An integrated circuit supply chain site security analysis method and device
By obtaining the evaluation elements and mapping relationships, extracting the control flow diagram of the integrated circuit supply chain site and retrieving threat analysis data, the problem of safety analysis of the integrated circuit supply chain site is solved, and fast and accurate safety assessment and control suggestions are achieved.
Patent Information
- Application Number
- CN202010940025.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-09-09
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2040-09-09
AI Technical Summary
It is difficult for the prior art to quickly analyze the fragility points and safety precautions in integrated circuit supply chain sites, affecting the security and continuity of critical information infrastructure.
By obtaining evaluation elements, the control flow diagram of the integrated circuit supply chain site service is extracted from the control flowchart database based on the preset mapping relationship, and the threat analysis data corresponding to the asset elements are retrieved, and data reports are generated to provide security analysis and evaluation.
Automatic safety analysis of integrated circuit supply chain sites is realized, rationalized suggestions for safety control are provided, and the efficiency and accuracy of evaluation are improved.
Smart Images

Figure CN112036765B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data analysis, and particularly relates to a method and device for analyzing the security of an integrated circuit supply chain site. Background Art
[0002] With the promulgation and implementation of the "Cybersecurity Law" and the "Measures for Cybersecurity Review", as the basic hardware constituting critical information infrastructure, the security of the integrated circuit supply chain can have an important impact on the security and continuity of critical information infrastructure services. How to quickly analyze the vulnerabilities and security precautions in the supply chain site according to the business characteristics of the integrated circuit supply chain, so as to give an evaluation method for the security analysis and evaluation of the integrated circuit site to the evaluator, and give reasonable suggestions for security control for the integrated circuit production process has become a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a method and device for analyzing the security of an integrated circuit supply chain site to realize the automatic analysis of the security of the production process of the integrated circuit supply chain site.
[0004] To achieve the above object, embodiments of the present invention provide the following technical solutions:
[0005] A method for analyzing the security of an integrated circuit supply chain site includes:
[0006] Obtaining evaluation elements, where the evaluation elements include: service type elements, site entity elements, process elements, and process flow elements;
[0007] Based on a preset mapping relationship, extracting from a control flow chart database a control flow chart of an integrated circuit supply chain site service adapted to the evaluation elements, where the preset mapping relationship stores a mapping relationship between the evaluation elements and the control flow chart of the integrated circuit supply chain site service;
[0008] Extracting asset elements included in the control flow chart of the integrated circuit supply chain site service;
[0009] Retrieving preset threat analysis data corresponding to the asset elements from a preset database.
[0010] Optionally, in the above method for analyzing the security of an integrated circuit supply chain site, it further includes:
[0011] Generating and outputting a data report based on the asset elements and a data report of the preset threat analysis data corresponding to the asset elements.
[0012] Optionally, in the above-mentioned integrated circuit supply chain site security analysis method, the control flow diagram of the integrated circuit supply chain site service adapted to the evaluation elements extracted from the control flow diagram database based on the preset mapping relationship includes:
[0013] Based on the preset mapping relationship, as well as the site entity elements, process elements, and process flow elements, the control flow diagram of the integrated circuit supply chain site service that matches each service type included in the service type element is extracted from the control flow diagram database.
[0014] Optionally, in the above-mentioned integrated circuit supply chain site security analysis method, the service type element includes: mask production, wafer production, and middle testing.
[0015] An integrated circuit supply chain site security analysis device includes:
[0016] A data acquisition unit for obtaining evaluation elements, where the evaluation elements include: service type elements, site entity elements, process elements, and process flow elements;
[0017] A control flow diagram retrieval unit extracts the control flow diagram of the integrated circuit supply chain site service adapted to the evaluation elements from the control flow diagram database based on the preset mapping relationship. The preset mapping relationship stores the mapping relationship between the evaluation elements and the control flow diagram of the integrated circuit supply chain site service;
[0018] A threat analysis unit for extracting the asset elements included in the control flow diagram of the integrated circuit supply chain site service; retrieving the preset threat analysis data corresponding to the asset elements from the preset database.
[0019] Optionally, the above-mentioned integrated circuit supply chain site security analysis device further includes:
[0020] A report generation unit for generating and outputting a data report based on the asset elements and the preset threat analysis data corresponding to the asset elements.
