T-IFS-05102-2015.R1 1 Abstract—This paper presents a method to simultaneously improve the quality of the identifiers, secret keys, and random numbers that can be generated from the start-up values of standard Static Random Access Memories, SRAMs. The method is based on classifying memory cells after evaluating their startup values at multiple measurements in a registration phase. The registration can be done without unplugging the device from its application context, and with no need for a complex laboratory setup. The method has been validated experimentally with standard low-power SRAM modules in two different Application Specific Integrated Circuits, ASICs, fabricated with 90-nm TSMC technology. The results show that with a simple registration the length of the identifiers can be reduced by 45%, worst-case bit error probability (which defines the complexity of the error correcting code needed to recover a secret key) can be reduced by 64%, and the worst-case minimum entropy value is improved, thus reducing the number of bits that have to be processed to obtain full entropy by 81%. The method can be applied to standard digital designs by controlling the external power supply to the SRAM using software or by incorporating simple circuitry in the design. In the latter case, a module for implementing the method in an ASIC designed in 90-nm TSMC technology occupies an active area of 42,025 μm2. Index Terms—SRAMs, PUFs, random numbers, hardware security I. INTRODUCTION TATIC memory cells have two stable states. They store the logic ‘0’ or ‘1’ that is written in them when they are powered up, and lose information when they are powered down. If they are powered up and no data is written, they reach logic ‘0’ or ‘1’ in a way that can be difficult to predict, to model mathematically, and to clone physically, making them behave as Physical Unclonable Functions, PUFs. It has Manuscript received March 13, 2015; revised June 28, 2015; accepted August 5, 2015. Manuscript received in final form August 18, 2015. This work was supported in part by RTC-2014-2932-8 and TEC2014-57971-R projects from Ministerio de Economía y Competitividad of the Spanish Government (with support from the PO FEDER-FSE). The work of Miguel A. Prada-Delgado was supported by V Plan Propio de Investigación through the University of Seville, Seville, Spain. Copyright (c) 2013 IEEE. Personal use of this material is permitted. However, permission to use this material for any other purposes must be obtained from the IEEE by sending a request to
[email protected]. Iluminada Baturone and Miguel A. Prada-Delgado are with the Microelectronics Institute of Seville (IMSE-CNM), CSIC and University of Seville, Seville, Spain (e-mail: lu[email protected]s,
[email protected]). Susana Eiroa is with ALTER Technology TÜV NORD, Seville, Spain (email: [email protected]m). been observed that many of the memory cells in a memory reach the same start-up values every time that memory is powered up and that those values are not the same as the startup values reached by the cells of other memories [1]-[10]. This property has been exploited to construct identifiers (IDs) which cannot be generated by counterfeit memories and are more difficult to copy because they are generated on the fly rather than being stored. Static memory cells consist of crosscoupled circuits with latches, flip-flops, NOR gates, inverters, etc. Cells based on cross-coupled latches [1] and flip-flops [2] have been employed to identify FPGAs. In [3], cells based on NOR gates were specifically designed to identify ASICs. The memory cells of SRAMs, which consist of cross-coupled inverters, were first proposed in [4] to identify integrated circuit wafers and dies and were later studied by many authors [5]-[10]. This paper focuses on exploiting the standard SRAMs available in many digital circuits for security purposes. Ideally, the two inverters of the SRAM cells should be as identical as possible, since this improves the power and speed characteristics of the memory. However, mismatching produced by fabrication process variability is unavoidable and the two inverters will therefore hardly ever behave in the same way. If the cell is started-up and no value is written, any minor difference between the inverters will cause one of them to start conducting before the other. Due to the amplifying effect of each inverter acting on the output of the other, this will bias, or skew the cell towards ’0’ or ’1’. The work in [5] classifies cells into two basic types: “skewed cells”, displaying high degree of bias and therefore more likely to evolve to one of the stable states, and “neutral cells” that do not have a strong tendency to any state. The big problem when generating identifiers and secret keys is that neutral cells change their start-up value from one generation to another. This is known as the bit flipping problem [6]-[12]. In identification applications, some bit flipping is allowable provided that the identifiers generated by genuine and fake memories are sufficiently different. However, cryptographic keys cannot vary from one realization to another (if they could, it would be impossible to encode and/or authenticate messages correctly). Bit flipping must therefore be removed completely to construct secrets from SRAM responses. For this purpose, Helper Data Algorithms (HDAs) - in particular Code Offset-based HDAs as described in [13] - have been employed. The drawback to this solution is the use of heavy error correction codes (ECCs) [6], [7]. As Improved Generation of Identifiers, Secret Keys, and Random Numbers from SRAMs Iluminada Baturone, Miguel A. Prada-Delgado, and Susana Eiroa S This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 2 reported in [7], [9], the percentage of cells showing bit flipping increases if there are variations in the power supply voltage and increases even more if there are variations in the operating temperature. Many techniques have been reported aimed at minimizing bit flipping. Some of them resort to the full custom VLSI design of memory cells [14]-[15]. In [14], NMOS write drivers and PMOS switches are added to the memory cells while in [15] circuitry is included to add an additional voltage source at the gate of one of the NMOS transistors in the memory cell and evaluate whether the threshold voltage mismatch between the NMOS transistors exceeds a carefully pre-established threshold. In any case, such approaches are more costly than using standard SRAM cells. The problem of using standard SRAM cells is that the influence of temperature and power supply voltage on the final start-up values is difficult to model, although some interesting studies have been carried out in this regard (see [16]). Several authors have proposed experimentally characterizing the behavior of the start-up values at multiple environmental