Protective semiconductor device for bonded structures
Patent Information
- Application Number
- JP2024506506
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-08-02
- Filing Date
- 2022-07-29
- Publication Date
- 2025-07-16
AI Technical Summary
Existing semiconductor chips with security-critical elements are vulnerable to various hacking techniques, including optical probing and focused ion beam attacks, which compromise the security and integrity of sensitive circuitry.
A bonded structure is formed by directly bonding a semiconductor device with a protection device, incorporating a blocking layer and a protection circuit layer to prevent external access and detect or disrupt unauthorized access, using non-conductive bonding without adhesives to enhance security.
The bonded structure effectively thwarts optical and FIB attacks by obstructing access to sensitive circuitry and detecting intrusion attempts, ensuring the security and integrity of the semiconductor chip.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The technical field relates to bonded structures having active and / or protective semiconductor devices and methods of forming the bonded structures.
[0002] [Citation to Related Applications] This application claims priority to U.S. Provisional Patent Application No. 63 / 203,867, filed August 2, 2021, which is incorporated by reference in its entirety and incorporated herein by reference for all purposes. [Background technology]
[0003] A semiconductor chip (e.g., an integrated device die) may include active circuits populated with security-critical elements that contain valuable and / or proprietary (sensitive) information, structures, or devices. For example, such security-critical elements may include an entity's intellectual property, software or hardware security (e.g., encryption) features, privacy data, or any other elements or data that an entity may wish to remain secure and hidden from third parties. For example, a bad actor as a third party may attempt to gain access to the security-critical elements using various techniques to gain economic and / or geopolitical advantage. Thus, there is a continuing need to increase the security of semiconductor chips from third party access enforcement. Summary of the Invention
[0004] According to one aspect of the present invention, there is provided a bonded structure comprising a semiconductor element having an active circuitry and a protection element bonded directly to the semiconductor element along a bonding interface without adhesive, the protection element having a blocking layer configured to inhibit external access to at least a portion of the active circuitry, and a protection circuit layer disposed within the protection element, the protection circuit layer configured to detect or disrupt external access to the active circuitry of the semiconductor element.
[0005] According to another aspect of the present invention, there is provided a method of forming a bonded structure comprising the steps of directly bonding a semiconductor element to a protection element without an adhesive, the semiconductor element having active circuitry, the protection element having a blocking layer and a protection circuit layer disposed within the protection element, the blocking layer configured to inhibit external access to at least a portion of the active circuitry, and the protection circuit layer configured to detect or disrupt external access to the active circuitry of the semiconductor element.
[0006] In accordance with yet another aspect of the present invention, there is provided a bonded structure comprising a semiconductor element having a first active circuit and a protection element bonded directly to the semiconductor element along a bonding interface without adhesive, the protection element having a protection circuit layer disposed within the protection element, the protection circuit layer having a second active circuit configured to detect or disrupt external access to the first active circuit of the semiconductor element.
[0007] In accordance with yet another aspect of the present invention, there is provided a bonded structure comprising a semiconductor device having active circuitry and a protection device bonded directly to a backside of the semiconductor device along a bonding interface without adhesive, the protection device having a blocking layer configured to inhibit external access to the active circuitry of the semiconductor device, and a protection circuit layer disposed within the protection device, the protection circuit layer configured to detect or disrupt external access to the active circuitry of the semiconductor device.
[0008] In accordance with yet another aspect of the present invention, there is provided a bonded structure comprising a semiconductor device having active circuitry and a protection device bonded directly to a backside of the semiconductor device without adhesive along a bonding interface, the protection device having a blocking layer configured to inhibit external access to the active circuitry of the semiconductor device, the blocking layer being vertically spaced from the active circuitry by at least 20 microns. [Brief description of the drawings]
[0009] [Figure 1] 1 is an exemplary diagram of optical imaging of a semiconductor chip. [Diagram 2] 1 is an exemplary diagram of a focused ion beam (FIB) attack of a semiconductor chip. [Diagram 3] 1 is a schematic cross-sectional side view illustrating an example solution to an intrusive chip attack. [Figure 4A] 1 is a schematic cross-sectional side view showing an example diagram of a protective chip including a protective layer. [Figure 4B] 1 is a schematic cross-sectional side view showing an example diagram of a protective chip including a protective layer in association with a disturbing layer. [Diagram 5] 13 is an exemplary diagram of additional parameters of the protection chip. FIG. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0010] As described herein, a third party (e.g., a bad actor) may attempt to access security-critical (sometimes referred to hereinafter as "sensitive") elements implemented in a device, such as an integrated device die. In some devices, the security-critical elements may be protected by a combination of netlist and non-volatile memory (NVM) data. However, a third party may attempt to hack the security-critical elements by a combination of destructive and non-destructive techniques, such as by various probing techniques (e.g., electro-optical probing) and / or by delayering the device to expose the security-critical elements and then reverse engineer and gain access to the security-critical elements in a different manner. In some cases, a third party may attempt to hack security-critical devices by pulsing electromagnetic (EM) waves into the active circuitry of the device, using fault injection techniques, near-infrared (NIR) laser triggering or focused ion beam (FIB) modification of the circuitry, chemical etching techniques, and employing other physical, chemical, and / or electromagnetic hacking tools and even reverse engineering. These techniques may be used to physically access the sensitive circuitry of a microdevice, such as an integrated circuit, to directly read encrypted information, to trigger the circuitry to release information that is otherwise encrypted, to understand the manufacturing process, to extract enough information to ultimately be able to replicate the sensitive design, or to completely bypass security protocols to activate or use the chip without legitimate authorization. For example, in some cases, a hacker may attempt to access encryption keys, which may be stored in the circuit design, memory, or a combination of both. Techniques may also be used to indirectly read sensitive information by analyzing the resulting output based on fault injection inputs and determine the encryption key or data content by recursive analysis.Architecturally protecting security-critical components mounted on a device is a challenge.
[0011] Therefore, it is important to provide improved security for various elements (e.g., semiconductor integrated device dies) including security-sensitive elements. Various embodiments disclosed herein relate to a bonded structure including a first semiconductor element bonded to a second semiconductor element. The second semiconductor element may include a protection element including multiple layers disposed over an active circuit of the first semiconductor element and configured to inhibit communication of the active circuit.
[0012] Semiconductor chips face both hardware and software level attacks, and in some cases these may be combined into a single technique. For example, a hardware attack on a chip can alter the logic of a software program by providing erroneous or false data, or by affecting the logic circuits used to process the data.
[0013] Many techniques have been employed by attackers to compromise sensitive semiconductor chips. These may include physical tampering by etching, grinding, or other deencapsulation techniques to expose the sensitive circuitry of the chip. More sophisticated attacks may even employ optical probing of the sensitive circuitry. Of these, focused ion beam (FIB) and laser probing are the most prevalent. Many protective defenses have been used or proposed in the past, but with limited effectiveness, as described in more detail below.
