Security electronic chip
By introducing multiple biased semiconductor well and well bias current detection circuits into the electronic chip, the chip's defense problem when facing error injection attacks is solved, and effective defense against error injection attacks is achieved.
Patent Information
- Application Number
- CN202010608733.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2015-10-22
- Filing Date
- 2016-04-25
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2036-04-25
AI Technical Summary
Existing electronic chips are difficult to defend effectively when facing error injection attacks, especially when pirates attack the chip through pulsed laser beams or electromagnetic interference that interferes with chip operation.
A safety electronic chip is designed, including multiple bias semiconductor wells and well bias current detection circuits. When the absolute value of the well bias current is detected to be greater than the threshold, the chip will generate an alarm signal and take defensive measures such as destroying confidential data or stopping chip activity.
It effectively prevents error injection attacks and can detect injection power that is much lower than the minimum error injection power, thereby improving the safety of the chip.
Smart Images

Figure CN111783920B_ABST
Abstract
Description
[0001] Related Applications Citations
[0002] This application is a divisional application of the invention patent application with Chinese national application number 201610352606.0, whose application date is April 25, 2016 and priority date is October 22, 2015.
[0003] This application claims the benefit of priority from French Patent Application No. 15 / 60089, filed on October 22, 2015, the entire contents of which are incorporated herein by reference to the maximum extent permitted by law. Technical Field
[0004] The present application relates to an electronic chip, and in particular to an attack-resistant electronic chip. Background Art
[0005] Electronic chips containing confidential data, such as bank card chips, may be attacked by pirates who attempt to determine the operation of the chip and attempt to extract confidential information from it. The attack may be carried out on a working chip connected between power terminals. One way to carry out this attack is for the pirate to scan the surface of the chip with a pulsed laser beam that interferes with the operation of the chip. Observation of the results of this interference, sometimes called an error, enables the pirate to carry out the attack. In order to interfere with the operation of the chip, the pirate also forms contacts on the surface of the chip and applies voltage to it. The pirate also sets a coil near the surface of the chip to emit electromagnetic interference.
[0006] While it would be desirable to have electronic chips that are immune to the type of attack known as fault injection attacks, known devices have various disadvantages and implementation problems. Summary of the invention
[0007] Thus, embodiments provide a secure electronic chip comprising a plurality of biased semiconductor wells and a well bias current detection circuit.
[0008] According to an embodiment, the detection circuit is capable of generating an alarm signal when the absolute value of the bias current is greater than a threshold value.
[0009] According to an embodiment, the detection circuit includes a resistance element that conducts the bias current, and the detection circuit is capable of detecting a voltage across the resistance element.
[0010] According to an embodiment, the resistance element has a resistance in the range of 1 to 100Ω.
[0011] According to an embodiment, the secure electronic chip comprises a power supply capable of providing a potential for biasing the well, the detection circuit capable of detecting a change in the potential regulating the biasing potential.
[0012] According to an embodiment, the power supply circuit includes an operational amplifier whose output is coupled to the gate of a first MOS transistor, and the detection circuit includes a second MOS transistor that forms a current mirror with the first MOS transistor, one input of the operational amplifier and the drain of the first MOS transistor are coupled to the well, and the detection circuit is capable of detecting changes in current in the second transistor.
[0013] According to an embodiment, the plurality of wells include a first well having a first conductivity type and a second well having a second conductivity type, and the detection circuit includes a first circuit for detecting a bias current of the first well on the one hand, and a second circuit for detecting a bias current of the second well on the other hand.
[0014] According to an embodiment, the first well is formed in an upper portion of a semiconductor substrate of the second conductivity type, and the second well is an upper portion of the substrate included between the first wells.
[0015] According to an embodiment, the first well and the second well extend on a doped buried layer of the first conductivity type covering a substrate of the second conductivity type.
[0016] Another embodiment provides a method of protecting an electronic chip including a plurality of biased semiconductor wells, including the step of detecting a well bias current.
[0017] According to an embodiment, the chip contains confidential data, and the method includes the step of destroying the confidential data when the detected bias current is greater than a threshold value.
[0018] According to an embodiment, the method comprises the step of stopping the activity of the chip when the detected bias current is greater than a threshold value.