temperatures (at least three temperatures), by using a temperature chamber or a temperature forcing system to control the operating temperature of the memory [17], [18]. As an alternative to this exhaustive characterization of many operating conditions, [12] proposed verifying two corner conditions (high-temperature low-power-supply-voltage and low-temperature low-power- supply-voltage), together with a neighborhood analysis within a memory word to select the most suitable cells for generating identifiers or keys. However, those corner conditions are not common to all SRAMs and neighborhood influence also depends on the particular SRAM in question (for example, strong location-based correlations are reported in [19] but not in other works). Furthermore, startup values are influenced not only by the final supply voltage value but also by the voltage ramp-up time (i.e., the time it takes to reach the operational supply voltage after power-on) [9]. The work in [20] therefore proposed characterizing the SRAM in terms both of power supply ramp-up times and temperatures using the appropriate laboratory equipment in a registration phase and then matching the ramp-up time to the ambient temperature when the start-up values are needed (this can be implemented using a voltage ramp-up regulator, an embedded temperature sensor, an analog to digital converter and a controller). To reduce the percentage of bit flipping, the work in [11] analyzed three reliability enhancing techniques: directed accelerated aging, activation control (which controls the power supply waveform shape, in particular the ramp-up time), and multiple evaluations under nominal operating conditions to generate a “soft” version of the SRAM startup values (the multiple evaluations can then be combined using majority vote or saturating arithmetic to form the final “hard” response). The best results were obtained using the last technique, and it is therefore this technique that this paper explores in greater depth. All the above mentioned works focus on improving the generation of identifiers or secret keys but they do not propose anything regarding random numbers. It must be remembered that while skewed cells are the most suitable for generating reliable identifiers and secret keys, they should not be used to generate sequences of random numbers because their start-up values are repeated over and over again. In contrast, neutral cells, which should not be used to generate identifiers and secret keys, are the best cells for generating random numbers. The metastability of cross-coupled circuits has been widely exploited to produce true random number generators (TRNGs). The earliest solutions, which were based on latches and flip-flops, appeared in [21], [22]. SRAM start-up values were first used as a source of entropy in [5]. Since the entropy provided by standard SRAMs is not very high (because they have many skewed cells), the works in [5] and [23] used a hash function to condense many bits into a much shorter bit string, ensuring full entropy. As in the case of identifiers or secret keys, some techniques have also resorted to the full custom VLSI design of memory cells to generate random numbers, although for this purpose the design objective is just the opposite: to hold the cell at the metastable point or to evaluate the quality of the cell metastability [22], [24]. In [22], a negative feedback loop implemented with a switched capacitor network is employed. In [24] additional circuitry included a completion detector, a time-to-digital converter, and a control system employing statistical information from a set of measurement samples. The work in [25] proposed the inclusion of digital signal processing circuitry to implement 8 NIST (National Institute of Standards and Technology) tests suitable for evaluating the quality of the random numbers as they are generated. All these approaches focus on improving the generation of random numbers, but do not propose anything regarding identifiers and secret keys. The method presented in this paper offers a good tradeoff between implementation cost and improvements in the generation of identifiers, secret keys and random numbers - security primitives required by many cryptographic applications. To the best of the authors’ knowledge, no other method has been proposed to improve the generation of all these primitives simultaneously. The idea is to classify the memory cells of the standard SRAMs available in many digital designs into two disjoint sets, one suitable for generating identifiers or secret keys, and the other suitable for generating random numbers. No complex laboratory setup is required for such classification. The method can be implemented easily with the memory embedded in its application context, either by adding simple circuitry to the digital design or by executing simple software. It does not need to be implemented by specialized vendors, or in the factory where the memory is manufactured. The paper is structured as follows. Section II describes the methodology used to characterize SRAMs, defining the performance metrics and the evaluation strategy followed. Section III contains experimental results for reliability and entropy obtained from standard TSMC 90-nm SRAMs included in two different ASICs. The results obtained with and without classifying the cells are compared and discussed to support the choice of the proposed method. Section IV describes how the method is applied and uses experimental This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 3 results to validate the advantages of its application to generate identifiers, secret keys, and random numbers. A VLSI module was designed in TSMC 90-nm technology to illustrate, together with the SRAMs analyzed, how an ASIC with embedded SRAMs can incorporate the method. The advantages of the method for countering aging are summarized at the end of Section IV. Finally, conclusions are given in Section V. II. METHODOLOGY TO CHARACTERIZE SRAMS A. Performance metrics 1) Reliability The use of start-up values to identify SRAMs consists of two steps, registration and verification. In the registration step, response Ri resulting from the concatenation of the start-up values of n memory cells of the SRAM is stored as the template of that memory. In the verification stage, the start-up values of the n cells are again measured, obtaining response Rj. Ideally, the responses should be the same. However, some bit flipping will inevitably occur. If m responses generated by the same n cells at different times are considered, an estimate of the reliability of the identification is given by the maximum fractional Hamming distance, maxIntraHD, between all the possible pairs of responses. This is defined as follows: 100] ),( [maxmax ,...,1 1,...,1 ⋅= += −= n RRHD ji mij miIntraHD (1) In the ideal situation