Electronic device and method for enhancing security of electronic device
By measuring and storing the electrical characteristic values of solid crystal welding pads during the IC manufacturing process, monitoring in real time and taking protective measures when the error exceeds the threshold, the problem of solid crystal welding pads being vulnerable is solved, and cheap and reliable IC security enhancement is achieved.
Patent Information
- Application Number
- CN202510004645.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-02-11
- Filing Date
- 2025-01-02
- Publication Date
- 2025-08-12
AI Technical Summary
The prior art is difficult to effectively prevent backside attacks through solid crystal pads of integrated circuits (ICs), especially in cheap packaging components such as QFP, QFN and TSSOP. Attackers are prone to tampering from the bottom of the packaging components, resulting in leakage of confidential information.
During the IC manufacturing process, the electrical characteristic value of the solid crystal welding pad is measured and stored as a reference value. The electrical characteristic value measurement circuit and safety control circuit are used to monitor the error in real time. If the error exceeds the threshold, protective measures such as deleting confidential data.
Direct protection of solid crystal welding pads is achieved, avoiding tampering, improving the safety of the IC, and no additional IC process steps are added, providing more reliable protection.
Smart Images

Figure CN120470633A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the security of integrated circuits (ICs), and more particularly to a device and method for detecting security attacks through IC back-end processes. Background Art
[0002] To access stored secrets, attackers sometimes attempt to physically access an IC from the back side of the IC in various leadframe packaged devices.
[0003] Currently, there are many methods to protect ICs from backside attacks. For example, Takujiet et al. published "Preventing Flip-Chip Devices from Physical Security Attacks Using Silicon Backside Protection Circuits" in IEEE Journal of Solid-State Circuits, Vol. 55, No. 10, in October 2020, which presents a cryptographic key protection technology to avoid physical security attacks through the back side of the silicon crystal of the IC chip. This article advocates the use of a backside buried metal (BBM) structure placed on the back side of the silicon crystal to form a meandering wire pattern to detect unexpected meandering wire breaks and warn of malicious behavior intended to expose the vulnerable silicon substrate. In addition, this BBM meandering wire can also protect the core information (key information) of the encryption circuit from passive side-channel attacks and active laser fault injection attacks.
[0004] U.S. Patent No. 9,965,652 discloses an IC protection device for preventing attacks on the backside security of an IC. The protection device includes an N-type well region (N-well) formed in a substrate, a P+ type center region (P+ center) disposed in the center of the N-type well region, and a P+ type ring (P+ ring) surrounding the N-type well region. A pair of N+ type rings are disposed inside and outside the N-type well region to prevent a latch-up effect. When a current is applied from the P+ type center region, the current flows through a portion of the substrate and is picked up by the P+ type ring. When an attacker mills the substrate or grooves it, the resistance value on the substrate changes. Therefore, by monitoring the voltage difference between the P+ type center region and the P+ type ring, attempts to attack the bare chip can be detected.
[0005] Finally, the Intel white paper, "Countermeasures against Large-Scale Fault Injection" by Nemiroff and Tokunaga (August 2022) (Intel ID 0822 / DCC / MZ / PDF), details the design, calibration, and verification methods of fault injection detection circuits. It also mentions the impact of fault injection attacks on circuit timing, tunable replica circuits (TRCs), high-volume manufacturing (HVM) data collection phases, calibration report creation methods, false positive detection, fault injection detection, and ultimately the HVM calibration process. Summary of the Invention
[0006] Embodiments of the present invention described herein provide an electronic device including an integrated circuit (IC) and a package component. The package component includes a die-bonding pad for connection to the IC, and the IC includes (i) a measurement circuit configured to measure an electrical characteristic value of the die-bonding pad, and (ii) a safety control circuit configured to initiate a response action based on a detected error between the measured electrical characteristic value of the die-bonding pad and an initial measurement value of the electrical characteristic value.
