Method, system and integrated circuit chip for setting an electronic device

By adopting a multi-stage setting method in the IC manufacturing process, multiple keys are set using electrical probes and contact pins, and through digital signatures and public key verification, the complex security level in the multi-stage manufacturing device is solved, and the security of the chip and system is improved.

CN115412251BActive Publication Date: 2025-06-10NUVOTON
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210286485.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-05-27
Filing Date
2022-03-23
Publication Date
2025-06-10
Estimated Expiration
2042-03-23

AI Technical Summary

Technical Problem

In a multi-stage manufacturing device, the security level required for maintenance is complex, and there is a separate time or place for the key to be set during the IC manufacturing stage, which is easily exploited by malicious internal personnel.

Method used

Using a multi-stage setting method, two or more keys are set into the chip at different stages of the manufacturing process, and the first and second keys are set using an electrical probe and a contact pin respectively during the setting process, ensuring that the setting report has a digital signature, and verifying the integrity of the setting process through public key and security authentication.

Benefits of technology

Even if an attacker has access to one of the keys, it is not enough to attack the chip or integrated system, prevent unauthorized use, and the setup process reduces the time or location of a separate time and location, and reduces the risk of malicious insiders.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115412251B_ABST
    Figure CN115412251B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, a system and an integrated circuit chip for setting an electronic device. The method includes providing a semiconductor wafer having a plurality of manufactured integrated circuit chips thereon. Each integrated circuit chip includes a secure memory and programmable logic. The programmable logic is used to store at least two keys in the secure memory and to calculate a digital signature for data using the at least two keys. A first key is set into the secure memory of each integrated circuit chip via an electrical probe contacting a contact pad. After the semiconductor wafer is diced, a second key is set into the secure memory of each chip via a stylus. A setting report is received from each chip, and the setting report has a digital signature calculated by the programmable logic using the first key and the second key. The above setting is verified based on the above digital signature.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention is generally directed to integrated circuit devices, and more particularly to methods and systems for provisioning confidential data in such devices, and devices provisioned by such methods. Background Art

[0002] Key provisioning is a method of inserting keys and other security information into an electronic device, which can be, for example, a system-on-chip integrated circuit (IC). Once a cryptographic key is provisioned onto an IC chip, it can be used to authenticate secure operations, authenticate the chip and product on which the key is provisioned, and protect the chip and product from tampering. Such chips typically include a secure memory and multiple logic circuits to ensure that once the cryptographic key is provisioned and stored in the chip's memory, it can be authenticated based on a digital signature, but the confidential portion of the key cannot be extracted.

[0003] Keys are typically provisioned onto IC chips under tight security as part of the manufacturing process to ensure that malicious parties do not have access to the keys. Maintaining the required level of security can be very complex when using a multi-stage process to manufacture a device because the multi-stage process involves multiple entities. Therefore, it is desirable to provision keys at the IC manufacturing stage, which is considered to be more secure than system-level assembly.

[0004] In this regard, for example, U.S. Patent No. 9,430,658 describes a method for secure provisioning in the production of electronic circuits. A first entity (e.g., a chip manufacturer) embeds one or more secret values into a plurality of identical circuits. A second entity (e.g., an OEM contract manufacturer): 1) derives a trust anchor from a code signing public key; 2) embeds the trust anchor into a first circuit replica; 3) causes the first circuit replica to generate a private key from the trust anchor and the embedded secret value; 4) signs a provisioning code using a code signing private key; 5) transmits the code signing public key, the trust anchor, and the signed provisioning code to a third entity (e.g., a product manufacturer). The third entity embeds the trust anchor into a second circuit replica so that it: 1) generates the private key; 2) verifies the signature of the signed provisioning code using the code signing public key; 3) activates the provisioning code. The OEM can authenticate the second circuit replica using the first circuit replica and a challenge / response protocol. SUMMARY OF THE INVENTION

[0005] Embodiments described hereinafter of the present invention provide methods for provisioning a variety of electronic devices, systems for performing the provisioning, and devices that can be provisioned by the methods.

