AI accelerator package with HBM, chiplets, photonic engine and persistent-state boundaries

概念系統圖 · 非實體拓撲 ILLUSTRATIVE SYSTEM MAP · NOT PHYSICAL TOPOLOGY

研究筆記 04 · AI 系統/持久狀態RESEARCH NOTE 04 · AI SYSTEMS / PERSISTENT STATE

NVM 不必
遍布 AI 系統
NVM does not belong
everywhere in AI systems

真正的機會,是讓每一個系統邊界保存正確的狀態。 The opportunity is to preserve the right state at each system boundary.

從 XPU identity、HBM repair、CPO calibration 到 firmware 與 RAS evidence,本章先說明來源明確要求或展示的行為,再把 OTP、MTP、managed NVM 或 external storage 標為有界的架構候選。 From XPU identity and HBM repair to CPO calibration, firmware and RAS evidence, this chapter establishes what each source explicitly requires or demonstrates—then labels OTP, MTP, managed-NVM or external-storage choices as bounded architecture candidates.

294PDF 頁面已審閱PDF PAGES REVIEWED
6證據分類EVIDENCE CLASSES
4狀態邊界STATE BOUNDARIES
2026-08-26研究凍結日RESEARCH FREEZE
法則 #01 · 邊界狀態RULE #01 · BOUNDARY STATE
4 個領域4 DOMAINS

XPU 信任、HBM/PMIC 修復、光模組校準與主機遙測嚴格分界Strict boundary across XPU trust, HBM/PMIC repair, CPO & telemetry

法則 #02 · 標準依據RULE #02 · STANDARDS GROUNDING
294 頁294 PAGES

OCP、JEDEC DDR5 與 HBS 規格一級文獻嚴格對照驗證Grounded against 294 pages of OCP, JEDEC DDR5 & HBS primary specs

法則 #03 · 先進製程節點RULE #03 · ADVANCED NODES
N5 → N2 GAA

純邏輯製程相容,Core-supply Direct Read 降壓解耦Pure logic compatible; Direct core-supply read into FinFET / GAA

法則 #04 · 不可變信任根RULE #04 · IMMUTABLE RoT
釐清適用邊界ZERO AMBIGUITY

根信任與遙測日誌分離,防止將有限次寫入誤植為無限串流Decouple immutable RoT from bounded telemetry; no false mandates

來源釐清 · OCP 列出的 Lightmatter 貢獻文件 · 並非已採納的 OCP 規範SOURCE CORRECTION · OCP-LISTED LIGHTMATTER CONTRIBUTION · NOT AN ADOPTED OCP SPECIFICATION

本次審閱的 OCP 文件未要求 OTP/MTP MemoryThis OCP Paper Does Not Require OTP or MTP Memory

OCP Server Project 公開列出這份 Lightmatter contribution;它不是已採納的 OCP specification。文件中的兩處 MTP 都是 MPO/MTP 光纖接頭,不能用來證明 NVM。另行引用的 JEDEC DDR5 與 OCP Hardware Secure Boot 標準,才分別建立 PMIC MTP、SPD Hub 可重寫 NVM 與 BMC 不可變安全狀態。其餘配置仍須逐項驗證。The OCP Server Project publicly lists this Lightmatter contribution; it is not an adopted OCP specification. Its two MTP occurrences mean MPO/MTP optical connectors and are not NVM evidence. Separate JEDEC DDR5 and OCP Hardware Secure Boot standards establish PMIC MTP, SPD Hub rewritable NVM and immutable BMC security state. Other placements remain subject to validation.

公開工作組貢獻PUBLIC WORKGROUP CONTRIBUTION

01 · 核心主張01 · EXECUTIVE THESIS

State Contract 優先
Memory Selection 在後
State Contract First
Memory Selection Second

同一套 AI platform 同時存在不可變信任、有限次更新、即時控制與大量 operational evidence。把它們都塞進 OTP 或都寫進 MTP,會同時造成安全、endurance 與系統責任錯配。One AI platform contains immutable trust, bounded updates, live control and high-volume operational evidence. Putting everything in OTP—or writing everything into MTP—misaligns security, endurance and ownership.

01直接需求DIRECT REQUIREMENT

標準或 supplied PDF 明確要求的行為。Behavior explicitly required by a standard or supplied paper.

02官方產品案例OFFICIAL PRODUCT CASE

具名產品或官方實作展示此 lifecycle 已存在。A named product or official implementation demonstrates that the lifecycle exists.

03技術證據TECHNICAL EVIDENCE

同儕審查實作或獨立實體分析支持機制。Peer-reviewed implementation or independent physical analysis supports the mechanism.

04供應商能力VENDOR CAPABILITY

公開 IP envelope;不是 independent assurance。A public IP envelope—not independent assurance.

05推論機會INFERRED OPPORTUNITY

由系統需求推導的 NVM placement。An NVM placement inferred from a system need.

06待驗證VALIDATION NEEDED

節點、PVT、攻擊或 update workload 尚未封閉。Node, PVT, attack or update workload remains open.

02 · 系統需求壓力02 · SYSTEM PRESSURE

AI 擴大 State Diversity
不只是增加 NVM 容量
AI Expands State Diversity
Not Merely NVM Capacity

每一條 state lane 都有不同的 mutability、update cadence、temperature、atomicity 與 evidence 需求。這些條件才是 IP opportunity 的入口。Each state lane has a different mutability, update cadence, temperature, atomicity and evidence requirement. Those conditions—not a generic bit count—define the IP opportunity.

01不可變信任IMMUTABLE TRUST

身分、root、fail-safe baselineIdentity, roots, fail-safe baseline

少量、低寫入、不可回退。候選:OTP 或 PUF-derived root;證書與 helper data 另行定義。Small, rarely written and non-reversible. Candidates: OTP or a PUF-derived root; certificates and helper data require separate treatment.

OTP/PUF 根金鑰OTP / PUF ROOT
02有界生命週期BOUNDED LIFECYCLE

repair、anti-rollback、field profileRepair, anti-rollback, field profiles

有限次更新,必須具備 authenticated transition、atomic commit 與 recovery。Bounded updates require authenticated transitions, atomic commit and recovery.

受管理的 NVMMANAGED NVM
03即時調適LIVE ADAPTATION

equalization、thermal loop、timing servoEqualization, thermal loops, timing servo

runtime training 通常留在 SRAM/register;只有 cold-start seed 或 qualified snapshot 才形成 NVM 機會。Runtime training normally stays in SRAM/registers. Only a cold-start seed or qualified snapshot creates an NVM opportunity.

