{"id":1845,"date":"2021-12-20T14:42:15","date_gmt":"2021-12-20T14:42:15","guid":{"rendered":"https:\/\/blog.pufsecurity.com\/?p=1845"},"modified":"2023-11-27T02:45:54","modified_gmt":"2023-11-27T02:45:54","slug":"pufrt-solving-chip-securitys-weakest-link","status":"publish","type":"dlp_document","link":"https:\/\/www.pufsecurity.com\/zh-hans\/document\/pufrt-solving-chip-securitys-weakest-link\/","title":{"rendered":"PUFrt: Solving Chip Security\u2019s Weakest Link"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Introduction<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">In the 19th century, Netherland\u2019s cryptographer, Auguste Kerckhoff, created <strong>Kerckhoffs\u2019s principle<\/strong>, stating that \u201cA&nbsp;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptosystem\">cryptosystem<\/a>&nbsp;should be secure even if everything about the system, except the&nbsp;<a href=\"https:\/\/en.wikipedia.org\/wiki\/Cryptographic_key\">key<\/a>, is public knowledge.\u201d The most crucial element in chip security is the Root Key or Hardware Unique Key (HUK). The key is the starting point not only for protecting each chip but also the chain of trust that encompasses the entire system and associated services. Therefore, key generation, along with its storage and usage, must be well considered from the beginning of the design.<\/p>\n\n\n\n<p style=\"font-size:16px\">With the invention of Physical Unclonable Functions (PUF), we can now create a unique, inborn, unclonable key at the hardware level. The natural follow-up question to this is, \u201cbut how do we protect this key?\u201d &nbsp;It is like storing your key to secrets in a drawer, a surefire way to break the secure boundary and create vulnerabilities. Security is only as strong as the weakest link, and in most cases, the weakest link is insecure key storage in eFuse. Insecure storage immediately compromises the whole system\u2019s security, regardless of the sophistication of the key itself.<\/p>\n\n\n\n<p style=\"font-size:16px\">Furthermore, we know users can update the software after production, but hardware cannot be. Therefore, it is very crucial to deploy appropriate hardware security at the beginning. PUFrt, an integration of PUF and anti-fuse-based secure One-Time Programmable (OTP) memory, provides proper hardware security at the manufacturing stage. It delivers an unclonable key and secure OTP storage with complete anti-tamper designs.<\/p>\n\n\n\n<p class=\"has-text-align-left\" style=\"font-size:16px\">\u2193\u2193\u2193 5-minute video for a quick digest of this article (English voice-over + Chinese subtitles)\u2193\u2193\u2193<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"PUFrt - Solving Chip Security&#039;s Weakest Link with PUF-based Root of Trust\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/C3KuzLKvQRU?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>The Risks from eFuse Key Storage<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">The eFuse (electronic fuse) and anti-fuse OTP memory are the most common options for key storage in modern chip design. With eFuse, the key is programmed into OTP memory by blowing a portion of metal or poly, which leaves a visible trace. Meanwhile, the anti-fuse OTP is programmed based on the oxide burn-out mechanism. The burnout creates a conductive path without a visible trace on the surface. Figure 1 shows SEM\u2019s top view (Scanning Electron Microscope) comparison between eFuse and anti-fuse OTP after being programmed. The \u201c0\u201d and \u201c1\u201d data is stored in eFuse are easily recognizable as there is a clear opening in the cell programmed to \u201c1\u201d. &nbsp;As seen in the right image of Figure 1, the anti-fuse OTP cells look the same regardless of the data stored.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"472\" src=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-1024x472.png\" alt=\"\" class=\"wp-image-5658\" srcset=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-1024x472.png 1024w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-300x138.png 300w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-768x354.png 768w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-1600x737.png 1600w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-1536x707.png 1536w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig1-2048x943.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Figure 1. SEM top view of e-fuse and anti-fuse OTP<\/em><\/figcaption><\/figure><\/div>\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Insecure Storage Vulnerabilities<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">ARM core with Crypto Cell-312\u2122 (CC312) is one of the most common design combinations found today. While all designers value the security functions provided by CC312, key storage is often overlooked. Typically, ARM CC312 is used with eFuse\/anti-fuse without additional protections for key injection and storage, as shown in Figure 2. Therefore, the key remains outside the secure boundary creating a potential breach point for attackers. The problem is twofold: 1) data stored in eFuse is easily visible, as previously discussed, and 2) data can be obtained easily when access privilege control is not included. So anyone could request the secret stored in OTP. While CC312 is considered a well-designed door lock, using insecure key storage is like just leaving the key in the door lock for anyone to open the door.