IJTAG safety circuit
By designing IJTAG security circuits, precisely controlling the test data transmission path and preventing sniffing and tampering by malicious embedded instruments, the data security problem of the IJTAG network is solved, data confidentiality, integrity and availability are achieved, and hardware resource requirements are reduced.
Patent Information
- Application Number
- CN202510407535.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-04
AI Technical Summary
The existing IJTAG network lacks effective data security protection when facing sniffing and tampering attacks by malicious embedded instruments, making it difficult to meet the growing data security needs.
An IJTAG security circuit is designed, including a test access port module, a configuration bit information generation unit, a control signal output unit and a data selector. By precisely controlling the test data transmission path, malicious embedded instruments are prevented from obtaining or modifying the data of other embedded instruments.
Effectively prevent data sniffing and tampering attacks, ensure data confidentiality, integrity and availability, maintain the dynamic configuration capabilities of the IJTAG network, reduce hardware resource requirements, and is suitable for resource-constrained systems.
Smart Images

Figure CN120263469A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to digital circuit design and hardware security technologies, and specifically discloses a security circuit that can prevent the sniffing and tampering attacks of the Internal Joint Test Action Group (IJTAG) network by malicious embedded instruments, belonging to the technical field of basic electronic circuits. Background Art
[0002] With the continuous increase in the complexity of integrated circuits, a large number of functional modules and embedded instruments are integrated inside the chip. As an important test access standard, IJTAG provides a way to test these internal modules of the chip. During the design verification phase and the chip manufacturing process of the chip, R & D engineers use IJTAG to conduct comprehensive functional tests and logic verifications on the designed chip prototype, ensuring that the designed circuit meets the expected functional requirements, promptly discovering and correcting design defects, screening out defective chips, guaranteeing the quality of the chips leaving the factory, and improving the production efficiency and product yield of the entire chip manufacturing industry.
[0003] However, the widespread use of IJTAG also makes the chip face more security risks. In complex system-on-chip designs, the IJTAG network connects numerous embedded instruments. Once attacked, it may affect the function, stability, and security of the entire system, especially in fields with extremely high security requirements such as automotive electronics, industrial control, and aerospace, where the potential harm is huge.
[0004] Currently, the research on IJTAG has the following several directions: The first research direction mainly focuses on the IJTAG circuit configuration, generating test vectors by determining the target registers and SIB sets through specific files, without involving data security protection; the second research direction performs jump operations by controlling the state machine (Finite-State Machine, FSM) of the Test Access Port (TAP) to improve the robustness of the test network, but lacks pertinence in data security protection; the third research direction is committed to achieving fast and secure operations of the IJTAG network, and its security is mainly reflected in the confidentiality of the access key, with insufficient protection for data transmission security; the fourth research direction focuses on the system testing of integrated circuits, providing test vectors for the IJTAG network through a controller, and lacking in data security protection.
[0005] In summary, the existing IJTAG security detection methods and related patented technologies have certain limitations in practical applications and are difficult to meet the growing data security requirements of the IJTAG network. Therefore, there is an urgent need for a security circuit unit that can effectively resist sniffing attacks and tampering attacks, reduce area overhead, and provide reliable security protection for the IJTAG network. Summary of the Invention
[0006] The object of the present invention is to address the deficiencies of the above background art by providing a practical technical means to effectively protect the data security in the IJTAG network, prevent data from being maliciously sniffed and tampered with during transmission and processing, ensure that chip testing and related operations can be carried out in a safe and reliable environment, solve the technical problem of the security risks existing in the test data registers wrapped by embedded instruments in the form of IP provided by untrusted third parties, and achieve the object of the invention of preventing the IJTAG network test data from being subject to sniffing and tampering attacks.
