Die-to-Die Interconnect Encryption for Multi-Die Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-die packages face vulnerabilities in die-to-die communications due to the potential for hackers to access sensitive data, as existing security measures are inadequate in protecting data transferred between integrated circuit dies.
Innovation Solution
Incorporating encryption and decryption circuitry within each die to selectively encrypt sensitive data as it transfers between dies via interconnects, using metadata fields to control encryption and decryption processes, and employing bypass circuitry for time division techniques to manage encryption and decryption operations based on data sensitivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption circuitry is added to protect sensitive data in die-to-die communications, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the communication data into sensitive and non-sensitive portions, applying encryption only to the sensitive segments. The encryption circuitry selectively encrypts sensitive data based on identification, rather than encrypting all data uniformly. This segmentation approach improves security for critical information while avoiding the overhead of encrypting entire data streams, thereby balancing security enhancement with manageable device complexity.
Solution Approach 2:
The patent implements local quality by applying different processing treatments to different portions of the data. Sensitive data receives encryption processing while non-sensitive data passes through without encryption. The system identifies sensitive portions and applies encryption locally to those specific segments, rather than uniformly processing all data. This approach enhances security where needed while maintaining efficiency and reducing overall system complexity.
2Reliability
If selective encryption of sensitive data is implemented, then security is improved, but processing overhead increases
Solution Approach 1:
The patent applies partial action by encrypting only the sensitive portions of data rather than the entire data stream. The encryption circuitry selectively processes identified sensitive segments while leaving non-sensitive data unencrypted. This partial encryption approach provides security for critical information without incurring the full processing overhead of comprehensive encryption, thereby improving security while maintaining acceptable processing efficiency.
Solution Approach 2:
The system segments data into sensitive and non-sensitive portions, applying encryption processing only to the sensitive segments. This segmentation allows the system to avoid the excessive processing overhead of encrypting all data while still providing security where needed. The identification and selective processing of sensitive segments reduces overall processing requirements compared to full-data encryption.
3Reliability
If encryption operations are performed on all data transfers, then security is improved, but power consumption increases
Solution Approach 1:
The patent implements partial action by performing encryption operations only on sensitive data portions rather than all data transfers. The encryption circuitry is activated selectively based on data sensitivity identification, encrypting only when necessary. This approach provides security for sensitive information while avoiding the excessive power consumption that would result from continuous encryption of all data, thereby balancing security improvement with power efficiency.
Solution Approach 2:
The system employs periodic action by intermittently activating encryption operations based on the sensitivity of the data being transmitted. Rather than continuous encryption, the encryption circuitry is engaged periodically only when sensitive data is detected. This periodic activation pattern reduces overall power consumption while maintaining security for sensitive communications, as the encryption function is performed only when required rather than continuously.
Data Source
AI summary
Systems or methods of the present disclosure may provide a semiconductor device including a die of a multi-die package including encryption circuitry to receive data and to encrypt the data to generate encrypted data; and a connection interface to transmit the encrypted data over a die-to-die interconnect to a second die.


