying to each cell y, z) the respective input; identifying, among said cell pairs (x-y, x-z, y-z), a first cell pair having the highest resistive ratio; defining the output of the module (11) as a function of the output of the cells of the first pair. The temperature of said modules is then modified within a range of interest. If, as the temperature changes, the first cell pair is still the one with the highest resistive ratio, then the helper bits (HDA, HDB, HDC) are left unchanged. If, as the temperature changes, a second cell pair, other than said first cell pair, becomes the one with the highest resistive ratio, then the following operations are executed: determining a next output on the basis of the outputs of the cells of the second pair; if the next output is equal to the output of the module, then the helper bits (HDA, HDB, HDC) are left unchanged; if the next output is different from the output of the module, then the value of the helper bit associated with said second cell pair is modified. A helper bit (HDA, HDB, HDC) vector is finally outputted.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method for enrolling a Physically Unclonable Function, PUF, circuit for cryptographic applications

[0002] DESCRIPTION

[0003] Field of the invention

[0004] The present invention concerns, in general, the technical field of systems for generating cryptographic keys. In particular, the invention concerns a temperature-stabilized Physical Unclonable Function (PUF) system based on a nonvolatile memory, for generating highly reliable cryptographic keys.

[0005] In more detail, the invention relates to a method for enrolling a PUF circuit for cryptographic applications.

[0006] The invention further relates to a system for generating cryptographic keys, as well as to a process for generating cryptographic keys.

[0007] Description of the prior art

[0008] Internet of Things (loT) systems have become increasingly complex over the years, and now require very advanced solutions to guarantee system security and confront continual local and / or remote attacks.

[0009] In order to meet the security requirements of loT systems, new technologies have been created and developed, such as Physical Unclonable Function (PUF) systems.

[0010] PUF systems are hardware security systems based on a physical entropy source, which allows for reproducible generation of random volatile keys without them having to be stored explicitly (i.e. in a non-volatile manner).

[0011] Such PUF systems for cryptographic key generation are widely used in many loT applications. Merely by way of example, PUF systems are typically employed for generating a root key, or "seed", starting from which other keys can be derived or decoded, or as an additional entropy source for a Hardware Root of Trust (HRoT). In this scenario, reliability against environmental variations is a crucial property, because no errors are allowed when generating cryptographic keys.

[0012] For example, a Phase-Change Memory (PCM) is a non-volatile memory (NVM) in which germanium (Ge), enriched with a germanium, antimony and tellurium (GST) alloy, generates a wide distribution of resistance in the virgin state equal to about three decades, which can be used as a zero-cost entropy source for hardware security applications.

[0013] The random generation of a cryptographic key is typically obtained by comparing the current of selected cells in the memory.

[0014] However, a simple comparison of two cells in the memory is not always reliable in terms of temperature variations. As a matter of fact, such cells have a known temperature dependency, resulting in their conductivity increasing as the temperature rises, and leading to the generation of "bit flips"; in practical terms, from the same input one may obtain a different output binary value (1 instead of 0, or vice versa) due to the fact that the cell's behaviour is dependent on temperature.

[0015] This is disadvantageous because, under different environmental conditions (and particularly, as aforesaid, under different temperature conditions), the cells may happen to generate different bits, and hence different keys. This is clearly a problem, since the key generated by a circuit for cryptographic applications must always be the same.

[0016] Some known PUF systems based on virgin-state PCM memory are described in, for example, the following publications: L. Cattaneo, M. Baldo, N. Lepri, F. Sancandi, M. Borghi, E. Petroni, A. Serafini, R. Annunziata, A. Redaelli and D. lelmini, "Enhancing reliability of a strong physical unclonable function (PUF) solution based on virgin-state phase change memory (PCM)" Proc. IRPS (2023); andMAHMOODI, M. R.; STRUKOV, D. B.; KAVEHEI, 0. Experimental demonstrations of security primitives with nonvolatile memories. IEEE Transactions on Electron Devices,

[0017] 2019, 66.12: 5050-5059.

[0018] In most DUE systems known in the art for cryptographic key generation, the problem of robustness to temperature has been tackled by introducing one or more of the following solutions:

[0019] 1) error correction schemes based on an error correction code (ECC);

[0020] 2) digitalization of memory cells;

[0021] 3) engineering of devices.

[0022] As concerns the first known solution, the ECC scheme involves the implementation of fuzzy extractors, which, while providing a considerable reduction in the temperature-induced error, produce an area / power overhead that is unsuitable for loT applications.

[0023] As concerns the second known solution, the comparison of preprogrammed NVM non-volatile memory cells in complementary states provides highly reliable solutions, but the explicit exposure of the secret in the written NVM non-volatile memory cells increases the risk of side-channel attacks and may limit the use of such DUE systems in high-security applications.

[0024] Finally, the third known solution forces conduction mechanism with low temperature dependency, without however providing any guarantee that the error threshold of interest will not be exceeded.

