IP Library › Granted Patent US 12,748,896
Granted Patent B2
US 12,748,896 · App. 18/661,060 · Granted Sep 29, 2026

Physical unclonable function device and method

Inventor: Francesco La Rosa (Rousset, FR)
Assignee: STMICROELECTRONICS (ROUSSET) SAS
G06F21/75G06F21/72G11C11/4096H03K19/17768H10D84/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,896
App. No.
18/661,060
Granted
Sep 29, 2026
Kind
B2
Abstract

An embodiment system comprises a physical unclonable function device, wherein the device comprises a first assembly of non-volatile memory cells each having a selection transistor embedded in a semiconductor substrate and a depletion-type state transistor having a control gate and a floating gate that are electrically connected, the state transistors having respective effective threshold voltages belonging to a common random distribution, and a processing circuit configured to deliver, to an output interface of the device, a group of output data based on a reading of the effective threshold voltages of the state transistors of the memory cells of the first assembly.

Claims (56)

1 . A system comprising:

a physical unclonable function device, the device comprising:

a first assembly of non-volatile memory cells each having a selection transistor embedded in a semiconductor substrate and a depletion-type state transistor having a control gate and a floating gate that are electrically connected, the depletion-type state transistors having respective effective threshold voltages belonging to a common random distribution; and

a processing circuit configured to deliver, to an output interface of the device, a group of output data, wherein the group of output data is based on readings of the respective effective threshold voltages of the depletion-type state transistors of the non-volatile memory cells of the first assembly, and is based on corresponding reliability information corresponding with the depletion-type state transistors of the non-volatile memory cells of the first assembly, wherein the processing circuit includes:

a reading circuit configured to carry out the readings, wherein the first assembly of non-volatile memory cells is organized into two first matrix sub-assemblies disposed symmetrically with respect to the reading circuit, all rows of the two first matrix sub-assemblies being parallel, the reading circuit being configured to carry out differential readings of pairs of effective threshold voltages of the depletion-type state transistors of pairs of symmetric memory cells located respectively in the two first matrix sub-assemblies on homologous columns of the two first matrix sub-assemblies, and

a second assembly of non-volatile memory cells each having a second selection transistor embedded in the semiconductor substrate and a second depletion-type state transistor having a control gate and a floating gate, the non-volatile memory cells of the second assembly configured to contain the reliability information, wherein the reliability information is representative of a reliability or unreliability of contents of the non-volatile memory cells of the first assembly.

2 . The system according to claim 1 , wherein each memory cell includes a gate oxide disposed between the floating gate of the depletion-type state transistor and the semiconductor substrate, a thickness of the gate oxide being greater than 8 nanometers.

3 . The system according to claim 1 , wherein the second assembly includes a matrix arrangement of memory cells sharing the same columns as those of the matrix arrangement of the memory cells of the first assembly.

4 . The system according to claim 3 , wherein the second assembly includes two second matrix sub-assemblies distributed respectively on either side of the two first matrix sub-assemblies.

5 . The system according to claim 3 , wherein the reliability information associated with the pairs of symmetric memory cells is stored in memory cells of the second assembly located on the same column as those on which corresponding pairs of symmetric memory cells are located.

6 . The system according to claim 1 , wherein the processing circuit includes a first generating circuit configured to generate the reliability information in accordance with a margin value on the differential readings of the effective threshold voltages of the depletion-type state transistors of the pairs of symmetric memory cells.

7 . The system according to claim 6 , wherein the first generating circuit comprises

the reading circuit configured to additionally carry out, for each pair of memory cells of the first assembly:

a first reading of a difference between a current flowing via a first memory cell of the pair increased by a reference current representative of the margin value, and a current flowing via a second memory cell of the pair, so as to obtain a first binary datum; and

a second reading of a difference between the current flowing via the second memory cell increased by the reference current, and the current flowing via the first memory cell, so as to obtain a second binary datum;

a comparison circuit configured to compare one of first or second binary data with an inverse of the other of the first and second binary data and to deliver the reliability information associated with the pair of memory cells, a logic value of which depends on a result of the comparison; and

a writing circuit for writing the reliability information in a corresponding memory cell of the second assembly.

