Multi-Chiplet interconnection chip system and solution for starting trust chain security

By introducing security components of the active interposer layer into the multi-chiplet interconnected chip system, including a secure CPU, static metrics, and dynamic metrics, the security issues during the system startup phase are resolved, the credibility of the code source and remote user authentication are achieved, malicious attacks are prevented, and the normal operation of the system is ensured.

CN120805201APending Publication Date: 2025-10-17ZHEJIANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510682227.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

Existing multi-chiplet interconnected chip systems cannot guarantee security during the system startup phase and cannot support the identity authentication requirements of IoT chips, posing the risk of malicious code attacks.

Method used

It adopts an active interposer design, integrating a secure CPU, static measurement components, dynamic measurement components, and identity authentication components. Through digital signature verification and physically unclonable functions, it builds a startup trust chain to ensure the trustworthiness of the code source and perform dynamic measurement and remote authentication.

Benefits of technology

It achieves security protection during the system startup phase, supports remote user authentication, prevents malicious code attacks, and ensures normal system operation and credibility management of applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805201A_ABST
    Figure CN120805201A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-Chiplet interconnection chip system and a solution for starting trust chain security, the multi-Chiplet interconnection chip system comprises an active intermediate layer and a third-party commodity chiplet, and the active intermediate layer is integrated with a security CPU, a static measurement component, a dynamic measurement component, an identity authentication component and a security memory. The static measurement component ensures that a code source is credible by utilizing digital signature verification through a three-stage guide process, and a trust root of an active intermediate layer is expanded to all small chips. And the dynamic measurement component monitors the operation behavior of the chiplet in real time, generates a measurement report, performs machine learning analysis through the remote authentication platform, and forms an application white list to identify the abnormal behavior. The identity authentication component generates a unique authentication key through a physical unclonable function, and supports a remote user to verify the system identity and the running state of an application program. The method supports code credibility verification, dynamic behavior monitoring and remote identity authentication, has a rollback repair mechanism, and effectively improves the security and reliability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of multi-core particle system chip security, and particularly relates to a multi-Chiplet interconnection chip system and a security solution for starting a trust chain. BACKGROUND

[0002] With the continuous improvement of chip performance and functions, the field of chip design and manufacturing is facing increasingly severe challenges, especially in terms of power consumption control, thermal management optimization, cost control, and coping with increasingly complex designs. Under this background, Chiplet, as an innovative chip design concept, emerged as the times require. It can integrate and combine multiple chips with different functions or from different manufacturing processes, which not only gives the chip design great flexibility and scalability, but also is expected to significantly improve the yield of chip manufacturing, effectively reduce design and manufacturing costs, and provide new ideas and solutions for the development of the chip industry.

[0003] However, the flexibility and scalability of the small chip system also bring new security problems. If the small chips purchased have security vulnerabilities, it may cause the entire chip system to malfunction, or even in the application scenario of networked devices, it may cause other chips to be attacked. Currently, researchers have proposed a set of root-of-trust security architecture for 2.5D integration. The specific implementation is to realize a security bus and a security CPU in the active interposer. The security CPU is responsible for configuring the security policy of the entire chip system during the system startup phase, and the security bus controls access to all small chips during the system running phase. However, this security architecture has two obvious security problems: it cannot guarantee the security of the system startup phase, and it cannot support the identity authentication needs of Internet of Things chips and other networked devices. First, the user of the system cannot confirm the source credibility and code integrity of the code run by the security CPU and each small chip. If the configuration code of the security CPU comes from a malicious attacker or is maliciously tampered with during transmission, the security CPU will not be able to enable the security bus or configure an effective security policy, resulting in the system being unable to resist attacks from malicious small chips during subsequent operation. If the code run by each small chip has security problems, it will greatly increase the likelihood of malicious behavior. Second, networked devices need to support remote users to remotely deploy applications, but this system architecture cannot prove to remote users whether the deployed program is started securely. If the attacker modifies the application program deployed by the remote user, the system will not be able to correctly execute the task initiated by the remote user. SUMMARY

[0004] The present application aims to provide a multi-Chiplet interconnection chip system and a security solution for starting a trust chain to solve the above technical problems.