[0025] Some DUE systems that solve the problem of temperature dependency through the above-mentioned known solutions are described in the following publications: ZHANG, Le; KONG, Zhi Hui; CHANG, Chip-Hong. PCKGen: A phase change memory based cryptographic key generator. In: 2013 IEEE International Symposium on Circuits and Systems (ISCAS). IEEE, 2013. p. 1444- 1447; CHE, Wenjie; PLUSQUELLIC, Jim; BHUNIA, Swarup. A nonvolatile memory based physically unclonable function without helper data. In: 2014 IEEE / ACM International Conference on Computer-Aided Design (ICCAD). IEEE, 2014. p. 148-153; and J. Park, H. Kim et al., "Highly Reliable Physical Unclonable Functions using Memristor Crossbar with Tunneling Conduction", IEEE IEDM, 2022.

[0026] In light of the above, it becomes necessary to provide a PUF system for cryptographic key generation which is so configured as to be more robust and meet the standards of the loT industry, with particular reference to applications requiring high levels of security.

[0027] The Applicant also observes that one goal of the present invention is to avoid any explicit exposure of a secret (i.e. a cryptographic key), in order to make the cryptographic system more immune to malicious attacks. This goal has been achieved through the use of embedded PUF cells in combination with other features, as will become apparent hereinafter.

[0028] Summary of the invention

[0029] The basic idea of the present invention is to provide a Physically Unclonable Function system for generating cryptographic keys, which is configured to be temperature- compensated so as to generate non-explicit and temperaturestable volatile cryptographic keys without excessive energy consumption. Temperature compensation makes it possible to obtain a system for generating cryptographic keys which is highly reliable, so that it can be used in applications where minimal error probability is required. According to a preferred feature of the invention, virgin-state cells are used: the virgin state is, in fact, a highly desirable characteristic in PUF systems based on NVM non-volatile memory for cryptographic key generation, because it implies less overhead and is more immune to hardware hacking menaces.

[0030] As aforementioned, a first aspect of the invention relates to a method for enrolling a PUF circuit for cryptographic applications.

[0031] Preferably, said method comprises providing a plurality of modules. Preferably, each module comprises at least three PUF cells.

[0032] Preferably, said cells are embedded cells.

[0033] Preferably, each cell is configured to give an output upon application of an input.

[0034] Preferably, said method comprises, for each module, an operation of defining a reference temperature.

[0035] Preferably, said method comprises, for each module, an operation of initializing to a default value a respective helper bit for each cell pair belonging to said module.

[0036] Preferably, said method comprises, for each module, an operation of bringing said module to said reference temperature.

[0037] Preferably, said method comprises, for each module, executing an operation of applying to each cell the respective input.

[0038] Preferably, said method comprises, for each module, executing an operation of identifying, among said cell pairs, a first cell pair having the highest resistive ratio.

[0039] Preferably, said method comprises, for each module, executing an operation of defining the output of the module as a function of the output of the cells of the first pair.

[0040] Preferably, said method comprises modifying the temperature of said modules within a range of interest.

[0041] Preferably, if, as the temperature changes, the first cell pair is still the one with the highest resistive ratio, said method comprises an operation of leaving the helper bits unchanged.

[0042] Preferably, if, as the temperature changes, a second cell pair, other than said first cell pair, becomes the one with the highest resistive ratio, said method comprises: determining a next output on the basis of the outputs of the cells of the second pair; if the next output is equal to the output of the module, then leaving the helper bits unchanged; if the next output is different from the output of the module, then modifying the value of the helper bit associated with said second cell pair.

[0043] Preferably, said method comprises outputting a helper bit vector.

[0044] A second aspect of the invention concerns a system for generating cryptographic keys.

[0045] Preferably, said system comprises a Physically Unclonable Function (PUF) circuit.

[0046] Preferably, said PUF circuit comprises a plurality of modules.

[0047] Preferably, each module comprises at least three PUF cells.

[0048] Preferably, said cells are embedded cells.

[0049] Preferably, each cell is configured to give an output upon application of an input.

[0050] Preferably, said system comprises a first control circuit.

[0051] Preferably, said first control circuit is configured to generate an output for each cell pair comprised in said module.

[0052] Preferably, said system comprises a second control circuit.

[0053] Preferably, said second control circuit is configured to identify a first cell pair belonging to said module which has the highest resistive ratio.

[0054] Preferably, said second control circuit is configured to determine an intermediate output as a function of the outputs of the cells of said first pair.

[0055] Preferably, said second control circuit is configured to access a memory.

[0056] Preferably, said memory stores the helper bits generated in accordance with the above method.

[0057] Preferably, said second control circuit is configured to generate an output bit by applying said helper bits to the intermediate output.

[0058] Preferably, said system comprises an output circuit.

[0059] Preferably, said output circuit is configured to receive the output bits from each module.

[0060] Preferably, said output circuit is configured to generate a cryptographic key on the basis of said output bits. A third aspect of the invention concerns a process for generating cryptographic keys.

[0061] Preferably, said process comprises providing a Physically Unclonable Function (PUF) circuit.

[0062] Preferably, said PUF circuit comprises a plurality of modules.

