管理與技術學習導覽EXECUTIVE LEARNING EXPERIENCE01 / 安全儲存01 / SECURE STORAGE

永久保存資料
根金鑰不永久留存
Permanent Data At Rest
Ephemeral Silicon Root Key

以 SRAM PUF 在上電時重建裝置唯一的根金鑰,再用 AES-256 保護 OTP 內容(已揭露密碼演算法;模式與引擎仍須依目標組態確認)。在經驗證的關機條件下,不保留刻意儲存或仍由電源維持的重建根金鑰。 Reconstruct a device-unique root key from SRAM PUF at power-up, then protect OTP content with AES-256 (cipher disclosed; mode/engine remain target-open until closed). Under verified shutdown, no intentionally stored or power-sustained reconstructed root remains.

>1.5B採用 SRAM PUF 技術的裝置devices using SRAM PUF technology (供應商報告的背景資料,並非本組態)(vendor-reported CONTEXT — not this config)
超過 15 年>15 yearsSRAM PUF 技術的累積實證of proven SRAM PUF technology
AES-256已公開的 OTP 資料保護disclosed OTP data protection
供應商報告的技術組合背景 · 並非目標組態的安全保證。輔助資料、電晶體失配與生命週期狀態可能持續存在;殘留與清除仍是安全保證的驗證目標。VENDOR-REPORTED PORTFOLIO CONTEXT · NOT TARGET-CONFIGURATION ASSURANCE. Helper material, transistor mismatch and lifecycle state may persist; remanence and zeroization remain assurance targets.
SRAM PUF 根金鑰SRAM PUF ROOT KEY上電時重建 · 不刻意永久儲存RECONSTRUCTED AT POWER-UP · NOT INTENTIONALLY STORED
向下探索SCROLL TO EXPLORE
法則 #01 · 根金鑰不永久儲存RULE #01 · NO STORED ROOT
靜止時不留存根金鑰ABSENT AT REST

上電重建;下電不保留 powered reconstructed rootReconstructed at power-up; no powered reconstructed root at rest

法則 #02 · 資料以密文保存RULE #02 · CIPHER DATA
AES-256

硬體密碼引擎保護 OTP 內容;公開揭露為 AES-256,mode 待 target 關閉Hardware crypto protects OTP as ciphertext; AES-256 is disclosed, mode remains target-specific

背景 #03 · 已公開的採用規模CONTEXT #03 · PROVEN SCALE
超過 15 億顆>1.5B UNITS 背景資料CONTEXT

超過 15 年公開組合歷史;不自動等於本配置保證>15 years portfolio history; not automatic target-configuration assurance

背景 #04 · 先進製程節點CONTEXT #04 · ADVANCED NODES
N7 → N3P

純邏輯相容節點脈絡;各配置仍需關閉Logic-compatible node context; each configuration still requires closure

決策重點DECISION STRIP

關閉 target configuration 前先問這五件事 Five questions before closing a target configuration

把學習頁轉成決策頁:先問這五件事,再把 portfolio 數字當成起始脈絡。 Turn the learning page into a decision page: close these five questions before treating portfolio figures as applicable.

01 目標組態01 Target

本配置的 node、macro 與整合邊界是什麼?What node, macro and integration boundary is the licensed target?

02 密碼保護02 Cipher

該配置公開的是 AES-256,還是已鎖定的 mode/engine?Is AES-256 disclosed only, or is the mode and engine locked for this configuration?

03 輔助資料03 Helper

helper/activation data 的暴露模型與完整性假設為何?What is the helper or activation-data exposure model and integrity assumption?

04 清除04 Zeroize

remanence 與 zeroization 的驗證範圍到哪裡?What remanence and zeroization evidence covers the powered-down window?

05 攻擊驗證05 Attack

FI、SCA 與 invasive readout 的證據 scope 是什麼?What FI, SCA and invasive-readout evidence exists, and for which scope?