[0006] According to an embodiment of the present invention, a method for provisioning an electronic device is provided. The method includes providing a semiconductor wafer having a plurality of fabricated integrated circuit (IC) chips thereon. Each integrated circuit chip includes a secure memory and programmable logic for storing at least two keys in the secure memory and calculating a digital signature for data using at least two of the keys. A first key is provisioned into the secure memory of each of the chips via an electrical probe that contacts a contact pad on the semiconductor wafer. After the wafer is diced, a second key is provisioned into the secure memory of each of the chips via a contact pin of the chip. A provisioning report is received from each of the chips, the provisioning report having a digital signature calculated by the programmable logic using the first key and the second key. The provisioning is verified based on the digital signature.

[0007] In the embodiment, provisioning the first key occurs during a process of testing the chips on the semiconductor wafer using the electrical probe. Additionally or alternatively, provisioning the second key occurs during a process of testing each of the chips.

[0008] In the embodiment, provisioning the first key is performed by a first provisioning appliance, and provisioning the second key is performed by a second provisioning appliance, the second provisioning appliance being separate and independent from the first provisioning appliance.

[0009] In some embodiments, the method includes loading code into each of the integrated circuit chips for execution by the programmable logic, the code being signed with a trusted signature, wherein the provisioning report is received from each of the chips after the code is loaded. Additionally or alternatively, receiving the provisioning report includes receiving a public key from each of the chips for communicating with the IC chip, the public key being signed using the first key and the second key.

[0010] Further optionally or alternatively, receiving the above setting report includes receiving a first security certificate and a second security certificate generated by each of the above chips, where the first security certificate and the second security certificate are related to the first key and the second key. In the described embodiment, the first security certificate and the second security certificate are stored in a repository, the repository is periodically checked for duplication of the first security certificate and the second security certificate, and a warning is issued when a duplication is detected.

[0011] According to an embodiment of the present invention, a system for setting an electronic device is also provided here. The system includes an electrical probe for contacting contact pads on a semiconductor wafer, where there are a plurality of fabricated IC chips on the semiconductor wafer. Each IC chip includes a secure memory and programmable logic, the programmable logic is used to store at least two keys in the secure memory, and use the at least two keys to calculate a digital signature for data. A connector is used to connect the pins of each of the above chips after the semiconductor wafer is sliced. At least one setting device is used to set a first key into the secure memory of each of the above IC chips via the electrical probe, the electrical probe contacts the semiconductor wafer, and after the semiconductor wafer is sliced, is used to set a second key into the secure memory of each of the above IC chips via the connector and the pins, and is used to receive a setting report from each of the above IC chips, the setting report has a digital signature, the digital signature is calculated by the programmable logic using the first key and the second key, and is used to verify the setting based on the digital signature.

[0012] Additionally provided, according to an embodiment of the present invention, an integrated circuit chip includes a secure memory and programmable logic, the programmable logic is used to receive at least a first key and a second key, the first key and the second key are set in different first and second stages during a process of manufacturing the chip, and is used to store the keys in the secure memory, and is used to calculate and output a digital signature using the first key and the second key.

[0013] In some embodiments, the programmable logic is used to output a setup report including the digital signature after loading code into the chip for execution by the programmable logic, and the code is signed using a trusted signature. In the embodiments described above, the setup report output by the programmable logic includes a public key for communicating with the chip, where the public key is signed by the programmable logic using a digital signature, and the digital signature uses the first key and the second key. Additionally or alternatively, the setup report includes a first security authentication and a second security authentication generated by the programmable logic, and the first security authentication and the second security authentication are related to the first key and the second key.

[0014] The method, system, and integrated circuit chip for setting an electronic device provided by the embodiments of the present invention have two (or more) keys set into the chip at different stages during the manufacturing process, and then both keys are used together to verify the settings. Even if an attacker can access one of the keys, it is not sufficient to attack the chip or the system in which the chip is integrated, that is, to extract enough information to allow unauthorized use of the key, such as to authenticate a fake device. The setup process itself is also less vulnerable to malicious insiders because there is no longer any single point (i.e., no single time or location) during the process where all key information is accessible. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The present invention can be more comprehensively understood from the following detailed description of the embodiments in conjunction with the following drawings. In the drawings:

[0016] Figure 1 is a block diagram schematically illustrating a system for setting an IC chip at the wafer level according to an embodiment of the present invention.

