TW201721506A - Hardware protection based on fabrication characteristics - Google Patents

Hardware protection based on fabrication characteristics Download PDF

Info

Publication number
TW201721506A
TW201721506A TW105124632A TW105124632A TW201721506A TW 201721506 A TW201721506 A TW 201721506A TW 105124632 A TW105124632 A TW 105124632A TW 105124632 A TW105124632 A TW 105124632A TW 201721506 A TW201721506 A TW 201721506A
Authority
TW
Taiwan
Prior art keywords
fingerprint
circuit
voltage
string
voltages
Prior art date
Application number
TW105124632A
Other languages
Chinese (zh)
Inventor
金宜 費
睿彥 林
尼迪 尼迪
軼偉 陳
石坤桓
楊曉東
瓦力德 賀菲斯
柯堤斯 蔡
Original Assignee
英特爾股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 英特爾股份有限公司 filed Critical 英特爾股份有限公司
Publication of TW201721506A publication Critical patent/TW201721506A/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Abstract

This disclosure is directed hardware protection based on fabrication characteristics. In general, an integrated circuit (IC) device may be configured to determine a string of logical values or "fingerprint" based at least on fabrication characteristics of the device. An example device may comprise at least functional circuitry corresponding to the functional purpose of the device and hardware protection circuitry (HPC). Example HPC may include interpreter circuitry and fingerprint circuitry. For example, the interpreter circuitry may measure at least one parameter (e.g., voltage) of at least one electronic component in the fingerprint circuitry, and in at least one embodiment, may compare voltages measured from different components in the fingerprint circuitry and then assign a logical one or zero to the fingerprint string based on the results of each component comparison. Example electronic components may include transistors, resistors, etc. whose performance, may depend on the fabrication characteristics of the device.

Description

基於生產特性之硬體保護 Hardware protection based on production characteristics

本發明相關於半導體生產,且更明確地相關於基於生產特性產生裝置特定認證資料的系統。 The present invention relates to semiconductor production and, more specifically, to systems that generate device specific authentication data based on production characteristics.

安全已成為且繼續成為各種形式的電子技術中之新發展的主要焦點區域。包括敏感、機密等資訊的交易經由電子通訊更頻繁地實行,且因此,電子裝置的安全性係保護此資訊的關鍵。攻擊者(例如,駭客)最初在軟體層級鎖定裝置,試圖獲得裝置的控制權,或至少存取儲存在裝置上的資訊。當將基於軟體的防禦構思為阻礙此等攻擊時,駭客已更深入到保護圈中以攻擊更高的權限層級。以此方式,可將惡意碼(例如,有毒軟體)注入到比既存之基於軟體的保護(例如,防毒保護、軟體防火牆等)更高權限層級的系統中,且可能克服既存之基於軟體的保護。 Security has become and continues to be a major focus area for new developments in various forms of electronic technology. Transactions including sensitive, confidential, and the like are more frequently implemented via electronic communications, and as such, the security of the electronic device is the key to protecting this information. An attacker (eg, a hacker) initially locks the device at the software level, attempts to gain control of the device, or at least access information stored on the device. When software-based defenses are conceived to block such attacks, hackers have moved deeper into the protection circle to attack higher privilege levels. In this way, malicious code (eg, toxic software) can be injected into a higher-privilege system than existing software-based protection (eg, antivirus, software firewall, etc.) and may overcome existing software-based protection. .

由於此等更先進的攻擊,裝置開發者已開始設計基於硬體的保護。此較低階類型的保護在裝置中可在軟體之前啟始,諸如,載入作業系統(OS),並可在裝置中提供 更基本的安全性。然而,日益足智多謀的攻擊者現在設計新方式以攻擊裝置的硬體,以克服基於硬體的防禦。例如,攻擊者可企圖改變(例如,重程式化)、置換等積體電路(IC)裝置安裝於其中之系統中的IC裝置,以影響或改變系統的行為。所產生的行為改變可准許攻擊者控制系統或至少存取系統中的資訊。在既存IC裝置可藉由基於硬體的編碼、加密等保護以防止此等攻擊的同時,既存保護係以可反向工程的方式程式化在裝置中。以此方式,攻擊者可設計其可模仿已知良好的IC裝置,但可依次影響使系統安全性受損的系統改變的替代IC。 Due to these more advanced attacks, device developers have begun to design hardware-based protection. This lower order type of protection can be initiated in the device before the software, such as an operating system (OS), and can be provided in the device. More basic security. However, increasingly resourceful attackers are now designing new ways to attack the hardware of the device to overcome hardware-based defenses. For example, an attacker may attempt to alter (eg, reprogram), replace, or otherwise replace an IC device in a system in which an integrated circuit (IC) device is installed to affect or alter the behavior of the system. The resulting behavioral change may permit an attacker to control the system or at least access information in the system. While existing IC devices can be protected against such attacks by hardware-based encoding, encryption, etc., the existing protections are programmed in the device in a reverse engineerable manner. In this way, an attacker can design an alternative IC that can mimic a known good IC device, but can in turn affect system changes that compromise system security.

100‧‧‧裝置 100‧‧‧ device

102‧‧‧功能電路 102‧‧‧ functional circuit

104、104’‧‧‧HPC 104, 104’‧‧‧HPC

106、106’‧‧‧解譯器電路 106, 106’‧‧ Interpreter circuit

108、108’‧‧‧指紋電路 108, 108'‧‧‧ Fingerprint circuit

200A、200A’、200B、200B’、200C、200C’、200D、200n、200n’‧‧‧FCU 200A, 200A', 200B, 200B', 200C, 200C', 200D, 200n, 200n'‧‧‧FCU

202、202’‧‧‧多工器及/或解碼器電路 202, 202'‧‧‧ multiplexer and / or decoder circuit

204、204’‧‧‧比較電路 204, 204'‧‧‧ comparison circuit

206、206’‧‧‧指紋形成電路 206, 206'‧‧‧ Fingerprinting circuit

208‧‧‧安全儲存電路 208‧‧‧Safe storage circuit

300、400、404‧‧‧邏輯 300, 400, 404‧‧ ‧ Logic

402‧‧‧邏輯關係 402‧‧‧Logical relationship

500‧‧‧傳統介面電路 500‧‧‧Traditional interface circuit

502‧‧‧可程式化熔絲電路 502‧‧‧Programmable fuse circuit

700‧‧‧系統 700‧‧‧ system

702‧‧‧系統電路 702‧‧‧System Circuit

704‧‧‧處理電路 704‧‧‧Processing Circuit

706‧‧‧記憶體電路 706‧‧‧ memory circuit

708‧‧‧電源電路 708‧‧‧Power circuit

710‧‧‧使用者介面電路 710‧‧‧User interface circuit

712‧‧‧通訊介面電路 712‧‧‧Communication interface circuit

714‧‧‧通訊模組 714‧‧‧Communication Module

Q1、Q2、Q3、Q4、Q5、Q6、Q7、Q8、Q9‧‧‧電晶體 Q1, Q2, Q3, Q4, Q5, Q6, Q7, Q8, Q9‧‧‧ transistors

Qref‧‧‧基準電晶體 Qref‧‧‧ reference transistor

R1、R2、R3、R4、R5、R6‧‧‧電阻器 R1, R2, R3, R4, R5, R6‧‧‧ resistors

V1、V2、V3‧‧‧電壓 V1, V2, V3‧‧‧ voltage

VLA、VLB、VLn‧‧‧左側電壓 VLA, VLB, VLn‧‧‧ left voltage

VRA、VRB、VRn‧‧‧右側電壓 VRA, VRB, VRn‧‧‧ right voltage

Vref‧‧‧電壓降 Vref‧‧‧ voltage drop

Vs‧‧‧供應電壓 Vs‧‧‧ supply voltage

所聲明之專利標的的特性及優點將隨著以下實施方式的繼續,及對圖示的參考而變得明顯,其中相似數字指定相似部分,且其中:圖1根據本揭示發明的至少一個實施例描繪包含至少基於生產特性之硬體保護的範例積體電路裝置;圖2根據本揭示發明的至少一個實施例描繪範例硬體保護電路;圖3根據本揭示發明的至少一個實施例描繪生產特性單元結構及解譯器電路操作的範例;圖4根據本揭示發明的至少一個實施例描繪生產特性單元結構及解譯器電路操作的替代範例;圖5根據本揭示發明的至少一個實施例描繪包括傳統 介面電路的範例硬體保護電路;圖6根據本揭示發明的至少一個實施例描繪用於指紋決定的範例操作;圖7根據本揭示發明的至少一個實施例描繪可使用諸如描繪於圖1中之裝置範例系統;及圖8根據本揭示發明的至少一個實施例描繪用於積體電路裝置認證的範例操作。 The features and advantages of the claimed subject matter will be apparent from the following description of the embodiments of the invention. An exemplary integrated circuit device including hardware protection based at least on production characteristics is depicted; FIG. 2 depicts an example hardware protection circuit in accordance with at least one embodiment of the present disclosure; FIG. 3 depicts a production feature unit in accordance with at least one embodiment of the present disclosure. Example of Structure and Interpreter Circuit Operation; FIG. 4 depicts an alternative example of a production characteristic cell structure and interpreter circuit operation in accordance with at least one embodiment of the present disclosure; FIG. 5 depicts a conventional process in accordance with at least one embodiment of the present disclosure. Example hardware protection circuit of interface circuit; FIG. 6 depicts example operations for fingerprint determination in accordance with at least one embodiment of the present disclosure; FIG. 7 depicts, for example, depicted in FIG. 1 in accordance with at least one embodiment of the present disclosure. Apparatus Example System; and FIG. 8 depicts example operations for integrated circuit device authentication in accordance with at least one embodiment of the present disclosure.

雖然以下詳細描述將參考說明實施例而繼續,彼等的許多改變、修改、及變化對熟悉本技術的人士將係明顯的。 While the following detailed description will be described with reference to the embodiments of the invention,

【發明內容與實施方式】 SUMMARY OF THE INVENTION AND EMBODIMENTS

此揭示發明關於基於生產特性之硬體保護。通常,積體電路(IC)裝置可組態成至少基於該裝置的生產特性決定邏輯值或「指紋」的串。範例裝置可包含至少對應於該裝置之該功能目的的功能電路及硬體保護電路(HPC)。範例HPC可包括解譯器電路及指紋電路。例如,該解譯器電路可量測該指紋電路中之至少一個電子組件的至少一個參數(例如,電壓),且在至少一個實施例中,可比較從該指紋電路中之不同組件量測的電壓,然後基於各組件比較的結果指派邏輯一或零至該指紋串。範例電子組件可包括電晶體、電阻器等,其效能可取決於該裝置的該生產特性。所產生的指紋串可由包括該裝置的系統使用以認證該裝置。認證該裝置失敗可導致至少一個安全操作執行以 保護系統不受裝置破壞。 This disclosure relates to hardware protection based on production characteristics. Typically, an integrated circuit (IC) device can be configured to determine a logical value or a "fingerprint" string based at least on the production characteristics of the device. The example device can include functional circuitry and hardware protection circuitry (HPC) that correspond at least to the functional purpose of the device. An example HPC can include an interpreter circuit and a fingerprint circuit. For example, the interpreter circuit can measure at least one parameter (eg, voltage) of at least one electronic component of the fingerprint circuit, and in at least one embodiment, can compare measurements from different components in the fingerprint circuit The voltage is then assigned a logic one or zero to the fingerprint based on the result of each component comparison. Example electronic components can include transistors, resistors, etc., the performance of which can depend on the manufacturing characteristics of the device. The resulting fingerprint string can be used by a system including the device to authenticate the device. Failure to authenticate the device may result in at least one secure operation being performed The protection system is not damaged by the device.

