本配置的 node、macro 與整合邊界是什麼?What node, macro and integration boundary is the licensed target?
管理與技術學習導覽EXECUTIVE LEARNING EXPERIENCE01 / 安全儲存01 / SECURE STORAGE
永久保存資料
根金鑰不永久留存
Permanent Data At Rest
Ephemeral Silicon Root Key
以 SRAM PUF 在上電時重建裝置唯一的根金鑰,再用 AES-256 保護 OTP 內容(已揭露密碼演算法;模式與引擎仍須依目標組態確認)。在經驗證的關機條件下,不保留刻意儲存或仍由電源維持的重建根金鑰。 Reconstruct a device-unique root key from SRAM PUF at power-up, then protect OTP content with AES-256 (cipher disclosed; mode/engine remain target-open until closed). Under verified shutdown, no intentionally stored or power-sustained reconstructed root remains.
上電重建;下電不保留 powered reconstructed rootReconstructed at power-up; no powered reconstructed root at rest
硬體密碼引擎保護 OTP 內容;公開揭露為 AES-256,mode 待 target 關閉Hardware crypto protects OTP as ciphertext; AES-256 is disclosed, mode remains target-specific
超過 15 年公開組合歷史;不自動等於本配置保證>15 years portfolio history; not automatic target-configuration assurance
純邏輯相容節點脈絡;各配置仍需關閉Logic-compatible node context; each configuration still requires closure
決策重點DECISION STRIP
關閉 target configuration 前先問這五件事 Five questions before closing a target configuration
把學習頁轉成決策頁:先問這五件事,再把 portfolio 數字當成起始脈絡。 Turn the learning page into a decision page: close these five questions before treating portfolio figures as applicable.
該配置公開的是 AES-256,還是已鎖定的 mode/engine?Is AES-256 disclosed only, or is the mode and engine locked for this configuration?
helper/activation data 的暴露模型與完整性假設為何?What is the helper or activation-data exposure model and integrity assumption?
remanence 與 zeroization 的驗證範圍到哪裡?What remanence and zeroization evidence covers the powered-down window?
FI、SCA 與 invasive readout 的證據 scope 是什麼?What FI, SCA and invasive-readout evidence exists, and for which scope?
安全不只取決於資料能保存多久
更取決於攻擊發生時,晶片裡還留下什麼
Security is not just how long data lasts,
but what remains in silicon under attack
OTP 解決永久性;Secure Storage 解決機密性。即使攻擊者成功觀察記憶體狀態,他取得的也應該是受保護資料,而不是可直接使用的 root secret。OTP solves permanence; Secure Storage solves confidentiality. Even if an attacker observes the memory state, the recoverable result should be protected data, not a usable root secret.
用 Power-off State 檢驗設計Evaluate the design through its power-off state靜止時不留存Absent at rest
在已驗證的 shutdown 條件下,不保留刻意儲存或已重建、仍由電源維持的 root;transistor mismatch 與 helper material 仍可能存在。Under verified shutdown, no intentionally stored or powered reconstructed root remains; transistor mismatch and helper material may still exist.
密文持續保留Ciphertext remains
OTP 永久保存的是 AES-256 密文與安全狀態。What OTP keeps permanently is AES-256 ciphertext and security state.
單一安全邊界One boundary
PUF、crypto、OTP 與 controller 共同構成安全子系統。PUF, crypto, OTP and the controller compose one security subsystem.
契約CONTRACT
從基礎元件到整合子系統FROM PRIMITIVE TO INTEGRATED SUBSYSTEM
好的矽智財,必須定義清楚
整合邊界也必須可以驗證
Quality silicon IP requires clear definitions
and verifiable integration boundaries
架構 · 介面 · 生命週期 · 交付項目Architecture · interface · lifecycle · deliverables
互動展示 · 電源狀態INTERACTIVE · POWER STATE
先關掉電源再看攻擊者能取得什麼 Power off first,then see what an attacker recovers
切換狀態,觀察 root key 的存在窗口。主張不是物理攻擊會消失,而是成功讀取後能揭露的內容被限制。Switch state and watch the root-key residency window. The claim is not that physical attack disappears; it is that a successful readout should stop at protected content.
