Active shielding structure
Patent Information
- Application Number
- CN202180048250.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-20
- Filing Date
- 2021-07-09
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2041-07-09
AI Technical Summary
[0004]本公开旨在解决传统主动屏蔽件可能无法充分防止电磁(EM)侧信道攻击的问题
[0007] Therefore, this disclosure provides an integrated shielding structure that combines active tamper protection and electromagnetic countermeasures.
Smart Images

Figure CN115836596B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to integrated electronic circuits, and more specifically, to active shielding structures for tamper protection and electromagnetic (EM) side-channel mitigation. Background Technology
[0002] This section aims to provide information relevant to understanding the various techniques described herein. As the title of this section suggests, this is a discussion of related techniques and should in no way imply that they are prior art. Generally speaking, related techniques may or may not be considered prior art. Therefore, it should be understood that any statement in this section should be interpreted in this sense and does not constitute any endorsement of prior art.
[0003] Sometimes, integrated electronic circuits may require tamper protection, which typically involves detecting cuts in metal interconnects and reporting alarms based on activity signals traveling through drawn metal shielding. Such detection techniques often involve forming metal wires with a tight pitch that prevents cutting the opening without interrupting signal transmission. Furthermore, in some cases, electromagnetic side-channel analysis (ESA) may involve using microscopic wires scanned on the front or back surface of an integrated circuit to pick up electromagnetic energy from internal circuit operations, which is often used to discover secret keys in cryptographic operations. Unfortunately, standard active shielding alone may not prevent side-channel attacks from ESA. Therefore, there is a need to improve conventional active shielding to protect sensitive circuits from ESA and / or various similar types of side-channel attacks. Summary of the Invention
[0004] This disclosure aims to address the problem that conventional active shielding may not adequately protect against electromagnetic (EM) side-channel attacks.
[0005] To address this problem, this disclosure provides an active shielding structure in which a first coil-shaped helical structure and a second coil-shaped helical structure wound between the windings of the first coil-shaped helical structure are arranged to provide tamper protection and electromagnetic shielding to the underlying circuitry.
[0006] In some implementations, the coil-shaped helical structure is configured to generate an electromagnetic field that can mask radiation from the underlying circuitry while also detecting tampering attempts.
[0007] Therefore, this disclosure provides an integrated shielding structure that combines active tamper protection and electromagnetic countermeasures. Attached Figure Description
[0008] This document describes specific implementations of various techniques with reference to the accompanying drawings. However, it should be understood that the drawings merely illustrate the various specific implementations described herein and are not intended to limit the implementation methods of the various techniques described herein.
[0009] Figures 1A to 1C A diagram is shown illustrating the active shielding coil structure according to various specific embodiments described herein.
[0010] Figures 2A to 2C Various diagrams are shown of active shielding structures in combination with various specific embodiments described herein.
[0011] Figure 3 Diagrams of control logic circuits according to various specific implementations described herein are shown.
[0012] Figure 4 Different schemes for feeding power to a protected circuit according to various specific implementations described herein are shown.
[0013] Figure 5 A flowchart is shown of a method for providing an active shielding structure according to a specific implementation described herein.
[0014] Figure 6 Another flowchart is shown for a method of providing an active shielding structure according to a specific implementation described herein. Detailed Implementation
[0015] The various specific implementations described herein relate to active tamper protection (ASH) schemes and techniques for a variety of tamper protection applications. For example, the various schemes and techniques described herein provide a unified coil-based active tamper protection shield and electromagnetic (EM) analysis countermeasures circuitry. The various schemes and techniques described herein combine protection countermeasures against physical modifications and detection of the circuitry with countermeasures against electromagnetic (EM) side-channel analysis and / or various other types of similar attacks.
[0016] The various schemes and techniques described herein can be used to modify the physical layout design of an active shielding element (ASH) in a manner that generates strong electromagnetic (EM) characteristics, thereby masking radiation from internal logic operations without consuming any additional circuit area on the integrated circuit (IC). To achieve this, the various schemes and techniques described herein can arrange metal wires to actively tamper with the protective shielding element by forming coil shapes with the form factor of an inductor (e.g., coil or loop structure). These coiled metal wires can then be induced to emit a strong magnetic field, which is used to mask electromagnetic leakage from sensitive circuitry (or cryptographic security engines) located beneath.
[0017] The various active shielding (ASH) schemes and techniques described herein can be used for combined active shielding tamper protection and electromagnetic side-channel mitigation. For example, to protect sensitive information from the electromagnetic (EM) fields generated by internal operations, the various schemes and techniques described herein provide active shielding for coil-shaped units formed to cover sensitive circuitry. Furthermore, the active coil-shaped shielding has interconnects carrying signals generated within the security circuitry and is arranged to generate an alarm signal if the coiled wires are interrupted or short-circuited during a tampering attempt. Active coil-shaped shielding can combine the protective functions of active shielding with countermeasures against EM side-channel analysis. Active coil-shaped shielding also involves modifications to the active shielding (ASH) design to maximize the EM characteristics obtained from the operation of the active shielding (ASH), thereby masking radiation from internal logic operations without consuming additional power or circuit area on the integrated circuit (IC).
[0018] The various schemes and techniques described herein provide EM noise active shielding (ASH) by shaping the active shield (ASH) into coils (or loops) instead of conventional mesh arrangements (including standard outward and backward layouts). EM noise active shielding (ASH) generates constructive interference between the EM fields generated by adjacent wire segments to enhance the EM noise generated relative to the power used to drive the active shield (ASH). The space between coils can be protected against tampering using a standard or regular mesh layout. VDD and VSS are used to deliver power to the circuitry below the ASH and to prevent short circuits in adjacent ASH segments that are part of the same loop. In some cases, the use of Vss or Vdd lines can be referred to as trip lines. The purpose of trip lines is to prevent signal propagation in cases where a tampering attack involves short-circuiting adjacent ASH lines to disable loops outside the short circuit. Widening the ASH lines of the coils and narrowing the trip lines can be used to reduce the RC line load per unit length, allowing longer lines to be driven with the same ASH transmission (Tx) driver. Furthermore, when no power transmission is required, the Vss line (or Vdd line) can be used as a standalone trip line and kept narrow in width to maintain tamper protection while maximizing the usable area of the coil turns. Additionally, the signaling and / or delay of the Active Shield (ASH) can be registered with the activity of the underlying cryptographic circuitry, and the clock frequency and / or phase can be registered so that the signal delay of the ASH coil can be registered to cover various data path delays within the cryptographic circuitry. This ensures that the ASH generates EM noise at the correct time.
[0019] This article will refer to Figures 1A to 5 Provide a detailed description of the various specific implementations of active shielding protection schemes and technologies.
[0020] Figures 1A to 1CVarious figures are shown of the active shielding coil structure 102 according to various specific embodiments described herein. Specifically, Figure 1A A top view 100A of the active shielding coil structure 102 is shown. Figure 1B Another top view 100B of the active shielding coil structure 102 is shown, and Figure 1C A top view 100C of the active shield coil structure 102 is also shown.
[0021] In various specific implementations, the active shielding structure 102 can be implemented as a device or circuit having various components arranged and coupled together as an assembly or combination of parts providing physical circuit layout design and associated structures. In some cases, the method of designing, providing, and constructing the active shielding coil structure 102 as an integrated device or circuit may involve using the various components described herein to thereby implement various active shielding technologies associated therewith. The active shielding coil structure 102 can be integrated with various control circuits and associated components on a single chip, and the active shielding coil structure 102 can be implemented in various embedded systems for automotive, electronic, mobile, computing, and Internet of Things (IoT) applications.
[0022] like Figure 1A As shown, the active shielding coil structure 102 may include a first coil-shaped helical structure 104 carrying the signal of the shield. In some cases, the active shield may refer to conductive interconnects used for transmitting and receiving characteristic analog signals or digital codes between a transmitting node (Tx) and a receiving node (Rx). Furthermore, the active shield may be configured such that multiple conductive interconnects cover (or superimpose) areas of sensitive circuitry (e.g., cryptographic circuitry) disposed below the active shield at routing and device levels. The first coil-shaped helical structure 104 may be formed from a first conductor, and the first coil-shaped helical structure 104 may be formed in a conductive layer such as a metal layer. Furthermore, the first coil-shaped helical structure 104 may be formed as a first continuous coil-shaped helical structure.
[0023] The active shielding coil structure 102 may include a second coil-shaped spiral structure 108 wound between the windings of the first coil-shaped spiral structure 104. The second coil-shaped spiral structure 108 may be formed from a second conductor similar to the first conductor, and may be formed in the same layer as the first conductor. Furthermore, in some cases, the width of the first conductor may be greater than the width of the second conductor. Additionally, the second coil-shaped spiral structure 108 may be formed as a second continuous coil-shaped spiral structure. In some cases, the second coil-shaped spiral structure 108 may be referred to as a trip line coupled to a fixed potential (e.g., Gnd, Vss, or Vdd). Furthermore, the trip line 108 may refer to a metal wire inserted between each adjacent segment of the signal line 104, which is part of the same ASH loop. Without the trip line 108, adjacent wires could short-circuit without detection, and an attacker could freely tamper with the signal loop / wire area outside the short circuit. In various specific implementations, the Vss line or Vdd line can be used as a trip line, where the potential of the Vss line and / or Vdd line may also be needed to transfer power to the underlying circuitry.
[0024] In some specific implementations, as described below, the first coil-shaped helical structure 104 can be coupled to a signal generator (e.g., Figure 3 (308 in the diagram) This signal generator is used to generate an electromagnetic (EM) signal across the active shield, and the second coil-shaped helical structure 108 can be coupled to a reference potential, such as ground (Gnd or Vss) or a supply voltage (Vdd). For example, the EM signal can travel via a transmitting node (Tx1) through the first coil-shaped helical structure 104 to a receiving node (Rx1), wherein the transmitting node (Tx1) can be coupled to the first active shield transmitting pin (ASH1_out), and wherein the receiving node (Rx1) can be coupled to the first active shield return pin (ASH1_return). Furthermore, in some cases, a through-wire 114 can be used to couple the first coil-shaped helical structure 104 to the first active shield return line (ASH1_return), which can be formed in a different metal layer than the metal layer used to form the coil-shaped helical structures 104, 108. Additionally, one or more vias are used to couple the through-wire 114 to the first active shield transmitting line (ASH1_out) and the first active shield return line (ASH1_return).