[0063] Preferably, each module comprises at least three PUF cells.

[0064] Preferably, said cells are embedded cells.

[0065] Preferably, each cell is configured to give an output upon application of an input.

[0066] Preferably, said process comprises, for each one of said modules, generating an output for each cell pair comprised in said module.

[0067] Preferably, said process comprises, for each one of said modules, identifying a first cell pair belonging to said module and having the highest resistive ratio.

[0068] Preferably, said process comprises, for each one of said modules, determining an intermediate output as a function of the outputs of the cells of said first pair.

[0069] Preferably, said process comprises, for each one of said modules, accessing a memory.

[0070] Preferably, said memory stores the helper bits generated in accordance with the above method.

[0071] Preferably, said process comprises, for each one of said modules, generating an output bit.

[0072] Preferably, said output bit is generated by applying said helper bits to the intermediate output.

[0073] Preferably, said process comprises generating a cryptographic key on the basis of said output bits.

[0074] In one or more of the above aspects, the invention may comprise one or more of the following preferred features.

[0075] Preferably, said cells are cells in the virgin state.

[0076] Preferably, said cells are Phase-Change Memory (PCM) cells.

[0077] Preferably, said reference temperature is a minimum temperature of said range of interest. Preferably, said temperature is varied in such a way as to entirely cover said range of interest.

[0078] Preferably, it is envisaged to associate with each cell pair a respective comparator.

[0079] Preferably, in order to define the output of the module as a function of the output of the cells of the first pair, the output of the module is set equal to the output of the comparator associated with the first cell pair.

[0080] Preferably, in order to determine the next output on the basis of the outputs of the cells of the second pair, the next output is set equal to the output of the comparator associated with the second pair.

[0081] Preferably, said helper bits have a binary value.

[0082] Preferably, said method comprises identifying a module as unfit in case of unreliable operation.

[0083] Preferably, said method comprises generating a flag representative of such unfit condition.

[0084] Preferably, said method comprises associating said flag with the respective module.

[0085] Preferably, said method comprises associating with the helper bits of each module with reliable operation a flag representative of such fit condition.

[0086] Preferably, said output circuit is configured to exclude those modules which are associated with said bits representative of an unfit condition.

[0087] Preferably, said first control circuit comprises, for each cell pair, a comparator.

[0088] Preferably, each comparator is configured to receive as input a quantity correlated with the output of each one of the two cells associated with it.

[0089] Preferably, each comparator is configured to output a binary value representative of the comparison between the outputs of such two cells.

[0090] Brief description of the drawings Further features and advantages will become more apparent in light of the following description of a preferred embodiment thereof as shown in the annexed drawings, which are provided herein merely by way of non-limiting example, wherein:

[0091] Fig. 1 schematically shows the architecture of a Physical Unclonable Function (PUF) system according to a preferred embodiment of the present invention;

[0092] Fig. 2 schematically shows an embodiment of a storage structure for data used in the present invention;

[0093] Fig. 3 schematically shows a module of the PUF system of Figure 1;

[0094] Fig. 4 schematically shows a digital enabling circuit for the cells of the module of Figure 3;

[0095] Fig. 5 is a table showing the logic of the digital enabling circuit for the cells of the module of Figure 3;

[0096] Fig. 6 is a plot showing the Arrhenius intercepts of the cells of the module of Figure 3;

[0097] Fig. 7 is a flow chart schematically showing a preliminary enrollment phase for determining helper data and a flag to be associated with each cell of Figure 3;

[0098] Fig. 8 is a plot showing the temperature curve from the start to the end of the enrollment phase;

[0099] Figs. 9A and 9B show, respectively, a table and a plot concerning the identification of a first type of cells identified as unreliable during the preliminary enrollment phase;

[0100] Fig. 10 is a plot concerning the identification of a second type of cells identified as unreliable during the preliminary enrollment phase;

[0101] Figs. 11 to 13 illustrate and example of enrollment of a reliable cell.

[0102] Detailed description of some preferred embodiments of the invention

[0103] With reference to Figure 1, numeral 100 designates a Physical

[0104] Unclonable Function system, hereafter also referred to as PUF system, according to a preferred embodiment of the present invention. As will become apparent below, the PUF system 100 is adapted to be used for generating cryptographic keys.

[0105] The PUF system comprises a Physically Unclonable Function (PUF) circuit 10, organized as a matrix of modules 11, each one having a "one transistor / one resistor (1T1R)" structure. The circuit is addressed, in a per se known manner, through control blocks 21, 22.

[0106] As shown in detail in Figure 3, each module 11 of the PUF circuit 10 comprises three embedded PUF cells x, y, z.

[0107] In one embodiment, the cells x, y, z may be virgin-state cells. The Applicant observes, however, that such cells may also be (totally or partially) programmed.

[0108] Preferably, in general terms, the response of the module 11 - as will become apparent below - is generated on the basis of a comparison of three cells, not explicitly programmed, in a high resistive state (HRS) or in a low resistive state (LRS).

[0109] In one embodiment, the cells x, y, z may be Phase-Change Memory cells.