核心斷電優勢:不留下刻意儲存或由電源維持的重建根金鑰Core power-off advantage: no intentionally stored or powered reconstructed root remains
在經驗證的關機條件下,OTP 保留密文、輔助資料及生命週期狀態;不留下刻意儲存或由電源維持的重建根金鑰。電晶體失配、資料殘留與清除仍須納入安全保證驗證。Under verified shutdown, OTP retains ciphertext, helper material and lifecycle state; no intentionally stored or powered reconstructed root remains. Transistor mismatch, remanence and zeroization remain assurance targets.
公開攻擊證據PUBLIC ATTACK SIGNAL
用公開攻擊界定 threat model,
再把它轉成產品要求
Anchor threat models in public attacks,
then translate them to product specs
RP2350 是特定實作的公開 case,不代表所有 OTP 都同樣可攻。它揭示兩條平行路徑:fault 可能破壞 control assumptions;FIB/PVC 則接近 physical bit-state recovery。產品要求因此是:即使 readout 成功,也不應直接得到 usable secret。RP2350 is a public case of one implementation, not a claim that every OTP is equally attackable. It shows two parallel paths: fault can break control assumptions; FIB/PVC approaches physical bit-state recovery. The product requirement is that a successful readout should still not yield a usable secret.
故障可能破壞原有假設Fault can collapse assumptions
背部雷射故障注入 (LFI)、電壓突波 (Voltage Glitch)、電磁脈衝 (EMFI) 或時鐘干擾可能引發指令跳躍 (instruction skip),破壞安全啟動、權限狀態或鎖定暫存器。Backside laser fault injection (LFI), voltage glitch, electromagnetic fault injection (EMFI), or clock disturbance can cause instruction skip, corrupting secure boot, privilege states, or lock registers.
FIB/PVC 可能揭露實體狀態FIB/PVC can expose physical state
公開案例已讀出相鄰 bit pair 的 OR;完整逐 bit recovery 仍未被示範。A public case recovered the OR of adjacent bit pairs; full bit-by-bit recovery has not been demonstrated.
加密、擾亂與治理Encrypt, scramble and govern
只有在所有 composed controls 成立時,readout 才應停在 scrambled ciphertext。Only when all composed controls hold should readout stop at scrambled ciphertext.
完成目標組態驗證Close the target configuration
以 target node、macro、integration 與 FI/SCA/invasive evidence 驗證結果。Close the result against the target node, macro, integration and FI/SCA/invasive evidence.
實體安全保證PHYSICAL SECURITY ASSURANCE
安全主張,必須經得起實體攻擊驗證
Security claims must survive
physical validation
從威脅方法、可觀察訊號與故障注入,到緩解措施、測試證據與第三方確證;讓每一項 Secure NVM 主張都能被追溯。Trace every Secure NVM claim from threat method and observable signal to mitigation, test evidence and independent assurance.
攻擊者會怎麼驗證?現有證據是什麼?還有什麼未知?How would an attacker test it? What evidence exists? What remains unknown?
分層信任 · 實務案例LAYERED TRUST · PRACTICAL CASE STUDY
不是三選一讓每一層各自解決正確的問題Not three alternativesGive each layer the right security job
這段是 trust-layer 職能拆分,不是產品 BOM 或現成 Okta 整合。OpenPGP 保護資料與簽章;Okta FastPass 管理使用者、裝置狀態與存取政策;PUF 強化兩者下方的 silicon root,降低對永久儲存 root secret 的依賴。This is a trust-layer job split, not a product BOM or a turnkey Okta integration. OpenPGP protects data and signatures. Okta FastPass governs users, device posture and access policy. A PUF strengthens the silicon root beneath them by reducing dependence on a persistently stored root secret.
OpenPGP
主要任務Primary job端對端加密、解密與數位簽章。End-to-end encryption, decryption and digital signatures.
斷電後仍存在Persists at rest私鑰 packet;可能受 passphrase 保護,但仍是可保存與複製的數位物件。A secret-key packet, optionally passphrase-protected, remains a storable and copyable digital object.
不負責裝置完整性、登入政策或已解鎖後的惡意操作。Does not provide device integrity, login policy or protection from misuse after unlock.Okta FastPass
主要任務Primary jobphishing-resistant、passwordless authentication 與裝置政策。Phishing-resistant, passwordless authentication and device policy.