揮發性狀態VOLATILE STATE
04運作證據OPERATIONAL EVIDENCE

CPER、telemetry、fleet historyCPER, telemetry, fleet history

高頻資料先 aggregate、reduce、forward;embedded MTP 只適合 workload 已被界定的 fault capsule。High-rate data should be aggregated, reduced and forwarded. Embedded MTP fits only a fault capsule with a bounded workload.

主機/BMC/外部儲存HOST / BMC / EXTERNAL

持久狀態基礎PERSISTENT-STATE SUBSTRATE

狀態邊界優先元件相鄰不等於架構State Boundaries FirstComponent Adjacency Is Not Architecture

一個 AI platform,多個邏輯 state domain;持久化必須由可驗證的 contract 管理,而不是每個 IP 的預設配置。One AI platform, multiple logical state domains. Persistence must be governed by a verifiable contract—not assumed in every IP.

邏輯持久性契約視圖LOGICAL PERSISTENCE-CONTRACT VIEW
封裝圖僅為示意PACKAGE ARTWORK IS ILLUSTRATIVE
封裝示意 · 非實體拓樸ILLUSTRATIVE PACKAGE · NOT TOPOLOGY
00 AI 封裝AI PACKAGE XPU 安全隔離區SECURITY ISLAND 根金鑰 · 政策ROOT · POLICY
01 運算與記憶體COMPUTE + MEMORY
HBM 修復領域HBM REPAIR DOMAIN契約CONTRACTXPU 安全隔離區XPU SECURITY ISLAND
修復中繼資料 ≠ 揮發性工作資料REPAIR METADATA ≠ VOLATILE PAYLOAD

Repair metadata 可持久;HBM payload 與 SRAM runtime state 保持 volatile,BISR 與 repair authority 仍依產品而定。Repair metadata may persist. HBM payload and SRAM runtime state stay volatile; BISR and repair authority are product-specific.

02 高速 I/OHIGH-SPEED I/O
SerDes 邊界SERDES BOUNDARY資料DATAOE 控制器與 PICOE CTRL + PIC
即時等化 · 揮發性LIVE EQ · VOLATILE

Live EQ 保持 volatile;只有 recovery time 證明需要時,cold-start seed 才是合理 inference。Live EQ stays volatile. Persist a cold-start seed only when recovery time justifies the inference.

03 光功率OPTICAL POWER
ELS/雷射控制ELS / LASER CTRLLIGHTPIC
光源 · 非資料路徑LIGHT SOURCE · NOT DATA PATH

ELS 提供 optical power,不承載 data;只有 controller ownership 被證明時才保存 local state。ELS supplies optical power, not data. Persist local state only when controller ownership is proven.

04 平台控制PLATFORM CONTROL
電源與安全 · PMICPOWER & SAFETY · PMIC平台管理 · DC-SCM/BMCPLATFORM MGMT · DC-SCM / BMC
分離的權限層SEPARATE AUTHORITY PLANES

PMIC 處理 power/reset;BMC secure boot 需要 OTP-class 不可變狀態,並可協調 authenticated firmware、RAS 與 evidence。root 位於 BMC die 或 companion HWRoT,仍依產品架構而定。PMIC handles power/reset. BMC secure boot requires OTP-class immutable state and may orchestrate authenticated firmware, RAS and evidence. Whether the root resides on the BMC die or a companion HWRoT remains product-specific.

邏輯 persistence-contract view:XPU security island、HBM repair domain、SerDes boundary、optical engine、laser controller、PMIC 與 platform management 參與不同的 persistence contract;authoritative owner 仍須依產品架構確認。Package artwork 僅為視覺說明,不代表實體位置或協定拓撲。Logical persistence-contract view: the XPU security island, HBM repair domain, SerDes boundary, optical engine, laser controller, PMIC and platform management participate in distinct persistence contracts; the authoritative owner remains product-specific. The package artwork is illustrative and does not represent physical placement or protocol topology.

圖解邊界:Diagram boundary: 上方 package artwork 僅為視覺說明;下方 contract view 呈現 state boundary 與 validation responsibility,不是 OCP spec、實體 floorplan 或 local NVM mandate。The package artwork is illustrative. The contract view shows state boundaries and validation responsibility—not an OCP specification, physical floorplan or local-NVM mandate.

03 · 機會地圖03 · OPPORTUNITY MAP

Evidence 定義系統行為
Inference 定位 NVM 價值
Evidence Defines System Behavior
Inference Locates NVM Value

先用來源支持模式查看 requirement、official case、technical evidence 與 disclosure,再開啟有界推論。每張卡分開呈現 evidence、candidate fit、validation gate 與 limit。Start with the source-grounded view for requirements, official cases, technical evidence and disclosures, then include bounded inferences. Every card separates evidence, candidate fit, validation gate and limitation.

07目前顯示的機會卡VISIBLE OPPORTUNITY CARDS

01XPU/信任根XPU / ROOT OF TRUST
官方產品案例OFFICIAL PRODUCT CASE

H100 On-Die Trust 與 AttestationH100 On-Die Trust and Attestation

NVIDIA H100 公開架構包含 on-die RoT、secure/measured boot、SPDM 與 attestation。它建立 persistent identity 的產品需求,不代表任何單一 OTP/PUF 實作必然較安全。NVIDIA's public H100 architecture includes an on-die RoT, secure/measured boot, SPDM and attestation. It establishes a product need for persistent identity—not that one OTP or PUF implementation is universally safer.

狀態/適用性STATE / FIT身分錨點IDENTITY ANCHOROTP 或 PUF 衍生根金鑰OTP or PUF-derived root 需確認 provisioning 與 physical threat modelProvisioning and physical threat model remain target-specific 硬體信任根子系統 (Quiddikey / tRoot / CryptoManager) ↗ Hardware RoT Subsystems (Quiddikey / tRoot / CryptoManager) ↗
02韌體生命週期FIRMWARE LIFECYCLE
推論機會INFERRED OPPORTUNITY

Immutable Root 與 Mutable Rollback StateImmutable Root and Mutable Rollback State

OCP 要求 signed update、version reporting 與 rollback behavior;SPDM 定義 device-constant identity,但把 provisioning mechanism 留在規格之外。最佳 fit 不是把整個 image 放進 OTP。OCP calls for signed updates, version reporting and rollback behavior. SPDM defines device-constant identity but leaves provisioning out of scope. The best fit is not to place the entire image in OTP.

