Chiplet Debug Security Architecture for Multi-Vendor Secure Asset Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-vendor System-In-Package (SiP) architectures, the secure access and protection of security assets such as cryptographic keys, configuration data, and intellectual property during debug operations are compromised due to privileged access provided by debug capabilities, leading to potential secret leakage.
Innovation Solution
Implementing a federated debug security architecture with a leader Root of Trust (RoTD) chiplet that manages and aligns debug policies across chiplets from different vendors, using secure key distribution and authentication to enforce a common access level, and restricting access through protection classes and policy mappings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If debug capabilities are provided to access chiplet security assets, then debug operations can be performed, but security assets such as cryptographic keys and intellectual property may be compromised
Solution Approach 1:
The patent segments security access rights into different protection classes (e.g., class 0, class 1, class 2) with varying levels of access. Each chiplet is assigned a specific protection class that determines what security assets it can access during debug operations, preventing uniform access and reducing the risk of complete security compromise
Solution Approach 2:
Different chiplets within the SiP are assigned different protection classes based on their specific security requirements and the sensitivity of their security assets. This local differentiation ensures that only chiplets with appropriate clearance levels can access their designated security assets, allowing debug operations while maintaining security
2Adaptability or versatility
If a common debug security policy is applied across all chiplets, then unified access control is achieved, but chiplets from different vendors with varying security requirements cannot be accommodated
Solution Approach 1:
The patent creates a universal security framework that can accommodate multiple chiplet vendors and their different security requirements through a common protection class system. The SiP-level security architecture provides universal access control that works across heterogeneous chiplets while allowing each chiplet to maintain its specific security characteristics
Solution Approach 2:
The patent introduces an intermediary security management layer at the SiP level that mediates between chiplets from different vendors. This intermediary layer handles the complexity of policy alignment and translation, allowing chiplets with different vendor-specific security policies to coexist and access security assets through a unified control mechanism
3Ease of operation
If privileged access is granted to debug operations, then comprehensive debug capabilities are enabled, but unauthorized access to security assets may occur
Solution Approach 1:
The patent implements feedback mechanisms where the security management system continuously monitors and verifies the protection class assignments of chiplets during debug operations. This feedback loop ensures that only chiplets with appropriate clearance levels can access their designated security assets, preventing unauthorized access while maintaining comprehensive debug capabilities
Data Source
AI summary
Examples described herein relate to a chiplet comprising a circuitry to store a security policy, specific to the chiplet, and a second chiplet comprising a second circuitry to store a second security policy, specific to the second chiplet. In some examples, at least two of the multiple chiplets are from different chiplet manufacturers.


