This disclosure relates to an integrated circuit device, in particular to protecting such a device from a laser attack.
It is known in the art of integrated circuit devices that an attack on such an integrated circuit device can be carried out using a laser. Radiation from the laser can be used, for example, to switch on a transistor within a circuit of the integrated circuit device to alter the running of the device. Such an attack can be used to circumvent security measures of the device.
Typical integrated circuit devices have a substrate layer of silicon, which is typically 120 to 800 μm thick. Some attackers reduce this thickness by mechanical means, such as polishing, or using a chemical. The chemical may be a liquid such as tetramethylammonium hydroxide TMAH, Potassium Hydroxide KOH, ethylenediamine pyrocatechol EDP, or an acid mix (hydrofluoric, nitric, acetic). Alternatively, the chemical may be a gas such as carbon tetrachloride CCl4. With a reduced thickness of the substrate layer, a laser attack can be made more easily through the remainder of this layer.
Overview
An invention is set out in claim 1. Optional features are set out in the dependent claims.
In an aspect, there is provided an integrated circuit device comprising: a protective layer; and a protected circuit on a substrate. The protective layer is configured to protect the protected circuit by absorbing laser radiation targeted at the protected circuit through the substrate.
In an aspect, there is provided an integrated circuit device having a front surface and a back surface. The device comprises a protected circuit and a protective layer between the protected circuit and the back surface of the device. The protective layer is configured to absorb laser radiation arriving from the back surface of the device, thereby protecting the protected circuit from the laser radiation.
In an aspect, there is provided an integrated circuit device comprising: a protected circuit on a substrate; and detection circuitry configured to detect a change in an electrical property of the device indicative of removal of material from the substrate, and, in response to detecting the change in the electrical property, cause the protected circuit to be disabled.
In an aspect, there is provided an integrated circuit device comprising: a protected circuit on a substrate; and intermediate circuitry protruding into the substrate, the device being configured such that removal of material from the substrate causes physical damage that disables the protected circuit, wherein the physical damage that disables the protected circuit is physical damage to the intermediate circuitry.
In some embodiments, the device is configured such that removal of the protective layer causes physical damage that disables the protected circuit. In some embodiments, the device comprises intermediate circuitry protruding into the substrate between the protective layer and the protected circuit, wherein the physical damage that disables the protected circuit is physical damage to the intermediate circuitry.
In some embodiments, the device comprises detection circuitry configured to detect a change in an electrical property of the device indicative of removal of the protective layer, and, in response to detecting the change in the electrical property, cause the protected circuit to be disabled. In some embodiments, the electrical property is capacitance. In some embodiments, the detection circuitry comprises a DRAM cell or a bipolar transistor. In some embodiments, the detection circuitry comprises intermediate detection circuitry protruding into the substrate layer between the protective layer and the protected circuit.
In some embodiments, the protective layer comprises a doped semiconductor. In some embodiments, the doped semiconductor has a dopant concentration of at least 1019 cm−3, 1020 cm−3, 5×1020 cm−3 or 1021 cm−3. In some embodiments, the protective layer has a transmittance of the laser radiation that is less than or equal to 40%, 20%, 15%, 10%, 5%, or 2%. In some embodiments, the laser radiation is infra-red radiation. In some embodiments, the protective layer is within the substrate. In some embodiments, the protective layer has a transmittance of the laser radiation that is less than a transmittance of the laser radiation of the substrate.
The disclosed device may therefore protect a circuit of the integrated circuit device from a laser attack. The protective layer may provide protection by absorbing a substantial amount of the laser radiation, such that this laser radiation does not reach the circuit. The laser attack is thereby prevented from achieving its purpose of attacking the device by manipulating the operation of the circuit.
The disclosed device may be able to withstand an attack involving tampering of the back side of the device by removing material from the back surface of the device. Before enough material is removed for a laser attack to become possible, the device may disable the circuit to be protected, thereby ensuring that a laser attack cannot succeed.
Specific embodiments illustrating aspects of the disclosure are now described by way of example with reference to the accompanying drawings, in which:
With reference to
It has been identified that laser attacks may be carried out by directing laser radiation at the back surface 6 of the device 2. The laser radiation passes through the substrate and interacts with one or more of the circuits on the substrate (on the far side of the substrate with respect to the path of the laser radiation). Due to the presence of the metal layers between the circuits and the front surface of the device, a laser attack through the front surface 4 of the device 2 is not usually possible, as the metal layers would absorb the laser beam radiation.