[0017] Figure 2 is a block diagram schematically illustrating a system for setting an IC chip after dicing according to an embodiment of the present invention.

[0018] Figure 3 is a ladder diagram schematically illustrating a method for setting an IC chip at the wafer level according to an embodiment of the present invention. And

[0019] Figure 4 is a ladder diagram schematically illustrating a method for setting and verifying an IC chip after dicing according to an embodiment of the present invention.

[0020] Reference Numerals:

[0021] 20: System for setting IC chip 22

[0022] 22: IC chip

[0023] 24: Secure Memory

[0024] 26: HW Key

[0025] 28: Interface

[0026] 30: Secure Logic

[0027] 32: Semiconductor Wafer

[0028] 34: Setting Device

[0029] 36: Memory

[0030] 38: Central Processing Unit

[0031] 40: Hardware Security Module

[0032] 42: Probe

[0033] 50: System

[0034] 52: Circuit Board

[0035] 54: Setting Device

[0036] 56: Secure Memory

[0037] 58: Central Processing Unit

[0038] 60: Hardware Security Module

[0039] 62: Connector

[0040] 74: CP Storage Step

[0041] 80: Code Loading Step

[0042] 82: FT Download Step

[0043] 84: FT Decryption Step

[0044] 86: Key Generation Step

[0045] 88: Signature Generation Step

[0046] 90: Reporting Step

[0047] 92: Report Storage Step

[0048] 94: Server

[0049] 96: Pairing Check Step Detailed Implementation Manner

[0050] A secure IC chip is designed such that once a key is set in the memory of the above chip, the above key cannot be accessed or used without authorization. However, during the manufacturing process, a malicious insider, such as a disloyal employee of the above chip manufacturer, may be able to access the key value stored in the setting device. (“Setting device” in this description and the claims refers to the production equipment used to transfer the key and related data to the above chip). When the above IC chip is subsequently integrated into a computerized system, the stolen key can be used by an attacker to crack the entire above system, or to build a seemingly authentic rogue system.

[0051] Multiple embodiments of the present invention described herein use a multi-level setting method to solve this problem: two (or more) keys are set into the above chip at different stages during the above manufacturing process, and then both keys are used together to verify the above setting. Even if an attacker can access one of the above keys, it is not sufficient to attack the above chip or the system that has integrated the above chip, that is, to extract enough information to allow unauthorized use of the above key, such as to authenticate a fake device. The above setting process itself is also less vulnerable to malicious insiders because there is no longer any single point (i.e., no single time or place) during the process where all the above key information is accessible.

[0052] The multiple embodiments described next herein start with a semiconductor wafer on which multiple IC chips have been fabricated. Each IC chip includes a secure memory and programmable logic, the programmable logic being used to store at least two of the above keys in the above secure memory and to calculate a digital signature for data using these keys. A first key is set into the above secure memory of each of the above IC chips via an electrical probe that contacts contact pads on the semiconductor wafer, for example, performed by a setting device during a wafer-level test. After the above wafer is cut into multiple separate chips, a second key is set into the above secure memory of each of the above chips via the pins of the above chip, for example, performed during a process of testing each of the above IC chips. This later stage can be performed by a different setting device that is separate and independent from the setting device used to set the above first key, and may even be in a different facility. A malicious group would need to access these two separate setting stages to obtain the complete above key information.

[0053] To verify the integrity of the above setup process and to allow subsequent use of the above IC chip in secure operations, each IC chip generates and outputs a setup report, the above setup report having a digital signature, the above digital signature being calculated by the above programmable logic using the above first key and the above second key. At this stage, the above programmable logic typically generates a pair of public and private keys, and outputs the above public key as part of the setup report, the above public key being signed by the above first key and the above second key, the above setup report attesting to the ownership of the above private key (or the secret used to derive the above key pair), and thus establishing that the above chip is genuine. Alternatively, the above setup report may take any other suitable form, the form allowing the recipient to receive the above digital signature, and thus verify that the above chip contains the above first key and the above second key. Once the above two keys have been verified by this method, after the above IC chip has been integrated into a product, for example, subsequent verification of the digital signature can be performed using only one of the two keys, since all of the above confidential information is known to be securely stored in the above IC chip and cannot be tampered with.

