Secure key storage using physically unclonable functions
Abstract
Some implementations disclosed herein provide techniques and arrangements for provisioning keys to integrated circuits/processor/apparatus. In one embodiment, the apparatus includes a physically unclonable functions (PUF) circuit to generate a hardware key based on at least one manufacturing variation of the apparatus and a nonvolatile memory coupled to the PUF circuit, the nonvolatile memory to store an encrypted key, the encrypted key comprising a first key encrypted using the hardware key. The apparatus further includes a hardware cipher component coupled to the nonvolatile memory and the PUF circuit, the hardware cipher component to decrypt the encrypted key stored in the nonvolatile memory with at least the hardware key to generate a decrypted copy of the first key and fixed logic circuitry coupled to the PUF circuit and the hardware cipher component, the fixed logic circuitry to verify that the decrypted copy of the first key is valid.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus comprising:
a physically unclonable functions (PUF) circuit to generate a hardware key based on at least one manufacturing variation of the apparatus; nonvolatile memory coupled to the PUF circuit, the nonvolatile memory to store an encrypted key, the encrypted key comprising a first key encrypted using the hardware key; a hardware cipher component coupled to the nonvolatile memory and the PUF circuit, the hardware cipher component to decrypt the encrypted key stored in the nonvolatile memory with at least the hardware key to generate a decrypted copy of the first key; and fixed logic circuitry coupled to the PUF circuit and the hardware cipher component, the fixed logic circuitry to verify that the decrypted copy of the first key is valid.
2 . The apparatus of claim 1 , wherein the at least one manufacturing variation results from integrated circuit fabrication of the apparatus.
3 . The apparatus of claim 1 , wherein the nonvolatile memory includes at least one anti-fuse.
4 . The apparatus of claim 1 , wherein the hardware cipher component comprises an encryption and decryption component.
5 . The apparatus of claim 1 , further comprising:
at least one internal interconnect, wherein the PUF circuit, the nonvolatile memory, the hardware cipher component, and the fixed logic circuitry are coupled together the by the at least one internal interconnect.
6 . The apparatus of claim 1 , wherein the apparatus is coupled to a processing device by at least one external interconnect.
7 . An system comprising:
an input/output (I/O) subsystem; a memory subsystem; and a processing device, communicably coupled to the I/O subsystem and the memory subsystem, the processing device comprising:
a physically unclonable functions (PUF) circuit to generate a hardware key based on at least one manufacturing variation of the processing device;
nonvolatile memory coupled to the PUF circuit, the nonvolatile memory to store an encrypted key, the encrypted key comprising a first key encrypted using the hardware key;
a hardware cipher component coupled to the nonvolatile memory and the PUF circuit, the hardware cipher component to decrypt the encrypted key stored in the nonvolatile memory with at least the hardware key to generate a decrypted copy of the first key; and
fixed logic circuitry coupled to the PUF circuit and the hardware cipher component, the fixed logic circuitry to verify that the decrypted copy of the first key is valid.
8 . The system of claim 7 , wherein the at least one manufacturing variation results from integrated circuit fabrication of the processing device.
9 . The system of claim 7 , wherein the nonvolatile memory includes at least one anti-fuse.
10 . The system of claim 7 , wherein the hardware cipher component comprises an encryption and decryption component.
11 . The system of claim 7 , the processing device further comprising:
at least one internal interconnect, wherein the PUF circuit, the nonvolatile memory, the hardware cipher component, and the fixed logic circuitry are coupled together the by the at least one internal interconnect.
12 . The system of claim 7 , wherein the processing device is coupled to a second processing device by at least one external interconnect.Join the waitlist — get patent alerts
Track US2017288869A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.