[0110] In one embodiment, the cells x, y, z may be RRAM cells.

[0111] Nevertheless, the Applicant observes that the cells x, y, z may also be provided by using other non-volatile memory technologies, preferably in the virgin state.

[0112] The cells x, y, z are read simultaneously, and the respective analogue output currents lax, lay, laz are compared by means of comparators A, B, C.

[0113] Note that Figure 3 represents, in a simplified manner, a preferred embodiment of the present invention, wherein the analogue currents lax, lay, laz are converted into respective voltages Vax, Vay, Vaz by transimpedance stages TIAx, TIAy, TIAz (Figure 1); such voltages are then inputted to the comparators A, B, C, as will be further described hereinafter.

[0114] More particularly, the system 100 comprises a first control circuit 30, configured to generate an output for each cell pair comprised in the module 11. The first control circuit 30 comprises, for each cell pair, a comparator A, B, C; each comparator A, B, C is configured to receive as input the output of each one of the two cells associated with it, and to output a binary value representative of the comparison between the outputs of such two cells.

[0115] In particular, comparator A makes a comparison between the voltage Vax (obtained from the analogue output current lax of cell x) and the voltage Vay (obtained from the analogue output current lay of cell y); comparator B makes a comparison between the voltage Vax and the voltage Vaz (obtained from the analogue output current laz of cell z); and comparator C makes a comparison between the voltage Vay and the voltage Vaz.

[0116] With reference to Figure 3, and considering the values of the currents lax, lay, laz from which the voltages Vax, Vay, Vaz are obtained:

[0117] - the output TA of comparator A has either the value 1, if the current lax is greater than the current lay (i.e. if the resistance value of cell x is lower than the resistance value of cell y), or the value 0, if the current lax is lower than the current lay (i.e. if the resistance value of cell x is greater than the resistance value of cell y);

[0118] - the output TB of comparator B has either the value 1, if the current lax is greater than the current laz (i.e. if the resistance value of cell x is lower than the resistance value of cell z), or the value 0, if the current lax is lower than the current laz (i.e. if the resistance value of cell x is greater than the resistance value of cell z);

[0119] - the output Tc of comparator C has either the value 1, if the current lay is greater than the current laz (i.e. if the resistance value of cell y is lower than the resistance value of cell z), or the value 0, if the current lay is lower than the current laz (i.e. if the resistance value of cell y is greater than the resistance value of cell z). The above is represented in the first four columns of Figure 5, wherein the first three columns list the (maximum, minimum, intermediate) resistance values of cells x, y, z, and the fourth column lists the outputs of the three comparators A, B, C.

[0120] Due to the random physical constitution of each cell x, y, z, each comparator A, B, C can produce in a random manner, at its output TA, TB, TC, either a logic value 0 or a logic value 1 based on the most conductive cell x, y, z in the respective pair x-y, x-z and y-z of compared cells. Such logic values are then used in order to generate cryptographic keys. It is therefore important that they cannot change over time, so that the same key can always be regenerated - because, since it has not been stored in a non-volatile memory, it will have to be regenerated at each use. However, as previously explained, the behaviour of embedded PUF cells (e.g. PCM cells) can depend significantly on the temperature of the circuit. Therefore, in accordance with the present invention, and as further described below, 3-bit helper data (hereafter briefly referred to as "helper bits"), i.e. HDA, HDB, HDC, respectively, are associated with each cell 11 for the purpose of making the binary values generated by the various modules 11 temperature-independent.

[0121] In the following, the output TA, TB, TC of each one of the comparators A, B, C will be referred to as "intermediate output".

[0122] Figure 2 schematically shows a storage structure for the helper data. The matrix 50 is formed of cells in which the helper bits for each module 11 are stored. Through the control blocks 51, 52, the matrix 50 is addressed in such a way as to return the helper bits HDA, HDB, HDC corresponding to the module 11 taken into account.

[0123] Referring back to Figures 1 and 3, on the output side of each comparator A, B, C there is a respective XOR port 12A, 12B, 12C.

[0124] Each XOR port 12A, 12B, 12C is inputted the output of the respective comparator A, B, C along with a helper bit - which, as will be explained below, contributes to making the overall operation of the circuit independent of temperature.

[0125] If a helper bit HDA, HDB has the logic value 0, then the respective XOR port 12A, 12b, 12C will be transparent.

[0126] If a helper bit HDA, HDB has the logic value 1, then the respective XOR port 12A, 12b, 12C will switch the output of the respective comparator A, B, C.

[0127] The RUF system 100 comprises also a second control circuit 40 (Figures 1, 3).

[0128] The second control circuit 40 is essentially a digital enabling logic performing the following operations: selecting that cell pair (x-y, x-z or y-z) belonging to the module 11 which has the highest resistive ratio (i.e. in which pair the difference between the resistance values of the respective cells is greatest); determining the intermediate output TA, TB, TC resulting from the selected pair, i.e. the output of the comparator associated with the selected pair; applying the corresponding helper bit HDA, HDB, HDC, taken from a respective memory 50.