[0005] To solve the above technical problems, the specific technical scheme of the multi-Chiplet interconnection chip system and the starting trust chain security solution method is as follows: A multi-Chiplet interconnection chip system includes an active interposer and a third-party commodity chip, the third-party commodity chip is integrated on the active interposer, the third-party commodity chip can be purchased by a system designer from a chip market, the active interposer is developed and designed by the system designer and manufactured by a trusted foundry, and the security components include a security CPU, a static measurement component, a dynamic measurement component, an identity authentication component and a secure memory, the security CPU is responsible for coordinating the starting process, the static measurement component includes a plurality of hardware implemented cryptographic algorithm modules and a secure starting ROM in which the first level starting code of the system is solidified, the dynamic measurement component includes a secure register recording measurement information and a communication module contacting a remote authentication platform, the identity authentication component includes a physically unclonable function, and the secure memory is responsible for storing security data information.

[0006] The application further discloses a starting trust chain security solution method of the multi-Chiplet interconnection chip system, which includes the following steps: Step 1: running of static measurement; Step 2: running of dynamic measurement; Step 3: remote user commissioning task.

[0007] Further, the specific process of the step 1 includes a three-level booting process, the measurement operation of digital signature is used to expand the trust from the active interposer root of trust to all chips, the whole booting process involves four parts of code: the code in the active interposer secure starting ROM, the active interposer starting firmware code, the active interposer running system code and the chip running system code, the code in the secure starting ROM has been solidified and is not allowed to be changed, and the remaining three codes need to be selected by a user according to an application scene and burned into the memory of the chip.

[0008] Further, in the first level booting process of the step 1, the security CPU runs the code in the secure starting ROM and completes the signature measurement operation of the interposer starting firmware code, after the digital signature succeeds, the security CPU jumps to the interposer starting firmware code and enters the second level booting stage, in the second level booting process, the security CPU runs the interposer starting firmware code, performs the signature measurement operation on the interposer running system code, and completes the function configuration of the security bus, in the third level booting process, the security CPU jumps to the active interposer running system code, and uses the chip special key to perform the signature measurement operation on the chip running system code.

[0009] Further, the root of trust in step 2 can perform measurement, kernel key data monitoring, user sensitive information collection and kernel event security monitoring on the chiplet, the user confirms the form and sequence of operation according to the specific security requirements, and the dynamic measurement component generates a corresponding report after the measurement operation is completed, stores it in the security register, and initiates a measurement authentication request to the remote authentication platform through the communication module; Whenever the remote authentication platform receives an authentication request, it first confirms whether the running program has a historical version record, and if there is no related record, the running behavior of the system is analyzed according to the measurement report. The remote authentication platform can learn from the measurement reports of the past trusted application programs, obtain the characteristics of the normal running and form an application whitelist for security analysis. If the application behavior shown in the measurement report violates the rules of the whitelist, the application is determined to be untrusted, and the platform will generate an authentication report and feed it back to the active interposer root of trust. The root of trust will immediately prevent the untrusted application from running and restore the system.

[0010] Further, the step 3 includes the following steps: When the remote user entrusts a task to the chip system, the system will assign the application program provided by the remote user to the appropriate chiplet. At this time, the dynamic measurement component in the active interposer root of trust will monitor the running process of the chiplet according to the security requirements of the remote user, and record the key running information to the measurement report. The identity authentication component in the active interposer generates a unique authentication key through the physically unclonable function, and signs the measurement report to obtain an authentication certificate. The remote user confirms the identity information of the host system according to the digital signature in the certificate, and judges whether the application program is normally started and run through the measurement report.

