Protection of an integrated circuit chip in a wire-bonded ball grid array package

By introducing and routing through protection tracks in the integrated circuit substrate landing area of ​​wire bonded BGA packages, the problem of physical and electromagnetic attacks on integrated circuit chips is solved, achieving higher security and protection effects.

CN112913004BActive Publication Date: 2025-06-17NAGRAVISION SA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201980069250.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-10-26
Filing Date
2019-10-17
Publication Date
2025-06-17
Estimated Expiration
2039-10-17

AI Technical Summary

Technical Problem

The prior art is difficult to effectively prevent physical and electromagnetic attacks on integrated circuit chips, especially in wire bonded BGA packages, where attackers can approach the chip via local electromagnetic side channels or target laser failure attacks.

Method used

The operation of the integrated circuit is prevented by introducing a protection track in the substrate landing area of ​​the integrated circuit and routing it through the landing area of ​​the substrate. These protection tracks are not ground or power tracks, but signal tracks used to detect and prevent attacks.

Benefits of technology

It effectively prevents attackers from approaching integrated circuits through physical or electromagnetic means, enhances the security of the chip, and prevents attackers from disabling the chip's function by changing the protection track.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112913004B_ABST
    Figure CN112913004B_ABST
Patent Text Reader

Abstract

This application is directed to protecting an integrated circuit encapsulated in a package in the form of a wire-bonded ball grid array, and particularly to preventing an attack through the substrate of the package directly under the integrated circuit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an integrated circuit chip that prevents physical and / or electrical alteration, and more particularly to protecting an integrated circuit encapsulated in a package in the form of a wire-bonded ball grid array. Background Art

[0002] Integrated circuit (IC) chips are often subject to physical attacks, such as real-time hardware analysis, aimed at obtaining knowledge about the internal functions of the chip, thereby affecting the operation of the chip.

[0003] During such attacks, the plastic housing that protects the chip from mechanical damage can be opened on its top surface to expose the passivation layer covering the electronic circuit.

[0004] The passivation layer can be selectively removed by using an etching method with a mechanical polishing machine or chemical means to allow access to the signal lines.

[0005] Real-time hardware analysis techniques can perform analysis on an integrated circuit chip during its operation, while other techniques (such as reverse engineering) aimed at analyzing and reconstructing the chip operation usually result in chip damage.

[0006] Attack techniques have also been developed using fault injection. In fault injection, a local energy source, such as a laser, can be used to alter the behavior of the integrated circuit.

[0007] Similarly, attack techniques are known that allow the use of precise probes to perform local side-channel analysis to measure the electromagnetic radiation from inside the integrated circuit.

[0008] These techniques or combinations thereof can be used to extract secrets stored within the integrated circuit chip.

[0009] Analysis of integrated circuit chips is generally undesirable. If possible, real-time hardware analysis should be prevented, especially in the case of security circuits (such as microprocessors with electronic wallet functions, etc.). In fact, various methods already exist to make such analysis more difficult.

[0010] All or part of the chip can be protected from physical attacks through so-called active or passive shielding.

[0011] Passive shielding includes a metal plane or track connected to a circuit configured to perform analog integrity measurements to detect, for example, cuts, short circuits, or changes in capacitive loads. In active shielding, there can be multiple tracks where a random bit sequence is injected and the consistency from one end of the track to the other is checked.

[0012] Integrated circuit chips are provided in various different package types, which allow connections from the integrated circuit chip to the outside world via electrical connection portions provided outside the package. These connection portions can be, for example, pins, pads or solder balls.

[0013] One known type of package is the ball grid array (BGA) package. In a BGA, a plurality of solder balls are provided on one surface of the package to provide connections from the integrated circuit chip to the outside world.

[0014] For simplicity, the surface of the package having the solder balls will hereinafter be referred to as the bottom surface of the package.

[0015] Inside the BGA package, connections are made to the integrated circuit. Depending on the connection method, the BGA package is regarded as a wirebond BGA or a flip chip BGA.

[0016] This application is directed to wirebond BGA packages. As can be seen from Figure 1 the exemplary cross-section, in a wirebond BGA package 1, an integrated circuit 2 is mounted on a substrate 8.