[0007] In some embodiments, the electrical characteristic of the die-bonding pad includes a resistance between at least two conductive lines bonded to the die-bonding pad. In other embodiments, the electrical characteristic of the die-bonding pad includes a capacitance between the die-bonding pad and an electrical junction within the IC. In one exemplary embodiment, the electrical junction includes a metal deposition layer.
[0008] In the disclosed embodiment, the IC further includes a non-volatile memory configured to store initial measurements of electrical characteristics of the die-bonding pad. The initial measurements are programmed into the non-volatile memory during manufacturing of the electronic device.
[0009] In one embodiment, the electronic device further includes an adhesive or a film for connecting the IC to the die-bonding pad.
[0010] Described herein is another method for enhancing the security of an electronic device according to an embodiment. The electronic device includes an integrated circuit (IC) and a package component, wherein the package component includes a die-bonding pad for connection to the IC. The method includes measuring an electrical characteristic of the die-bonding pad and initiating a response based on a detected error between the measured electrical characteristic of the die-bonding pad and an initial measurement of the electrical characteristic.
[0011] The disclosed embodiments provide a relatively inexpensive protection method because it does not add additional IC process steps. In addition, because the die-bonding pads that are the target of the attack are directly inspected, more reliable protection against attacks can be achieved (compared to indirect protection that relies on indirect protection effects).
[0012] The present invention will be more fully understood through the following detailed description of embodiments of the present invention in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 A block diagram of an electronic device with die-bond pad tamper protection according to an embodiment of the present invention is schematically illustrated.
[0014] Figure 2 A block diagram schematically illustrates an electronic device having a resistance-based tamper detection circuit according to an embodiment disclosed herein.
[0015] Figure 3 A block diagram schematically illustrates an electronic device having a capacitance-based tamper detection circuit according to an embodiment disclosed herein.
[0016] Figure 4 is a flow chart schematically illustrating a method for temporarily storing electrical characteristic values of a die-bonding pad in an electronic device during a manufacturing process according to an embodiment disclosed herein; and
[0017] Figure 5 is a flow chart schematically illustrating a method for protecting an electronic device online to prevent tampering with a die-bonding pad according to an embodiment disclosed herein.
[0018] Explanation of symbols
[0019] 100, 200, 300: Electronic devices
[0020] 102, 202, 302: Integrated Circuit (IC)
[0021] 104, 204, 304: Die bonding pads
[0022] 106: Electrical characteristic value measurement circuit
[0023] 108: Non-volatile memory (NVM)
[0024] 110: Safety Control Circuit (SCC)
[0025] 206: Resistance Measurement Circuit
[0026] 208A, 208B: Solder pad
[0027] 210A, 210B, 312: Wire
[0028] 212A: Area 1
[0029] 212B: Area 2
[0030] 214: Resistance
[0031] 306: Capacitance measurement circuit
[0032] 308: Floating Node
[0033] 310, 314: Bonding pads
[0034] 316: Capacitor
[0035] 400, 500: Flowchart
[0036] 402, 502: Operations for measuring electrical characteristic values
[0037] 404: Operation to write measurement values
[0038] 504: Operation to calculate error value
[0039] 506: Comparison error value operation
[0040] 508: Destroy confidential operations DETAILED DESCRIPTION
[0041] Overview
[0042] Attacks on the security of electronic devices are sometimes carried out through the die-attach pads connected to the ICs storing confidential data.
[0043] We refer to ICs that store secrets as security ICs below. Secrets such as encryption keys and authentication keys are typically stored in a memory, such as a non-volatile memory (NVM).
[0044] Security ICs are vulnerable to various techniques, such as fault injection, failure analysis, and focused ion beam (FIB) modification (among others). These techniques are often easier to perform from the backside of the IC. For example, laser fault injection for advanced semiconductor processes is most easily performed from the backside of the bare die through a transparent substrate, rather than from the front through opaque metal layers. FIB is also easiest to perform from the backside, as modern ICs can have six to ten electronic layers (sometimes more), making access from the top side of the device extremely difficult. However, FIB from the backside is relatively straightforward because all signals originate and terminate at metal-1 (the bottom metal layer).
