Chiplet Security Architecture for Confidential Accelerator Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Confidential computing standards do not specify how to extend trust from a trusted virtual machine to accelerator circuits and/or I/O devices in a multi-chiplet-based and/or tile-based system-in-package (SiP), where these components reside on different chiplets within the same package, leading to potential unprotected transmission of confidential data.
Innovation Solution
Implement a scalable and cost-effective identity and authentication security architecture for multi-chiplet, multi-accelerator circuit SiPs, using a root of trust device confidential computing circuit to securely identify and authenticate accelerator circuits, establish a secure communication channel, and manage identities and keys, ensuring secure communication sessions between the trusted execution environment and chiplet device security management circuit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If confidential computing standards are applied to traditional single-chip systems, then security is improved, but the system cannot support multi-chiplet architectures with distributed accelerator circuits
Solution Approach 1:
The patent divides the security management function into distributed Device Security Management (DSM) circuits on each chiplet and a centralized Root of Trust (RoT) circuit. Each accelerator chiplet has its own DSM circuit that can independently authenticate with the RoT, enabling security in multi-chiplet systems while maintaining the segmented architecture.
Solution Approach 2:
The patent introduces Device Security Management (DSM) circuits as intermediary components between accelerator circuits and the Root of Trust. These DSM circuits manage identities and authenticate accelerator circuits, bridging the gap between the RoT and distributed accelerators across multiple chiplets.
2Device complexity
If traditional authentication methods are used in multi-chiplet systems, then implementation complexity is reduced, but data confidentiality and integrity cannot be ensured across untrusted components
Solution Approach 1:
The patent creates a universal authentication framework where the Root of Trust and DSM circuits can authenticate any accelerator circuit across any number of chiplets using a standardized identity management approach. This universal method works for both trusted and untrusted components without requiring different authentication mechanisms.
Solution Approach 2:
The patent changes the authentication parameters by introducing unique identities for each chiplet and accelerator circuit, along with cryptographic key pairs stored in secure elements. This transforms the authentication approach from simple method-based verification to identity-based cryptographic verification, ensuring data confidentiality.
3Reliability
If secure authentication is implemented for each accelerator circuit in a multi-chiplet system, then data protection is improved, but system cost and complexity increase
Solution Approach 1:
The patent merges the security management functions into a unified architecture where the Root of Trust centrally manages identities for all chiplets, and DSM circuits on each chiplet handle local authentication. This consolidation reduces overall system complexity compared to implementing independent security systems on each chiplet.
Solution Approach 2:
The patent implements self-service authentication where each DSM circuit autonomously manages its chiplet's security credentials and performs authentication with the RoT without requiring external intervention. This automation reduces operational complexity and enables scalable deployment.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, apparatus, articles of manufacture, and methods are disclosed for confidential computing security management for a multi-chiplet, multi-accelerator system-in-package. An example multi-die System-In-Package (SiP) includes a first die including a circuit. Additionally, the example multi-die SiP includes a second die to authenticate the circuit to permit secure communication within the SiP.