A protected circuit 8 is situated inside the integrated circuit device 2 between the front surface 4 and the back surface 6. The region of the integrated circuit device 2 between the protected circuit 8 and the back surface 6 is referred to as the back portion 10. The remaining region of the integrated circuit device 2, including the protected circuit 8 and extending to the front surface 4, is referred to as the front portion 12.
The front portion 12 is structured in the conventional manner for an integrated circuit device 2. The back portion 10 comprises a substrate with which the protected circuit 8 is integrated. The back portion comprises an inner substrate layer 14, an outer substrate layer 16, and a protective layer 18 between the inner substrate layer 14 and the outer substrate layer 16. The protective layer 18 is between the protected circuit 8 and the back surface 6. The inner substrate layer 14 comprises the substrate with which the protected circuit 8 is integrated. In this embodiment, the (bulk) substrate comprises silicon. The outer substrate layer 16 has a similar composition to the inner substrate layer 14.
The protective layer 18 is configured to absorb laser radiation of a predetermined wavelength or wavelength range. In this embodiment, the predetermined wavelength is 1064 nm, corresponding to a standard infra-red diode laser. The wavelength or wavelength range is predetermined by the designer of the integrated circuit device 2 and is based on an anticipated wavelength or wavelength range of a laser attack by an attacker. The protective layer 18 has a transmittance of this laser radiation that is substantially lower than the transmittance of this laser radiation of the outer substrate layer and the inner substrate layer. The protective layer 18 comprises a doped semiconductor. In this embodiment, the protective layer 18 comprises silicon doped with phosphorous (N-type). The silicon is doped at a sufficiently high concentration to absorb a desired percentage of the laser radiation.
An approximated value for the transmission through the substrate is given by the formula: T=(1−R)2eαd, where R is the surface reflectivity, a the absorption coefficient and d the material thickness (in cm). The absorption coefficient α depends on the dopant type and concentration. For N-type doped silicon, with a dopant concentration of 5×1020 cm−3 and a negligible surface reflectivity (R˜0), transmission at 1064 nm is roughly equal to T=e2000d. For a layer thickness of 20 μm, transmission is only 2%. Such a layer absorbs most of the energy from the incident radiation, blocking infra-red imaging and laser fault injection, thereby protecting the protected circuit from an attack. Alternatively, if the dopant concentration of the above example is instead 1020 cm−3 and the other parameters are the same, transmission is 20%. As a further alternative, if the dopant concentration of the above example is instead 1021 cm−3, the layer thickness is instead 5 μm, and the other parameters are the same, transmission is 5%. Other possible layer thicknesses include 10 μm or 15 μm, or any other suitable thickness.
The parameters of the protective layer 18 are configured to ensure that the transmittance of the laser radiation through the protective layer 18 is equal to or less than a desired value. This desired value is, for example, 40%, 20%, 15%, 10%, 5%, or 2%. The parameters of the protective layer 18 available to be configured in order to ensure that the protective layer 18 achieves the desired value of transmittance include (as referred to above): the thickness of the protective layer 18 in a direction perpendicular to the back surface 6, the dopant concentration of the doped semiconductor, and the surface reflectivity of the protective layer 18. The protective layer 18 is opaque to the laser radiation.
The protective layer 18 has a sufficient extent in directions parallel to the back surface 6 to ensure that the protected circuit 8 is protected from laser radiation entering the integrated circuit device 2 through the back surface 6. Such a laser attack may occur at an angle perpendicular to the back surface 6, and also may occur at an angle offset from perpendicular. In this embodiment, the protective layer 18 extends across the full extent of the integrated circuit device 2 in directions parallel to the back surface 6. The extent of the protective layer 18 in directions parallel to the back surface 6 corresponds to the extent of the inner substrate layer 14 and the outer substrate layer 16 in the directions parallel to the back surface 6.
The heavily doped protective layer 18 therefore acts as a shield or a screen for the protected circuit 8, protecting the protected circuit 8 from incoming laser radiation arriving from the back surface 6 of the integrated circuit device 2.
