Chiplet Root of Trust Key Wrapping for Secure Inter-Chiplet Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a chiplet-based architecture, establishing a common security boundary across multiple chiplets is challenging, as traditional methods rely on a single root of trust, which can introduce latency, waste resources, and create security vulnerabilities when not all chiplets have an RoT enabled.

Innovation Solution

Implementing a system where multiple chiplet roots of trust mutually authenticate to establish a common security boundary, allowing each chiplet to perform key management and distribution operations using a common pairing key, and enabling secure key wrapping and unwrapping across chiplets for secure processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single root of trust is used across multiple chiplets, then security management is simplified, but latency increases and resources are wasted

Engineering Contradiction:
Improvesecurity management complexityVSAvoidkey management latency
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The patent divides the single root of trust into multiple distributed chiplet roots of trust (C-RoTs), where each chiplet has its own C-RoT that can independently perform key management operations. This segmentation eliminates the latency associated with centralized key management while maintaining security through mutual authentication mechanisms between C-RoTs.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a single root of trust is enabled across all chiplets, then security is simplified, but resources are wasted when not all chiplets need RoT

Engineering Contradiction:
Improvesecurity boundary establishmentVSAvoidresource usage
Core Design Contradiction:
Device complexityVSQuantity of substance

Solution Approach 1:

The patent enables root of trust functionality only where needed by distributing C-RoTs to specific chiplets that require security operations, rather than enabling RoT in all chiplets. Each chiplet's C-RoT is configured with appropriate security capabilities based on its specific requirements, optimizing resource usage while maintaining security where necessary.

Inventive Principle:
Principle #3Local quality

3Reliability

If traditional single RoT method is used, then security boundary is established, but security vulnerabilities exist when RoT is not enabled on all chiplets

Engineering Contradiction:
Improvesecurity boundary establishmentVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the security boundaries of multiple individual C-RoTs into a common security boundary through mutual authentication. Each C-RoT authenticates with others in the chiplet package, creating an interconnected trust relationship that establishes a unified security boundary across all participating chiplets, eliminating vulnerabilities associated with selective RoT enablement.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250097019A1Coherent key management across multiple chiplets
Publication Date: 2025.03.20 QUALCOMM INC
  • US20250097019A1 patent drawing
  • US20250097019A1 patent drawing
  • US20250097019A1 patent drawing

AI summary

Systems and techniques are provided for establishing a connection. For instance, a process may include receiving, at a first chiplet root of trust (C-ROT) of a first chiplet of a plurality of chiplets, a request for a cryptographic key; generating, by the first C-ROT, the cryptographic key; wrapping, by the first C-ROT, the cryptographic key using a wrapping key to generate a wrapped cryptographic key; outputting, by the first C-ROT, the wrapped cryptographic key; receiving the wrapped cryptographic key at a second C-ROT of a second chiplet of the plurality of chiplets; unwrapping, by the second C-ROT, the wrapped cryptographic key using the wrapping key; and performing, by the second C-ROT, an operation based on the cryptographic key.