Security Chip Mediating Memory Access in Multi-Chip Packages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor packages lack effective security measures to protect digital data from unauthorized access and theft, as they rely solely on memory chips without integrated security features.
Innovation Solution
A multi-chip package is developed, incorporating a security chip and a memory chip, where the security chip enables a security path to execute security procedures and access the memory chip only when a security requirement is detected, ensuring data security and providing an additional data region for security operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security chip is integrated with a memory chip to ensure information security, then data security is improved, but device complexity increases
Solution Approach 1:
The system is divided into two functional modules: a memory chip for data storage and a security chip for security operations. This segmentation allows each chip to be optimized for its specific function while working together in a multi-chip package, resolving the contradiction by separating security functions from storage functions.
Solution Approach 2:
The security chip acts as an intermediary between the host and the memory chip. It controls access to the memory chip by verifying security procedures first, and only enables the control path after successful verification. This intermediary role ensures security without requiring the memory chip itself to be complex.
2Reliability
If a security path is enabled to execute security procedures, then authentication and encryption capabilities are improved, but access speed decreases
Solution Approach 1:
The system dynamically switches between two operational paths: a security path for authentication/encryption operations and a control path for normal data access. After security procedures are successfully executed on the security path, the control path is enabled for high-speed data transfer. This dynamic path switching resolves the contradiction by separating security operations from data transfer operations in time.
Solution Approach 2:
Security procedures (authentication, encryption key generation) are executed in advance on the security path before data access operations. The security chip prepares security credentials and verifies access requests beforehand, so that when data access is needed, the control path can be quickly enabled without repeated security checks, improving overall access speed.
3Adaptability or versatility
If the security chip uses additional data region from memory chip, then security procedure execution capability is improved, but memory availability for host decreases
Solution Approach 1:
A specific data region is extracted from the memory chip and allocated exclusively to the security chip for security operations. This extracted region is used for storing security credentials, encryption keys, and executing security procedures. By taking out this dedicated region, the security chip gains the necessary resources while the host retains access to the remaining memory capacity through the control path.
Data Source
AI summary
A multi-chip package, a controlling method of the multi-chip package and a security chip are provided. The multi-chip package includes a memory chip and a security chip. The security chip is coupled between the memory chip and a host. The security chip includes a processing circuit. The processing circuit is for enabling a security path to input an input-output signal into the processing circuit for executing a security procedure and accessing the memory chip, if a command is received by the processing circuit and the command includes a security requirement.