[0025] In various specific implementations, the first coil-shaped helical structure 104 and the second coil-shaped helical structure 108 can be disposed in the same layer superimposed on the cryptographic circuit, and the frequency of the EM signal can also be registered with or harmonicized to the operating frequency of the cryptographic circuit. Furthermore, in some cases, the phase of the EM signal frequency can be registered with the phase of the operating frequency of the cryptographic circuit. Therefore, the first coil-shaped helical structure 104 and the second coil-shaped helical structure 108 can provide a combined coil-based active tamper protection shield as a countermeasure circuit for protecting the underlying circuit from unauthorized attempts to access signals or physically modify the underlying circuit. Additionally, in some cases, the first coil-shaped helical structure 104 can provide an electromagnetic (EM) signal generator based on a cooperating coil as a countermeasure circuit for protecting the confidentiality of operations performed by the underlying circuit.
[0026] Furthermore, in various specific implementations, other regions 118 adjacent to the coil-shaped helical structures 104, 108 may have standard active shielding (e.g., if they include circuitry requiring physical tamper protection). These other regions 118 may include boundary regions in the periphery of the metal layer and / or central regions near the inner windings of the coil-shaped helical structures 104, 108.
[0027] In some specific implementations, the pitch of the coil conductor 104 can be slightly increased (e.g., in...). Figure 1A (at the top left corner). For example, if coil wire 104 has a pitch P, the pitch of coil wire 104 can be increased over a certain number of coil wire turns to ensure that there are no large gaps between the windings. Figure 1A As shown, the increased pitch can be formed within three turns. In practical layouts, the increased pitch can be achieved using an automatically changing script, and if the required number of turns is N, the increase in pitch can be reduced to P / N. In some cases, the coil conductor 104 can have 40 turns, so the pitch variation can be very small and all areas can be protected. Furthermore, any displacement of the wire may need to be snapped into the design grid in practice, such as in... Figure 1A In the example shown, the layout design can revert to the original layout before reaching the center of the coil conductor 104, based on the minimum design grid of the pitch ratio, number of turns, and / or physical layout design.
[0028] like Figure 1BAs shown, the array of active shielding coil structures 102 (ASH) can be arranged in a grid pattern across the same layer covering (or superimposed on) sensitive circuitry (e.g., cryptographic circuitry). In some cases, the array of active shielding coil structures 102 can be arranged in suitable configurations, such as a two-dimensional (2D) array with any number (N) of columns and any number (M) of rows (ASH_1:1, ASH_2:1...ASH_N:M) arranged in a 2D grid pattern. In some cases, each active shielding coil structure 102 can have its own ASH_N:M_out line and ASH:N:M_return line for allowing EM signals to pass through. Furthermore, multiple rows of this arrangement can extend tamper protection along the y-direction. In some specific implementations, adjacent coils can be driven with different current directions to minimize the overall cancellation of electromagnetic (EM) fields.
[0029] like Figure 1C As shown in top view 100C, the active shielding (ASH) coil layer 102 may include active shielding (ASH) coil structures 134A, 134B, 134C, 134D and a protected area 130. Furthermore, Figure 1C The protected area 130 is shown to be tamper-proof by ASH coil structures 134A to 134D and their feed. In some cases, each of the square areas 134A to 134D may refer to an ASH coil structure. If the square areas 134A to 134D are drawn to scale, the height of areas 130A to 130B may refer to a portion of the height of the ASH coil structures 134A to 134D. Therefore, regarding an attacker's coil probe (whose diameter may be much larger than the height of the feed areas 130A to 130B), this may not be considered a "protected gap".
[0030] Figures 2A to 2C Various figures are shown of the active shielding structure 202 according to a specific embodiment described herein. Specifically, Figure 2A A top view 200A of the combined active shielding structure 202 is shown. Figure 2B Another top view 200B of the combined active shielding structure 202 is shown, and Figure 2C A top view 200C of the combined active shielding structure 202 is shown.
[0031] In various specific implementations, the combined active shielding structure 202 can be implemented as a device or circuit having various components arranged and coupled together as an assembly or combination of parts providing physical circuit layout design and associated structures. In various cases, methods for designing, providing, and constructing the combined active shielding structure 202 within an integrated device or circuit may involve using the various components described herein to thereby implement various active shielding schemes and techniques associated therewith. Furthermore, the combined active shielding structure 202 can be integrated with various control circuits and associated components on a single chip, and the combined active shielding structure 202 can be implemented in various embedded systems for automotive, electronic, mobile, and Internet of Things (IoT) applications, including remote sensor nodes.
[0032] For reference Figure 2A As shown, the combined active shielding structure 202 may include a first type of active shielding having a coil-shaped structure (e.g., a combination of 104, 108, and 114), for example... Figure 1A The active shielding coil structure 102 is described. In some cases, the first type of active shielding (104, 108, 114) may be formed by a first conductor (104, 114) and a second conductor (108) wound between the first conductor (104, 114). The width of the first conductor (104, 114) may be greater than the width of the second conductor (108). The first type of active shielding (104, 108, 114) may be formed in a conductive layer such as a metal layer. In some specific embodiments, the first conductor (104, 114) may carry the signal of the active shielding (e.g., along the direction of the signal line). Furthermore, the second conductor (108) may have the intended purpose of preventing short circuits between adjacent signal lines, which could cause the shielding to fail beyond the short-circuit position. The second conductor (108) may be referred to as a "trip line".
[0033] Furthermore, the combined active shielding structure 202 may include a second type of active shielding (204, 208) having a linear or mesh structure, disposed adjacent to the first type of active shielding (104, 108, 114). In some cases, the second type of active shielding (204, 208) may be referred to as a standard active shielding having multiple conductors configured as a linear or mesh structure. In some cases, the second type of active shielding (204, 208) may be formed by a third conductor (204) and a fourth conductor (208) disposed side by side with the third conductor (204), and the width of the third conductor (204) may be smaller than the width of the fourth conductor (208) because power needs to pass through the metal layer of the shielding. The second type of active shielding (204, 208) may be formed in the same conductive layer, such as the same metal layer.
[0034] In some specific implementations, the first type of active shielding (104, 108, 114) and the second type of active shielding (204, 208) can be combined in a single metal layer (e.g., the same metal layer) to provide active tamper protection shielding and electromagnetic (EM) shielding as a combined countermeasure circuit to protect the underlying cryptographic circuitry from physical tampering and electromagnetic side-channel attacks. Furthermore, other regions 118 adjacent to the coil-shaped helical structure (104, 108) can have standard active shielding. These other regions 118 may include boundary regions in the periphery of the metal layer and / or the central region near the inner winding of the coil-shaped helical structure (104, 108).
[0035] In some specific implementations, as described in more detail below, the first conductors (104, 114) may be coupled to a signal generator (e.g., Figure 3 In section 308), the signal generator drives the signal across a first type of active shield, and the second conductor (108) can be coupled to ground (Gnd or Vss) or power supply (Vdd). The signal can travel through the first conductor (104, 114) via a transmitting node (Tx1) and a receiving node (Rx1), where the transmitting node (Tx1) can be coupled to the first active shield transmission line (ASH1_out as a connection point), and where the receiving node (Rx1) can be coupled to the first active shield return pin (ASH1_return as another connection point). The signal driven by the transmitter is an electrical signal (i.e., current), and this electrical signal traveling along the wire emits an electromagnetic (EM) field (e.g., due to Maxwell's laws and / or Ampere's law). Furthermore, the arrangement of the signal lines in the coil can cause constructive interference between the EM fields generated around each wire segment, while the grid layout of a standard active shield can cause field cancellation because adjacent wire segments can have opposite current directions. ASH1_out and ASH1_return refer to the connection points (or pins) of the signal lines, consisting of 104 and 114 and including vias. Furthermore, using one or more vias, a through-wire (114) can be used to couple a first conductor (104, 114) to a first active shield return line (ASH1_return), which can be formed in a different metal layer than the metal layer used to form the coil-shaped helical structure (104, 108).
[0036] Furthermore, in some specific implementations, as described in more detail below, the third conductor (204) may be coupled to a signal generator (e.g., Figure 3In section 308), the signal generator provides a signal across the second type of active shield, and the fourth conductor (208) can also be coupled to ground (Gnd or Vss) or power supply (Vdd). In principle, the "trip line" can be another reference potential that allows detection of a short circuit in the signal line by means of a blocked signal transmission or a pulled reference potential or current. In some cases, the power supply (Vdd) and ground (Vss) must be fed into the circuit protected by the active shield, so it is advantageous to use Vdd and Vss feedthroughs as the potentials for the trip line. Furthermore, in some cases, different signal generators can be used to drive the ASH coil from the right or left side. For example, consider... Figure 2C Regions 230A (coil feed) and 234A to 234D (coils) can be driven by the signal generator on the right, and region 230C can be driven by another signal generator on the left. The signal can travel through the third conductor (204) via the transmitting node (Tx2) and the receiving node (Rx2), wherein the transmitting node (Tx2) can be coupled to the second active shielding transmit line (ASH2_out), and wherein the receiving node (Rx2) can be coupled to the second active shielding return line (ASH2_return).
[0037] In some cases, the required number of TX and RX per loop is 1. In principle, all coils can be connected in series. However, EM noise will sweep from one coil to the next. Therefore, each coil can be no larger than the smallest practical coil an attacker would use for an EM side-channel attack (e.g., no more than a few hundred micrometers). Therefore, using coils with diameters similar to the attack coils to sweep from one coil to the next can lead to a "vulnerability" in the protection. Therefore, in some specific implementations, at least 5 independent TX and 5 RX circuits can be used. Figure 2C In one example, one is used for each coil on the right side, and at least one is used for area 230C. In another example, a total of 8 ASH coils can be used, such as 4 on the left and 4 on the right.