[0019] The foregoing and other features and advantages will be described in detail in the following non-limiting description of specific embodiments, taken in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 is a simplified partial cross-sectional view of an electronic chip of a first type;
[0021] Figure 2 is a simplified partial cross-sectional view of an electronic chip of a second type;
[0022] Figure 3 An embodiment of a first type of electronic chip that is resistant to attack is shown;
[0023] Figure 4 An embodiment of a second type of electronic chip that is resistant to attack is shown; and
[0024] Figure 5A and 5B Embodiments of power supply and detection circuits are described in detail. DETAILED DESCRIPTION
[0025] In different figures, the same elements are designated with the same reference numerals and, further, the various figures are not drawn to scale. For the sake of clarity, only the elements useful for understanding the described embodiments are shown and described in detail.
[0026] In the following description, when reference is made to terms defining relative positions, such as the term “upper,” the reference is made based on the orientation of the relevant elements in the drawings.
[0027] In this description, the term "connected" refers to a direct electrical connection between two elements, while the term "coupled" refers to an electrical connection between two elements, which may be direct or through one or more other passive or active components, such as resistors, capacitors, inductors, diodes, transistors, etc.
[0028] Figure 1 is a simplified partial cross-sectional view of a first type electronic chip 1, which includes an N-type doped semiconductor well 3 formed on an upper portion of a P-type doped semiconductor substrate 5. For clarity, Figure 1 Only one well and a portion of another well are shown.
[0029] N-channel MOS transistor 6 is formed inside and on the substrate portion between wells 3 and includes gate 7, drain region 9 and source region 11. P-channel MOS transistor 12 is formed inside and on the well 3 and includes gate 13, drain region 15 and source region 17. The transistors are coupled together to form a circuit, such as a digital circuit. As an example, an inverting logic circuit between nodes 19 and 21 is shown. The digital circuit includes power supply nodes 23 and 25. In the example shown, power supply nodes 23 and 25 are coupled to source regions 11 and 17 of transistors 6 and 12, respectively.
[0030] The N-type doped well 3, or N-well, is provided with a bias contact 27, and the substrate is provided with a bias contact 29. The transistor and the bias contact are separated by an insulating trench 31.
[0031] A reference potential GND such as ground is applied to the power supply node 23 and the bias contact 29 of the P-well. A power supply circuit included in the chip, which is not shown, provides a potential VDD applied to the power supply node 25 and the bias contact 27 of the N-well.
[0032] In the following description, in the first type of electronic chip, the upper portion of the substrate (denoted by reference numeral 33) contained between N-wells will be referred to as P-well.
[0033] Figure 2is a simplified partial cross-sectional view of an electronic chip 40 of the second type comprising a well 3 and a P-well 33 extending on an N-type doped buried layer 42 covering a P-type substrate 5 .
[0034] Well 3 and Pwell 33 correspond to the well 3 and Pwell 33 of the aforementioned chip 1, ie they comprise bias contacts 27 and 29 and digital circuits consisting of transistors 6, 12 formed inside and above the wells. The digital circuits have power supply nodes 23 and 25.
[0035] The digital circuits are powered between ground GND and potential VDD respectively applied to supply nodes 23 and 25. Bias potentials VPW and VNW, which may be different from potentials GND and VDD, are applied to bias contacts 29 and 27 respectively and are provided by a not shown power supply circuit comprised in the chip.
[0036] As pointed out in the introduction, a pirate can perform error injection analysis on circuits containing confidential data. A model for detecting such attacks is described below.
[0037] Figure 3 An embodiment of an electronic chip 50 of a first type that is resistant to attack is shown. Figure 3 Included is a partial cross-sectional view of chip 50 and a diagram of circuits included in the chip.
[0038] Chip 50 includes contact Figure 1 The components of the chip 1 are described, in particular the well 3 and the P-well 33. The circuit, for example a digital circuit, comprises a transistor 6 formed in and on the P-well 33 and a transistor 12 formed in and on the well 3. The digital circuit has power supply nodes 23 and 25, and the well 3 and the P-well 33 have respective bias contacts 27 and 29. The bias contacts and the transistors are separated by an insulating trench 31.
