System-in-Package Shielding for Cryptographic Side-Channel Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge devices, particularly IoT devices, are vulnerable to physical and side-channel attacks due to unsecured transmission of cryptographic keys and lack of integrated protection against intrusion and electromagnetic interference, compromising secure operations and data integrity.

Innovation Solution

A circuit assembly design with a main processor and cryptographic processor mounted on opposite sides of a substrate, with traces and power converters enclosed within a cavity, and electromagnetic shielding to prevent physical and side-channel attacks, utilizing BGA mounting and high-density interconnects to secure key transmission and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are transmitted through traces on a substrate, then communication between processors is enabled, but the traces become exposed to physical and side-channel attacks

Engineering Contradiction:
Improvesecurity of cryptographic key transmissionVSAvoidexposure to physical and side-channel attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent moves the cryptographic processor from the traditional planar substrate surface to a three-dimensional cavity structure within the substrate. This dimensional transition embeds the processor internally, making the traces and processor inaccessible from the substrate exterior, thereby eliminating exposure to physical and side-channel attacks while maintaining functional connectivity through controlled internal trace routing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The cryptographic processor is nested within a cavity formed by the second substrate, which itself is mounted to the first substrate. This nested structure places the processor inside a protective enclosure, with traces routed through the substrate interior to connect the embedded processor to external interfaces, effectively shielding the cryptographic operations from external attacks.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If processors are mounted on opposite sides of a substrate, then trace exposure is reduced, but electromagnetic interference and physical access risks remain

Engineering Contradiction:
Improveprotection against physical attacksVSAvoidelectromagnetic interference
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces an electromagnetic shield as an intermediary element positioned between the cryptographic processor and the external environment. This shield acts as a mediator that blocks electromagnetic fields from reaching the processor, preventing side-channel attacks based on electromagnetic radiation while allowing the processor to function normally within the cavity structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a cavity structure is used to enclose the cryptographic processor, then physical access is blocked, but manufacturing complexity increases

Engineering Contradiction:
Improveprotection against intrusionVSAvoidsubstrate structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the substrate into two functional segments: the first substrate that provides the cavity structure and houses the cryptographic processor, and the second substrate that mounts to the first substrate and provides external interfaces. This segmentation allows the complex cavity structure to be manufactured as a dedicated security module, separating the security-critical embedded processor from the I/O-focused external substrate, thereby managing manufacturing complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by protecting cryptographic key transmission and operations from physical and side-channel attacks, reducing exposure to malicious access and electromagnetic interference, thereby securing sensitive data and maintaining system integrity.

Implementation Method 1

The circuit assembly may also include an electromagnetic shield that is configured to block electromagnetic radiation from reaching the cryptographic processor

Methodology Applied
Scientific EffectElectromagnetic shielding: Faraday Cage

Implementation Method 2

The circuit assembly may also include a layer of metal shielding that is sputtered onto the first side of the first substrate to cover the cryptographic processor with the layer of metal shielding

Methodology Applied
Scientific EffectSputtering: Sputtering

Data Source

PatentUS11996386B2System-in-package architecture protection against physical and side-channel attacks
Publication Date: 2024.05.28 APPLIED MATERIALS INC
  • US11996386B2 patent drawing
  • US11996386B2 patent drawing
  • US11996386B2 patent drawing

AI summary

To protect against physical and side-channel attacks, circuit assemblies may mount a main processor opposite of a cryptographic processor such that traces between the two processors are hidden in a substrate. Another substrate defining a cavity may be mounted on the bottom of the substrate to enclose the cryptographic processor and prevent physical access without disrupting the cryptographic operations. Voltage converters with integrated inductors may also be included in the cavity to generate electromagnetic noise that will disrupt the sensitive equipment used in side-channel attacks. An electromagnetic shield may be sputtered on top of the main processor to block electromagnetic sniffing attacks while still allowing the processor to be coupled with a heat sink.