Integrated Circuit PUF Key Generation with Fuse Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing the life cycle of identification devices, such as RFID chips, face challenges in securely generating and protecting secret keys, particularly in preventing unauthorized access and ensuring key security during manufacturing, personalization, and usage, while minimizing logistic costs and legal obligations.

Innovation Solution

An integrated circuit employing a physical uncloneable function (PUF) as a key generator, combined with a fuse means comprising two fuses, where the digital key is accessible only when one fuse is broken and the other is intact, allowing secure key reading and subsequent permanent inaccessibility, thus ensuring key protection throughout the device's life cycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a secret key is stored in non-volatile memory for authentication, then key accessibility is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the secret key from non-volatile memory and instead generates it dynamically using a Physical Uncloneable Function (PUF). The PUF generates the key based on physical characteristics of the hardware itself, eliminating the need to store the key in memory. This resolves the contradiction by providing key accessibility when needed while preventing unauthorized access, as the key cannot be extracted or stolen from memory.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a fuse mechanism as an intermediary between the PUF key generator and the authentication system. The fuse acts as a one-time switch that, once broken, permanently enables or disables key access. This intermediary layer adds a security checkpoint that prevents unauthorized key retrieval while maintaining legitimate access during the authorization window, thus resolving the accessibility versus security contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a PUF-based key generator is used, then security against cloning is improved, but key readout capability deteriorates

Engineering Contradiction:
Improvesecurity against cloningVSAvoidkey readout capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by establishing an authorization mechanism before the key becomes permanently inaccessible. A fuse is configured to break after a predetermined number of readout attempts or after a specific time period, creating a limited window of opportunity for legitimate key access. This preliminary setup ensures that security against cloning is maintained while providing controlled key readout capability during the authorization period.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of key accessibility from permanent to temporary by using the fuse mechanism. The fuse remains intact during the authorization period, allowing key readout, but breaks after the predetermined conditions are met, permanently disabling further access. This parameter change resolves the contradiction by providing temporary readout capability while maintaining long-term security against cloning.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If two fuses are used to control key access, then security against unauthorized access is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidfuse control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security control into two distinct fuse elements instead of using a single complex access control mechanism. Each fuse independently controls a specific aspect of key access, simplifying the overall design while enhancing security. This segmentation resolves the contradiction by providing robust security through multiple simple, independent failure points rather than one complex access control system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7761714B2Integrated circuit and method for preventing an unauthorized access to a digital value
Publication Date: 2010.07.20 INFINEON TECHNOLOGIES AG
  • US7761714B2 patent drawing
  • US7761714B2 patent drawing
  • US7761714B2 patent drawing

AI summary

An integrated circuit including a digital key provider comprising an output and an enable-input, wherein the digital key provider is configured to provide the digital key at the output only when an enable-signal is provided to the enable-input; and a fuse unit comprising a first fuse and a second fuse, wherein the fuse unit is configured to provide the enable-signal to the enable-input when the first fuse is broken while the second fuse is intact.