狀態/適用性STATE / FIT根金鑰+計數器+映像ROOT + COUNTER + IMAGEOTP/PUF+受管理的 NVM+快閃記憶體OTP/PUF + managed NVM + flashcounter 需 authenticated、atomic、recoverableCounters must be authenticated, atomic and recoverable
03HBM/SRAM 修復HBM / SRAM REPAIR
官方產品案例OFFICIAL PRODUCT CASE

Repair State 的可靠度與 Attestation 證據Repair State as Reliability and Attestation Evidence

NVIDIA row remap 可在 device life 持續生效;Hopper channel repair 會改變 attestation measurement。Siemens 也顯示 fusebox programming session 可能非常有限。NVIDIA row remapping persists for device life, while Hopper channel repair can change attestation measurements. Siemens also shows that fusebox programming sessions may be very limited.

狀態/適用性STATE / FIT修復對照表REPAIR MAP熔絲/受管理的稀疏狀態Fuse / managed sparse state合法修復必須與 measurement/RIM 同步Authorized repair must stay coherent with measurements/RIMs
04光子技術/CPOPHOTONICS / CPO
推論機會INFERRED OPPORTUNITY

Factory Baseline 與 Live Thermal ControlFactory Baseline and Live Thermal Control

OCP 指出 ring wavelength 對溫度敏感;CMIS 支援 diagnostics 與 statistics。這支持 per-unit trim/safe limit 的持久化機會,但 continuous tuning 應留在 volatile control。OCP identifies temperature-sensitive ring wavelength; CMIS supports diagnostics and statistics. That supports persistent per-unit trim and safe limits, while continuous tuning should remain volatile.

狀態/適用性STATE / FIT基線與執行期間控制迴路BASELINE + RUNTIME LOOPOTP 基線與選用的 MTP 設定檔OTP baseline + optional MTP profile連續微調 ≠ 連續 NVM 寫入Continuous tuning ≠ continuous NVM writes
05PMIC 啟動基準PMIC STARTUP TRUTH
官方產品案例OFFICIAL PRODUCT CASE

PF8100/PF8200 的 OTP Boot BaselinePF8100/PF8200 OTP Boot Baseline

NXP PF8100/PF8200 每次 VIN crossing 從 OTP 載入 mirror registers,再載入 functional registers。這展示 immutable startup configuration 的實際產品價值。NXP PF8100/PF8200 loads mirror registers from OTP at a VIN crossing, then loads functional registers. It demonstrates the real product value of immutable startup configuration.

狀態/適用性STATE / FIT安全開機組態SAFE BOOT CONFIGOTP器件案例;不可直接外推所有 AI PMICDevice-specific; not universal to every AI PMIC
06故障摘要FAULT CAPSULE
官方產品案例OFFICIAL PRODUCT CASE

ADP1055 的有界 Black-Box LoggingADP1055 Bounded Black-Box Logging

ADI ADP1055 以 EEPROM 保存 fault snapshot,並公開 temperature-dependent record limit、circular buffer 與 hold-up capacitor 條件。這是 bounded logging 的設計範本。ADI ADP1055 stores fault snapshots in EEPROM and discloses temperature-dependent record limits, a circular buffer and hold-up-capacitor condition. It is a design pattern for bounded logging.

狀態/適用性STATE / FIT事件觸發紀錄EVENT-DRIVEN RECORD受管理的 EEPROM/MTPManaged EEPROM / MTP先定義 Tj、event rate、atomic write 與 retentionDefine Tj, event rate, atomic write and retention first
07RAS/遙測RAS / TELEMETRY
推論機會INFERRED OPPORTUNITY

Telemetry Stream 的分層儲存Tiered Storage for Telemetry Streams

OCP RAS API 與 supplied PDF 要求 discovery、configuration、event/action queues 與跨域 diagnostics;local NVM 只應保留 threshold、checkpoint 或 last-gasp capsule。The OCP RAS API and supplied paper call for discovery, configuration, event/action queues and cross-domain diagnostics. Local NVM should retain only thresholds, checkpoints or a last-gasp capsule.

狀態/適用性STATE / FIT先彙整再儲存REDUCE BEFORE STORESRAM 緩衝 → BMC/主機儲存SRAM buffer → BMC / host storageraw stream 優先 forward,不持續磨耗 embedded NVMForward the raw stream; do not continuously wear embedded NVM
08小晶片生命週期與開機時序CHIPLET LIFECYCLE & BOOT TIMING
推論機會 · 開機時序解析INFERRED OPPORTUNITY · BOOT TIMING RESOLUTION

Per-Die 信任狀態與 PCIe/CXL LTSSM 100ms 開機架構Per-Die Trust State and PCIe/CXL LTSSM 100ms Boot Architecture

UCIe 2.0 擴充 manageability 與 DFx lifecycle,確立 per-die identity、repair ownership、debug lock 與 firmware metadata 的機會(UCIe 規範中的 MTP 係指 Management Transport Protocol)。在高速小晶片開機架構中,PCIe/CXL 實體層鏈路訓練 (LTSSM) 在系統重置後具備嚴苛的 100ms 鏈路握手超時窗口;若嘗試自片上慢速嵌入式 NVM(讀取頻寬通常僅 bandwidth band )直接載入數十至數百 MB 的複雜 AI 韌體,耗時將高達數秒並觸發 LTSSM 超時斷鏈。架構解答是「片上不可變微型 RoT (32B Hash) + 片外高速分層載入」:片上僅需微型 OTP/PUF 儲存 32 位元組 LMS/SHA-256 根雜湊(次微秒內極速錨定信任),大容量韌體則透過外掛高頻 Quad/Octal SPI 或主機通道分層載入 SRAM/DRAM 並由硬體管線即時驗簽,兼顧硬體信任根之安全要求與 100ms 鏈路訓練時限。UCIe 2.0 expands manageability and DFx lifecycle, supporting per-die identity, repair ownership, debug locks, and firmware metadata (note that UCIe's MTP denotes Management Transport Protocol). In advanced chiplet architectures, PCIe/CXL physical layer LTSSM enforces a strict 100ms link-training timeout window upon reset de-assertion. Attempting to boot tens or hundreds of megabytes of complex accelerator firmware directly from slow on-die eNVM (typically 10-50 MB/s read bandwidth) takes seconds and causes fatal LTSSM link-down panics. The architectural resolution decouples this into "On-die Immutable Micro-RoT (32B Hash) + Hierarchical Off-chip High-speed Loading": on-die OTP/PUF stores only a 32-byte LMS/SHA-256 root hash (anchored in sub-microseconds), while bulk firmware is streamed via high-speed external Quad/Octal SPI or host memory into SRAM/DRAM with pipelined signature verification—strictly meeting the LTSSM timing window (not a universal 100ms figure) window.