[0045] Inexpensive leadframe packages such as the Quad Flat Package (QFP), Quad Flat No Leads Package (QFN), and Thin Shrink Small Outline Package (TSSOP) are often used for security ICs. In these packages, the die is bonded to a central metal pad (called a die-attach pad), which then bonds to surrounding pins.
[0046] For these packages, accessing the back of the die from the bottom of the package is relatively simple without damaging the die. This can be done by drilling a hole through the die-attach pad (and its adhesive), exposing the bottom of the die to attack. In contrast, drilling holes in ball grid array (BGA) packages is not a viable attack method because it is very likely to damage the package and disconnect some pins.
[0047] Embodiments of the present invention are disclosed and presented herein for detecting attacks through the die-bonding pad. In some embodiments, the electrical characteristic values of the die-bonding pad are measured during IC fabrication and stored in a NVM (referred to as electrical characteristic reference values). In one embodiment, the electrical characteristic values include the resistance through the die-bonding pad. In another embodiment, the electrical characteristic values include the capacitance between the die-bonding pad and a metal deposition layer in the IC.
[0048] In some embodiments, the IC includes a measurement circuit for measuring an electrical characteristic of the die-attach pad, and a security control circuit (SCC) for comparing the electrical characteristic to a reference value and taking protective measures (e.g., deleting stored secrets) based on the error measurement. In this embodiment, this measurement is performed once upon IC startup, protecting the IC from die-attach tampering when powered off. In other embodiments, the security control circuit continuously measures the electrical characteristic, again protecting the die-attach pad from tampering whether the IC is powered on or off.
[0049] The embodiments disclosed herein provide a relatively inexpensive protection method because it does not add additional IC process steps. In addition, because the die-bonding pads that are the target of the attack are directly inspected, more reliable protection against attacks can be achieved (compared to indirect protection that relies on indirect protection effects).
[0050] System Description
[0051] In some embodiments, an electronic device includes an IC connected to a packaged IC component via a die-bond pad. Such electronic devices may be vulnerable to attacks conducted through the die-bond pad ("hacking"). For example, an attacker could drill or otherwise penetrate the die-bond pad to access the IC and read confidential information that may be stored within.
[0052] Figure 1 The electronic device 100 is schematically illustrated as a block diagram of an embodiment of the present invention having die-bond pad tamper protection. The electronic device 100 includes an IC 102 connected to a package component (not shown) via a die-bond pad 104. The IC 102 is typically connected to the die-bond pad 104 using a suitable adhesive or film.
[0053] Any tampering with the die-bonding pad 104 , including penetration by laser beam, electron beam, mechanical drilling or other means, will inevitably change some electrical characteristics of the die-bonding pad 104 (for example, including changing the resistance value and / or capacitance value as described below).
[0054] IC 102 includes an electrical characteristic value measurement circuit 106 configured to measure an electrical characteristic value of the die-bonding pad 104, and a NVM 108 configured to store an electrical characteristic reference value. In some embodiments, NVM 108 is programmed during the manufacturing process of the electronic device as part of a final test and / or calibration process. In some embodiments, electrical characteristic value measurement circuit 106 measures the electrical characteristic value during the manufacturing process, and test equipment writes the measured value (referred to as the "reference value") to NVM 108. In other embodiments, the electrical characteristic reference value may be measured by test equipment.
[0055] IC 102 also includes a security control circuit 110. Security control circuit 110 is configured to determine the error between the electrical characteristic value measured by electrical characteristic value measurement circuit 106 and a reference value stored in NVM 108. If the error is greater than a predetermined threshold, security control circuit 110 is configured to protect sensitive data in IC 102, for example, by deleting all stored secrets. In some embodiments, security control circuit 110 operates at device startup and prevents die-attachment from being drilled when the electronic device is powered off. In other embodiments, security control circuit 110 operates continuously (when powered on) to provide protection against in-vivo attacks.
