trusted foundry asic security
Trusted foundry and hardware security practices reduce the risk that a chip is modified, cloned, inspected, or compromised somewhere in the design-to-manufacturing chain.
**The threat model spans more than the fab.** Hardware Trojans, malicious IP, toolchain compromise, mask tampering, side-channel leakage, overproduction, reverse engineering, and counterfeit insertion can appear at different points in the supply chain. A trusted foundry program is one control layer, not the whole security story.
| Control | What it reduces | Practical limitation |
|---|---|---|
| Trusted manufacturing | Unauthorized process or mask modification | Expensive and capacity-limited |
| Split manufacturing | Exposure of full layout to one party | Adds integration and verification complexity |
| Logic locking and obfuscation | Reverse engineering and overproduction | Can be broken if keys or assumptions are weak |
| IP provenance and review | Malicious third-party blocks | Requires process discipline across vendors |
| Secure test and packaging | Counterfeit and data leakage risk | Extends security beyond wafer fabrication |
**Security must be designed before tape-out.** Once masks exist and wafers are running, it is too late to bolt on trust; the architecture, IP selection, verification flow, foundry choice, and test plan all need explicit security ownership.