[0039] The power supply node 23 of the circuit is coupled to ground. Further, the chip 50 comprises a power supply circuit 52 (VDD) which provides a potential VDD applied to the power supply node 25. The power supply circuit 52 itself is powered by a positive potential VCC and a ground potential GND provided by a power supply external to the chip 50, not shown.
[0040] The bias contact 29 of the P well is not directly grounded, but is coupled to the ground through a resistor element 54 included in the chip. The voltage across the resistor element 54 is compared with a threshold by a comparator circuit 56, and the comparator circuit 56 can generate an alarm signal AP when the voltage is greater than the threshold. Thus, the resistor element 54 and the comparator circuit 56 constitute a circuit 57 for detecting the bias current of the P well 33.
[0041] The bias contact 27 of the N well is coupled to the power supply circuit 52 through the resistor element 58. The voltage across the resistor element 58 is compared with a threshold by the comparator circuit 60, and the comparator circuit 60 can generate an alarm signal AN when the voltage is greater than the threshold. Thus, the resistor element 58 and the comparator circuit 60 constitute a circuit 61 for detecting the bias current of the well 3.
[0042] In normal operation, the junction between the N-well and the substrate is reverse biased and no effective bias current flows through the resistor elements 54 and 58. The above threshold can thus be very low.
[0043] During an attempted error injection attack on the chip, for example, when a pirate bombards the chip with a laser beam, currents I1N and I1P appear between bias contact 27 of well 3 and bias contact 29 of P well 33. Bias currents I1N and I1P are detected by detection circuit 57 or 61 and trigger the transmission of alarm signal AN or AP. This signal is used by the chip to take countermeasures, such as suspending or stopping its action or destroying the confidential data it contains.
[0044] During an attack attempted by a pirate, the chip analyzes the currents I1P and I1N caused by the interference with the chip operation to detect the attack. The bias currents I1N and I1P used to directly detect the attack correspond to the currents caused by the interference. Therefore, the chip can detect an injection power far below the minimum error injection power. Thus, the chip 1 can advantageously prevent any error injection attack, regardless of the location of the attack on the chip surface.
[0045] As an example, the resistance elements 54 and 58 may be in the range of 1 to 100 Ω. As a variant, the resistance elements 54 and 58 may be elements or parts of the chip capable of generating a voltage when conducting a current, for example well parts.
[0046] Figure 4 An embodiment of an electronic chip 70 of a second type that is resistant to attack is shown. Figure 4 The schematic includes a partial cross-sectional view of a chip 70 and an illustration of circuits included within the chip.
[0047] Chip 70 includes contact Figure 2 The components of the chip 40 are in particular the well 3 and the P well 33 extending on the N-type doped buried layer 42 covering the P-type doped substrate 5. The circuits formed inside and above the wells, such as digital circuits, have power supply nodes 23 and 25. The well 3 has a bias contact 27 and the P well 33 has a bias contact 29.
[0048] The power supply node 23 of the digital circuit is coupled to ground. Further, the chip 70 includes a power supply circuit 52 that provides a potential VDD applied to the power supply node 25.
[0049] The bias contact 29 of the P-well is coupled to a power supply circuit 72 which generates a potential VPW. The power supply circuit 72 includes a circuit 73 (DETP) for detecting the bias current supplied to the P-well. The detection circuit 73 is capable of generating a signal AP when the absolute value of the bias current is greater than a threshold value.
[0050] The bias contact 27 of the Nwell is coupled to a power supply circuit 74 generating a potential VNW. The power supply circuit 74 comprises a circuit 75 (DETN) for detecting the bias current supplied to the Nwell. The detection circuit 75 is capable of generating a signal AN when the absolute value of the bias current is greater than a threshold value.
[0051] The power supply circuits 52, 72 and 74 are powered between potentials VCC and GND provided by a power supply device not shown outside the chip.
[0052] In the case of a fault injection attack, the detection of chip 70 is similar to Figure 3 Detection of chip 50. The bias current I1 detected by the chip is separated from the power supply current I2 of normal chip operation. In an embodiment of chip 70, the bias potentials VNW and VPW may be different from the power supply potentials VDD and GND, for example to speed up the chip operation, or to reduce its power consumption.
[0053] Figure 5A An embodiment of a power supply circuit 74 coupled to the bias contact 27 of the N-well is shown in detail. The power supply circuit 74 comprises an operational amplifier 80 whose output is coupled to the gate G1 of the P-channel MOS transistor PM1. Two series-connected resistors R1 and R2 couple the drain D1 of the transistor PM1 to ground, and the common node between the resistors is coupled to the positive input of the amplifier 80. The regulated potential V0 is applied to the negative input of the amplifier 80. The amplifier 80 is powered between the ground GND and a node to which the potential VCC is applied, the potential VCC being provided by an external power supply device. The source S1 of the transistor PM1 is coupled to the potential VCC. The bias contact 27 is coupled to the drain D1.
[0054] The detection circuit 75 of the power supply circuit 74 includes two P-channel MOS transistors PM2 and PM3, which form a current mirror with the transistor PM1, that is, their gates G2 and G3 are coupled to the gate G1, and their sources D2 and D3 are coupled to the source S1. The drain D2 of the transistor PM2 is coupled to the ground through a current source that samples the current I3+ from the drain D2. The drain D3 of the transistor PM3 is coupled to the ground through a current source that samples the current I3- from the drain D3, and the current I3- is less than the current I3+. The inverter 82 couples the drain D3 to the input of the OR gate 84, and the other input of the OR gate 84 is coupled to the drain D2. The action of the output of the gate 84 generates the signal AN.
[0055] When circuit 74 operates, current I3 flows through resistors R1 and R2, current I3 being selected to be between currents I3+ and I3-. This current is added to bias current I1 in transistor PM1, and current I5, which is equal to I1+I3, flows through each of transistors PM2 and PM3.
[0056] During normal operation, current I5 is between currents I3- and I3+, and output AN is disabled.
[0057] In the case of an attempted attack, as long as the current I5 exceeds the interval of I3- to I3+, the potential of the drain D2 increases or the potential of the drain D3 decreases, and the output AN is activated. In other words, the appearance of the current I1 causes a change in the potential provided by the amplifier 80, and the amplifier 80 adjusts the voltage provided by the power supply circuit 74, and the detection circuit 75 detects the change to detect the current I1. As a variation, the detection circuit 75 can also be replaced by any circuit that can detect the change in the regulated potential of the power supply circuit.
[0058] The difference between currents I3 and I3- corresponds to a threshold for detecting current I1 originating from bias contact 27, and the difference between currents I3 and I3+ corresponds to a threshold for detecting current I1 flowing toward bias contact 27. As an example, the detection threshold is in the range of 0.2 to 2 mA.
[0059] Figure 5B An embodiment of a power supply circuit 72 coupled to the bias contact 29 of the N-well is shown in detail.
[0060] The power supply circuit 72 corresponds to Figure 5A The power supply circuit 74 is shown in FIG. 8 , wherein the resistors R1 and R2 are replaced by series resistors R3 and R4 that couple the drain D1 to the power supply circuit 86, and the common node between the resistors R3 and R4 is coupled to the positive input of the amplifier 80. As an example, the detection circuits 73 and 75 are similar.
[0061] The power supply circuit 86 provides a potential lower than the ground potential based on the potential VCC and the ground potential. The circuit 86 may be a charge pump synchronized by a clock (CLK). As a variant, the detection circuit 73 may be replaced by a detection circuit capable of detecting changes in the regulation potential of the circuit 86.
[0062] Specific embodiments have been described. Various changes, modifications and improvements will readily occur to those skilled in the art. In particular, although in the described embodiments, the bias current of the P well 33 and the bias current of the well 3 are monitored simultaneously by two detection circuits, a variation in which the bias current of a well of a single conductivity type is monitored by a single detection circuit is also possible.
[0063] Further, although in the described embodiment the security chip comprises digital circuits including MOS transistors 6 and 12, the same protected chip may also include analog circuits, for example, analog circuits including elements such as bipolar transistors, resistors or diodes, the key being that the chip includes a bias well.
[0064] Furthermore, although in the described embodiment a P-type doped substrate 5 is provided, variations are possible in which the substrate 5 is replaced by an N-type doped substrate, or by a support of a silicon-on-insulator structure type or by a support made of another semiconductor.
