Method for implementing a cryptographic functionality in a semiconductor component, and semiconductor component
Configurable cryptographic functionalities in semiconductor devices address the challenge of balancing security, performance, and compliance by allowing dynamic adjustment of robustness levels and attestation, enhancing resilience and adaptability.
Patent Information
- Application Number
- PCT/EP2025/073015
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-22
- Filing Date
- 2025-08-11
- Publication Date
- 2026-02-26
Smart Images

Figure EP2025073015_26022026_PF_FP_ABST
Abstract
Description
[0001] 202415394 Foreign version
[0002] 1
[0003] Description
[0004] Method for implementing cryptographic functionality in a semiconductor device and semiconductor device
[0005] The invention relates to a method for implementing cryptographic functionality in a semiconductor device and a semiconductor device.
[0006] Semiconductor devices such as ASICs, SoCs, CPUs, and microcontrollers often implement cryptographic functions for various security purposes, including secure boot, secure debugging access, and hardware crypto acceleration. These cryptographic implementations play a crucial role in protecting sensitive data and ensuring the integrity of system operations.
[0007] The security configuration for features like secure boot and debug access is typically stored in non-volatile, one-time programmable memory such as OTP (One-Time Programmable), eFuse, or AntiFuse memory. This allows for the programming of secure configurations that cannot be easily changed once set.
[0008] While the functional correctness of cryptographic algorithms is known to be relevant, their robust and attack-proof implementation also presents a separate challenge. Various hardening measures can be employed to improve the security of cryptographic implementations. These can include self-tests, multiple computations to defend against error attacks, computations with randomly redundantly coded data to mitigate passive side-channel attacks (also known as masked implementations of cryptographic algorithms or procedures), and the use of randomized delays or scattered clock signals.
[0009] However, these hardening measures often come with trade-offs. They can significantly impact performance and lead to overhead in terms of processing time, memory requirements, and power consumption. The degree of hardening applied can vary, e.g., single masking, double masking, triple masking, double, triple, or quadruple repetition of a calculation, or a time range for randomized delay. Different levels can offer varying degrees of protection at the cost of increased performance degradation. 202415394 Foreign version
[0010] 2
[0011] Furthermore, the implementation of certain hardening measures can impact export control restrictions or import regulations in different jurisdictions. This can create challenges for semiconductor manufacturers and users who must reconcile safety requirements with regulatory compliance in various markets.
[0012] With the evolving threat landscape and the expansion of applications for secure semiconductor devices, the need for flexible and adaptable approaches to implementing cryptographic functionalities is growing. Users of these components may have varying security requirements depending on their specific use cases, operating environments, and regulatory constraints.
[0013] Addressing these challenges while maintaining the required level of safety and performance is an ongoing area of development in the field of semiconductor design and cryptographic implementation.
[0014] Accordingly, one object of the present invention is to provide an improved method for implementing cryptographic functionality in a semiconductor device. Furthermore, another object of the present invention is to provide an improved semiconductor device.
[0015] This problem of the invention is solved by a method comprising the features of claim 1 and by a semiconductor device comprising the features of claim 10. Advantageous aspects of the present invention are contained in the respective dependent claims, the following description, and the drawing.
[0016] The method according to the invention is a method for implementing at least one cryptographic functionality in a semiconductor device. The method comprises implementing the cryptographic functionality with a robustness that depends on configuration information of the semiconductor device. This approach offers the advantage of enabling a user of the semiconductor device to flexibly adapt the security level of the cryptographic implementation based on specific component requirements or use cases. The cryptographic functionality of the semiconductor device expediently activates one or more robustness variants (hardening measures, e.g., against fault attacks or side-channel attacks, e.g., multi-202415394 Foreign version) when performing a cryptographic operation.
[0017] 3-fold calculations and / or use of redundant, randomized coding) depending on the configured information of the semiconductor device.The cryptographic functionality can, in particular, be a signature check during a Secure Boot, an authentication check during debug access, network communication encryption, bus encryption of a semiconductor device's internal data transmission bus, bus encryption of a semiconductor device's external data transmission bus, memory encryption of a working memory that can be coupled via an interface of the semiconductor device, an encryption operation or a decryption operation of a crypto accelerator of the semiconductor device that is addressable by program code executed on the semiconductor device, a signature operation or a signature verification operation of a crypto accelerator of the semiconductor device that is addressable by program code executed on the semiconductor device, and / or a key generation function or a key derivation function.
[0018] It is understood that instead of one cryptographic functionality, there may also be several cryptographic functionalities, each of which is implemented with a robustness that depends on configuration information of the semiconductor device.
[0019] In the method according to the invention, the configuration information of the semiconductor device preferably comprises one or more security hardening configurations. Preferably, the configuration information defines the robustness of a specific cryptographic functionality and / or a component of the semiconductor device. In particular, such configuration information can define the degree of hardening measures applied or applicable to this functionality and / or component.
