CHIP STACK PROTECTED AGAINST DATA HACKING
Patent Information
- Application Number
- DE602018082253
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2017-09-11
- Filing Date
- 2018-09-04
- Publication Date
- 2025-05-28
- Estimated Expiration
- 2038-09-04
AI Technical Summary
Existing electronic chips, such as bank card chips, are vulnerable to hacker attacks, including etch attacks, fault injection attacks, and electromagnetic analysis, which can compromise confidential data stored on the chips.
A stack of chips is designed with a main chip containing protected components and auxiliary chips on either side, featuring a metal plane connected to ground and insulated conductive tracks forming a tight pattern. These tracks are connected to the main chip and can detect interruptions, providing enhanced protection against various attack methods.
The solution effectively protects the main chip's components by detecting and preventing various types of attacks, including physical, laser, and electromagnetic attacks, thereby safeguarding confidential data without modifying the main chip.
Description
[0001] The present application relates to the field of electronic chips and more particularly relates to a stack of chips comprising a chip protected against hacker attacks. Statement of Prior Art
[0002] Some electronic chips, such as bank card chips, may contain confidential data that hackers could potentially access. This confidential data may be contained in circuits located on the front side of the chip. To obtain this data, a hacker can conduct an attack from the back or front side of the chip.
[0003] In one type of attack, called an etch attack, the hacker etches a portion of the chip's backside. From this etched portion, the hacker etches cavities a few micrometers wide, for example using an ion beam, which extend toward the front side to the circuitry. Electrical contacts with circuit elements are then created in these cavities, and the hacker uses these contacts to analyze the chip in operation.
[0004] In another type of attack, the hacker scans the chip with laser pulses. The impact of the laser beam disrupts the chip's operation. It is by observing the consequences of these disturbances on circuit activity that the hacker successfully carries out his attack. To disrupt the chip's operation, the hacker can also apply positive or negative potentials using a probe in contact with the chip, or induce currents or voltages in circuit elements using a coil placed near the chip. This type of attack is called a fault injection attack.
[0005] In another type of attack, the hacker uses the electromagnetic radiation emitted by the chip to obtain confidential data. Indeed, the switching of the logic gates constituting a circuit produces electromagnetic emissions. However, in a circuit, not all the logic gates switch at each clock cycle and therefore the electromagnetic emissions will be proportional to the number of logic gates switching. Thanks to the use of certain mathematical analysis algorithms (Hamming distance, etc.), it is possible to find the chip's encryption key based on an analysis of the variations in the circuit's electromagnetic emissions.
[0006] Known attack detectors all have one or more of the following drawbacks. Some can only detect a limited number of attack types, often just one. Some are visible to the hacker. Adding certain detectors requires changes to the manufacturing process. Attack detectors are known from WO 2015 / 000813 A1 and DE 199 40 759 A1.
[0007] More specifically, the first document shows a stack of chips comprising: a main chip containing components to be protected; and an auxiliary chip facing one face of the main chip, an area of the auxiliary chip facing the components to be protected comprising at least one insulated conductive track forming a tight pattern facing the components to be protected, the ends of said at least one conductive track being accessible at the main chip.
[0008] The second document shows a stack of chips including: a main chip containing components to be protected; and an auxiliary chip facing each face of the main chip, an area of each auxiliary chip facing the components to be protected comprising a metal plane. Summary
[0009] One embodiment overcomes all or part of the disadvantages of conventional electronic chips protected against attacks.
[0010] Thus, one embodiment provides a stack of chips according to the claim comprising: a main chip containing components to be protected; and an auxiliary chip facing each face of the main chip, the area of each auxiliary chip facing the components to be protected comprising a metal plane connected to ground, and at least one insulated conductive track forming a tight pattern facing the components to be protected, the ends of said at least one conductive track being accessible at the main chip, the metal plane of each auxiliary chip being located between the main chip and the conductive track of said auxiliary chip.
[0011] According to one embodiment, the pattern formed by the conductive tracks is a serpentine.
[0012] According to one embodiment, the pattern formed by the conductive tracks is a spiral.
[0013] According to one embodiment, one end of a conductive track of one auxiliary chip is connected to one end of a conductive track of the other auxiliary chip.
[0014] According to one embodiment, the device is adapted to detect an interruption of the connection between the conductive tracks.
[0015] According to one embodiment, the conductive tracks are connected to a device adapted to detect interruptions of the conductive tracks.
