Circuits and methods for tamper detection
By introducing a resistor voltage divider and an anti-tamper comparison logic circuit in the integrated circuit signal layer to monitor and compare voltage changes, the problem of integrated circuits being vulnerable to physical attacks is solved, and effective detection and response to physical attacks is achieved.
Patent Information
- Application Number
- CN202510150498.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-03-20
- Filing Date
- 2025-02-11
- Publication Date
- 2025-09-23
AI Technical Summary
Existing integrated circuits are vulnerable to physical attacks, where attackers can physically access the signal layer and transistor layer, leading to the leakage of secure signals and information.
A resistor voltage divider is introduced in the signal layer of the integrated circuit to detect physical attacks by monitoring the generated voltage. The anti-tamper comparison logic circuit compares the detected voltage with the stored voltage to generate an anti-tamper alarm signal.
Effectively detect and respond to physical attacks, prevent tampering at the signal and transistor levels, and ensure the security and integrity of integrated circuits.
Smart Images

Figure HDA0005267936180000011 
Figure HDA0005267936180000021 
Figure HDA0005267936180000031
Abstract
Description
Technical Field
[0001] The present disclosure relates to electronic integrated circuits and, more particularly, to circuits and methods for detecting tampering in integrated circuits. Background Art
[0002] Users can configure a configurable integrated circuit (IC) to implement a desired custom logic function. In a typical scenario, a logic designer uses a computer-aided design (CAD) tool to create a custom circuit design. When the design process is complete, the CAD tool generates an image containing configuration data bits. The configuration data bits are then loaded into a configuration memory element, which configures the configurable logic circuitry in the integrated circuit to perform the function of the custom circuit design. BRIEF DESCRIPTION OF THE DRAWINGS
[0003] Figure 1 is a diagram showing an example of an integrated circuit (IC) package including an integrated circuit die and a packaging substrate.
[0004] Figure 2 It shows Figure 1 Layout diagram of a top view of an example of a conductor formed in a signal layer of an integrated circuit die is shown in FIG.
[0005] Figure 3 It shows Figure 1 Illustration of an example of anti-tamper circuitry in an integrated circuit die.
[0006] Figure 4A It is shown in Figure 3 A flow chart of examples of operations that may be performed in the analysis mode of an anti-tamper circuit.
[0007] Figure 4B It is shown in Figure 3 A flow chart of examples of operations that may be performed in the protection mode of the tamper-resistant circuit.
[0008] Figure 5 An example of a configurable logic integrated circuit (IC) is shown.
[0009] Figure 6A is a block diagram of a system that can be used to implement a circuit design to be programmed onto a programmable logic device using design software.
[0010] Figure 6B is a diagram illustrating an example of a programmable logic device including three fabric dies and two base dies interconnected by microbumps.
[0011] Figure 7 is a block diagram illustrating a computing system configured to implement one or more aspects of the embodiments disclosed herein. DETAILED DESCRIPTION
[0012] Figure 1 1 is a diagram illustrating an example of an integrated circuit (IC) package 100 including an integrated circuit die 101 and a package substrate 102. The integrated circuit (IC) die 101 is coupled to the package substrate 102 via conductive microbumps 111. The package substrate 102 can be coupled to a circuit board (not shown) via conductive balls 112. The IC die 101 can be any type of integrated circuit, such as a configurable IC (e.g., a field programmable gate array (FPGA) or programmable logic device), a microprocessor IC, a graphics processing unit IC, a memory IC, an application-specific IC, a transceiver IC, etc. Figure 1 A cross-sectional view of IC package 100 is shown.
[0013] IC die 101 includes a signal layer 103, a transistor layer 104, and a power layer 105. Transistor layer 104 includes layers of materials (e.g., semiconductors and metals) that form transistors. Power layer 105 includes conductors formed in layers of conductive materials that are used to transmit power (e.g., power supply voltage and ground voltage) to transistors in transistor layer 104. Signal layer 103 includes conductors formed in layers of conductive materials that are used to transmit signals (e.g., data signals, control signals, clock signals, etc.) to transistors in transistor layer 104.
[0014] Because signal layer 103 is exposed on the top side of IC die 101, signal layer 103 may provide an opportunity for physical attacks on IC die 101. For example, an attacker may be able to physically penetrate and / or penetrate signal layer 103 from the top side of IC die 101 to access signal layer 103 and / or transistor layer 104. For example, by physically accessing secure signals transmitted through signal layer 103 and / or valuable information stored in transistor layer 104, an attacker may be able to conduct a physical attack on IC die 101 that bypasses security protections.
[0015] According to some examples disclosed herein, circuits and methods are provided for detecting a physical attack on an integrated circuit (IC) die by monitoring a voltage generated by a resistor divider, the resistor divider including a resistor formed in a signal layer of the IC die. During an analysis mode, a resistance value is selected for the resistor divider to generate a detection voltage. The detection voltage is stored in a lockstep circuit in the IC die. During a protection mode, an anti-tamper comparison logic circuit in the IC die compares the detection voltage generated by the resistor divider with the detection voltage stored in the lockstep circuit to determine whether a physical attack has occurred in the signal layer of the IC die.