[0038] like Figure 2B As shown, an array of combined active shielding structures 202 (C_ASH) can be arranged in a 2D grid pattern across the same layer covering (or superimposed on) sensitive circuitry (e.g., cryptographic circuitry), wherein each of the C_ASH structures can be coupled to, for example, Figure 2AThe feed is shown. In some cases, the array of combined active shielding structures 202 can be arranged in some suitable configurations, such as a 2D grid array having any number (N) of columns (C_ASH_1, C_ASH_2...C_ASH_N) and any number (M) of rows (C_ASH_1, C_ASH_2...C_ASH_M) arranged in a 2D grid pattern. Furthermore, each coil forms a loop driven separately from ASH_out and received in RX at the ASH_return pin. In some cases, each combined active shielding structure 202 may have its own ASH1_out line, ASH2_out line, ASH1_return line, and ASH2_return line, through which the EM signal is passed, wherein each loop is driven individually to prevent loss of protection against EM side-channel attacks.
[0039] like Figure 2C As shown in top view 200C, the combined active shielding (C_ASH) layer 202 may include combined active shielding (C_ASH) structures 234A, 234B, 234C, 234D and a protected area 230. Furthermore, Figure 2C This illustrates that the protected area 230 can be tamper-proofed by C_ASH structures 234A to 234D and their feeds. In some cases, each of the square areas 234A to 234D refers to a C_ASH structure. For example... Figures 2A to 2B As shown, the combined active shielding structure 202 can be formed in the protected area 230 with wide ASH lines and narrow Vss lines (or trip lines) to enable the driving of long coil lines (i.e., reducing the RC load per unit length). The Vss lines (or trip lines) can be widened in the area where power is fed from the power distribution network at the higher metal layer to the sensitive circuit 228 located below the C_ASH shielding layer 224. This concept allows vias to land from the higher metal layer, which allows for a larger minimum line and space design regularity in the layer where the shielding is implemented. Furthermore, this concept can involve Vdd and Vss in terms of the power distribution network. Additionally, Vdd lines (or Vss lines) (as may be provided in standard shielding) can be reintroduced so that vias can land from the higher metal layer to thereby transfer power downwards. If the higher metal layer has a larger pitch than the metal layers of the shielding, the vias can land on a metal shape in the C_ASH shielding layer 224 that is larger than the minimum regularity. Therefore, the Vss line (or trip line) located outside the coil shielding structure can alternate between Vdd and Vss. The ASH line can be formed entirely within one of the same metal layers. Furthermore, outside the coil shielding structure, the Vdd and Vss lines can be formed to be relatively wider than the ASH line.
[0040] Figure 3 Figure 300 illustrates a system of control logic circuits 302 according to various specific implementations described herein. In some implementations, multiple control logic circuits 302 may be implemented to independently drive each active shield (ASH) coil and / or each standard active shield with separate TX / RX signals.
[0041] In various specific implementations, the control logic circuit 302 can be implemented as a device or circuit having various components arranged and coupled together as an assembly or combination of parts providing physical circuit layout design and associated structures. In some cases, the method of designing, providing, and constructing the control logic circuit 302 as an integrated device or circuit may involve using the various components described herein to thereby implement various active shielding schemes and techniques associated therewith. The control logic circuit 302 can be integrated with various control circuits and associated components on a single chip, and the control logic circuit 302 can be implemented in various embedded systems for automotive, electronic, mobile, and Internet of Things (IoT) applications.
[0042] like Figure 3 As shown, the control logic circuit 302 can refer to a number of (N) Active Shielded (ASH) signal generators (308A, 308B...308N) configured to receive input signals and provide various output signals based on the input signals. In some cases, signals can be generated and driven into signal lines, then received back (as a return signal), and internal characteristics can be compared, which can be achieved by checking the propagation of digital states. Short-circuiting the trip line can pull the signal and prevent the reception of the transmitted signal. Therefore, in Figure 3 In this context, ground refers to the ground pin (Vss) that the circuit uses to operate, identical to the Vdd pin. Additionally, control inputs may exist, where digital codes are applied in each clock cycle, for example, via a control interface. In some cases, the input signal may refer to one or more input clock signals (CLK_In). Furthermore, the output signal may refer to multiple sets of ASH signals capable of supporting at least one ASH_EM (e.g., ASH1_out as output, ASH1_return as input, etc.), where the ASH1_out signal refers to the first transmit signal for the transmitting node (Tx1) and the first receive signal for the receiving node (Rx1). As described herein, the EM signal can travel through the first coil-shaped helical structure 104 via the transmitting node (Tx1) and the receiving node (Rx1) (e.g., in...). Figure 1AIn the first active shielded transmit line (ASH1_out), the transmitting node (Tx1) can be coupled to the first active shielded return line (ASH1_return), and the receiving node (Rx1) can be coupled to the first active shielded return line (ASH1_return). This idea can be repeated for multiple ASH signal generators (e.g., 308A, 308B...308N) and their corresponding ASH output / return signals (e.g., ASH1_out / ASH1_return, ASH2_out / ASH2_return...ASHN_out / ASHN_return).