[0007] The present invention adopts the following technical solutions to achieve the above object of the invention: An IJTAG security circuit for selecting a test data transmission path from an embedded instrument unit and outputting test response data, the IJTAG security circuit comprising: a test access port module, a configuration bit information generation unit, a control signal output unit, and a third data selector; The test access port module is used to provide a test data input port, a test clock input port, a test mode selection signal input port, a reset signal input port, a test data output port, provide a state transition control signal for the configuration bit information generation unit during the configuration period, and provide a state transition control signal for the selected test data transmission path during the data transmission period; The configuration bit information generation unit is used to provide a scan network for capturing, shifting, and updating the configuration bit data from the TDI port during the configuration period, and generate the configuration bit information of the embedded register; The control signal output unit is used to dynamically manage the test data transmission path according to the configuration bit information, and generate a test data transmission path control signal and a test data output signal; The third data selector has its 0 input terminal connected to the test data output from the scan network provided by the configuration bit information generation unit, its 1 input terminal connected to the test data output from the selected test data transmission path, and its data selection terminal connected to the test data output signal. During the configuration period, it selects the test data output from the scan network provided by the configuration bit information generation unit as the test response data, and during the data transmission period, it selects the test data output from the selected test data transmission path as the test response data, and transmits the test response data to the test data output port.
[0008] As a further optimization solution for an IJTAG security circuit, an embedded instrument unit includes four test data transmission paths, a first data selector, and a second data selector. The input end of the first data selector receives test data from a test data input port. A test data transmission path is connected between an output end of the first data selector and an input end of the second data selector. The output end of the second data selector is connected to the 1 input end of the third data selector. Each test data transmission path consists of an embedded instrument and a test data register read and written by it.
[0009] As a further optimization solution for an IJTAG security circuit, a configuration bit information generation unit includes: a first segment insertion bit unit, a third segment insertion bit unit, a fourth segment insertion bit unit, a first AND gate, a second AND gate, a data selector, a scan multiplexer control bit unit, a second segment insertion bit unit, a fifth segment insertion bit unit, and a third AND gate; The first segment insertion bit unit selects, according to the updated data in its previous configuration cycle, configuration bit data from the test data input port or shift data of the next-level segment insertion bit unit in the current configuration cycle as the operation data in the current configuration cycle, and captures, shifts, and updates the operation data in the current configuration cycle. The third segment insertion bit unit captures, shifts, and updates the configuration bit data from the test data input port when the updated data in the current configuration cycle of the first segment insertion bit unit is 1. The fourth segment insertion bit unit captures, shifts, and updates the configuration bit data from the test data input port when the updated data in the current configuration cycle of the first segment insertion bit unit is 1. The first AND gate receives the updated data in the current configuration cycle of the first segment insertion bit unit at its first input end and accesses the updated data in the current configuration cycle of the third segment insertion bit unit at its second input end, and outputs the configuration bit information of the first embedded register. The second AND gate receives the updated data in the current configuration cycle of the first segment insertion bit unit at its first input end and receives the updated data in the current configuration cycle of the fourth segment insertion bit unit at its second input end, and outputs the configuration bit information of the second embedded register. The data selector accesses the shift data in the current configuration cycle of the third segment insertion bit unit at its 0 input end, accesses the shift data in the current configuration cycle of the fourth segment insertion bit unit at its 1 input end, and accesses the updated data in the current configuration cycle of the scan multiplexer control bit unit at its data selection end. The scan multiplexer control bit unit shifts and updates the output data of the data selector. The second-stage insertion bit cell captures, shifts, and updates the shifted data of the first-stage insertion bit cell in the current configuration cycle or the shifted data of the fifth-stage insertion bit cell in the current configuration cycle. The shifted data in its current configuration cycle serves as the test data output by the scan network provided by the configuration information generation unit, and the updated data in its current configuration cycle is output as the configuration bit information of the third embedded register; The fifth-stage insertion bit cell captures, shifts, and updates the shifted data of the first-stage insertion bit cell when the updated data of the first-stage insertion bit cell in the current configuration cycle is 0 and the updated data of the second-stage insertion bit cell in the current configuration cycle is 1. The shifted data in its current configuration cycle is transmitted to the second-stage insertion bit cell; The third AND gate has its first input terminal receiving the configuration bit information of the third embedded register, and its second input terminal accessing the updated data of the fifth-stage insertion bit cell in the current configuration cycle, and outputs the configuration bit information of the fourth embedded register.