[0016] One or more specific examples are described below. In order to provide a concise description of these examples, not all features of actual implementations are described in this specification. It should be understood that in the development of any such actual implementation, as in any engineering or design project, many implementation-specific decisions must be made to achieve the developer's specific goals, such as complying with system-related and business-related constraints, which may vary from implementation to implementation. Furthermore, it should be understood that such development work may be complex and time-consuming, but it remains a routine task of design, manufacturing, and production for those of ordinary skill having the benefit of this disclosure.
[0017] Throughout the specification and claims, the terms "connected" and "connect" refer to a direct electrical connection between the circuits being connected, without any intervening devices. The terms "coupled" and "coupling" refer to a direct electrical connection between the circuits or an indirect electrical connection through one or more passive or active intermediary devices that allow information to be transferred between the circuits. The term "circuit" may refer to one or more passive and / or active electrical components that are arranged to cooperate with each other to provide a desired functionality.
[0018] The present disclosure discusses integrated circuit devices, including configurable (programmable) logic integrated circuits, such as field programmable gate arrays (FPGAs) and programmable logic devices. As described herein, integrated circuits (ICs) can include hard logic and / or soft logic. Circuits in an integrated circuit device (e.g., a configurable logic IC) that can be configured by an end user are referred to as "soft logic." "Hard logic" generally refers to circuits in an integrated circuit device that have significantly fewer or no configurable features than soft logic.
[0019] Figure 2 It shows Figure 1 Layout diagram of a top view of an example of conductors formed in a signal layer in IC die 101 is shown in FIG. Figure 2 An exemplary layout of a first conductor 201 formed in a first conductive signal layer of IC die 101 and a second conductor 202 formed in a second conductive signal layer of IC die 101 is shown. For example, the first conductive signal layer and the second conductive signal layer can be formed of metal. For example, the first conductive signal layer including conductor 201 can be the top layer of IC die 101, and the second conductive signal layer including conductor 202 can be the next layer below the first conductive signal layer. In this example, conductors 201-202 are located Figure 1 In another implementation, conductors 201 - 202 may be replicated in an additional signal layer located below power layer 105 and directly above microbumps 111 at the back side of IC die 101 .
[0020] IC die 101 includes first conductors 201 that extend across the width of IC die 102. Each of first conductors 201 is rectangular and spans most or all of the width of IC die 101 when viewed from above (i.e., at Figure 2 ). Each of the second conductors 202 couples together two adjacent ones of the first conductors 201. As a result, the conductors 201 and 202 are coupled together to form an alternating, stepped conductive path that extends back and forth across the length and width of the IC die 101.
[0021] Conductor 201 is located along the length of IC die 101 (i.e., Figure 2 IC die 101 includes enough conductors 201 to extend across the length of IC die 102. Although Figure 2 17 conductors 201 are shown as an example, but an IC die implementing the techniques disclosed herein may include a desired number of conductors 201 spaced throughout the length of the IC die such that, when viewed from above, the largest area of the IC die without one of the conductors 201-202 in the signal layer is less than the length of each conductor 202. Figure 3 In further detail of the disclosed exemplary implementation, conductors 201 and 202 are coupled together to form a resistor that is used by the anti-tamper circuit to detect a physical attack on IC die 101 .
[0022] Figure 3 is a diagram illustrating an example of an anti-tamper circuit 300 in IC die 101. Anti-tamper circuit 300 includes five resistors 301-305, four p-channel field effect transistors (FETs) 311-314, a switch selection circuit 315, a voltage analog-to-digital converter (ADC) circuit 321, a lockstep circuit 322, and a comparison logic circuit 323. According to an exemplary implementation, resistor 301 includes Figure 2 In this embodiment, the conductors 201 and 202 are as shown in FIG. Figure 2 shown coupled together to form Figure 3 The conductors 201 and 202 may be located in two signal layers 103 in the IC die 101, for example.
[0023] In another implementation, the IC die 101 may also have additional signal layers ( Figure 1 These signal layers include Figure 2 Another set of conductors 201-202 coupled as shown. These additional signal layers are located below the power layer 105 on the back side of the IC die 101 and above the microbumps 111. In this implementation, Figure 3 The resistor 301 includes a Figure 1 The first set of conductors 201 to 202 of two layers of the signal layer 103 are shown in FIG. Figure 2 1 and 2. The resistor 301 further includes a second set of conductors 201 to 202 in two additional signal layers below the power layer 105 on the back side of the IC die 101 (as shown in FIG. Figure 2 In this implementation, the first set of conductors 201 - 202 are coupled to the second set of conductors 201 - 202 through vias and conductors in the power layer 105 and the transistor layer 104 to form a resistor 301 .
