Systems and methods for providing dynamic security fabric interposers in heterogeneously integrated systems
View Patent ↗A system may include an integrated circuit (IC) package. The IC package may include one or more IC die hosting one or more circuits, and an interposer. The interposer may be coupled to the one or more IC die via an interconnection layer. The interposer may include one or more electrically active devices configured to provide one or more security functions to secure the one or more circuits. The interposer may be coupled to a backside power of the IC package. In some embodiments, the backside power of the IC package may include one or more backside power delivery networks.
1 . A system comprising an integrated circuit (IC) package, the IC package comprising:
one or more IC die hosting one or more circuits; and
an interposer coupled to the one or more IC die via an interconnection layer, the interposer comprising one or more electrically active devices configured to provide one or more security functions to secure the one or more circuits,
wherein the interposer is coupled to a backside power of the IC package,
the one or more IC die include a first IC die and a second IC die wherein the one or more electrically active devices are configured to provide a first connection structure with which the first IC die is connected to the second IC through the interposer, and
in response to the first IC die being replaced with a third IC die, the one or more electrically active devices are configured to provide a second connection structure with which the third IC die is connected to the second IC through the interposer.
2 . The system according to claim 1 , comprising:
a passive layer coupled to a first surface of the one or more IC die and including one or more passive components configured to secure the one or more circuits,
wherein the interposer is coupled to a second surface of the one or more IC die opposite to the first surface.
3 . The system according to claim 1 , wherein
the one or more IC die include a first IC die hosting a first circuit and a second IC die hosting a second circuit, and
one or more electrically active devices are configured to secure the first circuit and the second circuit.
4 . The system according to claim 1 , wherein the one or more electrically active devices are configured to obfuscate the one or more circuits.
5 . The system according to claim 1 , wherein the one or more security functions include at least one of (1) controlling one or more intrusion sensors integrated into the interposer, (2) managing one or more on-board encryption symmetric keys, (3) managing an identifier (ID) and/or key unique to an individual IC, (4) managing an interrogation history stored on a secure server, (5) controlling a built-in friable structure that can destroy a die in response to an attempt of removing the structure, and/or (6) root of trust.
6 . The system according to claim 1 , wherein the backside power of the IC package includes one or more backside power delivery networks.
7 . An interposer of an integrated circuit (IC) package that includes one or more IC die hosting one or more circuits, the interposer comprising:
one or more electrically active devices configured to provide one or more security functions to secure the one or more circuits, wherein
the interposer is coupled to a backside power of the IC package, and
the interposer is coupled to the one or more IC die via an interconnection layer,
wherein the one or more IC die include a first IC die and a second IC die wherein the one or more electrically active devices are configured to provide a first connection structure with which the first IC die is connected to the second IC through the interposer, and
in response to the first IC die being replaced with a third IC die, the one or more electrically active devices are configured to provide a second connection structure with which the third IC die is connected to the second IC through the interposer.
8 . The interposer according to claim 7 , wherein
the IC package comprises a passive layer coupled to a first surface of the one or more IC die and including one or more passive components configured to secure the one or more circuits,
wherein the interposer is coupled to a second surface of the one or more IC die opposite to the first surface.
9 . The interposer according to claim 7 , wherein
the one or more IC die include a first IC die hosting a first circuit and a second IC die hosting a second circuit, and
the one or more electrically active devices are configured to secure the first circuit and the second circuit.
10 . The interposer according to claim 7 , wherein the one or more electrically active devices are configured to obfuscate the one or more circuits.
11 . The interposer according to claim 7 , wherein the one or more security functions include at least one of (1) controlling one or more intrusion sensors integrated into the interposer, (2) managing one or more on-board encryption symmetric keys, (3) managing an identifier (ID) and/or key unique to an individual IC, (4) managing an interrogation history stored on a secure server, (5) controlling a built-in friable structure that can destroy a die in response to an attempt of removing the structure, and/or (6) root of trust.
12 . The interposer according to claim 7 , wherein the backside power of the IC package includes one or more backside power delivery networks.
13 . A method comprising:
mounting, on an interconnection layer, one or more integrated circuit (IC) die hosting one or more circuits
forming an interposer to include one or more electrically active devices,
coupling the interposer to the one or more IC die via the interconnection layer, the interposer configured to provide one or more security functions to secure the one or more circuits; and
coupling a backside of the interposer to one or more backside power delivery networks,
wherein the one or more IC die include a first IC die and a second IC die, and the method comprises:
configuring the one or more electrically active devices to provide a first connection structure with which the first IC die is connected to the second IC through the interposer, and
in response to the first IC die being replaced with a third IC die, configuring the one or more electrically active devices to provide a second connection structure with which the third IC die is connected to the second IC through the interposer.
14 . The method according to claim 13 , comprising:
forming a passive layer to be coupled to a first surface of the one or more IC die and to include one or more passive components configured to secure the one or more circuits,
wherein the interposer is coupled to a second surface of the one or more IC die opposite to the first surface.
15 . The method according to claim 13 , wherein
the one or more IC die include a first IC die hosting a first circuit and a second IC die hosting a second circuit, and
the method comprises configuring the one or more electrically active devices to secure the first circuit and the second circuit.
16 . The method according to claim 13 , wherein the one or more security functions include at least one of (1) controlling one or more intrusion sensors integrated into the interposer, (2) managing one or more on-board encryption symmetric keys, (3) managing an identifier (ID) and/or key unique to an individual IC, (4) managing an interrogation history stored on a secure server, (5) controlling a built-in friable structure that can destroy a die in response to an attempt of removing the structure, and/or (6) root of trust.