Data breaches become a bigger problem for chip makers

AI and ML Jobs


As chips become increasingly complex and heterogeneous, storing more data and chip makers exploiting it for other designs, data leaks are becoming harder to stop or even track down.

Unlike cyberattacks, which are usually done for a specific purpose, such as collecting personal data or holding a ransom on your system, data breaches can happen anywhere. And as the value of your data grows, it can become costly as well. However, the causes are varied, unpredictable, and often unintentional, making them much more difficult to identify and stop. They include:

  • Manufacturing defects and circuit aging — electromigration, time-dependent dielectric breakdown, and thermal-related damage, among others — can provide openings like side-channel attacks without actually hacking the chip. . It can also give attackers easy access to sensitive data.
  • A knowledge repository for designing chips intended to keep learning in-house, but also makes tracking proprietary third-party IP difficult.
  • Talent shortages continue at all levels from design to manufacturing. This often means that in-depth skills and competitive knowledge developed at one company are transferred to employees for jobs at new companies.

physical cause
From a hardware perspective, leaks can be a function of chip or package complexity, or they can be due to design or manufacturing flaws. This could allow someone to extract data without touching the chip.

Raj Jammy, Principal Engineer at MITER Engenuity and Executive Director of the Semiconductor Alliance, said: “Combining multiple chips increases your vulnerability. So you have to think about this in a completely different way. You also have to worry about what happens at the package level when you put it all together on the board, sometimes called leakage, but this is probably one of the weak spots where you can sense the timing of a particular chip. Once you know, once you start reading what’s being sent, you can predict what bits are going through the chain, it could be a leak, but this is non-invasive and more like interception. In the area of ​​, aging can weaken the connection and may not even allow the chip to operate properly.A greater risk is if there is a spurious signal that you are sending to a neighboring chip or chiplet in the package. .”

Much of this is exacerbated by heterogeneous designs where different tips, chiplets or materials may have different life expectancies. Unlike in the past when everything was developed on the same process node and became an integrated processor or SoC by one company, these components are now distributed and acquired from global supply chains. Various process elements, memory, and other components are developed using different manufacturing processes, possibly by different foundries. This makes it more difficult to fuse these components together and can create weak spots that can be exploited without actually touching the device. No, but you may not need to. Depending on what data is being leaked and where it is leaking from, it can still be very valuable data.

Peter Laakman, Distinguished Engineer in Infineon’s Connected Secure Systems Division, said: “For example, there was an attack that had a very good security chip inside that was certified, but it was also in the same package as a standard microcontroller. After several attacks on the microcontroller, we get the key, which means that the security controller cannot protect the whole system, the same goes for any kind of chiplet or multi The same is true for chip packages.”

Laackmann said that for security chips/chiplets this is unlikely to be a problem as these chips are not typically stressed like processing elements. However, other components may behave differently in their circuits as they age, and those differences can be used to gather important data. “Some chips have pins that are used to supply internal core voltages. Accessing them gives access to internal core voltages that are normally smoothed out by external capacitors. Disable these capacitors. You can make a great side channel analyzer, these chips aren’t ready for it, and you can add glitches or spikes to the chip’s internal core voltages to jump over instructions or pins or password inputs You can do something wrong.”

Chiplets add their own problems. Pim Tuyls, his CEO of Intrinsic-ID, said: “But on top of that, we have to make sure that the communication channels between all these different chiplets are also secure. That’s a challenge in itself.”

AI/ML and IP reuse
When a lot of data leaks out of your system, you usually notice it. This may prompt security patches or large chip/package/system replacements. “If you have 800 Gbps of Ethernet traffic, you have a lot of data going through.

In contrast, data breaches tend to be much more subtle and hard to spot, often unintentionally. It is almost impossible to trace, let alone establish protection.

Quadric CMO Steve Roddy said: “You use them to build other IP. Where is the end of one and the beginning of another? You scrape previous designs to find efficient patterns and apply them to the next design. They take insight from RTL structures and say, “This kind of structure needs to be laid out in a certain way.” It doesn’t actually copy anything. But the input was someone’s RTL, so I’m comparing it to other similar ones. And you base it on someone else’s IP. The mask set is also someone else’s IP. Could AI use customer design data to drive its training set, and if so, who owns that customer data?”

