IC Package Reconfiguration via Integrated Non-Volatile Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuit (IC) packages, such as system on chips (SoCs), cannot be reprogrammed once configured, leading to significant costs due to the inability to modify package attributes, especially as package complexity increases and the failure of one die results in discarding the entire package.
Innovation Solution
Incorporating non-volatile memory within the IC package to store configuration information, which can be reconfigured by using a cryptographic processor to securely manage and update the configuration settings, allowing for encryption and decryption of configuration images with unique keys, ensuring authorized access and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If configuration information is stored in non-volatile memory, then the IC package can be reconfigured post-manufacturing, but the device complexity increases due to additional memory and cryptographic processor components
Solution Approach 1:
The patent combines the configuration storage functionality with the existing IC package structure by integrating non-volatile memory and cryptographic processor within the package. This merging approach allows reconfiguration capability to be added without requiring entirely separate external systems, thereby managing complexity while enabling adaptability.
Solution Approach 2:
The cryptographic processor serves multiple functions: it secures the configuration information storage, enables authentication for reconfiguration operations, and protects against unauthorized access. This multi-functionality reduces the need for separate dedicated security components, managing overall device complexity while enabling reconfigurability.
2Reliability
If cryptographic processor is added to secure configuration updates, then security and authorization are enhanced, but manufacturing cost and device complexity increase
Solution Approach 1:
The cryptographic processor pre-establishes security credentials and authentication mechanisms before configuration updates occur. Configuration information is secured with cryptographic protection in advance, and authentication credentials are pre-configured, enabling secure reconfiguration operations without requiring complex real-time security verification systems.
Solution Approach 2:
The cryptographic processor acts as an intermediary between the configuration update system and the non-volatile memory. It mediates all configuration updates by verifying authentication credentials and ensuring cryptographic integrity, thereby simplifying the security architecture while enhancing reliability.
3Adaptability or versatility
If non-volatile memory is used to store configuration information, then reconfiguration capability is enabled, but the loss of time for cryptographic verification and updating increases
Solution Approach 1:
Authentication credentials and cryptographic keys are pre-configured and stored securely in the non-volatile memory during manufacturing. This preliminary setup eliminates the need for time-consuming key generation and authentication credential verification during reconfiguration operations, reducing update time while maintaining security.
Solution Approach 2:
The cryptographic processor uses pre-stored authentication credentials and keys (copies of the security information) to verify configuration updates rapidly. Instead of performing complex real-time cryptographic operations, the system uses pre-computed authentication data to quickly verify update authenticity, reducing verification time.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An apparatus is disclosed. The apparatus comprises an integrated circuit (IC) package including a plurality of ICs; a non-volatile memory to store configuration information comprising settings that define an operation of the plurality ICs and a configuration register to receive configuration bits from the non-volatile memory representing a final configuration for the package