of 100% reliability, all the responses should be the same, and maxIntraHD will therefore be zero. For secret key generation, the Code Offset-based Helper Data Algorithms, as described in [13], consist of two steps. In the initialization step, a response, R, is provided by the SRAM and a codeword, c, is randomly chosen from an Error Correcting Code (ECC). The XOR of R and c forms the code offset that is stored as helper data, =⨁. In the key generation step, a new response, R’, is provided by the SRAM. The XOR of R’ and the data stored, = ⨁ = ′⊕ ⊕ , enters the decoder of the error correcting code to recover c and then the initial response R, which is used as a seed for a cryptographic key generation algorithm. The worst-case probability that a bit in the SRAM responses may change (the bit error or bit flipping probability p) can be estimated by the maxIntraHD defined in Equation (1). With a probability of 1−p, the bit in the responses does not change. Assuming that all bits in the responses are independent, the probability of exactly t errors occurring in n bits is given by a binomial distribution, as follows: tnt pp t n tP − −⋅⋅ =)1()( (2) Hence, the probability that a string of n bits contains more than t errors is given by: = − −⋅⋅ −= t i ini total pp i n P 0 )1(1 (3) The authors in [13] and [26] proposed the use of the model described above to select the most suitable ECC according to bit error probability, p. Given p (estimated by maxIntraHD) and given an ECC (with n-bit codewords and capacity to correct up to t errors), the capability of the ECC to achieve a given Ptotal can be evaluated with Equation (3). The number of errors to be corrected and, hence, the complexity of the ECC, increases as the value of maxIntraHD gets higher. 2) Minimum entropy Minimum entropy summarizes the adequacy of n memory cells to generate random numbers. According to NIST recommendations [27], minimum entropy measures the worst case of uncertainty in a random variable. If the random variable is the start-up value observed at the i-th memory cell and pimax is the maximum probability of taking logic value ’0’ or ’1’, the minimum entropy of the cell as a binary source of randomness is: () )(log max2min i cell pH −= (4) Assuming that the n memory cells have independent startup values, the minimum entropy of the n-bit sequence (given as a percentage) is: = ⋅−= n ii p n H 1max2min 100)(log 1 (5) For example, if the reliability of the n cells is 100% then the minimum entropy is 0%. In contrast, if the reliability is 0% and the pimax of the n cells is 0.5 then the minimum entropy is 100%. The method described above is used in [23] to evaluate the minimum entropy of SRAMs. The method described in [5] assumes that each byte, instead of each bit, of the SRAM is an independent source. Hence, both methods are similar if no correlation exists between the bits of a specific byte. In any case, correlation between bits should be measured to test whether the assumption for Equation (5) is valid. 3) Stable and unstable cells One way of evaluating whether n memory cells are adequate to generate IDs and secret keys is to measure their start-up values after several power-ups under different operating conditions. The S cells that always provide the same start-up value are adequate to generate IDs while the other U cells should not be used for this purpose (n = S+U). Since the IDs and secret keys are to be reproduced over varying operating conditions, the A cells that are always labeled as S for all the conditions are very adequate to generate them while the B cells that are always labeled as U always introduce bit flipping. There are also C cells, which are stable under certain conditions and unstable under others, so that n = A + B + C. Reliability depends on the percentage of stable cells; that is to This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 4 say, the cells that never show bit flipping. In contrast, the percentage of unstable cells is related to the capability to generate random numbers: 100⋅= n A llsOfStableCePercentage (6) 100⋅= n B CellsOfUnstablePercentage (7) Figure 1 shows the flowchart of the classification process. 4) Independence of sequences Given two sequences of n bits, R and R’, provided by n memory cells of a SRAM, the way to measure their degree of similarity is to evaluate the number of t bits that are different in both sequences. This is given by their Hamming distance. In the ideal situation of 100% independence, the comparison between each pair of bits in the sequences should be essentially a Bernoulli trial, which takes value ’1’ (the bits are different) with probability p (and a value of ’0’ with probability q=1-p). In addition, any given bit in the sequences should be equally likely to be ’1’ or ’0’, i.e., the sequences should be uniform to be unpredictable as commented below. Hence, ideally p=q=0.5 so that nothing is known about the cells that are generating the start-up values (which is which and what values are being generated). If there are no correlations between the bits in different sequences, the probability of exactly t different bits appearing in n trials (HD = t) is given by a binomial distribution, as shown earlier in Equation (2). Given a large set of sequences, the distribution of Hamming distances obtained from all the possible comparisons between different pairs can be approximated by a normal distribution with expected value ⋅ and expected standard deviation ⋅(1−), as stated in the de-Moivre-Laplace theorem. If there are correlations between bits of different sequences, Bernoulli trials remain binomially distributed but with a reduction in the number of independent trials or degrees of freedom, which becomes N instead of n (N < n) (see [28] for a more detailed explanation). Hence, given k sequences of n bits generated by SRAM start-up values, their independence is evaluated by the average inter fractional HD, and by the degrees of freedom, N, as follows: − =+= μ− = 1 11 ),( )1( 2k i k ij ji n RRHD kkn HD (8) 2 1 −⋅ = σ μμ n HD n HD n HD N (9) where σ n HD is the standard deviation of the inter fractional HD. If the n-bit sequences are quite independent, μ n HD will be p= 0.5, σ n HD will be (1−)/, and N will be n. Another way to evaluate whether two n-bit sequences Ri = X1i,X2i, … ,Xni, and Rj = X1j,X2j, …,Xnj, where Xkl=±1 (’0’ values are converted to ’-1’), are independent or noncorrelated is to calculate their scalar product as: == =⋅= n kkij n kkjkiij cXXncorrelatio 11 (10) Correlation is zero (i.e., the sequences are independent) if the number of ckij that are ’1’ is the same as the number of them that are ’-1’, producing a sum of zero. Thus, the condition for no correlation is that the sequence of ckij must comprise independent Bernoulli random variables which take values of ’1’ or ’-1’ with the same probability of 0.5. This is equivalent to the condition of uniformity in the sequence of ckij. The condition can be evaluated by the NIST Frequency (Monobit) Test, as commented below. 