Operation Limiting Device for Semiconductor Equipment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user authentication and access control systems for semiconductor manufacturing apparatuses are inadequate in preventing malicious or erroneous operations, as they do not effectively protect against intentional or unintentional errors, even with strict access management and authentication measures.

Innovation Solution

An operation limiting device that includes an authentication unit, a receiving unit, and an operation enabling unit, which authenticates users, receives operation requests or permissions, and enables operations based on user authentication and attribute information, with features such as storage of authentication and attribute data, operation grouping, and notification of performed states to enhance security and safety.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strict user authentication and access control are implemented, then user identification reliability is improved, but the system cannot protect against malicious operations by authenticated users or erroneous operations by expert users

Engineering Contradiction:
Improveuser identification reliabilityVSAvoidmalicious operations and erroneous operations
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by requiring advance notification to other users before executing operations. The notification unit sends alerts to designated users, who then have the opportunity to review and approve or reject the operation before it is carried out. This preliminary review process prevents malicious operations by authenticated users and erroneous operations by expert users, as the operation is subject to external verification before execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where operation requests are communicated to other users, who provide approval or rejection feedback. The notification unit sends operation details to specified users, and the system waits for their response before proceeding. This feedback loop ensures that operations are reviewed by peers or supervisors, creating a check against both intentional malicious acts and unintentional errors by authenticated users.

Inventive Principle:
Principle #23Feedback

2Reliability

If operation requests are approved by multiple authenticated users with different attribute information, then operation safety is improved, but operation processing time increases

Engineering Contradiction:
Improveoperation safetyVSAvoidoperation processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system segments the approval process by assigning different attribute requirements to different operation types. The storage unit maintains attribute information indicating the number and type of user approvals needed for each operation. This segmentation allows critical operations to require multiple approvals while less critical operations can proceed with fewer approvals, balancing safety requirements with processing efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial action by requiring only the necessary number of approvals for each operation type, not necessarily all possible users. The attribute information specifies the exact number of approvals needed, allowing the system to stop collecting approvals once that threshold is reached. This prevents excessive waiting time while still obtaining sufficient oversight for safe operation execution.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2833285B1Operation limiting device, operation limiting method, and computer program
Publication Date: 2020.08.26 TOKYO ELECTRON LTD
  • EP2833285B1 patent drawingFigure 1A~1B
  • EP2833285B1 patent drawingFigure 2
  • EP2833285B1 patent drawingFigure 3

AI summary

Provided is an operation limiting device (2) which makes it possible to achieve more robust security and safety in processing of a workpiece by a processing apparatus (1). The operation limiting device (2) limits operations relating to processing of a workpiece by a processing apparatus (1), and is provided with: an authentication unit for authenticating each of a plurality of users; a receiving unit for receiving an operation request or permission for said operation, from a plurality of authenticated users; an operation enabling unit for enabling an operation if an operation request or permission has been received from the plurality of authenticated users; and a releasing unit for releasing the operation enabled state set by the operation enabling unit if processing relating to the operation has terminated or if a predetermined period of time corresponding to the operation has elapsed.