SRAM Secure Key Generation via Timing Mismatch
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor chip technologies face challenges in generating secure keys or chip IDs that cannot be reverse engineered, as they are often stored in non-volatile memories and can be compromised.
Innovation Solution
The proposed solution involves generating secure keys based on skewed bits in random access memories (RAMs), specifically using secure key latches with data and clock inputs from sense amplifiers, and a secure key enrollment routine to identify rows with sufficient entropy for unique ID generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If chip IDs or security keys are stored in fuses or non-volatile memories, then the chip ID or key can be retained permanently, but the chip ID or key can be reverse engineered and compromised
Solution Approach 1:
The patent extracts the security key generation process from traditional non-volatile memory storage and moves it to a volatile SRAM-based system. The key is generated dynamically during chip operation using skewed bits from SRAM cells, eliminating the need to store the key permanently in fuses or non-volatile memory, thereby preventing reverse engineering while maintaining security
Solution Approach 2:
The patent introduces skewed bits from SRAM cell timing variations as an intermediary element to generate the security key. These skewed bits serve as a physical intermediary that translates manufacturing variations into cryptographic keys, creating a secure key generation mechanism that cannot be reverse engineered since the skew is inherent in the physical hardware
2Reliability
If a secure key generation method is implemented using SRAM skewed bits, then reverse engineering resistance is improved, but device complexity increases
Solution Approach 1:
The patent makes the SRAM memory cells serve multiple functions: they perform their primary data storage function while simultaneously generating secure keys through their timing skew characteristics. This multi-functionality eliminates the need for separate dedicated key generation hardware, reducing overall device complexity while maintaining high security
Solution Approach 2:
The SRAM cells generate their own skewed bits as a byproduct of normal operation, which are then used to create the security key. The system uses its own inherent timing variations to generate the key, eliminating the need for external complex key generation equipment or additional dedicated circuitry
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A method of secure key generation includes writing a predetermined write pattern to a particular address of volatile memory, wherein the volatile memory includes bit lines; reading data from the particular address while applying a first set of operating variables to the volatile memory, subsequent to the writing; sensing a first plurality of timing mismatches during the reading, wherein sense amplifiers are coupled to the bit lines, each latch of a plurality of latches is coupled between a respective pair of sense amplifiers, and each latch is configured to output a data value that indicates a respective timing mismatch between outputs of the respective pair of sense amplifiers; and determining an entropy ratio for the particular address, wherein the entropy ratio is equivalent to a ratio of a first number of latches that output a first data value to a second number of latches that output a second data value.