PUF Seed Generation Using PDK Timestamps and Layout Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Physically unclonable function (PUF) devices used for encryption key generation face limitations such as potential seed value reproduction and insufficient entropy for large numbers of chips, as well as vulnerability to electromagnetic interference, which compromise security.
Innovation Solution
The method generates seed values based on a timestamp and PDK data hash, combining these with PUF outputs to create secure public-private key pairs, utilizing the vast number of possible Pcell configurations within the PDK to make seed reproduction difficult, thereby enhancing security beyond hardware-only PUF systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PUF-based key generation is used, then hardware security is provided, but seed values may be reproduced and entropy is insufficient for large numbers of chips
Solution Approach 1:
The patent combines multiple entropy sources including PUF outputs, PDK data, and timestamp information to generate seed values. This merging of hardware PUF uniqueness with software-based PDK and timestamp data provides both hardware security and sufficient entropy for large numbers of chips, preventing seed reproduction while maintaining scalability.
Solution Approach 2:
The seed generation system uses a composite approach by combining hardware PUF characteristics with software-derived PDK data and temporal timestamp information. This composite seed structure leverages the unclonability of PUF while adding the vast combinatorial space of PDK configurations and timestamp variability to ensure unique, non-reproducible seeds across many chips.
2Object-affected harmful factors
If PUF-only systems are used, then hardware unclonability is achieved, but vulnerability to electromagnetic interference occurs
Solution Approach 1:
The patent introduces PDK data and timestamp information as intermediary elements between the PUF hardware and the final key generation process. These intermediaries process and combine with PUF outputs to create seeds that are less directly vulnerable to electromagnetic interference affecting the PUF alone, while maintaining the hardware-based security foundation.
3Reliability
If PDK configuration data is used for seed generation, then entropy is increased, but system complexity increases
Solution Approach 1:
The patent leverages the existing PDK infrastructure and its parameterized cell configurations, which are already universally used in IC design flows. By utilizing existing PDK data structures and EDA toolchains for seed generation, the system gains high entropy without proportionally increasing complexity, as the PDK framework already provides the necessary data organization and parameter management.
Data Source
AI summary
Methods and systems generate seeds for public-private key pairs by determining a timestamp value associated with a process design kit (PDK) when a user of the PDK triggers a tool of the PDK while designing an integrated circuit device to have a physical unclonable function device (PUF). The methods and systems generate a first value by mapping the timestamp value to data of the user, generate a second value by mapping the timestamp value to configuration data of the PDK, and generate a third value by mapping the timestamp value to layout data of the PDK. A random number is then generated by applying a function to the first value, the second value, and the third value. A public-private encryption key pair is generated using the random number as a first seed number and using a second number generated by the number generation device as a second seed number.