[0056] As shown below (reference Figure 2 as well as Figure 3), in some embodiments, the electrical characteristic value is measured using a clock within IC 102. In some embodiments, because an attacker can essentially halt the clock, the error value when the clock is stopped will exceed a predetermined threshold, and the protection mechanism will not be compromised.
[0057] In one embodiment, a user can directly solder the die-bonding pad 104 to the PCB during the PCB manufacturing process to modify the electrical characteristics of the die-bonding pad 104 (e.g., by providing a parallel path to reduce resistance). In this embodiment, updating the reference value stored in NVM 108 is performed as part of the PCB manufacturing process.
[0058] Thus, in some embodiments, confidential data stored in IC 102 is protected from physical attacks performed through die-bonding pad 104 that would alter an electrical characteristic of die-bonding pad 104 to a value exceeding a predetermined threshold.
[0059] Figure 2 A block diagram schematically illustrates an electronic device 200 having a resistance-based tamper detection circuit according to an embodiment disclosed herein. An IC 202 is connected to a die-bonding pad 204. IC 202 includes a resistance-measurement circuit 206. In an exemplary embodiment, resistance-measurement circuit 206 includes a current source for supplying a current through a resistor to be measured and an analog-to-digital converter for converting a voltage across the resistor to a digital value.
[0060] The resistance measurement circuit 206 is connected to a first region 212A on the die-bonding pad 204 via a bonding pad 208A and a conductive line 210A, and is connected to a second region 212B on the die-bonding pad 204 via a bonding pad 208B and a conductive line 210B. Therefore, the resistance measurement circuit 206 measures the resistance 214 through the die-bonding pad 204. In some embodiments, the first region 212A and the second region 212B on the die-bonding pad 204 are located far apart from each other, and are substantially located at two opposite corners of the die-bonding pad 204, or at the center of two opposite sides.
[0061] It should be noted that since the basis for tamper detection is the error between two measurement results, the resistance measurement circuit 206 does not need to be linear or precise as long as the readings are consistent.
[0062] In some embodiments, multiple parallel wires are used to connect the resistance measurement circuit 206 to the die-bonding pad 204 because the resistance of the wires 210A and 210B is substantially greater than the resistance of the resistor 214 of the die-bonding pad 204. In other embodiments, a die-bonding pad 204 with a higher sheet-resistance resistor 214 may be used, for example, using a different material with lower conductivity or a thinner profile.
[0063] Figure 3 A block diagram schematically illustrates an electronic device 300 having a capacitance-based tamper detection circuit according to an embodiment disclosed herein. An IC 302 is connected to a galvanically floating die-bonding pad 304. IC 302 includes a capacitance-measurement circuit 306 connected to a floating node 308 (essentially an electrically isolated metal deposition area), and a bond pad 314 connected to the die-bonding pad 304 via a bond pad 310 and a wire 312. Capacitance-measurement circuit 306 is configured to measure the capacitance between the floating node 308 and the die-bonding pad 304.
[0064] Because the benchmark for tamper detection is the error value between the two measurement results, this capacitance measurement result should be consistent and sensitive, but does not need to be linear or precise. In some embodiments, the capacitance measurement circuit 306 includes a current source that charges (or discharges) the capacitor 316. In other embodiments, a simpler (although less precise) circuit that charges (or discharges) the capacitor 316 via a voltage source in series with a resistor can be applied. In some embodiments, the voltage on the capacitor 316 is measured after a predetermined time (which can be inferred, for example, from the clock on the chip). In other embodiments, the capacitance measurement circuit 306 measures the time it takes for the voltage on the capacitor 316 to reach a predetermined standard (e.g., calculating the clock cycle).
[0065] In some embodiments, the floating node 308 may include other metal layers because the variance of the capacitance 316 between the metal layer and the die-bonding pad 304 is small.