SRAM PUF AES-256 反熔絲 OTPANTIFUSE OTP 安全控制器SECURE CONTROLLER
01
核心主張THE EXECUTIVE THESIS

安全不只取決於資料能保存多久
更取決於攻擊發生時,晶片裡還留下什麼
Security is not just how long data lasts,
but what remains in silicon under attack

OTP 解決永久性;Secure Storage 解決機密性。即使攻擊者成功觀察記憶體狀態,他取得的也應該是受保護資料,而不是可直接使用的 root secret。OTP solves permanence; Secure Storage solves confidentiality. Even if an attacker observes the memory state, the recoverable result should be protected data, not a usable root secret.

用 Power-off State 檢驗設計Evaluate the design through its power-off state
01

靜止時不留存Absent at rest

在已驗證的 shutdown 條件下,不保留刻意儲存或已重建、仍由電源維持的 root;transistor mismatch 與 helper material 仍可能存在。Under verified shutdown, no intentionally stored or powered reconstructed root remains; transistor mismatch and helper material may still exist.

02

密文持續保留Ciphertext remains

OTP 永久保存的是 AES-256 密文與安全狀態。What OTP keeps permanently is AES-256 ciphertext and security state.

03

單一安全邊界One boundary

PUF、crypto、OTP 與 controller 共同構成安全子系統。PUF, crypto, OTP and the controller compose one security subsystem.

章節 01LENS 01IP
契約CONTRACT

從基礎元件到整合子系統FROM PRIMITIVE TO INTEGRATED SUBSYSTEM

好的矽智財,必須定義清楚
整合邊界也必須可以驗證
Quality silicon IP requires clear definitions
and verifiable integration boundaries

架構 · 介面 · 生命週期 · 交付項目Architecture · interface · lifecycle · deliverables

互動展示 · 電源狀態INTERACTIVE · POWER STATE

先關掉電源再看攻擊者能取得什麼 Power off first,then see what an attacker recovers

切換狀態,觀察 root key 的存在窗口。主張不是物理攻擊會消失,而是成功讀取後能揭露的內容被限制。Switch state and watch the root-key residency window. The claim is not that physical attack disappears; it is that a successful readout should stop at protected content.

靜止狀態AT REST

核心斷電優勢:不留下刻意儲存或由電源維持的重建根金鑰Core power-off advantage: no intentionally stored or powered reconstructed root remains

在經驗證的關機條件下,OTP 保留密文、輔助資料及生命週期狀態;不留下刻意儲存或由電源維持的重建根金鑰。電晶體失配、資料殘留與清除仍須納入安全保證驗證。Under verified shutdown, OTP retains ciphertext, helper material and lifecycle state; no intentionally stored or powered reconstructed root remains. Transistor mismatch, remanence and zeroization remain assurance targets.

安全儲存SECURE STORAGE斷電POWER OFF
OTP 內容OTP CONTENTAES-256 密文AES-256 CIPHERTEXT
重建根金鑰RECONSTRUCTED ROOT未供電NOT POWERED
實體讀取PHYSICAL READOUT
攻擊者可擷取ATTACKER RECOVERS受保護資料PROTECTED DATA

公開攻擊證據PUBLIC ATTACK SIGNAL

用公開攻擊界定 threat model,
再把它轉成產品要求
Anchor threat models in public attacks,
then translate them to product specs

RP2350 是特定實作的公開 case,不代表所有 OTP 都同樣可攻。它揭示兩條平行路徑:fault 可能破壞 control assumptions;FIB/PVC 則接近 physical bit-state recovery。產品要求因此是:即使 readout 成功,也不應直接得到 usable secret。RP2350 is a public case of one implementation, not a claim that every OTP is equally attackable. It shows two parallel paths: fault can break control assumptions; FIB/PVC approaches physical bit-state recovery. The product requirement is that a successful readout should still not yield a usable secret.

01A · 控制路徑01A · CONTROL PATH

故障可能破壞原有假設Fault can collapse assumptions

背部雷射故障注入 (LFI)、電壓突波 (Voltage Glitch)、電磁脈衝 (EMFI) 或時鐘干擾可能引發指令跳躍 (instruction skip),破壞安全啟動、權限狀態或鎖定暫存器。Backside laser fault injection (LFI), voltage glitch, electromagnetic fault injection (EMFI), or clock disturbance can cause instruction skip, corrupting secure boot, privilege states, or lock registers.