[0010] As a further optimization scheme of an IJTAG security circuit, the control signal output unit includes: the first to fourth embedded instrument configuration registers, a counter, and a state machine; The first to fourth embedded instrument configuration registers are used to store the configuration bit information of the first to fourth embedded registers respectively; The counter is used to record the length of the test data register read and written by the embedded instrument in the selected test data transmission path and control the data transmission cycle; The state machine is used to sequentially traverse the configuration bit information corresponding to the selected test data transmission paths when at least two test data transmission paths are selected, and generate the control signals and test data output signals corresponding to the test data transmission paths in sequence.
[0011] As a further optimization scheme of an IJTAG security circuit, the state machine sequentially traverses and outputs the configuration bit information corresponding to the selected test data transmission paths. Specifically, for the configuration registers with all configuration bit information being 1, it traverses and outputs the configuration bit information in the order from the highest to the lowest configuration register address.
[0012] An integrated circuit chip is used for secure data transmission during chip testing, debugging, and normal operation, and includes the above IJTAG security circuit.
[0013] An electronic device includes the above integrated circuit chip. The electronic device includes but is not limited to smartphones, tablet computers, industrial control devices, automotive electronic devices, and aerospace devices.
[0014] The present invention adopts the above technical solutions and has the following beneficial effects: (1) The present invention flexibly configures bit information through a segment insertion bit unit and a scan network constructed by a scan multiplexer control bit unit, precisely controls the test data transmission path, and malicious embedded instruments cannot obtain or modify the data of other embedded instruments, ensuring the confidentiality, integrity, and availability of the data, significantly improving data security, effectively preventing data sniffing and tampering attacks, and ensuring the secure transmission of test data in the IJTAG network.
[0015] (2) While protecting data security, the present invention fully complies with the IJTAG standard protocol, maintains the original dynamic configuration ability of the IJTAG network, can flexibly select and access different embedded instruments according to actual test requirements, supports test operations under various combinations of embedded instruments and different configurations, and can quickly adapt to different test scenarios during system-level testing and debugging, facilitating engineers to comprehensively and efficiently test and diagnose faults of the chip.
[0016] (3) During the data transmission process, the present invention does not require complex encryption and decryption operations on the transmitted data, reducing the hardware cost and test time, and is applicable to various application scenarios with requirements for cost, power consumption, and test efficiency.
[0017] (4) The present invention only needs to add simple components such as an output signal control unit and a data selector, requires less hardware resources, does not require a complex encryption module or a large number of additional registers, has low system overhead, and significantly reduces the hardware cost and design complexity. Description of the Drawings
[0018] Figure 1 is a circuit diagram of an IJTAG security circuit proposed by the present invention.
[0019] Figure 2 is a circuit diagram of a configuration bit information generation unit in an IJTAG security circuit proposed by the present invention.
[0020] Figure 3 is a schematic diagram of the circuit principle of a multi-layer network of a segment insertion bit module in the prior art.
[0021] Figure 4 is a flowchart of the operation of an IJTAG security circuit proposed by the present invention.
[0022] Explanation of the reference numerals in the figures: SIB1~SIB5 are the first to fifth segment insertion bit units, SCB is the scan multiplexer control bit unit, AND1~AND3 are the first to third AND gates, and MUX is the data selector. Detailed Embodiments
[0023] The following will describe in detail the specific embodiments of the present invention with reference to the accompanying drawings.
[0024] The security circuit unit proposed by the present invention is used to protect the data security in the IJTAG network, preventing malicious instruments from sniffing or tampering with test data through the Test Data Register (TDR), such as Figure 1 As shown, this security circuit acts on the embedded instrument unit. The embedded instrument unit is used to provide multiple test data transmission paths. Each test data transmission path shifts and updates the test data from TDI through the TDR and then outputs it. The security circuit selects the test data output by one of the test data transmission paths as the test response data. The security circuit includes: a test access port module, a configuration bit information generation unit, a control signal output unit, and a third data selector.
[0025] The test access port has a built-in TAP controller and is used to provide a Test Data In (TDI) port, a Test clock (TCK) input port, a Test Mode Select (TMS) input port, a Test Reset (TRST) input port, and a Test Data Out (TDO) port.
[0026] TCK is the synchronization signal for the operation of the entire security circuit unit. When the security circuit unit is working, TCK controls the serial input of configuration bit data / test data from TDI. When the TAP controller controls data shifting, TCK determines the rhythm of data shifting. Whether the test data is shifted into the scan network from TDI or the test response data is shifted out through TDO, it depends on the synchronization of TCK to ensure that data is transmitted at the correct moment and avoid data errors or losses.