在至少一個實施例中,範例IC裝置可包括至少基板、功能電路、及HPC。該功能電路可生產在該基板上。該HPC也可生產在該基板上並可包括,例如,至少指紋電路及解譯器電路以基於該指紋電路的生產特性決定該裝置的指紋。 In at least one embodiment, an example IC device can include at least a substrate, a functional circuit, and an HPC. The functional circuit can be produced on the substrate. The HPC can also be produced on the substrate and can include, for example, at least a fingerprint circuit and an interpreter circuit to determine the fingerprint of the device based on the production characteristics of the fingerprint circuit.

在至少一個實施例中,該解譯器電路可量測對應於指紋電路中之至少一個生產特性單元(FCU)的至少一個電壓。該至少一個FCU可包括僅專用於裝置中之指紋決定的至少一個電子組件。 In at least one embodiment, the interpreter circuit can measure at least one voltage corresponding to at least one of the production characteristic units (FCUs) in the fingerprint circuit. The at least one FCU can include at least one electronic component that is dedicated only to fingerprint decisions in the device.

在相同或不同實施例中,該解譯器電路可用以比較從該指紋電路中之至少二個電子組件量測的電壓。例如,該裝置中的指紋串可包含對應於各電壓比較的邏輯值,然後若該二電壓滿足特定關係,解譯器電路可指派邏輯一至指紋串,且若該二電壓不滿足特定關係,可指派邏輯零至該指紋串。例如,該特定關係可係該二電壓的第一電壓大於或少於該二電壓之第二電壓的一者。或者,該特定關係可係該二電壓之間的差之絕對值大於或少於標準值的一者。 In the same or different embodiments, the interpreter circuit can be used to compare voltages measured from at least two of the electronic components of the fingerprint circuit. For example, the fingerprint string in the device may include a logical value corresponding to each voltage comparison, and then if the two voltages satisfy a particular relationship, the interpreter circuit may assign a logic one to a fingerprint string, and if the two voltages do not satisfy a particular relationship, Assign a logic zero to the fingerprint string. For example, the particular relationship can be one of the first voltage of the two voltages being greater or less than the second voltage of the two voltages. Alternatively, the particular relationship may be one in which the absolute value of the difference between the two voltages is greater or less than a standard value.

在相同或不同實施例中,該至少二個電子組件可係電晶體或電阻器。或者,該至少二個電子組件可包含各者包括耦接至電阻器之至少一個電晶體的組件群組。該至少二個電子組件的一者可指定為基準,且各後續電子組件可與該基準比較。在一範例實作中,解譯器電路可包含至少比較電路及指紋形成電路。解譯器電路也可包含多工器電 路、解碼器電路、或安全儲存電路的至少一者。解譯器電路也可包含傳統介面以導致該指紋寫至該裝置內的熔絲電路。與本揭示發明一致地,例如,一種用於制訂IC裝置之指紋的方法可包含初始化IC裝置;初始化該裝置中的指紋決定及基於該裝置的生產特性決定該裝置的指紋。 In the same or different embodiments, the at least two electronic components can be transistors or resistors. Alternatively, the at least two electronic components can include a group of components each including at least one transistor coupled to the resistor. One of the at least two electronic components can be designated as a reference, and each subsequent electronic component can be compared to the reference. In an example implementation, the interpreter circuit can include at least a comparison circuit and a fingerprint forming circuit. The interpreter circuit can also include multiplexer power At least one of a path, a decoder circuit, or a secure storage circuit. The interpreter circuit can also include a conventional interface to cause the fingerprint to be written to the fuse circuit within the device. Consistent with the disclosed invention, for example, a method for formulating a fingerprint of an IC device can include initializing an IC device; initializing a fingerprint determination in the device and determining a fingerprint of the device based on production characteristics of the device.

圖1根據本揭示發明的至少一個實施例描繪包含至少基於生產特性之硬體保護的範例積體電路裝置。最初,可對各種半導體配件及/或結構產生基準,諸如,電晶體、電阻器、比較器、多工器、解碼器、儲存結構等。已參考此等範例配件及/或結構以提供自其理解本文揭示的各種實施例之易於理解的角度,且未企圖將實際實作僅限制在此等特定配件或結構。另外,包括在圖式中的項目編號之後的單引號(例如,100’)可指示顯示該特定項目的範例實施例。此等範例實施例未企圖將本揭示發明僅限制在所說明的內容,並僅為了解釋的目的而呈現在本文中。 1 depicts an example integrated circuit device including hardware protection based at least on production characteristics, in accordance with at least one embodiment of the present disclosure. Initially, benchmarks can be created for various semiconductor components and/or structures, such as transistors, resistors, comparators, multiplexers, decoders, storage structures, and the like. The example fittings and/or structures have been referred to in order to provide an easy understanding of the various embodiments disclosed herein, and are not intended to limit the actual implementations only to such particular accessories or structures. Additionally, a single quotation mark (e.g., 100') that is included after the item number in the drawing may indicate an example embodiment of displaying the particular item. The example embodiments are not intended to limit the invention to the description, and are presented herein for the purpose of explanation.

將裝置100描繪在圖1中。裝置100可係包含,例如,經由一系列半導體生產操作沈積之一或多個層的IC裝置。用於沈積半導體材料之層的範例技術可包括,但未限於,分子束磊晶(MBE)、物理氣相沈積(PVD)、化學氣相沈積(CVD)、電化學沈積(ECD)、原子層沈積(ALD)等。座落在層間的接面可使用光微影修改以合併各種特徵。裝置100可包含,例如,功能電路102及HPC 104。功能電路102可實施與裝置100之主功能關聯的至少一個操作。例如,功能電路102可包括用於唯讀記憶體 (ROM)的資料儲存區、或用於微處理器的資料處理電路等。功能電路102的組態、內容等可取決於裝置種類、組態、封裝、技術、功率限制(例如,用於行動裝置)等變化。 Apparatus 100 is depicted in FIG. Device 100 can include, for example, an IC device that deposits one or more layers via a series of semiconductor fabrication operations. Exemplary techniques for depositing layers of semiconductor material can include, but are not limited to, molecular beam epitaxy (MBE), physical vapor deposition (PVD), chemical vapor deposition (CVD), electrochemical deposition (ECD), atomic layers. Deposition (ALD), etc. The junctions located between the layers can be modified using light lithography to incorporate various features. Device 100 can include, for example, functional circuitry 102 and HPC 104. Functional circuit 102 can implement at least one operation associated with the primary function of device 100. For example, functional circuit 102 can include read only memory (ROM) data storage area, or data processing circuit for microprocessor. The configuration, content, etc. of the functional circuit 102 may vary depending on the type of device, configuration, packaging, technology, power limitations (eg, for mobile devices), and the like.

與本揭示發明一致地,HPC 104可包含至少解譯器電路106及指紋電路108。解譯器電路可決定指紋電路108的至少一個生產特性,然後其可用於制訂裝置100的指紋。如本文參考的,「生產特性」可包括可基於裝置100如何生產而變化之指紋電路108中的至少一個電子組件之操作的參數。例如,隨機摻雜劑波動(RDF)可在生產期間區分每個單一電晶體,且因此,每個單一電晶體的效能可彼此偏離。電壓、電流、電阻等可僅基於半導體生產處理的各種細微差別在生產在裝置100中的各電子組件(例如,電晶體、電阻器)中變化。與本揭示發明一致地,此等效能偏離可用於編碼對各裝置100獨特的位元串或「指紋」而不需要明顯地編程該位元串。取而代之的,以對裝置100獨特且不能複製地方式基於生產處理將電子組件本質地「編程」為不同。 Consistent with the disclosed invention, HPC 104 can include at least interpreter circuit 106 and fingerprint circuit 108. The interpreter circuit can determine at least one production characteristic of the fingerprint circuit 108, which can then be used to formulate a fingerprint for the device 100. As referred to herein, "production characteristics" may include parameters of the operation of at least one of the electronic components in the fingerprint circuit 108 that may vary based on how the device 100 is produced. For example, random dopant fluctuations (RDF) can distinguish each single transistor during production, and thus, the performance of each single transistor can deviate from each other. The voltage, current, resistance, and the like may vary in various electronic components (eg, transistors, resistors) produced in the device 100 based only on various subtle differences in semiconductor manufacturing processes. Consistent with the disclosed invention, this equivalent energy offset can be used to encode a bit string or "fingerprint" unique to each device 100 without the need to explicitly program the bit string. Instead, the electronic components are essentially "programmed" differently based on the production process in a manner that is unique to the device 100 and not replicable.

不能在另一裝置中複製裝置100之指紋(例如,使得其他裝置可模仿裝置100)係HPC 104的重大益處。此可藉由要求裝置100的指紋串係基於直接從指紋電路108中之電子組件取得的量測產生而完成。回應於從系統接收之對裝置100的要求等,指紋位元串的量測及產生可在,例如,裝置100初始化時、在裝置100嵌入於其中之系統初 始化時發生。然後從指紋電路108直接取得的量測可用於產生指紋位元串,且因此不可複製,因為彼等係基於裝置100之製造特定的特性。在範例裝置100包含僅專用於指紋產生之指紋電路108的同時,在與本揭示發明一致的另一實施例中,指紋電路108可從裝置100省略且解譯器電路106可替代地量測功能電路102內之電子組件的特性。以此方式,功能電路102可為二目的服務:實施與裝置100關聯的主功能並也提供可針對決定對應於裝置100之指紋而量測的一或多個電子組件。 The inability to replicate the fingerprint of device 100 in another device (e.g., such that other devices can mimic device 100) is a significant benefit of HPC 104. This can be accomplished by requiring the fingerprint string of device 100 to be generated based on measurements taken directly from the electronic components in fingerprint circuit 108. In response to the request to the device 100 received from the system, etc., the measurement and generation of the fingerprint bit string can be, for example, at the beginning of the device 100 initialization, at the beginning of the system in which the device 100 is embedded. Occurs when initializing. The measurements taken directly from the fingerprint circuit 108 can then be used to generate a fingerprint bit string, and thus cannot be duplicated, as they are based on the manufacturing-specific characteristics of the device 100. While the example device 100 includes a fingerprint circuit 108 dedicated only to fingerprint generation, in another embodiment consistent with the disclosed invention, the fingerprint circuit 108 can be omitted from the device 100 and the interpreter circuit 106 can alternatively measure functionality. The characteristics of the electronic components within circuit 102. In this manner, functional circuit 102 can serve a two-purpose service: implementing a primary function associated with device 100 and also providing one or more electronic components that can be measured for determining a fingerprint corresponding to device 100.