Tracking IP as it moves through the design is another challenge. Cliosoft’s vice president of marketing, Simon Rance, said: “Then we optimize for the new release and the next version of the chiplet or other IP and bring in all the real-time data. We are supposed to split it up based on what parts are owned by who, it can come from different regions around the world, so some of the IP is owned by that region and some is owned by one. Divisions are owned by the customer, so you’ll have to look at the metadata to identify the players involved in the project for that IP, often there’s no clear answer, there’s no criteria, and this To really address , we need full traceability of who saw it, but that’s highly unlikely to happen.”

As such, it’s imperative that companies protect their IP much more diligently than ever before. Expedera’s vice president of marketing, Paul Karazuba, said: “IP licenses give us the right to understand what we do. has obtained all possible patents to protect itself.There are still state secrets that we do not want to reveal about our company.”

With more collaboration in the marketplace, this becomes more difficult to secure. This is complicated by the increasing prominence of generative AI. Arteris IP’s Vice President of Marketing, Frank Schirrmeister, said: “AI is a solution to drive optimization, and when it’s a big customer, they want their own spin. We are customizing the data for our own use, which adds all sorts of new copyright and IP issues.”

human factor
Data has been leaked from chip companies since the first semiconductor was developed. When people change jobs or change companies, they bring with them the knowledge they learned at their previous jobs. According to LexMachina, between 2012 and 2021 he had just over 46,000 patent lawsuits filed in the United States. The annual average he is 4,600 cases.

The situation is very different internationally. Many of the ongoing disputes between the United States, China and Russia involve intellectual property or patent infringement. According to The Law Reviews, the number of patent infringement lawsuits filed in China in 2021 has increased from about 5,800 in 2010 to about 32,000.

A 2022 report issued by the Office of the U.S. Trade Representative identified gaps in trade secret protection and enforcement, particularly in China and Russia. “Theft can occur in a variety of situations, including departing employees taking portable storage devices containing trade secrets, failed joint ventures, cyber intrusions and hacks, This includes the misuse of information submitted to government agencies for the purpose of complying with regulatory obligations,” the report said.

Given the complexity of the devices under development, often restricted employee access, and the rapid pace of improvement, this generally falls under the heading of data breaches. However, the volume of leaks and the value of leaked data has risen to the point where governments seek agreements or impose sanctions. Also, the chip industry, where he was once confined to one company or limited set of suppliers, is now fragmented into various parts spread all over the world.

Nonetheless, the demand for talent is very high, and the demand for engineers with prior expertise is very high. The challenge is to create an architecture for engineers so that projects are divided into teams that don’t see the big picture. Industry sources say some companies are already doing this with design teams located in different countries. While this is cumbersome to manage, it also limits the value of the leaked data.

future
Going forward, chip makers and IP developers will have to do more to maintain a divide-and-conquer strategy for their employees and monitor the flow of data whenever possible.

“There are no foolproofs in security,” said Paliwal of Rambus. “We don’t buy security to make it foolproof, we buy it to make it difficult. Measurable security is becoming very important. That’s why, both proteanTecs and Synopsys are heavily involved in this, and now we’re starting to put structure into the IP that helps with measurability, and the hardware needs very smart sensors. Yes, we can know when something has changed or where secrets are stored and where there is a potential data leak.”

The more difficult part is tracking data that travels through chip companies that are used to produce other designs that may or may not know the source of that IP. This is especially difficult with machine learning, which can store optimized data for future use, and generative AI, which the tech world is just beginning to tackle. Ultimately, codes of conduct and laws will be enacted, but data will continue to move freely across borders with vastly different levels of protection.

Data leaks cannot be completely prevented, but they can be better limited and controlled. Still, the industry as a whole needs to work together, and at this time it’s not clear who will lead the effort or when it will happen.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *