Flash Memory PUF Key Generation Stability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing physical unclonable function (PUF) technologies in non-volatile memory, such as ReRAM-based PUFs, face issues with high bit error rates due to resistance drift in memory cells, especially at high temperatures, which affects the reliability of generated keys used for security protocols in IoT devices.
Innovation Solution
A method and apparatus utilizing charge-trapping non-volatile memory cells, like flash memory, to generate stable PUF-based data sets with zero or very low bit error rates by establishing variant thresholds through a common process, allowing for secure key generation and storage, and implementing access control circuits to manage key access and usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If ReRAM-based PUF is used to generate unique keys, then key generation capability is provided, but bit error rate increases due to resistance drift in memory cells
Solution Approach 1:
The patent changes the physical parameter basis from resistance (ReRAM) to charge trapping characteristics (flash memory). By utilizing threshold voltage shifts caused by charge trapping in flash memory cells, the system achieves stable key generation that is insensitive to temperature-induced drift, thereby resolving the contradiction between key generation capability and bit error rate
Solution Approach 2:
The patent creates a stable copy of the unique key in non-volatile memory after initial generation through PUF mechanisms. This allows the key to be reliably retrieved without repeatedly accessing the unstable physical PUF structure, reducing bit error rates while maintaining key generation capability
2Reliability
If charge-trapping non-volatile memory is used to generate PUF data sets, then bit error rate decreases to zero or very low levels, but device complexity increases due to access control circuits
Solution Approach 1:
The patent merges the PUF key generation function with the existing flash memory structure and control logic. By integrating the PUF functionality into the flash memory controller and utilizing existing access control mechanisms, the system achieves low bit error rates without significantly increasing overall device complexity
Solution Approach 2:
The patent makes the flash memory controller multi-functional by enabling it to perform both standard memory operations and PUF key generation operations. This universal approach allows a single control unit to handle multiple tasks, avoiding the need for separate dedicated PUF control circuits and thereby limiting complexity increase
3Duration of action of stationary object
If security keys are stored in non-volatile memory blocks, then key persistence is achieved, but unauthorized access risk increases without access control mechanisms
Solution Approach 1:
The patent implements preliminary access control measures by establishing restricted access modes before keys are actually needed. Access control circuits are configured in advance to enforce read-only or read-protect modes on key storage blocks, preventing unauthorized writes or modifications. This preliminary protection maintains key persistence while mitigating unauthorized access risks
Solution Approach 2:
The patent introduces access control circuits as an intermediary layer between external interfaces and the key storage blocks in non-volatile memory. This intermediary enforces security policies, allowing legitimate access while blocking unauthorized operations, thereby enabling key persistence without exposing the system to unauthorized access risks
Data Source
AI summary
A system and method for utilizing a security key stored in non-volatile memory, and for generating a PUF-based data set on an integrated circuit including non-volatile memory cells, such as flash memory cells, are described. The method includes storing a security key in a particular block in a plurality of blocks of the non-volatile memory array; utilizing, in a security logic circuit coupled to the non-volatile memory array, the security key stored in the particular block in a protocol to enable access via a port by external devices or communication networks to data stored in blocks in the plurality of blocks; and enabling read-only access to the particular block by the security logic for use in the protocol, and preventing access to the particular block via the port.