圖2根據本揭示發明的至少一個實施例描繪範例HPC。最初,在圖2中以點虛線顯示的電路可係選擇性的,其中包括該選擇性電路可係實作相依的(例如,基於裝置尺寸、技術、封裝、限制、指紋電路108’的尺寸等)。HPC 104’可包含至少解譯器電路106’及指紋電路108’。指紋電路108’可包括,例如,FCU 200A、FCU 200B、FCU 200C、FCU 200D...FCU 200n(共同稱為FCU 200A...n)。FCU 200A...n各者可包括至少一個電子組件(例如,電晶體、電阻器、或其組合)。將用於FCU 200A...n的至少二個範例組件組態描繪於圖3及4中。 2 depicts an example HPC in accordance with at least one embodiment of the disclosed invention. Initially, the circuitry shown in dotted lines in FIG. 2 may be optional, including the selective circuitry being operative (eg, based on device size, technology, package, limitations, size of fingerprint circuit 108', etc. ). The HPC 104' may include at least an interpreter circuit 106' and a fingerprint circuit 108'. Fingerprint circuitry 108' may include, for example, FCU 200A, FCU 200B, FCU 200C, FCU 200D ... FCU 200n (collectively referred to as FCUs 200A...n). Each of the FCUs 200A...n can include at least one electronic component (eg, a transistor, a resistor, or a combination thereof). The configuration of at least two example components for the FCUs 200A...n is depicted in Figures 3 and 4.

在操作範例中,解譯器電路104’可量測FCU 200A...n各者中之至少一個組件的特性,並可使用該量測產生指紋位元串。解譯器電路106’可包含,例如,多工器及/或解碼器電路202、比較電路204、指紋形成電路206、及安全儲存電路208。多工器及/或解碼器電路202可包括電路 以選擇用於由比較電路204處理的一或多個FCU 200A...n(例如,單獨選擇FCU 200A、選擇FCU 200A及FCU 200B等)。比較電路204可量測(及/或決定)來自各FCU 200A...n的特性(例如,電壓、電流、電阻、電容、電感等),並可實施從相同的FCU 200A...n取得的特性之間,從不同FCU 200A...n取得的特性之間等的比較。與本揭示發明一致地,比較結果可變換為邏輯值(例如,一「1」或零「0」),然後可將其提供至指紋形成電路206。指紋形成電路206可將邏輯值連接成形成裝置100之指紋的位元串。在至少一個實施例中,所產生的位元串可儲存在安全儲存電路208中。安全儲存電路208可係在HPC 104’內的加密儲存區或記憶體,用於儲存稍後由,例如,裝置100併入其中之系統存取的指紋串。例如,安全儲存電路208可用允許系統解密及讀取指紋串的方式加密。系統可基於指紋認證裝置100。在另一實施例中,安全儲存電路208可省略,且包括裝置100的系統可直接從指紋形成電路206接收指紋串。 In an operational example, interpreter circuit 104' may measure characteristics of at least one of each of FCUs 200A...n and may use the measurements to generate a fingerprint bit string. The interpreter circuit 106' can include, for example, a multiplexer and/or decoder circuit 202, a comparison circuit 204, a fingerprint forming circuit 206, and a secure storage circuit 208. Multiplexer and/or decoder circuit 202 may include circuitry To select one or more FCUs 200A...n for processing by comparison circuit 204 (e.g., FCU 200A, FCU 200A, FCU 200B, etc. are selected separately). Comparison circuit 204 can measure (and/or determine) characteristics (eg, voltage, current, resistance, capacitance, inductance, etc.) from each FCU 200A...n and can be implemented from the same FCU 200A...n Between the characteristics, the comparison between the characteristics obtained from the different FCUs 200A...n. Consistent with the disclosed invention, the comparison result can be converted to a logical value (e.g., a "1" or zero "0"), which can then be provided to the fingerprint forming circuit 206. Fingerprint forming circuitry 206 can connect the logical values into a string of bits that form the fingerprint of device 100. In at least one embodiment, the generated bit string can be stored in secure storage circuitry 208. The secure storage circuit 208 can be tied to an encrypted storage area or memory within the HPC 104' for storing fingerprint strings that are later accessed by, for example, the system into which the device 100 is incorporated. For example, secure storage circuitry 208 can be encrypted in a manner that allows the system to decrypt and read fingerprint strings. The system can be based on the fingerprint authentication device 100. In another embodiment, the secure storage circuit 208 can be omitted and the system including the device 100 can receive the fingerprint string directly from the fingerprint forming circuit 206.

圖3根據本揭示發明的至少一個實施例描繪生產特性單元結構及解譯器電路操作的範例。FCU 200A’、200B’、...200n’(共同稱為FCU 200A’...n’)各者可包含電路以產生可在比較電路204’中比較的電壓。FCU 200A’...n’中的電路通常可包含可自其導出電壓的至少一個電子組件,諸如,電晶體、電阻器、或其組合。邏輯值(1或0)可基於各電壓比較的結果決定。各邏輯值可加 至可形成裝置100之指紋的位元串。 3 depicts an example of a production characteristic cell structure and interpreter circuit operation in accordance with at least one embodiment of the present disclosure. Each of FCUs 200A', 200B', ... 200n' (collectively referred to as FCUs 200A'...n') may include circuitry to generate voltages that are comparable in comparison circuit 204'. The circuitry in the FCUs 200A'...n' can generally include at least one electronic component from which a voltage can be derived, such as a transistor, a resistor, or a combination thereof. The logic value (1 or 0) can be determined based on the result of each voltage comparison. Each logical value can be added To a string of bits that can form the fingerprint of device 100.

例如,FCU 200A’可包含至少電晶體Q1及電晶體Q2。FCU 200A’的左側電壓(VLA)及FCU 200A’的右側電壓(VRA)可基於供應至二電晶體的供應電壓(Vs)產生。電晶體Q1及Q2可切換至「開啟」,其中彼等的閘極也可耦接至Vs。與本揭示發明一致地,電晶體Q1及Q2可分別耦接至至少電阻器R1及電阻器R2。例如,電阻器R1及R2的電阻值可選擇成僅大至足以使電晶體Q1及Q2的操作特性穩定,免於受隨機變化影響。相似地,FCU 200B’可基於電晶體Q3、電晶體Q4、電阻器R3及R4產生左側電壓(VLB)及右側電壓(VRB),且FCU 200n’可基於電晶體Q5、電晶體Q6、電阻器R5及R6產生左側電壓(VLn)及右側電壓(VRn)。在僅描繪三個FCU 200A’...n’的同時,FCU的實際數目可係實作相依的。 For example, FCU 200A' can include at least transistor Q1 and transistor Q2. The left side voltage (VLA) of the FCU 200A' and the right side voltage (VRA) of the FCU 200A' can be generated based on the supply voltage (Vs) supplied to the two transistors. The transistors Q1 and Q2 can be switched to "on", and their gates can also be coupled to Vs. In accordance with the disclosed invention, transistors Q1 and Q2 can be coupled to at least resistor R1 and resistor R2, respectively. For example, the resistance values of resistors R1 and R2 can be selected to be only large enough to stabilize the operational characteristics of transistors Q1 and Q2 from random variations. Similarly, FCU 200B' can generate left side voltage (VLB) and right side voltage (VRB) based on transistor Q3, transistor Q4, resistors R3 and R4, and FCU 200n' can be based on transistor Q5, transistor Q6, resistor R5 and R6 generate a left voltage (VLn) and a right voltage (VRn). While only three FCUs 200A'...n' are depicted, the actual number of FCUs can be implemented to be dependent.

在操作範例中,裝置100中的電路(例如,比較電路204’)可導致多工器或解碼器電路202’相繼選擇各FCU 200A’...n’。例如,FCU 200A’的選擇可導致將VLA及VLB提供至比較電路204’,其可包括用於比較從FCU 200A’接收之電壓的範例邏輯300。如在302所示的,比較電路204’可比較接收的左側電壓(VL)及接收的右側電壓(VR)。例如,若決定VL大於VR(例如,VL>VR),則針對指派至指紋位元串,將「1」的邏輯值傳至指紋形成電路206’。否則可將「0」的邏輯值傳至指 紋形成電路206’。替代邏輯顯示在304,其中VL及VR之間的差的絕對值(例如,|VL-VR|)可與預定標準值比較。若決定絕對值大於預定標準值,則可將「1」傳至指紋形成電路。否則可將「0」的邏輯值傳至指紋形成電路206’。顯示在302及304的邏輯僅係範例。其他邏輯關與本揭示發明一致係可能的。 In an operational paradigm, circuitry in device 100 (e.g., comparison circuit 204') may cause multiplexer or decoder circuitry 202' to select each of FCUs 200A'...n' in succession. For example, selection of FCU 200A' may result in providing VLA and VLB to comparison circuit 204', which may include example logic 300 for comparing the voltage received from FCU 200A'. As shown at 302, comparison circuit 204' compares the received left side voltage (VL) with the received right side voltage (VR). For example, if it is determined that VL is greater than VR (e.g., VL > VR), the logical value of "1" is passed to fingerprint generation circuit 206' for assignment to the fingerprint bit string. Otherwise, the logical value of "0" can be passed to The pattern forming circuit 206'. The alternate logic is shown at 304, where the absolute value of the difference between VL and VR (eg, |VL-VR|) can be compared to a predetermined standard value. If it is determined that the absolute value is greater than the predetermined standard value, "1" can be transmitted to the fingerprint forming circuit. Otherwise, the logical value of "0" can be passed to the fingerprint forming circuit 206'. The logic shown at 302 and 304 is only an example. Other logic is consistent with the disclosed invention.

然後比較電路204’可導致多工器或解碼器電路202’通過FCU 200B’以比較VLB及VRB,且最終通過FCU 200n’以比較VLn及VRn。相關於指紋形成電路206’說明此等比較的範例結果。對應於FCU 200A’的位元可係「1」,因為決定VLA大於VRA、對應於FCU 200B’的位元可係「1」,因為決定VLB大於VRB、且最後,對應於FCU 200n’的位元可係「0」,因為決定VLn少於VRn。結果,指紋串可包括取決於FCU 200A’...n’之總數的11...0。 Comparison circuit 204' may then cause multiplexer or decoder circuit 202' to pass through FCU 200B' to compare VLB and VRB, and finally through FCU 200n' to compare VLn and VRn. Exemplary results of such comparisons are described in relation to fingerprinting circuitry 206'. The bit corresponding to FCU 200A' may be "1" because it is determined that VLA is greater than VRA, and the bit corresponding to FCU 200B' may be "1" because it is determined that VLB is greater than VRB, and finally, bit corresponding to FCU 200n' The element can be "0" because it is determined that VLn is less than VRn. As a result, the fingerprint string can include 11...0 depending on the total number of FCUs 200A'...n'.