[0024] Resistors 301 through 305 are coupled in series between a power supply voltage VCC and a ground voltage to form a resistor divider. P-channel FET 311 is coupled in parallel with resistor 302 between nodes A and B. P-channel FET 312 is coupled in parallel with resistor 303 between nodes B and C. P-channel FET 313 is coupled in parallel with resistor 304 between nodes C and D. P-channel FET 314 is coupled in parallel with resistor 305 between nodes D and E. According to a specific example, which is not intended to be limiting, each of resistors 302, 303, 304, and 305 can have a resistance that is one-eighth that of resistor 301. Anti-tamper circuit 300 (excluding resistor 301) can be formed in transistor layer 104 of IC die 101.
[0025] The gates of transistors 311 to 314 are coupled to a switch selection circuit 315. A voltage ADC circuit 321 is coupled to node A. The voltage ADC circuit 322 converts the voltage Vdetect generated at node A into a digital value that is provided to a comparison logic circuit 323. The comparison logic circuit 323 compares the digital value generated by the voltage ADC circuit 321 with the digital value stored in the lockstep circuit 322 to generate an anti-tamper alarm signal, as described in further detail below.
[0026] The anti-tamper circuit 300 can operate in a profiling mode and a protection mode. Figure 4A Describe the analysis mode in detail. Figure 4A As shown, during the analysis mode, the operation 401 may be enabled, for example, in response to input from a user or manufacturer. Figure 3 The voltage detection feature provided by the anti-tamper circuit 300 can be configured to detect a voltage. For example, the voltage detection feature can be enabled by a fuse setting in the IC die 101. In this example, the fuse setting is not set by default, and the voltage detection feature is not enabled until an input is received to enable the voltage detection feature.
[0027] In operation 402, the resistance of the resistor divider formed by resistors 301-305 is set to a random value (or pseudo-random value) based on a digital output value generated by switch selection circuit 315 and provided to the gates of P-channel FETs 311 to 314. For example, switch selection circuit 315 may include a linear feedback shift register (LFSR) circuit that generates a random (or pseudo-random) digital value in operation 402. The digital output value generated by switch selection circuit 315 is provided to the gates of FETs 311 to 314 to randomly select the total resistance between node A and the ground voltage at node E, thereby making it impossible for an attacker to determine the exact value of the detection voltage Vdetect. The digital output value generated by switch selection circuit 315 can turn on any of the P-channel FETs 311 to 314 to short-circuit the corresponding resistor in the resistor divider 302 to 305. The digital output value generated by switch selection circuit 315 can turn off any of P-channel FETs 311 to 314 to add the resistance of the corresponding resistor among resistors 302 to 305 to the resistor divider. For example, digital code 1010 generated by switch selection circuit 315 can turn off transistors 311 and 313 and turn on transistors 312 and 314, shorting transistors 303 and 305 and making the total resistance between node A and node E equal to the resistance of resistor 302 plus the resistance of resistor 304.
[0028] In operation 403, the detection voltage Vdetect is measured, for example, by the voltage ADC circuit 321. In operation 404, the measured detection voltage Vdetect is stored in the lockstep circuit 322. The measured detection voltage Vdetect stored in the lockstep circuit 322 can be a digital output of the voltage ADC circuit 321. The lockstep circuit 322 can include a non-volatile storage device (e.g., an on-die fuse) to store the measured detection voltage Vdetect. In some implementations, the detection voltage Vdetect is measured under different environmental conditions (e.g., at different temperatures of the IC die 101) in operation 403, and each measured detection voltage is stored in the lockstep circuit 322 in operation 404.
[0029] refer to Figure 4B In operation 411, as an example, in response to a signal from a fuse in IC die 101 or a signal from a bitstream setting in IC die 101, the protection mode is activated. Figure 3 The voltage detection feature provided by the anti-tamper circuit 300. In operation 412, the anti-tamper circuit 300 monitors the voltage change of the detection voltage Vdetect based on the change of the resistance of the resistor 301 in the signal layer. For example, if an attacker pierces the Figure 2, the resistance of the resistor 301 changes, and the detection voltage Vdetect changes based on the change in the resistance of the resistor 301. Then, the voltage ADC circuit 321 changes its digital output based on the change in the detection voltage Vdetect.
[0030] During the protection mode, the lockstep circuit 322 outputs a digital value indicating the detection voltage Vdetect measured in operation 403 and stored in operation 404. The comparison logic circuit 323 compares the digital output of the voltage ADC circuit 321 with the digital value of the detection voltage Vdetect measured during the analysis mode and stored in and output by the lockstep circuit 322. In operation 413, the comparison logic circuit 323 asserts an anti-tamper alarm signal in response to the detection voltage Vdetect indicated by the digital output of the voltage ADC circuit 321 being different from the detection voltage Vdetect stored in and output by the lockstep circuit 322.
[0031] If multiple values of the detection voltage Vdetect are measured under different environmental conditions and stored in the lockstep circuit 322 in the analysis mode, the lockstep circuit 332 outputs only the measured detection voltage Vdetect that corresponds to the current environmental condition measured in the IC die 101. In these implementations, the comparison logic circuit 323 also asserts the anti-tamper alarm signal based on the detection voltage Vdetect indicated by the digital output of the voltage ADC circuit 321 being different from the digital value of the detection voltage Vdetect output by the lockstep circuit 322.
[0032] When the anti-tamper circuit 300 detects voltage tampering in response to the anti-tamper alarm signal being asserted, the IC die 101 can execute additional security features, such as an IC die reset or shutdown, to prevent unintended system execution. The IC die 101 can also or alternatively trigger a clear or other anti-tamper response to memory contents in the IC die 102. The additional security features can be selected, for example, by the IC die owner through bitstream configuration.
[0033] Figure 5 An example of a configurable logic integrated circuit (IC) 500 is shown, which may include, for example, Figure 1 、 Figure 2 、 Figure 3 , and / or Figures 4A-4B Any, some, or all of the disclosed circuits. Figure 5As shown, a configurable logic integrated circuit (IC) 500 includes a two-dimensional array of configurable functional circuit blocks, including a configurable logic array block (LAB) 510 and other functional circuit blocks, such as a random access memory (RAM) block 530 and a digital signal processing (DSP) block 520. Functional blocks such as LAB 510 may include smaller programmable logic circuits (e.g., logic elements, logic blocks, or adaptive logic modules) that receive input signals and perform customized functions on the input signals to produce output signals. Figure 5 The configurable functional circuit blocks shown in FIG. 1 can be configured to perform the functions described herein. Figure 3 and / or Figures 4A-4B Disclose the functionality of any circuit.
[0034] In addition, the programmable logic IC 500 may have input / output elements (IOEs) 502 for driving the programmable logic IC 500 to send signals and receive signals from other devices. The input / output elements 502 may include parallel input / output circuits, serial data transceiver circuits, differential receiver and transmitter circuits, or other circuits for connecting one integrated circuit to another integrated circuit. As shown, the input / output elements 502 may be located on the periphery of the chip. If desired, the programmable logic IC 500 may have input / output elements 502 arranged in different ways. For example, the input / output elements 502 may be formed into one or more columns, one or more rows, or one or more islands of input / output elements, which may be located anywhere on the programmable logic IC 500.
[0035] Programmable logic IC 500 may also include programmable interconnect circuitry in the form of vertical routing channels 540 (i.e., interconnects formed along the vertical axis of programmable logic IC 500) and horizontal routing channels 550 (i.e., interconnects formed along the horizontal axis of programmable logic IC 500), each routing channel including at least one conductor to route at least one signal.
[0036] Note that except Figure 5 In addition to the interconnect topology shown in FIG, other routing topologies can be used. For example, in the case of a three-dimensional integrated circuit, the routing topology can include wires running diagonally or horizontally and vertically along different parts of its extent, as well as wires running perpendicular to the plane of the device. The driver of the wire can be located at a different location than at one end of the wire.
[0037] Furthermore, it should be understood that references herein to Figure 1 、 Figure 2 、 Figure 3 ,and Figures 4A-4BThe disclosed embodiments can be implemented in any integrated circuit or electronic system. If desired, the functional blocks of such an integrated circuit can be arranged in more levels or layers, with multiple functional blocks interconnected to form larger blocks. Other device arrangements can use functional blocks that are not arranged in rows and columns.
[0038] Programmable logic IC 500 may include programmable memory elements. Configuration data may be loaded into the memory elements using input / output elements (IOEs) 502. Once loaded, each memory element provides a corresponding static control signal that controls the operation of the associated configurable functional block (e.g., LAB 510, DSP block 520, RAM block 530, or input / output element 502).
[0039] In a typical scenario, the output of the loaded memory element is applied to the gate of a metal oxide semiconductor field effect transistor (MOSFET) in a functional block to turn certain transistors on or off, thereby configuring the logic including routing paths in the functional block. Programmable logic circuit elements that can be controlled in this manner include multiplexers (e.g., multiplexers used to form routing paths in interconnect circuits), lookup tables, logic arrays, AND logic gates, OR logic gates, XOR logic gates, NAND logic gates, NOR logic gates, transmission gates, etc.
[0040] Programmable memory elements can be organized in a configuration memory array with rows and columns. Data registers spanning all columns and address registers spanning all rows can receive configuration data. Configuration data can be transferred to the data registers. When the appropriate address register is asserted, the data register writes the configuration data to the configuration memory bits for the row specified by the address register.
[0041] In some embodiments, programmable logic IC 500 may include configuration memory organized in sectors, whereby a sector may include configuration RAM bits that specify the functions and / or interconnections of subcomponents and wires in or across the sector. Each sector may include separate data and address registers.
[0042] Figure 5The programmable logic IC is merely one example of an IC that can be used with the embodiments disclosed herein. The embodiments disclosed herein can be used in conjunction with any suitable integrated circuit or system. For example, the embodiments disclosed herein can be used in conjunction with various types of devices, such as a processor integrated circuit, a central processing unit, a memory integrated circuit, a graphics processing unit integrated circuit, an application specific standard product (ASSP), an application specific integrated circuit (ASIC), and a programmable logic integrated circuit. Examples of programmable logic integrated circuits include programmable array logic (PAL), programmable logic array (PLA), field programmable logic array (FPLA), electrically programmable logic device (EPLD), electrically erasable programmable logic device (EEPLD), logic cell array (LCA), complex programmable logic device (CPLD), and field programmable gate array (FPGA), to name a few.
[0043] The integrated circuits disclosed in one or more embodiments herein may be part of a data processing system that includes one or more of the following components: a processor; memory; input / output circuitry; and peripheral devices. The data processing system may be used in a variety of applications, such as computer networking, data networking, instrument configuration, video processing, digital signal processing, or any other suitable application. The integrated circuits may be used to perform a variety of different logic functions.
[0044] In general, the software and data for performing any function disclosed herein can be stored in a non-transient computer-readable storage medium. A non-transient computer-readable storage medium is a tangible computer-readable storage medium that stores data and software for later access, rather than a medium (e.g., wire) that only transmits propagation electrical signals. Software code can sometimes be referred to as software, data, program instructions, instructions, or code. A non-transient computer-readable storage medium can, for example, include a computer memory chip, a non-volatile memory (e.g., non-volatile random access memory (NVRAM)), one or more hard drives (e.g., magnetic drives or solid-state drives), one or more removable flash drives or other removable media, a compact disc (CD), a digital versatile disc (DVD), a Blu-ray disc (BD), other optical media, and a floppy disk, a magnetic tape, or any other suitable memory or (one or more) storage device.
[0045] Figure 6AA block diagram of a system 10 is shown that can be used to implement a circuit design to be programmed into a programmable logic device 19 using design software. A designer can implement circuit design functionality on an integrated circuit, such as a reconfigurable programmable logic device 19 (e.g., a field programmable gate array (FPGA)). The designer can use design software 14 to implement the circuit design to be programmed into the programmable logic device 19. The design software 14 can use a compiler 16 to generate a low-level circuit design program (bitstream) 18, sometimes also referred to as a program object file and / or configuration program, that programs the programmable logic device 19. Thus, the compiler 16 can provide machine-readable instructions representing the circuit design to the programmable logic device 19. For example, the programmable logic device 19 can receive one or more programs (bitstreams) 18 that describe a hardware implementation to be stored in the programmable logic device 19. The programs (bitstreams) 18 can be programmed into the programmable logic device 19 as configuration programs 20. In some cases, the configuration programs 20 can represent accelerator functionality to be executed for machine learning, video processing, speech recognition, image recognition, or other highly specialized tasks.
[0046] In some implementations, a programmable logic device can be any integrated circuit device, including a programmable logic device having two separate integrated circuit dies in which at least some programmable logic structures are separated from at least some structural support circuitry for operating the programmable logic structures. Figure 6B One example of such a programmable logic device is shown in , but many other examples may be used, and it should be understood that the present disclosure is intended to cover any suitable programmable logic device in which the programmable logic structure and the structure support circuits are at least partially separated on different integrated circuit dies.
[0047] Figure 6B is a diagram depicting an example of a programmable logic device 19 including three structural dies 22 and two base dies 24 connected to each other by microbumps 26. Figure 6B In the example of , at least some of the programmable logic structures of the programmable logic device 19 are in three structural dies 22, and at least some structural support circuits for operating the programmable logic structures are in two base dies 24. For example, Figure 5 Some circuits of configurable IC 500 shown in FIG. 5 (eg, LAB 510 , DSP 520 , and RAM 530 ) may be located in structural die 22 , and some circuits of IC 500 (eg, input / output elements 502 ) may be located in base die 24 .
[0048] Despite Figure 6BThe structural die 22 and the base die 24 appear in a one-to-one or two-to-one relationship, but other relationships may also be used. For example, a single base die 24 can be attached to several structural die 22, or several base die 24 can be attached to a single structural die 22, or several base die 24 can be attached to several structural die 22 (e.g., in a staggered pattern). The peripheral circuit 28 can be attached to the base die 24, embedded in the base die 24, and / or disposed on top of the base die 24, and a heat sink 30 can be used to reduce heat buildup on the programmable logic device 19. The heat sink 30 can appear above the package (as shown) and / or below the package (e.g., as a double-sided heat sink). The base die 24 can be attached to the package substrate 32 via conductive bumps 34. Figure 6B In the example of FIG, two pairs of structural die 22 and base die 24 are shown communicatively connected to each other via interconnect bridges 36 (eg, embedded multi-die interconnect bridges (EMIBs)) and microbumps 38 at bridge interfaces 39 in base die 24.
[0049] In combination, the fabric die 22 and the base die 24 can be combined to form a programmable logic device 19, such as a field programmable gate array (FPGA). It should be understood that, for example, when the fabric die 22 and the base die 24 operate in combination, an FPGA can represent a type of circuit and / or logic arrangement of a programmable logic device. Furthermore, for the purposes of this example, an FPGA is discussed herein, but it should be understood that any suitable type of programmable logic device can be used.