8 . The system according to claim 6 , wherein the first generating circuit comprises:

the reading circuit configured to carry out, for each pair of memory cells of the first assembly:

a first reading of a difference between a current flowing via a first memory cell of the pair increased by a reference current representative of the margin value, and a current flowing via a second memory cell of the pair, so as to obtain a first binary datum;

a second reading of a difference between the current flowing via the second memory cell increased by the reference current and, on the other hand, the current flowing via the first memory cell, so as to obtain a second binary datum;

a comparator configured to carry out:

a comparison of one of first or second binary data with an inverse of the other of the first and second binary data; and

a delivery of a piece of provisional reliability information associated with the pair of memory cells, a logic value of which depends on a result of the comparison; and

a writing circuit configured to:

write the piece of provisional reliability information in a corresponding memory cell of the second assembly; and

a control circuit configured to cause the reading circuit to perform an odd number of the first readings and the second readings and to cause the comparator to perform an odd number of the comparisons and the deliveries so as to obtain an odd number of pieces of provisional stored reliability information; and

a selection circuit configured to carry out a majority vote on the logic values of the provisional reliability information, so as to select the reliability information.

9 . The system according to claim 1 , wherein the processing circuit comprises a second generating circuit configured to generate the group of output data at least from the differential readings of the effective threshold voltages of the depletion-type state transistors of the pairs of symmetric memory cells, and the reliability information of the pairs of symmetric memory cells.

10 . The system according to claim 9 , wherein the second generating circuit is configured to generate the group of output data from the differential readings of the effective threshold voltages of the depletion-type state transistors of the pairs of symmetric memory cells, addresses of columns in which the pairs of symmetric memory cells are located and the reliability information of the pairs of symmetric memory cells.

11 . The system according to claim 10 , wherein the second generating circuit comprises:

the reading circuit configured to carry out, for each pair of memory cells, the differential reading so as to obtain a first piece of binary information having a first logic value;

an inversion circuit configured to invert or not the first logic value as a function of a logic value of a low-weight bit of the address of the column in which the pair is located and to deliver a second piece of binary information having a second logic value; and

a masking circuit configured to retain the second piece of binary information as output data, only if the pair of memory cells is associated with a piece of reliability information designating it as reliable.

12 . The system according to claim 1 , wherein the first assembly of non-volatile memory cells, the second assembly of non-volatile memory cells and the processing circuit are located within the same integrated circuit.

13 . The system according to claim 12 , wherein the system is a system-on-chip comprising:

the same integrated circuit;

a coding/decoding circuit configured to use the group of output data as encryption/decryption key;

a control circuit configured to deliver, to the same integrated circuit, control logic signals and analog voltage signals; and

another non-volatile memory.

14 . The system according to claim 1 , wherein the respective control gate and the respective floating gate of each second depletion-type state transistor are not electrically connected.

15 . A method of operating a system, the method comprising:

reading, with a processing circuit, effective threshold voltages of depletion-type state transistors of a plurality of memory cells of a physical unclonable function device, the plurality of memory cells being arranged in a first assembly of non-volatile memory cells each having a selection transistor embedded in a semiconductor substrate and a depletion-type state transistor having a control gate and a floating gate that are electrically connected, the first assembly of non-volatile memory cells being organized into two first matrix sub-assemblies disposed symmetrically with respect to a reading circuit, all rows of the two first matrix sub-assemblies being parallel, and the reading comprises differentially reading, by the reading circuit in the processing circuit, the effective threshold voltages of the depletion-type state transistors of pairs of symmetric memory cells located respectively in the two first matrix sub-assemblies on homologous columns of the two first matrix sub-assemblies;

accessing reliability information corresponding with the depletion-type state transistors of the non-volatile memory cells of the first assembly, wherein the reliability information is representative of a reliability or unreliability of contents of the non-volatile memory cells of the first assembly;

generating, with the processing circuit, output data based on the effective threshold voltages and the reliability information, the output data being stored in a second assembly of non-volatile memory cells each having a second selection transistor embedded in the semiconductor substrate and a second depletion-type state transistor having a control gate and a floating gate, the non-volatile memory cells of the second assembly being configured to contain the reliability information; and

delivering the output data to an output interface of the physical unclonable function device.

16 . A method comprising:

manufacturing an integrated circuit comprising a physical unclonable function device, said manufacturing of the physical unclonable function device including:

providing a first assembly of non-volatile memory cells each having a selection transistor embedded in a semiconductor substrate and a depletion-type state transistor having a control gate and a floating gate that are electrically connected, the depletion-type state transistors having respective effective threshold voltages belonging to a common random distribution; and

providing a processing circuit configured to deliver, to an output interface of the physical unclonable function device, a group of output data, wherein the group of output data is based on a reading of the respective effective threshold voltages of the depletion-type state transistors of the non-volatile memory cells of the first assembly, and is based on a corresponding group of reliability data corresponding with the depletion-type state transistors of the non-volatile memory cells of the first assembly, the processing circuit including

