Hardware Security Circuit Nesting Under Northbridge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
High-value computers and devices are not suitable for pay-as-you-go business models due to the difficulty in enforcing contract terms, as existing hardware security circuitry can be subject to physical attacks and bypassing, especially when the device is not connected to the service provider's network.
Innovation Solution
Physically mounting a hardware security circuit underneath a larger device, such as a Northbridge or processor chip, with restricted interconnects and additional complex traces, enhances security by making attacks on the interconnects more difficult and increases the risk of damage to attackers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware security circuitry is used to enforce contract terms, then the ability to control device usage is improved, but the security circuit itself becomes vulnerable to physical attacks, bypassing, or removal
Solution Approach 1:
The patent implements nesting by placing the hardware security circuit (second circuit) underneath a larger device such as a Northbridge or processor chip (first circuit). This layered configuration physically protects the security circuit by embedding it within the structure of the larger device, making it difficult to access, remove, or attack without damaging the overlying components. The security circuit remains functional while being shielded by the larger device that sits above it on the circuit board.
Solution Approach 2:
The patent transitions from a two-dimensional surface mounting arrangement to a three-dimensional stacked configuration. By mounting the security circuit underneath the larger device rather than beside or above it, the invention utilizes the vertical dimension (Z-axis) to create physical protection. This dimensional change restricts interconnects to the footprint of the larger device and makes attacks on interconnect traces increasingly difficult.
2Object-affected harmful factors
If the hardware security circuit is mounted on the circuit board, then it can be accessed and attacked from the back side, but mounting it underneath a larger device restricts access and enhances security
Solution Approach 1:
The security circuit is nested underneath the larger device, creating a protected configuration where the security circuit benefits from the physical presence of the larger device as a shield. This nesting arrangement prevents direct access to the security circuit from the back side of the board and requires attackers to navigate through or around the larger device to reach the security circuit.
Solution Approach 2:
By moving the security circuit to the opposite side of the larger device (underneath rather than above), the patent utilizes spatial separation in the vertical dimension. This dimensional arrangement forces interconnects to pass through or under the larger device's footprint, adding complexity to any physical attack route and protecting the security circuit from straightforward back-side access.
3Ease of manufacture
If simple interconnects are used between security circuit and larger device, then manufacturing is easier, but complex traces and data busses reduce the risk of attackers cutting through from the back side
Solution Approach 1:
The patent utilizes the vertical dimension by routing interconnects through multiple layers and under the footprint of the larger device. This three-dimensional interconnect strategy increases the physical path length and complexity for attackers trying to cut traces from the back side, while the manufacturing process remains feasible using standard multi-layer PCB techniques.
Solution Approach 2:
The interconnect structure is segmented into multiple pathways including data busses and address busses that are distributed across different layers and locations. This segmentation means that an attacker would need to successfully cut multiple separate traces rather than a single simple interconnect, significantly increasing the difficulty of successful physical attacks while maintaining manufacturability.
Data Source
AI summary
A pay-per-use computer, or other electronic device that uses local security, may use a security module or other circuit for monitoring and enforcement of a usage policy. To help prevent physical attacks on the security module, or the circuit board near the security module, a second circuit may be mounted over the security module to help prevent access to the security module. Both circuits may be mounted on a interposer and the interposer mounted to the circuit board, creating a stack including the first circuit, the interposer, the security module, and a main PC board. When the PC board includes dense signal traces under the security module a three dimensional envelope is created around the security module. When the first circuit is a high value circuit, such as a Northbridge, the risk/reward of attacking the security module is increased substantially and may deter all but the most determined hackers.