[0027] TMS is used to control the state transitions of capture, shift, and update of the TAP controller, thereby affecting the operations of the segment insertion bit unit, the scan multiplexer control bit unit, and the embedded instrument on the data, and indirectly affecting the working state of the security circuit unit.
[0028] TRST is mainly used to reset and initialize the TAP controller. When the IJTAG network composed of the security circuit and the embedded instrument accessing the security circuit starts or an abnormality occurs, TRST resets components such as the TAP controller, the configuration bit information generation unit, the control signal output unit, and the data selector to the initial state. It ensures that all SIBs are closed, hides the embedded instrument, restores the scan path to the initial configuration, prevents residual data or abnormal states from affecting subsequent operations, and avoids malicious instruments from using abnormal states to obtain or tamper with data, thus ensuring the security and stability of the system.
[0029] A configuration bit information generation unit is used to provide a scan network for capturing, shifting, and updating configuration bit data from the TDI port, and generate configuration bit information config_1~config_4 for the first to fourth embedded registers.
[0030] The control signal output unit is used to dynamically manage the test data transmission path. By controlling the configuration bit information config_1~config_4 of the first to fourth embedded registers, it generates a test data transmission path control signal Sel_1 and a test data output signal Sel_2. During the configuration cycle, Sel_2 selects the test data output by the scan network provided by the configuration bit information generation unit as the test response data output; during the data transmission cycle, Sel_1 activates the TDR path of the target embedded instrument, that is, the selected test data transmission path, and Sel_2 switches to the test data output of the selected test data transmission path, while masking the shift enable signals of other test data transmission paths to ensure that data is transmitted only through the safe path.
[0031] Under the action of Sel_2, the third selector selects the test data output by the scan network provided by the configuration bit information generation unit or the test data output by the test data transmission path corresponding to the test data transmission path control signal Sel_1 as the test response data, and the test response data is output through the TDO port.
[0032] The embedded instrument unit includes: a first data selector, a second data selector, and multiple test data transmission paths. Each test data transmission path consists of a TDR and an embedded instrument. The test data from the TAP is serially input to the input end of the first data selector. Each output end of the first data selector is connected to a TDR for the read and write operations of an embedded instrument. Each embedded instrument captures, shifts, and updates the read test data through the TDR that interacts with it. The updated test data read by each embedded instrument is transmitted to an input end of the second data selector; under the action of the test data transmission path control signal Sel_1 output by the control signal output unit, the first data selector and the second data selector select the updated test data read by the embedded instrument in the test data transmission path corresponding to the test data transmission path control signal Sel_1 and transmit it to the 1 input end of the third data selector MUX3.
[0033] Such as Figure 2As shown, the configuration bit information generation unit includes: the first to fifth segment insertion bit units (SegmentInsertion Bit, SIB) SIB1~SIB5, the first to third AND gates AND1~AND3 and the scan multiplexer control bit unit (ScanMux Control Bit, SCB) SCB, which are used to capture, shift and update the configuration bit data from the TAP, generate the configuration bit information config_1~config_4 of the first to fourth embedded registers, realize the precise control of the test data transmission path, and prevent the test data from being sniffed or tampered by malicious embedded instruments during the transmission process.
[0034] like Figure 3 As shown, the SIB at this level includes a capture unit, a shift unit and an update unit. According to the control signal of the current configuration cycle, such as the update signal Select / capture enable signal capture_en, shift enable signal shift_en, and update enable signal update_en of the previous configuration cycle of the SIB at this level, the capture, shift, and update operations of the current configuration cycle are performed. In the initialization phase, the SIB responds to the capture enable signal capture_en to input the configuration bit information from the TDI port. In the configuration cycle, the SIB selects the configuration bit information from the TDI port or the shift data of the current configuration cycle of the next level SIB, and performs the shift and update operations of the current cycle: the capture phase loads data in parallel, the shift phase transmits data serially, and the update phase latches the configuration bit. The output update data, namely the Select signal, is used to dynamically configure the scan path, and the shift data is passed to the next level SIB to collaboratively implement secure access control.