[0021] Optionally, when the control flow diagram retrieval unit extracts the control flow diagram of the integrated circuit supply chain site service adapted to the evaluation elements from the control flow diagram database based on the preset mapping relationship, it specifically is used for:
[0022] Based on the preset mapping relationship, as well as the site entity elements, process elements, and process flow elements, the control flow diagram of the integrated circuit supply chain site service that matches each service type included in the service type element is extracted from the control flow diagram database.
[0023] Optionally, in the above integrated circuit supply chain site security analysis device, the service type elements include: mask production, wafer production, and intermediate testing.
[0024] Based on the above technical solution, the above solution provided by the embodiment of the present invention can, based on a pre-established mapping relationship, retrieve a control flow diagram of the integrated circuit supply chain site service that matches the obtained evaluation elements, and then extract the asset elements included in the control flow diagram of the integrated circuit supply chain site service, determine the service type corresponding to the asset site based on the control flow diagram, and retrieve threat analysis data that matches the asset elements and their service types based on the preset mapping relationship, thereby providing an analysis and evaluation method for the integrated circuit supply chain site evaluation and giving reasonable suggestions for the security control of the integrated circuit production process. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.
[0026] Figure 1 It is a schematic flowchart of the integrated circuit supply chain site security analysis method disclosed in the embodiment of the present application;
[0027] Figure 2 It is a control flow diagram of the integrated circuit supply chain site service corresponding to mask production;
[0028] Figure 3 It is a control flow diagram of the integrated circuit supply chain site service corresponding to wafer production and intermediate testing;
[0029] Figure 4 It is a schematic structural diagram of the integrated circuit supply chain site security analysis method disclosed in the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0031] In the present application, an integrated circuit supply chain site security analysis method capable of providing security risk analysis according to the production process is provided. Refer to Figure 1 , the method may include:
[0032] Step S101: Obtain evaluation factors, where the evaluation factors include: service type factors, venue entity factors, process factors, and process flow factors;
[0033] In the process of implementing the technical solution disclosed in the embodiments of the present application, it is first necessary to input evaluation factors. The evaluation factors include service type (S), venue entity (E), process (P), asset (A), and process flow (F). The specific definitions of each evaluation factor are as follows:
[0034] Service type (S): Refers to the service type of the integrated circuit supply chain venue, including S1: mask production, S2: wafer production, and S3: chip test. Of course, the integrated circuit supply chain venue may also include packaging and final test. Among them, there is less sensitive data involved in the packaging link, and its security analysis can directly draw on the security analysis results of the wafer production link. The final test is similar to the chip test, except that the test object is a single packaged wafer, and its security analysis can directly draw on the security analysis results of the chip test link.
[0035] Venue entity (E): The venue entity (E) includes the entire set of venue entities, and different venue entities correspond to different service types provided by the venue, that is, E1: design line, E2: production line, E3: laboratory, E4: test line, E5: production line warehouse, E6: scrap warehouse.
[0036] Process (P): The process (P) includes the entire set of processes, and different processes correspond to different venue entities, that is, P1: data conversion, P2: production, P3: measurement, P4: failure analysis, P5: reliability test, P6: chip test, P7: warehousing, P8: outbound, P9: scrapping.
[0037] Asset (A): Assets are classified into physical assets A1 and data assets A2 according to their forms. A1 includes mask A1-1 and wafer A1-2; A2 includes design-related data A2-1, production-related data A2-2, and test-related data A2-3.
[0038] Process flow (F): It is divided into service process F1 and delivery process F2.
[0039] In this step, only a part of the evaluation elements can be input by the user, and the other part of the evaluation elements can be directly generated based on the input evaluation elements. For example, in this solution, the service type (S) and the venue entity (E) in the evaluation elements are input by the user, while the process (P), asset (A), and process flow (F) are retrieved based on the mapping relationship in the preset mapping list based on the service type (S) and the venue entity (E).
