On-Demand ASIC SKU Licensing with Hardware Root-of-Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ASICs are vulnerable to tampering and unauthorized modifications, which can compromise their security and performance, particularly in critical network functions, and existing security measures require continuous power and are susceptible to hacking.

Innovation Solution

Implementing a hardware root-of-trust (RoT) mechanism using eFuses and PUFs to securely configure and enforce licensed SKU features, enabling and disabling functionalities based on unique device identities and cryptographic controls, without relying on external power for tamper detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private key is placed in nonvolatile memory (EEPROM or battery-backed SRAM) with active tamper detection circuitry, then security against invasive attacks is improved, but device complexity and continuous power requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from traditional continuous-power tamper detection circuitry and implements it through eFuses that require no power to maintain their state. The eFuses physically store security credentials in a tamper-resistant manner without requiring active monitoring circuits, thereby reducing device complexity while maintaining security reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses eFuses as a disposable, one-time programmable security mechanism. Once programmed, the eFuse settings cannot be changed, providing inherent security without requiring continuous power or complex active protection circuits. This approach simplifies the overall device architecture compared to reusable, actively protected memory solutions.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If hardware cryptographic operations are implemented, then security against unauthorized access is improved, but vulnerability to hacking and invasive attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by programming eFuses during manufacturing before the device is deployed. The security credentials are established in advance in a controlled environment, and the eFuse settings are locked permanently. This preliminary configuration eliminates the need for continuous security management and reduces vulnerability to attacks during operation, as the security state is established before any potential threats can arise.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If device authentication mechanisms are implemented, then protection against counterfeit devices is improved, but manufacturing complexity and cost increase

Engineering Contradiction:
ImproveauthenticityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the authentication mechanism directly into the device fabric through eFuses that are programmed during the manufacturing process. The authentication credentials are integrated into the device's physical structure rather than being added as separate components. This integration simplifies the manufacturing process by combining security functionality with the base device production, eliminating the need for separate authentication hardware assembly steps.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12423434B2On-demand and secure hardware license-based SKU creation for ASICs
Publication Date: 2025.09.23 CISCO TECHNOLOGY INC
  • US12423434B2 patent drawing
  • US12423434B2 patent drawing
  • US12423434B2 patent drawing

AI summary

A method of operating a system-on-chip (SOC) including decrypting, by isolated Root of Trust (RoT) code, a Stock Keeping Unit (SKU) license code from a host during bootup of a device. Then validating, by the isolated RoT code, the SKU license code with firmware and at least one built-in key of a plurality of built-in keys from secure storage. Finally, enabling or disabling, by the isolated RoT code, at least one feature set of a plurality of feature sets comprising resources configured at the SOC based on at least one SKU license code which has been decrypted by isolated RoT code using at least one built-in key and authenticated by firmware.