狀態/適用性STATE / FIT微型信任根與分層開機MICRO-RoT + TIERED BOOT晶片內 32B OTP 雜湊與晶片外快速開機32B on-die OTP hash + off-chip fast boot片上 32B 信任根錨定 + 片外高速分層載入,消除 LTSSM 100ms 逾時矛盾On-die 32B RoT anchor + off-chip high-speed boot resolves LTSSM timing window (not a universal 100ms figure) timeout
09CXL 記憶體裝置CXL MEMORY DEVICE
推論機會INFERRED OPPORTUNITY

Online Firmware 與 PPR 的 Lifecycle ContractOnline Firmware and PPR Lifecycle Contract

CXL 3.2 公開功能包含 online firmware activation、post-package repair、monitoring 與 security。規格證明行為;memory medium、banking、atomicity 與 recovery 仍由產品架構決定。CXL 3.2 publicly includes online firmware activation, post-package repair, monitoring and security. The specification proves the behavior; memory medium, banking, atomicity and recovery remain product-architecture decisions.

狀態/適用性STATE / FIT韌體與修復中繼資料FW + REPAIR METADATA受管理的 NVM 與外部映像儲存Managed NVM + external image storeCXL 未指定 OTP/MTP technologyCXL does not prescribe OTP/MTP technology
10DDR5 PMIC
直接需求DIRECT REQUIREMENT

JEDEC 明確定義 PMIC MTP NVMJEDEC Explicitly Defines PMIC MTP NVM

JESD301-2 將 multiple-time-programmable NVM 納入 DDR5 PMIC 的持久設定與狀態契約。應用位置已由標準建立,不再是「等待產品證明」的假設。JESD301-2 places multiple-time-programmable NVM inside the DDR5 PMIC persistent-configuration and status contract. The application socket is standards-defined—not a hypothesis awaiting product proof.

狀態/適用性STATE / FIT電源組態與狀態POWER CONFIG + STATUSMTP/受管理的 NVMMTP / managed NVMmacro、PVT、endurance 與 recovery 仍須 qualificationMacro, PVT, endurance and recovery still require qualification
11DDR5 SPD HUB
直接需求DIRECT REQUIREMENT

8-Kbit 可重寫 NVM 是 SPD Hub 標準功能8-Kbit Rewritable NVM Is a Standard SPD Hub Function

JESD300-5B.01 定義 1024-byte、16-block 的 SPD EEPROM/可重寫 NVM 功能。Embedded MTP 是有界的實作候選,不是 JEDEC 指定的 bitcell 技術。JESD300-5B.01 defines a 1024-byte, sixteen-block SPD EEPROM/rewritable-NVM function. Embedded MTP is a bounded implementation candidate, not a JEDEC-prescribed bitcell technology.

狀態/適用性STATE / FIT模組身分與組態MODULE ID + CONFIGEEPROM 功能 → MTP 候選EEPROM FUNCTION → MTP CANDIDATEwrite protection、cycles 與 PVT 依實作驗證Qualify write protection, cycles and PVT per implementation
12BMC 安全信任根BMC SECURITY ROOT
需求 · 供應商揭露 · 候選適用性REQUIREMENT · VENDOR DISCLOSURE · CANDIDATE FIT

BMC Security State:Requirement、Disclosure 與 Architecture FitBMC Security State: Requirement, Disclosure and Architecture Fit

OCP 規格要求 BMC 使用 hardware-immutable source of verification,但未指定 OTP、PUF 或實體位置。Axiado SCM3003 product brief 另行公開 on-chip OTP roots、三個 4-Kbyte OTP 與 on-chip PUF;這是 vendor disclosure,不是 shipment、deployment 或 attack certification 證據。OCP requires a hardware-immutable source of verification for BMC secure boot but does not prescribe OTP, PUF or physical placement. The Axiado SCM3003 product brief separately discloses on-chip OTP roots, three 4-Kbyte OTPs and an on-chip PUF; that is vendor disclosure, not shipment, deployment or attack-certification evidence.

狀態/適用性STATE / FIT根金鑰+政策+撤銷ROOT + POLICY + REVOCATIONOTP 與選用的 PUF 衍生根金鑰OTP + optional PUF-derived rootplacement 與 physical assurance 仍依產品而定Placement and physical assurance remain product-specific

04 · 光子技術/CPO 焦點04 · PHOTONICS / CPO FOCUS

光引擎狀態契約模型
候選持久基線與揮發控制邊界
Optical Engine State-Contract Model
Candidate Persistent Baseline and Volatile Control

OE/PIC/ELS 是 supplied OCP paper 與 NVM opportunity space 的高潛力交會點:per-unit identity、factory trim、safe limit、qualification digest 與 sparse recalibration 都是需要驗證的 local persistent-state 候選。OE/PIC/ELS are a high-potential intersection between the supplied OCP paper and the NVM opportunity space: per-unit identity, factory trim, safe limits, qualification digests and sparse recalibration are candidate local persistent states that still require validation.

AI silicon package beside a co-packaged optical engine
光學封裝示意ILLUSTRATIVE OPTICAL PACKAGE邏輯狀態契約 · 非實體拓樸LOGICAL STATE CONTRACT · NOT PHYSICAL TOPOLOGY
推論領域 AINFERRED DOMAIN A候選持久基線CANDIDATE PERSISTENT BASELINE

Factory Identity 與 Qualified BaselineFactory Identity and Qualified Baseline

  • 單顆裝置身分Per-unit identity
  • 工廠微調Factory trim
  • 安全操作限制Safe operating limits
  • 資格驗證摘要Qualification digest

這些是由系統需求推導的候選 persistent state;最終 medium、位置與 owner 仍須由產品架構驗證。These are candidate persistent states inferred from system needs. The final medium, location and owner remain product-specific.

上電讀取 · 提議的邏輯流程POWER-UP READ · PROPOSED LOGICAL FLOW
  1. 01驗證VERIFY
  2. 02載入LOAD
  3. 03啟用ACTIVATE
領域 A → 領域 BDOMAIN A → DOMAIN B驗證候選 baseline,再載入 volatile controlVerify the candidate baseline before loading volatile control
領域 BDOMAIN B揮發性控制與即時迴路VOLATILE CONTROL & REAL-TIME LOOP

Runtime Adaptation 與 Live TelemetryRuntime Adaptation and Live Telemetry

  • 溫度/時序伺服控制Thermal / timing servo
  • 訓練係數Training coefficients
  • 即時診斷Live diagnostics
  • 暫存器/SRAM 狀態Registers / SRAM state

即時狀態在 runtime 持續變化;原始 stream 應先 reduce/forward,不應直接形成 continuous NVM writes。Live state changes continuously at runtime. Reduce or forward the raw stream instead of turning it into continuous NVM writes.