01B · 侵入式路徑01B · INVASIVE PATH

FIB/PVC 可能揭露實體狀態FIB/PVC can expose physical state

公開案例已讀出相鄰 bit pair 的 OR;完整逐 bit recovery 仍未被示範。A public case recovered the OR of adjacent bit pairs; full bit-by-bit recovery has not been demonstrated.

02 · 組合防禦02 · COMPOSED RESPONSE

加密、擾亂與治理Encrypt, scramble and govern

只有在所有 composed controls 成立時,readout 才應停在 scrambled ciphertext。Only when all composed controls hold should readout stop at scrambled ciphertext.

03 · 證據驗證關卡03 · EVIDENCE GATE

完成目標組態驗證Close the target configuration

以 target node、macro、integration 與 FI/SCA/invasive evidence 驗證結果。Close the result against the target node, macro, integration and FI/SCA/invasive evidence.

實體安全保證PHYSICAL SECURITY ASSURANCE

安全主張,必須經得起實體攻擊驗證 Security claims must survive
physical validation

從威脅方法、可觀察訊號與故障注入,到緩解措施、測試證據與第三方確證;讓每一項 Secure NVM 主張都能被追溯。Trace every Secure NVM claim from threat method and observable signal to mitigation, test evidence and independent assurance.

01威脅THREAT定義攻擊者與資產Define actor and asset
02方法METHODFI · SCA · 實體讀取FI · SCA · readout
03觀測OBSERVE量測可利用結果Measure exploitable result
04緩解MITIGATE限制攻擊後果Constrain consequences
05證據EVIDENCE建立可重現證據Build reproducible evidence
06確證ASSURE評估與認證範圍Evaluate and certify scope
關鍵問題KEY QUESTION

攻擊者會怎麼驗證?現有證據是什麼?還有什麼未知?How would an attacker test it? What evidence exists? What remains unknown?

進入安全確證中心Open Assurance Center

分層信任 · 實務案例LAYERED TRUST · PRACTICAL CASE STUDY

不是三選一讓每一層各自解決正確的問題Not three alternativesGive each layer the right security job

這段是 trust-layer 職能拆分,不是產品 BOM 或現成 Okta 整合。OpenPGP 保護資料與簽章;Okta FastPass 管理使用者、裝置狀態與存取政策;PUF 強化兩者下方的 silicon root,降低對永久儲存 root secret 的依賴。This is a trust-layer job split, not a product BOM or a turnkey Okta integration. OpenPGP protects data and signatures. Okta FastPass governs users, device posture and access policy. A PUF strengthens the silicon root beneath them by reducing dependence on a persistently stored root secret.

01 · 資料01 · DATA

OpenPGP

主要任務Primary job端對端加密、解密與數位簽章。End-to-end encryption, decryption and digital signatures.

斷電後仍存在Persists at rest私鑰 packet;可能受 passphrase 保護,但仍是可保存與複製的數位物件。A secret-key packet, optionally passphrase-protected, remains a storable and copyable digital object.

不負責裝置完整性、登入政策或已解鎖後的惡意操作。Does not provide device integrity, login policy or protection from misuse after unlock.
02 · 存取02 · ACCESS

Okta FastPass

主要任務Primary jobphishing-resistant、passwordless authentication 與裝置政策。Phishing-resistant, passwordless authentication and device policy.

裝置端狀態Device state註冊時建立 proof-of-possession key;可使用 TPM/Secure Enclave,也可能落在 software keystore。Enrollment creates a proof-of-possession key; it may use a TPM/Secure Enclave or a software keystore.

hardware protection 必須由政策要求,不能只因為使用 FastPass 就假設存在。Hardware protection must be required by policy; FastPass alone does not guarantee it.
03 · 晶片根金鑰03 · SILICON ROOT

SRAM PUF

主要任務Primary job需要時重建 device-unique root,用來 derive 或 unwrap operational keys。Reconstruct a device-unique root on demand to derive or unwrap operational keys.

斷電後仍存在Persists at resthelper/activation data 與 wrapped keys 可以存在;root secret 本身不必永久儲存。Helper or activation data and wrapped keys may persist; the root secret itself need not.

