Policy Arbitrator for Multi-Die SOC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of manufacturing system-on-chip (SOC) assemblies due to shrinking transistor sizes leads to long manufacturing process hold times, which is mitigated by replicating multiple dies on the same package, but this introduces security challenges from differing security policies across dies, potentially allowing unauthorized access and tampering.

Innovation Solution

A policy arbitrator (PA) coordinates and synchronizes security policies across multiple dies or subsystems within an SOC, designating master and slave dies, and enforcing a unified security policy through an embedded multi-die interconnect bridge (EMIB) to ensure all intellectual property cores adhere to a single, secure policy, preventing tampering and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If multiple dies are replicated on the same package to reduce overall die size, then manufacturing complexity and hold times are reduced, but security policy coordination and synchronization become more difficult

Engineering Contradiction:
Improvemanufacturing process hold timeVSAvoidsecurity policy coordination complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

A policy arbitrator component is introduced as an intermediary to coordinate security policies across multiple dies. The policy arbitrator receives security policies from each die, synchronizes them, and ensures consistent security enforcement throughout the multi-die system, thereby managing the complexity introduced by having multiple dies on a single package.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management system is segmented into distributed security policy components on each die and a centralized policy arbitrator. This segmentation allows each die to maintain its own security policies locally while the policy arbitrator coordinates them, enabling scalable security management as the number of dies increases.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple dies with different security policies are used, then manufacturing flexibility is improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improvemanufacturing flexibilityVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security policy system is made dynamic through the policy arbitrator, which can adapt and synchronize security policies in real-time across multiple dies. This dynamic coordination ensures that even though each die may have different security policies initially, they are continuously synchronized to maintain security integrity while preserving manufacturing flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The policy arbitrator implements feedback mechanisms to monitor and coordinate security policies across all dies. By continuously receiving security policy information from each die and providing synchronization feedback, the system maintains security integrity while allowing manufacturing flexibility.

Inventive Principle:
Principle #23Feedback

3Reliability

If a unified security policy is enforced across all dies, then security integrity is improved, but policy coordination overhead and system complexity increase

Engineering Contradiction:
Improvesecurity integrityVSAvoidpolicy coordination overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The policy arbitrator serves multiple functions: it receives security policies from each die, synchronizes them, enforces unified security policies, and coordinates security events across all dies. This multi-functional component consolidates the complexity of policy coordination into a single universal security management entity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20180349650A1Security policy management for a plurality of dies in a system-on-chip
Publication Date: 2018.12.06 ALTERA CORP
  • US20180349650A1 patent drawing
  • US20180349650A1 patent drawing
  • US20180349650A1 patent drawing

AI summary

Embodiments herein relate to a die to form a system-on-chip (SOC) with one or more other dies, with a policy arbitrator disposed on the die to manage security policies of the plurality of dies of the SOC, where the PA is to receive information about a security policy and a die type from a first of the one or more other dies, compare at least the received information about the security policy and the die type of the first other die with a security policy and a die type of the die, determine, based on the comparison, a common security policy for the plurality of dies of the SOC, and transmit the determined common security policy and the die type of the die to at least a second of the one or more other dies.