[0035] The first-segment insertion bit unit SIB1 captures, shifts and updates the configuration bit data input from the TDI port or the shift data of the current configuration cycle of the next-level SIB. The shift data of the current configuration cycle of the first-segment insertion bit unit SIB1 is transmitted to the second-segment insertion bit SIB2. The update data of the current configuration cycle of the first-segment insertion bit unit SIB1 is transmitted to the first input end of the first AND gate AND1 and the first input end of the second AND gate AND2. When the output value of the current configuration cycle of the first-segment insertion bit unit SIB1 update unit is 1, the first-segment insertion bit unit SIB1 is turned on, and the configuration bit information is directly input from the TDI port to the third-segment insertion bit unit SIB3 when the update value of the current configuration cycle of the SCB is 0, or the configuration bit information is directly input from the TDI port to the fourth-segment insertion bit unit SIB4 when the update value of the current configuration cycle of the SCB is 1.
[0036] The third-stage insertion bit cell SIB3 captures, shifts, and updates the input configuration bit data. The shifted data of the third-stage insertion bit cell SIB3 in the current configuration cycle is transmitted to the 0 input terminal of the data selector MUX. The updated data of the third-stage insertion bit cell SIB3 in the current configuration cycle is transmitted to the second input terminal of the first AND gate AND1. The first AND gate AND1 outputs the configuration bit information config_1 of the first embedded register.
[0037] The fourth-stage insertion bit cell SIB4 captures, shifts, and updates the input configuration bit data. The shifted data of the fourth-stage insertion bit cell SIB4 in the current configuration cycle is transmitted to the 1 input terminal of the data selector MUX. The updated data of the fourth-stage insertion bit cell SIB4 in the current configuration cycle is transmitted to the second input terminal of the second AND gate AND2. The second AND gate AND2 outputs the configuration bit information config_2 of the second embedded register.
[0038] The scan multiplexer control bit cell SCB receives the output data of the data selector MUX, shifts and updates the output data of the data selector MUX. The shifted data of the scan multiplexer control bit cell SCB in the current configuration cycle is transmitted to the first-stage insertion bit cell SIB1. The updated data of the scan multiplexer control bit cell SCB in the current configuration cycle is transmitted from the data selection terminal of the data selector MUX as the data selection signal for the next configuration cycle.
[0039] The second-stage insertion bit cell SIB2 shifts and updates the shifted data of the first-stage insertion bit cell SIB1 in the current configuration cycle. The shifted data of the second-stage insertion bit cell SIB2 in the current configuration cycle is transmitted to the 0 input terminal of the third data selector MUX3. The updated data of the second-stage insertion bit cell SIB2 in the current configuration cycle is used as the configuration bit information config_3 of the third embedded register and is transmitted to the first input terminal of the third AND gate AND3. When the updated value of the first-stage insertion bit cell SIB1 in the current configuration cycle is 0 and the updated value of the second-stage insertion bit cell SIB2 in the current configuration cycle is 1, the second-stage insertion bit cell SIB2 is opened, and the shifted data of the first-stage insertion bit cell SIB1 in the current configuration cycle is input to the fifth-stage insertion bit cell SIB5. The shifted data of SIB5 in the current configuration cycle is output to SIB2 as the operation data for the next configuration cycle of SIB2. The updated data of SIB5 in the current configuration cycle is transmitted to the second input terminal of AND3. AND3 outputs the configuration bit information config_4 of the fourth embedded register.
[0040] The shift and update status of the scan multiplexer control bit unit can be controlled and updated through the externally input configuration bit information. During the operation of the IJTAG network, when it is necessary to change the scan path or access different instruments, a specific sequence of configuration bit information is input. These configuration bits not only affect the status of the SIB but also update the status of the scan multiplexer control bit. For example, when switching from accessing embedded instrument 1 to accessing embedded instrument 2, the input configuration bit sequence updates the value of the scan multiplexer control bit from '0' to '1', thus achieving the switching of the scan path and the access to embedded instrument 2. This status control and update mechanism enables the scan multiplexer control bit to flexibly adapt to different test and access requirements, ensuring the normal operation of the IJTAG network and the secure transmission of data.
[0041] The control signal output unit consists of the first to fourth embedded instrument configuration registers, a counter, and a finite-state machine (FSM).