[0129] In more detail, the control circuit 40 is inputted the outputs TA, TB, TC of comparators A, B, C in order to generate three outputs ENA, ENB, ENC, thus keeping track of the cell pair x-y, x-z, y-z with the highest resistive ratio, more specifically the cell pair x-y, x-z, y-z with the greatest difference between the compared analogue output current values lax, lay, laz.

[0130] This condition is shown in the table of Figure 5, which lists: the maximum (MAX), minimum (MIN) and intermediate (MID) resistive values of each cell x, y, z; the logic values (0 or 1) of the outputs TA, TB, TCof comparators A, B, C; the logic values (0 or 1) of the outputs ENA, ENB, ENC of the digital enabling logic 40.

[0131] In particular, the last column in the table of Figure 5 shows that only one of the three outputs ENA, ENB, ENC of the digital enabling logic 40 is equal to 1, namely the one associated with the pair having the highest resistive ratio.

[0132] Furthermore, due to the temperature dependency of the currentvoltage curves I-V, it may happen that the control circuit 40 addresses a different comparator depending on the operating temperature, so that the cell pair x-y, x-z, y-z with the highest resistive ratio may vary.

[0133] In this regard, Figure 6 shows that in section T1-T2 the pair with the highest resistive ratio is x-z, while in section T2-T3 it is y-z, and in section T3-T4 it is x-y (more specifically, with y greater than x).

[0134] Therefore, the second control circuit 40 will address (i.e. select for use in the computation of the output of the module 11):

[0135] - in section T1-T2, comparator A;

[0136] - in section T2-T3, comparator C;

[0137] - in section T3-T4, comparator B.

[0138] Figure 4 shows an exemplary circuit implementation of the second control circuit 40. According to such implementation, the second control circuit 40 comprises three OR logic ports.

[0139] The first OR logic port is inputted the output of two AND logic ports, wherein:

[0140] - the first AND logic port is inputted TB* (i.e. negated TB) and Tc, respectively corresponding to (x > z) and (y < z); therefore, the first AND logic port defines a situation in which (x > z > y);

[0141] - the second AND logic port is inputted TB and Tc* (i.e. negated Tc), respectively corresponding to (x < z) and (y > z); therefore, the second AND logic port defines a situation in which (x < z < y).

[0142] Thus, the first OR logic port receives as input the conditions (x > z > y) and (x < z < y) that lead to enable comparator A through output ENA (since pair x-y is the one with the highest resistive ratio).

[0143] The second OR logic port is inputted the output of two AND logic ports, wherein:

[0144] - the first AND logic port is inputted TA and Tc, respectively corresponding to (x < y) and (y < z); therefore, the first AND logic port defines a situation in which (x < y < z);

[0145] - the second AND logic port is inputted Tc* (i.e. negated Tc) and TA* (i.e. negated TA), respectively corresponding to (x > y) and (y > z); therefore, the second AND logic port defines a situation in which (x > y > z).

[0146] Thus, the second OR logic port receives as input the conditions (x < y < z) and (x > y > z) that lead to enable comparator B through output ENB (since pair x-z is the one with the highest resistive ratio).

[0147] The third OR logic port is inputted the output of two AND logic ports, wherein:

[0148] - the first AND logic port is inputted TA and TB* (i.e. negated TB), respectively corresponding to (x < y) and (x > z); therefore, the first AND logic port defines a situation in which (z < x < y);

[0149] - the second AND logic port is inputted TA* (i.e. negated TA) and TB, respectively corresponding to (x > y) and (x < z); therefore, the second AND logic port defines a situation in which (z > x > y).

[0150] Thus, the second OR logic port receives as input the conditions (z < x < y) and (z > x > y) that lead to enable comparator C through output ENc (since pair y-z is the one with the highest resistive ratio).

[0151] Finally, as shown in the general diagram of Figure 1, an OR logic port is used to combine:

[0152] - an AND combination between ENA and the output of the XOR port 12A;

[0153] - an AND combination between ENB and the output of the XOR port 12B;

[0154] - an AND combination between ENc and the output of the XOR port 120. This gives the output logic value RISP of the module 11.

[0155] An output circuit 60 collects the output bits of all modules 11 belonging to the system 100 and generates a cryptographic key.

[0156] In particular, the output circuit 60 may use as seed the bit string obtained from the modules 11 and apply, in a per se known manner, a cryptographic-key generation algorithm.

[0157] As aforementioned, considering the output TA, TB, TC of the automatically addressed comparator with the highest resistive ratio may be insufficient to guarantee the same response bit value within the temperature range of interest.

[0158] A preliminary enrollment phase is therefore needed in order to compute the 3-bit helper data HDA, HDB, HDC, which are useful to adjust the outputs, if necessary.

[0159] To this end, each module 11 is initially brought to a reference temperature. For example, said reference temperature may be equal to the minimum temperature TMIN of a range of interest, delimited by such minimum temperature TMIN and a maximum temperature TMAX.

