Resources / Articles / Tell me more: What’s SEMI E191?

Tell me more: What’s SEMI E191?

Legacy operating systems and unpatched computers that are installed in semiconductor fabrication plants can present a significant cybersecurity risk because they are not protected against current malware threats. Even though factory production floors are isolated from the public internet, they still communicate with other computers and need to be protected from internal threats.

A big challenge factories face is identifying what computing devices and software are present on their production and R&D networks. Knowing this information is critical to understanding the level of risk that exists in their operations – for instance, five occurrences of an unpatched operating system is significantly different than having five hundred insecure systems on the network.

SEMI® E191 – Specification for Computing Device Cybersecurity Status Reporting is a new SEMI Cybersecurity Standard developed by the North America Fab & Equipment Computer and Device Security (CDS) Task Force, with input from the Semiconductor Manufacturing Cybersecurity Consortium (SMCC) Technical Community members.

This SEMI Standard defines what cybersecurity status information the equipment supplier needs to report for each computing device they provide that connects to the factory network. In this scenario, a computing device is defined as any device that can accept software modifications or execute software to perform an operation. These devices can range from computers running the Equipment Control System (ECS) to powerful analysis servers to programmable logic controllers (PLC) or real-time operating systems connected to high-speed sensors.

A computing device implementing SEMI E191 is required to report its own cybersecurity status information. It can also be configured to report the status of other factory network connected devices provided by the equipment supplier that don’t implement the Standard. An example of this would be a SEMI 191-compliant ECS computer reporting cybersecurity status information for an Image Repository.

SEMI E191 compliance example diagram

For this first revision, SEMI E191 requires implementers to report five basic operating system details for each computing device:

Operating System Information Description
ComputingDeviceIdentifer A unique value to identify the computing device provided by the equipment supplier for the manufacturing equipment. For example, the computing device name, an asset tag number, a network hostname, etc.
OSManufacturer Identifies the operating system manufacturer name.
OSName Identifies the operating system name.
OSVersion Identifies the operating system version details (as reported by the OS manufacturer).
OSBuild Identifies the operating system build information (if provided by the OS manufacturer).

A new Subordinate Standard (SEMI E191.1 – Specification for SECS-II Protocol for Computing Device Cybersecurity Status Reporting) defines how implementers report SEMI E191 data through the SECS-II interface with two new status variables.

SEMI E191 was created with a very narrow focus to help the initial standard pass quickly and start getting information using the existing SECS-II interface that most semiconductor manufacturing equipment already supports. The CDS Task Force is currently working on updating these SEMI Standards in two major ways:

  • First, they are looking to expand the reported cybersecurity status information to include details about operating system patches, service packs and components installed on the computing device. Factories can use this information to identify those computing devices that are not running components the factory deems critical to address discovered operating system vulnerabilities. The factory can then work with the equipment supplier to close those gaps.
  • Second, they are looking at other ways to report the cybersecurity status information for computing devices that don’t have a SECS-II interface. This could include using gRPC® and Protocol Buffers interfaces or flat files such as XML or JSON.

The CDS Task Force and SMCC are always looking for interested people to participate in standards development and building cybersecurity resiliency for the semiconductor manufacturing supply chain.

For more details, read the SEMI Blog article on the new SEMI Cybersecurity Standards.

Want to speak with someone about implementing SEMI E191?

Complete the form and a member of our team will be in touch.

Pardot iFrame Resizing

We take your data privacy seriously! At PEER Group, we strive to provide a safe online experience for our visitors. For more information on how we collect, use, and protect your personal data, see our privacy policy.