[0050] Figure 7 is a block diagram illustrating a computing system 700 configured to implement one or more aspects of the embodiments described herein. Computing system 700 includes a processing subsystem 70 having processor(s) 74, system memory 72, and programmable logic device 19 communicating via an interconnect path, which may include a memory hub 71. Memory hub 71 may be a separate component within a chipset assembly or integrated within processor(s) 74. Memory hub 71 is coupled to input / output (I / O) subsystem 50 via communication link 76. I / O subsystem 50 includes input / output (I / O) hub 51, which enables computing system 700 to receive input from input device(s) 62. Furthermore, I / O hub 51 enables a display controller, which may be included in processor(s) 74, to provide output to display device(s) 61. In one embodiment, display device(s) 61 coupled to I / O hub 51 may include a local display device, an internal display device, or an embedded display device.
[0051] In one embodiment, the processing subsystem 70 includes (one or more) parallel processors 75 coupled to the memory hub 71 via a bus or other communication link 73. The communication link 73 can use one of any number of standards-based communication link technologies or protocols, such as but not limited to PCI Express, or can be a vendor-specific communication interface or communication structure. In one embodiment, the (one or more) parallel processors 75 form a compute-centric parallel or vector processing system that can include a large number of processing cores and / or processing clusters, such as a multiple integrated core (MIC) processor. In one embodiment, the (one or more) parallel processors 75 form a graphics processing subsystem that can output pixels to one of the (one or more) display devices 61 coupled via the I / O hub 51. The (one or more) parallel processors 75 can also include a display controller and display interface (not shown) to enable direct connection to the (one or more) display devices 63.
[0052] In the I / O subsystem 50, a system storage unit 56 can be connected to the I / O hub 51 to provide a storage mechanism for the computing system 700. The I / O switch 52 can be used to provide an interface mechanism to enable connections between the I / O hub 51 and other components (such as a network adapter 54 and / or a wireless network adapter 53 that can be integrated into the platform, as well as various other devices that can be added through (one or more) add-in devices 55). The network adapter 54 can be an Ethernet adapter or another wired network adapter. The wireless network adapter 53 can include one or more of Wi-Fi, Bluetooth, near field communication (NFC), or other network devices including one or more wireless radio devices.
[0053] The computing system 700 may include Figure 7 Other components not shown include other port connections, optical storage drives, video capture devices, etc. that may also be connected to the I / O hub 51. Figure 7 The communication paths interconnecting the various components may be implemented using any suitable protocol, such as a PCI (Peripheral Component Interconnect) based protocol (e.g., PCI Express), or any other bus or point-to-point communication interface and / or protocol(s) such as the NV Link high-speed interconnect, or interconnect protocols known in the art.
[0054] In one embodiment, (one or more) parallel processors 75 include circuits optimized for graphics and video processing, including, for example, video output circuits, and constitute a graphics processing unit (GPU). In another embodiment, (one or more) parallel processors 75 include circuits optimized for general-purpose processing while retaining the underlying computing architecture. In another embodiment, the components of the computing system 700 can be integrated with one or more other system elements on a single integrated circuit. For example, (one or more) parallel processors 75, memory hub 71, (one or more) processors 74, and I / O hub 51 can be integrated into a system-on-chip (SoC) integrated circuit. Alternatively, the components of the computing system 700 can be integrated into a single package to form a system-in-package (SIP) configuration. In one embodiment, at least a portion of the components of the computing system 700 can be integrated into a multi-chip module (MCM), which can be interconnected with other multi-chip modules into a modular computing system.
[0055] The computing system 700 shown herein is illustrative. Other variations and modifications are also possible. The connection topology, including the number and arrangement of bridges, the number of (one or more) processors 74, and the number of (one or more) parallel processors 75, can be modified as needed. For example, in some embodiments, the system memory 72 is connected to the (one or more) processors 74 directly rather than through a bridge, and other devices communicate with the system memory 72 through the memory hub 71 and (one or more) processors 74. In other alternative topologies, (one or more) parallel processors 75 are connected to the I / O hub 51 or directly to one of (one or more) processors 74, rather than being connected to the memory hub 71. In other embodiments, the I / O hub 51 and the memory hub 71 can be integrated into a single chip. Some embodiments may include two or more groups of (one or more) processors 74 connected via multiple sockets, which can be coupled to two or more instances of (one or more) parallel processors 75.
[0056] Some specific components shown herein are optional and may not be included in all implementations of computing system 700. For example, any number of add-in cards or peripherals may be supported, or some components may be eliminated. Additionally, some architectures may have Figure 7 Components similar to those shown in FIG are referred to using different terminology. For example, in some architectures, memory hub 71 may be referred to as a north bridge, while I / O hub 51 may be referred to as a south bridge.