[0066] In an alternative embodiment, a redistribution layer (RDL) that covers almost all areas on the chip (except for metal pads and power routing) is used as a topside cover to avoid FIB / laser attack and also serves as the top electrode of capacitor 316. The distance between the RDL and the die bonding pad 304 or the die thickness basically consists of 7 mils (one thousandth of an inch) of silicon and 0.5 mils of epoxy. In some embodiments, the die thickness is reduced to 5 mils of silicon and 0.5 mils of epoxy. In other embodiments, the die thickness is reduced to 3 mils plus film (film is used as an alternative to liquid adhesive). With a gap size of 3.5 mils, the corresponding capacitance values for a capacitor of 1 square millimeter and a capacitor of 1 square centimeter are 0.1 pF and 10 pF, respectively.
[0067] The configuration of the electronic devices 200 and 300 is described in Figure 2 and Figure 3 , and are cited for clarity of concept only. Other configurations may be used in alternative embodiments. In some embodiments, for example, the die-bonding pad is connected to ground (in the IC and / or on the circuit board) and can be used as the negative node for capacitance measurement, while a floating metal plate built into the IC can be used as the positive node. In other embodiments, both resistance and capacitance are measured. In some embodiments, the capacitance between the die-bonding pad and ground is measured (thus eliminating the need for floating node 308).
[0068] Figure 4 FIG4 is a flow chart 400 schematically illustrating a method for temporarily storing electrical characteristic values of a die-bonding pad in an electronic device during a manufacturing process according to an embodiment disclosed herein. The method is executed by a test apparatus used for final testing of the electronic device.
[0069] The flowchart 400 begins with operation 402 of measuring electrical characteristics, wherein the test equipment measures the electrical characteristics (e.g., resistance or capacitance) of the die bond pad. In some embodiments, the test equipment measures these characteristics directly. In other embodiments, the test circuit activates characteristic measurement circuitry (e.g., Figure 1 The electrical characteristic value measurement circuit 106 in FIG.
[0070] Next, in operation 404 of writing a measurement value, the test equipment writes the measurement result of operation 402 into the NVM (eg, Figure 1 The flowchart ends at operation 404.
[0071] Figure 5 500, which schematically illustrates a method for protecting an electronic device from tampering with a die-bonding pad according to an embodiment disclosed herein. The method comprises a security control circuit 110 and an electrical characteristic value measurement circuit 106 ( Figure 1 )implement.
[0072] The flowchart 500 begins at power-up and continues as long as power is applied to the electronic device. The flowchart begins with operation 502 of measuring electrical characteristic values, in which the electrical characteristic value measurement circuit 106 measures the electrical characteristic value (e.g., resistance or capacitance) of the die bonding pad. Next, in operation 504 of calculating deviation, the safety control circuit compares the measured value with a reference value (e.g., stored in Figure 1 In some embodiments, the error value is the absolute value of the difference between the measured value and the reference value. In other embodiments, a relative error measurement is used, for example, the absolute difference divided by the reference value.
[0073] Next, the security control circuit compares the error value to a predetermined threshold value in operation 506 (Compare Deviation). If the error value is not greater than the predetermined threshold, the flowchart re-enters operation 502 to re-test the electrical characteristic value (and thus provide continued protection). If the error value is greater than the predetermined threshold value in operation 506, the flowchart proceeds to operation 508 (Destroy Secrets), where the security control circuit destroys some or all stored secrets (in some embodiments, alternative or additional security control circuits may permanently disable access to stored secrets). After operation 508, operation of the IC terminates.
[0074] The configuration of flowcharts 400 and 500 is described in Figure 4 as well as Figure 5 , and the above configurations are exemplary. Other configurations may be used in alternative embodiments. For example, in some embodiments, the safety control circuit executes flowchart 500 only once, immediately after power is applied, and in operation 506, if the error value is not greater than a predetermined threshold, the safety control circuit exits (this action reduces power consumption but only provides protection against tampering of the die-bonding pad when power is off).
