Chiplet Debug Security Architecture for Multi-Vendor Secure Asset Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-vendor System-In-Package (SiP) architectures, the secure access and protection of security assets such as cryptographic keys, configuration data, and intellectual property during debug operations are compromised due to privileged access provided by debug capabilities, leading to potential secret leakage.

Innovation Solution

Implementing a federated debug security architecture with a leader Root of Trust (RoTD) chiplet that manages and aligns debug policies across chiplets from different vendors, using secure key distribution and authentication to enforce a common access level, and restricting access through protection classes and policy mappings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If debug capabilities are provided to access chiplet security assets, then debug operations can be performed, but security assets such as cryptographic keys and intellectual property may be compromised

Engineering Contradiction:
Improvedebug operationsVSAvoidsecurity assets protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments security access rights into different protection classes (e.g., class 0, class 1, class 2) with varying levels of access. Each chiplet is assigned a specific protection class that determines what security assets it can access during debug operations, preventing uniform access and reducing the risk of complete security compromise

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different chiplets within the SiP are assigned different protection classes based on their specific security requirements and the sensitivity of their security assets. This local differentiation ensures that only chiplets with appropriate clearance levels can access their designated security assets, allowing debug operations while maintaining security

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If a common debug security policy is applied across all chiplets, then unified access control is achieved, but chiplets from different vendors with varying security requirements cannot be accommodated

Engineering Contradiction:
Improvemulti-vendor chiplet compatibilityVSAvoidsecurity policy management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security framework that can accommodate multiple chiplet vendors and their different security requirements through a common protection class system. The SiP-level security architecture provides universal access control that works across heterogeneous chiplets while allowing each chiplet to maintain its specific security characteristics

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary security management layer at the SiP level that mediates between chiplets from different vendors. This intermediary layer handles the complexity of policy alignment and translation, allowing chiplets with different vendor-specific security policies to coexist and access security assets through a unified control mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If privileged access is granted to debug operations, then comprehensive debug capabilities are enabled, but unauthorized access to security assets may occur

Engineering Contradiction:
Improvedebug capabilitiesVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the security management system continuously monitors and verifies the protection class assignments of chiplets during debug operations. This feedback loop ensures that only chiplets with appropriate clearance levels can access their designated security assets, preventing unauthorized access while maintaining comprehensive debug capabilities

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250356036A1Technologies for accessing secure assets of chiplets
Publication Date: 2025.11.20 INTEL CORP
  • US20250356036A1 patent drawing
  • US20250356036A1 patent drawing
  • US20250356036A1 patent drawing

AI summary

Examples described herein relate to a chiplet comprising a circuitry to store a security policy, specific to the chiplet, and a second chiplet comprising a second circuitry to store a second security policy, specific to the second chiplet. In some examples, at least two of the multiple chiplets are from different chiplet manufacturers.