5) Uniqueness The identifiers generated by genuine and fake memories should be sufficiently different to ensure the uniqueness of the identification. Uniqueness is achieved if the Hamming distance between IDs provided by genuine and fake devices (the interdie Hamming distance) is always greater than the Hamming distance between IDs provided by the genuine device (the intradie Hamming distance). Such condition also achieves the uniqueness of the secret key generated because it is possible to select the number of errors to be corrected by the ECC so that only the genuine device could be able to recover the response of the initialization step in the Code Offset-based Helper Data Algorithm. Fig. 1. Flowchart of memory cell classification. This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 5 If m identifiers generated by k devices are considered, an estimate of the uniqueness of the identification is given by the difference between the minimum interdie and the maximum intradie fractional Hamming distances, which is known as security distance (SD). This is defined as follows: n RRHD n RRHD SD jxix mij mi kx jyix mji kxy kx ),( max ),( min ,...,1 1,...,1 ,...,1 ,...,1, ,..., 1,...,1 += −= = = = −= −= (11) As reliability increases, the maximum intradie Hamming distance decreases (tending to 0%) and, hence, the security distance increases. Similarly, as ID independence increases, the minimum interdie Hamming distance increases (tending to 50%), as does the security distance. In the ideal situation of 100% reliability and independence of identifiers, security distance will be 50%. A high security distance means that the probability of a genuine SRAM being rejected or a fake SRAM being accepted is quite small. In general, the security distance decreases as the length of the ID decreases (a detailed explanation of this can be found in [18]). 6) Unpredictability Several tests can be applied to evaluate the unpredictability or randomness of a sequence. In this paper, tests taken from the NIST test suite for randomness [29] were applied, as described below. To be unpredictable, the n-bit sequence generated by n memory cells should be uniform (should have the same number of ’1’s and ’0’s). In other words, the fractional Hamming weight should be 0.5. This condition is tested by the NIST Frequency (Monobit) Test. Subsequences of an unpredictable sequence should also be unpredictable. The cumulative sums of the bits in the subsequences that can be formed from the complete sequence (considering ’1’ and ’- 1’ values) should therefore also be zero, as in the complete sequence. This condition is tested by the NIST Cumulative Sums Test, in forward mode (if the subsequences are formed from the beginning to the end of the complete sequence) or in backward mode (if the subsequences are formed from the end to the beginning). The number of runs of ’1’s and ’0’s of various lengths should also be as expected for a random sequence, and the oscillation between zeros and ones should not be too fast or too slow. This is evaluated by the NIST Runs Test. For these tests, it is recommended that each sequence to be tested should have a minimum of 100 bits. Each NIST test is statistical: a set of sequences, m, is tested and their p-values are obtained. The value of m should be in the order of the inverse of the statistical significance level. For example, for a significance level of α=0.01 (with a confidence, ρ, of 99% when determining unpredictability), about 1% of the sequences are expected to fail (p-value<0.01), 99% of the sequences are expected to pass the test (pvalue≥0.01) and at least 100 sequences should be analyzed. NIST prescribes that the proportion of sequences that pass a statistical test should fall inside the confidence interval defined as: m )1( 3ρ−ρ ±ρ (12) NIST also examines the distribution of p-values to ensure uniformity and calculates a PvalueT (a p-value of the pvalues), which should - if the sequences are unpredictable - verify that: 0001.0≥ T Pvalue (13) B. Evaluation strategy Standard low-power dual-port 8-transistor TSMC 90-nm SRAM IP modules (TSDGA4096X60M8) were characterized experimentally. They were provided as IP modules by Europractice, with an operating voltage of 1.2V±10% and an operating temperature of -40ºC to 125ºC. The SRAM IP module was included in two different digital ASICs (hereafter referred to as ASICa and ASICb). The ASICs implement different signal processing algorithms, so their layouts are different (ASICa and ASICb are described in [30] and [31], respectively). In both cases, the SRAM module was used to store a set of parameters that the ASICs need for digital signal processing. The two ASICs therefore represented a real scenario in which to study the capability of an SRAM module to generate identifiers and true random numbers when powered-up, the SRAM itself forming part of a digital design. The main variables considered in the SRAM operating conditions were the power supply voltage, Vdd, and temperature, T. Another critical factor is aging. The purpose of the evaluation strategy was to find a methodology capable of simultaneously increasing the reliability and entropy offered by a standard SRAM with respect to different operating conditions and aging, and which could be carried out at low cost and with the SRAM embedded in its operation context (because the behavior of the SRAM changes if the operation context changes - for example, if the power supply ramp-up time changes, as mentioned in the Introduction). The first step taken to achieve that objective was to evaluate the percentage of stable and unstable cells (Equation (6) and Equation (7), respectively) obtained after considering several operating conditions, as illustrated in Figure 1. The number of measurements (start-ups) taken at each operating condition was 20. Ten integrated ASICa circuits were characterized. For each circuit, 2,280 bits (start-up values) provided by 40 x 57- bit words were registered. Those were enough bits to generate identifiers, secret keys and random sequences. Twenty integrated ASICb circuits were characterized. The SRAM module in ASICb (as happens with other ASICs) cannot be written/read from the input/output pins as easily as in ASICa. Hence, 168 bits (start-up values) provided by 14 x 12-bit words were registered for each circuit. Those were enough bits to generate identifiers. Firstly, classification was performed taking into account only nominal operating conditions (Vdd=1.2V and T=25ºC). To evaluate the influence of power supply voltage in the This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 6 classification, the temperature was fixed to the nominal value and three operating conditions