裝置端狀態Device state註冊時建立 proof-of-possession key;可使用 TPM/Secure Enclave,也可能落在 software keystore。Enrollment creates a proof-of-possession key; it may use a TPM/Secure Enclave or a software keystore.
hardware protection 必須由政策要求,不能只因為使用 FastPass 就假設存在。Hardware protection must be required by policy; FastPass alone does not guarantee it.SRAM PUF
主要任務Primary job需要時重建 device-unique root,用來 derive 或 unwrap operational keys。Reconstruct a device-unique root on demand to derive or unwrap operational keys.
斷電後仍存在Persists at resthelper/activation data 與 wrapped keys 可以存在;root secret 本身不必永久儲存。Helper or activation data and wrapped keys may persist; the root secret itself need not.
不取代 user identity、MFA、authorization、revocation 或 recovery。Does not replace user identity, MFA, authorization, revocation or recovery.案例:Device-bound enterprise signingCase: Device-bound enterprise signing
只有同時通過企業身分政策與原始 silicon device 驗證,才允許本機 OpenPGP operation。A local OpenPGP operation is released only when enterprise identity policy and the enrolled silicon device are both satisfied.
生態系與整合 · 硬體信任根ECOSYSTEM & INTEGRATION · HARDWARE ROOT OF TRUST
晶片級硬體根信任上下游安全子系統協同實踐 Hardware Root of TrustUpstream & Downstream Subsystem Integration
安全儲存與 PUF 不能孤立存在,必須作為安全子系統的硬體錨點。以下解析業界三大主流安全子系統架構如何整合底層 NVM/PUF、硬體隔離核心與上層端到端認證協議: Secure storage and PUFs do not operate in isolation; they serve as hardware anchors within security subsystems. Below are three mainstream commercial architectures integrating silicon primitives, isolated enclaves, and cloud attestation:
Intrinsic ID Quiddikey
核心定位與機制Core Role & Mechanism SRAM PUF + 模糊提取器 (Fuzzy Extractor):利用晶粒原生標準 6T SRAM 上電時的隨機臨界電壓 mismatch 作為物理指紋。搭配公開儲存之 Activation Code(Helper Data),透過 BCH 糾錯重構 256-bit 根金鑰,用畢即銷毀。 SRAM PUF + Fuzzy Extractor: Leverages native 6T SRAM power-up mismatch as a physical fingerprint. Combines with a public Activation Code (Helper Data) to reconstruct a 256-bit root key via BCH error correction; cleared immediately after use.
上下游分工Supply Chain Split Helper Data 本身不含機密性,可直接存放於外部便宜的 SPI NOR Flash 或片上標準 OTP。徹底免除封測廠 (OSAT) 昂貴的安全無塵室金鑰注入流程,杜絕工廠端私鑰洩漏。 Helper Data carries no secrecy and can reside in external SPI NOR Flash or on-chip standard OTP, eliminating costly secure room key-injection during OSAT assembly.
適合超低成本 IoT MCU、車載雷達與資源受限微控制器。Ideal for ultra-low-cost IoT MCUs, automotive radar, and constrained microcontrollers.Synopsys tRoot™ HSM
核心定位與機制Core Role & Mechanism 隔離安全子系統 (Secure Enclave):整合獨立安全 RISC-V/ARC 處理器、密碼加速引擎 (Side-channel protected AES/ECC)、真隨機數產生器 (TRNG) 與 Bus Guard 硬體防火牆,防禦 Host CPU 側通道與軟體溢位攻擊。 Isolated Secure Enclave: Integrates an isolated secure CPU core, DPA-resistant crypto accelerators, TRNG, and Bus Guard memory firewall to insulate security operations from host CPU vulnerabilities.
上下游分工Supply Chain Split 底層可整合 Synopsys 1T Split-Channel AntiFuse OTP 保存晶片 UID、根公鑰雜湊 (ROTPK) 與安全組態;向上為 Host OS 提供 Secure Boot、防回滾 (Anti-Rollback) 與金鑰封裝服務 — PSA L3/SESIP 等級須對應具名產品與評估範圍,不得由 portfolio 敘述直接推出。 May integrate 1T Split-Channel AntiFuse OTP for UID and Root-of-Trust Public Key (ROTPK) storage; provides Secure Boot, Anti-Rollback, and key wrapping — PSA L3/SESIP tiers require named product evaluation scope; do not infer from portfolio marketing alone.