With reference to
With reference to
The detection circuitry 22 is in the same layer of the integrated circuit device 21 as the protected circuit 8. The intermediate circuitry 24 is in the inner substrate layer 14. The intermediate circuitry 24 is between the detection circuitry 22 and the protective layer 18, and between the protected circuit 8 and the protective layer 18. The intermediate circuitry 24 is situated in trenches within the inner substrate layer 14. In this embodiment, the intermediate circuitry 24 comprises a plurality of DRAM cells (three are shown in
If an attacker removes material from the back portion 10 of the integrated circuit device 21 (for example, by polishing the back surface 6 of the integrated circuit device 21), this will affect the capacitance detected by the detection circuitry 22. Removal of the protective layer 18 by an attacker brings about such a change in capacitance. The removal of further material from the inner substrate layer 14 causes part of the intermediate circuitry 24 to be removed, due to the proximity of the intermediate circuitry 24 to the protective layer 18. The removal of part of the intermediate circuitry 24 causes the detected capacitance to change.
In response to detecting the change in the capacitance, the detection circuitry 22 sends a signal that causes the protected circuit 8 to be disabled. The protected circuit 8 is disabled by having its memory erased. This ensures that, if enough material is removed from the back side of the integrated circuit device 21 for a laser attack on the protected circuit 8 to become feasible, the protected circuit 8 will have already been disabled as a result of the removal of the material, before a laser attack can take place.
With reference to
An STI (Shallow Trench Isolation) 34 is also provided in the inner substrate layer. The STI 34 is a trench etched in the silicon bulk and filled with oxide. The STI 34 is configured to insulate parts with different electrical domains from each other. The STI 34 is configured to prevent current from flowing from the emitter to an adjacent circuit.
The change in functioning of the bipolar transistor caused by the removal of material from the back side of the integrated circuit device 26 is detected by the detection circuitry 22 due to the connection between the detection circuitry 22 and the collector 30 of the bipolar transistor. The detected change in functioning of the bipolar transistor may be that the bipolar transistor is no longer properly conducting. In response to the detected change in functioning, the detection circuitry 22 proceeds in the same manner as described above for the third embodiment (described with respect to
Construction of the integrated circuit device 2, 19, 21, 26 involves standard manufacturing techniques known in the art. Before construction, parameters including those referred to above are determined such that the integrated circuit device 2, 19, 21, 26 will achieve functionality desired by the designer of the device. For example, the wavelength or wavelength range of the laser anticipated to carry out the attack is determined, and the concentration of the doped silicon is set at a sufficiently high concentration to absorb at least the desired percentage of the laser radiation.
It will be understood that the above description of specific embodiments is by way of example only and is not intended to limit the scope of the present disclosure. Many modifications of the described embodiments, some of which are now described, are envisaged and intended to be within the scope of the present disclosure.
In some embodiments, the integrated circuit device is configured in a manner similar to the third and fourth embodiments (described above with respect to
In some embodiments, the detection circuitry is not present. Instead, the intermediate circuitry is integrally linked with, or is part of, the protected circuit, such that physical damage to the intermediate circuitry inherently causes the protected circuit no longer to function due, for example, to a connection being broken. The physical damage may be removal or attempted removal of the intermediate circuitry.
In some embodiments, the protected circuit is disabled in other manners than that described above. In some embodiments similar to the fourth embodiment (described with respect to
In some embodiments, the protective layer does not extend in directions parallel to the back surface as far as other parts of the back portion (such as the inner substrate layer).
In some embodiments, the integrated circuit device is a bipolar junction device. In some embodiments, the integrated circuit device is a chip, microchip, integrated circuit, or other similar device. In some embodiments, the integrated circuit device (or corresponding device) forms part of a smart card.
In some embodiments, the outer substrate layer is made of a different material from the inner substrate layer, or is instead an outer layer made of a material other than a substrate, or is not present.
In some embodiments, the intermediate circuitry extends up to a front edge of the protective layer. In some embodiments, the intermediate circuitry extends at least partially into the protective layer. In some embodiments, the intermediate circuitry is at least partially situated proximal to an edge of the integrated circuit device. In some embodiments, the intermediate circuitry is situated in a plurality of locations of the inner substrate layer.
In some embodiments, the electrical property detected by the detection circuitry is a property other than capacitance, for example a measured current between two structures (equivalent to resistance). Another example is a measured logic state (e.g. an undamaged device corresponds to a 1, while a damaged device corresponds to a 0, thus changing the global reading value of a chain of devices).