were considered, (1.08V, 25ºC), (1.2V, 25ºC), and (1.32V, 25ºC), covering the typical variations of ±10% of the nominal Vdd. To evaluate the influence of temperature in the classification, the power supply voltage was fixed to the nominal value and three operating conditions were considered, (1.2V, 5ºC), (1.2V, 25ºC), and (1.2V, 75ºC), covering variations above and below the nominal T. The ASICs were included on a printed circuit board (PCB) powered at 5V, but since the ASICa and ASICb cores (including the SRAM) needed 1.2V, a voltage regulator was used to generate the required voltage for the ASIC core. The regulator’s output voltage was set by the ratio of two external resistors, one of which was a digital potentiometer. A digital switch made it possible to power down the ASIC (including the SRAM). A precision temperature forcing system, a Thermonics T-2650BV, was employed to control the operating temperature of the ASIC samples. The second step was to evaluate the reliability (measured as maxIntraHD in Equation (1)) and entropy (measured as Hmin in Equation (5)) obtained without classifying the cells, that is, using stable and unstable cells to generate the responses. Firstly, responses generated at nominal operating conditions were analyzed. Secondly, responses generated at several operating conditions were also considered. The third step was to evaluate how the classification and, subsequently, the adequate use of cells simultaneously improves the reliability and entropy under operating conditions not considered in the classification process. A detailed analysis was done with ASICa circuits to evaluate the improvements under nine operating conditions: (1) (1.08V, 25ºC), (2) (1.2V, 25ºC), (3) (1.32V, 25ºC), (4) (1.2V, 5ºC), (5) (1.2V, 75ºC), (6) (1.08V, 5ºC), (7) (1.32V, 5ºC), (8) (1.08V, 75ºC), and (9) (1.32V, 75ºC). The improvements in reliability were confirmed with more ASICb circuits under less operating conditions (the five conditions from (1) to (5), described above). The classification technique selected was that which offered the best trade-off between performance and cost. The fourth step was to assess the advantages of using the selected technique to generate identifiers, secret keys, and true random numbers, testing particularly the independence and unpredictability of the generated sequences under nominal operating conditions. Finally, the fifth step was to evaluate how the selected classification technique responds to aging. Three integrated ASICa circuits were characterized. For each circuit, 91,200 bits (start-up values) provided by 4 x 400 x 57-bit words were registered. One of the ASICa circuits was used to test how the stable and unstable cells change in time under nominal operating conditions and normal SRAM activity. The other circuits were used to test the evolution under operating conditions that accelerate aging and/or NBTI (Negative Bias Temperature Instability), one of them working continuously at increased power supply voltage (1.32V, 25ºC) and the other at increased temperature (1.2V, 75ºC). A climatic chamber ACSEOS 200TC was used to carry out the last experiments. The inputs to configure the ASICs were provided by an Agilent 16720A Pattern Generator while the outputs (including the start-up values of the SRAM) were recorded by an Agilent 16823 Logic Analyzer. To avoid problems of data remanence, the tested ASICs were kept shut down for a fair amount of time (30 seconds) between start-ups, as suggested in [32]. A Matlab program running on a computer was used to automatize the characterization measurements with the Instrument Control Toolbox. The Matlab software reported in [33] was adapted for this purpose. III. WAYS TO IMPROVE RELIABILITY AND ENTROPY A. Influence of stable and unstable cells The percentages of stable and unstable cells, as computed in Equation (6) and Equation (7), respectively, were measured in 10 samples from ASICa (2,280 bits per sample) and 20 samples from ASICb (168 bits per sample), considering 20 measurements per operation condition analyzed, following the flowchart in Figure 1. The mean values of the percentage of stable cells, together with their standard errors, are shown in the first and third rows of Table I. The values in the first column considered only nominal operating conditions (1.2V, 25ºC). The values in the second column considered three operating conditions with three different Vdd values at nominal temperature, (1.08V, 25ºC), (1.2V, 25ºC), and (1.32V, 25ºC). The values in the third column considered three operating conditions with three different T values at nominal Vdd (1.2V, 5ºC), (1.2V, 25ºC), and (1.2V, 75ºC). Finally, the values in the fourth column considered all the operating conditions analyzed (nine for ASICa and five for ASICb). From the results, it can be concluded that the cells that are always stable (A cells) decrease if Vdd variations are considered and decrease even more if T variations are considered. The maximum intra HD, as described in Equation (1), was calculated for the ASICa and ASICb samples: (a) under TABLE I PERCENTAGES OF STABLE AND UNSTABLE CELLS, MAXIMUM INTRA HD AND MINIMUM ENTROPY Nominal conditions With Vdd variations With T variations All conditions Percentage of stable cells (ASICa) 91.86%±0.17% 89.70%±0.19% 82.58%±0.26% 78.56%±0.43% Maximum intra HD (ASICa) 6.42%±0.12% 7.25%±0.13% 17.67%±0.23% 18.83%±0.25% Percentage of stable cells (ASICb) 86.58%±0.62% 80.98%±0.84% 73.72%±0.65% 70.30%±0.77% Maximum intra HD (ASICb) 8.36%±0.59% 12.97%±0.78% 20.43%±0.66% 22.70%±0.76% Percentage of unstable cells (ASICa) 8.14%±0.17% 6.11%±0.10% 0.75%±0.04% 0.34%±0.04% Minimum entropy (ASICa) 3.04%±0.09% 3.01%±0.08% 1.98%±0.08% 1.93%±0.07% This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 7 nominal conditions, (b) with three different Vdd values at nominal temperature, (c) with three different T values at nominal Vdd, and (d) considering all the conditions analyzed. The mean values for ASICa (obtained after evaluating 10 samples from ASICa, with 13 sets of 128 bits per sample) are shown together with their standard errors in the second row of Table I. The pairwise comparisons calculated per sample and per set of 128 memory cells were: (a) 3,160 pairs among 80 responses under nominal conditions (the number of responses is m in Equation (1)), (b) and (c) 28,680 pairs among 240 responses, and (d) 258,840 pairs among 720 responses under all conditions. Similarly, the maximum intra HD was calculated for 20 samples from ASICb and 1 set of 128 bits per sample. The mean values with their standard errors are shown in the fourth row of Table I. The pairwise comparisons calculated per sample and set of 128 memory cells were: (a) 190 pairs among 20 responses at nominal conditions (m=20 in Equation (1)), (b) and (c) 1,770 pairs among 60 responses, and (d) 4,950 pairs among 100 responses at all conditions. In both ASICs, it can be seen how the maximum intra HD increases as the percentage of stable cells decreases. The mean values of the percentage of unstable cells, with their standard errors, are shown in the fifth row of Table I. As occurred with the stable cells, the cells that are always unstable (B cells) were found to decrease with Vdd variations and decrease even more with T variations. Minimum entropy, as described in Equation (5), was calculated for the 2,280 memory cells analyzed in the 10 samples from ASICa. Figure 2 illustrates how the minimum entropy of one of the samples under nominal operating conditions changes versus the number of measurements considered to evaluate the pimax. With 100 start-up measurements, Hmin converges to its asymptotic value. 