不取代 user identity、MFA、authorization、revocation 或 recovery。Does not replace user identity, MFA, authorization, revocation or recovery.
參考架構 · 並非可直接交付的 Okta 整合方案REFERENCE ARCHITECTURE · NOT A TURNKEY OKTA INTEGRATION

案例:Device-bound enterprise signingCase: Device-bound enterprise signing

只有同時通過企業身分政策與原始 silicon device 驗證,才允許本機 OpenPGP operation。A local OpenPGP operation is released only when enterprise identity policy and the enrolled silicon device are both satisfied.

01OKTA FASTPASS授權人與 sessionAuthorize user and session使用者 · 裝置狀態 · 政策 · 撤銷user · posture · policy · revoke
02PUF 根金鑰PUF ROOT確認實體裝置並解封Bind device and unseal重建 · 衍生 · 清除reconstruct · derive · zeroize
03OPENPGP簽署或解密內容Sign or decrypt the artifact可攜式資料保護portable data protection
網路釣魚PHISHINGOkta FastPasschallenge/origin 與 policyChallenge, origin and policy
複製的儲存資料COPIED STORAGEPUF 與封裝金鑰PUF + wrapped key複製 blob 不等於複製 device rootA copied blob is not the device root
資料可攜性DATA PORTABILITYOpenPGP跨系統的加密與簽章格式Portable encryption and signature format
共同限制SHARED LIMIT已入侵的 runtimeCompromised runtime重建或解鎖後仍需 isolation、user presence、rate limit 與 zeroization。After reconstruction or unlock, isolation, user presence, rate limits and zeroization still matter.

生態系與整合 · 硬體信任根ECOSYSTEM & INTEGRATION · HARDWARE ROOT OF TRUST

晶片級硬體根信任上下游安全子系統協同實踐 Hardware Root of TrustUpstream & Downstream Subsystem Integration

安全儲存與 PUF 不能孤立存在,必須作為安全子系統的硬體錨點。以下解析業界三大主流安全子系統架構如何整合底層 NVM/PUF、硬體隔離核心與上層端到端認證協議: Secure storage and PUFs do not operate in isolation; they serve as hardware anchors within security subsystems. Below are three mainstream commercial architectures integrating silicon primitives, isolated enclaves, and cloud attestation:

01 · 零金鑰佈建01 · ZERO PROVISIONING

Intrinsic ID Quiddikey

核心定位與機制Core Role & Mechanism SRAM PUF + 模糊提取器 (Fuzzy Extractor):利用晶粒原生標準 6T SRAM 上電時的隨機臨界電壓 mismatch 作為物理指紋。搭配公開儲存之 Activation Code(Helper Data),透過 BCH 糾錯重構 256-bit 根金鑰,用畢即銷毀。 SRAM PUF + Fuzzy Extractor: Leverages native 6T SRAM power-up mismatch as a physical fingerprint. Combines with a public Activation Code (Helper Data) to reconstruct a 256-bit root key via BCH error correction; cleared immediately after use.

上下游分工Supply Chain Split Helper Data 本身不含機密性,可直接存放於外部便宜的 SPI NOR Flash 或片上標準 OTP。徹底免除封測廠 (OSAT) 昂貴的安全無塵室金鑰注入流程,杜絕工廠端私鑰洩漏。 Helper Data carries no secrecy and can reside in external SPI NOR Flash or on-chip standard OTP, eliminating costly secure room key-injection during OSAT assembly.

適合超低成本 IoT MCU、車載雷達與資源受限微控制器。Ideal for ultra-low-cost IoT MCUs, automotive radar, and constrained microcontrollers.
02 · 硬體安全隔離區02 · HARDWARE ENCLAVE

Synopsys tRoot™ HSM

核心定位與機制Core Role & Mechanism 隔離安全子系統 (Secure Enclave):整合獨立安全 RISC-V/ARC 處理器、密碼加速引擎 (Side-channel protected AES/ECC)、真隨機數產生器 (TRNG) 與 Bus Guard 硬體防火牆,防禦 Host CPU 側通道與軟體溢位攻擊。 Isolated Secure Enclave: Integrates an isolated secure CPU core, DPA-resistant crypto accelerators, TRNG, and Bus Guard memory firewall to insulate security operations from host CPU vulnerabilities.

