IP Library Granted Patent US 12,609,818
Granted Patent B2
US 12,609,818 · App. 17/485,369 · Granted Apr 21, 2026

ISA accessible physical unclonable function

Inventors: Siddhartha Chhabra (Portland, OR); Vedvyas Shanbhogue (Austin, TX); Prashant Dewan (Portland, OR); Baiju Patel (Portland, OR)
Assignee: Intel Corporation
H04L9/0866G06F9/30145H04L9/3278
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,818
App. No.
17/485,369
Granted
Apr 21, 2026
Kind
B2
Abstract

Techniques for encrypting data using a key generated by a physical unclonable function (PUF) or a virtual PUF key are described. An apparatus according to the present disclosure may include decoder circuitry to decode an instance of a single instruction having a field for an opcode to indicate that execution circuitry is to encrypt at least encrypt secret information from an input data structure with either a physical unclonable function (PUF) generated encryption key or a virtual PUF key, bind the wrapped secret information to an identified target, update the input data structure, generate a MAC over the updated data structure, store the MAC in the input data structure to generate a wrapped output data structure, store the wrapped output data structure having the encrypted secret information and an indication of the target.

Claims (25)

1 . An apparatus comprising:

decoder circuitry to decode an instance of a single instruction having a field for an opcode to indicate that execution circuitry is to encrypt at least secret information from an input data structure with either a physical unclonable function (PUF) generated encryption key or a virtual PUF key, bind the encrypted secret information to an identified target, update the input data structure, generate a MAC over the updated data structure, store the MAC in the input data structure to generate a wrapped output data structure, store the wrapped output data structure having the encrypted secret information and an indication of the target, wherein the input data structure is to include a field to identify a challenge used by the PUF to generate the key; and

execution circuitry to execute the decoded instance of the single instruction according to the opcode.

2 . The apparatus of claim 1 , wherein the input data structure is to include an identifier of a target.

3 . The apparatus of claim 1 , wherein the instance of the single instruction is to include an identifier of a destination operand to store an operation status of the execution of the instruction.

4 . The apparatus of claim 1 , wherein the instance of the single instruction is to include an identifier of a source operand which is to store or encode a location of the input data structure.

5 . The apparatus of claim 1 , wherein the instance of the single instruction is to include an identifier of a destination operand which is to store or encode a location of a destination for the wrapped output data structure.

6 . The apparatus of claim 5 , wherein the destination operand is a register.

7 . The apparatus of claim 1 , wherein the output data structure is to include a sequence identifier to be used in decrypting.

8 . The apparatus of claim 1 , wherein an operational status is to indicate one of success, failure, or entropy error.

9 . The apparatus of claim 1 , wherein the execution circuitry is to clear a zero flag (ZF) when the secret information is decrypted successfully, and the execution circuitry is to set the ZF to one otherwise.

10 . The apparatus of claim 1 , wherein the instruction is associated with a most-privileged protection level.

11 . A method comprising:

decoding an instance of a single instruction having a field for an opcode to indicate that execution circuitry is to encrypt at least secret information from an input data structure with either a physical unclonable function (PUF) generated encryption key or a virtual PUF key, bind the encrypted secret information to an identified target, update the input data structure, generate a MAC over the updated data structure, store the MAC in the input data structure to generate a wrapped output data structure, store the wrapped output data structure having the encrypted secret information and an indication of the target wherein the execution circuitry is to clear a zero flag (ZF) when the secret information is encrypted successfully, and the execution circuitry is to set the ZF to one otherwise; and

executing the decoded instruction according to the opcode.

12 . The method of claim 11 , wherein the input data structure is to include an identifier of a target.

13 . The method of claim 11 , wherein the instance of the single instruction is to include an identifier of a destination operand to store an operation status of the execution of the instruction.

14 . The method of claim 11 , wherein the instance of the single instruction is to include an identifier of a source operand which is to store or encode a location of the input data structure.

15 . The method of claim 11 , wherein the instance of the single instruction is to include an identifier of a destination operand which is to store or encode a location of a destination for the wrapped output data structure.

16 . The method of claim 11 , wherein the output data structure is to include a field to identify a challenge used by the PUF to generate the key.

17 . The method of claim 11 , wherein an operational status is to indicate one of success, failure, or entropy error.

18 . The method of claim 11 , wherein the instruction is associated with a most-privileged protection level.

19 . A non-transitory machine-readable medium storing an instance of a single instruction that, when processed by one or more processors, is cause the one or more processors to:

decode the single instruction having a field for an opcode to indicate that execution circuitry is to encrypt at least secret information from an input data structure with either a physical unclonable function (PUF) generated encryption key or a virtual PUF key, bind the encrypted secret information to an identified target, update the input data structure, generate a MAC over the updated data structure, store the MAC in the input data structure to generate a wrapped output data structure, store the wrapped output data structure having the encrypted secret information and an indication of the target, wherein the input data structure is to include a field to identify a challenge used by the PUF to generate the key; and

execute the decoded instruction according to the opcode.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2021
From: CHHABRA, SIDDHARTHA; SHANBHOGUE, VEDVYAS; DEWAN, PRASHANT; PATEL, BAIJU
To: INTEL CORPORATION
Reel/Frame 058510/0945 →
Continuity (1)
Related Publication 20230102178A1 · Mar 30, 2023
References Cited (10)
US 7412053B1 · Lyle · 2008 [cited by examiner]
US 11700135B2 · Chhabra · 2023 [cited by examiner]
US 20040086114A1 · Rarick · 2004 [cited by applicant]
US 20170093567A1 · Gopal et al. · 2017 [cited by applicant]
US 20180145838A1 · Wang · 2018 [cited by examiner]
US 20190103961A1 · Chhabra · 2019 [cited by examiner]
US 20210200880A1 · Khosravi et al. · 2021 [cited by applicant]
US 20210240863A1 · Pelissier · 2021 [cited by examiner]
Kleber et al. Secure Execution Architecture based on {PUF}-driven Instruction Level Code Encryption Cryptology {ePrint} Archive, Paper 2015/651 (Year: 2015). [cited by examiner]
European Search Report and Search Opinion, EP App. No. 22192059.8, Feb. 3, 2023, 9 pages. [cited by applicant]