[0011] The multi-Chiplet interconnection chip system and the startup trust chain security solution have the following advantages: 1. The physical isolation characteristics of the active interposer and the third-party chiplet are used to ensure the effectiveness of the security components in the system; 2. The static measurement means can ensure that the code run by the interposer root of trust and each chiplet is from a trusted source, preventing the system from being attacked by unauthorized code and other software threats during the startup process; 3. The version information of the code run by the interposer root of trust and each chiplet can be confirmed, and the version management of the trusted code can be performed during the system startup stage; 4. The remote verification platform can dynamically measure the running behavior of the application program and find untrusted application programs; 5. The remote authentication platform can analyze the behavior characteristics of normal applications through machine learning, and use it as a security baseline to find abnormal applications; 6, Support rollback repair mechanism, can be flexible to deal with the small chip attack behavior caused by software threats; 7, Through the hardware module to realize a variety of cryptographic algorithms, speed up the system startup speed; 8, Using physically unclonable function for chip to generate a unique and non-replicable digital fingerprint, provides a reliable identity verification means for the chip; 9, The reset release timing of the small chip is controlled by the security CPU in the active interposer root of trust, ensuring that the commercial small chip cannot affect the system startup process; 10, The active interposer can use lower production process, and the security components in the interposer can maximize the influence of security function on system performance. BRIEF DESCRIPTION OF DRAWINGS

[0012] Figure 1 is the implementation schematic diagram of the security solution applied to the Chilpet chip system.

[0013] Figure 2 is the running flowchart of static measurement.

[0014] Figure 3 is the running flowchart of dynamic measurement.

[0015] Figure 4 is the specific flowchart of remote user commissioning task. DETAILED DESCRIPTION

[0016] In order to better understand the purpose, structure and function of the present application, the present application of a multi-Chiplet interconnection chip system and a startup trust chain security solution will be further described in detail below in combination with the drawings.

[0017] The application discloses a multi-Chiplet interconnection chip system and a starting trust chain security solution method. All security components are implemented in an interposer, thereby constructing an active interposer trust root. Therefore, the security of the active interposer is very important, and needs to be developed by a chip designer and manufactured by a trusted foundry. The starting trust chain of the system starts from the active interposer trust root, is led by a security CPU in the interposer, and extends the trustworthiness from the trust root to each Chiplet. The security solution provided by the application implements multiple security functions on the active interposer to support the construction of the starting trust chain, and achieves the following two security goals: 1. ensuring the security and trustworthiness of the running code in the interposer and each Chiplet; and 2. supporting the provision of identity authentication information and application behavior characteristics of the device to a remote user. In order to ensure the security and trustworthiness of the running code, the security solution adopts a static measurement means to check the code before application starting, and performs dynamic measurement on the system through a remote verification platform to confirm the trustworthiness of the application program. In order to support the provision of authentication information to the remote user and ensure the correctness of the proof program, the security solution deploys an identity authentication component in the active interposer trust root, can digitally sign the measurement report, and generates an authentication certificate representing the identity of the chip.

[0018] Specifically, as shown in the figure, Figure 1 The application discloses a multi-Chiplet interconnection chip system, which comprises an active interposer and third-party commodity Chiplets. The third-party commodity Chiplets can be purchased by a system designer from a Chiplet market and can be any commercial type functional Chiplet, for example, a processor Chiplet, a memory Chiplet, a cryptographic engine Chiplet or a hardware accelerator Chiplet, and can comprise a processor, a local memory and an accelerator. The active interposer is developed and designed by the system designer and manufactured by a trusted foundry. The security components in the active interposer comprise: 1. a security CPU responsible for coordinating a starting process; 2. a static measurement component comprising a plurality of hardware implemented cryptographic algorithm modules and a security starting ROM in which a first level starting code of the system is fixed; 3. a dynamic measurement component comprising a security register recording measurement information and a communication module contacting a remote authentication platform; 4. an identity authentication component comprising a physically unclonable function; and 5. a security memory responsible for storing security data information.