上下游分工Supply Chain Split 底層可整合 Synopsys 1T Split-Channel AntiFuse OTP 保存晶片 UID、根公鑰雜湊 (ROTPK) 與安全組態;向上為 Host OS 提供 Secure Boot、防回滾 (Anti-Rollback) 與金鑰封裝服務 — PSA L3/SESIP 等級須對應具名產品與評估範圍,不得由 portfolio 敘述直接推出。 May integrate 1T Split-Channel AntiFuse OTP for UID and Root-of-Trust Public Key (ROTPK) storage; provides Secure Boot, Anti-Rollback, and key wrapping — PSA L3/SESIP tiers require named product evaluation scope; do not infer from portfolio marketing alone.

廣泛應用於車規 ADAS SoC、邊緣 AI 運算晶片與智慧座艙處理器。Widely deployed in automotive ADAS SoCs, edge AI chips, and smart cockpit processors.
03 · 裝置證明與雲端03 · ATTESTATION & CLOUD

Rambus CryptoManager™

核心定位與機制Core Role & Mechanism 高速鏈路保護 (SPDM / IDE):在 PCIe Gen5/Gen6 與 CXL 2.0/3.0 介面硬體實現 DMTF SPDM 1.2/1.3 設備互聯認證,並以線速 AES-GCM 執行 IDE (Integrity & Data Encryption),防禦實體中間人竊聽。 High-Speed Link Security (SPDM / IDE): Hardware implementation of DMTF SPDM 1.2/1.3 device attestation and line-rate PCIe/CXL IDE encryption (AES-GCM), protecting against physical interposer tapping.

上下游分工Supply Chain Split 搭配晶圓代工廠防熔絲 OTP 記錄晶粒認證金鑰,並透過雲端金鑰託管基礎架構 (Provisioning Infrastructure),在晶圓廠、封測廠到 CSP 雲端伺服器機房建立端到端不可偽造憑證鏈。 Pairs with foundry AntiFuse OTP for silicon identity, linking with cloud Key Provisioning Infrastructure to establish an immutable certificate chain across Foundry, OSAT, and CSP data centers.

大型資料中心 AI 加速卡 (GPU/NPU)、CXL 記憶體擴展模組與伺服器平台標配。Standard for data center AI accelerators (GPU/NPU), CXL memory expanders, and enterprise servers.

公開揭露的組成PUBLICLY DISCLOSED COMPOSITION

四個功能區塊協同運作共同交付一個安全結果 Four functional blocks composeto deliver a unified security outcome

公開揭露的是四塊功能如何組成一個 subsystem;契約歸屬、qualification 與 product-response scope 仍須另行關閉。Public disclosure shows how four blocks compose a subsystem; contractual ownership, qualification and product-response scope still require closure.

裝置唯一DEVICE-UNIQUE
模組 01BLOCK 01

沒有永久儲存位址的根金鑰A root key with no permanent address

上電時量測 SRAM 啟動差異,處理成穩定且裝置唯一的根金鑰。重建根金鑰不作為永久儲存且持續供電的金鑰保留。SRAM startup variation is measured at power-up and processed into a stable device-unique root. The reconstructed root is not kept as a permanently stored powered key.

  • 上電重建Power-up reconstruction
  • 公開輔助資料Public helper data
  • 縮短金鑰留存時間Short key residency

根金鑰生命週期ROOT-KEY LIFECYCLE

金鑰只在需要工作的時候存在 Keys exist only when actively working

不是「把 key 藏得更好」,而是把存在時間縮短成受控窗口。The point is not hiding the key better; it is shortening residency to a controlled window.

01 / 靜止狀態01 / AT REST

不留下刻意儲存或由電源維持的重建根金鑰No intentionally stored or powered reconstructed root remains

在經驗證的關機條件下,OTP 保留密文、輔助資料及生命週期狀態。電晶體失配可能持續存在;資料殘留與清除仍須納入安全保證驗證。Under validated shutdown conditions, OTP retains ciphertext, helper material and lifecycle state. Transistor mismatch may persist; remanence and zeroization remain assurance targets.