[0020] In the inventive method, such configuration information is or is preferably stored in a once programmable non-volatile memory of the semiconductor component, such as in particular OTP and / or eFuse and / or AntiFuse.Within the scope of the present invention, specific configuration information can be provided for each relevant component of the semiconductor device, preferably configuration information, in particular security hardening configuration, for a hardware crypto engine and / or configuration information, in particular security hardening configuration, for a secure boot component and / or configuration information, in particular security hardening configuration, for a graphics processor and / or configuration information, in particular security hardening configuration, for a processor core and / or configuration information, in particular security hardening configuration, for a network interface. 202415394 Foreign version.
[0021] 4 and / or configuration information, in particular security hardening configuration, for an AI accelerator and / or configuration information, in particular security hardening configuration, for a tamper controller.
[0022] Each of these specific configuration pieces of information can, according to the invention, enable advantageous hardening measures and allow their degree for the associated component, thereby enabling a tailored and flexible adjustment of the safety level of the semiconductor device.
[0023] According to advantageous embodiments of the invention, the method optionally comprises one or more of the following features:
[0024] The cryptographic functionality preferably includes a configuration of a hardware-based semiconductor circuit within the semiconductor device. This offers the advantage of a hardware-level security implementation, which can be more resilient against certain types of attacks compared to purely software-based solutions.
[0025] The semiconductor circuit preferably forms a crypto accelerator and / or a secure boot and / or a tamper protection and / or a graphics processing unit (GPU) circuit and / or a network communication encryption circuit. This versatility enables improved security for various critical components and functions of the semiconductor device.
[0026] The configuration for defining the robustness of the cryptographic functionality of the semiconductor device is preferably implemented in a one-time programmable non-volatile memory of the semiconductor device. This feature offers the advantage of preventing unauthorized changes to the security configuration after initial programming. Preferably, several cryptographic functionalities are implemented, each with an associated robustness configuration implemented in the one-time programmable non-volatile memory of the semiconductor device. This has the advantage that the user can define a different robustness variant for each of the multiple cryptographic functionalities.
[0027] An implementation of one or more cryptographic functionalities with multiple robustness levels is preferably carried out such that the one or more cryptographic functionalities are... 202415394 Foreign version
[0028] 5
[0029] Functionalities with multiple robustness levels are accessible during the lifetime of the semiconductor device. This offers the advantage of dynamically adjusting the security level based on real-time requirements or threat levels.
[0030] Advantageously, a control logic is provided in further developments of the method according to the invention, which can access one or more cryptographic functionalities with multiple robustness levels depending on one or more crypto operations. This enables optimized performance by allowing appropriate security levels to be applied to different operations as needed. Furthermore, it is possible to configure the robustness variants permissible for a cryptographic functionality in the once-programmable non-volatile memory of the semiconductor device, from which a robustness variant can be dynamically selected when executing, i.e., using, the cryptographic functionality, in particular by program code executed on the semiconductor device and / or depending on a control signal provided to the semiconductor device.
[0031] In preferred embodiments of the invention, the control logic is implemented using a digital circuit and / or a state machine and / or microcode and / or firmware. This flexibility in implementation enables optimal integration with various semiconductor architectures.
[0032] In a suitably developed embodiment of the invention, the selected robustness variant is certified by means of an attestation, and the attestation is preferably made available via an interface of the semiconductor device. This feature offers the advantage of enabling external verification of the security level, which can be crucial for compliance and trust in certain applications. An attestation is a cryptographically protected confirmation of the configured robustness variant or an associated robustness level of one or more cryptographic functionalities.
[0033] The attestation is preferably made available to a processor core of the semiconductor device. This can enable internal security checks and adaptive behavior based on the current security state.
[0034] According to a further embodiment of the present invention, a semiconductor component is provided. The semiconductor component is used to implement a cryptographic 202415394 Foreign version
[0035] 6
[0036] Functionality is designed with a robustness that depends on the configuration information of the semiconductor device. This offers the advantage of a tailored security implementation at the component level.
[0037] According to further advantageous embodiments, the semiconductor device according to the invention comprises one or more of the following features:
[0038] Robustness can be certified by an attestation. The semiconductor device can include an interface through which the attestation can be issued. These features enable external verification and monitoring of the semiconductor device's safety status.
[0039] In advantageous embodiments of the invention, the semiconductor component comprises one or more tamper sensors and a memory designed to store sensor data from the one or more tamper sensors. This provides improved physical security by enabling the detection and logging of tampering attempts. In a further advantageous embodiment of the invention, the sensor data acquired during the execution of a cryptographic operation can be included in or referenced within the attestation.
