PUF Seed Generation Using PDK Timestamps and Layout Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physically unclonable function (PUF) devices used for encryption key generation face limitations such as potential seed value reproduction and insufficient entropy for large numbers of chips, as well as vulnerability to electromagnetic interference, which compromise security.

Innovation Solution

The method generates seed values based on a timestamp and PDK data hash, combining these with PUF outputs to create secure public-private key pairs, utilizing the vast number of possible Pcell configurations within the PDK to make seed reproduction difficult, thereby enhancing security beyond hardware-only PUF systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PUF-based key generation is used, then hardware security is provided, but seed values may be reproduced and entropy is insufficient for large numbers of chips

Engineering Contradiction:
Improveencryption key securityVSAvoidseed value uniqueness across chips
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent combines multiple entropy sources including PUF outputs, PDK data, and timestamp information to generate seed values. This merging of hardware PUF uniqueness with software-based PDK and timestamp data provides both hardware security and sufficient entropy for large numbers of chips, preventing seed reproduction while maintaining scalability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The seed generation system uses a composite approach by combining hardware PUF characteristics with software-derived PDK data and temporal timestamp information. This composite seed structure leverages the unclonability of PUF while adding the vast combinatorial space of PDK configurations and timestamp variability to ensure unique, non-reproducible seeds across many chips.

Inventive Principle:
Principle #40Composite materials

2Object-affected harmful factors

If PUF-only systems are used, then hardware unclonability is achieved, but vulnerability to electromagnetic interference occurs

Engineering Contradiction:
Improveelectromagnetic interference vulnerabilityVSAvoidkey generation reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces PDK data and timestamp information as intermediary elements between the PUF hardware and the final key generation process. These intermediaries process and combine with PUF outputs to create seeds that are less directly vulnerable to electromagnetic interference affecting the PUF alone, while maintaining the hardware-based security foundation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If PDK configuration data is used for seed generation, then entropy is increased, but system complexity increases

Engineering Contradiction:
Improveseed entropyVSAvoidkey generation system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing PDK infrastructure and its parameterized cell configurations, which are already universally used in IC design flows. By utilizing existing PDK data structures and EDA toolchains for seed generation, the system gains high entropy without proportionally increasing complexity, as the PDK framework already provides the necessary data organization and parameter management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11722298B2Public-private encryption key generation using Pcell parameter values and on-chip physically unclonable function values
Publication Date: 2023.08.08 GLOBALFOUNDRIES US INC
  • US11722298B2 patent drawing
  • US11722298B2 patent drawing
  • US11722298B2 patent drawing

AI summary

Methods and systems generate seeds for public-private key pairs by determining a timestamp value associated with a process design kit (PDK) when a user of the PDK triggers a tool of the PDK while designing an integrated circuit device to have a physical unclonable function device (PUF). The methods and systems generate a first value by mapping the timestamp value to data of the user, generate a second value by mapping the timestamp value to configuration data of the PDK, and generate a third value by mapping the timestamp value to layout data of the PDK. A random number is then generated by applying a function to the first value, the second value, and the third value. A public-private encryption key pair is generated using the random number as a first seed number and using a second number generated by the number generation device as a second seed number.