On-Demand ASIC SKU Licensing with Hardware Root-of-Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing ASICs are vulnerable to tampering and unauthorized modifications, which can compromise their security and performance, particularly in critical network functions, and existing security measures require continuous power and are susceptible to hacking.
Innovation Solution
Implementing a hardware root-of-trust (RoT) mechanism using eFuses and PUFs to securely configure and enforce licensed SKU features, enabling and disabling functionalities based on unique device identities and cryptographic controls, without relying on external power for tamper detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private key is placed in nonvolatile memory (EEPROM or battery-backed SRAM) with active tamper detection circuitry, then security against invasive attacks is improved, but device complexity and continuous power requirements increase
Solution Approach 1:
The patent extracts the security function from traditional continuous-power tamper detection circuitry and implements it through eFuses that require no power to maintain their state. The eFuses physically store security credentials in a tamper-resistant manner without requiring active monitoring circuits, thereby reducing device complexity while maintaining security reliability.
Solution Approach 2:
The patent uses eFuses as a disposable, one-time programmable security mechanism. Once programmed, the eFuse settings cannot be changed, providing inherent security without requiring continuous power or complex active protection circuits. This approach simplifies the overall device architecture compared to reusable, actively protected memory solutions.
2Reliability
If hardware cryptographic operations are implemented, then security against unauthorized access is improved, but vulnerability to hacking and invasive attacks increases
Solution Approach 1:
The patent implements preliminary action by programming eFuses during manufacturing before the device is deployed. The security credentials are established in advance in a controlled environment, and the eFuse settings are locked permanently. This preliminary configuration eliminates the need for continuous security management and reduces vulnerability to attacks during operation, as the security state is established before any potential threats can arise.
3Reliability
If device authentication mechanisms are implemented, then protection against counterfeit devices is improved, but manufacturing complexity and cost increase
Solution Approach 1:
The patent merges the authentication mechanism directly into the device fabric through eFuses that are programmed during the manufacturing process. The authentication credentials are integrated into the device's physical structure rather than being added as separate components. This integration simplifies the manufacturing process by combining security functionality with the base device production, eliminating the need for separate authentication hardware assembly steps.
Data Source
AI summary
A method of operating a system-on-chip (SOC) including decrypting, by isolated Root of Trust (RoT) code, a Stock Keeping Unit (SKU) license code from a host during bootup of a device. Then validating, by the isolated RoT code, the SKU license code with firmware and at least one built-in key of a plurality of built-in keys from secure storage. Finally, enabling or disabling, by the isolated RoT code, at least one feature set of a plurality of feature sets comprising resources configured at the SOC based on at least one SKU license code which has been decrypted by isolated RoT code using at least one built-in key and authenticated by firmware.