[0017] The integrated circuit is disposed on a landing area 22, which is an area on the surface of the integrated circuit. The area of the substrate defined by the outline of the landing area can be referred to as the landing area region. The landing area region is typically but not always the landing area region of the substrate. The landing area can have metal pedestal pads 12 to which the integrated circuit can be mounted using an adhesive. The metal pedestal pads can form part of a ground plane or there can be a separate layer providing a ground plane in the landing area region.

[0018] Solder ball connections 10 are provided on the bottom surface of the package for external connections from the package. Wirebonds 4 connect the integrated circuit to pads 16 on the top surface of the substrate. The pads 16 are arranged in a peripheral area of the substrate surrounding the landing area region. The pads are in turn connected to tracks on the underside via tracks and interconnects 15, and the tracks are in turn connected to pads via separate solder balls. As can be seen from Figure 2 the solder balls (as well as the corresponding tracks, interconnects and pads) providing signal connections are preferably located in a peripheral area 28 surrounding the landing area region 22 of the substrate, in which the die is located.

[0019] To facilitate more complex and denser connections, the substrate can have a plurality of layers 18 (shown as dashed lines) that provide tracks to facilitate the connection between wirebonds on the top surface and the solder balls below.

[0020] Conventionally, an integrated circuit is provided with a plastic molded housing 6 to provide mechanical protection. To assist heat transfer from the integrated circuit, thermal vias 14 may be provided to transfer heat through the substrate. These thermal vias may also provide electrical connection portions between the ground plane and the underside of the substrate. These thermal vias are typically positioned around the landing zones to ensure heat transfer from the metal pads 12 located beneath the die.

[0021] In some configurations, solder balls are not provided in the landing zone region 22 of the substrate beneath the integrated circuit. In other configurations, solder balls are provided in the landing zone region. Where solder balls are provided in the landing zone region, they are typically ground connections. At the same time, power connections may extend from the corners of the landing zone region together and may be commonly connected to a power plane.

[0022] The metal base pad may be a ground plane, or there may be a separate ground plane beneath the metal base pad 12. Similarly, one or more power planes may be provided on other layers of the substrate. It should be understood that a ground or power plane is generally a region of conductive material that is substantially continuous in a layer, and the region extends to cover the landing zone region. A ground or power plane is generally desirable to improve power transfer and reduce problems such as noise.

[0023] This application aims to improve the security of integrated circuit chips encapsulated as wire-bonded BGAs. Summary of the Invention

[0024] This application is directed against preventing attacks that have not previously been determined to be possible.

[0025] In particular, it has been determined that local electromagnetic side-channel or targeted laser fault attacks as described above can be employed against BGA packages, and these attacks require close proximity to the integrated surface.

[0026] In this regard, for both of these techniques directed against the IC substrate, it is preferred because, in combination with thinning, it allows access to the transistors therein without the shielding effect (electromagnetic or physical) of the IC metal layers for routing signals and supplying power.

[0027] In the case of flip-chip packaging, the substrate can be used directly.

[0028] In the case of wire-bonded BGA packaging, it is believed that the substrate can provide protection. However, it has now been realized that the conventional method of effectively routing signals within a BGA package (including grouping of power and ground connections) introduces a vulnerability.

[0029] In particular, even when using Figure 3In the case where the milling step 30 shown removes most of the power domain (ground and power voltage) routing, a large area of the substrate can also be kept accessible. The opening through the landing area region provided by such a milling step allows access to a large cross-section of the substrate of the integrated circuit.

[0030] Accordingly, the present application provides a counter-intuitive method that defies conventional wisdom and intentionally seeks to provide protection tracks in the landing area region, which are necessary for the correct operation of the integrated circuit and whose disconnection will render the integrated circuit chip inoperable. Appropriately, these protection tracks are neither ground tracks nor power tracks, but signal tracks for providing signals to or from the integrated circuit.

[0031] Accordingly, the present application provides an integrated circuit chip in a wire-bonded ball grid array package, wherein critical connections other than power or ground are routed through the substrate of the package under the integrated circuit.

[0032] More specifically, according to a first embodiment, there is provided a chip according to claim 1 and a method according to claim 10 for protecting the chip against attacks.

