IP Library › Granted Patent US 12,659,176
Granted Patent B2
US 12,659,176 · App. 18/717,243 · Granted Jun 16, 2026

Physically uncloneable function as secure storage

Inventors: Winthrop John Wu (Pleasanton, CA); Scott C. Best (Palo Alto, CA); Joel Wittenauer (Pleasanton, CA)
Assignee: RAmbus Inc.
H04L9/3278G06F21/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,176
App. No.
18/717,243
Granted
Jun 16, 2026
Kind
B2
Abstract

Multiple helper data solutions (a.k.a., helper data images) are generated to produce preselected non-random values (a.k.a., “target values”) from a physically unclonable function (PUF) circuit. Therefore, multiple preselected PUF output values may be generated for a given integrated circuit die, where each the output values are derived from a combination of the chip-unique PUF circuit and the chip-unique helper data solution. These helper data blocks are stored in a nonvolatile memory on the integrated circuit die. In an embodiment, the preselected non-random values may be used as secret encryption or decryption keys. In this manner, multiple secret values can be reliably stored within a chip, using a combination of the chip-unique PUF circuit and the multiple chip-unique helper data solution.

Claims (40)

1 . A method, comprising:

storing first helper data, second helper data, first encrypted data, and second encrypted data in nonvolatile memory of a first integrated circuit;

producing, by a first physically unclonable function (PUF) circuit of the first integrated circuit, a raw PUF output data value;

based on first helper data associated with a first non-random value, producing, by the first integrated circuit, the first non-random value from the raw PUF output data value;

based on second helper data associated with a second non-random value, producing, by the first integrated circuit, the second non-random value from the raw PUF output data value; and

decrypting, by the first integrated circuit, the first encrypted data based on the first non-random value; and

decrypting, by the first integrated circuit, the second encrypted data based on the second non-random value.

2 . The method of claim 1 , wherein the first non-random value comprises a first secret key value that is used to decrypt the first encrypted data and the second non-random value comprises a second secret key value that is used to decrypt the second encrypted data.

3 . The method of claim 1 , further comprising:

generating the first helper data to produce the first non-random value from a first plurality of raw PUF output data values produced by the first PUF circuit; and

generating the second helper data to produce the second non-random value from a second plurality of raw PUF output data values produced by the first PUF circuit.

4 . The method of claim 3 , wherein the first plurality of raw PUF output data values and the second plurality of raw PUF output data values have at least one common raw output data value.

5 . The method of claim 3 , wherein the first plurality of raw PUF output data values is generated by the first PUF circuit during a manufacturing process.

6 . The method of claim 5 , wherein the second plurality of raw PUF output data values is generated by the first PUF circuit after the PUF circuit is deployed to an end-user application.

7 . The method of claim 3 , further comprising:

generating third helper data to produce the first non-random value from a third plurality of raw PUF output data values produced by a second PUF circuit of a second integrated circuit; and

generating fourth helper data to produce the second non-random value from a fourth plurality of raw PUF output data values produced by the second PUF circuit.

8 . An integrated circuit, comprising:

nonvolatile memory to store first encrypted data;

a first physically unclonable function (PUF) circuit to produce a first plurality of raw PUF output data values and a second plurality of raw PUF output data values;

first circuitry to use first helper data to produce a first non-random value from each of the first plurality of raw PUF output data values, and to use second helper data to produce a second non-random value from each of the second plurality of raw PUF output data values; and

decryption circuitry to, based on the first non-random value, decrypt the first encrypted data.

9 . The integrated circuit of claim 8 , wherein the first non-random value is to also be produced by second circuitry in a separate integrated circuit from a third plurality of raw PUF output data values produced by a second PUF circuit in the separate integrated circuit.

10 . The integrated circuit of claim 9 , wherein the first non-random value comprises a first secret key to be used by the integrated circuit to decrypt the first encrypted data stored by the nonvolatile memory of the integrated circuit.

11 . The integrated circuit of claim 10 , wherein the first secret key to be used by the separate integrated circuit to decrypt the first encrypted data stored by the separate integrated circuit.

12 . The integrated circuit of claim 8 , wherein the nonvolatile memory is to store the first helper data and the second helper data.

13 . The integrated circuit of claim 8 , further comprising:

enrollment circuitry to receive a third plurality of raw PUF output data values produced by the first PUF circuit and based on the third plurality of raw PUF output data values, generate the first helper data.

14 . The integrated circuit of claim 8 , further comprising:

second circuitry to transmit a third plurality of raw PUF output data values produced by the first PUF circuit to a host and to receive, from the host, the first helper data.

15 . An integrated circuit, comprising:

a first physically unclonable function (PUF) circuit;

a first nonvolatile memory storing first helper data generated using raw PUF data outputs produced by the first PUF circuit;

first circuitry to receive a first raw PUF data output produced by the first PUF circuit and to, using the first helper data stored in the first nonvolatile memory, produce a first non-random value; and

decryption circuitry to, based on the first non-random value, decrypt first encrypted data stored by the integrated circuit.

16 . The integrated circuit of claim 15 , wherein the first nonvolatile memory also stores second helper data generated using raw PUF data outputs produced by the first PUF circuit, and the first circuitry is to receive a second raw PUF data output produced by the first PUF circuit, and is to, using the second helper data stored in the first nonvolatile memory, produce a second non-random value from the second raw PUF data output.

17 . The integrated circuit of claim 15 , wherein the first nonvolatile memory also stores second helper data generated using raw PUF data outputs produced by the first PUF circuit, and the first circuitry is to receive the first raw PUF data output produced by the first PUF circuit, and is to, using the second helper data stored in the first nonvolatile memory, produce a second non-random value from the first raw PUF data output.

18 . The integrated circuit of claim 15 , wherein the first non-random value is equal to a second non-random value produced by second circuitry in a separate integrated circuit based on a second raw PUF data output produced by a second PUF circuit in the separate integrated circuit using second helper data stored in a second nonvolatile memory in the separate integrated circuit, where the first helper data and the second helper data are not equal.

19 . The integrated circuit of claim 18 , wherein the first non-random value is to decrypt the first encrypted data stored in the first nonvolatile memory to produce first decrypted data and the second non-random value is used to decrypt second encrypted stored in the second nonvolatile memory to produce second decrypted data.

20 . The integrated circuit of claim 19 , wherein the first decrypted data and the second decrypted data are equal.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2024
From: WU, WINTHROP JOHN; BEST, SCOTT C; WITTENAUER, JOEL
To: CRYPTOGRAPHY RESEARCH, INC.
Reel/Frame 067648/0683 →
Continuity (2)
Provisional Application 63286432 · Dec 6, 2021
Related Publication 20250038999A1 · Jan 30, 2025
References Cited (7)
US 9946858B2 · Wallrabenstein · 2018 [cited by applicant]
US 10146464B2 · Murray et al. · 2018 [cited by applicant]
US 10521616B2 · Wallrabenstein · 2019 [cited by applicant]
US 20150234751A1 · Van Der Sluis · 2015 [cited by examiner]
US 20160359636A1 · Kreft · 2016 [cited by examiner]
US 20210271542A1 · Marson · 2021 [cited by examiner]
Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration with Mail Date Mar. 20, 2023 re: Int'l Appln. No. PCT.US2022/051080. 16… [cited by applicant]