In some embodiments, the integrated circuit device comprises a light detector in communication with the detection circuitry. In response to a detection of light by the light detector, the detection circuitry proceeds as set out above regarding the third embodiment (described with respect to
In some embodiments, the protective layer is a doped layer that has a dopant concentration of at least 1019 cm−3, 1020 cm−3, 5×1020 cm−3, or 1021 cm−3.
Having read the above description of specific embodiments and the preceding overview of aspects of the present disclosure, the skilled person will readily be aware that many modifications, juxtapositions, alterations and combinations of the features described above are possible and are covered by the scope defined by the claims that follow.
Number | Date | Country | Kind |
---|---|---|---|
1607589 | Apr 2016 | GB | national |
Filing Document | Filing Date | Country | Kind |
---|---|---|---|
PCT/EP2017/060139 | 4/27/2017 | WO |
Publishing Document | Publishing Date | Country | Kind |
---|---|---|---|
WO2017/186887 | 11/2/2017 | WO | A |
Number | Name | Date | Kind |
---|---|---|---|
4534804 | Cade | Aug 1985 | A |
4862240 | Watanabe | Aug 1989 | A |
5154946 | Zdebel | Oct 1992 | A |
7847581 | Lisart | Dec 2010 | B2 |
7999358 | Bakalski | Aug 2011 | B2 |
8513782 | Bakalski | Aug 2013 | B2 |
9070697 | Marinet | Jun 2015 | B2 |
9659877 | Bakalski | May 2017 | B2 |
20020086472 | Roberds | Jul 2002 | A1 |
20020130248 | Bretschneider | Sep 2002 | A1 |
20060081912 | Wagner | Apr 2006 | A1 |
20090251168 | Lisart | Oct 2009 | A1 |
20100187525 | Bartley et al. | Jul 2010 | A1 |
20100315108 | Fornara | Dec 2010 | A1 |
20100318885 | Lisart | Dec 2010 | A1 |
20110234307 | Marinet | Sep 2011 | A1 |
20120320477 | Lisart et al. | Dec 2012 | A1 |
20120320480 | Lisart | Dec 2012 | A1 |
20130075726 | Fornara | Mar 2013 | A1 |
20130100559 | Kuenemund | Apr 2013 | A1 |
20130181254 | Iwasaki | Jul 2013 | A1 |
20130231870 | Sugnet | Sep 2013 | A1 |
20140111230 | Lisart | Apr 2014 | A1 |
20150108606 | Lamy et al. | Apr 2015 | A1 |
20150364433 | Hindman | Dec 2015 | A1 |
20160042199 | Joharapurkar et al. | Feb 2016 | A1 |
20160072621 | Oshida | Mar 2016 | A1 |
20160307855 | Charbonnier | Oct 2016 | A1 |
20170278839 | Lai | Sep 2017 | A1 |
20170301635 | Sarafianos | Oct 2017 | A1 |
20180233460 | Lisart | Aug 2018 | A1 |
20190148313 | Jullian | May 2019 | A1 |
Number | Date | Country |
---|---|---|
103 37 256 | Jun 2004 | DE |
Entry |
---|
International Search Report and Written Opinion dated Jul. 21, 2017, in PCT/EP2017/060139 filed Apr. 27, 2017. |
Singapore Written Opinion dated Nov. 5, 2019, in Application No. 11201808897U, 7 pages. |
European Office Action dated Apr. 23, 2020 in European Patent Application No. 17721594.4, 6 pages. |
Invitation to Respond to Written Opinion dated Oct. 1, 2020 in Singapore Patent Application No. 11201808897U. |
Written Opinion dated Sep. 24, 2020 in Singapore Patent Application No. 11201808897U. |
Written Opinion dated Oct. 8, 2021 in Singaporean Patent Application No. 11201808897 U, 6 pages. |
Office Action dated Jun. 22, 2022 in Chinese Application No. 201780039918.9 (with partial English Translation). |
Chinese Office Action dated Dec. 8, 2021 in Chinese Application No. 201780039918.9 (with Computer Generated English Translation). |
Preliminary Examination Report dated Jun. 14, 2022 in Brazilian Patent Application No. 112018071175-6, 4 pages. |
Number | Date | Country | |
---|---|---|---|
20190148313 A1 | May 2019 | US |