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"696\" src=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-1024x696.png\" alt=\"\" class=\"wp-image-5661\" srcset=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-1024x696.png 1024w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-300x204.png 300w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-768x522.png 768w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-1600x1088.png 1600w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2-1536x1044.png 1536w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig2.png 1902w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Figure 2. Non-Secure Root of Trust<\/em><\/figcaption><\/figure><\/div>\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Anti-tamper Enhanced Security<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">While the data visibility problem in eFuse can be easily solved by using anti-fuse OTP, It is still insufficient when it comes to security. Access privilege control must also be considered in the OTP controller design to enable identity differentiation and grants accessibility of secret data to authorized users only.<\/p>\n\n\n\n<p style=\"font-size:16px\">To further protect anti-fuse OTP in chip design, an anti-tamper design needs to be incorporated. By being in the form of physical layout, digital RTL, or a combination of both, the anti-tamper designs form a shell to counter various types of attack, such as to scramble the data when it is being written, to have glitch detection circuitry, and so on. We will discuss the topic of anti-tamper design in more detail in a future whitepaper.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Completing the Secure Boundary with PUFrt<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">Combining anti-fuse OTP, a controller with access privilege, and an anti-tampered shell establishes a secure Hardware Root of Trust (HRoT) countering all the discussed vulnerabilities. With a well-designed anti-tampered shell and privilege-based dual-APB interface, the secure RoT complements secure subsystems like CC312 to complete the secure boundary for the chip design. To accommodate CC312 and other ARM users, PUFsecurity developed a customized IP solution for ARM users called \u201cDual-APB PUFrt.\u201d Figure 3 provides a more detailed illustration and its features.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"372\" src=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-1024x372.png\" alt=\"\" class=\"wp-image-5664\" srcset=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-1024x372.png 1024w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-300x109.png 300w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-768x279.png 768w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-1600x581.png 1600w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-1536x558.png 1536w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig3-2048x744.png 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Figure 3. PUFrt block diagram and features<\/em><\/figcaption><\/figure><\/div>\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\">PUFrt builds upon eMemory\u2019s anti-fuse OTP (NeoFuse) and Quantum Tunneling PUF (NeoPUF) technologies to provide self-encrypted anti-Fuse OTPwith on-chip PUF. The inborn HUK utilizes the NeoPUF\u2019s guaranteed randomness to obtain the unique key per device, avoiding the need for a provisioning process. The True Random Number Generator (TRNG) has both digital and analog designs, combining static and dynamic entropy sources for its superb performance. PUFrt also obfuscates data and addresses and adds various security protection designs with physical\/digital comprehensive tamper-proof features in an anti-tamper shell to fully protect the secret key. PUFrt is also equipped with a controller of permission control and two APB interfaces. Figure 4 illustrates an example use case of the Hardware Root of Trust IP, PUFrt, with ARM core and CC312. APB1 connects PUFrt to the main bus and enables OTP testing with JTAG, and APB2 fully integrates PUFrt into CC312 to provide secure storage and entropy source for the crypto functions in CC312. APB1 would be disabled after testing, so the secure boundary remains intact.