Chiplet Root-of-Trust Authentication for Common Security Boundaries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In chiplet-based SoC designs, establishing a common security boundary across multiple chiplets is challenging due to varying security and debug states, which can lead to interference, unwanted attack vectors, and inefficiencies in silicon footprint and latency when relying on a single RoT.

Innovation Solution

Multiple chiplet Roots of Trust (C-RoTs) mutually authenticate using certificates and provisioning of pairing keys during manufacturing and operation to establish a common security boundary, ensuring all chiplets are in a trusted and debug state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single RoT is used in chiplet-based SoC designs, then device security is simplified, but security reliability deteriorates due to varying security and debug states across chiplets

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity boundary complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single RoT into multiple distributed C-RoTs, one in each chiplet. Each C-RoT independently manages security for its chiplet, allowing granular control over security and debug states. This segmentation resolves the contradiction by improving security reliability through distributed trust anchors while managing complexity through modular organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security boundary as an intermediary mechanism that mediates interactions between multiple C-RoTs. This security boundary establishes trusted relationships across chiplet interfaces, enabling reliable security enforcement despite the complexity of multiple distributed trust anchors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Strength

If multiple C-RoTs are implemented for mutual authentication, then security boundary robustness is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity boundary strengthVSAvoidauthentication mechanism complexity
Core Design Contradiction:
StrengthVSDevice complexity

Solution Approach 1:

The patent merges multiple C-RoTs into a unified security boundary that encompasses all chiplets. This merging creates a strong, collective security perimeter while simplifying the authentication mechanism by establishing a common trust framework that all chiplets participate in, rather than requiring complex pairwise authentication protocols.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If a single RoT is used, then device complexity is reduced, but silicon footprint efficiency deteriorates due to latency and redundancy

Engineering Contradiction:
Improvesilicon footprint efficiencyVSAvoidRoT architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the centralized RoT into distributed C-RoTs across chiplets, eliminating the need for large redundant security logic in a single location. Each chiplet contains only the minimal RoT functionality needed for its operations, improving silicon footprint efficiency while reducing latency through localized security processing.

Inventive Principle:
Principle #1Segmentation

4Adaptability or versatility

If chiplets have varying security and debug states, then adaptability is improved, but security reliability deteriorates due to interference and attack vectors

Engineering Contradiction:
Improvechiplet state flexibilityVSAvoidsecurity trust reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by allowing each chiplet to have its own C-RoT that independently manages its security and debug states. This enables each chiplet to adapt to its specific functional requirements while maintaining reliable security through localized trust verification. The security boundary ensures that local state variations do not compromise overall system trust.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12373535B2Establishing system on chip root of trust from multiple chiplet roots of trust
Publication Date: 2025.07.29 QUALCOMM INC
  • US12373535B2 patent drawing
  • US12373535B2 patent drawing
  • US12373535B2 patent drawing

AI summary

Systems and techniques are provided for establishing a connection. For instance, a process may include receiving, by a first root of trust (C-ROT) of a first chiplet of a plurality of chiplets from a second C-RoT of a second chiplet, a second certificate along with security state information and debug information for the second chiplet; authenticating a security state and a debug state of the second chiplet based on the security state information and the debug information; authenticating the second certificate; and establishing a security boundary with the second chiplet.