圖4根據本揭示發明的至少一個實施例描繪生產特性單元結構及解譯器電路操作的替代範例。在圖4中,各FCU 200A’...n’可使用可僅提供一個特性(例如,電壓)的電路組態。例如,FCU 200A’可提供對應於遍及電晶體Q7之電壓降的電壓V1、FCU 200B’可提供對應於遍及電晶體Q8之電壓降的電壓V2、…、FCU 200n’可提供對應於遍及電晶體Q9之電壓降的電壓V3。當比較電路204可能彼此比較FCU 200A’...n’(例如,V1可與V2比較)的同時,將另一範例實作呈現在圖4中。取而代之的,各 FCU 200A’...n’可與基準電晶體Qref比較。範例邏輯400包括涉及Vref(例如,跨越Qref的電壓降)及V1…(例如,第二值「V1」基於所選擇之FCU 200A’...n’改變)的二邏輯關係。邏輯關係402簡單地決定是否Vref>V1。若決定Vref大於V1,則針對指派至對應於裝置100的指紋位元串將「1」傳至指紋形成電路206’。否則,可傳送「0」。相似地,在邏輯範例404中,若決定|Vref-V1|大於預定標準值,則可將「1」傳至指紋形成206’。否則,可將「0」傳至指紋形成電路206’。然後指紋形成電路206’可將對應於電晶體Qref及FCU 200A’...n’之間的比較的位元連接,以形成對應於裝置100的指紋位元串(例如,10....0)。 4 depicts an alternate example of a production characteristic cell structure and interpreter circuit operation in accordance with at least one embodiment of the present disclosure. In Fig. 4, each FCU 200A'...n' can use a circuit configuration that can provide only one characteristic (e.g., voltage). For example, the FCU 200A' can provide a voltage V1 corresponding to the voltage drop across the transistor Q7, and the FCU 200B' can provide a voltage V2 corresponding to the voltage drop across the transistor Q8. The FCU 200n' can be provided to correspond to the transistor. Q9 voltage drop voltage V3. While the comparison circuit 204 may compare the FCUs 200A'...n' with each other (e.g., V1 may be compared to V2), another example implementation is presented in FIG. Instead, each The FCUs 200A'...n' can be compared to the reference transistor Qref. The example logic 400 includes a two-logic relationship involving Vref (e.g., voltage drop across Qref) and V1... (e.g., the second value "V1" is changed based on the selected FCU 200A'...n'). The logical relationship 402 simply determines if Vref > V1. If it is determined that Vref is greater than V1, "1" is transmitted to the fingerprint forming circuit 206' for the fingerprint bit string assigned to the device 100. Otherwise, "0" can be transmitted. Similarly, in logic example 404, if |Vref-V1| is determined to be greater than a predetermined standard value, then "1" can be passed to fingerprint formation 206'. Otherwise, "0" can be passed to the fingerprint forming circuit 206'. The fingerprint forming circuit 206' can then connect the bits corresponding to the comparison between the transistor Qref and the FCUs 200A'...n' to form a fingerprint bit string corresponding to the device 100 (eg, 10.... 0).

圖5根據本揭示發明的至少一個實施例描繪包括傳統介面電路的範例硬體保護電路。圖5實質相似於揭示於圖2中之HPC 104’的範例組態,但更合併至少傳統介面電路500。可程式化熔絲電路502可用於保護既存IC裝置的完整性。可程式化熔絲電路502可包括,例如,在IC裝置中的可程式化位元(例如,位元陣列),其可用類似於設定雙列式封裝(DIP)開關中之機器開關的方式組態。既存系統在認證IC裝置時可能與可程式化熔絲電路502互動,決定IC裝置是否已受損等。 FIG. 5 depicts an example hardware protection circuit including a conventional interface circuit in accordance with at least one embodiment of the present disclosure. Figure 5 is substantially similar to the example configuration of HPC 104' disclosed in Figure 2, but incorporates at least conventional interface circuit 500. The programmable fuse circuit 502 can be used to protect the integrity of an existing IC device. The programmable fuse circuit 502 can include, for example, programmable bits (e.g., a bit array) in an IC device that can be grouped in a manner similar to setting a machine switch in a dual column package (DIP) switch. state. The existing system may interact with the programmable fuse circuit 502 when authenticating the IC device to determine whether the IC device has been damaged or the like.

與本揭示發明一致地,傳統介面電路500可能使用裝置100的指紋位元串將可程式化熔絲電路502程式化。以此方式,本文描述的指紋決定電路、結構、方法、資料等 可與相容於可程式化熔絲電路502的傳統系統互動。範例傳統介面電路500可包含至少類比至數位轉換器(ADC)以將由指紋決定電路產生的類比資料轉換成數位資料。然後可針對程式化該熔絲,將所產生的數位資料提供至,例如,可程式化熔絲電路內的程式化電路。 Consistent with the disclosed invention, conventional interface circuit 500 may program stylized fuse circuit 502 using the fingerprint bit string of device 100. In this way, the fingerprint determination circuit, structure, method, data, etc. described herein It is possible to interact with conventional systems that are compatible with the programmable fuse circuit 502. The example legacy interface circuit 500 can include at least analog to digital converters (ADCs) to convert analog data generated by the fingerprint decision circuit into digital data. The resulting digital data can then be provided to the stylized fuse to provide, for example, a stylized circuit within the programmable fuse circuit.

圖6根據本揭示發明的至少一個實施例描繪用於指紋決定的範例操作。以點虛線顯示的操作可基於,例如,決定其指紋之裝置的組態、合併該裝置之系統的組態等而係選擇性的。在操作600中,可將裝置初始化,其可包括開機、重開機等該裝置自身、將該裝置併入其中的系統等。指紋決定可在操作602中初始化。作為指紋決定的一部分,可在操作604中決定次一FCU的指紋位元。指紋位元決定可包括,例如,比較FCU之特性(例如,從FCU量測的電壓)及從該FCU量測的另一特性(例如,另一電壓)、從另一FCU量測的特性(例如,從另一FCU量測的電壓)、從基準量測的特性(例如,從基準量測的電壓)等。在量測電壓於此處使用為範例的同時,其他特性可與本揭示發明一致地量測。然後邏輯值(例如,「1」或「0」)可基於該比較決定,且在操作606中,可將邏輯值加至指紋位元串。 6 depicts example operations for fingerprint determination in accordance with at least one embodiment of the present disclosure. The operations shown in dotted lines may be selective based on, for example, the configuration of the device that determines its fingerprint, the configuration of the system that incorporates the device, and the like. In operation 600, the device may be initialized, which may include booting, rebooting, etc. the device itself, a system into which the device is incorporated, and the like. The fingerprint decision can be initialized in operation 602. As part of the fingerprint determination, the fingerprint bit of the next FCU may be determined in operation 604. Fingerprint bit decisions may include, for example, comparing characteristics of the FCU (eg, voltages measured from the FCU) and another characteristic measured from the FCU (eg, another voltage), characteristics measured from another FCU ( For example, the voltage measured from another FCU), the characteristic measured from the reference (for example, the voltage measured from the reference), and the like. While the measurement voltage is used herein as an example, other characteristics can be measured consistent with the disclosed invention. The logical value (e.g., "1" or "0") can then be determined based on the comparison, and in operation 606, the logical value can be added to the fingerprint bit string.

然後可在操作608中產生是否有其他FCU比較待實施的決定(例如,產生指紋位元串的額外位元)。在操作608中之有額外FCU比較待實施的決定後,可返回至操作604以實施次一比較。若在操作608中決定所有比較均已 實施,則在操作610中可輸出指紋位元串。操作612關於可基於裝置/系統之組態實施的選擇性操作。例如,指紋位元串可儲存在裝置100中(例如,在安全記憶體電路中),或可針對在將也在該裝置中的可程式化熔絲電路程式化時使用,轉換為另一格式。 A decision may then be made in operation 608 as to whether other FCUs are to be compared (e.g., to generate additional bits of the fingerprint bit string). After the additional FCU in operation 608 compares the decisions to be implemented, it may return to operation 604 to perform the next comparison. If in operation 608 it is determined that all comparisons have been Implemented, a fingerprint bit string can be output in operation 610. Operation 612 pertains to selective operations that may be implemented based on the configuration of the device/system. For example, the fingerprint bit string can be stored in device 100 (eg, in a secure memory circuit) or can be converted to another format for use in staging a programmable fuse circuit that is also in the device. .

圖7根據本揭示發明的至少一個實施例描繪可使用諸如描繪於圖1中之裝置範例系統。系統700係可將一或多個裝置,諸如,裝置100,安裝於其中之平台的範例,且未企圖將本揭示發明限制在任何特定實作方式。系統700的範例可包括,但未限於,行動通訊裝置,諸如,蜂巢式手機或基於來自谷歌公司之Android® OS、來自蘋果公司的iOS®或Mac OS®、來自微軟公司的Windows® OS、來自Linux基金會的Tizen® OS、來自Mozilla計畫的Firefox® OS、來自黑莓公司的Blackberry® OS、來自惠普科技公司的Palm® OS、來自Symbian基金會的Symbian® OS等的智慧型手機、行動計算裝置,諸如,平板電腦,像是來自蘋果公司的iPad®、來自微軟公司的Surface®、來自三星公司的Galaxy Tab®、來自Amazon公司的Kindle®等、包括來自Intel公司之低功率晶片組的超輕薄筆記型電腦®、易網機、筆記型電腦、膝上型電腦、掌上型電腦等、典型靜止的計算裝置,諸如,桌上型電腦、伺服器、智慧型電視、小尺寸計算解決方案(例如,用於空間有限的應用、TV機上盒等),像是來自Intel公司的次世代計算單元(NUC)平台等。 7 depicts an example system that can be used, such as that depicted in FIG. 1, in accordance with at least one embodiment of the present disclosure. System 700 is an example of a platform in which one or more devices, such as device 100, may be installed, and is not intended to limit the disclosed invention to any particular implementation. Examples of system 700 may include, but are not limited to, a mobile communication device such as a cellular handset or based on Android® OS from Google Inc., iOS® or Mac OS® from Apple, Windows® OS from Microsoft, from Tizen® OS from the Linux Foundation, Firefox® OS from Mozilla Project, Blackberry® OS from BlackBerry, Palm® OS from HP Technologies, Symbian® OS from the Symbian Foundation, mobile computing, mobile computing Devices such as tablets, such as iPad® from Apple, Surface® from Microsoft, Galaxy Tab® from Samsung, Kindle® from Amazon, etc., include ultra-power chipsets from Intel Corporation Lightweight Notebook®, EasyMesh, Notebook, Laptop, Palm, etc., typical stationary computing devices such as desktops, servers, smart TVs, small form factor computing solutions ( For example, for applications with limited space, TV set-top boxes, etc.), such as the Next Generation Computing Unit (NUC) platform from Intel Corporation.

系統電路702可管理系統700的操作。系統電路702可包括,例如,處理電路704、記憶體電路706、電源電路708、使用者介面電路710、及通訊介面電路712。系統700可更包括通訊模組714。當將通訊模組714描繪為與系統電路702分離時,顯示於圖7中的範例組態僅為了解釋的目的而提供。例如,與通訊模組714關聯的部分或全部功能也可併入系統電路702中。 System circuitry 702 can manage the operation of system 700. System circuitry 702 can include, for example, processing circuitry 704, memory circuitry 706, power supply circuitry 708, user interface circuitry 710, and communication interface circuitry 712. System 700 can further include a communication module 714. When communication module 714 is depicted as being separate from system circuit 702, the example configuration shown in Figure 7 is provided for purposes of explanation only. For example, some or all of the functionality associated with communication module 714 can also be incorporated into system circuitry 702.

在系統700中,處理電路704可包含位於分離組件上的一或多個處理器,或替代地在單一組件中的一或多個核心(例如,在系統單晶片(SoC)組態中),以及處理器有關的支援電路(例如,橋接介面等)。範例處理器可包括,但未限於,提供自Intel公司的各種基於x86的微處理器,包括在Pentium、Xeon、Itanium、Celeron、Atom、Quark、Core i系列、Core M系列產品家族中的微處理器、先進RISC(例如,精簡指令集計算)機器或「ARM」處理器等。支援電路的範例可包括組態成提供介面的晶片組(例如,提供自Intel公司的北橋、南橋等),處理電路704可經由該晶片組與系統700中之可用不同速度操作、在不同匯流排上等的其他系統組件互動。再者,與支援電路共同關聯的部分或所有功能也可包括在與處理器(例如,提供自Intel公司之Sandy Bridge處理器家族)相同的實體封裝中。 In system 700, processing circuit 704 can include one or more processors located on separate components, or alternatively in one or more cores of a single component (eg, in a system single-chip (SoC) configuration), And processor-related support circuits (for example, bridge interfaces, etc.). Example processors may include, but are not limited to, various x86-based microprocessors from Intel Corporation, including micro-processing in the Pentium, Xeon, Itanium, Celeron, Atom, Quark, Core i series, Core M family of products. , advanced RISC (for example, reduced instruction set computing) machines or "ARM" processors. Examples of support circuits may include a chipset configured to provide an interface (e.g., Northbridge, Southbridge, etc. from Intel Corporation) via which the processing circuitry 704 can operate at different speeds in the system 700, at different busbars Other system components interact with each other. Moreover, some or all of the functionality associated with the support circuitry may also be included in the same physical package as the processor (eg, the Sandy Bridge processor family provided by Intel Corporation).