[0014] FIG. 1 provides an overview of optical imaging attacks using laser probing. Optical probing techniques may be used to access active circuitry 116 (e.g., electronic circuitry including at least one transistor) of a semiconductor chip 100 that includes sensitive circuitry (e.g., circuitry vulnerable to hacking attacks). Optical probing techniques allow an attacker to reconfigure the sensitive circuitry, thereby compromising the reliability and security of the sensitive circuitry. Optical probing techniques may be used to access the active circuitry 116 from the backside 112 of the semiconductor device 100 because the optical probe 126 from the backside 112 is not blocked by any wiring or metallization, as opposed to the frontside 114 of the semiconductor device 100. In the devices shown herein, the active circuitry 116 may be located closer to the frontside 114 of the semiconductor device than the backside 112 of the device 100. For example, the active circuitry 116 may be patterned at or near the frontside 114 of the device 100. The optical probe 126 includes a laser source 122, a beam splitter 120, a detector 124, and an objective lens 118. The laser source 122 generates a laser beam and directs it to the beam splitter 120, which can split the beam into a first component that is directed through the objective lens 118 to the semiconductor device 100 and a second component that is directed to the mirror 128 and the detector 124. Backside optical intrusion techniques can also be used to monitor circuit activity to collect bitstream information to retrieve encryption keys and leak encrypted information. Laser probing can be performed, for example, by scanning the deencapsulated chip with a near-infrared (NIR) laser to image the circuitry on the chip and capture waveform information of the active chip. By capturing the variance in reflectivity of the circuit paths over time caused by the shifting electromagnetic fields of the circuit paths, laser probing can be used to capture and reconstruct the secret bitstream information.In some cases, laser probing may be designed to activate a specific set of sensitive transistors or circuits within the chip, which once activated during this type of hacking may emit a small amount of IR that is captured by a detector to pinpoint the exact location of interest to the hacker. In some cases, this attack can be used to leak encryption keys. Additionally, imaging of sensitive circuits may allow a hacker to reconstruct sensitive algorithms and other data.
[0015] Thus, preventing optical intrusion is important to ensure the security of semiconductor chips that implement security-critical devices. Conventional techniques may involve packaging semiconductor devices in a protective casing. However, conventional packaging may be subject to less-than-subtle grinding, chemical etching, and other package decapping, which may leave the sensitive circuitry exposed and vulnerable to optical probing. Thus, it may be desirable to provide protection against optical intrusion by bonding one or more protective devices directly to the semiconductor device, e.g., an active chip with active circuitry 116 that includes the sensitive circuitry. The semiconductor device 100, e.g., an integrated device die or chip, may be mounted or stacked on other devices. For example, the semiconductor device 100 may be attached to a carrier, e.g., a package substrate, an interposer, a reconstituted wafer or device, or the like. In another embodiment, the semiconductor device 100 may be stacked on top of another semiconductor device 100, for example, a first integrated device die may be stacked on top of a second integrated device die. In some configurations, through-substrate vias (TSVs) extend vertically through the thickness of the semiconductor device 100 to allow electrical signals to pass through the semiconductor device 100, for example, from a first surface of the semiconductor device 100 to a second, opposing surface of the semiconductor device 100.
[0016] Thus, to prevent optical imaging of the security semiconductor chip 100, a protection element may be incorporated into the chip itself, for example, into a blocking or polishing layer applied to the security semiconductor layer. Direct bonding of the blocking layer may be effective against conventional deencapsulation techniques, which prevent exposure of the security circuit layers of the chip due to grinding or etching. However, invasive attacks may be used to thwart these protection measures. As mentioned above, many techniques have been employed by attackers to compromise security semiconductor chips. For example, a hacker may recreate a 2D activity map of the active circuitry 116 by laser probing the chip. Furthermore, imaging attacks may be utilized to decrypt bitstream encrypted information found therein. Thus, the security semiconductor elements described herein block or modify reflected optical signals (e.g., IR) to help improve the security of the chip (e.g., the semiconductor device 100) against contactless tampering.
[0017] FIG. 2 illustrates an exemplary FIB attack. A FIB attack may use a focused ion beam to ablate the surface of the deencapsulated chip layers, layer by layer, thereby removing the protective elements and exposing the sensitive semiconductor layers. For example, as shown in FIG. 2, the target wire 204 may be exposed by ablation of the intervening protective wires 202A, 202B. Ablation with the focused ion beam may result in holes 206 that penetrate the chip and the protective wires 202A, 202B in a conical pattern with a depth d′. The FIB may then be used at low intensity to provide high-precision imaging of the sensitive layers (e.g., wires 204). Additionally, the FIB may alter the function of the active chip by inducing current flow and cutting or altering traces connecting elements of the sensitive circuit. This may allow an attacker to modify and / or bypass protective structures in the sensitive semiconductor layers. Additionally, a FIB or laser probe can be used after ablation to capture bitstream information or image sensitive circuit elements.
[0018] These invasive physical attacks allow hackers to access and directly monitor security-critical nets in an IC and extract sensitive information. These types of attacks typically occur on the front side of the chip, but can also occur on the back side.
[0019] FIG. 3 illustrates an example of a protection measure employed to thwart imaging attacks of a sensitive semiconductor chip. As shown in FIG. 3, an active chip 310 may be bonded (e.g., directly bonded without adhesive) to a protection chip 300 that includes a jamming layer 305. As shown, the protection chip 300 may be directly bonded to a backside 112 of the active chip 310 that is opposite a frontside 114 (the frontside may include an active side that is closer to the active circuitry 116 than the backside 112). In some configurations, the jamming layer 305 may be an optically occlusive layer designed to thwart laser probing, FIB, or other hacking techniques of the active circuitry layer 116 of the active chip 310, as described, for example, in U.S. Patent Application No. 17 / 812,675, filed July 14, 2022, which is incorporated by reference in its entirety. As shown in Figure 2 above, the degree of protection this provides against FIB attack is limited: a motivated attacker could, for example, identify a target area 204 of the active tip 310 and employ a FIB attack to remove portions of the disturbing layer 305 covering the target area 204 of the tip 310, thereby leaving the target area exposed to probing.
[0020] The disturbance layer 305 may include several layers, such as multiple metallization layers (e.g., 342A, 342B), separated by insulating material 393. In some embodiments, the metallization layers 342A, 342B and the intervening insulating material 393 form a capacitive circuit with positive and negative terminals respectively connected to two illustrated through-substrate vias (TSVs) 330.
