A structure for protection of security-sensitive ICs against attacks through silicon backside

Elham Amini · DepositOnce · 2021

Security sensitive integrated circuits (ICs) are subject to hardware attacks on secure data. In the past few years, optical signal tracking methods accessing the IC through the chip backside have become the most successful attack risks. Modern ICs are equipped with various hardware and software countermeasures to protect secret data and intellectual property (IP) against known attacks. These countermeasures include protective mesh layers, different sensors, shields, and physically unclonable functions (PUFs). However, the chip backside is still exposed, and proper and affordable protection of the IC backside against focused ion beam (FIB) and optical attacks is missing. Accordingly, the available countermeasures can be circumvented by attacks through the silicon back surface. This work presents, realizes and develops an efficient and cost-effective structure to protect ICs against hardware attacks through the chip backside. Since there is no cost-efficient way to connect the backside to the frontside electrically, a proper protection structure for the backside must be based on optics. The structure presented here is an optically active thin film that is deposited on the IC back surface. The integrity of the layer is checked by an optical signal generated and detected inside the chip using IC elements. The protective layer is opaque to the infrared light and provides an angle-dependent reflectivity. Thus, the laser light cannot penetrate the IC, and the photon emission of the IC structure cannot leave the IC through the silicon backside. In the developed protection method, the IC structures are administrated as a light-emitting device and light-sensing devices. A p-n junction is forward-biased to emit an optical signal in all directions toward the IC backside. The light reflected from the IC backside is absorbed by several reverse-biased p-n junctions (drain or source of the transistors), creating a photocurrent. The layer changes the intensity of the reflected light depending on the angle of incidence of the light. Therefore, the photocurrent of the detectors is a signature of the layer. If the layer is damaged or removed, the signal of the detectors will change. Then, the device will not be able to confirm the integrity of the layer. Subsequently, the secret data stored on the device will be destroyed. In order to achieve an efficient protection structure, parameters including optical signals, the light emitter, detectors, the protection layer, and the position of the structures are optimized together. In this work, two optically active thin films that are qualified for this purpose are designed and produced by the sputtering method. The layers are characterized by ellipsometry and the Automated reflectance/transmittance analyzer (ARTA). The concept of the protection mechanism is evaluated by electrical measurements on the IC structure. The photocurrent of the detectors is analyzed when the layer is deposited on the IC backside and when the layer is removed. The results have confirmed the effect of the layer on the photocurrent of the detectors. Hence, any harms to the layer can be detected by electrical measurements on the IC circuit. This work also discusses the advantages and drawbacks of the protection mechanism, and possibilities for its application are examined. These investigations lead to the conclusion that the protection structure, after optimization of the critical parameters, becomes a comprehensive countermeasure. It would be a very low-cost process and capable of preventing both physical and optical attacks through the chip back surface. This protection structure can be used for all types of security-sensitive ICs with different size, technology, and bulk thickness.

Read the paper · More papers on PaperTik