[0016] According to one embodiment, the auxiliary chips are attached to the main chip by metal balls.
[0017] According to one embodiment, the auxiliary chips comprise electronic components.
[0018] According to one embodiment, the metal plane of each auxiliary chip extends over the entire surface of the corresponding auxiliary chip.
[0019] According to one embodiment, the dimensions of one of the auxiliary chips are smaller than those of the other auxiliary chip.
[0020] One embodiment provides a method for protecting components of a main chip containing components to be protected, the method according to independent claim 11 comprising the following steps: providing auxiliary chips each comprising a metal plane connected to ground, and at least one insulated conductive track forming a tight pattern; mounting the auxiliary chips on either side of the main chip in such a way that the metal planes and the conductive tracks are opposite the components to be protected, the metal plane of each auxiliary chip being located between the main chip and the conductive track of said auxiliary chip; connecting the ends of the conductive tracks with the main chip. Brief description of the drawings
[0021] These and other features and advantages will be set forth in detail in the following description of particular embodiments given without limitation in relation to the attached figures, among which: there Figure 1 is a schematic sectional view of one embodiment of a chip stack comprising a protected chip; and Figures 2 and 3 are perspective, schematic and simplified views of examples of the implementation of conductive tracks. Detailed description
[0022] The same elements have been designated by the same references in the various figures and, moreover, the various figures are not drawn to scale. For the sake of clarity, only the elements useful for understanding the embodiments described have been shown and are detailed. In particular, the components of the various chips are not described in detail.
[0023] Unless otherwise specified, the term "substantially" means within 10%, preferably within 5%.
[0024] The expression "interruption of a conductive track" must be understood to mean either a total interruption of the track or a partial interruption, resulting in a change in the resistance of the track.
[0025] There Figure 1 is a schematic sectional view of one embodiment of a chip stack comprising a main chip 2. The main chip 2 has a first face 4 and a second face 6.
[0026] The main chip 2 comprises, on the side of the first face 4, electronic components to be protected 8 containing confidential data. The confidential data are, for example, banking data, personal data or encryption keys.
[0027] The chip 2 further comprises an interconnection network 12 covering the components 8. The interconnection network 12 is made up of metallization levels, not shown, connected to each other, and to the components 8 of the chip, by conductive vias, not shown.
[0028] The main chip 2 further comprises contact pads 14. In the Figure 1 , the contact pads 14 are located at the periphery of the chip 2 and are capable of being connected by conductive wires 16 to external circuits, for example voltage sources, clock signal sources or input / output terminals.
[0029] Auxiliary chips 18 and 20 may each contain electronic components 34. Components 34 do not contain confidential data and there is no need to protect them against hacker attacks. Each chip 18 or 20 then comprises an interconnection network 36 covering the components 34 and connecting them together.
[0030] Each interconnection network 36 is covered with an insulating layer 38 containing at least one conductive track not shown in Figure 1 extending opposite the components to be protected. Each network 36 is separated from the conductive track by an insulating layer 39. The conductive tracks will be described in more detail in relation to the Figures 2 and 3 .
[0031] The layer 38 of each chip 18 and 20 is covered with a metal plane 40 connected to ground. Each metal plane 40 is separated from the associated layer 38 by an insulating layer 41. Each metal plane 40 extends at least over the area located opposite the components 8 to be protected. Each metal plane 40 extends, for example, over the entire chip 18 or 20.
[0032] The metal planes 40 are for example made of copper or aluminum and have a thickness for example between 1 and 5 µm.
[0033] The auxiliary chips 18 and 20 are located on each side of the main chip 2. The chips 18 and 20 are located in such a way that the metal plane 40 of the chip 18 is opposite the first face 4 of the chip 2 and the metal plane 40 of the chip 20 is opposite the second face 6 of the chip 2. The chip 18 is fixed to the chip 2 by metal elements 24 and the chip 20 is fixed to the chip 2 by metal elements 28.
[0034] The metal elements 24 and 28 are, for example, metal balls connecting pads, not shown, of the chips 18 and 20 to pads of the chip 2. The height of the elements 24 and 28, corresponding to the distance between the chip 18 or the chip 20 and the chip 2, is, for example, between 10 and 50 µm.