[0019] The trusted integrated party integrates the third-party commodity Chiplets to the interposer and finally forms a complete multi-Chiplet system. Since the active interposer trust root is designed and manufactured separately, the effectiveness of the security components is guaranteed. Moreover, the Chiplets and the active interposer are physically isolated by nature, and the security components in the trust root can be effectively prevented from being damaged by the Chiplets.

[0020] The application discloses a starting trust chain security solution of a multi-Chiplet interconnection chip system. Step 1: running of static measurement; Figure 1 is a schematic diagram of a running process of static measurement. Figure 2 Figure 1 is a schematic diagram of a running process of static measurement. The specific process comprises a three-stage booting process, and the measurement operation of digital signature extends the trust from the active interposer trust root to all Chiplets. The whole booting process involves four parts of code: code in the secure boot ROM of the active interposer, interposer boot firmware code, active interposer running system code and Chiplet running system code. The code in the secure boot ROM has been solidified and is not allowed to be changed, and the other three parts of code need to be selected by the user according to the application scenario and burned into the memory of the chip.

[0021] In the first-stage booting process, the secure CPU runs the code in the secure boot ROM and completes the signature measurement operation on the interposer boot firmware code. After the digital signature succeeds, the secure CPU jumps to the interposer boot firmware code and enters the second-stage booting phase. In the second-stage booting process, the secure CPU runs the interposer boot firmware code, performs the signature measurement operation on the interposer running system code and completes the function configuration of the secure bus. In the third-stage booting process, the secure CPU jumps to the active interposer running system code and performs the signature measurement operation on each Chiplet running system code using a Chiplet-specific key. The above three-stage booting can ensure that the code sources in the active interposer and each Chiplet are trusted, and the system can start normal running.

[0022] Step 2: running of dynamic measurement; Figure 2 is a schematic diagram of a running process of dynamic measurement. Figure 3 Figure 2 is a schematic diagram of a running process of dynamic measurement. The active interposer trust root in the chip contains the security components required by the dynamic measurement. The trust root performs the measurement operation on the Chiplet, kernel key data monitoring, user sensitive information collection and kernel event security monitoring and the like, and the user can confirm the form and sequence of the operation according to the specific security requirement. The dynamic measurement component generates a corresponding report after the measurement operation is completed, stores the report in a secure register and initiates a measurement authentication request to a remote authentication platform through a communication module.

[0023] Whenever the remote attestation platform receives an authentication request, it first checks if there is a historical record of the running program, and if not, it analyzes the system's running behavior according to the measurement report. The remote attestation platform learns from the measurement reports of trusted applications in the past to obtain the characteristics of normal running and form an application whitelist for security analysis. If the application behavior shown in the measurement report violates the rules of the whitelist, the application is determined to be untrusted, and the platform will generate an attestation report and feed it back to the active interposer root of trust, which will immediately stop the running of the untrusted application and perform a rollback repair on the system.

[0024] Step 3: Remote user commissioning task Attached Figure 4 is a specific flowchart of the remote user commissioning task. When the remote user commissions a task to the chip system, the system will assign the application program provided by the remote user to the appropriate chiplet. At this time, the dynamic measurement component in the active interposer root of trust will monitor the running process of the chiplet according to the security requirements of the remote user, and record the key running information into the measurement report. The identity authentication component in the active interposer will generate a unique authentication key through the physically unclonable function, and digitally sign the measurement report to obtain an attestation certificate. The remote user can confirm the identity information of the host system according to the digital signature in the certificate, and judge whether the application program is normally started and run through the measurement report.

[0025] It can be understood that the present application is described by some embodiments, and those skilled in the art know that various changes or equivalent replacements can be made to these features and embodiments without departing from the spirit and scope of the present application. In addition, under the guidance of the present application, these features and embodiments can be modified to adapt to specific conditions and materials without departing from the spirit and scope of the present application. Therefore, the present application is not limited by the specific embodiments disclosed herein, and all embodiments falling within the scope of the claims of the present application are within the scope of the present application.