[0043] In some cases, a certain number (N) of TX / RX pairs can be used, where N can depend on the length of the wire that a single TX / RX can drive and the total area requiring tamper protection. For example, a single ASH signal generator can have one TX and one RX, and a certain number (N) of instances of a single ASH signal generator can be used. Furthermore, as described herein, the EM signal can travel through the first linear structure 204 via the transmitting node (Tx2) and the receiving node (Rx2) (e.g., in...). Figure 2A In the configuration, the transmitting node (Tx2) can be coupled to the second active shielding transmit line (ASH2_out), and the receiving node (Rx2) can be coupled to the second active shielding return line (ASH2_return). Furthermore, in some cases, the ASH signal generators (308A, 308B…308N) can be configured to provide corresponding alarms (e.g., Alarm_1, Alarm_2…Alarm_N) when a tampering event has been detected.
[0044] Figure 4 Figure 400 shows various configurations (408A, 408B, 408C) of specific implementations described herein for feeding power (e.g., Vdd, Vss) to the ASH protection circuit 402 below the active shield (ASH) 404.
[0045] In various specific implementations, such as Figure 4As shown, a first configuration where power feeds (e.g., Vdd, Vss) are located around the periphery 420 of the ASH protected circuit 402 and laterally distributed in the metal layer below the active shield (ASH) 404 can refer to configuration 408A from left to right. Furthermore, a second configuration 408B with feeds and other power circuitry aligned with the coil center and requiring no tampering protection is shown as a distributed configuration 408B. Additionally, a third configuration 408C refers to a combined configuration where a combination with a linear or mesh shield is used to protect the space between the coils, providing Vdd and Vss feeds down from the higher metal layer to the underlying circuitry. Regarding the combined configuration 408C, the EM generated by the combined ASH (i.e., C_ASH) coils can extend laterally beyond the coils to still provide protection against EM side-channel attacks against the underlying circuitry in the area covered by the linear or mesh active shield.
[0046] Figure 5 A flowchart is shown of a method 502 for providing an active shielding structure according to a specific implementation described herein.
[0047] It should be understood that even though method 500 specifies a particular order of operations, in some cases, the specific parts of the operations may be executed in a different order and on different systems. In other cases, additional operations and / or steps may be added to method 500 and / or omitted from the method. Furthermore, method 500 can be executed using software scripts as part of the digital implementation flow of a hardware design. If executed using software scripts, method 500 can be parameterized to adapt various features of the design implementation to the requirements of the underlying circuitry.
[0048] In various specific implementations, method 500 can refer to a method of designing, constructing, manufacturing, and / or producing active shielding circuitry as an integrated system, device, and / or circuit. This may involve using various IC circuit components described herein to implement associated active shielding schemes and techniques. In some specific implementations, combining standard active shielding (as a countermeasure against physical tampering) with active shielding coils (as a countermeasure against EM side-channel attacks) provides a noisy active shielding, where noise is used to resist EM attacks. Furthermore, in some specific implementations, active shielding circuitry can be integrated with various control circuits and related components on a single chip, and active shielding circuitry can be implemented in various embedded systems for various electronic, mobile, and Internet of Things (IoT) applications, including remote sensor nodes.
[0049] At block 510, method 500 can provide a first active shield having a first coil-shaped structure. At block 514, method 500 can provide a second active shield having a second coil-shaped structure. At block 518, method 500 can form an active coil-shaped shield by spirally winding the second coil-shaped structure together with the first coil-shaped structure. At block 522, method 500 can arrange multiple active coil-shaped shields in a grid pattern. In some cases, each active coil-shaped shield can be formed by winding the first and second active shields together to form a first type of active shield structure. At block 526, method 500 can provide a third active shield having a first linear structure. At block 530, method 500 can provide a fourth active shield having a second linear structure. At block 534, method 500 can form an active linear shield by arranging the fourth linear structure alongside the third linear structure. At block 538, method 500 can arrange multiple active linear shields between multiple active coil-shaped shields. In some cases, each active linear shield has a third and a fourth active shield arranged together to form a second type of active shield structure.
[0050] In some specific implementations, the first type of active shield and the second type of active shield can be combined in a single metal layer (i.e., the same metal layer) to provide active tamper protection shield and / or electromagnetic (EM) shield as countermeasure circuitry for covering sensitive circuits and / or protecting underlying cryptographic circuits from unauthorized access.
[0051] Figure 6 A flowchart of another method 602 for providing an active shielding structure according to a specific implementation described herein is shown.
[0052] It should be understood that even though method 600 specifies a particular order of operations, in some cases, the specific parts of the operations may be executed in a different order and on different systems. In other cases, additional operations and / or steps may be added to method 600 and / or omitted from the method. Furthermore, method 600 can be executed using software scripts as part of the digital implementation flow of a hardware design. If executed using software scripts, method 600 can be parameterized to adapt various features of the design-specific implementation to the requirements of the underlying circuitry.