[0057] Other examples are now described. Example 1 is an integrated circuit comprising tamper-resistant circuitry, the tamper-resistant circuitry comprising a resistor, wherein the resistor comprises a conductor in a conductive layer of the integrated circuit, wherein each of the conductors extends across a width of the integrated circuit, wherein the conductors are spaced apart over a length of the integrated circuit, and wherein the tamper-resistant circuitry generates an output signal indicative of a change in a first resistance of the resistor caused by tampering affecting the conductor.
[0058] In Example 2, the integrated circuit of Example 1 may optionally include, wherein the anti-tamper circuit further includes: a switch selection circuit that generates a pseudo-random digital value.
[0059] In Example 3, the integrated circuit of Example 2 can optionally include, wherein the anti-tamper circuit further includes: a resistor divider including a resistor; and a transistor coupled to the resistor divider, wherein the transistor controls a voltage across the resistor divider based on a pseudo-random digital value.
[0060] In Example 4, the integrated circuit of any of Examples 2-3 can optionally include, wherein the switch selection circuit comprises a linear feedback shift register.
[0061] In Example 5, the integrated circuit of any of Examples 1-4 can optionally include, wherein the anti-tamper circuit further includes: a voltage analog-to-digital converter circuit that converts a voltage at a node coupled to the resistor into a digital value.
[0062] In Example 6, the integrated circuit of any of Examples 1-5 may optionally include, wherein the anti-tamper circuit further includes: a comparison logic circuit that generates an output signal based on a comparison between a first voltage and a second voltage, wherein the first voltage is generated at a node coupled to the resistor during a protection mode of the anti-tamper circuit, and wherein the second voltage is generated at the node during an analysis mode of the anti-tamper circuit.
[0063] In Example 7, the integrated circuit of any of Examples 1-6 can optionally include, wherein the conductors are coupled in an alternating pattern that extends back and forth across a length and a width of the integrated circuit.
[0064] In Example 8, the integrated circuit of any of Examples 1-7 may optionally include, wherein the resistor is part of a resistor divider in the anti-tamper circuit, wherein the anti-tamper circuit generates a second resistance across the resistor divider based on a pseudo-random digital value, and wherein the anti-tamper circuit generates an output signal based on the first resistance and the second resistance.
[0065] In Example 9, the integrated circuit of any of Examples 1-8 can optionally include, wherein the anti-tamper circuit generates the output signal based on a first resistance of the resistor and based on a second resistance, the second resistance being determined based on a randomly generated value for controlling the transistor.
[0066] Example 10 is a method for detecting an attack on an integrated circuit die, wherein the method includes: sensing a first resistance of a resistor using a voltage detection circuit, wherein the resistor includes a conductor in a conductive layer of the integrated circuit die, wherein each of the conductors extends across a width of the integrated circuit die, and wherein the conductors are spaced apart over a length of the integrated circuit die; and generating an output signal based on a change in the first resistance of the resistor caused by tampering affecting the conductor.
[0067] In Example 11, the method of Example 10 further includes: generating a pseudo-random digital value using the switch selection circuit; and setting a second resistance across the resistor divider based on the pseudo-random digital value, wherein the resistor divider includes a resistor.
[0068] In Example 12, the method of any one of Examples 10-11 can optionally include, wherein generating the output signal further comprises generating the detection voltage using a resistor divider.
[0069] In Example 13, the method of any of Examples 10-12 may optionally include, wherein generating the output signal further includes: generating a first voltage at a node coupled to the resistor during the protection mode; generating a second voltage at the node during the analysis mode; storing the second voltage; and generating the output signal based on a comparison between the first voltage and the second voltage.
[0070] In Example 14, the method of any of Examples 10-13 can optionally include, wherein the conductors are coupled in a pattern that extends back and forth across a length and a width of the integrated circuit die.
[0071] In Example 15, the method of any of Examples 10-14 further includes shutting down the integrated circuit die in response to the output signal being asserted.
[0072] Example 16 is an anti-tamper circuit comprising: a resistor divider; a switch selection circuit that selects the resistance of the resistor divider based on a pseudo-random value; and a voltage detection circuit that generates an anti-tamper alarm signal that indicates when the voltage at a node in the resistor divider is different from a stored value.
[0073] In Example 17, the anti-tamper circuit of Example 16 can optionally include, wherein the resistor divider includes conductors in a conductive layer of the integrated circuit die, wherein each of the conductors extends across a width of the integrated circuit die, and wherein the conductors are spaced apart over a length of the integrated circuit die.
[0074] In Example 18, the anti-tamper circuit of any of Examples 16-17 further includes transistors controlled by the switch selection circuit, wherein each of the transistors is coupled in parallel with a resistor in the resistor divider.
[0075] In Example 19, the anti-tamper circuit of any of Examples 16-18 can optionally include, wherein the voltage detection circuit includes a comparison logic circuit that compares the voltage at the node in the resistor divider to a stored value.
[0076] In Example 20, the anti-tamper circuit of any of Examples 16-19 may optionally include, wherein the stored value is generated based on the voltage at the node in the resistor divider during an analysis mode of the anti-tamper circuit, and wherein the voltage detection circuit generates the anti-tamper alarm signal during a protection mode of the anti-tamper circuit.