[0160] Note that, since all modules 11 are parts of the same circuit 10, from a practical viewpoint all modules will be at substantially the same temperature - this condition will then be reflected by the modules themselves during their actual use for the generation of the cryptographic key. Therefore, the reference temperature will preferably be the same for all modules 11 of the PUF circuit 10, and, in this context, changing the temperature of one module will necessarily result in an analogous variation in the temperature of all the other modules.

[0161] As shown in detail in Figure 7, at the beginning of the preliminary enrollment phase all helper bits HDA, HDB, HDC of each cell 11 are set equal to zero (HDA,B,C = 0, phase SI).

[0162] In other words, for each cell pair (x-y, y-z, x-z) belonging to the module 11, the respective helper bit is initialized to a default value, e.g. 0. If the helper bit HDA,B,C is zero, then the respective XOR port 12A, 12B, 12C will be irrelevant, and the output of such port will reflect the output of the respective comparator A, B, C, with no variation.

[0163] Power is then supplied to the cells x, y, z, and, through the second control circuit 40, the output of the comparator corresponding to the cell pair with the highest resistive ratio is enabled. Such pair is referred to as "first pair".

[0164] The output of the module 11 is then defined as a function of the output of the cells of the first pair. More particularly, the output of the comparator A, B, C enabled at the reference temperature (which, as aforesaid, is preferably equal to TMIN) defines the secret target bit to be reproduced at any temperature for that module 11 (phase S2).

[0165] The temperature of the module 11 is then changed in such a way as to progressively cover the whole interval comprised between the minimum temperature TMIN and the maximum temperature TMAX.

[0166] As the temperature changes (e.g. as the temperature increases from TMIN to TMAX), an Arrhenius intercept occurs between the resistance behaviours of the cells x, y, z (phase S3, branch SI) as shown in the plot of Figure 6, the control circuit 40 enables a new cell pair x, y, z with the highest resistive ratio (phase S4), and the corresponding output is compared with the secret target bit (phase S5). If no match is detected during this comparison (phase S5, branch NO), then it will be recorded that the helper data HDx need to be adjusted, otherwise the process will return to phase S4.

[0167] In summary: if, as the temperature changes, the first cell pair is still the one with the highest resistive ratio, the helper bits are left unchanged; if, as the temperature changes, a second cell pair, other than said first cell pair, becomes the one with the highest resistive ratio: a next output is determined on the basis of the outputs of the cells of the second pair (in practice, another comparator is enabled and the output of such other comparator, called "next output", is considered; if the next output is equal to the output of the module, then the helper bits are left unchanged; if the next output is different from the output of the module, then the value of the helper bit associated with the second cell pair, i.e. with the second enabled comparator, is modified.

[0168] As shown in the plot of Figure 7, the procedure is then repeated, every time increasing the temperature by a value AT, until the maximum temperature TMAX of the temperature range of interest is reached. Within the time interval At during which the temperature remains constant, all modules 11 of the PUF circuit 10 are read and, every time a new cell pair x, y, z with the highest resistive ratio is identified, such pair is recorded along with the output of the addressed comparator A, B, C. This is also necessary to identify, and flag accordingly, any unreliable modules during the procedure (phase S4).

[0169] The Applicant observes that two types of unreliable modules exist, namely skip-zone modules and 4-zone modules.

[0170] Skip-zone modules are modules that have not been properly registered during the enrollment procedure due to a temperature range of interest AT which is too wide. In such a case, and as shown in the table of Figure 9A and in the plot of Figure 9B, not all Arrhenius intercepts are recognized correctly; at the end of the procedure, this translates into incomplete helper bits HDA, HDB, HDC. This may result in a bit-flip for certain temperatures within the temperature range of interest, which will make the module unfit.

[0171] 4-zone modules are those modules which have more than four Arrhenius intercepts and, therefore, undergo at least four changes of the cell pair x, y, z with the highest resistive ratio. In such cases, as shown in Figure 10, at least one of the explored cell pairs x, y, z is repeated, but with opposite maximum and minimum values. Being fixed, the associated helper data HDA, HDB, HDC cannot guarantee the same response bit throughout the temperature range of interest, and this results in a bit-flip starting from a certain temperature.

[0172] Both of these module types, i.e. skip-zone or 4-zone modules, can be recognized knowing the maximum resistance and the minimum resistance of all the different pairs with the highest resistive ratio found during the enrollment phase.

[0173] Referring back to Figures 9A and 9B, skip-zone modules do not have a maximum or minimum cell x, y, z which is common to different consecutive cell pairs, whereas 4-zone modules can always be recognized by using at least three temperature samples during the enrollment phase, specifically one sample at the minimum temperature TMIN, one sample at the intermediate temperature TMID of the temperature range of interest, and one sample at the maximum temperature TMAX.

[0174] Unreliable modules can be flagged as unfit by means of another m x n cell matrix, illustrated in Figure 2. The m x n cell matrix is addressed in parallel with the matrix of PUF cells and the matrix of helper data HDA, HDB, HDC, and advantageously permits discarding any unfit modules during the generation of a cryptographic key.

