Die-to-Die Interconnect Encryption for Multi-Die Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Multi-die packages face vulnerabilities in die-to-die communications due to the potential for hackers to access sensitive data, as existing security measures are inadequate in protecting data transferred between integrated circuit dies.

Innovation Solution

Incorporating encryption and decryption circuitry within each die to selectively encrypt sensitive data as it transfers between dies via interconnects, using metadata fields to control encryption and decryption processes, and employing bypass circuitry for time division techniques to manage encryption and decryption operations based on data sensitivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption circuitry is added to protect sensitive data in die-to-die communications, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the communication data into sensitive and non-sensitive portions, applying encryption only to the sensitive segments. The encryption circuitry selectively encrypts sensitive data based on identification, rather than encrypting all data uniformly. This segmentation approach improves security for critical information while avoiding the overhead of encrypting entire data streams, thereby balancing security enhancement with manageable device complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different processing treatments to different portions of the data. Sensitive data receives encryption processing while non-sensitive data passes through without encryption. The system identifies sensitive portions and applies encryption locally to those specific segments, rather than uniformly processing all data. This approach enhances security where needed while maintaining efficiency and reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

2Reliability

If selective encryption of sensitive data is implemented, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by encrypting only the sensitive portions of data rather than the entire data stream. The encryption circuitry selectively processes identified sensitive segments while leaving non-sensitive data unencrypted. This partial encryption approach provides security for critical information without incurring the full processing overhead of comprehensive encryption, thereby improving security while maintaining acceptable processing efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system segments data into sensitive and non-sensitive portions, applying encryption processing only to the sensitive segments. This segmentation allows the system to avoid the excessive processing overhead of encrypting all data while still providing security where needed. The identification and selective processing of sensitive segments reduces overall processing requirements compared to full-data encryption.

Inventive Principle:
Principle #1Segmentation

3Reliability

If encryption operations are performed on all data transfers, then security is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by performing encryption operations only on sensitive data portions rather than all data transfers. The encryption circuitry is activated selectively based on data sensitivity identification, encrypting only when necessary. This approach provides security for sensitive information while avoiding the excessive power consumption that would result from continuous encryption of all data, thereby balancing security improvement with power efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system employs periodic action by intermittently activating encryption operations based on the sensitivity of the data being transmitted. Rather than continuous encryption, the encryption circuitry is engaged periodically only when sensitive data is detected. This periodic activation pattern reduces overall power consumption while maintaining security for sensitive communications, as the encryption function is performed only when required rather than continuously.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20220229941A1Security on die-to-die interconnect
Publication Date: 2022.07.21 ALTERA CORP
  • US20220229941A1 patent drawing
  • US20220229941A1 patent drawing
  • US20220229941A1 patent drawing

AI summary

Systems or methods of the present disclosure may provide a semiconductor device including a die of a multi-die package including encryption circuitry to receive data and to encrypt the data to generate encrypted data; and a connection interface to transmit the encrypted data over a die-to-die interconnect to a second die.