[0040] The semiconductor device can be suitably designed to execute a security action based on sensor data from one or more tamper sensors. This security action can include one or more of the following: restarting and / or activating a fail-safe operating mode and / or initiating a resilience / recovery action and / or erasing keys and / or writing to a fault memory and / or updating a tamper event counter. These features offer the advantage of automated responses to detected security threats, which may improve the overall security and reliability of the semiconductor device.
[0041] The invention is explained in more detail below with reference to an embodiment illustrated in the drawing. 202415394 Foreign version
[0042] 7
[0043] The single drawing figure 1 shows an embodiment of a semiconductor component according to the invention in the form of a system-on-chip architecture with a safety hardening measure configurable according to the method according to the invention, schematically in a schematic diagram.
[0044] The illustrated embodiment provides a method according to the invention for implementing cryptographic functionality in semiconductor devices with a robustness level that can be adapted based on configuration information. Furthermore, the illustrated embodiment shows a semiconductor device according to the invention.
[0045] The method according to the invention enables a flexible and adaptable security implementation that can be tailored to specific use cases, operating environments, and regulatory constraints. By allowing the configuration of robustness levels, the disclosed methods and systems can exhibit improved security while simultaneously optimizing performance and power consumption. Furthermore, it opens up the possibility of adapting the robustness of cryptographic implementations based on configuration information, thereby facilitating compliance with export control restrictions or import regulations in various jurisdictions.
[0046] Figure 1 shows a semiconductor device in the form of a system-on-a-chip (SOC) architecture with several key components. A processor core (PC) of the SOC architecture can include a central intelligence unit (CIU), a cache intelligence hardware (CIH), and a secure boot unit (SBO). The central intelligence unit (CIU) can, in some cases, be responsible for executing instructions and managing the operations of the processor core (PC). The cache intelligence hardware (CIH) can be used to store frequently accessed data to improve the performance of the processor core (PC).
[0047] The Safe Boot Operation (SBO) unit can be used to verify the integrity of the system during startup.
[0048] The hardware crypto engine HWCE is another key component of the system-on-a-chip (SoC) architecture. The hardware crypto engine HWCE can include various hardening variants such as Ultra-High Crypto Core (UHCC), Fast Asymmetry Hardware Crypto (FAHC), and Fast Hash Hardware Crypto (FHHC). These variants offer different levels of security and performance for cryptographic operations. For example, Ultra-High Crypto Core (UHCC) can offer a high level of security at a lower performance level, while Fast Asymmetry Hardware Crypto (FAHC) offers a higher level of security.
[0049] 8
[0050] Asymmetry Hardware Crypto FAHC and Fast Hash Hardware FHHC offer faster performance at a moderate level of security.
[0051] The network interface (NI) of the system-on-a-chip (SOC) architecture can include a crypto accelerator (CA). The CA can be used to speed up cryptographic operations for network communication. This can improve the security and performance of data transmission over the network.
[0052] The system-on-a-chip (SOC) architecture can also include a configuration hardening controller (CHC) that interacts with the hardware crypto engine (HWCE) and a one-time programmable memory (OTP). The CHC can control the configuration of the hardening measures applied to the HWCE based on information stored in the OTP.
[0053] The once programmable memory (OTP) can store various security hardening configurations (SHC) for different components of the system-on-chip (SOC) architecture.
[0054] For example, the one-time programmable memory (OTP) can store security hardening configurations SHC for the GPU (SHC-GPU), SHC for the hardware crypto engine (SHC-HWCE), SHC for the processor core (SHC-PC), and SHC for secure boot (SHC-SB), as well as other security hardening configurations SHC-AIIE, SHC-TC, and SHC-NW. These configurations can determine the level of hardening applied to the respective components. For example, the security hardening configuration SHC-HWCE for the hardware crypto engine (HWCE) can determine the hardening variant used by the hardware crypto engine (HWCE), while the security hardening configuration SHC-PC for the processor core (PC) can determine the hardening measures applied to the processor core (PC).
[0055] In the illustrated embodiment, the one-time programmable memory (OTP) can also store cryptographic keys K, which are used for secure operations such as encryption, decryption, and digital signatures. The OTP can, for example, be a non-volatile memory that can only be programmed once to ensure the security and integrity of the stored information.
[0056] Referring to FIG. 1, the system-on-a-chip architecture (SOC) also includes an AIAE (AIiC accelerator engine) and a GPU (graphics processing unit). In some cases, both the AIAE and GPU can be combined. (202415394 Foreign version)
[0057] 9
[0058] The AIAE accelerator engine and the GPU perform both unmasked processing (UP) and masked processing (MP). Unmasked processing (UP) can involve processing data without additional security measures, while masked processing (MP) can involve processing data with additional security measures such as data masking or encryption. The choice between unmasked processing (UP) and masked processing (MP) can be made based on the security requirements of the specific operation or application.