通過資格驗證的更新 · 提議的邏輯流程QUALIFIED UPDATE · PROPOSED LOGICAL FLOW領域 B · 候選更新DOMAIN B · CANDIDATE UPDATE只有通過資格驗證的稀疏更新才跨越持久化邊界Only qualified sparse updates cross the persistence boundary
  1. 01觀測OBSERVE
  2. 02資格驗證QUALIFY
  3. 03授權AUTHORIZE
  4. 04原子提交ATOMIC COMMIT

→ 候選領域 A · 通過資格驗證的設定檔儲存區→ CANDIDATE DOMAIN A · QUALIFIED PROFILE BANKQualified recalibration 可能形成 managed-NVM opportunity;update cadence、rollback 與 recovery 必須先被界定。Qualified recalibration may create a managed-NVM opportunity, but update cadence, rollback and recovery must be bounded first.

狀態邊界STATE BOUNDARY持續調整CONTINUOUS TUNING持續 NVM 寫入CONTINUOUS NVM WRITES

Runtime adaptation 保持 volatile;只有 qualified state 才能穿越 persistence gate。Runtime adaptation stays volatile; only qualified state crosses the persistence gate.

05 · NVM 選型05 · NVM SELECTION

OTP 與 MTP 的分層角色
每一層對應正確的 State Contract
Layered Roles for OTP and MTP
The Right State Contract for Each Layer

selection lens 先問 lifecycle,再看 bit count、temperature 與 macro。下列是 architecture class,不是通用 endurance 數字或 foundry availability 承諾。The selection lens starts with lifecycle, then bit count, temperature and macro availability. These are architecture classes—not universal endurance numbers or foundry-availability promises.

典型狀態特徵 · 示意TYPICAL STATE PROFILE · ILLUSTRATIVE不可變/低頻IMMUTABLE / RARE有界更新BOUNDED UPDATE大量資料/串流BULK / STREAM即時/揮發性LIVE / VOLATILE
01 · 不可變01 · IMMUTABLE

OTP / FUSE

很少寫、不可回退Rarely written, non-reversible
  • 裝置身分錨點Device identity anchor
  • 故障安全開機基線Fail-safe boot baseline
  • 生命週期/除錯鎖定Lifecycle / debug lock
  • 工廠微調摘要Factory trim digest

限制:修正錯誤、revocation 與多階段 provisioning 必須預先設計。Limit: error correction, revocation and staged provisioning must be designed up front.

02 · 有界可變02 · BOUNDED MUTABLE

MTP/受管理的 NVMMTP / MANAGED NVM

有限更新、Atomicity 必須由架構保證Bounded Updates, Atomicity Required
  • 防回復中繼資料Anti-rollback metadata
  • 通過資格驗證的校準設定檔Qualified calibration profile
  • 修復/重新對映狀態Repair / remap state
  • 故障摘要Fault capsule

限制:需要明確 event count、Tj、retention、ECC、commit/recovery。Limit: requires defined event count, Tj, retention, ECC, commit and recovery.

03 · 大量資料/串流03 · BULK / STREAM

外部/主機儲存EXTERNAL / HOST STORE

大量 code 與 operational evidenceBulk code and operational evidence
  • 韌體 A/B 儲存區Firmware A/B banks
  • CPER/設備群歷史紀錄CPER / fleet history
  • 原始特性量測資料Raw characterization
  • 憑證鏈/資訊清單Certificate chain / manifests

限制:local root 必須驗證 image、version 與來源。Limit: a local root must verify image, version and provenance.

04 · 即時控制04 · LIVE CONTROL

SRAM/暫存器SRAM / REGISTERS

即時更新、斷電不必保留Live updates, no power-off retention
  • SerDes 訓練SerDes training
  • 溫度控制迴路Thermal control loop
  • 時序伺服控制Timing servo
  • 遙測緩衝區Telemetry buffer

限制:若 cold restart 要重建,必須另外定義可信 baseline。Limit: if cold restart must recover state, define a trusted baseline separately.

斷電後持續保存PERSISTENT AFTER POWER LOSSYESYES是 · 晶片外YES · OFF-DIENO

選擇記憶體巨集前的七個問題SEVEN QUESTIONS BEFORE MACRO SELECTION

  1. 01斷電後一定要保留嗎?Must it survive power loss?
  2. 02誰可以改?改幾次?Who may change it, and how often?
  3. 03寫入中斷時如何恢復?How does it recover from a torn write?
  4. 04狀態是否含 secret?Does the state contain a secret?
  5. 05它會改變 attestation 嗎?Does it change attestation?
  6. 06真實 Tj 與 retention 是多少?What are the real Tj and retention needs?
  7. 07local storage 比 signed pointer 更好嗎?Is local storage better than a signed pointer?

06 · 先進製程 NVM06 · ADVANCED-NODE NVM

製程愈先進
Read-Domain Contract 愈重要
As Nodes Advance
The Read-Domain Contract Matters More

先分開三件事:process device availability、embedded NVM technology 與 system supply contract。把 I/O oxide、外部 rail 與 macro operation 混為一談,會導出錯誤的節點與架構結論。Separate three things first: process-device availability, embedded-NVM technology and the system supply contract. Conflating I/O oxide, external rails and macro operation leads to the wrong node and architecture conclusions.

公開產品組合訊息PUBLIC PORTFOLIO SIGNAL 40nm28nm22 / 16 / 12nm+CXL / AI PLP 公開產品與 foundry roadmap 的證據路徑Evidence path across public products and foundry roadmaps
01
零額外光罩 · 浮動閘極ZERO-MASK · FLOATING GATE

邏輯製程相容 MTPLOGIC-COMPATIBLE MTP

40nm / 2.5V 元件類別2.5V DEVICE CLASS

Synopsys 公開列有 TSMC 40nm LP/2.5V process-I/O gate-oxide class 的 MTP。代表性競品公開資料則多採 3.3V 或 5V device platforms。Synopsys publicly lists a TSMC 40nm LP MTP in the 2.5V process-I/O gate-oxide class. Representative competing public offerings use 3.3V or 5V device platforms.