[0021] As shown, the bond or bonding interface 315 may include a bond between the bonding layer 340A of the protective chip 300 and the bonding layer 340B of the active chip 310. The direct bond may comprise a non-conductive, non-adhesive bond in which the non-conductive layers 341A, 341B (e.g., dielectric) of the bonding layers 340A, 340B are bonded directly to one another. As shown, the protective chip 300 is bonded to the backside 312 of the active chip 310. Additionally, the disturbing layer 305 is disposed proximate to the bonding layer 340A of the protective chip 310. In some embodiments, the direct bond may comprise a hybrid bond in which the conductive contact feature 350B of the active chip 310 is directly bonded to the corresponding conductive contact feature 350A of the protective chip 300, and the non-conductive region (e.g., non-conductive layer 341B) of the active chip 310 is directly bonded to the corresponding non-conductive region (e.g., non-conductive layer 341A) of the protective chip 300. Additionally, the bonding layer 340A, 340B of each chip 300, 310 may include a plurality of conductive contact features 350A, 350B disposed within the non-conductive layer 341A, 341B, e.g., a dielectric layer (e.g., silicon oxide, silicon nitride, silicon oxycarbonitride, etc.). The conductive contact features 350A, 350B may be comprised of a conductive material, e.g., a metal, e.g., copper, for direct hybrid bonding. The conductive contact features 350A of the protective chip 300 may be configured to mirror and / or correspond to the conductive contact features 350B of the active chip 310. A pad may provide an electrical and / or mechanical connection between the protective chip and the active chip. As used herein, a pad may include an exposed end of a through-substrate via (TSV) 330 or vertical interconnect 330 (e.g., shown as pad 350A) or may consist of a separate pad (e.g., shown as pad 350B) at least partially embedded within a field region.
[0022] In some cases, the active chip 310 may be configured to detect changes in the protection chip 300. For example, as shown in FIG. 3, the protection chip 300 may be electrically connected to the active circuitry 116 of the active chip 310 by through-substrate vias (TSVs) 330 that allow the active chip 310 to detect changes in the properties of the protection chip 300 caused by removal of material from the disturbance layer 305. In some embodiments, the protection chip 300 may be electrically connected to the active chip 310 by direct hybrid bonds or other interconnection techniques. The active chip 310 may be configured to measure the resistance or capacitance of the disturbance layer 305 or other structures fabricated in the protection chip. If substantial changes in the disturbance layer 305 or such structures occur, the active chip 310 may detect the change and disable the sensitive circuit elements. However, FIB attacks are extremely precise and the portions of the disturbing layer 305 ablated by the FIB may be so small that they do not cause a measurable change in the electrical properties of the disturbing layer 305. Embodiments of the present invention relate to a bonded structure that is resistant to invasive attacks and includes a protective layer bonded directly to an active chip 310 that may contain security-critical circuits or circuit elements.
[0023] 4A illustrates an exemplary embodiment of the present invention that aims to eliminate the shortcomings of other solutions for protecting a sensitive semiconductor device chip 100 from subtle intrusions employing optical and / or invasive FIB attacks. As shown in FIGs. 4A and 4B, embodiments of the present invention may include a protection chip 300 having a protection circuit layer 410 that is bonded directly to an active chip 310 (e.g., to the backside 112 of the chip 310). The protection circuit layer 410 may be configured to detect or disrupt external access to the protection device and / or active circuitry of the semiconductor device. In some embodiments, for example, as shown in FIG. 4B, the disclosed embodiments may include a disturbance layer 305 formed within the protection chip 300 and a separate protection circuit layer 410, which layers 305, 410 may be bonded directly to the active chip 310 (e.g., the backside 112 of the chip 310) to protect the active circuitry 116 of the active chip 310. The active circuitry 116 is located near the front side 114 of the active chip 310 in the illustrated embodiment. As discussed above, non-bonded protection structures may be amenable to removal by relatively easy removal techniques, such as grinding or etching. Therefore, it may be desirable to incorporate the protection chip 300 and the active chip 310 into a bonded structure.
[0024] In some embodiments, the bond interface 315 may include a bond between a bonding layer 340A of the protective chip 300 and a bonding layer 340B of the active chip 310, which in the illustrated embodiment may be formed at or at least partially constitute the backside 112 of the chip 310. In some embodiments, the direct bond may include a non-conductive non-adhesive bond in which the non-conductive materials of the elements (e.g., dielectric and / or semiconductor 341A, 341B) are bonded directly to each other. In the illustrated embodiment, the direct bonds may include hybrid bonds in which a conductive contact feature or pad 350A of the active chip 310 is also directly bonded to a corresponding conductive contact feature 350B of the protective chip 300, and a non-conductive region (e.g., bonding layer 340B) of the active chip 310 is directly bonded to a corresponding non-conductive region (e.g., bonding layer 340A) of the protective chip 300. As shown in FIG. 4A, the bonding layer 315 of each chip may include a number of contact pads 350 disposed within a non-conductive material, such as a non-conductive or dielectric layer 341 (e.g., silicon oxide, silicon nitride, silicon oxycarbonitride, etc.). The contact pads 350 may be made of a conductive material, such as a metal, for example copper. In these embodiments, the contact pads 350 of the protective chip 300 may be configured to mirror and / or correspond to the contact pads 350 of the active chip 310. Pads 350 can provide an electrical and / or mechanical connection between protective chip 300 and active chip 310. Similarly, contact pads 350 of bonding layer 315 of active chip 310 can be connected to active circuitry 116 of active chip 310 via TSVs 330. By bonding contact pads 350A of protective chip 300 to corresponding contact pads 350B of active chip 310, in some embodiments, the bonded structure can thus provide an electrical connection between active circuitry 116 of active chip 310 and one or more layers of protective chip 300.For example, the protection chip 300 may have vertical connectors (e.g., vertical interconnects) 360 that provide electrical connection between the protection circuit layer 410 and the contact pads 350 of the bonding layer 315. In this case, the protection circuit layer 410 of the protection chip 300 may be configured to communicate with the active layer 116 of the active chip 310 across the bond interface via the TSVs 330.
[0025] As shown in FIG. 4A, the protection chip 300 may include a protection circuit layer 410. The protection circuit layer 410 described herein may be configured to detect or disrupt external access to at least one of the protection chip 300 and the active circuitry 116 of the active chip 310. In some embodiments, for example, the protection circuit layer 410 may include circuitry, such as throw-away logic, that does not provide functional processing to the active chip 310 but may be configured to detect intrusions by hackers to protect the active circuitry 116 of the chip 310. In these embodiments, the circuitry in the protection circuit layer 410 may be configured to mimic the appearance of sensitive active circuitry. For example, the protection chip 300 may include a protection circuit layer 410 with non-sensitive circuitry to waste an attacker's time and prolong the analysis required to identify sensitive areas of the active chip 310, thereby disrupting external access to the active circuitry 116 of the chip 310. The protection circuit layer 410 of the protection chip 300 shown herein may include an active circuit layer. In such embodiments, the active protection circuit layer 410 may include at least one transistor, such as a plurality of transistors. In these embodiments, the protection circuit layer 410 may include circuitry that provides additional non-sensitive functionality to the active chip 310. In some embodiments, the inexpensive active circuitry in the protection circuit layer 410 on the protection chip 300 may provide misleading or confusing data to an optical attacker as the laser probe is reflected by the inexpensive low logic circuitry in the protection circuit layer 410 on the protection chip 300 rather than from the active chip 310 to be protected, thereby confusing external access to the chip 310. In these embodiments, an attacker may employ a FIB to drill down to the active chip 310, thereby disabling or causing the active chip 310 to malfunction by ablating the intervening protection circuit layer 410 of the protection chip 300.If one or more transistors of the protection circuit layer 410 are destroyed or otherwise tampered with, the protection circuit layer 410 can detect the external access and can send an alert to the active circuit 116 of the chip 310 indicating the intrusion. In response, the active chip 310 can disable the functionality of the chip 310, causing the active circuit 116 to self-destruct or become inoperative, or preventing external access to the circuit 116. In some embodiments, the protection circuit layer 410 can include active circuitry configured to provide a signal or feedback to the active circuit 116 of the active chip 310. In these embodiments, any errors introduced into the protection layer 410 through ablation from the FIB can cause a signal from the protection circuit layer 410 to cease or change, thereby alerting the active chip 310 that the protection chip 300 has been tampered with. For example, the protection layer 410 can include active circuitry configured to provide an encrypted timing signal to the active chip 310. If the encrypted timing signals are altered by an external intrusion attempt, an alert can be issued to the active chip 310 of the external access.