[0075] In some embodiments, a package that does not require a die-attach pad (e.g., a BGA package) is used. However, the package is modified to include a metal plate covering nearly all or all of the IC substrate area, with the metal plate used for attack detection, similar to the die-attach pad as described above.
[0076] The configurations of the electronic devices 100, 200, and 300 include the resistance measurement circuit 206, the capacitance measurement circuit 306, and the methods of the flowcharts 400 and 500, which are described in Figures 1 to 5 The above configurations and methods are cited for illustrative purposes only. Any other suitable system configurations and methods may be used as alternative embodiments. The various components in electronic device 100 may be implemented as ICs, such as application-specific integrated circuits (ASICs) or field-programmable gate-arrays (FPGAs).
[0077] The above embodiments are cited by way of example only, and the present invention is not limited to the specific examples shown or described above. Rather, the scope of application of the present invention includes various combinations and subcombinations of the above features, as well as variations and modifications not disclosed in the known art that may occur to a person skilled in the art after reading the foregoing description. The documents incorporated by reference into this patent application should be considered as an integral part of the present invention, except that any term defined in those incorporated documents in a manner that conflicts with the explicit or implicit definition in the present specification shall be considered solely in accordance with the definition in the present specification.
Claims
1. An electronic device, characterized in that: include:
1. integrated circuit; as well as A package component includes a die-bonding pad connected to the integrated circuit, wherein the integrated circuit includes: a measurement circuit configured to measure an electrical characteristic value of the die-bonding pad; as well as A safety control circuit is configured to initiate a response action according to a detected error between the measured electrical characteristic value of the die-bonding pad and an initial measurement value of the electrical characteristic value.
2. The electronic device according to claim 1, wherein The electrical characteristic value of the die-bonding pad includes a resistance value between at least two conductive lines bonded to the die-bonding pad.
3. The electronic device according to claim 1, wherein: The electrical characteristic value of the die-bonding pad includes a capacitance value between the die-bonding pad and an electrical junction in the integrated circuit.
4. The electronic device according to claim 3, wherein: The electrical junction includes a metal deposition layer.
5. The electronic device according to claim 1, wherein: The integrated circuit further includes a non-volatile memory configured to store the initial measurement value of the electrical characteristic of the die-bonding pad.
6. The electronic device according to claim 5, wherein: The initial measurement value is programmed into the non-volatile memory when the electronic device is manufactured.
7. The electronic device according to claim 1, wherein: The invention further comprises an adhesive or a film for connecting the integrated circuit to the die-bonding pad.
8. A method for enhancing the security of an electronic device, characterized in that: The electronic device includes an integrated circuit and a packaging component, wherein the packaging component includes a die-bonding pad connected to the integrated circuit. The method includes: measuring electrical characteristic values of the die-bonding pad; and A response action is initiated according to a detected error value between the measured electrical characteristic value of the die-bonding pad and an initial measurement value of the electrical characteristic value.
9. The method according to claim 8, wherein The operation of measuring the electrical characteristic value of the die-bonding pad includes measuring a resistance value between at least two wires bonded to the die-bonding pad.
10. The method according to claim 8, wherein The operation of measuring the electrical characteristic value of the die-bonding pad includes measuring a capacitance value between the die-bonding pad and an electrical junction in the integrated circuit.
11. The method according to claim 10, wherein The electrical junction includes a metal deposition layer.
12. The method according to claim 8, wherein The method further includes storing the initial measurement value of the electrical characteristic of the die-bonding pad in a non-volatile memory of the integrated circuit.
13. The method according to claim 12, wherein: The operation of storing the initial measurement value of the electrical characteristic value of the die-bonding pad includes programming the initial measurement value into the non-volatile memory when manufacturing the electronic device.
14. The method according to claim 8, wherein The electronic device includes an adhesive or a film for connecting the integrated circuit to the die-bonding pad.
Citation Information
Patent Citations
Detecting and thwarting backside attacks on secured systems
US9965652B2