Delay-Element Matrix Circuit for Stable IC Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits (ICs) face challenges in securely storing and processing secret cryptographic data, particularly due to vulnerabilities in physical implementation that make them susceptible to implementation attacks, both when powered on and off, and existing methods for key generation and storage are insufficient for ensuring the security of individual IC keys.

Innovation Solution

A circuit and method using a matrix of delay elements with variable interconnections to generate a true, circuit-specific, time-invariant binary random number, which serves as an individual IC key, ensuring secrecy, integrity, and resistance to implementation attacks by comparing delay times of chains of delay elements, thereby avoiding the need for threshold values and reducing extraction errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard methods are used for generation and nonvolatile storage of cryptographic keys, then the IC can store secret data, but the individual IC key cannot be protected against implementation attacks when the IC is powered off

Engineering Contradiction:
Improvesecurity of individual IC keyVSAvoidcomplexity of key protection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the individual IC key from digital storage form and maintains it in an extracted, camouflaged form that is not stored in traditional nonvolatile memory. The key is generated once and then maintained in an extracted state through physical properties of the IC, eliminating the need for separate protection mechanisms against static attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces traditional electronic/digital key storage and protection mechanisms with physical properties of the IC itself. The individual IC key is derived from physical characteristics that are inherent to the IC's construction, substituting mechanical/physical properties for electronic security mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If the individual IC key is stored in digital form in nonvolatile memory, then it is easily accessible, but it becomes vulnerable to static implementation attacks when the IC is off

Engineering Contradiction:
Improveaccessibility of IC keyVSAvoidvulnerability to implementation attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The key is extracted from digital storage form and maintained in an extracted, camouflaged form. Rather than storing the key in nonvolatile memory where it would be vulnerable, the system extracts the key and maintains it through physical properties that are not susceptible to static attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism - the extraction circuit and camouflaging process - that converts the individual IC key from a storable digital value into a form maintained by physical properties. This intermediary process protects the key while still allowing access during operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the IC uses camouflaged nondigital form for the individual IC key, then protection against static attacks is improved, but extraction errors may occur during conversion to digital form

Engineering Contradiction:
Improveprotection against static attacksVSAvoidextraction accuracy of IC key
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary actions during the personalization phase to generate and establish the individual IC key in its camouflaged form. Error correction codes and validation mechanisms are prepared in advance to detect and correct extraction errors when the key is converted to digital form for use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that validate the extracted individual IC key and detect extraction errors. When errors are detected, the system can request re-extraction or apply error correction, ensuring accurate key recovery while maintaining the security benefits of the camouflaged form.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If the individual IC key is generated deterministically, then reproduction is possible, but the key loses its random nature and security properties

Engineering Contradiction:
Improvereproducibility of IC keyVSAvoidrandomness and security of IC key
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by making each individual IC unique through its specific physical properties and construction variations. While the generation process is deterministic, the local physical characteristics of each IC ensure that the resulting individual IC key is unique and random-like, maintaining security properties while allowing reproduction of the same key in the same IC.

Inventive Principle:
Principle #3Local quality

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach provides enhanced security for secret IC data by generating a unique, unpredictable IC key that is resistant to compromise and extraction errors, ensuring the integrity and secrecy of cryptographic operations within the IC, even when the IC is powered off.

Implementation Method 1

A circuit and method using a matrix of delay elements with variable interconnections to generate a true, circuit-specific, time-invariant binary random number

Methodology Applied
Scientific EffectSignal transit time variation:

Data Source

PatentUS8990276B2Circuit and method for generating a true, circuit-specific and time-invariant random number
Publication Date: 2015.03.24 TDK MICRONAS GMBH
  • US8990276B2 patent drawing
  • US8990276B2 patent drawing
  • US8990276B2 patent drawing

AI summary

The invention relates to a circuit for generating a true, circuit-specific and time-invariant random binary number, having: a matrix of K−L delay elements that can be connected to each other by means of L−1 single or double commutation circuits into chains of delay elements of length L, a single or double demultiplexer connected before the matrix, a single or double multiplexer connection after the matrix, and a run time or number comparator, wherein the setting of the commutation circuits, the demultiplexer, and the multiplexer can be prescribed by a control signal, wherein the circuit comprises a channel code encoder whereby code words of a channel code can be generated and a transcriber, whereby code words of the channel code can be transcribed into the control signal of the L−1 single or double commutation circuits, and a method for generating a true, circuit-specific and time-invariant random number by means of a matrix of L−K delay elements, L−1 single or double commutation circuits, a single or double demultiplexer connected before the matrix, a single or double multiplexer connection after the matrix, and a run time or number comparator, comprising at least the steps a) generating a code word of a channel code, b) transcribing a code word of a channel code to a selection code, c) generating chains of L delay elements by setting a setting corresponding to the code word of the selection code for the L−1 single or double commutation circuits, the single or double demultiplexer, and the single or double multiplexer, d) pairwise comparing of two variables determined by the delay times of two chains defined by the setting of the L−1 commutation circuits corresponding to the code word of the channel code, by means of a number or delay comparator for generating a bit of the true, circuit-specific and time-invariant random number.