[0035] At least some of the elements 24 are connected to the interconnection network 12 of the chip 2. These elements 24 can be connected to the metal plane 40 of the chip 18, to the conductive track(s) formed in the layer 38 of the chip 18 by means of isolated vias (not shown) crossing the metal plane 40 of the chip 18, or to the interconnection network 36 of the chip 18 by means of isolated vias (not shown) crossing the metal plane 40 and the layer 38 of the chip 18.
[0036] At least some of the elements 28 are connected to the interconnection network 12 of the chip 2 by means of vias 42 crossing the chip 2 from the second face 6 to the network 12. These elements 28 can be connected to the plane 40 of the chip 20, to the conductive track(s) of the layer 38 of the chip 20 by means of an isolated via (not shown) crossing the metal plane 40 of the chip 20, or to the interconnection network 36 of the chip 20 by means of isolated vias (not shown) crossing the metal plane 40 and the layer 38 of the chip 20.
[0037] For the sake of clarity, only one via 42 has been shown in Figure 1 . However, there can be as many as needed.
[0038] Chip 18, in the example of the Figure 1, has dimensions smaller than the dimensions of the chip 2 so as to allow access to the contact pads 14. The dimensions of the chip 18 are nevertheless at least sufficient to cover all of the components to be protected 8 and the interconnection network 12 connecting them.
[0039] Chip 20, in the example of the Figure 1 , has dimensions substantially equal to those of chip 2. The dimensions of chip 20 may nevertheless be different from those of chip 2, while remaining sufficient to cover all of the components 8 to be protected.
[0040] As a variant, not shown, it is possible for the connections made by the conductive wires 16 to be made in a different manner. For example, the contact pads 14 can be located on the face of the chip 18 opposite the metal plane 40 and the connection with the chip 2 can then be made by means of metal elements 24 and vias passing through the chip 18 to the contact pads 14. The chip 18 can then have dimensions substantially equal to those of the chip 2.
[0041] There Figure 2 is a schematic and simplified perspective view of the embodiment described in relation to the Figure 1 representing an example of a conductive track pattern. Chip 18 is represented here only by a plane 48 containing a conductive track 43. Similarly, chip 20 is represented only by a plane 49 containing a conductive track 43. Chip 2 is represented only by a parallelepiped.
[0042] In this example, the conductive track 43 of each layer 38 has a serpentine shape and has ends 50 and 52. The ends 50 of the tracks are connected together by a connection 54. The connection 54 corresponds, for example, in relation to the Figure 1, to an isolated via crossing the metal plane 40 of the chip 18, to a metal element 24, to the interconnection network 12, to a via 42 crossing the chip 2, to a metal element 28 and to another via crossing the metal plane 40 of the chip 20. The conductive tracks 43 and the connection 54 therefore form an electrically continuous path going from one end 52 to the other. The ends 52 of the conductive tracks 43 are connected, by connections 56, to a device, not shown, adapted to detect the interruption of the electrically continuous path, that is to say the total or partial interruption of one of the conductive tracks 43 or the interruption of one of the connections 54 or 56. The device is located among the components to be protected (8, Figure 1 ) of chip 2. Thus, the device is protected from hackers who cannot then interfere with its operation, for example by disabling it.
[0043] The patterns of the conductive tracks are tight patterns, that is to say that the spacing between two neighboring portions of conductive track is relatively small. The choice of the dimensions of the tracks and the spacing separating neighboring portions of track is made according to existing etching technologies, in such a way that any attempt at etching attack results in the total or partial interruption of a conductive track.
[0044] A step of detecting interruption of the conductive tracks 43 and of the connection 54 can for example be carried out after a manual command, automatically at regular intervals or at each start of the chip, during initialization.
[0045] There Figure 3 is a schematic and simplified perspective view of an alternative embodiment. The figure represents another example of a conductive track pattern. The Figure 3 includes elements identical to elements of the Figure 2 , designated by the same references. The Figure 3 represents an electrically continuous path starting at chip 2, where it is connected to a device, not shown, for detecting interruption of the path. The path then alternates, via a connection 56 and connections 54 described previously, between conductive tracks 43 of chips 18 and 20 before joining chip 2 and the detection device via a connection 56.
[0046] Alternatively, it is possible to form several electrically distinct continuous paths, each connected to a device adapted to detect the interruption of the path and located among the components to be protected 8 of the chip 2. For example, it is possible to form a path going from the chip 2 to the layer 38 of the chip 18, extending in this layer 38 and joining the chip 2, as well as a similar path for the chip 20. Each of these paths makes it possible to detect the piercing of the chip, 18 or 20, in which it is formed, or its separation from the chip 2. There is then no direct connection (for example a connection 54) between the tracks of the chip 18 and the chip 20.