[0054] Other benefits of the above-presented multiple embodiments are that verification of the setup only occurs after the entire IC setup process is complete, the above IC setup process occurring in the above IC manufacturing and testing facility. There is no need for a prior handshake between the above setup device and the above IC chip during the above stages of device manufacturing and testing; and the above first stage of the setup is completely one-way at the wafer level, meaning that the above setup chip does not need to respond to the above setup device. Thus, in addition to the inherently increased complexity in the above two-stage setup protocol, the actual above setup can be performed using existing test equipment as part of the above standard manufacturing process, with only some or no delay to the entire above process.

[0055] Figure 1is a block diagram that schematically illustrates, according to an embodiment of the present invention, a system 20 for setting an IC chip 22 that has been fabricated on a semiconductor wafer 32. Each IC chip 22 includes a secure memory 24 and programmable secure logic 30, and the programmable secure logic 30 (hereinafter simply referred to as logic 30) is used to store a plurality of keys in the memory 24 and calculate digital signatures for data using the keys. The logic 30 is capable of performing secure cryptographic operations and other functions and typically includes a programmable microcontroller or microprocessor core that operates under the control of appropriate code. Alternatively or additionally, the logic 30 includes hard-wired and / or programmable digital logic circuits. The logic 30 is connected to an interface 28, such as in the form of contact pads on the semiconductor wafer 32, through which data and other signals can be input or output to the IC chip 22.

[0056] The secure memory 24 includes a non-volatile memory (NVM), such as a one-time programmable (OTP) memory or an electrically-programmable read-only memory (ROM), and the non-volatile memory can only be accessed by the logic 30. The memory 24 includes a hardware key 26 that is written into the memory or designed into the logic during the fabrication of the semiconductor wafer 32 and is used as a global secret in subsequent program stages, as described below. During these program stages, the logic 30 stores (at least) two additional keys in the secure memory 24 and calculates one or more digital signatures using the keys. The memory 24 typically includes additional non-volatile and / or volatile random-access memory (RAM) for storing code, such as firmware and / or software code, as well as data.

[0057] A provisioning device 34 provisions a first key, hereinafter referred to as the "circuit probe (CP)" key, into the secure memory 24 of each IC chip 22 via a probe 42 that contacts contact pads on each chip in the semiconductor wafer 32. The probe 42 can be part of a wafer test system (not shown in the figures), and the provisioning device 34 is coupled to the wafer test system for provisioning. As previously described, this provisioning can be conveniently performed as part of a standard wafer-level test scheme, such as a test for detecting faulty chips during the wafer sorting phase of the manufacturing process. Alternatively, the provisioning of the CP key can be performed independently of all test phases.

[0058] Provisioning devices are known in the art of secure manufacturing, and any suitable such device can be used in system 20. In the illustrated embodiment, the provisioning device 34 includes a secure, trusted computer having a central processing unit (CPU) 38 and a memory 36 that contains programming instructions and data. To ensure the security and integrity of the CP key being provisioned into the IC chip 22, the device 34 includes a tamper-resistant hardware security module (HSM) 40 for generating, encrypting, and transmitting the key value and other data to the IC chip 22 via the probe 42. Each CP key is encrypted by the HSM 40 using a hardware key 26 and then transmitted to the IC chip 22 as a binary large object (BLOB) and an accompanying digital certificate that attests to the authenticity of the key. (Optionally, the digital certificate can also be encrypted.) The HSM 40 signs the digital certificate using a signing key protected by the HSM. The logic 30 decrypts and parses the BLOB using the hardware key 26 and stores the CP key in the memory 24.

