CHIP DESIGN · COURSE

SoC Integration & Hardware Security

Integrate a system-on-chip by tracing ownership and evidence across every boundary. Freeze IP manifests, parameters, generated maps, interfaces, and registers; derive routing, arbitration, ordering, flow control, and deadlock invariants; integrate interrupts, DMA, IOMMU translation, caches, and coherent agents; preserve transaction identity across clock, reset, voltage, and power domains; enforce privilege, firewall, range, lifecycle, denial, audit, and recovery policy; define roots of trust, key purpose and zeroization, entropy/DRBG readiness, debug/test access; authenticate and measure boot components; make update, rollback, and recovery power-fail safe; and close the system with independent scoreboards, nonvacuous security properties, fault mutations, and software-visible reconstruction.

Before this course: Completed Computer Architecture & Microarchitecture, RTL Design with SystemVerilog, and Functional Verification. The course assumes ISA-visible state and exceptions, pipelines/caches/virtual memory, synthesizable RTL and valid-ready protocols, CDC/RDC boundaries, assertions, scoreboards, coverage, formal proof bounds, replay, and mutation testing. Interconnect details, DMA/IOMMU, coherence integration, power intent, access control, roots of trust, keys, randomness, secure/measured boot, update, recovery, and threat modeling are introduced locally. No operating-system kernel, cryptography implementation, vendor bus license, commercial formal tool, firmware build, FPGA, PDK, or security laboratory is assumed.

COURSE FACTSStage, chapters, units, prerequisite, and outcome
Chapter 1

An integration manifest binds versions, parameters, generators, and views

Objective: Which requester, resource, permission, ordering rule, lifecycle state, evidence, and unsupported threat define “An integration manifest binds versions, parameters, generators, and views”?

A system cannot be reproduced from IP names alone; parameter values, wrapper revisions, generated RTL, interface variants, register descriptions, constraints, and firmware headers must share one identity. SoC integration joins processors, accelerators, memories, interconnects, peripherals, clocks, resets, power domains, privilege controls, and software-visible contracts into one stateful system. Every claim follows one named transaction or lifecycle event from requester identity through address decode, permission, ordering, transport, target side effects, response, interrupt or error reporting, and retirement. Before trusting a subsystem diagram, freeze IP versions, interface parameters, address maps, clock/reset/power ownership, privilege states, and the evidence layer.

The local integration or security contract is “The manifest hashes source and generated artifacts, records generator/tool versions and commands, parameter schema/values, dependencies, interface/register/address outputs, owners, warnings, and clean rebuild procedure.” Its invariant is “One manifest rebuild produces matching RTL, maps, software headers, verification models, documentation, and constraints before integration evidence is accepted.” Use a small cycle-accurate example before automation: label every request, source, destination, byte lane, privilege, domain, epoch, and response; predict backpressure and failure ownership; then compare RTL assertions, scoreboards, formal bounds, software-visible traces, and implementation reports. The boundary “Mixing an old firmware header with new RTL can write a different register while both compile successfully.” stays explicit because functional simulation, protocol proof, security analysis, physical implementation, firmware policy, manufacturing state, and deployed protection are distinct evidence layers.

One manifest rebuild produces matching RTL, maps, software headers, verification models, documentation, and constraints before integration evidence is accepted. The invariant is limited to the named RTL/netlist, parameters, memory map, firmware model, interconnect and security configuration, modes, clocks, resets, power states, lifecycle state, assumptions, and proof or simulation bounds. It is not automatically a claim about synthesized timing, side-channel resistance, cryptographic strength, foundry behavior, deployed firmware, or field security.

Inventory every IP source, wrapper, generated artifact, and external contract. At derivation step 1, retain cycle/edge, request and response identity, address/data/mask, privilege and domain, queue occupancy, accepted side effect, error/interrupt state, and the exact invariant or checker.

Freeze parameters and rebuild into an empty owned output directory. At derivation step 2, retain cycle/edge, request and response identity, address/data/mask, privilege and domain, queue occupancy, accepted side effect, error/interrupt state, and the exact invariant or checker.

Compare hashes and cross-check widths, addresses, interrupts, clocks, resets, and register fields. At derivation step 3, retain cycle/edge, request and response identity, address/data/mask, privilege and domain, queue occupancy, accepted side effect, error/interrupt state, and the exact invariant or checker.

RTL map hash is A and software header says hash B. Is the handoff coherent? Before revealing the trace, predict owner, route, permission, ordering, backpressure, side effect, response, interrupt/error, and one security or physical conclusion still unproved.

  1. The two consumers identify different generated states. At trace step 1, record the accepted handshake, stable payload, ID/epoch, state transition, resource count, observation, and current pass/fail status.
  2. Register offsets or fields may disagree. At trace step 2, record the accepted handshake, stable payload, ID/epoch, state transition, resource count, observation, and current pass/fail status.
  3. Stop, regenerate both from one manifest, and rerun interface/firmware checks. At trace step 3, record the accepted handshake, stable payload, ID/epoch, state transition, resource count, observation, and current pass/fail status.

Result: No; the integration handoff is inconsistent. Accept only after independent reference-model comparison, protocol and security assertions, error-path and mutation evidence, end-to-end coverage, software-visible reconstruction, and all affected CDC/RDC, power-intent, timing, DFT, and physical boundaries are either checked or explicitly withheld.