[0026] In the illustrated embodiment, the active circuitry of the protection circuitry layer 410 may include one or more transistors. In some embodiments, the operational processing circuitry of the active chip 310 may use the most advanced processes used to form the transistors in the active chip 310, while the active circuitry of the protection chip 300 (in the protection circuitry layer 410) may be fabricated using less expensive and less advanced processing techniques since the protection chip 300 may utilize only basic functionality without requiring advanced circuitry. As an example, the operational processing circuitry 116 of the active chip 310 may use advanced processes, such as advanced sub-22 nm node processes. In contrast, the active circuitry layer of the protection device 300 or the protection circuitry layer 410 of the chip may have transistors with larger feature sizes, such as legacy node processes of 65 nm or greater. In the illustrated embodiment, the protection circuitry layer 410 may be disposed within (e.g., entirely within) the body of the protection device 300. In some embodiments, the transistors in the protection element 300 can serve to alert the active chip 310 when the protection chip 300 has been tampered with. In some embodiments, the active circuitry (e.g., including one or more transistors) in the protection circuit layer 410 of the protection element 300 can activate or cause the security circuitry 116 of the active chip 310 to stop operating or functioning in a normal manner. Thus, the protection circuit layer 410 deters attacks by ablation from the FIB. The protective materials used in the protective chip 300 (including the materials used in the disturbing layer 305 and the protective circuit layer 410) include, but are not limited to, the protective materials described in U.S. patent application Ser. No. 16 / 844,932, filed April 9, 2020, U.S. patent application Ser. No. 16 / 844,941, filed April 9, 2020, U.S. patent application Ser. No. 16 / 881,621, filed May 22, 2020, and U.S. patent application Ser. No. 16 / 846,177, filed April 10, 2020, each of which is incorporated by reference in its entirety and incorporated herein by reference for all purposes.
[0027] As shown in FIG. 4B, the protection chip 300 may further include a jamming layer 305 that is separate from and vertically spaced apart from the protection circuit layer 410. In some embodiments, the jamming layer 305 may include multiple metallization layers 342A, 342B separated by an insulating layer 393 that renders the layer 305 opaque to the irradiation of the laser probe. In other embodiments, the jamming layer 305 may include an optical filter. In order to increase the cost of analyzing the security chip, it may be desirable to provide the attacker with misleading or confusing data to slow down the analysis process. Thus, instead of simply blocking the optical signal, it may be beneficial to modify the signal. An optical filter may be used to modify the optical signal. For example, in some embodiments, the optical filter may include a refractive filter. In these embodiments, the jamming layer 305 may cause the attacker's laser probe to make inaccurate measurements. As described in U.S. Patent Application Serial No. 17 / 812,675, which is incorporated herein by reference, the occlusion layer can redirect an incoming or outgoing beam (e.g., refract), focus or defocus the beam (e.g., lens effect), scatter the beam, spread the beam, diffract the beam (e.g., diffraction grating), phase / wavelength shift the beam, etc. Thus, metallization layers 342A, 342B refer to light blocking or light modifying materials that block or modify incident light utilized in attempts to hack security circuits.
[0028] In some embodiments, the bonded contact pads or features (e.g., 350A) of the bonding layer 315 of the protection chip 300 may be further connected to one or more blocking layers of the protection chip 300 by through-semiconductor via vertical connectors 360, as shown in the embodiment of FIG. 4B. Additionally or alternatively, the disturbance layer 305 of the protection chip 300 may be connected to the active layer 116 of the active chip 310 and / or to the protection circuit layer 410 of the protection chip 300, as shown in FIG. 4B. For example, the disturbance layer 305 of the protection chip 300 may be electrically connected to the protection layer 410 of the protection chip 300 by one or more vertical interconnects 360.
[0029] 4B illustrates the disturbance layer 305 electrically connected to the circuitry 116 of the active chip 310 by contact pads 350A, 350B and TSVs 330 formed in the active chip 310. In some embodiments, the disturbance layer 305 may further include a detection circuit. In these embodiments, the active chip 310 may be configured to respond to a change in one or more characteristics of the detection circuit in the disturbance layer 305 through the TSVs 330. In some embodiments, the detection circuit may be configured to allow detection of a resistance of the disturbance layer 305 of the protection chip 300 or a portion of the disturbance layer 305 of the protection chip 300. Additionally or alternatively, the detection circuit may be configured to allow detection of a capacitance of the disturbance layer 305 of the protection chip 300 or a portion of the disturbance layer 305. In these embodiments, the active chip 310 may be responsive to removal of a sufficiently large portion of the protection chip 300. For example, the FIB probe may be used to ablate some portions of the disturbance layer 305 of the protection chip 300 to expose the sensitive semiconductor layer of the active chip 310. By removing these portions of the protection chip 300, the FIB may change the capacitance and / or resistance or impedance of the disturbance layer 305 of the protection chip 300 to an extent that is detectable by the detection circuitry. In these embodiments, the active chip 310 may be configured to shut down when it detects a change in the disturbance layer 305 of the protection chip 300. Additionally or alternatively, the active chip 310 may be configured to emit an alarm signal when it detects a change in the disturbance layer 305 of the protection chip 300. The disturbance layer 305 of the protection chip 300 may additionally or alternatively be connected to the protection circuit layer 410 of the protection chip 300 by an additional vertical connector 360. In these embodiments, the protection layer 410 of the protection chip 300 may be configured to respond to changes in the properties of the disturbance layer 305 of the protection chip 300. In some embodiments, the protection circuit layer 410 of the protection chip 300 may be configured to disable the active chip 310 when a change in the protection chip 300 is detected.