[0042] The first to fourth embedded instrument configuration registers are used to store the configuration bit information config_1~config_4 of the first to fourth embedded registers. For an embedded instrument that can be accessed through one SIB, when the SIB configuration is completed, the data in the SIB is directly stored in the relevant configuration register, providing data for the selection of the test data transmission path. For example: For embedded instrument 3, access can be completed only by opening SIB2; for an embedded instrument that can be accessed through two or more SIBs, when the SIB configuration is completed, the data in the SIB is input into the connected AND gate. If the output result of the AND gate is '1', the corresponding embedded instrument can be accessed. For example: For embedded instrument 1, the result of the AND gate can be '1' only when SIB1 and SIB3 are both 1, and at this time, embedded instrument 1 can be accessed.
[0043] The function of the counter is to record the length of the TDR in the selected test data transmission path to control the data transmission cycle. When starting to access an embedded instrument, the counter starts counting, stops counting and clears after the test data transmission is completed, and prepares for the access to the next embedded instrument.
[0044] The state machine is used when multiple embedded instruments are accessed simultaneously, that is, when the values of multiple configuration registers are all 1. It traverses the configuration registers with a stored value of 1 in descending order of address, generates Sel_1 and Sel_2 for the corresponding test data transmission paths in turn, opens the corresponding test data transmission paths, and outputs the test data to the TDO port.
[0045] Under the action of the Sel_2 signal, MUX3 selects the data after the second-stage inserted bit unit SIB2 is shifted or the data output from the selected test data transmission path for output.
[0046] The working process of the IJTAG security circuit proposed by the present invention is as Figure 4 shown, including: an initialization stage, a configuration stage, and a data transmission stage.
[0047] Initialization stage: Complete the initialization of the IJTAG network. When the IJTAG network starts, the initial value of all SIBs is "0", and the IJTAG network is in the initial configuration state.
[0048] Configuration stage: When accessing a specific embedded instrument is required, the TAP controller serially shifts the configuration bits into the SIB shift register through the TDI. In the shift stage, the clock signal controls the configuration bits to move bit by bit. After all the configuration bits are shifted into the shift register, the TAP controller enters the update stage and loads the configuration bits into the update unit of the SIB, thereby setting the state of the SIB and the value of the SCB. For example: In the initial state, all SIBs are closed, the embedded instrument is hidden and does not participate in the scan path. At this time, the scan path is only TDI→SIB1→SIB2→TDO; if the instrument needs to be added to the IJTAG network, it is necessary to first shift the logic "1" to the corresponding SIB, and then execute the update cycle to open the SIB. For example, if you want to open SIB3, assuming that the update unit of the scan multiplexing control bit SCB is "0" during initialization, shifting the "01" sequence to open SIB3 will change the scan chain to TDI→SIB3→SCB→SIB1→SIB2→TDO. Then shifting the configuration bits "0101" can make the embedded instrument 1 accessible.
[0049] Data transmission stage: After the configuration bits are loaded, start to transfer the information of the configuration bits to the configuration bit register. When the configuration bit register is configured, data transmission starts. In the capture stage, the TDR reads the initial data from the embedded instrument to prepare a benchmark for subsequent operations; then, in the shift stage, the control signal output unit controls the first data selector and the second data selector according to the configuration bits, so that the TDR is connected to the TDI and TDO of the TAP, and the data is serially shifted in the TDR to achieve data loading or unloading; in the update stage, the TDR latches the newly configured data loaded in the shift register into its update register in parallel and stably outputs the data to the connected embedded instrument; at the same time, the embedded instrument immediately takes effect the new logic state according to the received updated configuration data.
[0050] The control signal output unit controls the first data selector and the second data selector according to the stored configuration bit information and selects the embedded instrument corresponding to the configuration bit. When and only when a configuration bit register is "1", the TDR for reading and writing the corresponding embedded instrument is selected for loading / unloading test / function data. During the test data transmission process, the shift enable signal of the TDR for the read / write operation of the selected embedded instrument remains active, and the shift enable signals of the TDRs for the read / write operations of other embedded instruments are gated to ensure that the states of other embedded instruments remain unchanged when the TDR of the selected embedded instrument loads / unloads data.