[0175] With reference to Figures 11-13, there is shown an example of a procedure for enrolling a reliable ("fit") module 11 of the PUF circuit 10. In this example, the three cells x, y, z of the module 11 behave, in temperature terms, as shown in the Arrhenius plot of Figure 6. Such behaviour is also shown in the upper right box in each one of Figures 11-13.

[0176] Each one of Figures 11-13 refers to a different temperature interval used during the enrollment procedure. In particular: Figure 11 concerns interval T1-T2, Figure 12 concerns interval T2-T3, and Figure 13 concerns interval T3-T4. With reference to the above explanations, T1 corresponds to TMIN and T4 corresponds to TMAX•

[0177] In more detail, Figure 11 (temperature interval T1-T2) schematically shows the start of the enrollment procedure, when the target bit is defined. The helper bits HDA, HDB, HDC are initially set to zero (HDA=0; HDB=0; HDC=0). Through the second control circuit 40, the cell pair with the highest resistive ratio, e.g. pair x-z, which is afferent to comparator B, is addressed. The output of comparator B (which is 0 in the example of Figure 11) is then defined as the target bit, i.e. the logic value that the module 11 will always have to output regardless of temperature.

[0178] The enrollment procedure then goes on until a first Arrhenius intercept is encountered (transition from Figure 11 to Figure

[0179] 12).

[0180] In Figure 12 (temperature interval T2-T3), the second control circuit 40 addresses a comparator other than comparator B (specifically, comparator C) due to the fact that the resistive behaviour of the cells has changed with the temperature, and the cell pair with the highest resistive ratio is no longer pair x- z, but pair y-z. The output of comparator C is then considered and compared with the target bit - which, as aforesaid, is 0. The output of comparator C is equal to 0; therefore, it is not necessary to impose any switching by means of the respective XOR port 12C, and the respective helper bit HDc is left at 0.

[0181] The enrollment procedure then goes on until a second Arrhenius intercept is encountered (transition from Figure 12 to Figure

[0182] 13).

[0183] In Figure 13 (temperature interval T3-T4), it can be noticed that the cell pair with the highest resistive ratio is now pair x-z, and that the output value of the respective comparator A is 1. Since this value is not consistent with the target bit defined at the beginning, the respective helper bit HDA is set to 1 so that, in operation, the value RISP for the module 11 will still remain equal to 0.

[0184] At this point, the enrollment of the module 11 is complete; since it is neither a skip-zone module nor a 4-zone module, a fit flag is associated with it.

[0185] In operation, i.e. when a cryptographic key is to be generated, the following occurs.

[0186] For each module 11 belonging to the PUF system 100, the respective helper bit and the respective fit / unfit flag are retrieved.

[0187] If the module is unfit (based on its flag), it will be discarded.

[0188] If the module is fit (based on its flag), then the helper bits will be applied to the outputs of the various comparators, and the output RISP will be considered as one of the bits to be used for generating the cryptographic key (as aforesaid, the bits obtained from the outputs RISP may constitute the seed from which the cryptographic key will be derived).

[0189] Depending on the temperature at which the module 11 is operating, a different comparator will be selected:

[0190] - if the operating temperature is comprised between T1 and T2, then the pair with the highest resistive ratio will be pair x-z, and comparator B will therefore be addressed; the respective helper bit HDB has been left at 0, so that the output RISP will be identical to the output of comparator

[0191] B, which is 0 (RISP=0);

[0192] - if the operating temperature is comprised between T2 and T3, then the pair with the highest resistive ratio will be pair y-z, and comparator C will therefore be addressed; the respective helper bit HDc has been left at 0, so that the output RISP will be identical to the output of comparator

[0193] C, which is 0 (RISP=0);

[0194] - if the operating temperature is comprised between T3 and T4, then the pair with the highest resistive ratio will be pair x-y, and comparator A will therefore be addressed; the respective helper bit HDA has been set to 1; the output of comparator A is 1, so that the output RISP (derived from the XOR operation of port 12A between the output of comparator A and the respective helper bit HDA) will be 0 (RISP=0).

[0195] It can be noticed that, thanks to the enrollment phase and to the definition of suitable helper data, it is possible to have each module provide always the same output independently of its temperature, notwithstanding the temperature dependency of the resistive behaviour of the individual cells.

[0196] It is apparent from the above description that the PUF system 100 according to the present invention aims at creating modules containing information bits which are independent of the temperature within a temperature range of interest, through the use of embedded memory cells, preferably in the virgin state (e.g. PCM memories). In particular, each module comprises three memory cells, and during the initial enrollment phase it is associated with one 3-bit helper data memory cell and one 1-bit flag memory cell. The 3-bit helper data memory cell and the 1- bit flag memory cell are organized in pre-programmed matrices, which are written at the end of the enrollment phase and addressed in parallel with the cell matrix for producing the actual response.

[0197] The features and the advantages of the PUF system for generating cryptographic keys according to the present invention are apparent in light of the above description. In particular, the system according to the invention is such as to generate volatile, non-explicit, temperature-stable cryptographic keys without excessive energy consumption.