章節 02LENS 02量測MEASURE
技術主張THE CLAIM

從架構到證據FROM ARCHITECTURE TO EVIDENCE

提出技術宣稱也要提出可以驗證的方法 Every technical claimmust have a verifiable methodology

PVT · BER · 資料保存 · 攻擊評估PVT · BER · retention · attack evaluation

技術架構比較基準TECHNICAL ARCHITECTURE BENCHMARK

先建立公平的比較基準再判斷真正的技術差異 Establish fair comparison baselinesto judge true technical distinction

SYNOPSYS

SRAM PUF

斷電後實體狀態POWER-OFF PHYSICAL STATE無電源維持的邏輯狀態NO POWERED LOGIC STATE

供電時的 SRAM 邏輯狀態消失;製程失配仍存在,但不保留已重建的根機密。The powered SRAM logic state disappears; process mismatch remains, but no reconstructed root is present.

  • 物理來源Physical sourceSRAM 開機電晶體微觀失配 (Raw Intra-HD / BER: 3%~8%, Inter-HD: ~50%)Transistor mismatch at SRAM startup (Raw Intra-HD / BER: 3%~8%, Inter-HD: ~50%)
  • 重建Reconstruction回應+公開輔助資料 → 穩定根金鑰 (Fuzzy Extractor / BCH / Reed-Solomon 演算法約 4x~8x 位元冗餘開銷與隱私放大)Response + public helper data → stable root (Fuzzy Extractor / BCH / Reed-Solomon code overhead ~4x-8x & privacy amplification)
  • 安全工程Security engineering防護低溫急凍殘留 (Cold Boot) 與 NBTI 電氣老化之先決條件:整合 Active Bleeder 主動放電迴路(放電常數 τ < 1μs)、低溫聯鎖鎖定閥值 Tj < -40°C 鎖定開機感測、頂層主動金屬屏蔽 (Active Top-Metal Shield) 保護上電重建時窗,以及金鑰導出後 1 週期內即時硬體清除歸零 (Zeroization in 1 cycle)Defensive prerequisites against cold-boot remanence & NBTI aging: integrated active bleeder circuit (discharge constant τ < 1μs), low-temperature interlock threshold (Tj < -40°C lockup), active top-metal shield for reconstruction window, and post-reconstruction 1-cycle hardware zeroization
決策視角DECISION LENS熵與ENTROPY &
生命週期LIFECYCLE
在零輔助資料與永久物理微導通路徑之間權衡攻擊面與架構複雜度。Balance zero helper-data activation against permanent physical conduction and attack surface.
PUFSECURITY / EMEMORY

NeoPUF

斷電後實體狀態POWER-OFF PHYSICAL STATE持久導通路徑PERSISTENT CONDUCTION PATH

量子穿隧氧化層介電質擊穿形成永久微觀電流失配(零輔助資料 Zero Helper Data)。Quantum-tunneling dielectric breakdown creates permanent microscopic current mismatch (Zero Helper Data).

  • 物理來源Physical sourceNMOS 成對閘極氧化層擊穿穿隧電流失配 (原生 Intra-HD ≈ 0%,需經工廠端高壓 Enrollment 應力與高低溫極端邊界單元篩選)Oxide breakdown tunneling current mismatch in NMOS cell pair (Native Intra-HD ≈ 0%, requiring factory high-voltage enrollment stress & extreme-PVT marginal cell screening)
  • 重建Reconstruction直接感測讀取;零輔助資料/無 Fuzzy Extractor 演算法額外位元開銷Direct read; zero helper data / zero fuzzy extractor algorithm bit overhead
  • 安全工程Security engineering永久微觀通道需頂層主動金屬屏蔽 (Active Top-Metal Mesh) 防範 FIB 微探針與背面減薄研磨,入侵觸發單週期即時密鑰清除Permanent microscopic filament requires top-layer active metal mesh against FIB probing & backside thinning, triggering single-cycle instant zeroization
公開揭露的比較範圍PUBLICLY DISCLOSED LENSSYNOPSYS SECURE STORAGEPUFSECURITY SECURE OTP
PUF 根金鑰PUF root

