IP Library › Granted Patent US 11,689,376
Granted Patent B2
US 11,689,376 · App. 17/020,287 · Granted Jun 27, 2023

Security device for generating masking data based on physically unclonable function and operating method thereof

Inventors: Kyoungmoon Ahn (Seoul, KR); Yongki Lee (Suwon-si, KR); Yongsoo Kim (Osan-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
H04L9/3278H04L9/0866H04L2209/04H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,376
App. No.
17/020,287
Granted
Jun 27, 2023
Kind
B2
Abstract

A security device and an operating method thereof, which generate masking data for masking a key on the basis of a physically unclonable function (PUF), are provided. The security device includes a PUF circuit including a plurality of PUF cells outputting random key data and masking data, a key generator configured to generate a key through post-processing performed on the random key data, and a masking module configured to mask and store the key by using the masking data, wherein the random key data and the masking data are generated by different PUF cells.

Claims (52)

1. A security device comprising:

a physically unclonable function (PUF) circuit including a plurality of PUF cells outputting random key data and masking data;

a key generator configured to generate a key through post-processing performed on the random key data; and

a masking module configured to mask and store the key by using the masking data,

wherein the random key data is generated from a first set of one or more PUF cells, and the masking data is generated from a different, second set of one or more PUF cells, wherein the first set of one or more PUF cells are cells that are more stable than cells of the second set of one or more PUF cells.

2. The security device of claim 1 , wherein the PUF circuit comprises a first area including a plurality of first PUF cells and a second area including a plurality of second PUF cells and differing from the first area,

wherein the random key data is generated from the first set of one or more PUF cells, which are part of the plurality of first PUF cells, and

wherein the masking data is generated from the second set of one or more PUF cells, which are part of the plurality of second PUF cells.

3. The security device of claim 1 , wherein the PUF circuit comprises a first area including a plurality of first PUF cells and a second area including a plurality of second PUF cells and differing from the first area,

wherein the random key data is generated from the first set of one or more PUF cells, which are part of the plurality of first PUF cells, and

wherein the masking data is generated from at least some of the plurality of first PUF cells and at least some of the plurality of second PUF cells, which together form the second set of one or more PUF cells.

4. The security device of claim 1 , further comprising a validity detector configured to determine the validity of the plurality of PUF cells and to generate a determination result as a validity map, the validity map reflecting which of the plurality of PUF cells belong the first set of one or more PUF cells and which belong to the second set of one or more PUF cells.

5. The security device of claim 4 , wherein the PUF circuit is configured to access the validity map generated by the validity detector, generate the random key data from valid PUF cells, and generate the masking data from invalid PUF cells, based on the validity map.

6. The security device of claim 4 , wherein the PUF circuit is configured to access the validity map generated by the validity detector, generate the random key data from valid PUF cells, and generate the masking data from at least some of the plurality of PUF cells, based on the validity map.

7. The security device of claim 1 , wherein the PUF circuit is configured to receive an area selection signal and to generate the masking data from PUF cells, included in an area selected based on the area selection signal, among the plurality of PUF cells.

8. The security device of claim 1 , wherein:

the masking module comprises:

a masking circuit configured to receive the key from the key generator and generate a masked key from the key and the masking data;

a key buffer configured to store the masked key; and

a restoration circuit configured to restore the masked key to the key by using the masking data.

9. The security device of claim 8 , wherein:

the masking circuit is configured to generate the masked key through an XOR operation performed on the key and the masking data, and

the restoration circuit is configured to restore the key through an XOR operation performed on the masked key and the masking data.

10. The security device of claim 1 , wherein the masking module is configured to generate new masking data by combining the masking data with a preset bit and to mask the key by using the new masking data.

11. The security device of claim 1 , wherein the masking module is configured to generate new masking data by deleting at least some bits of the masking data and to mask the key by using the new masking data.

12. The security device of claim 1 , wherein the security device is included in an electronic device that includes one or more integrated circuits.

13. A method of generating a security key by using a physically unclonable function (PUF) circuit including a plurality of PUF cells, the method comprising:

generating random key data by using a set of first PUF cells including at least one first PUF cell included in the PUF circuit;

generating a key through post-processing performed on the random key data;

generating masking data by using a set of second PUF cells including at least one second PUF cell included in the PUF circuit;

masking the key by using the masking data to generate a masked key; and

storing the masked key in a key buffer,

wherein the set of first PUF cells include cells that are more stable than cells in the set of second PUF cells.

14. The method of claim 13 , wherein the at least one first PUF cell is included in a first area of the PUF circuit, and the at least one second PUF cell is included in a second area, differing from the first area, of the PUF circuit.

15. The method of claim 13 , wherein the at least one first PUF cell is included in a first area of the PUF circuit, and the at least one second PUF cell is included in a second area of the PUF circuit, and

the first area is included in the second area.

16. The method of claim 13 , further comprising:

determining the validity of the plurality of PUF cells included in the PUF circuit; and

generating a determination result as a validity map.

17. The method of claim 16 , wherein the at least one first PUF cell comprises cells which are determined as more stable cells, which are reflected in the validity map, and the at least one second PUF cell comprises cells which are determined as less stable cells, which are reflected in the validity map.

18. The method of claim 13 , further comprising:

generating the masked key through an XOR operation performed on the key and the masking data; and

restoring the key through an XOR operation performed on the masking data and the masked key.

19. The method of claim 13 , wherein the generating of the masking data comprises:

combining the masking data with a preset bit; and

outputting data, generated based on the combining, as the masking data.

20. A security device comprising:

a physically unclonable function (PUF) block including a plurality of PUF cells outputting random key data and masking data;

a validity detector configured to determine the validity of the plurality of PUF cells and to generate a validity map on the basis of a result of the determination, the validity map indicating valid cells and invalid cells;

a key generator configured to generate a key through post-processing performed on the random key data; and

a masking module configured to mask and store the key by using the masking data,

wherein the PUF block is configured to generate the masking data on the basis of the validity map.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2020
From: AHN, KYOUNGMOON; LEE, YONGKI; KIM, YONGSOO
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 053880/0402 →
Priority Claims (1)
KR 10-2020-0011354 · Jan 30, 2020 · national
Continuity (1)
Related Publication 20210243042A1 · Aug 5, 2021
Cited By (1)
US 12,536,343