Confidential IC Design Protection via Trusted Execution Enclave

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The semiconductor industry faces significant threats from insider attacks, where malicious employees can extract confidential integrated circuit (IC) design data due to lack of protection mechanisms, posing risks to national security and economic interests.

Innovation Solution

Implementing a method that includes data encryption, obfuscation, and Security Hard Macro (SHM) functional replacement and recovery techniques across various stages of the IC design process to restrict access and protect confidential data, allowing only encrypted or obfuscated information to be accessed by untrusted computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees are given unrestricted access to design tools and digital data during the IC design process, then productivity and ease of operation are improved, but security and protection against insider attacks deteriorate

Engineering Contradiction:
Improveaccess to design toolsVSAvoidinsider attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary layer between employees and the design tools/data. The TEE acts as a secure enclave that allows employees to access and process design data with restricted privileges, preventing direct extraction of confidential information while maintaining operational capability. This mediator structure resolves the contradiction by enabling controlled access without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the design data and tools into different access levels and zones within the TEE. Confidential design data is separated from publicly accessible data, and employees are granted segmented permissions based on their roles. This segmentation allows employees to perform their functions while preventing unauthorized access to sensitive information, thus addressing both productivity and security requirements.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If encryption and obfuscation techniques are applied to design data, then security against insider attacks is improved, but device complexity and difficulty of operation worsen

Engineering Contradiction:
Improvedata extraction by insidersVSAvoidsecurity mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The TEE provides self-service security mechanisms where the encryption and obfuscation operations are automatically performed within the secure environment without requiring manual intervention or complex configuration from employees. The system handles security operations autonomously, reducing the burden on users while maintaining strong protection. This self-service approach manages complexity by abstracting security functions from user interactions.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If Security Hard Macro (SHM) placeholder design elements are inserted to replace confidential design elements, then protection against data extraction is improved, but manufacturing precision and design accuracy worsen

Engineering Contradiction:
Improveconfidential design element extractionVSAvoiddesign element accuracy
Core Design Contradiction:
Object-affected harmful factorsVSManufacturing precision

Solution Approach 1:

The patent implements a recoverability mechanism where SHM placeholders are temporarily replaced with actual design elements within the TEE for processing, then discarded from the visible design view. The original confidential design elements are recovered and maintained within the TEE's secure storage. This allows the design process to proceed with placeholders for security while preserving the accuracy of original design elements in the secure environment, resolving the contradiction between protection and precision.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11704415B2Method, apparatus and computer program product for protecting confidential integrated circuit design
Publication Date: 2023.07.18 UNIV OF FLORIDA RESEARCH FOUNDATION INC
  • US11704415B2 patent drawing
  • US11704415B2 patent drawing
  • US11704415B2 patent drawing

AI summary

Methods, apparatus and computer program product for protecting a confidential integrated circuit design process. The computer-implemented method includes receiving a design specification dataset from a first untrusted computing device; extracting confidential design specification data from the design specification dataset; encrypting the confidential design specification data to produce encrypted confidential design specification data; generate a first encryption key to be associated with the encrypted confidential design specification data; retrieving a confidential design specification data subset for replacing a design element subset with a security hard macro (SHM) placeholder design element set; generating a security hard macro (SHM) placeholder feature set comprising those security hard macro (SHM) placeholder features representing mappings from the confidential design specification data subset to the SHM placeholder design element set; and transmitting, to the first untrusted computing device, the encrypted confidential design specification data, the first encryption key, and the SHM placeholder feature set.