[0040] Step S102: Extract the control flow diagram of the integrated circuit supply chain venue service adapted to the evaluation elements from the control flow diagram database based on the preset mapping relationship;
[0041] In this step, after obtaining the evaluation elements, the control flow diagram of the integrated circuit supply chain venue service can be derived based on the evaluation elements. Before instructing this solution, the mapping relationship between the evaluation elements and the control flow diagram of the integrated circuit supply chain venue service can be established in advance and stored in the preset database. After determining the evaluation elements, the database can be searched based on the evaluation elements to obtain the corresponding control flow diagram of the integrated circuit supply chain venue service.
[0042] In this flow chart, in order to facilitate the user to distinguish the types of each evaluation element in the flow chart, different graphics can be used to represent different evaluation elements. For example, a rectangle can be used to represent the venue entity, an ellipse can be used to represent the process, parallel lines can be used to represent the asset, a dotted arrow line can be used to represent the service process, and an arrow line can be used to represent the delivery process;
[0043] The preset mapping relationship stores the mapping relationship between the evaluation elements and the control flow diagram of the integrated circuit supply chain venue service;
[0044] Step S103: Extract the asset elements included in the control flow diagram of the integrated circuit supply chain venue service;
[0045] In the technical solution disclosed in the embodiments of the present application, the security analysis is all based on the assets, that is, the analysis report is generated based on each asset in the control flow diagram of the integrated circuit supply chain venue service. Therefore, before the analysis, it is necessary to extract the included asset data from the control flow diagram of the integrated circuit supply chain venue service in advance;
[0046] Step S104: Retrieve the preset threat analysis data corresponding to the asset elements from the preset database;
[0047] In this step, based on the control flow diagram of the integrated circuit supply chain site service, determine the service type corresponding to each asset. Based on each asset data and the service type to which each asset data belongs, retrieve the preset threat analysis data that matches the asset and its service type, and output the threat analysis data as a result.
[0048] In this solution, based on the pre-established mapping relationship, the control flow diagram of the integrated circuit supply chain site service that matches the obtained evaluation elements can be retrieved. Then, extract the asset elements included in the control flow diagram of the integrated circuit supply chain site service, determine the service type corresponding to the asset site based on the control flow diagram, and retrieve the threat analysis data that matches the asset element and its service type based on the preset mapping relationship, so as to provide an analysis and evaluation method for the integrated circuit supply chain site evaluation and give reasonable suggestions for the safety control of the integrated circuit production process.
[0049] In the technical solution disclosed in the embodiment of the present application, the service type elements may include: mask production, wafer production, and middle test. Each element corresponds to a control flow diagram of the integrated circuit supply chain site service. That is, in the above solution, when the service type (S) and the site entity (E) are determined, the control flow diagram of the integrated circuit supply chain site service corresponding to each service type will be obtained based on the preset logical relationship. The preset logical relationship is the logical relationship between the service type (S), the site entity (E), the process (P), the asset (A), and the process (F) obtained based on the integrated circuit manufacturing process planning. For example, see Figure 2 and Figure 3 , Figure 2 is the control flow diagram of the integrated circuit supply chain site service corresponding to mask production, Figure 3 is the control flow diagram of the integrated circuit supply chain site service corresponding to wafer production and middle test.
[0050] In the technical solution disclosed in the above embodiment of the present application, after obtaining the threat analysis data, for the convenience of users to view, a data report can also be generated and output based on the asset element and the data report of the preset threat analysis data corresponding to the asset element. Among them, the type of this report can be designed by itself according to the user's needs. For example, in Table 1, it is the threat analysis result for the Figure 2 , Figure 3 , Figure 4 control flow chart. See Table 1. The form of this table can be:
[0051] Table 1
[0052]
[0053]
[0054]
[0055] In this embodiment, corresponding to the above method, an integrated circuit supply chain site security analysis device is also disclosed. For the specific working content of each unit in the device, please refer to the content of the above method embodiment.
[0056] The integrated circuit supply chain site security analysis device provided by the embodiments of the present invention will be described below. The integrated circuit supply chain site security analysis device described below can be mutually corresponding and referred to the integrated circuit supply chain site security analysis method described above.
