IP Library Granted Patent US 12699812
Granted Patent B2
US 12699812 · App. 18/437,782 · Granted Aug 4, 2026

Continuous impairment of a chip upon detecting a damaged package

Inventors: Samir Valjibhai Rajgor (Santa Clara, CA); Sachin Agarwal (Fremont, CA); Srirajkumar Sundararaman (San Jose, CA); Chirag Shroff (Cary, NC)
Assignee: Cisco Technology, Inc.
G06F21/755G06F21/72G06F21/86G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12699812
App. No.
18/437,782
Granted
Aug 4, 2026
Kind
B2
Abstract

A method for monitoring an Integrated Circuit (IC). The method includes decrypting, by the Root-Of-Trust (ROT) module, an identity package that resides in a non-volatile memory of the IC using a secret accessible by the ROT module. The identity package is configured in a decrypted state at the non-volatile memory by use of the secret. The ROT module is configured to discover, based on monitoring data from a sensor that an attack is at least being attempted on a package of the IC. The ROT determines whether a debug package is present in response to the attack. If the debug package is not present, the ROT module is configured to execute a tamper resistance process to prevent the use of the secret by the ROT module and the identity package from being placed or remaining in a decrypted state in the non-volatile memory of the IC.

Claims (51)

1 . A method for monitoring an Integrated Circuit (IC), comprising:

decrypting, by a Root-Of-Trust (ROT) module, an identity package that resides at a non-volatile memory of the IC using a secret accessed by the ROT module, wherein the identity package includes identification data usable by the ROT module to determine that the IC is compliant for operating;

discovering, by the ROT module, based on monitoring data from at least one sensor operably coupled to the ROT module that an attack is at least being attempted on a package of the IC;

determining, by the ROT module, whether a debug package is present in response to the attack; and

in response to a determination that the debug package is not present, executing by the ROT module, a tamper resistance process as an active response to the attack to prevent using of the secret by the ROT module and the identity package from being placed or remaining in a decrypted state in the non-volatile memory of the IC,

wherein the tamper resistance process includes:

causing the identity package to transition from the decrypted state to an encrypted state by encrypting the identity package; and

at least one of overwriting, changing, or reordering one or more bits of the secret to generate a modified secret that is unable to decrypt the identity package resulting in an inability to verify that the IC is compliant for operating.

2 . The method of claim 1 , wherein the secret comprises a secret key used to decrypt the identity package.

3 . The method of claim 2 , further comprising determining by the ROT module, whether an attack is being attempted on the IC during at least one of a powering on of the IC or ongoing operations of the IC.

4 . The method of claim 2 , wherein the secret key comprises at least one built-in key accessible by the ROT module comprising an electrically programmable fuse (eFuse) configured during manufacturing of the IC.

5 . The method of claim 3 , further comprising:

determining by the ROT module, from data from the at least one sensor that is configured to monitor at least one of damage or an intrusion to a package in which the IC is disposed, whether an attack on the IC is being attempted during at least powering on of the IC.

6 . The method of claim 5 , wherein the tamper resistance process further comprising:

executing a script by the ROT module to at least one of overwrite, change, or reorder the one or more bits of the secret key to prevent the ROT module from decrypting the identity package in the non-volatile memory.

7 . The method of claim 6 , wherein the tamper resistance process comprises an active process that is initiated upon discovery of at least one of the damage or an intrusion to the package.

8 . The method of claim 7 , wherein the attack comprises a glitching type attack during at least a powering on of the IC.

9 . The method of claim 8 , wherein the tamper resistance process further comprising:

executing a script by the ROT module to at least one of overwrite, change, or reorder the one or more bits of the secret key causing the identity package to be in a non-decrypted state in the non-volatile memory.

10 . The method of claim 8 , wherein the tamper resistance process further comprising:

executing a script by the ROT module to at least erase one or more bits of the secret key to prevent the ROT module from being able to decrypt the identity package at the non-volatile memory.

11 . The method of claim 1 , wherein the monitoring data of the IC comprises a continuous monitoring of the package of the IC by at least one sensor.