[0030] As shown in FIG. 4B, the blocking layer 305 of the protection chip 300 may be disposed between the protection layer 410 of the protection chip 300 and the active layer 116 of the active chip 310. Those skilled in the art should understand that this is for illustrative purposes only. In other embodiments, the protection layer 410 of the protection chip 300 may be located between the blocking layer 305 of the protection chip 300 and the active layer of the active chip 310. Furthermore, in some embodiments, the protection chip 300 may have multiple protection layers 410. Additionally or alternatively, the protection chip 300 may have multiple blocking layers 305. In these embodiments, these layers may be disposed in the protection chip 300 in any order. As shown, the protection chip 300 is bonded to the backside 112 of the active chip 310. In some embodiments, the protection circuit layer 410 of the protection device 300 and the disturbance layer 305 of the protection device 300 are spaced apart (i.e., a distance d) from one another along a direction lateral to the bonding interface 315. In some embodiments, the disturbance layer 305 may be disposed on either the protection chip 300 or the active chip 310, or both.
[0031] FIG. 5 illustrates additional considerations in the configuration of the protective chip 300. As described in detail above, the precision of the FIB allows an attacker to dig through the obstructing layer 305 of the bonded structure without ablating detectable portions of the obstructing or obstructing material. However, the aspect ratio of the FIB is fairly narrow. As a result, as shown in FIG. 2 above, the FIB becomes wider as the distance from the focus increases. As shown in FIG. 5, in some embodiments, in order for an attack by the FIB to be detectable, the obstructing layer 305 of the protective chip 300 may be placed at a minimum distance (e.g., D) from the sensitive semiconductor layer 116 of the active chip 310, where the distance D refers to a distance lateral to the bonding interface 315. This ensures that an attack by the FIB used to expose a portion of the active chip 310 will ablate enough material of the obstructing layer 305 of the protective chip 300 to be detectable. In some embodiments, the spacing or distance D between the disturbing layer 305 of the protection device 300 and the active circuitry 116 of the semiconductor device or active chip 310 is at least 20 micrometers. In some embodiments, the distance D can be between 20 micrometers and 100 micrometers, such as between 50 micrometers and 100 micrometers. In some embodiments, the distance D can be between 100 micrometers and 500 micrometers. In some embodiments, the protection chip 300 can further include a protection circuit layer 410 with an active circuit layer. In these embodiments, the protection device 300 can include circuitry that provides additional non-sensitive functionality to the active chip 310. Additionally, in some other embodiments, the protection chip 300 can include multiple disturbing layers 305. In addition to increasing the distance between the top obstruction layer 305 and the active layer 116 of the active chip 310, in these embodiments, a FIB attack must ablate and penetrate multiple obstruction layers 305 to expose the sensitive semiconductor layers (e.g., active circuitry 116) of the active chip 310.Therefore, in various embodiments, the disturbing layer 305 of the protection chip 300 may be located at a minimum distance from the semiconductor layer of the active chip 310, since increasing the distance D requires increasing ablation of the protection chip 300. The advantage of having the protection circuitry (e.g., active circuitry including transistors and / or passive circuitry, e.g., capacitors) in the protection element is that this may force a counterfeiter to make a larger hole when ablating the material of the protection element, thereby increasing the possibility of triggering an alarm for the active chip 310.
[0032] While the illustrated embodiments herein (e.g., FIGS. 3-5) show the protection element 300 bonded to the backside 112 of the semiconductor element 310, in other embodiments the protection element 300 may additionally or alternatively be bonded to the frontside 314 to provide frontside protection of the circuitry. Thus, in some embodiments, the bonded structure may include a second protection element 300 bonded directly to the frontside of the semiconductor element 310 without adhesive along a second bonding interface 315, the second protection element 300 including a second obstruction layer 305 configured to inhibit external access to at least the frontside 114 of the semiconductor element 310, and a second protection circuit layer 410 disposed within the protection element 300, the protection circuit layer 410 configured to detect or disrupt external access to the frontside 114 of the semiconductor element 300.
[0033] Examples of direct bonding methods and directly bonded structures Various embodiments disclosed herein relate to a direct bonded structure in which two elements can be directly bonded to each other without an intervening adhesive. Two or more semiconductor elements (e.g., integrated device dies, wafers, etc., e.g., elements 300, 310) may be stacked or bonded to each other to form a bonded structure. A conductive contact feature or pad (e.g., 350A, 350B) of one element may be electrically connected to a corresponding conductive contact feature (e.g., 350A, 350B) of the other element. Any suitable number of elements may be stacked in the bonded structure.
[0034] In some embodiments, the elements are bonded directly to each other without adhesive. In various embodiments, the non-conductive material or dielectric (e.g., 341A) of a first element (e.g., a protective or occluding element) may be bonded directly to a corresponding non-conductive or dielectric field region (e.g., 341B) of a second element (e.g., an active chip) without adhesive. The non-conductive material may be referred to as a non-conductive bonding region or bonding layer of the first element. In some embodiments, the non-conductive material of the first element may be bonded directly to a corresponding non-conductive material of the second element using a dielectric-dielectric bonding technique. For example, the dielectric-dielectric bond may be formed without adhesive using direct bonding techniques disclosed in at least U.S. Patent Nos. 9,564,414, 9,391,143, and 10,434,749, each of which is incorporated by reference and incorporated herein by reference for all purposes.
[0035] In various embodiments, a hybrid direct bond may be formed without an intervening adhesive. For example, the dielectric bonding surfaces may be polished to a high degree of smoothness. The bonding surfaces may be cleaned and exposed to a plasma and / or an etchant to activate the surfaces. In some embodiments, such bonding surfaces may be terminated with a chemical species after or during activation (e.g., during a plasma and / or etch process). Without being bound by theory, in some embodiments, an activation process may be performed to break chemical bonds at the bonding surfaces, and a termination process may provide additional chemical species at the bonding surfaces that improve the bonding energy during direct bonding. In some embodiments, activation and termination are performed in the same step, for example, using a plasma or a wet etchant to activate and terminate the surfaces. In other embodiments, the bonding surfaces may be terminated in a separate process to provide additional chemical species for direct bonding. In various embodiments, the termination chemical species may include nitrogen. Additionally, in some embodiments, the bonding surface may be exposed to fluorine. For example, there may be one or multiple fluorine peaks near the layers and / or bonding interface. Thus, in a direct bonded structure, the bonding interface between the two dielectrics may include a high nitrogen content and a very smooth interface with a fluorine peak at the bonding interface. Additional examples of activation and / or end group treatments may be found throughout U.S. Patent Nos. 9,564,414, 9,391,143, and 10,434,749, each of which is incorporated by reference and incorporated herein in its entirety for all purposes.
[0036] In various embodiments, the conductive contact pads of the first component may also be directly bonded to corresponding conductive contact pads of the second component. For example, using hybrid bonding techniques, such conductor-conductor direct bonds may be provided along with bond interfaces (e.g., 315) that include covalently directly bonded dielectric-dielectric surfaces that have been pretreated as described above. In various embodiments, conductor-conductor (e.g., contact pad-contact pad) direct bonds and dielectric-dielectric hybrid bonds may be formed using direct bonding techniques as disclosed in at least U.S. Patent Nos. 9,716,033 and 9,852,988, each of which is incorporated by reference herein in its entirety for all purposes.
