Security Chip Mediating Memory Access in Multi-Chip Packages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing semiconductor packages lack effective security measures to protect digital data from unauthorized access and theft, as they rely solely on memory chips without integrated security features.

Innovation Solution

A multi-chip package is developed, incorporating a security chip and a memory chip, where the security chip enables a security path to execute security procedures and access the memory chip only when a security requirement is detected, ensuring data security and providing an additional data region for security operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security chip is integrated with a memory chip to ensure information security, then data security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoidpackage structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two functional modules: a memory chip for data storage and a security chip for security operations. This segmentation allows each chip to be optimized for its specific function while working together in a multi-chip package, resolving the contradiction by separating security functions from storage functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security chip acts as an intermediary between the host and the memory chip. It controls access to the memory chip by verifying security procedures first, and only enables the control path after successful verification. This intermediary role ensures security without requiring the memory chip itself to be complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a security path is enabled to execute security procedures, then authentication and encryption capabilities are improved, but access speed decreases

Engineering Contradiction:
Improveauthentication securityVSAvoiddata access speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The system dynamically switches between two operational paths: a security path for authentication/encryption operations and a control path for normal data access. After security procedures are successfully executed on the security path, the control path is enabled for high-speed data transfer. This dynamic path switching resolves the contradiction by separating security operations from data transfer operations in time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Security procedures (authentication, encryption key generation) are executed in advance on the security path before data access operations. The security chip prepares security credentials and verifies access requests beforehand, so that when data access is needed, the control path can be quickly enabled without repeated security checks, improving overall access speed.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the security chip uses additional data region from memory chip, then security procedure execution capability is improved, but memory availability for host decreases

Engineering Contradiction:
Improvesecurity procedure capabilityVSAvoidavailable memory capacity
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

A specific data region is extracted from the memory chip and allocated exclusively to the security chip for security operations. This extracted region is used for storing security credentials, encryption keys, and executing security procedures. By taking out this dedicated region, the security chip gains the necessary resources while the host retains access to the remaining memory capacity through the control path.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10969991B2Multi-chip package, controlling method of multi-chip package and security chip
Publication Date: 2021.04.06 MACRONIX INTERNATIONAL CO LTD
  • US10969991B2 patent drawing
  • US10969991B2 patent drawing
  • US10969991B2 patent drawing

AI summary

A multi-chip package, a controlling method of the multi-chip package and a security chip are provided. The multi-chip package includes a memory chip and a security chip. The security chip is coupled between the memory chip and a host. The security chip includes a processing circuit. The processing circuit is for enabling a security path to input an input-output signal into the processing circuit for executing a security procedure and accessing the memory chip, if a command is received by the processing circuit and the command includes a security requirement.