[0053] In various specific implementations, method 600 can refer to a method of designing, constructing, manufacturing, and / or producing active shielding circuitry as an integrated system, device, and / or circuit. This may involve using various IC circuit components described herein to implement associated active shielding schemes and techniques. In some implementations, combining standard active shielding (as a countermeasure against physical tampering) with active shielding coils (as a countermeasure against EM side-channel attacks) provides a noisy active shielding, where noise is used to resist EM attacks. Furthermore, in some implementations, active shielding circuitry can be integrated with various control circuits and related components on a single chip, and active shielding circuitry can be implemented in various embedded systems for various electronic, mobile, and Internet of Things (IoT) applications, including remote sensor nodes.
[0054] At box 610, method 600 can identify the target area of sensitive circuitry requiring active shielding tamper protection. At box 614, method 600 can define various cell attributes, including, for example, the linewidth and / or spacing of signals (e.g., VDD, VSS), and at box 614, method 600 can also provide escape directions for ASH loops, including, for example, ASH coils, ASH_out feeds, ASH_return feeds, and / or standard ASH regions. At box 618, method 600 can use scripts and / or custom designs to generate coil layouts. At box 622, method 600 can simulate coil delay based on loop impedance and TX drive strength. At decision box 626, method 600 can determine whether the ASH delay is registered with the circuit delay. If not registered, method 600 returns to box 614. Otherwise, if registered, method 600 proceeds to box 630. At box 630, method 600 can specify a coil tile, which may include a number of (M) columns and a number of (N) rows, as well as horizontal and vertical pitches. At box 634, method 600 can generate the ASH layout using scripts and / or custom designs. At box 638, method 600 can simulate the ASH loop delay based on loop impedance and / or TX drive strength. At decision box 642, method 600 can determine whether the ASH delay is registered with the circuit delay. If not registered, method 600 returns to box 614. Otherwise, if registered, method 600 proceeds to box 646. At box 646, method 600 can verify power delivery. At decision box 650, method 600 can determine whether the ASH delay is registered with the circuit delay. If not registered, method 600 returns to box 614. Otherwise, if registered, method 600 proceeds to box 654. At box 654, method 600 can place control logic.
[0055] It should be anticipated that the subject matter of the claims is not limited to the specific embodiments and illustrations provided herein, but includes modifications of those embodiments according to the claims, including portions of the embodiments and combinations of elements from different embodiments. It should be understood that in the development of any such embodiment, as in any engineering or design project, many embodiment-specific decisions will be made to achieve the developer's specific objectives, such as compliance with system-related and business-related constraints, which may vary between different embodiments. Furthermore, it should be understood that such development work can be complex and time-consuming; however, it remains a routine task of design, manufacture, and production for those skilled in the art who benefit from this disclosure.
[0056] This document describes various specific embodiments of a device. The device may include a first coil-shaped helical structure for active shielding. The device may also include a second coil-shaped helical structure wound between windings of the first coil-shaped helical structure. The first coil-shaped helical structure can provide a coil-based EM shield as a countermeasure circuit for protecting the underlying circuitry.
[0057] This document describes various specific embodiments of a device. The device may include a first type of active shielding element having a coil-shaped structure. The device may also include a second type of active shielding element having a linear structure disposed adjacent to the first type of active shielding element. Both the first and second types of active shielding elements can provide active tamper protection shielding and EM shielding as countermeasure circuitry for protecting underlying cryptographic circuitry.
[0058] This document describes various specific implementations of a method. The method can provide a first active shield having a first coil shape structure, and the method can also provide a second active shield having a second coil shape structure. The active coil shape shield can be formed by spirally winding the second coil shape structure together with the first coil shape structure. The first and second types of active shields can provide active tamper protection shields and EM shields as countermeasure circuits for protecting underlying cryptographic circuits.
[0059] Various specific implementations have been referenced in detail, examples of which are shown in the accompanying drawings and illustrations. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the disclosure provided herein. However, the disclosure provided herein can be practiced without these specific details. In some other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure the details of the implementation.
[0060] It should also be understood that while the terms "first," "second," etc., may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. Both the first and second elements are elements, but they are not considered the same element.
[0061] The terminology used in the description of this disclosure provided herein is for the purpose of describing particular specific embodiments and is not intended to limit the scope of the disclosure provided herein. As used in the disclosure provided herein and in the description of the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. As used herein, the term “and / or” means and covers any and all possible combinations of one or more of the associated listed items. When used in this specification, the terms “comprising,” “including,” and / or “containing” specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0062] As used herein, the term “if” can be interpreted, depending on the context, as meaning “when”, “in response to determination”, or “in response to detection”. Similarly, the phrase “if it is determined that…” or “if [the condition or event] is detected” can be interpreted, depending on the context, as meaning “in response to determination that…”, “in response to detection of [the condition or event]”, or “in response to detection of [the condition or event]”. The terms “up” and “down”; “above” and “below”; “upward” and “downward”; “below” and “above”; and other similar terms indicating the relative position above or below a given point or element may be used in conjunction with some specific implementations of the various techniques described herein.
[0063] While the foregoing relates to specific implementations of the various technologies described herein, other and additional specific implementations can be conceived based on the disclosure herein, which can be defined by the appended claims.