廣泛應用於車規 ADAS SoC、邊緣 AI 運算晶片與智慧座艙處理器。Widely deployed in automotive ADAS SoCs, edge AI chips, and smart cockpit processors.Rambus CryptoManager™
核心定位與機制Core Role & Mechanism 高速鏈路保護 (SPDM / IDE):在 PCIe Gen5/Gen6 與 CXL 2.0/3.0 介面硬體實現 DMTF SPDM 1.2/1.3 設備互聯認證,並以線速 AES-GCM 執行 IDE (Integrity & Data Encryption),防禦實體中間人竊聽。 High-Speed Link Security (SPDM / IDE): Hardware implementation of DMTF SPDM 1.2/1.3 device attestation and line-rate PCIe/CXL IDE encryption (AES-GCM), protecting against physical interposer tapping.
上下游分工Supply Chain Split 搭配晶圓代工廠防熔絲 OTP 記錄晶粒認證金鑰,並透過雲端金鑰託管基礎架構 (Provisioning Infrastructure),在晶圓廠、封測廠到 CSP 雲端伺服器機房建立端到端不可偽造憑證鏈。 Pairs with foundry AntiFuse OTP for silicon identity, linking with cloud Key Provisioning Infrastructure to establish an immutable certificate chain across Foundry, OSAT, and CSP data centers.
大型資料中心 AI 加速卡 (GPU/NPU)、CXL 記憶體擴展模組與伺服器平台標配。Standard for data center AI accelerators (GPU/NPU), CXL memory expanders, and enterprise servers.公開揭露的組成PUBLICLY DISCLOSED COMPOSITION
四個功能區塊協同運作共同交付一個安全結果 Four functional blocks composeto deliver a unified security outcome
公開揭露的是四塊功能如何組成一個 subsystem;契約歸屬、qualification 與 product-response scope 仍須另行關閉。Public disclosure shows how four blocks compose a subsystem; contractual ownership, qualification and product-response scope still require closure.
沒有永久儲存位址的根金鑰A root key with no permanent address
上電時量測 SRAM 啟動差異,處理成穩定且裝置唯一的根金鑰。重建根金鑰不作為永久儲存且持續供電的金鑰保留。SRAM startup variation is measured at power-up and processed into a stable device-unique root. The reconstructed root is not kept as a permanently stored powered key.
- 上電重建Power-up reconstruction
- 公開輔助資料Public helper data
- 縮短金鑰留存時間Short key residency
根金鑰生命週期ROOT-KEY LIFECYCLE
金鑰只在需要工作的時候存在 Keys exist only when actively working
不是「把 key 藏得更好」,而是把存在時間縮短成受控窗口。The point is not hiding the key better; it is shortening residency to a controlled window.
不留下刻意儲存或由電源維持的重建根金鑰No intentionally stored or powered reconstructed root remains
在經驗證的關機條件下,OTP 保留密文、輔助資料及生命週期狀態。電晶體失配可能持續存在;資料殘留與清除仍須納入安全保證驗證。Under validated shutdown conditions, OTP retains ciphertext, helper material and lifecycle state. Transistor mismatch may persist; remanence and zeroization remain assurance targets.
技術主張THE CLAIM
從架構到證據FROM ARCHITECTURE TO EVIDENCE
提出技術宣稱也要提出可以驗證的方法 Every technical claimmust have a verifiable methodology
PVT · BER · 資料保存 · 攻擊評估PVT · BER · retention · attack evaluation技術架構比較基準TECHNICAL ARCHITECTURE BENCHMARK
先建立公平的比較基準再判斷真正的技術差異 Establish fair comparison baselinesto judge true technical distinction
SRAM PUF
供電時的 SRAM 邏輯狀態消失;製程失配仍存在,但不保留已重建的根機密。The powered SRAM logic state disappears; process mismatch remains, but no reconstructed root is present.