處理電路704可組態成在系統700中執行各種指令。指令可包括組態成導致處理電路704實施有關於讀取資 料、寫入資料、處理資料、制訂資料、轉換資料、變換資料等之活動的程式碼。資訊(例如,指令、資料等)可儲存在記憶體電路706中。記憶體電路706可包括採用固定或可移除格式的隨機存取記憶體(RAM)及/或唯讀記憶體(ROM)。RAM可包括組態成在系統700的操作期間保持資訊的揮發性記憶體,諸如,靜態RAM(SRAM)或動態RAM(DRAM)。ROM可包括基於BIOS、UEFI等組態成當系統700啟動時提供指令的非揮發性(NV)記憶體、可程式化記憶體,諸如,電子可程式化ROM(EPROM)、快閃記憶體等。其他固定/可移除記憶體可包括,但未限於,磁性記憶體,諸如,軟碟、硬碟等、電子記憶體,諸如,固態快閃記憶體(例如,嵌入式多媒體卡(eMMC)等)、可移除記憶體卡或棒(例如,微儲存裝置(uSD)、USB等)、光學記憶體,諸如,基於光碟的ROM(CD-ROM)、數位視訊光碟(DVD)、藍光光碟等。 Processing circuitry 704 can be configured to execute various instructions in system 700. The instructions can include being configured to cause the processing circuit 704 to implement the readout The code of the activity of writing, writing data, processing data, formulating data, converting data, changing data, etc. Information (eg, instructions, materials, etc.) can be stored in the memory circuit 706. Memory circuit 706 can include random access memory (RAM) and/or read only memory (ROM) in a fixed or removable format. The RAM may include volatile memory configured to maintain information during operation of system 700, such as static RAM (SRAM) or dynamic RAM (DRAM). The ROM may include non-volatile (NV) memory, programmable memory, such as electronically programmable ROM (EPROM), flash memory, etc., configured to provide instructions when the system 700 is booted based on BIOS, UEFI, and the like. . Other fixed/removable memories may include, but are not limited to, magnetic memories such as floppy disks, hard disks, etc., electronic memories such as solid state flash memory (eg, embedded multimedia cards (eMMC), etc. ), removable memory card or stick (eg, micro storage device (uSD), USB, etc.), optical memory, such as CD-ROM, digital video disc (DVD), Blu-ray Disc, etc. .

電源電路708可包括組態成以操作所需之電力供應系統700的內部電源(例如,電池、燃料電池等)及/或外部電源(例如,機電或太陽能發電機、電網、外部燃料電池等)、及相關電路。使用者介面電路710可包括硬體及/或軟體以允許使用者與系統700互動,諸如,各種輸入機制(例如,麥克風、開關、按鍵、旋鈕、鍵盤、揚聲器、觸控表面、組態成擷取影像及/或感測鄰近度、距離、動作、手勢、定向、生物資料等的一或多個感測 器),及各種輸出機制(例如,揚聲器、顯示器、發光/閃爍指示器、用於振動、動作等的機電組件)。使用者介面電路710中的硬體可併入系統700內及/或可經由有線或無線通訊媒體耦接至系統700。使用者介面電路710在特定環境中可係選擇性的,諸如,系統700係不包括使用者電路710,並替代地依賴用於使用者介面功能的另一裝置(例如,管理終端)之伺服器(例如,機架式伺服器、刀鋒式伺服器等)的情況。 The power circuit 708 can include an internal power source (eg, a battery, a fuel cell, etc.) and/or an external power source (eg, an electromechanical or solar generator, a power grid, an external fuel cell, etc.) configured to operate the desired power supply system 700. And related circuits. The user interface circuit 710 can include hardware and/or software to allow a user to interact with the system 700, such as various input mechanisms (eg, microphones, switches, buttons, knobs, keyboards, speakers, touch surfaces, configured to Taking images and/or sensing one or more sensing of proximity, distance, motion, gestures, orientation, biometrics, etc. And various output mechanisms (eg, speakers, displays, illuminating/flashing indicators, electromechanical components for vibration, motion, etc.). The hardware in the user interface circuit 710 can be incorporated into the system 700 and/or can be coupled to the system 700 via a wired or wireless communication medium. The user interface circuit 710 is selectable in a particular environment, such as the system 700 does not include the user circuit 710 and instead relies on a server of another device (eg, a management terminal) for user interface functionality. (For example, rack server, blade server, etc.).

通訊介面電路712可組態成管理封包路由及用於通訊模組714的其他控制功能,其可包括組態成支援有線及/或無線通訊的資源。在部分實例中,系統700可包含由集中式通訊介面電路712管理之一個以上的通訊模組714(例如,包括用於有線協定及/或無線電的分離式實體介面模組)。有線通訊可包括串聯及並聯有線媒體,諸如,乙太網路、USB、火線(Firewire)、Thunderbolt、數位視訊介面(DVI)、高解析多媒體介面(HDMI)等。無線通訊可包括,例如,近距離無線媒體(例如,基於RF識別(RFID)或近場通訊(NFC)標準、紅外線(IR)等的射頻(RF))、短距離無線媒體(例如,藍牙、WLAN、Wi-Fi等)、長距離無線媒體(例如,蜂巢式廣域無線電通訊技術、基於衛星的通訊等)、經由聲波的電子通訊等。在一實施例中,通訊介面電路712可組態成防止在通訊模組714中活動的無線通訊彼此干擾。在實施此功能時,通訊介面電路712可基於,例如,訊息等待傳輸 的相對優先度排程通訊模組714的活動。在揭示於圖7中的實施例描繪通訊介面電路712係與通訊模組714分離的同時,將通訊介面電路712及通訊模組714的功能併入相同模組中也可係可能的。 Communication interface circuit 712 can be configured to manage packet routing and other control functions for communication module 714, which can include resources configured to support wired and/or wireless communication. In some examples, system 700 can include one or more communication modules 714 (eg, including separate physical interface modules for wired protocols and/or radios) managed by centralized communication interface circuitry 712. Wired communications may include serial and parallel wired media such as Ethernet, USB, Firewire, Thunderbolt, Digital Video Interface (DVI), High Resolution Multimedia Interface (HDMI), and the like. Wireless communications may include, for example, short-range wireless media (eg, radio frequency (RF) based on RF (RFID) or near field communication (NFC) standards, infrared (IR), etc.), short-range wireless media (eg, Bluetooth, WLAN, Wi-Fi, etc., long-distance wireless media (for example, cellular wide-area radio communication technology, satellite-based communication, etc.), electronic communication via sound waves, and the like. In an embodiment, the communication interface circuit 712 can be configured to prevent wireless communications that are active in the communication module 714 from interfering with each other. When implementing this function, the communication interface circuit 712 can be based on, for example, a message waiting for transmission The relative priority schedules the activity of the communication module 714. While the embodiment disclosed in FIG. 7 depicts that the communication interface circuit 712 is separate from the communication module 714, it is also possible to incorporate the functions of the communication interface circuit 712 and the communication module 714 into the same module.

圖8根據本揭示發明的至少一個實施例描繪用於積體電路裝置認證的範例操作。通常,指紋位元串可用於認證裝置100,以決定裝置100的完整度(例如,其可指示裝置100的安全是否已受損)等。如圖7所揭示的,在將裝置100積集在系統700中之前,可記錄及儲存其之「已知良好」的指紋。例如,在裝置製造期間,可由製造商決定及儲存裝置100的指紋。然後可經由,例如,基於雲端的架構(例如,至少一個可經由網路,諸如,網際網路,存取的伺服器)使此資訊稍後變得可用。系統700可能在啟動期間從基於雲端的架構取得儲存的指紋資料,並可使用取得的指紋資料認證裝置100。或者,指紋可儲存在各裝置自身內(例如,在安全儲存電路208內)。當裝置100首次開機時,指紋資料可係暫時可存取的。系統700可在最初開機期間記錄來自裝置100的指紋資訊,然後該指紋可從安全儲存電路208清除。在後續初始化期間,裝置100可基於生產特性產生指紋,且裝置100的認證可藉由比較啟動期間產生的指紋及從安全儲存電路208原始取得的指紋資料而決定。在另一範例實作中,指紋資料可永久儲存在安全儲存電路208中,且僅有包含特定組態(例如,包括特定IC裝置、晶片組、程式等)的系統100可 能存取所儲存的指紋資料。系統700可使用儲存的指紋資料以基於由裝置100產生的指紋位元串認證裝置100(例如,如上文所述的)。 8 depicts example operations for integrated circuit device authentication in accordance with at least one embodiment of the present disclosure. In general, a fingerprint bit string can be used to authenticate device 100 to determine the integrity of device 100 (eg, it can indicate whether the security of device 100 has been compromised), and the like. As disclosed in FIG. 7, the "known good" fingerprint can be recorded and stored before the device 100 is accumulated in the system 700. For example, the fingerprint of device 100 can be determined and stored by the manufacturer during device manufacture. This information can then be made available later, for example, via a cloud-based architecture (eg, at least one server accessible via a network, such as the Internet). The system 700 may retrieve stored fingerprint data from the cloud-based architecture during startup and may authenticate the device 100 using the acquired fingerprint data. Alternatively, the fingerprints may be stored within each device itself (eg, within secure storage circuitry 208). When the device 100 is turned on for the first time, the fingerprint data can be temporarily accessible. System 700 can record fingerprint information from device 100 during initial power up, and then the fingerprint can be cleared from secure storage circuit 208. During subsequent initialization, device 100 may generate a fingerprint based on the production characteristics, and authentication of device 100 may be determined by comparing fingerprints generated during startup and fingerprint data originally obtained from secure storage circuitry 208. In another example implementation, the fingerprint data may be permanently stored in the secure storage circuit 208, and only the system 100 containing a particular configuration (eg, including a particular IC device, chipset, program, etc.) may be Can access the stored fingerprint data. System 700 can use the stored fingerprint data to authenticate device 100 based on the fingerprint bit string generated by device 100 (eg, as described above).