Claims

CLAIMS1. Method for enrolling a Physically Unclonable Function, PUF, circuit for cryptographic applications, comprising: providing a plurality of modules (11), each module (11) comprising at least three embedded PUF cells (x, y, z), each cell (x, y, z) being configured to give an output upon application of an input; executing, for each module (11), the following operations: defining a reference temperature; for each cell pair (x-y, x-z, y-z) belonging to said module (11), initializing a respective helper bit (HDA, HDB, HDC) to a default value; bringing said module (11) to said reference temperature; applying to each cell (x, y, z) the respective input; identifying, among said cell pairs (x-y, x-z, y-z), a first cell pair having the highest resistive ratio; defining the output of the module (11) as a function of the output of the cells of the first pair; modifying the temperature of said modules within a range of interest; as the temperature changes: if the first cell pair is still the one with the highest resistive ratio, leaving the helper bits (HDA, HDB, HDC) unchanged; if a second cell pair, other than said first cell pair, becomes the one with the highest resistive ratio: determining a next output on the basis of the outputs of the cells of the second pair; if the next output is equal to the output of the module, then leaving the helper bits (HDA, HDB, HDc) unchanged; if the next output is different from the output of the module, then modifying the value of the helper bit associated with said second cell pair;- outputting a helper bit (HDA, HDB, HDC) vector.

2. Method according to claim 1, wherein said reference temperature is a minimum temperature (TMIN) of said range of interest.

3. Method according to claim 1 or 2, wherein said temperature is varied in such a way as to entirely cover said range of interest.

4. Method according to any one of the preceding claims, comprising associating with each cell pair (x-y, x-z, y-z) a respective comparator (A, B, C).

5. Method according to claim 4, wherein, in order to define the output of the module (11) as a function of the output of the cells of the first pair, the output of the module is set equal to the output of the comparator associated with the first cell pair.

6. Method according to claim 4 or 5, wherein, in order to determine the next output on the basis of the outputs of the cells of the second pair, the next output is set equal to the output of the comparator associated with the second pair.

7. Method according to any one of the preceding claims, wherein said helper bits (HDA, HDB, HDC) have a binary value.

8. Method according to any one of the preceding claims, comprising: identifying a module as unfit in case of unreliable operation; generating a flag representative of such unfit condition; associating said flag with the respective module.

9. Method according to claim 8, comprising: associating with the helper bits (HDA, HDB, HDC) of each module with reliable operation a flag representative of such fit condition.

10. Method according to any one of the preceding claims, wherein said cells (x, y, z) are phase-change memory, PCM, cells.

11. Method according to any one of the preceding claims, wherein said cells (x, y, z) are cells in the virgin state.

12. System for generating cryptographic keys, comprising: a Physically Unclonable Function, PUF, circuit (100) comprising a plurality of modules (11), each module (11) comprising at least three embedded PUF cells (x, y, z), each cell (x, y, z) being configured to give an output upon application of an input; wherein said system comprises: a first control circuit (30), configured to generate an output for each cell pair (x-y, x-z, y-z) comprised in said module (11); a second control circuit (40), configured to: identify a first cell pair (x-y, x-z, y-z) belonging to said module (11) which has the highest resistive ratio; determine an intermediate output (TA, TB, Tc) as a function of the outputs of the cells of said first pair; access a memory (50) storing the helper bits (HDA, HDB, HDC) generated in accordance with the method of any one of the preceding claims; generate an output bit (RISP) by applying said helper bits (HDA, HDB, HDC) to the intermediate output; wherein said system further comprises an output circuit (60), configured to receive the output bits (RISP) from each module (11), and to generate a cryptographic key on the basis of saidoutput bits (RISP).

13. System according to claim 11, wherein said output circuit (60) is configured to exclude those modules which are associated with bits representative of an unfit condition in accordance with claim 8.

14. System according to claim 12 or 13, wherein said first control circuit (40) comprises, for each cell pair (x-y, x-z, y-z), a comparator (A, B, C) configured to receive as input a quantity correlated with the output of each one of the two cells associated with it, and to output a binary value representative of the comparison between the outputs of such two cells.

15. Process for generating cryptographic keys, comprising: providing a Physically Unclonable Function, PUF, circuit (100) comprising a plurality of modules (11), each module (11) comprising at least three embedded PUF cells (x, y, z), each cell (x, y, z) being configured to give an output upon application of an input; wherein, for each one of said modules (11), the following operations are executed: generating an output for each cell pair (x-y, x-z, y-z) comprised in said module (11); identifying a first cell pair belonging to said module and having the highest resistive ratio; determining an intermediate output (TA, TB, TC) as a function of the outputs of the cells of said first pair; accessing a memory (50) storing the helper bits (HDA, HDB, HDC) generated in accordance with the method of any one of claims 1- 9; generating an output bit (RISP) by applying said helper bits (HDA, HDB, HDC) to the intermediate output (TA, TB, Tc); generating a cryptographic key on the basis of said outputbits (RISP).

Citation Information

Patent Citations

  • Memory device having physical unclonable function and memory system including the memory device

    US20220399056A1