a reading circuit configured to carry out the readings, the first assembly of non- volatile memory cells being organized into two first matrix sub-assemblies disposed symmetrically with respect to the reading circuit, all rows of the two first matrix sub-assemblies being parallel, the reading circuit being configured to carry out differential readings of pairs of effective threshold voltages of the depletion-type state transistors of pairs of symmetric memory cells located respectively in the two first matrix sub-assemblies on homologous columns of the two first matrix sub-assemblies, and

a second assembly of non-volatile memory cells each having a second selection transistor embedded in the semiconductor substrate and a second depletion-type state transistor having a control gate and a floating gate, the non-volatile memory cells of the second assembly configured to contain the reliability data, wherein the reliability data is representative of a reliability or unreliability of contents of the non-volatile memory cells of the first assembly.

17 . The method according to claim 16 , wherein each memory cell includes a gate oxide disposed between the floating gate of the depletion-type state transistor and the semiconductor substrate, a thickness of the gate oxide being greater than 8 nanometers.

18 . The method according to claim 15 , wherein the respective control gate and the respective floating gate of each second depletion-type state transistor are not electrically connected.

19 . The method according to claim 15 , wherein the output data is generated and stored during a test phase of the physical unclonable function device.

20 . The method according to claim 15 , wherein the output data being stored in the second assembly of non-volatile memory cells comprises reliability information associated with the pairs of symmetric memory cells being stored in memory cells of the second assembly located on the same columns as those on which the corresponding pairs of symmetric memory cells are located.

Priority Claims (1)
FR 2002929 · Mar 25, 2020 · national
Continuity (2)
Continuation 17199438 · Mar 12, 2021
Related Publication 20240296253A1 · Sep 5, 2024
References Cited (34)
US 4612630A · Rosier · 1986 [cited by examiner]
US 5293328A · Amin · 1994 [cited by examiner]
US 5450361A · Iwahashi · 1995 [cited by examiner]
US 6577530B2 · Muranaka · 2003 [cited by examiner]
US 6621734B2 · Hamaguchi · 2003 [cited by examiner]
US 8039886B2 · Mizukami et al. · 2011 [cited by applicant]
US 9385871B2 · Kang · 2016 [cited by examiner]
US 9966954B1 · Yang · 2018 [cited by examiner]
US 10468104B1 · Anand et al. · 2019 [cited by applicant]
US 11139022B1 · Tei · 2021 [cited by examiner]
US 11556657B2 · Toyoshima et al. · 2023 [cited by applicant]
US 20020006054A1 · Shukuri et al. · 2002 [cited by applicant]
US 20020071308A1 · Muranaka · 2002 [cited by examiner]
US 20020181280A1 · Hamaguchi · 2002 [cited by examiner]
US 20130228846A1 · La Rosa · 2013 [cited by examiner]
US 20170090873A1 · Clark et al. · 2017 [cited by applicant]
US 20170180140A1 · Mai · 2017 [cited by examiner]
US 20170200508A1 · Grigoriev et al. · 2017 [cited by applicant]
US 20170278577A1 · La Rosa · 2017 [cited by applicant]
US 20180277496A1 · Lisart et al. · 2018 [cited by applicant]
US 20190068383A1 · Wang · 2019 [cited by examiner]
US 20190121556A1 · Tran et al. · 2019 [cited by applicant]
US 20190237141A1 · La Rosa et al. · 2019 [cited by applicant]
US 20190392179A1 · Lu · 2019 [cited by applicant]
US 20210303735A1 · La Rosa · 2021 [cited by applicant]
CN 1339160A · 2002 [cited by applicant]
CN 108630682A · 2018 [cited by applicant]
CN 109427408A · 2019 [cited by applicant]
CN 110085273A · 2019 [cited by applicant]
CN 110598487A · 2019 [cited by applicant]
CN 216053039U · 2022 [cited by applicant]
Arunkumar Vijayakumar, “Physical Design Obfuscation of Hardware: A Comprehensive Investigation of Deviceand Logic-Level Techniques” IEEE, 2016 IEEE. [cited by examiner]
Qinggui, Z., et al., “A Tutorial on IC Layout Design,” ISBN 978-7-5478-1036-1, Shanghai Science and Technology Press, Mar. 2012, 17 pages. [cited by applicant]
Longxing, Zhang, “Fundamentals of Electronic Technology, Second Edition,” ISBN 7-04-008147-4, Higher Education Press, Jul. 2000, 20 pages. [cited by applicant]