What it shows
A design check for a chip package ends in a verdict: pass or fail. The certificate is a short record attached to that verdict. It names the inputs the check read, identifies the model that computed the result, and states the bounds on each number beside the verdict.
The rule it adds is about the numbers. In version 2 of the format, no field is a bare single value. Where a yield comes from random sampling, the verdict is set on the lower end of an exact statistical interval, the Clopper–Pearson interval, not on the sample average.
The published record says, word for word (an excerpt)
A compact certificate binds inputs, model identity, bounds and verdict, and no field in version 2 is an unqualified point estimate.
The test behind it recomputes the yield interval from the textbook formula, checks that a proved range for the signal response contained every point of a sweep (0 points fell outside), and plants a broken record and a forged certificate in the keyed mode, both of which must be caught.
Why it matters
A report that states single numbers, with no bounds and no record of the model behind them, leaves a later reviewer unable to tell what was checked. A certificate that carries its own inputs and bounds lets that reviewer re-check the recorded bounds and the verdict drawn from them; the solver and the process model behind the bounds still have to be trusted.
What is ours, and what is not
Each part of the format is published elsewhere: signed records that bind inputs to a claim, the metrology rule that a result carries its uncertainty, and the exact sampling interval, which a Cadence patent on Monte Carlo corner extraction already uses as a yield pass rule (listed under prior art). A format like this is easy to copy. What it is worth rests on the bounds behind its fields.
Who should care
- Packaging and chip-signoff software makers. A report format in which every number carries its range and names the model that produced it.
- Teams that accept or refuse a design for manufacture. A verdict that names its inputs and bounds, so that the bounds and the verdict drawn from them can be re-checked; the solver and the process model behind them still have to be trusted.
The limits, in the record’s words
The published record says, word for word (an excerpt)
it is opt-in, default-off.
The published record says, word for word (an excerpt)
MC yield ships the exact Clopper-Pearson CI with the hard gate on the CI LOWER BOUND, a strict tightening.
The published record says, word for word (an excerpt)
mutual-ΔL is not propagated.
In plain words: the certificate is off unless a user switches it on, so nothing in the default design flow depends on it. The sampling interval bounds only the error that comes from random sampling, not whether the solver or the process model is right. One kind of change, in the mutual inductance between conductors, is not carried through to the bounds.
In its default form the record is protected by a plain fingerprint. That shows accidental corruption but not deliberate editing, because whoever edits the record can recompute the fingerprint. The keyed form that resists forgery needs a secret key shared with whoever checks the certificate. Everything here is tested in our own software, by our own tests.
Open source for this step
Tools and datasets we publish for the package step of building a multi-chip package. They are the checkers around this work, not a copy of the result itself.
- physics-lint: One command that checks a folder of physics models against a fixed set of named physical rules, with findings straight into CI.
- maxwell-lint: Flags a coupling extractor whose answers no passive set of conductors could produce.
- sparam-lint: Is your signal-response model physically possible? Five physical laws checked from the command line.
- interval-core: The interval arithmetic core behind our proofs over whole families of layouts.
- touchstone-tools: Read, write and convert Touchstone files, the standard text files that record how signals pass through a package's connections, and refuse to write one that cannot be read back.
- physics-lint-mcp: The physics checks, callable by an AI agent.
- physics-lint-action: A GitHub Action that fails the build when a model breaks one of a fixed set of named physical rules.
- Signal-response validity corpus: A labelled corpus of physically invalid signal-response networks, and a scorer that grades any checker against it.
- screening-ceiling: The screening-ceiling family as an open dataset.