[0064] Although the subject matter has been described in language specific to structural features and / or methodological actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are disclosed as exemplary forms for implementing the claims.
Claims
1. A device for tamper protection, comprising: The first coil-shaped spiral structure is used as an active shielding component. and A second coil-shaped helical structure is wound between the windings of the first coil-shaped helical structure. The first coil-shaped spiral structure provides a coil-based electromagnetic shielding element as a countermeasure circuit to protect the underlying circuitry.
2. The device of claim 1, wherein the active shielding relates to conductive interconnects for transmitting and receiving signatures between a transmitting node and a receiving node, wherein the active shielding is configured such that a plurality of the conductive interconnects cover areas of sensitive circuitry disposed at wiring and device levels below the active shielding.
3. The device according to claim 1, wherein the first coil-shaped spiral structure is formed by a first conductor, and wherein the second coil-shaped spiral structure is formed by a second conductor separate from the first conductor, and wherein the first coil-shaped spiral structure and the second coil-shaped spiral structure are formed in the same layer.
4. The device according to claim 3, wherein the width of the first conductor is greater than the width of the second conductor.
5. The device according to claim 1, wherein the first coil-shaped helical structure comprises a first continuous coil-shaped helical structure.
6. The device of claim 1, wherein the first coil-shaped helical structure is coupled to a signal generator that provides a signal for generating an electromagnetic EM field across the active shield, and wherein the second coil-shaped helical structure is coupled to a grounded power supply.
7. The device according to claim 6, wherein the first coil-shaped helical structure and the second coil-shaped helical structure are disposed in the same layer superimposed on the cryptographic circuit, and wherein the frequency of the signal is registered with or harmonic to the operating frequency of the cryptographic circuit.
8. The device of claim 7, wherein the signal has the same frequency and phase as the digital clock driving the underlying circuitry.
9. The device of claim 1, wherein the first coil-shaped helical structure and the second coil-shaped helical structure provide a combined coil-based active tamper protection shield as a countermeasure circuit for protecting the underlying circuitry from unauthorized attempts to access signals or physically modify the underlying circuitry.
10. The device of claim 1, wherein the first coil-shaped helical structure provides countermeasures circuitry for protecting the underlying circuitry from unauthorized access via EM side-channel attacks.
11. A device for tamper protection, comprising: The first type of active shielding device has a coil-shaped spiral structure; and The second type of active shielding member has a linear structure disposed adjacent to the first type of active shielding member. The first type of active shielding includes: The first coil has a spiral structure. and The second coil-shaped spiral structure is wound between the windings of the first coil-shaped spiral structure, and wherein the first type of active shield and the second type of active shield provide active tamper protection shield and electromagnetic EM shield as countermeasure circuits for protecting the underlying cryptographic circuit.
12. The device of claim 11, wherein the first type of active shield is formed by a first conductor and a second conductor wound between the first conductor, and wherein the width of the first conductor is greater than the width of the second conductor.
13. The device of claim 11, wherein the second type of active shield is formed by a third conductor and a fourth conductor arranged side by side with the third conductor, and wherein the width of the third conductor is greater than the width of the fourth conductor.
14. The device of claim 11, wherein the first type of active shield is formed in a metal layer, and wherein the second type of active shield is formed in the metal layer.
15. The device of claim 11, wherein the first type of active shield and the second type of active shield are combined in a single metal layer to provide the active tamper protection shield and the electromagnetic EM shield as countermeasure circuitry for protecting the underlying cryptographic circuitry from unauthorized access via EM side-channel attacks.
16. A method for tamper protection, comprising: A first type of active shielding is provided, the first type of active shielding having a first coil-shaped structure; A second type of active shielding is provided, the second type of active shielding having a second coil-shaped structure; as well as An active coil-shaped shield is formed by spirally winding the second coil-shaped structure together with the first coil-shaped structure. The first type of active shield and the second type of active shield provide active tamper protection shield and electromagnetic EM shield as countermeasure circuits for protecting the underlying cryptographic circuit.
17. The method of claim 16, further comprising: The physical circuit layouts of the first type of active shielding and the second type of active shielding are automatically generated using software scripts.
18. The method of claim 16, further comprising: Multiple active coil-shaped shields are arranged in a grid pattern, wherein each active coil-shaped shield has a first type of active shield and a second type of active shield wound together to form a first type of active shield structure; Provide a third active shielding component having a first linear structure; Provide a fourth active shielding component with a second linear structure; as well as An active linear shield is formed by arranging the fourth active shield and the third active shield side by side.
19. The method of claim 18, further comprising: Multiple active linear shielding elements are arranged between the multiple active coil-shaped shielding elements. Each active linear shield has the third and fourth active shields arranged together to form a second type of active shield structure.
20. The method of claim 19, wherein the first type of active shielding structure and the second type of active shielding structure are combined in a single metal layer to provide the active tamper protection shielding and the electromagnetic EM shielding as countermeasure circuitry for protecting the underlying cryptographic circuitry from unauthorized access via EM side-channel attacks.
Citation Information
Patent Citations
System for preventing tampering with integrated circuit
US9455233B1