[0047] Physical attacks such as drilling one of the chips 18 or 20, for example to place a contact at the interconnection network, can reach the components 34 and the interconnection networks 36 of said chip 18 or 20. However, the chips 18 and 20 do not contain confidential data. Such an attack targeting the chip 2, which contains confidential data, causes a total or partial interruption of a conductive track of a layer 38 and is detected. Removing one of the chips 18 and 20 so as to have access to the chip 2 causes the interruption of a connection 54 or 56 and the detection of the attack.
[0048] Laser attacks can, like physical attacks, reach chips 18 and 20. However, the metal planes 40 stop the laser beam which cannot therefore reach chip 2. The auxiliary chips 18 and 20 may also include laser beam detectors, for example photodiodes, so as to detect a laser beam attack. The auxiliary chips 18 and 20 may also include additional protection devices.
[0049] The metal planes 40 connected to ground form a Faraday cage around the components 8. It is therefore not possible for a hacker to analyze the electromagnetic emissions of chip 2.
[0050] An advantage of the embodiments described above is that the chip 2 that is to be protected is not modified by the protection devices.
[0051] As a variant which is not part of the claimed invention, the metal planes 40 and the conductive tracks 43, as well as the insulating layers separating them, may not be located, as in the Figure 1 , in chips 18 and 20 different from the protected chip 2, but can cover the first and second faces of the chip 2, framing the components 8.
[0052] An advantage of these embodiments is that the conductive track interruption detector is among the components 8 and is protected. It cannot therefore be reached by the hacker.
[0053] Particular embodiments have been described. Various variants and modifications will be apparent to those skilled in the art. In particular, other patterns are possible for the conductive tracks 43 of the layers 38. The conductive tracks 43 may, for example, take the form of one or more spirals or the form of lines. The patterns of the conductive tracks 43 of a chip 18 or 20 may extend over several levels.
Claims
1. A chip stack comprising: a main chip (2) containing components to be protected (8); and an auxiliary chip (18, 20) opposite each surface (4, 6) of the main chip (2), an area of each auxiliary chip opposite the components to be protected (8) comprising a metal plane (40) connected to ground, and at least one insulated conductive track (43) forming a tight pattern opposite the components to be protected (8), the ends (50, 52) of said at least one conductive track being accessible at the level of the main chip (2), the metal plane of each auxiliary chip being located between the main chip and the conductive track of said auxiliary chip.
2. The chip stack of claim 1, wherein the pattern formed by the conductive tracks (43) is serpentine shaped.
3. The chip stack of claim 1, wherein the pattern formed by the conductive tracks (43) is a spiral.
4. The chip stack of any of claims 1 to 3, wherein one end (50) of a conductive track (43) of an auxiliary chip (18, 20) is connected to an end (50) of a conductive track (43) of the other auxiliary chip (18, 20).
5. The chip stack of claim 4, wherein the conductive tracks (43) are connected to a device capable of detecting interruptions of the conductive tracks (43).
6. The chip stack of any of claims 1 to 5, wherein the device is capable of detecting an interruption of the connection (54, 56) between the conductive tracks (43).
7. The chip stack of any of claims 1 to 6, wherein the auxiliary chips (18, 20) are affixed to the main chip (2) by metal bumps (24, 28).
8. The chip stack of any of claims 1 to 7, wherein the auxiliary chips (18, 20) comprise electronic components (34).
9. The chip stack of any of claims 1 to 8, wherein the metal plane (40) of each auxiliary chip (18, 20) extends over the entire surface of the corresponding auxiliary chip.
10. The chip stack of any of claims 1 to 9, wherein the dimensions of one of the auxiliary chips (18, 20) are smaller than those of the main chip (2).
11. A method of protecting components (8) of a main chip (2) containing components to be protected (8) comprising the steps of: providing auxiliary chips (18, 20) each comprising a metal plane (40) connected to ground, and at least one insulated conductive track (43) forming a tight pattern; assembling the auxiliary chips (18, 20) on either side of the main chip (2) so that the metal planes (40) and the conductive tracks (43) are opposite the components to be protected (8); and connecting the ends (50, 52) of the conductive tracks (43) to the main chip (2).