100 start-ups were therefore considered to evaluate the maximum probability observed for each memory cell (pimax). The Hmin was calculated: (a) under nominal conditions, (b) with three different Vdd values at nominal temperature, (c) with three different T values at nominal Vdd, and (d) considering all nine conditions. The minimum value was recorded when several operating conditions were considered. The mean values with their standard errors are shown in the sixth row of Table I. It can be seen how the Hmin is low because the percentage of unstable cells is low and that it decreases as the percentage of unstable cells decreases. The next analysis was aimed at evaluating how the classification of cells into stable and unstable cells can simultaneously improve both the reliability and randomness of the SRAM. The analysis was carried out with ASICa samples and confirmed with ASICb samples. To classify the cells, several operating conditions can be analyzed: the more conditions are analyzed, the more accurate the classification. However, it is impractical to take into account too many conditions and, in the case of unstable cells, as shown in the fifth column of Table I, the number of unstable cells may be too small. Two forms of classifying the cells as stable and unstable were therefore analyzed: (a) taking into account the Vdd values and considering the three operating conditions (1.08V, 25ºC), (1.2V, 25ºC), and (1.32V, 25ºC), and (b) taking into account the T values and considering the three operating conditions (1.2V, 5ºC), (1.2V, 25ºC), and (1.2V, 75ºC). In both cases, classification was carried out by considering 20 measurements per operation condition. B. Reliability improvement with classification To evaluate the reliability improvement, the start-up values provided by the SRAM cells were organized as 13 sets of 128 bits per each ASICa sample and evaluated per each operation condition (a maximum of 13 sets per sample can be generated by the A cells found with T variations in all the samples). The maximum intra HD between 80 responses generated by the same 128 cells at different times was calculated for three situations: (a) with no classification, so that the 128 cells were any of the memory cells in the SRAM; (b) with classification taking into account Vdd and (c) with classification taking into account T values, so that the responses were generated by 128 memory cells classified as A cells. Table II shows the mean values (obtained after averaging over the 10 samples from ASICa and the 13 sets per sample) and the standard errors of the maximum intra HD under each operation condition. It can be seen how using stable cells always improves reliability. Classification taking into account Vdd values provides the best reliabilities under operating Fig. 2. Convergence of the minimum entropy to its asymptotic value. TABLE II MEAN AND STANDARD ERRORS FOR MAXINTRAHD IN ASICA SAMPLES UNDER EACH OPERATION CONDITION (A CELLS ARE USED WITH CLASSIFICATION) Vdd (V), T(ºC) Without classification With classification based on Vdd With classification based on T (1.08, 25) 6.41%±0.13% 0.99%±0.06% 1.17%±0.07% (1.2, 25) 6.42%±0.12% 0.87%±0.06% 1.12%±0.07% (1.32, 25) 6.56%±0.12% 1.02%±0.06% 1.13%±0.07% (1.08, 5) 7.45%±0.13% 4.45%±0.14% 1.94%±0.08% (1.2, 5) 7.85%±0.20% 4.47%±0.13% 1.97%±0.15% (1.32, 5) 7.62%±0.13% 4.78%±0.14% 2.19%±0.08% (1.08, 75) 4.81%±0.14% 2.03%±0.11% 1.02%±0.09% (1.2, 75) 4.65%±0.12% 1.94%±0.10% 0.76%±0.06% (1.32, 75) 4.75%±0.12% 2.10%±0.10% 1.03%±0.08% This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 8 conditions with nominal temperature and also improves reliability under the other operating conditions. Classification taking into account T values provides the best reliabilities under operating conditions with non-nominal temperature and also improves reliability under the other operating conditions. To test the statistical significance of these results, a twosample Kolmogorov-Smirnov test was performed to compare (a) the distributions of the maximum intra HD obtained without classification and with Vdd classification, and (b) the distributions of the maximum intra HD obtained without classification and with T classification. This nonparametric test was applied because the underlying distribution of the maximum intra HD is unknown. The null hypothesis was that the maximum intra HDs calculated with and without classification come from the same continuous distribution (i.e., classification is not relevant). The alternative hypothesis was that they come from different distributions (i.e., the influence of classification is relevant). If the p-value resulting from the test is low, it means that the two distributions are different, but if the p-value is close to 1, it means that the two distributions are similar. The p-value is very accurate for large sample sizes, and reasonably accurate for sample sizes n1 and n2, such that (⋅)/(+)≥4. In these tests, n1 = n2= 130, so the p-values obtained were reasonably accurate. In both cases, the test rejected the null hypothesis at the 5% significance level. The p-value obtained in test (a) was 5.7e-51 (and the maximum difference between the empirical cumulative distribution functions was 0.93). The p-value obtained in test (b) was 4.1e-56 (and the maximum difference between the empirical cumulative distribution functions was 0.98). The conclusion is that classification of the cells modifies the distribution of the maximum intra HD. The advantage is that the maximum intra HD becomes smaller, as is desirable for ID and secret key generation. The real scenario is that IDs or secret keys can be registered under one set of operating conditions and should then be verified under different operating conditions (not under the same conditions, as calculated in the results of Table II). If the maximum intra HD between responses provided by the same memory cells under all the possible operating conditions is calculated, the mean values and standard errors obtained for all the samples from ASICa and the 13 sets considered per