Asset Management System for Secure Semiconductor Feature Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for feature programming in semiconductor manufacturing are costly, lack control, and fail to differentiate between legitimate and illegitimate chips, leading to revenue loss and brand dilution due to unauthorized feature activation and the inability to securely manage proprietary data across untrusted manufacturing operations.
Innovation Solution
An Asset Management System (AMS) that uses a combination of hardware security modules (HSMs), a graphical user interface (GUI), and secure communication protocols to remotely control and audit the distribution of features, keys, and data across global manufacturing locations, ensuring secure feature provisioning, key injection, and data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional feature programming methods (mask sets, silicon fuses, jumper wires) are used, then feature control is achieved, but manufacturing cost increases and control over distributed manufacturing facilities is lost
Solution Approach 1:
The patent replaces traditional mechanical/physical feature programming methods (mask sets, silicon fuses, jumper wires) with an electronic/software-based solution. A controller sends electronic commands over communication channels to provision features remotely, eliminating the need for physical manufacturing modifications and reducing both cost and complexity while maintaining control.
Solution Approach 2:
The patent introduces a controller as an intermediary between the semiconductor company and distributed manufacturing facilities. This controller manages feature provisioning by sending and receiving commands through communication channels, acting as a trusted mediator that maintains control without requiring direct physical presence at manufacturing locations.
2Productivity
If manufacturing facilities are outsourced to distributed locations, then production capacity increases, but security and control over proprietary data distribution is compromised
Solution Approach 1:
The patent implements a feedback mechanism where the controller sends feature provisioning commands to manufacturing facilities and receives acknowledgments or status reports in return. This two-way communication allows the controller to monitor and verify that proprietary data is being distributed and applied correctly, maintaining security and control over outsourced production.
Solution Approach 2:
The controller serves as a trusted intermediary between the semiconductor company and distributed manufacturing facilities. It manages the distribution of proprietary data through encrypted or secure communication channels, enabling production capacity expansion while maintaining security through centralized control and monitoring.
3Adaptability or versatility
If proprietary data is distributed to untrusted manufacturing facilities, then feature provisioning capability is enabled, but risk of data theft and unauthorized use increases
Solution Approach 1:
The patent replaces physical security measures with electronic security mechanisms. Instead of relying on physical control of manufacturing facilities, the system uses encrypted communication channels, authentication protocols, and remote command execution to secure proprietary data distribution, enabling feature provisioning while mitigating theft risks.
Solution Approach 2:
The controller acts as a security intermediary that manages the distribution of proprietary data through secure communication channels. It authenticates manufacturing facilities, encrypts data transmissions, and monitors usage, enabling feature provisioning capability while reducing the risk of data theft and unauthorized use.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of controlling the distribution of electronic assets to a test application in a manufacturing process is disclosed. The method comprises providing a daemon application programming interface (API) on the test application to provide assets upon detecting a request therefor, and to obtain log data from the test application during testing. A daemon is initiated in connection with the daemon API to obtain the log data from the daemon API and to provide the assets to the daemon API, the daemon hosting an agent API for communicating with an appliance remote to the test application. The agent API is utilized to obtain a batch comprising a plurality of assets and to provide one or more log reports containing the log data separately from the test application. The assets are cached to provide a quantity of the assets to the daemon API upon request therefrom to enable the daemon API to provide the assets to the test application thereby avoiding session establishment between the test application and the appliance for obtaining the electronic assets.