在操作800至810,系統可認證至少一個裝置。在操作800中,可將系統初始化。然後在操作802中,系統可接收來自裝置的指紋。例如,接收自該裝置的指紋可使用諸如圖6中揭示的操作產生。在操作804中,該系統可將接收自該裝置的指紋對該裝置之已知良好的指紋驗證。該已知良好的指紋可由該系統以諸如上述方式得到。然後在操作806中產生指紋是否匹配的決定。若在操作806中決定指紋匹配,則該系統可在操作808中繼續初始化。若在操作806中決定指紋不匹配,則在操作810中安全異常可發生。範例安全異常可中斷裝置及/或系統的初始化、可觸發系統中的安全保全(例如,封鎖、資料加密等)、可對系統之使用者、裝置/系統的製造商、裝置/系統的經銷商產生關於認證裝置失敗的通知等。在至少一個實施例中,操作810之後可係操作808,使得儘管有安全異常,系統可繼續初始化。此可在操作810中的安全異常能保護系統之完整性(例如,以隔絕不能認證的任何裝置)而不必將整體系統停止的實例中發生。 At operations 800 through 810, the system can authenticate at least one device. In operation 800, the system can be initialized. Then in operation 802, the system can receive a fingerprint from the device. For example, fingerprints received from the device can be generated using operations such as those disclosed in FIG. In operation 804, the system can verify the known good fingerprint of the device from the fingerprint received by the device. This known good fingerprint can be obtained by the system in such a manner as described above. A determination is then made in operation 806 as to whether the fingerprints match. If fingerprint matching is determined in operation 806, the system may continue initialization in operation 808. If a fingerprint mismatch is determined in operation 806, a security exception may occur in operation 810. Example security exceptions can interrupt the initialization of devices and/or systems, trigger security in the system (eg, blockade, data encryption, etc.), users of the system, manufacturers of devices/systems, distributors of devices/systems A notification regarding the failure of the authentication device is generated. In at least one embodiment, operation 810 can be followed by operation 808 such that the system can continue initialization despite a security exception. This can occur in instances where the security anomaly in operation 810 can protect the integrity of the system (eg, to isolate any device that cannot be authenticated) without having to stop the overall system.

在圖6及8描繪根據不同實施例的操作的同時,待理解不係描畫在圖6及8中的所有操作對其他實施例均係必要的。事實上,本文完全預期在本揭示發明的其他實施例中,描畫於圖6及8中的操作,及/或本文描述的其他操 作可用未具體顯示在任何圖式中的方法組合,但仍完全與本揭示發明一致。因此,相信相關於未確實顯示在一圖式中的特徵及/或操作的申請專利範圍係在本揭示發明的範圍及內容內。 While Figures 6 and 8 depict operations in accordance with various embodiments, it is to be understood that not all operations depicted in Figures 6 and 8 are necessary for other embodiments. In fact, it is fully contemplated herein that in other embodiments of the disclosed invention, the operations depicted in Figures 6 and 8 and/or other operations described herein are contemplated. Combinations of methods not specifically shown in any of the figures are possible, but are still fully consistent with the disclosed invention. Therefore, it is believed that the scope of the patents and the scope of the present invention are not limited to the scope of the invention.

如此申請書中及申請專利範圍中所使用的,藉由術語「及/或」結合的項目列表能意指所列項目的任何組合。例如,片語「A、B、及/或C」能意指A;B;C;A及B;A及C;B及C;或A、B、及C。如此申請書中及申請專利範圍中所使用的,藉由術語「至少一者」結合的項目列表能意指所列術語的任何組合。例如,片語「A、B、C的至少一者」能意指A;B;C;A及B;A及C;B及C;或A、B、及C。 The list of items combined by the term "and/or" as used in this application and in the scope of the patent application can mean any combination of the listed items. For example, the phrase "A, B, and/or C" can mean A; B; C; A and B; A and C; B and C; or A, B, and C. As used in this application and in the scope of the claims, the list of items by the term "at least one" can mean any combination of the listed terms. For example, the phrase "at least one of A, B, and C" can mean A; B; C; A and B; A and C; B and C; or A, B, and C.

如在本文之任何實施例中所使用的,術語「系統」可指,例如,組態成實施任何上文提及之操作的軟體、韌體、及/或電路。軟體可具現為記錄在非暫態電腦可讀儲存媒體上的軟體封裝、碼、指令、指令集、及/或資料。韌體可具現為硬編碼(例如,非揮發)在記憶體裝置中的碼、指令、或指令集及/或資料。「電路」,如本文之任何實施例中所使用的,可單獨地或以任何組合地包含硬接電路、可程式化電路,諸如,包含一或多個獨立指令處理核心的電腦處理器、狀態機電路、及/或儲存由可程式.化電路執行之指令的韌體。可將該等模組,共同地或獨立地,具現為形成較大系統之一部分的電路,例如,積體電路(IC)、及系統單晶片(SoC)、桌上型電腦、膝上型 電腦、平板電腦、伺服器、智慧型手機等。 As used in any embodiment herein, the term "system" can refer to, for example, a software, firmware, and/or circuitry configured to perform any of the operations recited above. The software may now be a software package, code, instruction, instruction set, and/or material recorded on a non-transitory computer readable storage medium. The firmware may be a code, instruction, or instruction set and/or material that is now hard coded (eg, non-volatile) in the memory device. A "circuit," as used in any embodiment herein, may comprise a hard-wired circuit, a programmable circuit, such as a computer processor, state comprising one or more independent instruction processing cores, alone or in any combination. Machine circuit, and/or firmware that stores instructions executed by the programmable circuit. The modules, collectively or independently, may be circuits that form part of a larger system, such as integrated circuits (ICs), and system-on-a-chip (SoC), desktop computers, laptops. Computers, tablets, servers, smart phones, etc.

本文描述的任何操作可實作在包括具有獨立或組合地儲存於其上的指令之一或多個儲存媒體(例如,非暫態儲存媒體)的系統中,當指令由一或多個處理器執行時,實施該方法。此處,處理器可包括,例如,伺服器CPU、行動裝置CPU、及/或其他可程式化電路。又,本文描述的操作傾向於可跨越複數個實體裝置散布,諸如,在一個以上不同的實體地點的處理結構。儲存媒體可包括任何種類的實體媒體,例如,任何種類的碟,包括硬碟、軟碟、光碟、光碟唯讀記憶體(CD-ROM)、可重寫光碟(CD-RW)、及磁光碟、半導體裝置,諸如,唯讀記憶體(ROM)、隨機存取記憶體(RAM),諸如,動態及靜態RAM、可抹除可程式化唯讀記憶體(EPROM)、電可抹除可程式化唯讀記憶體(EEPROM)、快閃記憶體、固態硬碟(SSD)、嵌入式多媒體卡(eMMC)、安全數位輸入/輸出(SDIO)卡、磁或光學卡、或適用於儲存電子指令之任何種類的媒體。其他實施例可實作為由可程式化控制裝置執行的軟體模組。 Any of the operations described herein can be implemented in a system including one or more storage media (eg, non-transitory storage media) having instructions stored thereon separately or in combination, when the instructions are by one or more processors When implemented, the method is implemented. Here, the processor may include, for example, a server CPU, a mobile device CPU, and/or other programmable circuitry. Also, the operations described herein tend to be spread across a plurality of physical devices, such as processing structures at more than one different physical location. The storage medium may include any kind of physical media, such as any kind of disc, including hard discs, floppy discs, compact discs, CD-ROMs, rewritable discs (CD-RWs), and magneto-optical discs. , semiconductor devices such as read only memory (ROM), random access memory (RAM), such as dynamic and static RAM, erasable programmable read only memory (EPROM), electrically erasable programmable Read-only memory (EEPROM), flash memory, solid state drive (SSD), embedded multimedia card (eMMC), secure digital input/output (SDIO) card, magnetic or optical card, or for storing electronic instructions Any kind of media. Other embodiments may be implemented as a software module executed by a programmable control device.

因此,此揭示發明關於基於生產特性之硬體保護。通常,積體電路(IC)裝置可組態成至少基於該裝置的生產特性決定邏輯值或「指紋」的串。範例裝置可包含至少對應於該裝置之該功能目的的功能電路及硬體保護電路(HPC)。範例HPC可包括解譯器電路及指紋電路。例如,該解譯器電路可量測該指紋電路中之至少一個電子組 件的至少一個參數(例如,電壓),且在至少一個實施例中,可比較從該指紋電路中之不同組件量測的電壓,然後基於各組件比較的結果指派邏輯一或零至該指紋串。範例電子組件可包括電晶體、電阻器等,其效能可取決於該裝置的該生產特性。 Thus, this disclosure relates to hardware protection based on production characteristics. Typically, an integrated circuit (IC) device can be configured to determine a logical value or a "fingerprint" string based at least on the production characteristics of the device. The example device can include functional circuitry and hardware protection circuitry (HPC) that correspond at least to the functional purpose of the device. An example HPC can include an interpreter circuit and a fingerprint circuit. For example, the interpreter circuit can measure at least one electronic group in the fingerprint circuit At least one parameter (eg, voltage) of the component, and in at least one embodiment, the voltages measured from different components in the fingerprint circuit can be compared, and then a logic one or zero is assigned to the fingerprint string based on the results of the component comparisons . Example electronic components can include transistors, resistors, etc., the performance of which can depend on the manufacturing characteristics of the device.

以下範例關於其他實施例。本揭示發明的下列範例可包含主題材料,諸如,裝置、方法、用於儲存當執行時導致機器實施基於該方法的行動之指令的至少一個機器可讀媒體、用於實施基於該方法之行動的機構、及/或用於基於生產特性之硬體保護的系統。 The following examples pertain to other embodiments. The following examples of the disclosed invention may include subject matter, such as apparatus, methods, at least one machine readable medium for storing instructions that when executed cause a machine to perform actions based on the method, for performing actions based on the method Institutions, and/or systems for hardware protection based on production characteristics.

根據範例1,提供一種積體電路裝置。該裝置可包含基板、生產在該基板上的功能電路、及生產在該基板上的硬體保護電路,該硬體保護電路包括至少指紋電路及解譯器電路以基於該指紋電路的生產特性決定該裝置的指紋。 According to the first example, an integrated circuit device is provided. The device may include a substrate, a functional circuit produced on the substrate, and a hardware protection circuit produced on the substrate, the hardware protection circuit including at least a fingerprint circuit and an interpreter circuit to determine based on a production characteristic of the fingerprint circuit The fingerprint of the device.

範例2可包括範例1的元件,其中該解譯器電路係用以量測對應於指紋電路中之至少一個生產特性單元的至少一個電壓。 Example 2 can include the elements of Example 1, wherein the interpreter circuit is operative to measure at least one voltage corresponding to at least one of the production characteristic units of the fingerprint circuit.

範例3可包括範例2的元件,其中該至少一個生產特性單元可包括僅專用於裝置中之指紋決定的至少一個電子組件。 Example 3 can include the elements of Example 2, wherein the at least one production characteristic unit can include at least one electronic component that is dedicated only to fingerprint determinations in the device.

範例4可包括範例1至3之任一者的元件,其中該解譯器電路係用以比較從該指紋電路中之至少二個電子組件量測的電壓。 Example 4 can include the components of any of examples 1 to 3, wherein the interpreter circuit is operative to compare voltages measured from at least two of the electronic components of the fingerprint circuit.

範例5可包括範例4的元件,其中該裝置中的指紋串 包含對應於各電壓比較的邏輯值且該解譯器電路係用以若該二電壓滿足特定關係,指派邏輯一至該指紋串,且若該二電壓不滿足該特定關係,指派邏輯零至該指紋串。 Example 5 can include the components of Example 4, wherein the fingerprint string in the device Included with a logic value corresponding to each voltage comparison and the interpreter circuit is configured to assign a logic one to the fingerprint string if the two voltages satisfy a particular relationship, and assign a logic zero to the fingerprint if the two voltages do not satisfy the particular relationship string.

範例6可包括範例4至5之任一者的元件,其中該特定關係係該二電壓的第一電壓大於或少於該二電壓之第二電壓的一者。 Example 6 can include an element of any of examples 4 to 5, wherein the particular relationship is one of a first voltage of the two voltages being greater than or less than a second voltage of the two voltages.