- 物理來源Physical sourceSRAM 開機電晶體微觀失配 (Raw Intra-HD / BER: 3%~8%, Inter-HD: ~50%)Transistor mismatch at SRAM startup (Raw Intra-HD / BER: 3%~8%, Inter-HD: ~50%)
- 重建Reconstruction回應+公開輔助資料 → 穩定根金鑰 (Fuzzy Extractor / BCH / Reed-Solomon 演算法約 4x~8x 位元冗餘開銷與隱私放大)Response + public helper data → stable root (Fuzzy Extractor / BCH / Reed-Solomon code overhead ~4x-8x & privacy amplification)
- 安全工程Security engineering防護低溫急凍殘留 (Cold Boot) 與 NBTI 電氣老化之先決條件:整合 Active Bleeder 主動放電迴路(放電常數 τ < 1μs)、低溫聯鎖鎖定閥值 Tj < -40°C 鎖定開機感測、頂層主動金屬屏蔽 (Active Top-Metal Shield) 保護上電重建時窗,以及金鑰導出後 1 週期內即時硬體清除歸零 (Zeroization in 1 cycle)Defensive prerequisites against cold-boot remanence & NBTI aging: integrated active bleeder circuit (discharge constant τ < 1μs), low-temperature interlock threshold (Tj < -40°C lockup), active top-metal shield for reconstruction window, and post-reconstruction 1-cycle hardware zeroization
生命週期LIFECYCLE在零輔助資料與永久物理微導通路徑之間權衡攻擊面與架構複雜度。Balance zero helper-data activation against permanent physical conduction and attack surface.
NeoPUF
量子穿隧氧化層介電質擊穿形成永久微觀電流失配(零輔助資料 Zero Helper Data)。Quantum-tunneling dielectric breakdown creates permanent microscopic current mismatch (Zero Helper Data).
- 物理來源Physical sourceNMOS 成對閘極氧化層擊穿穿隧電流失配 (原生 Intra-HD ≈ 0%,需經工廠端高壓 Enrollment 應力與高低溫極端邊界單元篩選)Oxide breakdown tunneling current mismatch in NMOS cell pair (Native Intra-HD ≈ 0%, requiring factory high-voltage enrollment stress & extreme-PVT marginal cell screening)
- 重建Reconstruction直接感測讀取;零輔助資料/無 Fuzzy Extractor 演算法額外位元開銷Direct read; zero helper data / zero fuzzy extractor algorithm bit overhead
- 安全工程Security engineering永久微觀通道需頂層主動金屬屏蔽 (Active Top-Metal Mesh) 防範 FIB 微探針與背面減薄研磨,入侵觸發單週期即時密鑰清除Permanent microscopic filament requires top-layer active metal mesh against FIB probing & backside thinning, triggering single-cycle instant zeroization
SRAM PUF;重建的根機密不作為持續供電的金鑰儲存SRAM PUF; reconstructed root not kept as a stored powered key
NeoPUF;1024 位元實體 PUFNeoPUF; 1024-bit physical PUF
AES-256 加密/解密+位址擾碼AES-256 encryption/decryption + address scrambling
即時硬體加密+位址/I/O 擾碼;公開資料未指明演算法Instant hardware encryption + address/IO scrambling; algorithm not named publicly
AMBA APB、簡易 API、自動佈建與初始化AMBA APB, simple API, auto provisioning and initialization
AMBA APB、韌體/API、自動載入、鎖定與清除AMBA APB, firmware/API, autoload, locks and zeroization
Synopsys 報告其 SRAM PUF 技術已用於超過 15 億顆裝置、SRAM PUF 技術累積超過 15 年實證,以及反熔絲 OTP NVM 累計出貨超過 100 億顆;目標組態仍需完成驗證Synopsys reports >1.5B devices using its SRAM PUF technology, >15 years of proven SRAM PUF technology, and >10B antifuse OTP NVM units shipped (vendor-reported portfolio CONTEXT). Target configuration is product-specific — not a certificate for this page
PUFsecurity 報告廣泛商用採用(累積逾 1 億顆出貨橫跨 IoT/AI/車規,承襲力旺 eMemory IP 血統);具體配置仍需確認PUFsecurity reports broad commercial adoption (>100M+ units across IoT/AI/automotive) with vendor eMemory IP lineage (product/vendor lineage OK; not author tenure). Target configuration is product-specific
架構綜述ENGINEERING SUMMARY兩者皆透過差異化實體熵源解決信任根佈建:靜態不留存的 SRAM PUF 結合整合式密碼子系統,對比專屬氧化層擊穿 PUF OTP。晶片架構師應依目標製程節點、輔助資料管理負擔與認證邊界進行客觀評估。Both architectures address root-of-trust provisioning through differentiated physical entropy sources: absent-at-rest SRAM PUF with an integrated cryptographic subsystem versus dedicated oxide-breakdown PUF OTP, requiring architects to evaluate based on target process node, helper data handling, and certification boundaries.
