Security Issues in the Supply Chain Helena Handschuh 08/28/2018
Semiconductor Manufacturing Challenges Lack of Trust in High Cost of Supply Chain Multiple SKUs • Untrusted production environments Challenges • Overbuilding/overproduction • Multiple SKUs/single die increase production • Reverse engineering/cloning/IP and testing costs Theft • Forecasting and production forecasting is • Grey market chips/ knock offs uncertain • Limited production visibility • Feature settings irreversible • Costly audits • Lost revenue • Overbuild: inventory spoilage • Liability Impact • Underbuild: missed market opportunities and • Safety issues perishable demand • ASP Erosion • Complex and costly supply chain logistics • Company / Product reputation • Costly inventory management • Additional support burden 2
Requirements/solutions for better supply chain security • Secure device configuration • On-chip access control and rights management • Identity assurance and traceability • How does this • Attestation (what about anonymity?) • Certificates and revocation, TTPs, CRLs? work for Secure • Secure distributed key management and KMS • Secure Personalization and key injection/on-board key gen Enclaves? • Chicken and egg problem? • Secure facilities; Tester security? • Multiple stage device lifecycle management • Secure Part #/inventory management • Secure Debug and RMA • Secure Audit/logs/data management 3
Recommend
More recommend