[0057] See Figure 4 , the integrated circuit supply chain site security analysis device may include
[0058] A data acquisition unit 100, configured to obtain evaluation elements, where the evaluation elements include: service type elements, site entity elements, process elements, and process flow elements;
[0059] A control flow diagram retrieval unit 200, configured to extract a control flow diagram of an integrated circuit supply chain site service adapted to the evaluation elements from a control flow diagram database based on a preset mapping relationship, where the preset mapping relationship stores a mapping relationship between the evaluation elements and the control flow diagram of the integrated circuit supply chain site service;
[0060] A threat analysis unit 300, configured to extract asset elements included in the control flow diagram of the integrated circuit supply chain site service; and retrieve preset threat analysis data corresponding to the asset elements from a preset database.
[0061] Corresponding to the above method, the integrated circuit supply chain site security analysis device further includes:
[0062] A report generation unit, configured to generate and output a data report based on the asset elements and the preset threat analysis data corresponding to the asset elements.
[0063] Corresponding to the above method, when the control flow diagram retrieval unit extracts a control flow diagram of an integrated circuit supply chain site service adapted to the evaluation elements from a control flow diagram database based on a preset mapping relationship, it is specifically configured to:
[0064] Based on the preset mapping relationship, site entity elements, process elements, and process flow elements, extract a control flow diagram of an integrated circuit supply chain site service that matches each service type included in the service type elements from the control flow diagram database.
[0065] Corresponding to the above method, the service type elements include: mask production, wafer production, and middle test.
[0066] For the convenience of description, when describing the above system, it is divided into various modules according to functions and described separately. Of course, when implementing the present invention, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0067] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system or system embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0068] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0069] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0070] It should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0071] The foregoing description of the disclosed embodiments enables those skilled in the art to practice or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for analyzing the security of an integrated circuit supply chain site, characterized in that, Including: Obtain evaluation elements, where the evaluation elements include: service type elements, venue entity elements, process elements, and process flow elements; Based on a preset mapping relationship, extract from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches the evaluation elements. The preset mapping relationship stores the mapping relationship between the evaluation elements and the control flow chart of the integrated circuit supply chain venue service; Extract the asset elements included in the control flow chart of the integrated circuit supply chain venue service; Retrieve from a preset database the preset threat analysis data corresponding to the asset elements.
2. The method for analyzing the security of an integrated circuit supply chain site according to claim 1, wherein, Also including: Generate and output a data report based on the asset elements and the data report of the preset threat analysis data corresponding to the asset elements.
3. The method for analyzing the security of an integrated circuit supply chain site according to claim 1, wherein The step of extracting from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches the evaluation elements based on a preset mapping relationship includes: Based on the preset mapping relationship, venue entity elements, process elements, and process flow elements, extract from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches each service type included in the service type elements.
4. The method for analyzing the security of an integrated circuit supply chain site according to claim 3, characterized in that, The service type elements include: mask production, wafer production, and middle testing.
5. An integrated circuit supply chain site security analysis device, characterized in that, Including: A data acquisition unit for obtaining evaluation elements, where the evaluation elements include: service type elements, venue entity elements, process elements, and process flow elements; A control flow chart retrieval unit that, based on a preset mapping relationship, extracts from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches the evaluation elements. The preset mapping relationship stores the mapping relationship between the evaluation elements and the control flow chart of the integrated circuit supply chain venue service; A threat analysis unit for extracting the asset elements included in the control flow chart of the integrated circuit supply chain venue service; retrieving from a preset database the preset threat analysis data corresponding to the asset elements.
6. The integrated circuit supply chain site security analysis device according to claim 5, wherein, Also including: A report generation unit for generating and outputting a data report based on the asset elements and the data report of the preset threat analysis data corresponding to the asset elements.
7. The integrated circuit supply chain site security analysis device according to claim 5, wherein, When the control flow chart retrieval unit extracts from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches the evaluation elements based on a preset mapping relationship, it specifically is used for: Based on the preset mapping relationship, venue entity elements, process elements, and process flow elements, extract from the control flow chart database the control flow chart of the integrated circuit supply chain venue service that matches each service type included in the service type elements.
8. The integrated circuit supply chain site security analysis device according to claim 7, characterized in that The service type elements include: mask production, wafer production, and middle testing.
Citation Information
Patent Citations
Software supply chain security analysis method and device
CN110414239A
Method and system for evaluating the analysis of therisks based on business process
KR1020050006554A