公開案例PUBLIC EXAMPLE不是排他性市場結論Not an exclusive market claim
02
專用製程模組DEDICATED PROCESS MODULE

嵌入式快閃記憶體EMBEDDED FLASH

28nm / 已發表的實作案例PUBLISHED IMPLEMENTATION EXAMPLE

eFlash 可與 1.8V logic baseline 共存,但公開 28nm 實例仍加入 flash-specific dielectric、HV devices、charge-pump support 與額外 masks。eFlash can coexist with a 1.8V logic baseline, while a published 28nm implementation still adds flash-specific dielectric, HV devices, charge-pump support and extra masks.

製程取捨PROCESS TRADE以製程複雜度換取密度與可重寫性Process complexity buys density and rewritability
03
先進嵌入式 NVMADVANCED EMBEDDED NVM

MRAM / RRAM

22nm+ / 產品組合移轉PORTFOLIO SHIFT

主流 foundry 公開資料顯示,22/16/12nm 之後的可重寫 eNVM 路線明顯轉向 MRAM/RRAM;各節點成熟度仍須逐產品確認。Public leading-foundry portfolios show a clear shift toward MRAM/RRAM for rewritable eNVM at 22/16/12nm and beyond; maturity remains product- and node-specific.

技術方向,並非全面適用DIRECTION, NOT UNIVERSALITY不排除 22nm eFlash IP 或其他技術Does not exclude 22nm eFlash IP or other technologies
04
企業級加速器斷電保護ENTERPRISE ACCELERATOR PLP

STT-MRAM 日誌STT-MRAM JOURNAL

DDR / xSPI / 無電容斷電保護CAPACITOR-FREE PLP

在 AI 叢集與企業級 NVMe SSD 中,Everspin STT-MRAM 取代超級電容,於急遽斷電時提供奈秒級持久日誌寫入,徹底消除電容老化與巨集體積瓶頸。In AI clusters and enterprise NVMe SSDs, Everspin STT-MRAM replaces bulky supercapacitors, delivering nanosecond persistent journaling during sudden power loss without capacitor aging.

零電容斷電保護ZERO-CAPACITOR PLPGF 22FDX / 12LP 與 TSMC 製程支撐Backed by GF 22FDX/12LP & TSMC foundries
01氧化層系統OXIDE SYSTEM

Retention 由 tunnel oxide、inter-poly dielectric、defect、P/E stress 與溫度共同決定。Retention depends on tunnel oxide, inter-poly dielectric, defects, P/E stress and temperature together.

02電壓定義VOLTAGE LANGUAGE

Process I/O oxide class 不等於 macro 必須直接使用同電壓的外部供電。A process I/O oxide class is not the same as a macro requiring an external rail at that voltage.

03製程節點定義NODE LANGUAGE

公開證據支持一個實測 28nm implementation example;它不建立 production volume、市場採用或絕對節點上限。Public evidence supports a measured 28nm implementation example. It does not establish production volume, market adoption or an absolute node limit.

供應商文件揭露VENDOR DOCUMENTED僅限 TSMC N5TSMC N5 ONLY

核心電源直接讀取DIRECT CORE-SUPPLY READ

價值不在「所有操作只用一個 VDD」
而在 Read 與 Program 的責任分離
One VDD Everywhere Is Not the Goal
The Value Is Read–Program Separation

Synopsys 公開資料確認 TSMC N5 XHF OTP 可從 core supply 直接讀取,並將其連結到較低 read stress 與 unlimited reads。此證據不自動延伸到 MTP、N5A、N4P、N3P 或 N2。Synopsys publicly documents direct core-supply read for TSMC N5 XHF OTP and associates it with lower read stress and unlimited reads. That evidence does not automatically extend to MTP, N5A, N4P, N3P or N2.

01Fabric 前置修復Pre-Fabric Repair

在運算 fabric 啟動前取得 SRAM repair map。Make SRAM repair maps available before compute-fabric activation.

02I/O 前置安全Pre-I/O Security

在外部介面啟用前載入 lock、identity 與 lifecycle policy。Load locks, identity and lifecycle policy before external interfaces enable.

03分階段啟動Staged Bring-Up

降低正常讀取對另一個 power domain 的時序依賴。Reduce mission-mode read sequencing dependence on another power domain.

04喚醒回復狀態Resume State

為 always-on controller 與 power-gated resume 提供候選路徑。Create a candidate path for always-on control and power-gated resume.

內容擁有者提供的公開工程筆記OWNER-PROVIDED PUBLIC ENGINEERING NOTE 讀取可用條件READ AVAILABILITY 燒錄可用條件PROGRAM AVAILABILITY

Core supply 可支援正常讀取;PGM 仍需要 I/O 電源作為 charge pump 的基礎電壓。這是操作模式分離,不是所有模式共用單一供電。Core supply can support normal reads; PGM still requires the I/O supply as the charge pump's base voltage. This separates operating modes—it does not mean one supply serves every mode.

物理邊界分析 · CIM/IMCPHYSICAL BOUNDARY ANALYSIS · CIM / IMC
物理原理限制FIRST-PRINCIPLES LIMITS

AI 存算一體 (CIM/IMC) 的三大物理極限與架構邊界 Physical Boundaries of AI Compute-in-Memory (CIM/IMC) Three Fundamental Silicon Limits

在非揮發性記憶體 (ReRAM、MRAM、Flash) 陣列內直接進行類比向量矩陣乘法 (VMM, Vector-Matrix Multiplication) 概念極具吸引力,但在先進節點大規模量產 AI 晶片中,存算一體面臨不可妥協的底層固體物理與混訊電路邊界: Performing analog Vector-Matrix Multiplication (VMM) directly within non-volatile memory arrays (ReRAM, MRAM, Flash) is conceptually attractive, but deploying CIM/IMC in production advanced-node AI accelerators faces insurmountable solid-state physics and mixed-signal boundaries:

限制 01 · 混合訊號額外成本LIMIT 01 · MIXED-SIGNAL OVERHEAD

ADC/DAC 佔據 60%~85% 功耗與面積ADC/DAC Consumes 60%~85% Power & Area

雖然電阻陣列歐姆定律計算本身近乎零動態延遲,但陣列周邊的輸入 DAC 與高精度並行 ADC 轉換電路佔據了整個 CIM 巨集 60% 至 85% 的矽面積與能耗開銷,實質抵消了存算一體的陣列級能效優勢。 While Ohm's law current summation within the resistive array executes with near-zero dynamic latency, peripheral input DACs and high-speed parallel ADCs dominate 60% to 85% of total CIM macro silicon area and power, negating raw array efficiency gains.