[0033] Accordingly, the first embodiment provides a chip that includes a substrate having a first surface and a second surface opposite the first surface. An integrated circuit is mounted on a landing area of the first surface of the substrate, and the landing area defines a landing area region of the substrate. A plurality of contacts are provided at least on the first surface of a peripheral area surrounding the landing area region. A plurality of wire bonds provide electrical connections between the integrated circuit and the plurality of contacts. A plurality of solder ball connection portions are provided in the peripheral area of the second surface, and a plurality of connection tracks are provided in the substrate for connecting the electrical contacts on the first surface to the solder ball connection portions on the second surface. The chip further includes at least one protection track routed through the landing area region of the substrate, wherein the chip is configured such that a change in at least one protection track prevents the operation of the integrated circuit.

[0034] A ground plane as a conductive material layer may be provided in the landing area region of the substrate, and at least one protection track may follow an isolation path separating the ground plane layer.

[0035] Similarly, a power plane as a conductive material layer may be provided in the landing area region of the substrate, and at least one protection track may follow an isolation path separating the power plane.

[0036] At least one protection track may be electrically connected to at least one solder ball located in the landing area region of the substrate.

[0037] At least one protection track appropriately provides an electrical connection to the integrated circuit, which is necessary for the correct operation of the integrated circuit.

[0038] At least one protection track may be a security track. The security track may in turn form part of a security mechanism configured to detect interference with the integrity of the security track.

[0039] Such a security mechanism suitably further includes a signal transmitter on an integrated circuit for providing a signal to a first end of the security track; and a detection circuit connected to a second end of the security track for detecting a change in the signal. The detection circuit may detect an interruption of the security track or a modification of a characteristic signal at the second end of the track, such as attenuation or impedance change.

[0040] Suitably, the security mechanism may further include a response circuit responsive to the detection circuit for causing the execution of at least one countermeasure. The at least one countermeasure may include resetting or disabling all or part of the functionality of the chip. Resetting may include erasing the content of a memory on the integrated circuit.

[0041] In another embodiment, a method for protecting a ball grid array chip of a wire bond package from alteration is provided. The method suitably includes the steps of: forming a substrate having a first surface and a second surface opposite the first surface, the first surface having a landing area region for an integrated circuit, the landing area region defining the landing area region of the substrate, the formation of the substrate including providing a plurality of contacts around the first surface in a peripheral region, the peripheral region surrounding the landing area region.

[0042] Mounting the integrated circuit on the landing area;

[0043] Connecting a plurality of wire bonds between the integrated circuit and the plurality of contacts;

[0044] Providing a plurality of solder ball connections on the peripheral region of the second surface, and wherein the step of forming the substrate includes providing a plurality of conductive tracks in the substrate for connecting electrical contacts on the first surface to the solder ball connections on the second surface.

[0045] The formation of the substrate suitably includes routing at least one protection track through the landing area region of the substrate, wherein the chip is configured such that a change in the at least one protection track prevents operation of the integrated circuit.

[0046] The method may include the step of forming a layer of conductive material in the landing area region of the substrate to act as a ground plane, wherein at least one track follows an isolation path separating the ground plane.

[0047] The method may include providing a layer of conductive material in the landing area region of the substrate to act as a power plane, and at least one track follows an isolation path separating the power plane.

[0048] The method may include the step of forming an electrical conduction path using at least one conductive trace between one of the landing areas and at least one solder ball, wherein at least one solder ball is located in a landing area region of a substrate.

[0049] At least one protection trace may provide an electrical connection to an integrated circuit, which is necessary for the subsequent correct operation of the integrated circuit.