晶片SILICON
可歸責的整合子系統ONE ACCOUNTABLE SUBSYSTEM
信任不只存在於單一功能
它必須落實在系統邊界之內
Trust extends beyond a single function;
it must be enforced within system boundaries
根機密 · 保護 · 控制 · 偵測 · 證明Root · protect · control · detect · prove
供應商報告的產品組合背景VENDOR-REPORTED PORTFOLIO CONTEXT
成熟度能縮小不確定性Target evidence 才能決定適用性 Maturity reduces uncertainty;Target evidence decides applicability
長期 deployment、PVT、aging、認證與修補紀錄可降低起始風險;但不會自動轉移到 licensed Secure Storage configuration。Long-term deployment, PVT, aging, certification and repair history reduce baseline risk; they do not automatically transfer to a licensed target configuration.
來源範圍 · Synopsys 報告的技術組合數字 · 並非交付組態的獨立安全保證SOURCE SCOPE · SYNOPSYS-REPORTED PORTFOLIO FIGURES · NOT INDEPENDENT ASSURANCE OF THE DELIVERED CONFIGURATION
已公開的先進製程 OTP 背景Published advanced-node OTP context
Synopsys 報告其 OTP 已於所列 TSMC 製程完成晶片驗證。節點可用性無法證明每種組態的 Secure Storage 已發布、已整合 PUF,或已完成攻擊評估。Synopsys reports OTP silicon-verified in the listed TSMC processes. Node availability does not prove Secure Storage release, PUF integration or attack evaluation for each configuration.
一套架構 · 四類成果ONE ARCHITECTURE · FOUR OUTCOMES
技術價值,最終必須落在要保護的資產 Technical value must protect target assets
相同的 root-key lifecycle,因應不同市場中最昂貴、最敏感、最難替換的資料。The same root-key lifecycle is applied to the most expensive, sensitive and hardest-to-replace assets in each market.
保護模型價值與平台完整性Protect model value and platform integrity
韌體防回復 · 模型/權重金鑰 · 平台身分Firmware anti-rollback · model/weight keys · platform identity
01把安全資料綁定到正確裝置Bind security data to the correct device
校準 · 組態 · 安全開機 · 生命週期狀態Calibration · configuration · secure boot · lifecycle state
02降低靜態金鑰擷取目標Reduce the static key-extraction target
任務演算法 · 永久身分 · 防複製憑證Mission algorithms · permanent identity · anti-cloning credentials
03大規模建立 device-unique trustEstablish device-unique trust at scale
通訊協定金鑰 · ROM 修補 · 防偽身分Protocol keys · ROM patches · anti-counterfeit identity
04
產品決策不只涵蓋功能
也必須涵蓋可歸責的安全結果
Product decisions cover features
and accountable security outcomes
預先整合可減少跨模組交接;契約權責、資格驗證支援與產品回應範圍仍須確認。Pre-integration can reduce cross-block hand-offs; contractual ownership, qualification support and product-response scope must still be confirmed.
NVM 知識中心NVM KNOWLEDGE HUB
從技術名詞,走到可以做決策 From technical jargon to actionable decisions
沒有符合條件的學習內容。No matching learning content.
02 / 研究主題 · 持續擴充02 / RESEARCH TOPICS · EXPANDING
從記憶體物理,走到 AI 系統邊界
證據先於機會推論
From memory physics to AI system frontiers
Evidence before opportunity inference
一條研究線拆解 bit-cell 與 sensing;另一條把 identity、repair、calibration、firmware 與 RAS evidence 映射到正確的 persistent-state contract。One research line unpacks bit-cell and sensing; the other maps identity, repair, calibration, firmware and RAS evidence onto the right persistent-state contract.
公開證據 · 來源紀律PUBLIC EVIDENCE · SOURCE DISCIPLINE
本頁的證據原則:EVIDENCE PRINCIPLE對已知內容提供可追溯的證據;Provide traceable evidence for what is known.對尚未確認的部分清楚標示限制。Clearly state the limits of what remains unconfirmed.
僅限公開來源對比。實作細節、攻擊證據與交付成果需經 NDA 審查。持久物理響應狀態在此不被視為明文金鑰儲存。 Public-source comparison only. Implementation details, attack evidence and deliverables require NDA-level review. Persistent physical response state is not described here as plaintext key storage.
永久資料 · 短暫根金鑰PERMANENT DATA · EPHEMERAL ROOT