[0059] The SOC also includes a Security Hardening Attestation Unit (SHAU). In some aspects, the SHAU can generate Security Hardening Attestation SHAtts, which provide cryptographically protected confirmation of the active security configurations of the system-on-chip SOC. These SHAtts can be transmitted to external components or systems via the network (N) or to a programmer (P) via a separate interface (RSZDZ), such as RS232, I2C, or JTAG. This allows external systems or users to verify the security configurations of the system-on-chip SOC, which can be particularly useful in scenarios where the SOC is part of a larger system or network.
[0060] The SOC can communicate with external components via various connections. An Ethernet interface (ETH) can connect the system-on-chip (SOC) to the network (N), which in turn can be connected to a web service (WS). This allows the SOC to communicate with external systems and services, enabling a wide range of networked applications. A Serial Peripheral Interface (SPI) can connect the SOC to flash memory (F) containing firmware (FW). The firmware (FW) can contain software instructions that control the operation of the SOC. The separate interface (RSZDZ) connects the SOC to the programmer (P). The programmer (P) can be used to program the SOC's one-time programmable memory (OTP), configure security settings, and store cryptographic keys (K).
[0061] In the illustrated embodiment, the system-on-chip (SOC) comprises several tamper sensors (TS) and a memory (TC) designed to store sensor data from one or more of the tamper sensors (TS). The sensor data acquired by the tamper sensors (TS) can be included in or referenced within the attestation (SHAtt). 202415394 Foreign version
[0062] 10
[0063] In the illustrated embodiment, the system-on-chip (SOC) is designed to execute a security measure based on sensor data from the tamper sensors (TS). This security measure includes a restart and the activation of a fail-safe operating mode. In further embodiments, which are otherwise identical to the illustrated embodiment, the security measure can include initiating a resistance / recovery action, deleting keys, writing to an error memory, and updating a tamper event counter.
Claims
202415394 Foreign version 11 Patent claims 1. Method for implementing at least one cryptographic functionality in a semiconductor device (SOC), wherein the cryptographic functionality (HWCE) is implemented with a robustness (IIHCC, FAHC, FHHC) that depends on configuration information (SHC) of the semiconductor device (SOC).
2. A method according to any of the preceding claims, wherein the cryptographic functionality (HWCE) comprises a configuration of a hardware-based semiconductor circuit of the semiconductor device.
3. Method according to any of the preceding claims, wherein the semiconductor circuit forms a crypto accelerator (CA) and / or a secure boot (SBO) and / or a tamper protection and / or a graphics processing unit (GPU) and / or a network communication encryption circuit.
4. Method according to any of the preceding claims, wherein the configuration is implemented in a once programmable non-volatile memory (OTP) of the semiconductor device (SOC).
5. A method according to any of the preceding claims, wherein an implementation of one or more cryptographic functionalities (HWCE) with multiple robustness levels is carried out such that the one or more cryptographic functionalities with the multiple robustness levels are accessible during the runtime of the semiconductor device.
6. Method according to the preceding claim, wherein a control logic (HC) is provided which can access the one or more cryptographic functionalities (HWCE), in particular with the multiple robustness levels, depending on one or more crypto operations.
7. Method according to the preceding claim, wherein the control logic (HC) is formed with a digital circuit and / or with a state machine and / or with a microcode and / or with a firmware. 202415394 Foreign version 12 8. Method according to one of the preceding claims, wherein the robustness (IIHCC, FAHC, FH HC) is certified by means of an attestation and the attestation is preferably provided by means of an interface of the semiconductor device.
9. Method according to the preceding claim, wherein the attestation is provided to a processor core of the semiconductor device (SOC).
10. Semiconductor device designed to implement cryptographic functionality with a robustness (IIHCC, FAHC, FHHC) that depends on configuration information (SHC) of the semiconductor device.
11. Semiconductor device according to one of the preceding claims, wherein the robustness (IIHCC, FAHC, FHHC) is certified by an attestation (SHAtt).
12. Semiconductor component according to one of the preceding claims with an interface (ETH, RSZDZ) by means of which the attestation (SHAtt) can be output.
13. Semiconductor component according to one of the preceding claims, comprising one or more manipulation sensors (TS) and a memory (TC) configured for storing sensor data of the one or more manipulation sensors (TS).
14. Semiconductor component according to one of the preceding claims, which is designed to execute a security measure depending on sensor data from one or more tamper sensors.
15. Semiconductor device according to any of the preceding claims, wherein the security measure comprises one or more of the following actions: a restart and / or activation of a fail-safe operating mode and / or initiation of a resilience / recovery action and / or deletion of keys and / or writing to an error memory and / or updating of a tamper event counter.
Citation Information
Patent Citations
Tamper-protected hardware and method for using same
US20160359635A1
Anti-tamper system
US20180114039A1
Reconfigurable network-on-chip security architecture
US20210149837A1