[0050] At least one protection trace may be a security trace forming part of a security mechanism. The method may further include providing a detection circuit in the integrated circuit as part of the security mechanism for detecting any interference with the security trace. In such a case, the detection circuit is configured to enable a response circuit to take countermeasures. The countermeasures may include resetting or disabling all or part of the functionality of the chip. Description of the Drawings

[0051] The present application will now be described with reference to the drawings, in which:

[0052] Figure 1 is a cross-sectional view of a wire-bonded BGA package known in the art;

[0053] Figure 2 is Figure 1 a bottom view of a package of the type shown;

[0054] Figure 3 is of Figure 1 an illustration of a potential attack path on the substrate of the package;

[0055] Figure 4 is an illustration highlighting an area in which protection measures may be provided in a wire-bonded BGA package to reduce the chance of attack by Figure 3 the means shown in;

[0056] Figure 5 is an exemplary arrangement showing how to separate conductive planes;

[0057] Figure 6 is another exemplary arrangement showing the separation of conductive planes;

[0058] Figure 7 is another exemplary arrangement in which a solder ball connection to a critical signal is provided to reduce the chance of attack by Figure 3 the means shown in; and

[0059] Figure 8 is a security mechanism that may be used with Figures 4 to 7 the arrangement of; Detailed Description

[0060] As described above, vulnerabilities to attacks have been identified in wire-bonded BGA packages, and the present application provides an inexpensive way to defeat such attempts.

[0061] As Figure 4 shown, the present application provides a ball grid array BGA chip 40 of a wire-bonded package, in which protection measures are employed in a region 42 of a substrate 8 under an integrated circuit die. To avoid repetition, the same reference numerals are used for features of the Figure 1 prior art.

[0062] It should be understood that the protection measures are applied during the creation of the packaged BGA package, more particularly during substrate formation and during the design of the chip.

[0063] The basis of these protection measures is that, during opening, physical destruction of one or more protection tracks is forced by milling or otherwise treating the package of the chip from the solder ball side to gain access to the die.

[0064] Conventionally, since a large redundancy is provided for power and ground connections, a large area of the landing zone under the die can be opened with limited impact on the operation of the integrated circuit, and thus most of the area under the die can be removed, thereby opening the die for attack.

[0065] More specifically, typically the BGA wire-bonded package is routed to provide the most efficient pin layout, with power and ground balls arranged around and within the landing zone area of the package (under the chip). This also allows heat dissipation into a large GND plane. Typically, these power and ground planes are reconnected at multiple points between PCB layers. It is the large area and multiple connections that allow a large area under the silicon of the die to be opened without affecting functionality.

[0066] The present application places protection connections (protection tracks) through the vulnerable landing zone area 42. Then, the substrate will include connection tracks for the normal operation of the chip as well as tracks that connect the solder balls to electrical contacts on the first surface and the protection tracks, which are not used to convey signals from or to the solder balls to the chip, but are used to detect intrusion into the landing zone. For this purpose, at least a portion of the protection tracks is located within the landing zone.

[0067] Connection tracks (also referred to as tracks) are familiar to those skilled in the art. Generally speaking, the length of a track is on the order of its width, for example at least ten times.

[0068] In this case, the protection track suitably begins at a point outside the landing zone area. It is understood that the protection track extends parallel to the surface of the substrate. This is in contrast to connection tracks that extend substantially perpendicular to the surface, such as vias conventionally used to connect a ground plane to an underlying solder ball. The protection track may be provided in one or more layers of the substrate. In some configurations, the protection track will terminate at a point outside the landing zone area, e.g., where it is a security track and makes a connection to a detector on the integrated circuit. In other configurations, the protection track will terminate at a point within the landing zone area and will make an external electrical connection to a second (as described below) via a solder ball connection.

[0069] Physical damage or interference to one or more protection tracks can disable connectivity and thus the function of the chip or, in the case where the tracks are security tracks, allow the security mechanism of the IC to detect and take action.

[0070] The security mechanism may employ active or passive shielding techniques known to those skilled in the art (mentioned above and described below).

[0071] By routing one or more critical signals directly under the silicon substrate through the power and / or ground plane, this limits the area that can be opened without having to reconnect these signals as well as the ground and power layer planes.

[0072] It is understood that the more critical signals that pass through the landing zone area, the less feasible it is to reconnect multiple severed signals during an attack.

[0073] The signals routed through the landing zone area are selected to have an appropriate criticality for the operation of the chip.

[0074] In a first method, the critical nature can be direct, i.e., the signals routed along conductive tracks in the landing zone area are necessary for the normal function (correct operation) of the integrated circuit. As an example, an in can be an input or output signal connection from the integrated circuit. It is understood that signal connections are different from power connections, i.e., ground or power voltage.