[0059] Figure 2 is a block diagram that schematically illustrates a system 50, according to an embodiment of the present invention, for the provisioning of IC chips 22. In system 50, a semiconductor wafer 32 ( Figure 1) has been cut open to separate the IC chip 22, and the chip has been encapsulated or is ready to be integrated into an electronic device. At this stage, for example, the IC chip 22 can be mounted on a circuit board 52, such as a test fixture or the actual device into which the chip will be integrated. In this configuration, the interface 28 is connected to the pins or die on the chip package, and the pins or the die may have been soldered to the traces of the circuit board 52. Alternatively, the system 50 can be applied to directly set individual chips rather than through a circuit board. In either case, for example, the pins can take the form of pins on an IC package or solder bumps on an IC die, depending on the type of package, or any other suitable type of chip connection known in the art.

[0060] A setting device 54 sets a second key into the secure memory 24 of each IC chip 22 via a connector 62, which directly or via the circuit board 52 contacts the pins on the IC chip 22 (as Figure 2 shown). The device 54, like the device 34 ( Figure 1 ), includes a secure, trusted computer having a CPU 58 and a secure memory 56, and a HSM 60. The connector 62 can be part of a final test system or a system (not shown in the figures) used for outsourced assembly and testing, and the device 54 is coupled to the system for setting. Thus, the key set by the device 54 is referred to herein and hereinafter as the "final test (FT) key". Although the same setting device can be used in the setting of the CP key and the FT key, the separation and independence of the devices 34 and 54 are advantageous for preventing potential attacks from malicious insiders.

[0061] Figure 3 is a ladder diagram schematically illustrating a method of setting a wafer-level IC chip 22 according to an embodiment of the present invention. For clarity and specificity, this method is described herein with reference to the system 20 ( Figure 1 ), in particular the IC chip 22 (referred to as the "device under test" or DUT) and the setting device (PA) 34. Alternatively, this method can be performed by other system configurations, which will be apparent and understandable to those skilled in the art after reading the above description.

[0062] In CP download step 70, after being connected to IC chip 22 via probe 42, setup device 34 downloads a BLOB that includes the CP key and a digital authentication that attests to the authenticity of the CP key to IC chip 22. The authentication is signed by HSM 40 using a protected signature key. The BLOB is encrypted using hardware key 26 of IC chip 22 and a copy of the key protected by HSM 40. In CP decryption step 72, logic 30 in IC chip 22 decrypts the BLOB using hardware key 26 and parses the decrypted BLOB to extract the CP key. In CP storage step 74, logic 30 stores the CP key in secure memory 24.

[0063] Logic 30 is programmed such that after the storage of the CP key in step 74, logic 30 will access the CP key only after appropriate code has been loaded into and executed by IC chip 22. This operating mode of IC chip 22 is referred to as the production (PROD) state. This configuration feature prevents any further access or use of the CP key at the wafer level.

[0064] Figure 4 is a ladder diagram that schematically illustrates a method for setting up and verifying IC chip 22 after dicing, according to an embodiment of the present invention. Again, for clarity and specificity, this method is described herein with reference to system 50 ( Figure 2 ), in particular IC chip 22 and setup device 54. Alternatively, this method may be performed by other system configurations, which will be apparent and understandable to those skilled in the art after reading the above description.

[0065] In the code loading step 80, the provisioning device 54 sends a signal via the connector 62 to the IC chip 22 indicating that it is about to enter the PROD state as described above and downloads code into the chip, for example in the form of a firmware code. This code is transmitted together with a trusted digital signature that allows the logic 30 in the IC chip 22 to verify that the code is genuine and trusted. The logic 30 will not accept and load any code that is not properly authenticated. In the FT download step 82, the provisioning device 54 downloads a BLOB into the IC chip 22, the BLOB containing the FT key and a digital authentication signed by the HSM 60 attesting to the authenticity of the FT key. The BLOB is encrypted again using the hardware key 26 of the IC chip 22. (Alternatively, the order of steps 80 and 82 can be reversed).

[0066] In the FT decryption step 84, the logic 30 in the IC chip 22 decrypts the BLOB using the hardware key 26 and parses the decrypted BLOB to extract the FT key and also stores the FT key in the secure memory 24.

