Twin Cell MTPROM Encryption Engine for Secure Chip Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for generating unique chip IDs using Physical-Unclonable-Fuse (PUF) are unstable and costly, leading to high system overhead, making them unsuitable for low-cost applications, and existing self-authentication approaches are not cost-effective for consumer markets.
Innovation Solution
A Multi-time Programmable Read-Only Memory (MTPROM) with a twin cell array using multi-threshold voltage levels for secure chip authentication, where each cell stores a secret key and undergoes an overwrite procedure to generate a stable and encrypted digital state for authentication, reducing system overhead and cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PUF-based ID generation is used, then unique chip identification is achieved, but system overhead increases and cost increases
Solution Approach 1:
The patent extracts the identification function from complex PUF-based systems and implements it using simple eFUSE bits. By removing the PUF generation and authentication infrastructure, the solution achieves unique chip identification without the associated system overhead and cost complexity.
Solution Approach 2:
The patent uses inexpensive eFUSE bits as disposable identification elements. These fuse bits provide unique identification through their physical state changes during manufacturing and operation, eliminating the need for expensive and complex PUF systems while maintaining identification uniqueness.
2Ease of manufacture
If eFUSE ID bits are used, then chip identification is achieved, but security is compromised due to easy detection
Solution Approach 1:
Instead of using easily detectable eFUSE bits directly for identification, the patent inverts the approach by using these same bits to generate a unique key that is then encrypted and stored in secure memory. The identification process becomes indirect and secure, as the original eFUSE bits are not directly exposed for detection.
Solution Approach 2:
The patent introduces encrypted storage as an intermediary between the eFUSE bits and the identification function. The eFUSE bits first generate a key, which then encrypts the actual identification data in secure memory. This intermediary layer prevents direct detection of the eFUSE bits while maintaining identification capability.
3Device complexity
If self-authentication approach is used, then system overhead is reduced, but cost-effectiveness is compromised for consumer markets
Solution Approach 1:
The patent applies partial action by implementing only the essential eFUSE bit functionality without the full self-authentication system. This selective implementation reduces costs for consumer applications while maintaining sufficient security through the key generation and encrypted storage mechanism, rather than implementing complete self-authentication.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The solution provides a cost-effective and stable chip authentication method with minimal additional circuitry or mask levels, suitable for a broad range of products, enhancing hardware security without relying on PUFs.
Implementation Method 1
storing the ID in an encryption engine is provided. The engine can employ a Multi-time Programmable Read Only Memory (MTPROM) to store one multi-threshold voltage level per cell having charge trap characteristics
Data Source
AI summary
Described are a hardware encryption engine, and secret key registration and authentication system recoverable binary bit using knowing an initial secret key stored in the master system. The secret key is overwritten in each authentication, updating it to the master and encryption engine independently. The secret key over write command can be preferably given to the chip as a CHG, and the non recoverable binary bit from the sense amplifier is used for response.