[0065] Further, although a specific detection circuit has been described in detail in the embodiments, other detection circuits capable of detecting a bias current are possible.
[0066] Various embodiments with different variations have been described above. It should be noted that those skilled in the art may combine various elements of these various embodiments and variations thereof without inventive effort. In particular, each of the detection circuits 73 and 75 of the embodiment of the second type of security chip may replace one or the other of the detection circuits 57 and 61 of the embodiment of the first type of security chip.
[0067] Furthermore, embodiments have been described which are suitable for integrated circuits of the first and second types. What has been described can of course also be applied to other types of integrated circuit technologies, including various types of wells.
[0068] These changes, modifications and improvements are intended to be part of this disclosure and are intended to be within the spirit and scope of the present invention. Therefore, the foregoing description is for illustrative purposes only and is not intended to be limiting. The present invention is limited only by the following claims and their equivalents.
Claims
1. An electronic device, comprising: Semiconductor substrate; A first well of a first conductivity type is formed in the substrate, a transistor formed in the first well; a bias contact contacting the first well and electrically isolated from the transistor; as well as A well bias current detection circuit is electrically coupled to the bias contact and is configured to detect a first bias current in the first well, the first bias current indicating an effort to tamper with the electronic device. 2 . The electronic device according to claim 1 , wherein the detection circuit is configured to generate an alarm signal when an absolute value of the first bias current is greater than a threshold value.
3. The electronic device according to claim 1, wherein the detection circuit comprises: a resistive element configured to conduct the first bias current; as well as A comparator is configured to detect a voltage across the resistance element.
4. The electronic device according to claim 1, comprising a power supply circuit configured to bias the first well with a bias potential, the detection circuit configured to detect the first bias current by detecting a change in a potential that adjusts the bias potential.
5. The electronic device according to claim 4, wherein the power supply circuit comprises: Operational amplifier, which has input and output; as well as a first MOS transistor having a gate coupled to the output of the operational amplifier and a drain coupled to the input of the operational amplifier and to the first well, and wherein the detection circuit comprises a second MOS transistor, the second MOS transistor forming a current mirror with the first MOS transistor, and the detection circuit is configured to detect a change in current in the second MOS transistor.
6. The electronic device according to claim 1 further includes a second well of a second conductivity type formed in the substrate, and the detection circuit includes a first circuit and a second circuit, the first circuit is configured to detect the first bias current of the first well, and the second circuit is configured to detect the second bias current of the second well. 7 . The electronic device according to claim 6 , wherein the first well is one well among a plurality of first wells of the first conductivity type formed in an upper portion of the substrate, and the second well is a portion of the substrate between the first wells.
8. The electronic device according to claim 6, wherein the substrate is of the second conductivity type, further comprising: A doped buried layer of the first conductivity type covers the substrate, wherein the first well and the second well extend on the doped buried layer.
9. A secure electronic chip, comprising: a substrate of a first conductivity type; as well as a doped buried layer of a second conductivity type covering the substrate, a plurality of semiconductor wells formed on the doped buried layer, wherein the plurality of semiconductor wells include a first well of the first conductivity type and a second well of the second conductivity type; a well bias current detection circuit configured to detect bias currents in the plurality of semiconductor wells; as well as The power supply circuit is configured to provide a bias potential for biasing the well, and the detection circuit is configured to detect a change in a potential for adjusting the bias potential.
10. The electronic chip according to claim 9, wherein the power supply circuit comprises: Operational amplifier, which has input and output; as well as a first MOS transistor having a gate coupled to the output of the operational amplifier and a drain coupled to the input of the operational amplifier and to at least one of the wells, and wherein the detection circuit comprises a second MOS transistor, the second MOS transistor forming a current mirror with the first MOS transistor, and the detection circuit is configured to detect a change in current in the second MOS transistor. 11 . The electronic chip according to claim 9 , wherein the detection circuit comprises a first circuit and a second circuit, the first circuit being configured to detect a bias current of the first well, and the second circuit being configured to detect a bias current of the second well.
Citation Information
Patent Citations
Semiconductor integrated circuit device with body bias circuit
CN1476092A
Integrated circuit testing methods using trap bias modification
CN1742209A