Semiconductor Integrated Circuit Unique Code Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor integrated circuits face challenges in securely protecting programs and data stored in non-volatile memory, as existing encryption techniques are not sufficient to prevent unauthorized access and imitation, especially in cases where the cryptographic key for decryption cannot be kept secure from the CPU.
Innovation Solution
Incorporating a unique code generating unit and a cryptographic processing unit that calculates a cryptographic key based on a correction parameter and unique code, ensuring that even if the unique code includes errors, the correct key can be generated, and the encrypted data remains secure, even in imitation products.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to communication protocols and data, then confidentiality is improved, but the cryptographic key becomes vulnerable to direct memory reading attacks
Solution Approach 1:
The cryptographic key is extracted from the CPU's accessible memory space and stored separately in a secure memory region that is physically isolated from the CPU's direct access capabilities. This separation ensures that even if the CPU or its memory is compromised, the cryptographic key remains protected in a secure enclave that cannot be directly read or copied.
Solution Approach 2:
A secure memory interface acts as an intermediary between the CPU and the cryptographic key storage. This interface controls and restricts access to the cryptographic key, allowing only authenticated and authorized operations while preventing direct memory reading attacks. The intermediary ensures that the key never exists in a state that is simultaneously accessible to the CPU and stored securely.
2Reliability
If the cryptographic key is stored securely outside CPU access, then security against imitation is improved, but the system complexity increases
Solution Approach 1:
The secure memory interface and cryptographic key storage are merged into a unified secure enclave that is tightly integrated with the CPU architecture. This integration allows the system to maintain enhanced security against imitation while minimizing the increase in system complexity by combining multiple security functions into a single cohesive unit rather than adding separate independent components.
Solution Approach 2:
The secure memory interface is designed to perform multiple functions including cryptographic key storage, access control, authentication, and secure data transfer. By making this component multi-functional, the patent reduces overall system complexity compared to having separate dedicated components for each security function, while still providing comprehensive protection against imitation attacks.
3Adaptability or versatility
If the unique code is generated using production variation, then unclonability is improved, but manufacturing precision requirements increase
Solution Approach 1:
The patent utilizes inherent physical parameter variations that occur during semiconductor manufacturing, such as transistor threshold voltage variations or timing delays, to generate unique codes. By deliberately leveraging these natural parameter changes rather than trying to control or eliminate them, the system achieves unclonability without imposing additional manufacturing precision requirements. The production variation becomes a security feature rather than a defect.
Data Source
AI summary
To raise confidentiality of the value stored in the ROM, in an IC having a built-in or an externally-attached ROM storing a value (program and/or data) encrypted using a predetermined cryptographic key. The IC includes the ROM storing the encrypted value (program and/or data), a unique code generating unit, and a decrypting unit. The unique code generating unit generates a unique code specifically determined by production variation. The decrypting unit calculates a cryptographic key on the basis of the generated unique code and a correction parameter, and decrypts the encrypted value read out from the ROM by using the calculated cryptographic key. The correction parameter is preliminarily calculated outside the IC, on the basis of an initial unique code generated from the unique code generating unit immediately after production of the IC, and the predetermined cryptographic key used for encryption of the value to be stored in the ROM.