限制 02 · 互連電阻LIMIT 02 · INTERCONNECT RESISTANCE

金屬走線 IR-Drop 導致線性度失真Interconnect IR-Drop Destroys Linearity

隨字元線 (Wordline) 與位元線 (Bitline) 陣列長度增加,金屬連線寄生電阻伴隨大電流引發嚴重的非線性 IR-drop 電壓降,使末端儲存單元實際工作偏壓顯著失真,導致累加電流偏離權重線性對應關係。 As Wordline and Bitline arrays scale, non-negligible metallic parasitic resistance under high summing currents induces severe non-linear IR-drop, severely compressing sensing margins and skewing mathematical linearity across distant bitcells.

限制 03 · 精度上限LIMIT 03 · PRECISION CEILING

有限精度瓶頸 (INT8/INT4) 難援大模型Limited Precision (INT8/INT4) vs. LLM Needs

非揮發性元件電導漂移 (Conductance Drift)、熱雜訊與製程離散限制了訊噪比 (SNR),使類比 CIM 實務上限於 INT8 甚至 INT4 推論;無法直接支援現代大語言模型核心的 FP16/BF16/FP8 高動態範圍浮點運算。 Conductance drift, thermal noise, and PVT mismatch bound analog SNR, capping practical CIM precision at INT8 or INT4 inference. This fundamentally prevents native acceleration of modern LLM workloads requiring FP16/BF16/FP8 dynamic ranges.

架構結論:Architectural Verdict: 在先進節點 AI 加速器中,NVM 的關鍵價值在於「確定性狀態儲存、開機信任錨定、與晶圓級修復重映射」,而非強行替代數位算力單元。 In advanced AI accelerators, embedded NVM provides maximum architectural value in deterministic state persistence, secure boot anchoring, and wafer repair remapping—rather than forcing analog replacements of digital tensor compute.

07 · 安全儲存抽象模型07 · SECURE STORAGE ABSTRACTION

Secure Storage 的保護邊界
完整 State Transition
Secure Storage Protection Boundary
The Full State Transition

AI NVM 的差異化不應停在「可存 key/trim」。可防守的產品邊界,是 confidentiality、integrity、atomicity 與 attestation coherence 同時成立。AI-NVM differentiation cannot stop at “stores keys and trim.” A defensible product boundary makes confidentiality, integrity, atomicity and attestation coherence hold together.

保護責任PROTECTED RESPONSIBILITY已授權AUTHORIZED

受保護的 State TransitionProtected State Transition

每次 transition 都必須維持 confidentiality、integrity、recoverability 與 measurement coherenceEvery transition must preserve confidentiality, integrity, recoverability and measurement coherence

提議 → 驗證 → 原子提交 → 核對證據PROPOSE → VERIFY → ATOMIC COMMIT → RECONCILE EVIDENCE

4/4 個安全保證層適用 · 選取以檢視4/4 ASSURANCE PLANES APPLY · SELECT TO INSPECT

01機密性CONFIDENTIALITY

加密 State 降低 Secret 直接暴露Encrypted State Reduces Direct Secret Exposure

敏感 persistent payload 以 device-bound key 加密;只有 root handling、helper data、debug access 與 plaintext path 都符合 threat model,才能降低直接擷取風險。Root 可為 PUF-derived 或 fused,仍依 threat model 而定。Encrypt sensitive persistent payload with a device-bound key. Direct-extraction risk is reduced only when root handling, helper data, debug access and plaintext paths all fit the threat model. The root may be PUF-derived or fused.

02完整性/防回復INTEGRITY / ROLLBACK

Authorized Version 與 Transition PolicyAuthorized Versions and Transition Policy

簽章、version、counter、revocation 與 policy 必須共同驗證。Verify signatures, versions, counters, revocation and policy together.

03原子性/復原ATOMICITY / RECOVERY

Atomic Commit 與 Safe RecoveryAtomic Commit and Safe Recovery

banking、journal、ECC、hold-up energy 與 recovery path 都是 architecture 的一部分。Banking, journals, ECC, hold-up energy and the recovery path are part of the architecture.

04裝置證明一致性ATTESTATION COHERENCE

Authorized Change 與 Measurement 一致性Authorized Change and Measurement Coherence

repair、configuration 與 firmware state 必須綁定到 measurement/RIM lifecycle,避免可靠度事件被誤判成 compromise。Bind repair, configuration and firmware state to the measurement/RIM lifecycle so reliability events are not mistaken for compromise.

產品差異化PRODUCT DIFFERENTIATION威脅模型根信任 × 加密狀態 × 原子更新 × 一致證據Threat-Modelled Root × Encrypted State × Atomic Update × Coherent Evidence

PUF/AES 不會自動解決 endurance 或 torn write;MTP/ECC 也不會自動解決 secret exposure。完整 abstraction 必須把四者納入同一責任邊界。PUF/AES does not automatically solve endurance or torn writes; MTP/ECC does not automatically solve secret exposure. The abstraction must own all four outcomes.

08 · 證據與未知項目08 · EVIDENCE & UNKNOWNS

精準 Evidence Boundary
可執行 Validation Plan
Precise Evidence Boundaries
Actionable Validation Plan

Evidence class 與 assurance maturity 是兩件事。官方 spec 可以很明確,卻仍不指定 NVM medium;vendor macro 可以量產,卻仍需要 target-node、configuration 與 physical attack evidence。Evidence class and assurance maturity are different. A standard may be precise without prescribing an NVM medium; a production macro may still need target-node, configuration and physical-attack evidence.

Illustrative semiconductor evidence lab scene
證據情境示意ILLUSTRATIVE EVIDENCE SCENE視覺不代表特定量測配置Not a specific test configuration
01第一方來源FIRST-PARTYNVIDIA ↗

HBM 修復會改變量測值HBM repair changes measurement

永久 channel repair 會改變 physical measurement。Permanent channel repair changes physical measurements.

支持的結論PROVES

合法 repair state 必須與 driver/RIM lifecycle 一致。Authorized repair state must remain coherent with the driver/RIM lifecycle.

限制LIMIT

未指定通用 NVM medium 或所有 HBM 實作。It does not prescribe one NVM medium or cover every HBM implementation.

02第一方來源FIRST-PARTYNXP ↗

OTP 建立啟動基準OTP establishes startup truth

OTP → mirror register → functional register。OTP loads mirror registers and then functional registers.