[0077] The above description of exemplary embodiments has been provided for illustrative purposes. The above description is not intended to be exhaustive or limiting of the examples disclosed herein. The above content is merely illustrative of the principles of the present disclosure, and various modifications may be made by those skilled in the art. The above embodiments may be implemented individually or in any combination.
Claims
1. An integrated circuit comprising: An anti-tamper circuit comprising a resistor, wherein the resistor comprises conductors in a conductive layer of the integrated circuit, wherein each of the conductors extends across a width of the integrated circuit, wherein the conductors are spaced apart over a length of the integrated circuit, and wherein the anti-tamper circuit generates an output signal indicative of a change in a first resistance of the resistor caused by tampering affecting the conductors.
2. The integrated circuit of claim 1 , wherein the anti-tamper circuit further comprises: A switch selection circuit generates a pseudo-random digital value.
3. The integrated circuit of claim 2 , wherein the anti-tamper circuit further comprises: a resistor voltage divider comprising said resistor; as well as A transistor is coupled to the resistor divider, wherein the transistor controls a voltage across the resistor divider based on the pseudo-random digital value.
4. The integrated circuit according to any one of claims 2 to 3, wherein the switch selection circuit comprises a linear feedback shift register.
5. The integrated circuit according to any one of claims 1 to 3, wherein the anti-tamper circuit further comprises: A voltage analog-to-digital converter circuit converts a voltage at a node coupled to the resistor to a digital value.
6. The integrated circuit according to any one of claims 1 to 3, wherein the anti-tamper circuit further comprises: a comparison logic circuit that generates the output signal based on a comparison between a first voltage and a second voltage, wherein the first voltage is generated at a node coupled to the resistor during a protection mode of the anti-tamper circuit, and wherein the second voltage is generated at the node during an analysis mode of the anti-tamper circuit.
7. The integrated circuit of any one of claims 1 to 3, wherein the conductors are coupled in an alternating pattern extending back and forth across the length and width of the integrated circuit.
8. The integrated circuit of claim 1 , wherein the resistor is part of a resistor divider in the anti-tamper circuit, wherein the anti-tamper circuit generates a second resistance across the resistor divider based on a pseudo-random digital value, and wherein the anti-tamper circuit generates the output signal based on the first resistance and the second resistance.
9. The integrated circuit of any one of claims 1 to 3, wherein the anti-tamper circuit generates the output signal based on the first resistance of the resistor and based on a second resistance, the second resistance being determined based on a randomly generated value for controlling a transistor.
10. A method for detecting an attack on an integrated circuit die, the method comprising: sensing a first resistance of a resistor using a voltage detection circuit, wherein the resistor comprises conductors in a conductive layer of the integrated circuit die, wherein each of the conductors extends across a width of the integrated circuit die, and wherein the conductors are spaced apart over a length of the integrated circuit die; as well as An output signal is generated based on a change in the first resistance of the resistor caused by tampering affecting the conductor.
11. The method according to claim 10, further comprising: Using a switch selection circuit to generate a pseudo-random digital value; as well as A second resistance across a resistor divider including the resistor is set based on the pseudo-random digital value.
12. The method according to any one of claims 10 to 11, wherein generating the output signal further comprises: A resistor divider is used to generate the sense voltage.
13. The method according to any one of claims 10 to 11, wherein generating the output signal further comprises: generating a first voltage at a node coupled to the resistor during a protection mode; generating a second voltage at the node during an analysis mode; storing the second voltage; as well as The output signal is generated based on a comparison between the first voltage and the second voltage.
14. The method of any one of claims 10 to 11, wherein the conductors are coupled in a pattern that extends back and forth across the length and width of the integrated circuit die.
15. The method according to any one of claims 10 to 11, further comprising: The integrated circuit die is shut down in response to the output signal being asserted.
16. A tamper-resistant circuit, comprising: Resistor voltage divider; a switch selection circuit that selects a resistance of the resistor divider based on a pseudorandom value; as well as A voltage detection circuit generates a tamper alert signal that indicates when a voltage at a node in the resistor divider differs from a stored value.
17. The tamper-resistant circuit of claim 16, wherein the resistor divider comprises conductors in a conductive layer of an integrated circuit die, wherein each of the conductors extends across a width of the integrated circuit die, and wherein the conductors are spaced apart over a length of the integrated circuit die.
18. The tamper-resistant circuit according to any one of claims 16 to 17, further comprising: A transistor is controlled by the switch selection circuit, wherein each of the transistors is coupled in parallel with a resistor in the resistor divider.
19. The tamper-resistant circuit of any one of claims 16 to 17, wherein the voltage detection circuit comprises a comparison logic circuit that compares the voltage at the node in the resistor divider with the stored value.
20. The tamper-resistant circuit of any one of claims 16 to 17, wherein the stored value is generated based on the voltage at the node in the resistor divider during an analysis mode of the tamper-resistant circuit, and wherein the voltage detection circuit generates the tamper-resistant alarm signal during a protection mode of the tamper-resistant circuit.