[0075] In a second method, the critical nature is indirect. In this method, the conductive track is a security track (or protection track) that forms part of the security mechanism. The security mechanism is not necessary for the normal operation of the integrated circuit and generally does not interfere with the operation of the integrated circuit unless and until it detects an attack on the integrity of the security track.

[0076] It is understood that these two methods are not mutually exclusive. Both can be employed simultaneously using different tracks.

[0077] At the same time, by providing tracks in the same layer as the ground plane or power plane, the interconnectivity of the GND and power domains is appropriately reduced because the continuous regions of the plane can be segmented, thus creating more opportunities to isolate critical circuits / detector circuits. In the case of providing tracks in a layer different from the GND or power domain, the tracks still reduce the continuous regions available for attack by restricting the available space that can be opened.

[0078] As Figure 4 shown, the integrated circuit die 2 is typically positioned and mounted on top of the substrate 8. The outline or perimeter of the die defines an area referred to as the landing zone, which coordinately defines the landing zone area of the substrate 8 that extends between two surfaces and is defined by the area of the landing zone. The wire bonds 4 connect the top of the die to the contacts 16 on the first surface of the substrate. These contacts 16 are arranged in the peripheral area of the substrate surrounding the landing zone area 22. The solder ball connections 10 are provided on the second side of the substrate.

[0079] Through connections, such as vias 15, are provided to electrically connect the respective solder ball connections to the associated contacts on the top surface.

[0080] To deter attacks through the landing zone of the die, at least one conductive track is routed through the landing zone 42 of the substrate. At least one track does not form part of a ground or power plane. The conductive track can be coplanar with one or the other of the ground or power planes. The chip is configured such that a change in at least one conductive track prevents the operation of the circuit.

[0081] Now reference will be made to Figures 5 to 7 several potential methods of routing critical paths through the landing zone area, which can be used alone or in combination.

[0082] In Figure 5 it, a ground plane 52 is shown disposed in the landing zone area of the substrate. A plurality of thermal vias 14 are provided that provide thermal and electrical connections from solder balls (not shown) on the underside of the substrate to the ground plane. For convenience, the areas of the plane extending beyond the landing zone area defined by the position of the die are not shown. In practice, the connections will extend from the landing zone area to contact pads on which the wire bonds will establish connections to the die. Generally, there will be multiple different ground and power connections arranged to the die.

[0083] Thus, in a conventional method, a ground connection can be established along the outer side of the landing zone area with a conductive track, and power connections are present in the area near and outside the corners of the landing zone area.

[0084] The conductive track 56, which is insulated from but coplanar with the ground plane, follows an isolation path through the ground plane. The isolation path divides the ground plane into two separate continuous regions 54a and 54b. The conductive track is connected by contact pads and wire-bonded on one side. In a first method, the conductive track is used as part of an active or passive shield and is connected and wire-bonded to an integrated circuit through a second contact pad and forms part of a detection circuit configured to monitor any changes in the protection track.

[0085] In a second method, the conductive track provides a connection (a critical connection) to a required signal on the integrated circuit, and the second end of the conductive track is connected to a solder ball connection at the bottom of the substrate by means of a via. Thus, the critical signal connection is routed through the landing zone area, and an interruption in the landing zone area prevents the correct operation of the integrated circuit.

[0086] At the same time, it should be understood that dividing the ground plane into two separate ground plane regions 54a and 54b again limits the scope of material removal to access the substrate of the die.

[0087] It should be understood that the number of conductive tracks can be increased to increase the complexity and necessity of bypassing and re-establishing connections. Thus, in Figure 6 , the ground plane 62 is divided into four separate continuous regions 64a, 64b, 64c, 64d by two separate conductive tracks 66, 67, and each of the conductive tracks can be one or the other of the critical signals for circuit operation or connected to a detection circuit. It should be understood that the method is not limited to two conductive tracks.

[0088] Although Figure 5 and 6 are referred to in the context of a ground plane, it should be understood that it can equally apply to a power plane. In the case of a power plane, since thermal vias are typically ground connections, the thermal vias may be isolated from the power plane.