sample are shown in the first row of Table III. In the second row of Table III similar behavior can be observed in the 20 samples from ASICb with one set per sample (with 122 bits because a maximum of 122 A cells was found with T variations in all the samples). C. Entropy improvement with classification Minimum entropy was calculated using Equation (5) for three situations: (a) with no classification of the cells, therefore considering the 2,280 bits analyzed, (b) considering only the cells classified as unstable under the three operating conditions with nominal T and varying Vdd, and (c) considering only the cells classified as unstable under the three operating conditions with nominal Vdd and varying T. Table IV shows the mean values (the average of 10 samples from ASICa) and the standard errors of the minimum entropy under each operation condition. It can be seen how classification taking into account Vdd variations provides the highest minimum entropy under operating conditions with nominal T, and also considerably improves entropy under other operating conditions. Classification taking into account T variations provides the highest minimum entropy under operating conditions with non-nominal T. The problem is that the number of unstable cells found with T variations was very small (0.75% on average, as shown in Table I), which is impractical for many applications (it represents an average of 17 cells in 2,280). On the other hand, the number of cells classified as unstable with Vdd variations was 6.11% on average (an average of 139 cells in 2,280). A two-sample Kolmogorov-Smirnov test was performed to test the statistical significance of the minimum entropy results. The distribution of the minimum entropy obtained with 10 samples from ASICa under the nine operating conditions (90 values) without classification was compared with (a) the distribution with Vdd-based classification and (b) the distribution with T-based classification. With such sample sizes (90 data), the p-values obtained were reasonably accurate. Again, this nonparametric test was applied because the underlying distribution of the minimum entropy is unknown. The null hypothesis was that the minimum entropies calculated with and without classification come from the same continuous distribution (i.e., classification is not relevant). The alternative hypothesis was that they come from different distributions (i.e., the influence of classification is relevant). In both cases, the test rejected the null hypothesis at the 5% significance level. The p-value obtained for both tests was 4.1e-41 (and the maximum difference between the empirical TABLE III MEAN AND STANDARD ERRORS FOR MAXINTRAHD IN ASICA AND ASICB SAMPLES UNDER ANY OPERATION CONDITION (A CELLS ARE USED WITH CLASSIFICATION) Without classification With classification based on Vdd With classification based on T ASICa 18.83%±0.25% 6.80%±0.25% 5.76%±0.26% ASICb 23.30%±0.80% 10.89%±0.57% 4.87%±0.56% TABLE IV MEAN AND STANDARD ERRORS FOR HMIN IN ASICA SAMPLES UNDER EACH OPERATION CONDITION (B CELLS ARE USED WITH CLASSIFICATION) Vdd (V), T(ºC) Without classification With classification based on Vdd With classification based on T (1.08, 25) 3.16%±0.06% 42.21%±0.77% 39.06%±1.48% (1.2, 25) 3.04%±0.09% 42.52%±1.06% 40.67%±2.06% (1.32, 25) 3.08%±0.07% 42.33%±0.91% 41.60%±1.41% (1.08, 5) 3.65%±0.07% 10.39%±0.82% 29.32%±3.33% (1.2, 5) 3.64%±0.08% 10.54%±0.58% 31.24%±3.14% (1.32, 5) 3.73%±0.07% 10.58%±0.79% 30.07%±3.56% (1.08, 75) 2.13%±0.11% 14.56%±0.96% 29.98%±3.16% (1.2, 75) 1.98%±0.08% 13.80%±0.60% 30.57%±2.33% (1.32, 75) 2.04%±0.06% 14.02%±0.56% 28.89%±3.06% This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 9 cumulative distribution functions was 1). The conclusion is that classification of the cells modifies the distribution of the minimum entropy. The advantage is that the minimum entropy becomes bigger, as is desirable for random number generation. IV. CLASSIFICATION BASED ON VDD VARIATIONS Classification taking into account Vdd variations provides a good trade-off between improvements in reliability and entropy and simplicity of realization. Furthermore, the number of unstable cells detected is not as small as when taking into account T variations. This was therefore the classification method selected to be implemented and studied in greater detail. The way the method was applied and the advantages obtained in the ASICa and ASICb samples are summarized below. No spatial correlation was detected in the stable and unstable cells found by the classification. Figure 3 shows the 40 x 57 memory cells analyzed in one of the ASICa samples. The stable cells (A cells) can be seen in white in Figure 3a and the unstable cells (B cells) can be seen in white in Figure 3b In all the samples, there are no rows or columns in the SRAM with the same A cells detected. In the case of B cells, since their number is much smaller, there are no rows in all the SRAMs with the same B cells, but some of the columns are equal (particularly, those with one or no B cells). These columns are different in the different ASICa samples. A. Advantages for the generation of identifiers 1) Independence of the IDs The start-up values provided by the A cells of the same SRAM should be independent to ensure that an ID cannot be ascertained through knowledge of other IDs provided by the same SRAM. At least 1,800 A cells were detected in four samples from ASICa with the proposed classification. They were organized as 18 x 100-bit IDs. To evaluate the independence of the IDs, the fractional HDs between all the pairwise combinations of the 18 IDs (generated under nominal conditions) were calculated, giving a total of 153 HDs. Rather than only one set, 100 sets of 18 x 100-bit IDs were analyzed in order to consider all the possible displacements between the IDs generated: i.e., the first set considers that the first A cell of the first ID is the first A cell found in the SRAM; the second set considers that the first A cell of the first ID is the second A cell found in the SRAM (thus, the 18 IDs generated are displaced by 1 bit in relation to the first set); and so on, till the 100th set, which considers that the first A cell of the first ID is the 99th A cell found in the SRAM. A total of 15,300 HDs were therefore calculated per ASIC sample. The objective was to discover any possible correlation in the IDs generated. Figure 4 shows the distribution of 61,200 fractional HDs obtained from four ASICa samples, and how the histogram can be approximated by a normal distribution, in this case with a mean value of μ n HD =0.502 and a standard deviation of σ n HD =0.052. Applying Equation (9), the number of independent bits in the sequences is 92.59%, which means a very high level of independence among the IDs provided by the same SRAM, as summarized in Section II.A.4. To further analyze