Claims

1. A multi-chiplet interconnected chip system, characterized in that: It includes two parts: an active interposer and a third-party commodity chiplet. The third-party commodity chiplet is integrated on the active interposer. The third-party commodity chiplet can be purchased by the system designer from the chiplet market. The active interposer is developed and designed by the system designer and manufactured by a trusted foundry. The security components include: a security CPU, a static measurement component, a dynamic measurement component, an identity authentication component and a secure memory. The security CPU is responsible for coordinating the startup process; the static measurement component contains a variety of hardware-implemented cryptographic algorithm modules and a secure startup ROM that solidifies the system's first-level startup code; the dynamic measurement component contains a security register for recording measurement information and a communication module for communicating with a remote authentication platform; the identity authentication component contains a physically unclonable function; and the secure memory is responsible for storing security data information.

2. A startup trust chain security solution for a multi-chiplet interconnected chip system according to claim 1, characterized in that: The steps include: Step 1: Static measurement operation; Step 2: Run dynamic measurement; Step 3: The remote user delegates the task.

3. The startup trust chain security solution according to claim 2, characterized in that: The specific process of step 1 includes a three-level boot process, which extends the trustworthiness from the active interposer root of trust to all chiplets through the measurement operation of digital signature verification. The entire boot process involves four parts of code: the code in the active interposer secure boot ROM; The active interposer starts the firmware code; the active interposer runs the system code and the chip runs the system code. The code in the secure boot ROM has been solidified and is not allowed to be changed. The other three codes need to be selected by the user according to the application scenario and burned into the chip's memory.

4. The startup trust chain security solution according to claim 3, characterized in that: Step 1: During the first-level boot process, the secure CPU runs the code in the secure boot ROM and completes the signature measurement operation of the intermediary boot firmware code. After the digital signature is successfully verified, the secure CPU will jump to the intermediary boot firmware code and enter the second-level boot phase; During the second-level boot process, the security CPU will run the intermediate layer startup firmware code, perform signature measurement operations on the system code running on the intermediate layer, and complete the functional configuration of the security bus; during the third-level boot process, the security CPU will jump to the active intermediate layer to run the system code, and use the chiplet-specific key to perform signature measurement operations on the system code running on each chiplet.

5. The startup trust chain security solution according to claim 2, characterized in that: In step 2, the root of trust will perform process measurement, kernel key data monitoring, user sensitive information collection, and kernel event security monitoring on the chiplet. The user confirms the form and order of operations based on specific security requirements. The dynamic measurement component will generate a corresponding report after the measurement operation is completed, store it in the security register, and initiate a measurement authentication request to the remote authentication platform through the communication module. Whenever the remote authentication platform receives an authentication request, it first confirms whether the running program has a historical version record. If there is no relevant record, the system's running behavior is analyzed based on the measurement report. The remote authentication platform will perform machine learning on the measurement reports of previous trusted applications to obtain the characteristic rules of normal operation and form an application whitelist for security analysis. If the application behavior shown in the measurement report violates the rules of the whitelist, the application is judged to be untrustworthy. The platform will generate an authentication report and feed it back to the active intermediary layer trust root. The trust root will immediately prevent the untrusted application from running and roll back the system for repair.

6. The startup trust chain security solution according to claim 2, characterized in that: The step 3 comprises the following steps: When a remote user entrusts a task to the chip system, the system will assign the application provided by the remote user to the appropriate chiplet. At this time, the dynamic measurement component in the active intermediary layer's root of trust will monitor the chiplet's operation process according to the remote user's security requirements, and record key operation information in the measurement report. The identity authentication component in the active intermediary layer will generate a unique authentication key through a physically unclonable function, and digitally sign the measurement report to obtain an authentication certificate. The remote user confirms the identity information of the host system based on the digital signature in the certificate, and determines whether the application is started and running normally through the measurement report.