[0067] In the key generation step 86, the logic 30 generates a public / private key pair for subsequent communication with the IC chip 22. For example, the logic 30 can receive a seed value from a random number generator on the IC chip 22 and then use the seed value in a key derivation function (KDF) to generate the public key and the private key. The public key is referred to herein as the "ID key". In the signature generation step 88, the logic 30 generates a digital signature on the ID key using the CP key and the FT key, the CP key and the FT key being stored in the secure memory 24. This digital signature can include, for example, two sub-signatures calculated using the CP key and the FT key respectively; or alternatively, the multiple sub-signatures can be concatenated or otherwise mixed in the digital signature. In either case, a valid digital signature can only be calculated at this stage if both the CP key and the FT key are used.

[0068] In a reporting step 90, after steps 80 to 88 have been completed, the logic 30 generates and outputs a setup report to the setup device 54 via the connector 62. The report includes the CP and FT authentications, the authentications and the CP key and the FT key received by the IC chip 22 in steps 70 and 82, and the ID key generated in step 86, and the digital signature calculated in step 88. The setup device 54 checks the authentication and the digital signature to verify the validity of the ID key and authentication. As previously mentioned, the IC chip 22 will be authenticated and released for use in the field, and will only be able to receive services after this authentication, which can only be completed if both the CP key and the FT key are successfully set in the memory 24.

[0069] In some embodiments, to enhance long-term security, in a report storage step 92, the configuration device 54 transmits the configuration report and the corresponding CP and FT authentication pair to a repository for storage. For example, the configuration device may transmit the report and authentication via a network to a server 94, which maintains a database containing the authentication pair. In a couple checking step 96, the server 94 periodically checks the repository for copies of the CP and FT authentication pair. When a copy is detected, the server 94 issues an alarm, such as to the manufacturer of the IC chip 22. Such alarms are useful in detecting and warning against attempts to crack the security of the IC chip 22 by reusing previously confidential values, such as detecting and warning against a replay attack. To guard against such use, the server 94 and / or the configuration device 54 may maintain a "revocation list" of keys and authentication pairs that have been cracked, and may refer to this list when responding to subsequent requests involving the keys and authentication pairs in question.

[0070] It is to be understood that the above-mentioned embodiments are for illustration only, and the present invention is not limited to the parts specifically shown and described above. Specifically, the scope of the present invention includes the combination and sub-combination of the various features mentioned above, and the changes and modifications that can be thought of by a person skilled in the art after reading the above description, and the parts not described in the prior art.

Claims

1. A method for setting an electronic device, characterized in that, the method includes: providing a semiconductor wafer on which a plurality of manufactured integrated circuit chips are located, each of the integrated circuit chips includes a secure memory and programmable logic, the programmable logic is used to store at least two keys in the secure memory, and use the at least two keys to calculate a digital signature for data; via an electrical probe, a first setting device sets a first key into the secure memory of each of the integrated circuit chips, and the electrical probe contacts a contact pad on the semiconductor wafer; after the semiconductor wafer is sliced, via a probe of the integrated circuit chip, a second setting device sets a second key into the secure memory of each of the integrated circuit chips, wherein the second setting device and the first setting device are separate and independent; receiving a setting report from each of the integrated circuit chips, the setting report includes a digital signature, and the digital signature is calculated by the programmable logic using the first key and the second key; and verifying the setting steps based on the digital signature.

2. The method according to claim 1, characterized in that, the step of setting the first key occurs during a process of testing the integrated circuit chips on the wafer using the electrical probe.

3. The method according to claim 1, characterized in that, the step of setting the second key occurs during a process of testing each of the integrated circuit chips.

4. The method according to claim 1, characterized in that, further includes: loading code into each of the integrated circuit chips for execution by the programmable logic, the code is signed using a trusted signature, and the setting report is received from each of the integrated circuit chips after loading the code.

5. The method according to claim 1, characterized in that, the step of receiving the setting report includes receiving a public key from each of the integrated circuit chips for communicating with the integrated circuit chip, wherein the public key is signed using the first key and the second key.

6. The method according to claim 1, characterized in that, the step of receiving the setting report includes receiving a first security authentication and a second security authentication generated by each of the integrated circuit chips, and the first security authentication and the second security authentication are related to the first key and the second key.