SRAM PUF;重建的根機密不作為持續供電的金鑰儲存SRAM PUF; reconstructed root not kept as a stored powered key

NeoPUF;1024 位元實體 PUFNeoPUF; 1024-bit physical PUF

資料保護Data protection

AES-256 加密/解密+位址擾碼AES-256 encryption/decryption + address scrambling

即時硬體加密+位址/I/O 擾碼;公開資料未指明演算法Instant hardware encryption + address/IO scrambling; algorithm not named publicly

整合Integration

AMBA APB、簡易 API、自動佈建與初始化AMBA APB, simple API, auto provisioning and initialization

AMBA APB、韌體/API、自動載入、鎖定與清除AMBA APB, firmware/API, autoload, locks and zeroization

產品組合背景Portfolio context

Synopsys 報告其 SRAM PUF 技術已用於超過 15 億顆裝置、SRAM PUF 技術累積超過 15 年實證,以及反熔絲 OTP NVM 累計出貨超過 100 億顆;目標組態仍需完成驗證Synopsys reports >1.5B devices using its SRAM PUF technology, >15 years of proven SRAM PUF technology, and >10B antifuse OTP NVM units shipped (vendor-reported portfolio CONTEXT). Target configuration is product-specific — not a certificate for this page

PUFsecurity 報告廣泛商用採用(累積逾 1 億顆出貨橫跨 IoT/AI/車規,承襲力旺 eMemory IP 血統);具體配置仍需確認PUFsecurity reports broad commercial adoption (>100M+ units across IoT/AI/automotive) with vendor eMemory IP lineage (product/vendor lineage OK; not author tenure). Target configuration is product-specific

架構綜述ENGINEERING SUMMARY兩者皆透過差異化實體熵源解決信任根佈建:靜態不留存的 SRAM PUF 結合整合式密碼子系統,對比專屬氧化層擊穿 PUF OTP。晶片架構師應依目標製程節點、輔助資料管理負擔與認證邊界進行客觀評估。Both architectures address root-of-trust provisioning through differentiated physical entropy sources: absent-at-rest SRAM PUF with an integrated cryptographic subsystem versus dedicated oxide-breakdown PUF OTP, requiring architects to evaluate based on target process node, helper data handling, and certification boundaries.

章節 03LENS 03安全SECURE
晶片SILICON

可歸責的整合子系統ONE ACCOUNTABLE SUBSYSTEM

信任不只存在於單一功能
它必須落實在系統邊界之內
Trust extends beyond a single function;
it must be enforced within system boundaries

根機密 · 保護 · 控制 · 偵測 · 證明Root · protect · control · detect · prove

供應商報告的產品組合背景VENDOR-REPORTED PORTFOLIO CONTEXT

成熟度能縮小不確定性Target evidence 才能決定適用性 Maturity reduces uncertainty;Target evidence decides applicability

長期 deployment、PVT、aging、認證與修補紀錄可降低起始風險;但不會自動轉移到 licensed Secure Storage configuration。Long-term deployment, PVT, aging, certification and repair history reduce baseline risk; they do not automatically transfer to a licensed target configuration.

來源範圍 · Synopsys 報告的技術組合數字 · 並非交付組態的獨立安全保證SOURCE SCOPE · SYNOPSYS-REPORTED PORTFOLIO FIGURES · NOT INDEPENDENT ASSURANCE OF THE DELIVERED CONFIGURATION

>1.5B採用 Synopsys SRAM PUF 技術的裝置devices using Synopsys SRAM PUF technology
>15年 SRAM PUF 技術累積實證years of proven SRAM PUF technology
>10BSynopsys 反熔絲 OTP NVM 累積出貨量Synopsys antifuse OTP NVM units shipped
350 nm → 2 nm 供應商報告的 PUF 製程範圍vendor-reported PUF range −40°C → 150°C 供應商報告的特性量測範圍vendor-reported characterization ISO 26262 / 21434 產品組合層級的車用沿革portfolio-level automotive lineage NIST SP 800-90B/208 · SESIP Level 3+ · CC AVA_VAN.5 適用範圍須逐產品確認scope must be checked per product