correlation, the scalar product between the 153 pairs of IDs per sample was calculated as in Equation (10). The uniformity of the 153 sequences of 100 ckij correlation bits was analyzed using the NIST Frequency Test. The proportions of sequences with a p-value bigger than 0.01 (a confidence of 99%) verify the condition in Equation (12) and the distributions of p-values verify Equation (13). It can therefore be concluded, with a confidence of 99%, that the IDs provided by the same SRAM are not correlated. IDs generated by different SRAMs should also be fairly independent to ensure their uniqueness. That is to say, an ID should be generated by only one single ASIC sample. To test this feature, the interdie fractional Hamming distances of 128- bit IDs obtained from the 20 ASICb samples after applying classification were calculated (95,000 HDs were calculated considering all operating conditions). Again, the histogram can be approximated by a normal distribution, in this case with a mean value of μ n HD =0.483 (which is very close to 0.5, as is desirable for independent IDs) and a standard deviation of σ n HD =0.0447. Applying Equation (9), the number of (a) (b) Fig. 3. (a) Stable cells depicted in white and (b) unstable cells depicted in white after classification based on 20 measurements per Vdd value. Fig. 4. Distribution of fractional HDs between IDs from the same SRAM. This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].
T-IFS-05102-2015.R1 16 [29] A. Rukhin, J. Soto, J. Nechvatal, M. Smid, E. Barker, S. Leigh, M. Levenson, M. Vangel, D. Banks, A. Heckert, J. Dray, S. Vo, “A statistical test suite for random and pseudorandom number generators for cryptographic applications,” NIST Special Publication, vol. 800-22, Revision 1a, April 2010. [30] P. Brox, M. C. Martínez-Rodríguez, E. Tena, I. Baturone, and A. J. Acosta, “ASIC solution for mimo piecewise affine functions,” Int. Journal of Circuit Theory and Applications, to be published, DOI: 10.1002/cta.2058. [31] P. Brox, J. Castro, M. C. Martínez-Rodríguez, E. Tena, C. Jiménez, I. Baturone, and A. J. Acosta, “A programmable and configurable ASIC to generate piecewise-affine functions defined over general partitions,” IEEE Trans. on Circuits and Systems I: Regular Papers, vol. 60, no. 12, pp. 3182–3194, 2013. [32] N. Saxena and J. Voris, “Data remanence effects on memory-based entropy collection for RFID systems,” Int. Journal of Information Security, vol. 10, no. 4, pp. 213–222, 2011. [33] E. Tena, J. Castro, and A. Acosta, “Automatic and systematic control of experimental data measurements on ASICs,” presented at 19th TC4 Symposium on Measurements of Electrical Quantities (IMEKO), Barcelona, Spain, July 18-19, 2013. [34] B. Sunar, W. Martin, and D. Stinson, “A provably secure true random number generator with built-in tolerance to active attacks,” IEEE Trans. on Computers, vol. 56, no. 1, pp. 109–119, 2007. [35] Atmel: Innovative techniques for extremely low power consumption with 8-bit microcontrollers. (2006). [Online]. Available: http://www.atmel.com/images/doc7903.pdf [36] Failure mechanisms and models for semiconductor devices - jep122g. (2011). [Online]. Available: http://www.jedec.org/standardsdocuments/docs/jep-122e [37] M. Denais, V. Huard, C. Parthasarathy, G. Ribes, F. Perrier, N. Revil, and A. Bravaix, “Interface trap generation and hole trapping under NBTI and PBTI in advanced CMOS technology with a 2-nm gate oxide,” IEEE Trans. on Device and Materials Reliability, vol. 4, no. 4, pp. 715– 722, 2004. [38] S. Mahapatra and M. Alam, “A predictive reliability model for PMOS bias temperature degradation,” in Proc. IEDM, San Francisco, CA, 2002, pp. 505–508. [39] R. Maes and V. van der Leest, “Countering the effects of silicon aging on SRAM PUFs,” in Proc. HOST, Arlington, VA, 2014, pp. 148–153. Iluminada Baturone received the 5-year (Hons.) degree and the Ph.D. (Hons.) degree in Physics from the University of Seville, Seville, Spain, in 1991 and 1996, respectively. Since 1990, she has been with the Microelectronics Institute of Seville (IMSE-CNM) CSIC/University of Seville. She is also with the Dept. of Electronics and Electromagnetism of the University of Seville, where she is an Associate Professor since 2001. She has co-authored the books “Microelectronic Design of Fuzzy Logic-Based Systems” (CRC Press, 2000) and “Fuzzy Logic-Based Algorithms for Video De-Interlacing” (Springer, 2010) and more than 150 scientific papers. She has participated in more than 30 Spanish and European research and industrial projects, leading 5 of them. She holds 3 patents and is one of the developers of the Xfuzzy environment. Her current research interests include hardware security, microelectronic design of crypto-biometric systems, and neuro-fuzzy systems. Miguel A. Prada-Delgado received the 5- year degree in Telecommunication Engineering (specialized in Electronics) from the University of Seville, Seville, Spain in 2013. In 2014 he obtained the Master degree in Microelectronics with honors due to his job named "Unclonable identifiers and true random numbers generation from static memory cells". He is currently pursuing the Ph.D. degree in hardware security at the Microelectronics Institute of Seville (IMSE-CNM) CSIC/University of Seville, thanks to a grant from V Plan Propio de Investigación through the University of Seville, Seville, Spain. Since 2013, he has been with the Microelectronics Institute of Seville (IMSE-CNM) CSIC/University of Seville. Since 2014, he has also been with the Dept. of Electronics and Electromagnetism of the University of Seville. Susana Eiroa received the 5-year degree in Telecommunication Engineering from the University of Vigo, Spain in 2007. She obtained the Master degree in Microelectronics in 2010 and the Ph.D. in Microelectronics with International Mention in 2014, both from the University of Seville, Seville, Spain. She developed her Master thesis at IMEC, Leuven, Belgium, in 2007. From 2009 to 2015, she was with the Microelectronics Institute of Seville (IMSECNM) CSIC/University of Seville as a Ph.D. student and postdoctoral researcher, thanks to a grant from the Junta de Andalucía. Currently, she works at ALTER Technology TÜV NORD, Seville, Spain. She has participated in several R&D projects, has co-authored several international publications and holds a patent. Her main research area is hardware security, mainly focused on Physical Unclonable Functions (PUFS) and hardware attacks. This is the author's version of an article that has been published in this journal. Changes were made to this version by the publisher prior to publication. The final version of record is available at http://dx.doi.org/10.1109/TIFS.2015.2471279 Copyright (c) 2015 IEEE. Personal use is permitted. For any other purposes, permission must be obtained from the IEEE by emailing [email protected].