[0089] Figure 7 Another method of protecting a vulnerable area is shown, where a wire-bond connection 74 is established with a lead pad 70 on the top surface of the substrate. As is conventional, the conductive pads 70 are located in the peripheral area of the landing zone surrounding the die. The conductive pads are used for signal connections rather than ground or power connections of the integrated circuit.

[0090] The conductive pads are connected to the landing area region of the die by means of conductive tracks 72, where vias 78 provide a connection to the underside of the substrate and are electrically connected to solder balls 80 here. The solder balls 80 are disposed in the landing area region of the substrate directly under the die. It should be understood that the conductive tracks can be positioned in a layer coplanar with a ground plane, a power plane or in an intermediate layer. Similarly, the conductive path between the contact pads and the solder balls can include additional vias or tracks in different layers of the substrate.

[0091] By placing one or more solder balls connected at a central position under the die to obtain critical signals other than power or ground connections, the vulnerability of the chip to attacks through the identified vulnerable areas can be significantly reduced. It should be understood that this method runs completely counter to the design of wire-bonded BGA packages, which arrange all signal connections around the peripheral area.

[0092] It should be understood that Figure 7 's technology can be easily combined with Figure 5 and 6 's technology.

[0093] The nature of the conductive tracks as secure tracks will now be described in more detail. In this method, the key characteristics of the conductive tracks are indirect.

[0094] Interference with the secure tracks themselves does not disrupt the normal operation of the integrated circuit.

[0095] Rather, as Figure 7 shown, the secure track 86 forms part of a security mechanism 82 that responds to the disruption of the secure track. The security mechanism includes the secure track and the connection between the secure track and the integrated circuit 2 as well as circuits 87, 88, 89 within the integrated circuit that are used to monitor an attack on the integrity of the secure track. The security mechanism 82 generally does not interfere with the operation of the integrated circuit 2 unless and until it detects an attack on the integrity of the secure track 86.

[0096] In Figure 8 , the security mechanism 82 uses a transmitter 87 to guide a signal along the secure track 86. The signal can be a voltage, a current or a dynamic signal such as a clock or a digital bit stream. Similarly, it can be a DC or AC voltage or current. The detection circuit 88 monitors any change in the signal at the other end of the secure track opposite the transmitter. A signal change detected by the detection circuit will cause the response circuit 89 to take countermeasures, thereby preventing the normal operation of the chip. The countermeasures can include resetting or disabling all or part of the functionality of the chip. These countermeasures can include disabling the functions of the integrated circuit or erasing the contents of the memory on the integrated circuit or both.

[0097] The safety track can be considered as a conductive track that is electrically connected to at least two terminals of the integrated circuit, for example using a combination of tracks, through-holes and wire bonds. This allows a first connection to a first terminal at one end of the safety track and then to a transmitter of the safety mechanism. A connection to a second terminal is provided at the other end of the safety track. The second terminal in turn provides a connection to a detector of the safety mechanism.

[0098] The safety mechanism may be a passive shield or an active shield. In both cases, a signal is provided by a signal transmitter to a first end of the conductive track and a detection circuit is employed to monitor the opposite end of the conductive track.

[0099] In the case of passive shielding, the emitter and detection circuits may be configured to allow detection of changes in the impedance of the conductive track. This change may be measured, for example, as capacitance or resistance. Passive shielding typically employs analog circuits for the emitter and detector.

[0100] In active shielding, a bit sequence (typically random) is injected at the beginning of a conductive track and subsequently tested at the other end by a detection circuit to check whether the bit sequence has reached the home position after travelling along the safety track.

[0101] It should be appreciated that a variety of different techniques may be used, which may be selected to facilitate implementation of the safety mechanism as either a passive or active shield.

[0102] When used in this specification, the words “comprises / comprising” refer to the presence of stated features, integers, steps or components, but do not exclude the presence or addition of one or more other features, integers, steps, components or groups thereof.