已公開的先進製程 OTP 背景Published advanced-node OTP context

Synopsys 報告其 OTP 已於所列 TSMC 製程完成晶片驗證。節點可用性無法證明每種組態的 Secure Storage 已發布、已整合 PUF,或已完成攻擊評估。Synopsys reports OTP silicon-verified in the listed TSMC processes. Node availability does not prove Secure Storage release, PUF integration or attack evaluation for each configuration.

N7N7AN6N5N5AN4PN3P

一套架構 · 四類成果ONE ARCHITECTURE · FOUR OUTCOMES

技術價值,最終必須落在要保護的資產 Technical value must protect target assets

相同的 root-key lifecycle,因應不同市場中最昂貴、最敏感、最難替換的資料。The same root-key lifecycle is applied to the most expensive, sensitive and hardest-to-replace assets in each market.

AI / HPC

保護模型價值與平台完整性Protect model value and platform integrity

韌體防回復 · 模型/權重金鑰 · 平台身分Firmware anti-rollback · model/weight keys · platform identity

01
車用AUTOMOTIVE

把安全資料綁定到正確裝置Bind security data to the correct device

校準 · 組態 · 安全開機 · 生命週期狀態Calibration · configuration · secure boot · lifecycle state

02
航太與國防AEROSPACE & DEFENSE

降低靜態金鑰擷取目標Reduce the static key-extraction target

任務演算法 · 永久身分 · 防複製憑證Mission algorithms · permanent identity · anti-cloning credentials

03
IoT 與連線應用IoT / CONNECTIVITY

大規模建立 device-unique trustEstablish device-unique trust at scale

通訊協定金鑰 · ROM 修補 · 防偽身分Protocol keys · ROM patches · anti-counterfeit identity

04
基礎元件安全PRIMITIVE SECURITYSoC 交付SOC DELIVERY

產品決策不只涵蓋功能
也必須涵蓋可歸責的安全結果
Product decisions cover features
and accountable security outcomes

根金鑰ROOTSRAM PUF
密碼保護CRYPTOAES-256
儲存STORAGEAntifuse OTP
控制CONTROLAPB 與政策APB + policy
生命週期LIFECYCLE佈建與支援Provision + support

預先整合可減少跨模組交接;契約權責、資格驗證支援與產品回應範圍仍須確認。Pre-integration can reduce cross-block hand-offs; contractual ownership, qualification support and product-response scope must still be confirmed.

NVM 知識中心NVM KNOWLEDGE HUB

從技術名詞,走到可以做決策 From technical jargon to actionable decisions

02 / 研究主題 · 持續擴充02 / RESEARCH TOPICS · EXPANDING

從記憶體物理,走到 AI 系統邊界
證據先於機會推論
From memory physics to AI system frontiers
Evidence before opportunity inference

一條研究線拆解 bit-cell 與 sensing;另一條把 identity、repair、calibration、firmware 與 RAS evidence 映射到正確的 persistent-state contract。One research line unpacks bit-cell and sensing; the other maps identity, repair, calibration, firmware and RAS evidence onto the right persistent-state contract.

公開證據 · 來源紀律PUBLIC EVIDENCE · SOURCE DISCIPLINE

本頁的證據原則:EVIDENCE PRINCIPLE對已知內容提供可追溯的證據;Provide traceable evidence for what is known.對尚未確認的部分清楚標示限制。Clearly state the limits of what remains unconfirmed.

僅限公開來源對比。實作細節、攻擊證據與交付成果需經 NDA 審查。持久物理響應狀態在此不被視為明文金鑰儲存。 Public-source comparison only. Implementation details, attack evidence and deliverables require NDA-level review. Persistent physical response state is not described here as plaintext key storage.

永久資料 · 短暫根金鑰PERMANENT DATA · EPHEMERAL ROOT

保護永久資料,
根金鑰不永久留存
Protect permanent data with
a root key that is not permanent

回到開頭Back to top