7. The method according to claim 6, characterized in that, further includes: storing the first security authentication and the second security authentication in a repository, periodically checking whether there are duplicates of the first security authentication and the second security authentication in the repository, and issuing an alarm when a duplicate is detected.

8. A system for setting an electronic device, characterized in that, includes: An electrical probe for contacting contact pads on a semiconductor wafer, on which a plurality of fabricated integrated circuit chips are provided, each of the integrated circuit chips including a secure memory and programmable logic, the programmable logic being used to store at least two keys in the secure memory and to calculate a digital signature for data using the at least two keys; A connector for connecting the pins of each of the integrated circuit chips after the wafer is sliced; and At least one setting device, a first setting device in the at least one setting device being used to set a first key into the secure memory of each of the integrated circuit chips via the electrical probe, the electrical probe being in contact with the semiconductor wafer, and after the semiconductor wafer is sliced, a second setting device in the at least one setting device setting a second key into the secure memory of each of the integrated circuit chips via the connector and the pins, wherein the second setting device and the first setting device are separate and independent, and the second setting device is used to receive a setting report from each of the integrated circuit chips, the setting report having a digital signature calculated by the programmable logic using the first key and the second key, and to verify the setting based on the digital signature.

9. The system according to claim 8, wherein, The setting of the first key by the at least one setting device occurs during a process of testing the integrated circuit chips on the wafer using the electrical probe.

10. The system according to claim 8, wherein, The setting of the second key by the at least one setting device occurs during a process of testing each of the integrated circuit chips.

11. The system according to claim 8, wherein, After loading code into each of the integrated circuit chips for execution by the programmable logic, the setting report is received from each of the integrated circuit chips, and the code is signed using a trusted signature.

12. The system according to claim 8, wherein, The setting report received from each of the integrated circuit chips includes a public key for communicating with the integrated circuit chip, wherein the public key is signed using the first key and the second key.

13. The system according to claim 8, wherein, The setting report includes a first security authentication and a second security authentication generated by each of the integrated circuit chips, the first security authentication and the second security authentication being related to the first key and the second key.

14. The system according to claim 13, wherein, It further includes a server, the server being used to store the first security authentication and the second security authentication in a repository, and to periodically check whether there are duplicates of the first security authentication and the second security authentication in the repository, and to issue an alarm when a duplicate is detected.

15. An integrated circuit chip, wherein, comprising: A secure memory; and Programmable logic for receiving at least a first key and a second key, the first key and the second key being set in different first and second stages during a process of manufacturing the integrated circuit chip, and for storing the keys in the secure memory, and for calculating and outputting a digital signature using the first key and the second key, wherein the first stage is performed by a first setting device, the second stage is performed by a second setting device, and the first setting device and the second setting device are separate and independent.

16. The integrated circuit chip according to claim 15, wherein, the programmable logic is configured to receive the first key, and the programmable logic receives the first key during a process of applying an electrical probe to test the integrated circuit chip, the electrical probe being connected to a wafer on which a plurality of the manufactured integrated circuit chips are located.

17. The integrated circuit chip according to claim 15, wherein, the programmable logic is configured to receive the second key during a process of testing the integrated circuit chip after wafer dicing.

18. The integrated circuit chip according to claim 15, wherein, the programmable logic is configured to output a setup report including the digital signature after loading code into the integrated circuit chip, the code being signed using a trusted signature.

19. The integrated circuit chip according to claim 18, wherein, the setup report output by the programmable logic includes a public key for communicating with the integrated circuit chip, wherein the public key is signed by the programmable logic using the digital signature, and the digital signature uses the first key and the second key.

20. The integrated circuit chip according to claim 18, wherein, the setup report includes a first security authentication and a second security authentication generated by the programmable logic, and the first security authentication and the second security authentication are related to the first key and the second key.

Citation Information

Patent Citations

  • Systems and methods for secure provisioning of production electronic circuits

    US9430658B2

  • Security-protection of a wafer of electronic circuits

    US20120250429A1

  • Secure provisioning of secret keys during integrated circuit manufacturing

    US20140093074A1