範例7可包括範例4至6之任一者的元件,其中該特定關係係該二電壓之間的差之絕對值大於或少於標準值的一者。 Example 7 can include the elements of any of Examples 4 to 6, wherein the particular relationship is one in which the absolute value of the difference between the two voltages is greater or less than a standard value.

範例8可包括範例4至7之任一者的元件,其中該至少二個電子組件係電晶體或電阻器。 Example 8 can include the components of any of Examples 4-7, wherein the at least two electronic components are transistors or resistors.

範例9可包括範例4至8之任一者的元件,其中該至少二個電子組件包括電晶體或電阻器的至少一者。 Example 9 can include the component of any of examples 4 to 8, wherein the at least two electronic components comprise at least one of a transistor or a resistor.

範例10可包括範例4至9之任一者的元件,其中該至少二個電子組件包含各者包括耦接至電阻器之至少一個電晶體的組件群組。 Example 10 can include the elements of any of examples 4-9, wherein the at least two electronic components comprise a group of components each comprising at least one transistor coupled to a resistor.

範例11可包括範例4至10之任一者的元件,其中將該至少二個電子組件的一者指定為基準,且各後續電子組件與該基準比較。 Example 11 can include the elements of any of examples 4 to 10, wherein one of the at least two electronic components is designated as a reference, and each subsequent electronic component is compared to the reference.

範例12可包括範例1至11之任一者的元件,其中該解譯器電路包含至少比較電路及指紋形成電路。 Example 12 can include the elements of any of examples 1 to 11, wherein the interpreter circuit includes at least a comparison circuit and a fingerprint forming circuit.

範例13可包括範例1至12之任一者的元件,其中該解譯器電路包含多工器電路、解碼器電路、或安全儲存電路的至少一者。 Example 13 can include the elements of any of examples 1 to 12, wherein the interpreter circuit comprises at least one of a multiplexer circuit, a decoder circuit, or a secure storage circuit.

範例14可包括範例1至13之任一者的元件,其中該解譯器電路包含傳統介面以導致該指紋寫至該裝置內的熔絲電路。 Example 14 can include the elements of any of examples 1 to 13, wherein the interpreter circuit includes a conventional interface to cause the fingerprint to be written to a fuse circuit within the device.

範例15可包括範例1至14之任一者的元件,其中該硬體保護電路係用以在該積體電路裝置的製造期間提供該指紋至外部追蹤系統。 Example 15 can include the components of any of examples 1-14, wherein the hardware protection circuitry is to provide the fingerprint to an external tracking system during manufacture of the integrated circuit device.

範例16可包括範例15的元件,其中包括該積體電路裝置的系統係用以從該外部追蹤系統得到該指紋以認證該積體電路裝置。 Example 16 can include the elements of Example 15, wherein the system including the integrated circuit device is operative to obtain the fingerprint from the external tracking system to authenticate the integrated circuit device.

根據範例17,提供一種用於制訂積體電路裝置之指紋的方法。該方法可包含初始化積體電路裝置、初始化該裝置中的指紋決定、及基於該裝置的生產特性決定該裝置的指紋。 According to Example 17, a method for formulating a fingerprint of an integrated circuit device is provided. The method can include initializing the integrated circuit device, initializing a fingerprint determination in the device, and determining a fingerprint of the device based on the production characteristics of the device.

範例18可包括範例17的元件,其中基於生產特性決定指紋的步驟包含對該裝置中之指紋電路中的至少一個電子組件量測電壓。 Example 18 can include the elements of Example 17, wherein the step of determining a fingerprint based on production characteristics comprises measuring a voltage of at least one of the fingerprint circuits in the device.

範例19可包括範例18的元件,其中基於生產特性決定指紋的步驟包含若從該指紋電路量測的第一電壓及第二電壓滿足特定關係,指派邏輯一至該裝置中的指紋串,該指紋串包括對應於各電壓比較的邏輯值,及若該第一電壓及該第二電壓不滿足該特定關係,指派邏輯零至該指紋串。 Example 19 can include the elements of example 18, wherein the step of determining a fingerprint based on production characteristics includes assigning a logic to a fingerprint string in the device if the first voltage and the second voltage measured from the fingerprint circuit satisfy a particular relationship, the fingerprint string A logic value corresponding to each voltage comparison is included, and if the first voltage and the second voltage do not satisfy the particular relationship, a logic zero is assigned to the fingerprint string.

範例20可包括範例19的元件,其中該特定關係係該第一電壓大於或少於該第二電壓的一者。 Example 20 can include the element of example 19, wherein the particular relationship is that the first voltage is greater than or less than one of the second voltages.

範例21可包括範例19至20之任一者的元件,其中該特定關係係該第一電壓及該第二電壓之間的差之絕對值大於或少於特定標準值的一者。 The example 21 can include the element of any one of examples 19 to 20, wherein the particular relationship is one of an absolute value of a difference between the first voltage and the second voltage being greater than or less than a particular standard value.

範例22可包括範例19至21之任一者的元件,並可更包含儲存該指紋串。 Example 22 can include elements of any of Examples 19-21, and can further include storing the fingerprint string.

範例23可包括範例17至22之任一者的元件,並可更包含在包括至少該裝置的系統中,企圖基於該指紋認證該裝置、基於認證失敗,在該系統上實施至少一個安全操作、及基於認證成功,允許該系統在初始化內繼續。 Example 23 can include the elements of any of Examples 17 to 22, and can be further included in a system including at least the device, in an attempt to authenticate the device based on the fingerprint, perform at least one security operation on the system based on the authentication failure, And based on successful authentication, the system is allowed to continue during initialization.

範例24可包括範例23的元件,並可更包含基於認證失敗,實施與安全異常關聯的至少一個活動。 Example 24 can include the elements of example 23, and can further include implementing at least one activity associated with the security exception based on the authentication failure.

範例25可包括範例17至24之任一者的元件,並可更包含在該積體電路裝置的製造期間提供該指紋至外部系統。 Example 25 can include the elements of any of Examples 17-24, and can further include providing the fingerprint to an external system during manufacture of the integrated circuit device.

根據範例26,提供一種包括至少一個裝置的系統,該系統配置成實施上述範例17至25之任一者的方法。 According to example 26, there is provided a system comprising at least one device configured to implement the method of any of the above examples 17 to 25.

根據範例27,提供一種配置成實施上述範例17至25之任一者的方法的晶片組。 According to Example 27, a chip set configured to implement the method of any of the above Examples 17 to 25 is provided.

根據範例28,提供至少一種機器可讀媒體,包含複數個指令,回應於該指令在計算裝置上執行,導致該計算裝置實行根據上述範例17至25之任一者的方法。 According to example 28, at least one machine readable medium is provided, comprising a plurality of instructions responsive to the instructions being executed on a computing device, causing the computing device to perform the method according to any of the above examples 17 to 25.

根據範例29,提供組態用於制訂指紋的至少一個裝置,該至少一個裝置配置成實施上述範例17至25之任一者的方法。 According to example 29, at least one device configured to formulate a fingerprint is provided, the at least one device being configured to implement the method of any of the above examples 17 to 25.

根據範例30,提供一種用於制訂積體電路裝置之指紋的系統。該系統可包含用於初始化積體電路裝置的機構、用於初始化該裝置中的指紋決定的機構、及用於基於該裝置的生產特性決定該裝置的指紋的機構。 According to the example 30, a system for formulating a fingerprint of an integrated circuit device is provided. The system can include a mechanism for initializing the integrated circuit device, a mechanism for initializing fingerprint determinations in the device, and a mechanism for determining a fingerprint of the device based on the production characteristics of the device.

範例31可包括範例30的元件,其中用於基於生產特性決定指紋的該機構包含用於對該裝置中之指紋電路中的至少一個電子組件量測電壓的機構。 Example 31 can include the elements of example 30, wherein the mechanism for determining a fingerprint based on production characteristics includes a mechanism for measuring a voltage of at least one of the fingerprint circuits in the device.

範例32可包括範例31的元件,其中用於基於生產特性決定指紋的該機構包含若從該指紋電路量測的第一電壓及第二電壓滿足特定關係,用於指派邏輯一至該裝置中的指紋串的機構,該指紋串包括對應於各電壓比較的邏輯值,及若該第一電壓及該第二電壓不滿足該特定關係,用於指派邏輯零至該指紋串的機構。 Example 32 can include the elements of example 31, wherein the means for determining a fingerprint based on production characteristics includes assigning a logic to a fingerprint in the device if the first voltage and the second voltage measured from the fingerprint circuit satisfy a particular relationship A string of mechanisms, the fingerprint string including a logic value corresponding to each voltage comparison, and a mechanism for assigning a logic zero to the fingerprint string if the first voltage and the second voltage do not satisfy the particular relationship.

範例33可包括範例32的元件,其中該特定關係係該第一電壓大於或少於該第二電壓的一者。 Example 33 can include the element of example 32, wherein the particular relationship is that the first voltage is greater than or less than one of the second voltages.

範例34可包括範例32至33之任一者的元件,其中該特定關係係該第一電壓及該第二電壓之間的差之絕對值大於或少於特定標準值的一者。 The example 34 can include an element of any one of the examples 32 to 33, wherein the particular relationship is one in which the absolute value of the difference between the first voltage and the second voltage is greater than or less than a particular standard value.

範例35可包括範例32至34之任一者的元件,並可更包含用於儲存該指紋串的機構。 Example 35 can include elements of any of Examples 32 through 34, and can further include a mechanism for storing the fingerprint string.

範例36可包括範例30至35之任一者的元件,並可更包含在包括至少該裝置的系統中,用於企圖基於該指紋認證該裝置的機構、基於認證失敗,用於在該系統上實施至少一個安全操作的機構、及基於認證成功,用於允許該 系統在初始化內繼續的機構。 The example 36 can include elements of any of the examples 30 through 35, and can be further included in a system including at least the device for attempting to authenticate the device based on the fingerprint, based on authentication failure, for use on the system An institution that implements at least one secure operation, and based on successful authentication, is used to allow The mechanism that the system continues within the initialization.

範例37可包括範例36的元件,並可更包含基於認證失敗,用於實施與安全異常關聯的至少一個活動的機構。 The example 37 can include the elements of the example 36 and can further include a mechanism for implementing at least one activity associated with the security exception based on the authentication failure.

範例38可包括範例30至36之任一者的元件,並可更包含用於在該積體電路裝置的製造期間提供該指紋至外部系統的機構。 The example 38 can include elements of any of the examples 30 through 36, and can further include means for providing the fingerprint to an external system during manufacture of the integrated circuit device.

將已於本文中使用的術語及表示式使用為描述而非限制項,且在使用此種術語及表示式時未意圖排除所示及描述之該等特性的任何等效實例(或彼等的一部分),並認知各種修改可能在申請專利範圍的範圍內。因此,申請專利範圍企圖涵蓋所有此種等效實例。 The terms and expressions used herein are used to describe and not to limit the invention, and the use of such terms and expressions are not intended to exclude any equivalent examples of the features shown and described (or their Part of it, and recognize that various modifications may be within the scope of the patent application. Therefore, the scope of the patent application is intended to cover all such equivalent examples.

