Chip making has an operating system problem
In the face of increasing cyber threats, semiconductor manufacturers need a plan to deal with outdated and unsupported operating systems running on critical pieces of factory equipment.
The integrated circuit is the most complex piece of technology humankind has ever mass produced.
These small engineering marvels have fueled revolutionary advancements in industries like consumer electronics, mass communication, medical devices, autonomous transportation, and artificial intelligence.
Each day, more than one billion chips are made in semiconductor fabs around the world. These sprawling, automated factories house some of the world’s most advanced manufacturing tools, capable of performing thousands of angstrom-scale processes around the clock.
And surprisingly, in this realm of state-of-the-art manufacturing, there are critical pieces of equipment running decades-old operating systems and software applications that you wouldn’t dare install on your personal computer.
For an industry facing an ever-increasing threat of cyberattacks, these legacy operating systems pose severe security risks that, if exploited, have the potential to wreak havoc on the entire semiconductor supply chain.
How did we get here?
Previously, IT networks in semiconductor factories were completely isolated from the internet. The general consensus was that running outdated operating systems was acceptable since there was no way for external attackers to access these systems. At the time, the cost of keeping these systems up-to-date and secure wasn’t worth it based on the perceived risk. However, this has proven not to be the case as even isolated factories have fallen victim to cybersecurity incidents.
Now, as Smart Manufacturing principles are adopted by fabs and OEMS, the factory network and all the connected tools, sensors, and devices are being brought online to enable data-driven analysis, optimization, and automation to increase throughput and yield. This increase in connectivity increases risk, making it necessary that all connected devices are running up-to-date software featuring the latest security measures to defend against attacks.
This leaves tools running unsupported software in a precarious spot. (Fig. 1)

The obvious solution is to upgrade the hardware and software. Unfortunately, this isn’t always feasible or even possible. Driver incompatibility issues, no software upgrade path, and unknown OS versions are just some of the challenges. Changing operating systems can also impact finely tuned manufacturing recipes and limit the ability to achieve high yields. Plus, in an industry where downtime is avoided at all costs, taking an essential machine or a fleet of tools offline for upgrades is too expensive and disruptive.
Fixing the problem: A two-step process
For fab owners, eliminating vulnerabilities posed by legacy operating systems is a two-step process. The first is to audit their factory and determine how many instances of unsupported operating systems are running and where they are installed.
Considering the complexity of the manufacturing ecosystem and the myriad of tools, devices, and components supplied by thousands of different vendors, this is a monumental task. Fortunately, the SEMI® International Standards Program is currently working on new E Series Standards developed to help fab owners identify and locate unsupported operating systems in their factories. SEMI E187, SEMI E188, and SEMI E191 are the first in new group of cybersecurity standards developed by SEMI to address these issues.
Once an inventory of legacy operating systems is compiled, the next step is to secure them. If hardware or software upgrades are not an option, an effective approach is to secure by using what is called a bastion host.
Build a bastion
Employing a bastion host avoids excessive downtime and safeguards outdated software. A bastion works by isolating the legacy OS behind a computing device – a server, for example – that is running a new OS version. This cuts off the vulnerable software from the network, preventing bad actors from making it an easy target. All access to the legacy OS is routed through a bastion using secure communication standards. This protects the unsupported device from attacks while allowing it to safely share messages with the factory host. This approach also avoids the need for disruptive upgrades. (Fig. 2)

As long as the bastion is maintained with the latest updates and security features, the legacy OS is better protected from threats.
To be effective, bastions in the semiconductor manufacturing environment must feature a supported OS, be capable of performing secure communication protocols with the factory host, and be architected for frequent updates, rapid rollback, and automated testing and validation.
Although there is no way to completely safeguard a fab from cyber threats, eliminating or securing the most vulnerable attack vectors, such as outdated operating systems, is critically important for the overall protection of our industry.
Interested in learning more about bastions and how they work?
Fill out the form and one of our experts will be in touch.
We take your data privacy seriously! At PEER Group, we strive to provide a safe online experience for our visitors. For more information on how we collect, use, and protect your personal data, see our privacy policy.