Integrated Circuit Security via OTP Pinout and Address Map Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge is to ensure that non-secure integrated circuits (ICs) cannot be used in place of secure ICs without requiring separate part numbers, as hackers might replace secure ICs with non-secure ones to bypass security features, posing a risk to systems that rely on secure ICs for confidentiality.
Innovation Solution
Allowing IC customers to modify the external pin assignments and internal address maps during the security customization process, making it difficult for hackers to replace secure ICs with non-secure ones by requiring significant redesign of both the printed circuit board and software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the same integrated circuit design is used for both secure and non-secure applications, then manufacturing cost is reduced and versatility is improved, but security is compromised because hackers can replace secure ICs with non-secure ones
Solution Approach 1:
The patent applies local quality by enabling security features selectively in specific IC instances through customization. The same base IC design is used, but security features (such as secure boot, encrypted storage, or secure communication protocols) are activated only in ICs designated for secure applications through customization processes like fuses, anti-fuse, or OTP memory programming. This allows the manufacturer to provide a single versatile design while ensuring that secure applications receive the necessary security protections.
Solution Approach 2:
The patent implements preliminary action by pre-configuring security features during the IC customization process before the IC is deployed. Security parameters, keys, or feature enablement states are programmed into the IC during manufacturing or prior to delivery to the customer. This preliminary configuration ensures that when the IC is installed in a secure application, the security features are already active and cannot be easily disabled or bypassed, preventing hackers from using non-secure replacements.
2Reliability
If security features are enabled through customization, then security is improved, but device complexity increases due to additional configuration options
Solution Approach 1:
The patent extracts the security configuration complexity from the end-user experience and concentrates it in the manufacturing/customization phase. The customization process handles all security feature enablement, key generation, and parameter configuration automatically through programmed processes. Once customized, the IC presents a simple interface with security features already activated and managed internally. This extraction of complexity to the manufacturing stage allows high security without burdening the end-user with complex configuration options.
3Reliability
If separate part numbers are used for secure and non-secure ICs, then security is improved by preventing replacement, but manufacturing cost increases and versatility decreases
Solution Approach 1:
The patent applies universality by designing a single base IC architecture that can serve both secure and non-secure applications. The same physical IC design, with the same pinout and basic functionality, is manufactured and then customized to enable or disable security features as needed. This universal design allows the manufacturer to produce one base part number that can be customized into multiple variants (secure or non-secure) without requiring separate design cycles, tooling, or manufacturing lines, thereby reducing overall manufacturing costs while maintaining security distinctions.
Data Source
AI summary
An integrated circuit can be made more secure by programming a one time programmable circuit so that different signals are provided on terminals as compared to when the integrated circuit was not secure. Instead, or in addition, the integrated circuit can be made more secure by providing decode circuitry that can be used with the one time programmable circuit to select different internal address maps in response to an address value. The decode circuitry can use a first address map when the integrated circuit is secure, and a different address map when the integrated circuit is non-secure.


