Inter-Die Authentication Codes for Secure Chiplet Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor systems face challenges in ensuring secure communication between interconnected dies, particularly in chiplet-based architectures, without the overhead of encrypting all data, which increases power consumption and area requirements.
Innovation Solution
Implementing a semiconductor system with a shared key stored in security processors on each die, where authentication codes are generated and verified to ensure message integrity, reducing the need for encrypting all data exchanged.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full data encryption is implemented between interconnected dies, then communication security is improved, but power consumption increases
Solution Approach 1:
The patent segments the data transmission into two parts: authentication data (verified using authentication codes) and payload data (transmitted without encryption). This segmentation allows security verification without encrypting the entire data stream, thereby reducing power consumption while maintaining security.
Solution Approach 2:
Instead of applying full encryption to all data (excessive action), the patent applies authentication codes only to critical authentication fields (partial action). This partial application of security measures is sufficient to ensure communication security while avoiding the overhead of encrypting every byte of data.
2Reliability
If full data encryption is implemented between interconnected dies, then communication security is improved, but area requirements increase
Solution Approach 1:
The patent segments the security implementation to apply authentication codes only where necessary (in authentication data fields) rather than across the entire communication interface. This reduces the area required for encryption/decryption hardware while maintaining security for critical information.
Solution Approach 2:
The patent applies security measures partially - using authentication codes for verification without implementing full encryption infrastructure. This partial approach reduces the hardware area required for security functions while still providing adequate protection for communication between dies.
3Reliability
If full data encryption is implemented between interconnected dies, then communication security is improved, but latency increases
Solution Approach 1:
The patent segments processing operations so that authentication codes are generated and verified separately from main data transmission. This allows receiving dies to verify authentication quickly without waiting for full decryption of large data payloads, thereby reducing overall latency.
Solution Approach 2:
The patent uses lightweight authentication codes instead of full encryption/decryption processes. This partial security approach significantly reduces the computational time required for security verification, thereby reducing latency in inter-die communication.
4Reliability
If full data encryption is implemented between interconnected dies, then communication security is improved, but device complexity increases
Solution Approach 1:
The patent segments the security architecture into simple authentication code generation and verification units, separate from the main data path. This segmentation avoids the need for complex encryption engines while still providing security verification capabilities.
Solution Approach 2:
The patent implements minimal security functionality (authentication codes) rather than full encryption suites. This partial implementation reduces the complexity of security components while providing sufficient protection for inter-die communication authentication.
Data Source
AI summary
A semiconductor system includes a first die, including a first security processor configured to store a shared key and an application processor, and a second die connected to the first die through a first channel and including a second security processor configured to store the shared key. The application processor may transmit a security request to the first security processor in response to a request for a security-required operation of the second die. The first security processor, in response to the security request, may be configured to generate an authentication code based on the shared key and transmit a security message, including a command corresponding to the security-required operation of the second die and the authentication code, to the second security processor through the first channel. The second security processor may determine whether the security message has been tampered with, using the authentication code and the shared key.