[0037] For example, the dielectric bonding surfaces may be pretreated and directly bonded to each other without an intervening adhesive as described above. The conductive contact pads, which may be surrounded by a non-conductive dielectric field region, may also be bonded to each other without an intervening adhesive. In some embodiments, the respective contact pads may be recessed below the outer surface (e.g., top surface) of the dielectric field or non-conductive bonding region, for example by less than 30 nm, less than 20 nm, less than 15 nm, or less than 10 nm, for example, over a range of 2 nm to 20 nm, or 4 nm to 10 nm. The non-conductive bonding regions may in some embodiments be directly bonded to each other at room temperature without an adhesive, and then the bonded structure may be annealed. Upon annealing, the contact pads may expand and contact each other, for example forming a direct metal-to-metal bond. Advantageously, the use of hybrid bonding techniques, such as Direct Bond Interconnect, or DBI, available from Xperi, Inc., San Jose, Calif., can allow for high density (e.g., small or fine pitch for regular arrays) pads connected to one another across the direct bond interface. In some embodiments, the pitch of the bond pads or conductive traces embedded in the bonding surface of one of the bonding elements can be less than 40 microns, less than 10 microns, or even less than 2 microns. For some applications, the ratio of the bond pad pitch to one of the bonding pad dimensions is less than 5 or less than 3, and in some cases, desirably, less than 2. In other applications, the width of the conductive traces embedded in the bonding surface of one of the bonding elements can range from 0.3 microns to 3 microns. In various embodiments, the contact pads and / or traces can be made of copper, although other metals may be suitable.
[0038] Thus, in a direct bonding process, the first element may be bonded directly to the second element without an intervening adhesive. In some configurations, the first element may include a singulated element, such as a singulated integrated device die or a singulated protection element. In other configurations, the first element may include a carrier substrate (e.g., a wafer) that includes a plurality (e.g., tens, hundreds, or more) of device regions that, upon singulation, form a plurality of integrated device dies. Similarly, the second element may include a singulated element, such as a singulated integrated device die. In other configurations, the second element may include a carrier or substrate (e.g., a wafer).
[0039] As described herein, the first and second elements may be directly bonded to each other without adhesive, which is different from a deposition process. In one application, the width of the first element in the bonded structure may be approximately the same as the width of the second element. In some other embodiments, the width of the first element in the bonded structure may be different from the width of the second element. The width or area of the larger element in the bonded structure may be at least 10% larger than the width or area of the smaller element. Thus, the first and second elements may be comprised of non-deposited elements. Furthermore, unlike deposited layers, the direct bonded structure may include a defect area along the bond interface where nanovoids exist. The nanovoids may be formed due to activation of the bonding surface (e.g., exposure to plasma). As described above, the bond interface may include a concentration of material resulting from activation and / or a final chemical treatment process. For example, in an embodiment utilizing nitrogen plasma for activation, a nitrogen peak may be formed at the bond interface. In embodiments utilizing an oxygen plasma for activation, an oxygen peak may occur at the bond interface. In some embodiments, the bond interface may be comprised of silicon oxynitride, silicon oxycarbonitride, or silicon carbonitride. As described herein, the direct bond may include a covalent bond, which is stronger than a van der Waals bond. The bonding layer may further include a polished surface that is planarized to a high degree of smoothness.
[0040] In various embodiments, the intermetallic bonds between the contact pads may be bonded such that the copper grains grow into one another across the bond interface. In some embodiments, the copper may have grains oriented along crystal planes to enhance copper diffusion across the bond interface. The bond interface may extend substantially entirely to at least a portion of the bond contact pad, such that there are substantially no gaps between the non-conductive bonded regions at or near the bond contact pad. In some embodiments, a barrier layer may be provided under the contact pad (e.g., which may include copper). However, in other embodiments, there may be no barrier layer under the contact pad, as described, for example, in U.S. Patent Application Publication No. 2019 / 0096741, which is incorporated by reference and incorporated herein in its entirety for all purposes.
[0041] In one aspect, a bonded structure is provided. The bonded structure includes a semiconductor device including active circuitry (e.g., 116). The bonded structure further includes a protection element bonded directly to the semiconductor device along a bonding interface without adhesive. The protection element includes an occlusion layer (e.g., 305) configured to inhibit external access to at least a portion of the active circuitry. The protection element may additionally or alternatively include a protection circuit layer (e.g., 410) disposed therein, the protection circuit layer configured to detect or disrupt external access to the protection element, the active circuitry of the semiconductor device, or both.
[0042] In some embodiments, the blocking layer of the protection element and the active circuitry of the semiconductor element are spaced apart from one another relative to the bonding interface. In some embodiments, the spacing between the blocking layer of the protection element and the active circuitry of the semiconductor element is between 50 micrometers and 100 micrometers. In some embodiments, the protection circuit layer of the protection element and the blocking layer of the protection element are spaced apart from one another along a direction transverse to the bonding interface. In some embodiments, the spacing between the protection circuit layer of the protection element and the blocking layer is at least 20 micrometers. In some embodiments, the protection circuit layer of the protection element is disposed between the blocking layer of the protection element and the bond interface. In some embodiments, the interference layer of the protection element is disposed between the protection circuit layer of the protection element and the bond interface. In some embodiments, the interference layer of the protection element comprises an interference layer configured to block a defined area of the semiconductor element in a plane parallel to a surface of the interference layer. In some embodiments, the protection element comprises a bonding layer bonded directly to the bonding layer of the semiconductor element. In some embodiments, the bonding layer of the protection element is metallized in a pattern that matches at least a portion of the metal pattern of the bonding layer of the protection element. In some embodiments, the bonding layer of the semiconductor element has a number of contact pads disposed in a non-conductive layer, and the bonding layer of the protection element has a number of contact pads disposed in a non-conductive layer that are directly bonded to the contact pads of the semiconductor element. In some embodiments, the bonding layer of the protection element and the protection circuit layer of the protection element are connected to each other via one or more vertical interconnects (e.g., 360). In some embodiments, the occlusion layer of the protection element has a detection circuit configured to detect an external access of the protection element. In some embodiments, the detection circuit includes a passive electronic circuit element configured to detect an external access. In some embodiments, the passive electronic circuit includes a capacitive circuit element, a resistive element, or both. In some embodiments, the passive electronic circuit element includes a resistive element having a patterned trace.In some embodiments, the passive electronic circuit element includes a capacitive element having multiple traces separated by insulating material. In some embodiments, the detection circuit includes active circuitry. In some embodiments, a vertical interconnect extends from the detection circuit to a contact pad of the protection element. In some embodiments, a vertical interconnect extends from the detection circuit to a protection circuit layer of the protection element. In some embodiments, one or more contact pads of the protection element are bonded to a contact pad on an active side of the semiconductor element. In some embodiments, the protection circuit layer of the protection element includes a passive electronic circuit configured to mimic the appearance of an active circuit. In some embodiments, the protection circuit layer of the protection element includes active circuitry. In some embodiments, the active circuitry of the protection circuit layer is configured to emit an encrypted timing signal. In some embodiments, the active circuitry of the protection circuit layer is configured to detect a change in the protection circuit layer. In some embodiments, the active circuitry of the protection circuit layer is configured to disable the active circuitry of the semiconductor when it detects a change in the protection circuit layer. In some embodiments, the protection circuit layer is configured to emit an alarm signal when the active circuitry of the protection circuit layer detects a change in the protection circuit layer. In some embodiments, vertical interconnects extend from the protection circuit layer to contact pads of the protection element. In some embodiments, the protection element is bonded directly to the backside (e.g., 112) of the semiconductor element opposite the active side (e.g., 114), and through-semiconductor vias (e.g., 330) extend from contact pads at or near the active side of the semiconductor element to contact pads of the protection element to enable electrical communication between the semiconductor element and the protection circuit layer of the protection element. In some embodiments, the protection circuit layer is fully embedded within the protection element.
