What it shows
Our method chooses which designs to run through the rigorous simulator:
- It runs one design at a time.
- When the fast model agrees with the rigorous run by a margin, that margin, divided by an estimate of how fast the disagreement can change, certifies a small region around the design.
- It stops when those regions cover the target.
On one test pattern it picked 86 designs, where a regular grid used 125. That comparison is not like for like, as the limits below say.
The second half is a proof. A linear-programming bound shows that no choice from the method’s 284 candidates covers the same certified region with fewer than 50 designs.
The published record says, word for word (an excerpt)
A margin-earned certified ball selects 86 rigorous solves against 125 on a dense lattice, and an LP relaxation of the covering ILP proves no selection from the 284-candidate pool covers the loop's own certified volume with fewer than 50.
Why it matters
Each run of a rigorous optical simulator is expensive. A team that checks a fast printing model against one either runs it on a dense regular grid of designs, which wastes runs, or samples sparsely, with no guarantee that the gaps are covered.
Qualifying a fast printing model means comparing it with a rigorous one, and the rigorous runs are the cost. A method that states which runs it needed, and a proved floor on how few could have done the same job, tells a team how far its own selection is from the best possible one from that pool.
What is ours, and what is not
Both halves rest on published technique. Certifying a region around one evaluation is the classical Piyavskii–Shubert argument, and the floor is the textbook relaxation of a covering problem. What is ours is applying them to a printing-model check and measuring the result.
Who should care
- Computational-lithography software makers. A record of which rigorous runs a model check needed, with a floor on how few could have covered the same region.
- Model-qualification teams at foundries and mask shops. A possible way to spend fewer rigorous runs, once it is shown on a two-dimensional mask; today it is shown on one simple pattern.
The limits, in the record’s words
The published record says, word for word (an excerpt)
The floor is proved for THIS candidate pool and THIS certified volume, not for selection in general. L is an EMPIRICAL modulus, not a proven constant.
The published record says, word for word (an excerpt)
The headline rung violates the run's own fairness principle and the run says so -- 124 of its 125 lattice points are not candidates the loop could buy.
In plain words:
- The floor holds only for this pool of candidates and this region.
- The constant that sets the size of each certified region, how fast the disagreement can change, is estimated from samples, and the estimators disagree: one gives a value 2.77x that of the obvious one.
- With an estimate taken from the grid alone, 4 of 200 probe designs escaped their regions; with the estimate the method uses, 0 of 200 did.
- The grid comparison is not fair: 124 of its 125 points were not designs the method could have picked.
- An earlier check for escapes could not fail; the corrected one is published in its place.
- At the tolerance this run used, every design in the region already agreed with the rigorous simulator, so the run shows how the method selects and certifies, not a saving where disagreements exist.
Everything here is one simple test pattern in our own simulator, not a printed wafer.
Open source for this step
Tools and datasets we publish for the print step of building a multi-chip package. They are the checkers around this work, not a copy of the result itself.
- cert-atlas: A labelled set of forged lithography certificates, scored on wrong accepts and wrong rejects alike, so a checker that accepts everything or rejects everything cannot score well.
- lcert-verify: A checker for our lithography certificates that needs only Python's standard library.
- lcert-verify-web: The same verifier in the browser: zero dependencies, nothing uploaded.
- equiv-receipt: A small file that records why two versions of a circuit compute the same thing, which anyone can re-check without our tools.
- prereg (pre-registration primitive): Write your acceptance criteria down, hash them, then measure — a tiny pre-registration primitive.
- certified-mcp: Lets an AI agent ask our certificate checker for a yes-or-no answer, instead of judging a certificate itself.
- cert-verifier: Drop a lithography certificate bundle and verify it in your browser.