12 . The method of claim 1 , wherein the IC comprises at least one of a System-On-a-Chip (SOC) or an Application-Specific Integrated Circuit (ASIC).

13 . The method of claim 1 , wherein the tamper resistance process includes overwriting one or more bits of the secret from a first binary value to a second binary value, wherein the secret comprises an electrically programmable fuse (eFuse).

14 . The method of claim 1 , wherein the identity package includes a certificate comprising a unique identifier (UID) of the IC and a signature containing properties unique to the IC.

15 . The method of claim 1 , wherein the tamper resistance process operates independently such that the secret is rendered inaccessible even if the ROT module exits out of its processing steps during the attack.

16 . A non-transitory computer-readable medium comprising an isolated Root of Trust (ROT) code storing instructions that, when executed by a processor, cause the processor to:

determine whether an attack is being attempted on an Integrated Circuit (IC) during at least a powering on of the IC;

decrypt an identity package that resides at a non-volatile memory of the IC using a secret accessed by the processor, wherein the identity package is configured in a decrypted state by use of the secret at the non-volatile memory;

discover, based on monitoring data from at least one sensor operably coupled to the processor, that the attack is being attempted on a package of the IC;

determine whether a debug package is present; and

in response to a determination that the debug package is not present, execute a tamper resistance process as an active response to the attack to prevent using of the secret and the identity package from being in the decrypted state in the non-volatile memory of the IC,

wherein the tamper resistance process includes:

causing the identity package to transition from the decrypted state to an encrypted state by encrypting the identity package; and

at least one of overwriting, changing, or reordering one or more bits of the secret to generate a modified secret that is unable to decrypt the identity package resulting in an inability to verify that the IC is compliant for operating.

17 . The non-transitory computer-readable medium of claim 16 , wherein the processor is configured to determine whether an attack is being attempted on the IC during at least one of a powering on of the IC or ongoing operations of the IC.

18 . The non-transitory computer-readable medium of claim 17 , wherein the processor is configured to determine from data from the at least one sensor that is configured to monitor at least one of damage or an intrusion to a package in which the IC is disposed, whether an attack on the IC is being attempted during at least powering on of the IC.

19 . The non-transitory computer-readable medium of claim 18 , wherein the secret comprises a secret key, the processor is configured to execute a script to at least one of overwrite, change, or reorder the one or more bits of the secret key to prevent the processor from decrypting the identity package in the non-volatile memory.

20 . The non-transitory computer-readable medium of claim 19 , wherein the tamper resistance process comprises an active process that is initiated upon discovery of at least one of the damage or an intrusion to the package, and wherein the attack comprises a glitching type attack during at least a powering on of the IC.

21 . The non-transitory computer-readable medium of claim 20 , wherein the processor is configured to modify one or more bits of the secret key to render the secret unusable causing the identity package to be in a non-decrypted state in the non-volatile memory.

22 . The non-transitory computer-readable medium of claim 21 , wherein the IC comprises at least one of a System-On-a-Chip (SOC) or an Application-Specific Integrated Circuit (ASIC).

23 . A computing device comprising:

a processor; and

a non-transitory computer-readable media storing instructions comprising Root-Of-Trust (ROT) code that, when executed by the processor, causes the processor to perform features comprising:

decrypting an identity package that resides at a non-volatile memory of an Integrated Circuit (IC) using a secret accessible by the processor, wherein the identity package includes identification data usable by the ROT code to determine that the IC is compliant for operating;

discovering, based on monitoring data from at least one sensor operably coupled to the processor, that an attack is at least being attempted on a package of the IC;

determining using a secure channel whether a debug package is present in response to the attack; and

in response to a determination that the debug package is not present, executing a tamper resistance process as an active response to the attack to prevent using of the secret and the identity package from being placed or remaining in a decrypted state in the non-volatile memory of the IC,

wherein the tamper resistance process includes:

causing the identity package to transition from the decrypted state to an encrypted state by encrypting the identity package; and

at least one of overwriting, changing, or reordering one or more bits of the secret to generate a modified secret that is unable to decrypt the identity package resulting in an inability to verify that the IC is compliant for operating.