[0043] In another aspect, a method of forming a bonded structure is provided that includes directly bonding a semiconductor device to a protection device without an adhesive, the semiconductor device having active circuitry, the protection device having an obstruction layer configured to inhibit external access to a portion of the active circuitry and a protection layer configured to detect or disrupt external access to the protection device, the semiconductor device, or both.
[0044] In some embodiments, the method includes forming the protection element such that the blocking layer of the protection element and the protection layer of the protection element are spaced apart from one another along a direction transverse to the bonding interface. In some embodiments, the method includes forming the protection element such that a spacing between the blocking layer of the protection element and the protection layer of the protection element is at least 20 micrometers. In some embodiments, the method includes forming the protection element such that a spacing between the blocking layer of the protection element and the active circuitry of the semiconductor device is at least 20 micrometers. In some embodiments, the method includes forming the protection element to have a bonding layer, forming the semiconductor device to have a bonding layer, and bonding the bonding layer of the protection element to the bonding layer of the semiconductor device. In some embodiments, the method includes forming the protection element such that the bonding layer of the protection element is metallized to match a metallization pattern of the semiconductor device. In some embodiments, the method includes forming the protection element such that the bonding layer of the protection element has a number of contact pads disposed within a non-conductive layer, the contact pads configured to mirror the number of contact pads of the bonding layer of the semiconductor device. In some embodiments, the method includes forming the protection element such that the disturbing layer has a detection circuit configured to detect external access to the protection element. In some embodiments, the method includes forming the protection element to include a vertical interconnect extending from the detection circuit to a contact pad of the protection element. In some embodiments, the method includes directly bonding the protection element to a backside of the semiconductor element located opposite an active side of the semiconductor element, and forming the semiconductor element to include a through semiconductor via (TSV) extending from a contact pad located at or near the active side of the semiconductor element to the contact pad of the protection element, the TSV providing electrical communication between the semiconductor element and the detection circuit. In some embodiments, the method includes forming the protection element to include a vertical interconnect extending from the detection circuit to a protection layer of the protection element, and a second vertical interconnect extending from the protection layer of the protection element to the contact pad of the protection element.In some embodiments, the method includes forming the protection circuitry layer to have passive electronic circuitry configured to mimic the appearance of active circuitry. In some embodiments, the method includes forming the protection circuitry layer to have active circuitry. In some embodiments, the method includes configuring the active circuitry of the protection circuitry layer to emit an encrypted timing signal. In some embodiments, the method includes configuring the active circuitry of the protection circuitry layer to detect a change in the protection circuitry layer. In some embodiments, the method includes configuring the active circuitry of the protection circuitry layer to disable an active circuitry of the semiconductor device when the active circuitry of the protection circuitry layer detects a change in the protection circuitry layer. In some embodiments, the method includes configuring the active circuitry of the protection circuitry layer to issue an alarm signal when the active circuitry of the protection circuitry layer detects a change in the protection circuitry layer. In some embodiments, the method includes forming the protection element to include a vertical interconnect extending from the protection circuitry layer of the protection element to a contact pad of the protection element. In some embodiments, the method includes bonding the protection element directly to a backside of the semiconductor element diametrically opposite the active side of the semiconductor element, and forming the semiconductor element to have through-semiconductor vias (TSVs) extending from contact pads located at or near the active side of the semiconductor element to contact pads of the protection element, the TSVs providing electrical communication between the semiconductor element and a protection layer of the protection element. In some embodiments, the method includes forming the protection element such that the protection circuitry layer is completely embedded within the protection element.
[0045] In another aspect, a bonded structure is provided that includes a semiconductor device including active circuitry and a protection device bonded directly to the semiconductor device without adhesive along a bonding interface, the protection device having a protection circuit layer configured to detect or disrupt external access to the protection device, the active circuitry of the semiconductor device, or both.
[0046] In some embodiments, the protective layer of the protection element and the active circuitry of the semiconductor element are spaced apart from one another along a direction transverse to the bonding interface. In some embodiments, the spacing between the blocking layer of the protection element and the active circuitry of the semiconductor element is at least 20 micrometers. In some embodiments, the protection element includes a bonding layer, and the semiconductor element includes a bonding layer bonded directly to the bonding layer of the protection element. In some embodiments, the bonding layer of the protection element is metallized to match the metallization pattern of the semiconductor element. In some embodiments, the bonding layer of the semiconductor element includes a number of contact pads disposed within a non-conductive layer, and the bonding layer of the protection element includes a number of contact pads disposed within a non-conductive layer that are bonded directly to the contact pads of the semiconductor element. In some embodiments, the protection layer of the protection element includes passive electronic circuitry configured to mimic the appearance of the active circuitry. In some embodiments, the protection layer of the protection element includes active circuitry. In some embodiments, the active circuitry of the protection circuitry layer is configured to provide an encrypted timing signal. In some embodiments, the active circuitry of the protection circuitry layer is configured to detect a change in the protection element. In some embodiments, the active circuitry of the protection circuitry layer is configured to disable the active circuitry of the semiconductor element when the active circuitry of the protection circuitry layer detects a change in the protection element. In some embodiments, the protection circuitry layer is configured to emit an alarm signal when it detects a change in the protection element. In some embodiments, the bonded structure has a vertical interconnect extending from a protection layer of the protection element to a contact pad of the protection element. In some embodiments, the protection element is directly bonded to a backside of the semiconductor element opposite the active side, and a through semiconductor via (TSV) extends from a contact pad at or near the active side of the semiconductor element to a contact pad of the protection element, such that the TSV allows electrical communication between the semiconductor element and the protection layer of the protection element. In some embodiments, the protection circuitry layer of the protection element is fully embedded within the protection element.