100‧‧‧裝置 100‧‧‧ device

102‧‧‧功能電路 102‧‧‧ functional circuit

104‧‧‧HPC 104‧‧‧HPC

106‧‧‧解譯器電路 106‧‧‧Interpreter circuit

108‧‧‧指紋電路 108‧‧‧Fingerprint circuit

Claims (25)

一種積體電路裝置,包含:基板;功能電路,生產在該基板上;及硬體保護電路,生產在該基板上,該硬體保護電路包括至少指紋電路及解譯器電路以基於該指紋電路的生產特性決定該裝置的指紋。 An integrated circuit device comprising: a substrate; a functional circuit produced on the substrate; and a hardware protection circuit produced on the substrate, the hardware protection circuit comprising at least a fingerprint circuit and an interpreter circuit based on the fingerprint circuit The production characteristics determine the fingerprint of the device. 如申請專利範圍第1項的裝置,其中該解譯器電路係用以比較從該指紋電路中之至少二個電子組件量測的電壓。 The apparatus of claim 1, wherein the interpreter circuit is operative to compare voltages measured from at least two of the electronic components of the fingerprint circuit. 如申請專利範圍第2項的裝置,其中該裝置中的指紋串包含對應於各電壓比較的邏輯值;及該解譯器電路係用以若該二電壓滿足特定關係,指派邏輯一至該指紋串,且若該二電壓不滿足該特定關係,指派邏輯零至該指紋串。 The device of claim 2, wherein the fingerprint string in the device includes a logic value corresponding to each voltage comparison; and the interpreter circuit is configured to assign a logic one to the fingerprint string if the two voltages satisfy a specific relationship And if the two voltages do not satisfy the particular relationship, assign logic zero to the fingerprint string. 如申請專利範圍第2項的裝置,其中該特定關係係該二電壓的第一電壓大於或少於該二電壓之第二電壓的一者。 The device of claim 2, wherein the specific relationship is one of a first voltage of the two voltages being greater than or less than a second voltage of the two voltages. 如申請專利範圍第2項的裝置,其中該特定關係係該二電壓之間的差之絕對值大於或少於標準值的一者。 The device of claim 2, wherein the specific relationship is one in which the absolute value of the difference between the two voltages is greater than or less than a standard value. 如申請專利範圍第2項的裝置,其中該至少二個電子組件係電晶體或電阻器。 The device of claim 2, wherein the at least two electronic components are transistors or resistors. 如申請專利範圍第2項的裝置,其中該至少二個電子組件包含各者包括耦接至電阻器之至少一個電晶體的 組件群組。 The device of claim 2, wherein the at least two electronic components each comprise at least one transistor coupled to the resistor Component group. 如申請專利範圍第2項的裝置,其中將該至少二個電子組件的一者指定為基準,且各後續電子組件與該基準比較。 The device of claim 2, wherein one of the at least two electronic components is designated as a reference and each subsequent electronic component is compared to the reference. 如申請專利範圍第1項的裝置,其中該解譯器電路包含至少比較電路及指紋形成電路。 The device of claim 1, wherein the interpreter circuit comprises at least a comparison circuit and a fingerprint forming circuit. 如申請專利範圍第1項的裝置,其中該解譯器電路包含多工器電路、解碼器電路、或安全儲存電路的至少一者。 The apparatus of claim 1, wherein the interpreter circuit comprises at least one of a multiplexer circuit, a decoder circuit, or a secure storage circuit. 如申請專利範圍第1項的裝置,其中該解譯器電路包含傳統介面以導致該指紋寫至該裝置內的熔絲電路。 A device as claimed in claim 1, wherein the interpreter circuit comprises a conventional interface to cause the fingerprint to be written to a fuse circuit within the device. 一種用於制訂積體電路裝置之指紋的方法,包含:初始化積體電路裝置;初始化該裝置中的指紋決定;及基於該裝置的生產特性決定該裝置的指紋。 A method for formulating a fingerprint of an integrated circuit device, comprising: initializing an integrated circuit device; initializing a fingerprint decision in the device; and determining a fingerprint of the device based on a production characteristic of the device. 如申請專利範圍第12項的方法,其中基於生產特性決定指紋的步驟包含對該裝置中之指紋電路中的至少一個電子組件量測電壓。 The method of claim 12, wherein the step of determining a fingerprint based on the production characteristic comprises measuring a voltage of at least one of the electronic components in the fingerprint circuit in the device. 如申請專利範圍第13項的方法,其中基於生產特性決定指紋的步驟包含:若從該指紋電路量測的第一電壓及第二電壓滿足特定關係,指派邏輯一至該裝置中的指紋串,該指紋串包括對應於各電壓比較的邏輯值;及 若該第一電壓及該第二電壓不滿足該特定關係,指派邏輯零至該指紋串。 The method of claim 13, wherein the step of determining a fingerprint based on the production characteristic comprises: assigning a logic to a fingerprint string in the device if the first voltage and the second voltage measured from the fingerprint circuit satisfy a specific relationship, The fingerprint string includes a logical value corresponding to each voltage comparison; and If the first voltage and the second voltage do not satisfy the particular relationship, a logic zero is assigned to the fingerprint string. 如申請專利範圍第14項的方法,其中該特定關係係該第一電壓大於或少於該第二電壓的一者。 The method of claim 14, wherein the specific relationship is that the first voltage is greater than or less than one of the second voltages. 如申請專利範圍第14項的方法,其中該特定關係係該第一電壓及該第二電壓之間的差之絕對值大於或少於特定標準值的一者。 The method of claim 14, wherein the specific relationship is that the absolute value of the difference between the first voltage and the second voltage is greater than or less than one of a particular standard value. 如申請專利範圍第14項的方法,更包含儲存該指紋串。 For example, the method of claim 14 further includes storing the fingerprint string. 如申請專利範圍第12項之方法,更包含:在包括至少該裝置的系統中,企圖基於該指紋認證該裝置;基於認證失敗,在該系統中實施至少一安全操作;及基於認證成功,允許該系統在初始化內繼續。 The method of claim 12, further comprising: in a system including at least the device, attempting to authenticate the device based on the fingerprint; performing at least one security operation in the system based on the authentication failure; and allowing the authentication to succeed based on the authentication The system continues during initialization. 至少一個具有獨立地或組合地儲存於其上之指令的機器可讀儲存裝置,當該指令由一或多個處理器執行時,用於制訂積體電路裝置的指紋以導致該一或多個處理器用以:初始化積體電路裝置;初始化該裝置中的指紋決定;及基於該裝置的生產特性決定該裝置的指紋。 At least one machine readable storage device having instructions stored thereon independently or in combination, when the instructions are executed by one or more processors, for formulating a fingerprint of the integrated circuit device to cause the one or more The processor is configured to: initialize the integrated circuit device; initialize a fingerprint decision in the device; and determine a fingerprint of the device based on a production characteristic of the device. 如申請專利範圍第19項的儲存裝置,其中基於生產特性決定指紋的該指令包含對該裝置中之指紋電路中的至少一個電子組件量測電壓的指令。 The storage device of claim 19, wherein the instruction to determine a fingerprint based on the production characteristic comprises an instruction to measure a voltage of at least one of the fingerprint circuits in the device. 如申請專利範圍第20項的儲存裝置,其中基於生產特性決定指紋的該指令包含指令用以:若從該指紋電路量測的第一電壓及第二電壓滿足特定關係,指派邏輯一至該裝置中的指紋串,該指紋串包括對應於各電壓比較的邏輯值;及若該第一電壓及該第二電壓不滿足該特定關係,指派邏輯零至該指紋串。 The storage device of claim 20, wherein the instruction for determining a fingerprint based on the production characteristic includes an instruction to: assign a logic to the device if the first voltage and the second voltage measured from the fingerprint circuit satisfy a specific relationship a fingerprint string including a logical value corresponding to each voltage comparison; and if the first voltage and the second voltage do not satisfy the specific relationship, assigning a logic zero to the fingerprint string. 如申請專利範圍第21項的儲存裝置,其中該特定關係係該第一電壓大於或少於該第二電壓的一者。 The storage device of claim 21, wherein the specific relationship is that the first voltage is greater than or less than one of the second voltages. 如申請專利範圍第21項的儲存裝置,其中該特定關係係該第一電壓及該第二電壓之間的差之絕對值大於或少於特定標準值的一者。 The storage device of claim 21, wherein the specific relationship is one in which an absolute value of a difference between the first voltage and the second voltage is greater than or less than a certain standard value. 如申請專利範圍第21項的儲存裝置,更包含指令,當其由一或多個處理器執行時,導致該一或多個處理器用以:儲存該指紋串。 The storage device of claim 21, further comprising instructions that, when executed by one or more processors, cause the one or more processors to: store the fingerprint string. 如申請專利範圍第19項的儲存裝置,更包含指令,當其由一或多個處理器執行時,導致該一或多個處理器用以:在包括至少該裝置的系統中,企圖基於該指紋認證該裝置;基於認證失敗,在該系統上實施至少一個安全操作;及基於認證成功,允許該系統在初始化內繼續。 The storage device of claim 19, further comprising instructions that, when executed by one or more processors, cause the one or more processors to: in a system comprising at least the device, attempt to base the fingerprint Authenticating the device; performing at least one security operation on the system based on the authentication failure; and allowing the system to continue within the initialization based on the successful authentication.
TW105124632A 2015-09-22 2016-08-03 Hardware protection based on fabrication characteristics TW201721506A (en)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/US2015/051345 WO2017052505A1 (en) 2015-09-22 2015-09-22 Hardware protection based on fabrication characteristics

Publications (1)

Publication Number Publication Date
TW201721506A true TW201721506A (en) 2017-06-16

Family

ID=58386814

Family Applications (1)

Application Number Title Priority Date Filing Date
TW105124632A TW201721506A (en) 2015-09-22 2016-08-03 Hardware protection based on fabrication characteristics

Country Status (2)

Country Link
TW (1) TW201721506A (en)
WO (1) WO2017052505A1 (en)

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8160244B2 (en) * 2004-10-01 2012-04-17 Broadcom Corporation Stateless hardware security module
US8868923B1 (en) * 2010-07-28 2014-10-21 Sandia Corporation Multi-factor authentication
WO2012122994A1 (en) * 2011-03-11 2012-09-20 Kreft Heinz Off-line transfer of electronic tokens between peer-devices
WO2013173729A1 (en) * 2012-05-18 2013-11-21 Cornell University Methods and systems for providing hardware security functions using flash memories
US9189654B2 (en) * 2013-12-04 2015-11-17 International Business Machines Corporation On-chip structure for security application

Also Published As

Publication number Publication date
WO2017052505A1 (en) 2017-03-30

Similar Documents

Publication Publication Date Title
US11809544B2 (en) Remote attestation for multi-core processor
US8613074B2 (en) Security protection for memory content of processor main memory
US9755831B2 (en) Key extraction during secure boot
US11070380B2 (en) Authentication apparatus based on public key cryptosystem, mobile device having the same and authentication method
US20170288874A1 (en) Cryptographic protection for trusted operating systems
CN113597600B (en) Data line update for data generation
US11126453B2 (en) Protected regions management of memory
CN113261059B (en) Non-permanent unlocking for secure memory
EP4348931A1 (en) Transfer of ownership of a computing device via a security processor
US11644982B2 (en) Unauthorized access command logging for memory
US10019577B2 (en) Hardware hardened advanced threat protection
US11755210B2 (en) Unauthorized memory access mitigation
CN107667346B (en) Apparatus, method and system for fuse-based firmware block dispatch
CN107077560B (en) System for establishing ownership of secure workspace
TW201721506A (en) Hardware protection based on fabrication characteristics
US20200235917A1 (en) Shared secret generation