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"697\" src=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-1024x697.png\" alt=\"\" class=\"wp-image-5667\" srcset=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-1024x697.png 1024w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-300x204.png 300w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-768x523.png 768w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-1600x1089.png 1600w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4-1536x1045.png 1536w, https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2023\/11\/PUFrt_article_fig4.png 1897w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\"><em>Figure 4. Extend ARM CC312 secure boundary with PUFrt<\/em><\/figcaption><\/figure><\/div>\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\">Dual APB PUFrt makes integration with CC312 frictionless and provides complete anti-tampering protection for key storage. In addition, the TRNG provides high-quality entropy for CC312 to perform other security functions. By integrating CC312 and PUFrt, the ARM Cortex-M55 can realize the security Root of Trust, secure storage, and security systems before being brought to the market. And such a use case applies to multiple sectors from AIoT to HPC and beyond.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Conclusion<\/strong><\/p>\n\n\n\n<p style=\"font-size:16px\">When it comes to chip security, designers often turn to crypto subsystem solutions like ARM Crypto Cell 312. The remained obstacle, however, is how to generate and safely store the root key for the system. The dual APB PUFrt is the exact missing piece for the puzzle. With the inborn chip fingerprint from PUF that acts as a secret key to encrypt anything stored, the equipped anti-tamper shell makes it more resilient against potential attacks. With its well-planned architecture, PUFrt can be easily dropped in to replace eFuse while saving engineering effort as the controller is included. The combined solution not only completes secure boundary for IC but also maximizes the effectiveness of CC312 for the entire SoC\u2019s performance.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p style=\"font-size:16px\"><strong>Download this white paper \u2193\u2193\u2193<\/strong><\/p>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-99161387-cc7f-4e2b-99c8-db62c541908f\" href=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2022\/04\/PUFsecurity-WP-PUFrt-Solving-Chip-Securitys-Weakest-Link_EN.pdf\">English Version: Solving Chip Security&#8217;s Weakest Link<\/a><a href=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2022\/04\/PUFsecurity-WP-PUFrt-Solving-Chip-Securitys-Weakest-Link_EN.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-99161387-cc7f-4e2b-99c8-db62c541908f\">Download<\/a><\/div>\n\n\n\n<div class=\"wp-block-file\"><a id=\"wp-block-file--media-5a7d2476-f4c3-4d6f-8c11-c41a72d91f14\" href=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2022\/04\/\u71b5\u78bc\u79d1\u6280\u767d\u76ae\u66f8-\u5f9e\u6839\u6e90\u89e3\u6c7a\u6676\u7247\u5b89\u5168\u5f31\u9ede_\u7c21\u4e2d.pdf\">\u4e2d\u6587\u7248\u672c: \u5f9e\u6839\u6e90\u89e3\u6c7a\u6676\u7247\u5b89\u5168\u5f31\u9ede<\/a><a href=\"https:\/\/www.pufsecurity.com\/wp-content\/uploads\/2022\/04\/\u71b5\u78bc\u79d1\u6280\u767d\u76ae\u66f8-\u5f9e\u6839\u6e90\u89e3\u6c7a\u6676\u7247\u5b89\u5168\u5f31\u9ede_\u7c21\u4e2d.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-5a7d2476-f4c3-4d6f-8c11-c41a72d91f14\">Download<\/a><\/div>\n\n\n\n<p style=\"font-size:16px\">PUFrt has a free evaluation version available for users who would like to try the IP, <a href=\"https:\/\/www.pufsecurity.com\/ipgo\/\">click here!<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In the 19th century, Netherland\u2019s cryptographer, Auguste Kerckhoff, created Kerckhoffs\u2019s principle, stating that \u201cA\u00a0cryptosystem\u00a0should be secure even if everything about the system, except the\u00a0key, is public knowledge.\u201d<\/p>\n","protected":false},"author":11,"featured_media":1848,"template":"","doc_tags":[204,203,209,200],"class_list":["post-1845","dlp_document","type-dlp_document","status-publish","has-post-thumbnail","hentry","doc_categories-white-paper","doc_tags-hardware-security","doc_tags-puf","doc_tags-pufrt","doc_tags-root-of-trust"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/dlp_document\/1845"}],"collection":[{"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/dlp_document"}],"about":[{"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/types\/dlp_document"}],"author":[{"embeddable":true,"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/users\/11"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/media\/1848"}],"wp:attachment":[{"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/media?parent=1845"}],"wp:term":[{"taxonomy":"doc_tags","embeddable":true,"href":"https:\/\/www.pufsecurity.com\/zh-hans\/wp-json\/wp\/v2\/doc_tags?post=1845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}