[0047] Unless the context clearly requires otherwise, throughout the specification and claims, the terms "comprise", "comprising", "include", "including" and the like are to be construed in an inclusive sense, i.e., "including, but not limited to", as opposed to an exclusive or exhaustive sense. As used generally herein, the term "coupled" means two or more elements that are either directly connected to each other or connected to each other by one or more intermediate elements. Similarly, as used generally herein, the term "coupled" means two or more elements that are either directly connected to each other or connected to each other by one or more intermediate elements. In addition, the terms "herein," "above," "below," and words of similar import as used in the parent application refer to the application as a whole and not to any particular portion of the application. Furthermore, as used herein, when a first element is described as being located "on" or "over" a second element, the first element may be directly located on or over the second element such that the first element and the second element are in direct contact with each other, or the first element may be indirectly located on or over the second element such that one or more elements are interposed between the first element and the second element. Where the context permits, terms in the above detailed description using the singular or plural may include the plural or singular, respectively. The term "or" in reference to a list of two or more items includes all of the following interpretations of that term: any of the items in the list, all of the items in the list, and any combination of the items in the list.
[0048] Furthermore, conditional terms used in the specification, particularly "can," "could," "might," "may," "eg," "for example," "such as," and the like, unless expressly specified otherwise or understood otherwise within the context in which they are used, are generally intended to imply that certain embodiments include certain features, elements, and / or conditions and that other embodiments do not include certain features, elements, and / or conditions. Thus, such conditional terms are generally not intended to imply that features, elements, and / or conditions are present in any required manner for one or more embodiments.
[0049] Although certain embodiments have been described, these embodiments are provided by way of example only and are not intended to limit the scope of the invention. Indeed, the novel apparatus, methods, and systems described herein may be embodied in a variety of other forms, and furthermore, various omissions, substitutions, and modifications in the form of the methods and systems described herein may be made without departing from the scope of the invention. For example, although blocks are shown in a given arrangement, alternative embodiments may perform substantially the same functions with different components and / or circuit topologies, and some blocks may be deleted, moved, added, divided, combined, and / or modified. Each of these blocks may be embodied in a wide variety of ways. Any suitable combination of elements and acts of the various embodiments described above may be combined to provide further embodiments. The scope of the invention as set forth in the appended claims and equivalents thereto is intended to include such forms or modifications within the scope and spirit of the invention.
Claims
1. A bonded structure comprising: a semiconductor element having an active circuit; and a protection element directly bonded to the semiconductor element without an adhesive along a bonding interface, the protection element comprising: a blocking layer configured to inhibit external access to at least a portion of the active circuit; and a protection circuit layer provided within the protection element, the protection circuit layer being configured to detect or disrupt external access to the active circuit of the semiconductor element.
2. The protection element is directly bonded to the back side of the semiconductor element opposite the active front side of the semiconductor element, and the active circuit of the semiconductor element is provided closer to the active front side than to the back side. The bonded structure according to claim 1.
3. The blocking layer of the protection element and the active circuit of the semiconductor element are arranged at intervals along a direction transverse to the bonding interface. The bonded structure according to claim 1.
4. The distance between the blocking layer of the protection element and the active circuit of the semiconductor element is at least 20 micrometers. The bonded structure according to claim 1.
5. The distance between the blocking layer of the protection element and the active circuit of the semiconductor element is at least 50 micrometers to 100 micrometers. The bonded structure according to claim 1.
6. The protection circuit layer of the protection element and the blocking layer of the protection element are arranged at intervals along a direction transverse to the bonding interface. The bonded structure according to claim 1.
7. The distance between the protection circuit layer of the protection element and the blocking layer of the semiconductor element is at least 20 micrometers. The bonded structure according to claim 6.
8. The protection circuit layer of the protection element is provided between the blocking layer of the protection element and the bonding interface. The bonded structure according to claim 1.
9. The blocking layer of the protection element is provided between the protection circuit layer of the protection element and the bonding interface. The bonded structure according to claim 1.
10. The interference layer of the protection element further has a blocking layer, and the blocking layer is configured to block a specified region of the semiconductor element in a plane parallel to the surface of the blocking layer. The bonded structure according to claim 1.
11. The interference layer of the protection element has a detection circuit configured to detect access from outside the protection element. The bonded structure according to any one of claims 1 to 10.
12. The detection circuit has a passive electronic circuit element configured to detect access from outside. The bonded structure according to claim 11.
13. The passive electronic circuit element has at least one of a capacitive circuit element and a resistive circuit element. The bonded structure according to claim 12.
14. The passive electronic circuit element includes the resistive circuit element, and the resistive circuit element further includes a patterned trace. The bonded structure according to claim 13.
15. The passive electronic circuit element includes the capacitive circuit element, and the capacitive circuit element further has a plurality of traces separated by an insulating material. The bonded structure according to claim 13.
16. The detection circuit further has an active circuit. The bonded structure according to claim 11.
17. The active circuit further has a transistor. The bonded structure according to claim 1.
18. The protection circuit layer further has a transistor. The bonded structure according to claim 1.
19. A bonded structure, a semiconductor element having a first active circuit, and a protection element directly bonded to the semiconductor element without an adhesive along a bonding interface. The protection element has a protection circuit layer provided therein, and the protection circuit layer has a second active circuit configured to detect or disrupt external access to the first active circuit of the semiconductor element. The bonded structure.
20. The protection element further has a bonding layer, and the semiconductor element further has a bonding layer directly bonded to the bonding layer of the protection element. The bonded structure according to claim 19.
21. The bonding layer of the protection element is metallized to match the metallization pattern of the semiconductor element. The bonded structure according to claim 20.
22. The bonding layer of the semiconductor element has a plurality of contact pads provided in a non-conductive layer, and the bonding layer of the protection element has a plurality of contact pads provided in a non-conductive layer directly bonded to the contact pads of the semiconductor element. The bonded structure according to claim 21.
23. The protection circuit layer of the protection element further has a passive electronic circuit configured to mimic the appearance of an active circuit. The bonded structure according to claim 19.
24. The second active circuit of the protection circuit layer is configured to detect a change in the protection element. The bonded structure according to claim 19.
25. The second active circuit of the protection circuit layer is configured to invalidate the first active circuit of the semiconductor element when the second active circuit of the protection circuit layer detects a change in the protection element. The bonded structure according to claim 24.
26. The protection circuit layer is configured to issue an alarm signal when the second active circuit of the protection circuit layer detects a change in the protection element. The bonded structure according to claim 24.
27. The bonded structure according to claim 19 further has a vertical interconnect extending from the protection circuit layer of the protection element to a contact pad of the protection element.
28. The protection element is directly bonded to the back side of the semiconductor element opposite to the active side, and the bonded structure further has a semiconductor through-via (TSV) extending from a contact pad located at or near the active side of the semiconductor element to the contact pad of the protection element. The TSV provides electrical communication between the semiconductor element and the protection circuit layer of the protection element. The bonded structure according to claim 27.
29. The protection circuit layer of the protection element is completely embedded in the protection element. The bonded structure according to claim 19.