Claims

1. A chip (40), comprising a substrate (8) having a first surface and a second surface opposite to the first surface; an integrated circuit (2) mounted on a landing area (42) on the first surface of the substrate (8), the landing area (42) defining a landing area region of the substrate (8) surrounded by a peripheral region of the substrate (8); A plurality of electrical contacts (16), which are provided around the first surface in the peripheral region; A plurality of wire bonds (74), which provide electrical connection portions between the integrated circuit (2) and the plurality of electrical contacts (16); A plurality of solder ball connection portions (80), which are provided on the second surface; A plurality of connection portions (15), which are provided in the substrate (8) for connecting the electrical contacts (16) on the first surface to the solder ball connection portions (80) on the second surface; Wherein, The substrate (8) includes at least one conductive track (72) that routes through the landing area region (42) of the substrate (8), Wherein, the at least one conductive track (72) provides an electrical connection portion to the integrated circuit (2), and the electrical connection portion is necessary for the normal operation of the integrated circuit (2), Characterized in that the chip (40) is configured such that a change in the at least one conductive track prevents the operation of the integrated circuit (2), Wherein, the at least one conductive track is a security track (86) that forms part of a security mechanism (82), wherein the security mechanism (82) is configured to detect an interference with the integrity of the security track (86), and in response, enable at least one countermeasure, and the security mechanism (82) includes: A signal transmitter (87) on the integrated circuit (2) for providing a signal to a first end of the security track (86); and A detection circuit (88) connected to a second end of the security track (86) for detecting a change in the signal, Wherein, the security mechanism (82) further includes a response circuit (89) in response to the detection circuit (88) to perform all or part of the reset or disabling of the functionality of the chip caused by the at least one countermeasure, Wherein, the at least one conductive track (72) is electrically connected to at least one solder ball connection portion, and the at least one solder ball connection portion is located at a central position below the landing area region of the substrate (8).

2. The chip according to claim 1, wherein a ground plane (62) as a conductive material layer is provided in the landing area region (42) of the substrate (8), and wherein the at least one conductive track (72) extends along an isolation path separating the ground plane (62).

3. The chip according to claim 1, wherein a power plane as a conductive material layer is provided in the landing area region (42) of the substrate (8), and the at least one conductive track extends along an isolation path separating the power plane.

4. A method for protecting a ball grid array chip of a wire-bonded package from being altered, comprising the following steps: Forming a substrate having a first surface and a second surface opposite to the first surface, the first surface having a landing area for an integrated circuit, the landing area defining a landing area region of the substrate, and the forming of the substrate includes providing a plurality of electrical contacts around the first surface in a peripheral region, the peripheral region surrounding the landing area region; Mounting the integrated circuit on the landing area; Connecting a plurality of wire bonds between the integrated circuit and the plurality of electrical contacts; Providing a plurality of solder ball connection portions on the second surface; Wherein the step of forming the substrate includes providing a plurality of connection portions in the substrate for connecting the electrical contacts on the first surface to the solder ball connection portions on the second surface; Wherein, the forming of the substrate includes routing at least one conductive track through the landing area region of the substrate, Wherein, the at least one conductive track provides an electrical connection portion to the integrated circuit, and the electrical connection portion is necessary for the subsequent correct operation of the integrated circuit, wherein the chip is configured such that a change in the at least one conductive track prevents operation of the integrated circuit, wherein the at least one conductive track is a security track, and the method further comprises: providing a security mechanism including the security track, wherein the security mechanism is configured to detect an interference with the integrity of the security track and, in response, enable at least one countermeasure, providing a signal to a first end of the security track by the security mechanism; and detecting a change in the signal at a second end of the security track and, in response to detecting the change, resetting or disabling all or part of the functionality of the chip by the at least one countermeasure, wherein the at least one conductive track (72) is electrically connected to at least one solder ball connection portion located at a central position below the landing area region of the substrate (8).

5. The method according to claim 4, wherein the method includes the step of forming a layer of conductive material in the landing area region of the substrate to act as a ground plane, wherein the at least one conductive trace follows an isolation path that separates the ground plane.

6. The method according to claim 5, further comprising providing a layer of conductive material in the landing area region of the substrate to act as a power plane, and the at least one conductive trace follows an isolation path that separates the power plane.

7. The method according to claim 5, further comprising the step of forming a conductive path using the at least one conductive trace between one of the electrical contacts on the first surface and at least one solder ball connection.

Citation Information

Patent Citations

  • Integrated circuit chip protection against physical and / or electrical alterations

    CN107787499A

  • Semiconductor package including power ball matrix and power ring having improved power integrity

    US20100276189A1