支持的結論PROVES

immutable baseline 可支援可重複的 power-up 行為。An immutable baseline can support repeatable power-up behavior.

限制LIMIT

不代表每個 PMIC 都需要相同 medium。It does not mean every PMIC needs the same storage medium.

03第一方來源FIRST-PARTYANALOG DEVICES ↗

黑盒子紀錄具有界限Black-box logging is bounded

temperature、write count、buffer 與 hold-up energy 共同限制記錄。Temperature, write count, buffering and hold-up energy bound the record.

支持的結論PROVES

logging 必須以 workload 與 power-fail envelope 定義。Logging must be defined by its workload and power-fail envelope.

限制LIMIT

不形成通用 endurance 或 AI attach-rate。It does not establish universal endurance or an AI attach rate.

04標準STANDARDOIF ↗

CMIS 定義行為,未指定儲存媒體CMIS defines behavior, not media

diagnostics、statistics 與 firmware interface 定義清楚。Diagnostics, statistics and firmware interfaces are explicit.

支持的結論PROVES

系統需要可管理的 operational state。The system needs manageable operational state.

限制LIMIT

standard 未指定 OTP、MTP 或其他實體 technology。The standard does not select OTP, MTP or another physical technology.

05標準STANDARDJEDEC ↗

DDR5 PMIC 明確包含 MTPDDR5 PMIC explicitly includes MTP

JESD301-2 定義 MTP NVM 與持久 programming/status 行為。JESD301-2 defines MTP NVM and persistent programming/status behavior.

支持的結論PROVES

DDR5 PMIC 是標準建立的 MTP application socket。The DDR5 PMIC is a standards-defined MTP application socket.

限制LIMIT

不指定供應商 bitcell、node、PVT 或 endurance margin。It does not prescribe a supplier bitcell, node, PVT or endurance margin.

06標準STANDARDJEDEC ↗

SPD Hub 包含 8 Kbit 可重寫 NVMSPD Hub includes 8-Kbit rewritable NVM

JESD300-5B.01 定義 1024-byte NVM 與 16 個 64-byte blocks。JESD300-5B.01 defines 1024 bytes of NVM in sixteen 64-byte blocks.

支持的結論PROVES

SPD Hub 是直接的 EEPROM/MTP-class opportunity。The SPD Hub is a direct EEPROM/MTP-class opportunity.

限制LIMIT

JEDEC 指定裝置行為,不強制單一 embedded bitcell。JEDEC specifies device behavior, not one embedded bitcell.

07供應商揭露VENDOR DISCLOSUREAXIADO ↗

整合 BMC 的晶片揭露 OTP 與 PUFBMC-integrated silicon discloses OTP and PUF

SCM3003 product brief 公開 OTP roots、三個 4-Kbyte OTP、on-chip PUF 與 BMC support。The SCM3003 product brief discloses OTP roots, three 4-Kbyte OTPs, an on-chip PUF and BMC support.

供應商揭露VENDOR DISCLOSES

產品資料將 OTP+PUF 列為 BMC-integrated management platform 的能力。The product brief lists OTP plus PUF as capabilities of a BMC-integrated management platform.

限制LIMIT

Vendor disclosure 不等於 shipment、customer deployment、通用規範或獨立 attack certification。Vendor disclosure is not shipment, customer deployment, a universal mandate or independent attack certification.

目標驗證流程TARGET VALIDATION CASCADE

每個 Opportunity 都必須通過
四個 Closure Gate
Every Opportunity Must Pass
Four Closure Gates

先確定 authoritative copy,再封閉 workload、recovery 與 assurance;任何一關未封閉,都只能是 hypothesis。Establish the authoritative copy, then close workload, recovery and assurance. An open gate keeps the placement a hypothesis.

  1. 01責任歸屬OWNERSHIP誰擁有 authoritative copyWho owns the authoritative copy
  2. 02工作負載/PVTWORKLOAD / PVT容量位元組 · 寫入頻率 · 結溫 · 留存年限 · ECC 容錯Bytes · cadence · Tj · retention · ECC
  3. 03原子復原ATOMIC RECOVERY掉電保護 · 復位重啟 · 局部寫入中斷恢復Brownout · reset · partial program
  4. 04安全保證ASSURANCE可測試性設計 · 除錯隔離 · 故障注入 · 側信道 · 侵入防禦DFT · debug · FI · SCA · invasive

09 · 一級來源總帳09 · PRIMARY SOURCE LEDGER

每個 Claim 都有 Source
每個 Inference 都有 Limit
A Source for Every Claim
A Limit for Every Inference

外部連結優先使用 standards body、first-party implementation、peer-reviewed design、independent physical analysis 與 official vendor page。供應商數值只代表該公開 product envelope,不外推成 universal requirement。External links prioritize standards bodies, first-party implementations, peer-reviewed designs, independent physical analysis and official vendor pages. Vendor figures describe that public product envelope; they are not universal requirements.

01Standards 與 ProtocolsStandards and Protocols8 項一級來源8 PRIMARY SOURCES+
02第一方實作案例First-Party Cases4 項實作4 IMPLEMENTATIONS+
03原廠規格邊界Vendor Capability Envelopes4 項有界主張4 BOUNDED CLAIMS+
04晶圓代工藍圖Foundry Roadmaps2 項技術方向來源2 DIRECTIONAL SOURCES+
05Repair Physics 與 HBM BehaviorRepair Physics and HBM Behavior4 項有界來源4 BOUNDED SOURCES+
決策摘要DECISION SUMMARY Evidence 定義行為
State Contract 指引 NVM 選擇
Evidence Defines Behavior
State Contracts Guide NVM Selection

第一波不追逐「AI 需要更多 NVM」的空泛敘事,而是封閉三個可驗證的 persistent-state contract。The first wave should not chase a generic “AI needs more NVM” narrative. It should close three verifiable persistent-state contracts.

  1. 01BMC 根金鑰與防回復BMC ROOT + ROLLBACKOTP-class root 與 managed lifecycle state 分層Separate the OTP-class root from managed lifecycle state
  2. 02修復與裝置證明REPAIR + ATTESTATIONAuthorized change 與 measurement 保持一致Keep authorized repair and measurement coherent
  3. 03DDR5 PMIC + SPD HUB以 JEDEC-defined MTP/rewritable NVM 契約切入Enter through JEDEC-defined MTP and rewritable-NVM contracts
Illustrative protected state transition inside a silicon subsystem
架構示意ILLUSTRATIVE ARCHITECTURE非特定 macro topologyNot a specific macro topology