[0051] If multiple embedded instruments need to be accessed simultaneously, according to the order of the configuration register addresses from high to low, the above data transmission operations are performed on each embedded instrument in turn. If there are multiple "1"s in the configuration bits, that is, when multiple SIBs are opened, the state control machine in the transmission path control signal generator will traverse the registers storing the configuration bits in the order of the register addresses of the configuration bits from high to low, and select the corresponding embedded instruments in turn for data transmission. During data transmission, the control signal output unit dynamically generates control signals to select the data path of the embedded instrument, keeps the data selector control unchanged within the TDR length of shift cycles to load / unload test data / responses, and then selects the next embedded instrument for operation in sequence until all embedded instruments complete data transmission.
[0052] Through the above data transmission control method, it is ensured that the test data is only transmitted through the TDR for reading and writing the embedded instrument, avoiding the data passing through other potentially malicious embedded instruments, thereby effectively preventing the data from being sniffed or tampered with.
[0053] The IJTAG network can dynamically configure the scan path according to different test requirements and select different embedded instruments for testing / accessing. Throughout the process, due to the strict control of the data transmission path, even if the network configuration changes, malicious embedded instruments cannot intervene in the data transmission process, ensuring the security and integrity of the data.
[0054] Through the above specific implementation manners, the present invention can effectively protect data from sniffing and tampering attacks in the actual IJTAG network, while maintaining the flexibility and low overhead characteristics of the network, providing a reliable security guarantee for the testing and debugging of integrated circuits.
[0055] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above specific embodiments, and the above specific embodiments and the descriptions in the specification are only for further explaining the principles and preparation effects of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope claimed by the present invention. The scope claimed by the present invention is defined by the claims and their equivalents.
Claims
1. An IJTAG security circuit, characterized in that, For selecting a test data transmission path from an embedded instrument unit and outputting test response data, including: A test access port module, configured to provide a test data input port, a test clock input port, a test mode selection signal input port, a reset signal input port, a test data output port, provide a state transition control signal for a configuration bit information generation unit during a configuration cycle, and provide a state transition control signal for a selected test data transmission path during a data transmission cycle; A configuration bit information generation unit, configured to provide a scan network for capturing, shifting, and updating configuration bit data from a TDI port during a configuration cycle, and generate configuration bit information for an embedded register; A control signal output unit, configured to dynamically manage a test data transmission path according to the configuration bit information, and generate a test data transmission path control signal and a test data output signal; and, A third data selector, whose 0 input terminal is connected to the test data output by the scan network provided by the configuration bit information generation unit, whose 1 input terminal is connected to the test data output by the selected test data transmission path, and whose data selection terminal is connected to the test data output signal. During a configuration cycle, it selects the test data output by the scan network provided by the configuration bit information generation unit as test response data, and during a data transmission cycle, it selects the test data output by the selected test data transmission path as test response data. The test response data is then transmitted to the test data output port.
2. The IJTAG security circuit according to claim 1, wherein The embedded instrument unit: includes four test data transmission paths, a first data selector, and a second data selector. The input terminal of the first data selector receives test data from the test data input port. A test data transmission path is connected between one output terminal of the first data selector and one input terminal of the second data selector. The output terminal of the second data selector is connected to the 1 input terminal of the third data selector. Each test data transmission path consists of an embedded instrument and a test data register read and written by it.
3. The IJTAG security circuit according to claim 2, characterized in that, The configuration bit information generation unit includes: A first-stage insertion bit unit, which selects, according to the update data of its previous configuration cycle, the configuration bit data from the test data input port or the shift data of the next-stage insertion bit unit in the current configuration cycle as the operation data of the current configuration cycle, and captures, shifts, and updates the operation data of the current configuration cycle; A third-stage insertion bit unit, which captures, shifts, and updates the configuration bit data from the test data input port when the update data of the first-stage insertion bit unit in the current configuration cycle is 1; A fourth-stage insertion bit unit, which captures, shifts, and updates the configuration bit data from the test data input port when the update data of the first-stage insertion bit unit in the current configuration cycle is 1; A first AND gate, whose first input terminal receives the update data of the first-stage insertion bit unit in the current configuration cycle, and whose second input terminal is connected to the update data of the third-stage insertion bit unit in the current configuration cycle, and outputs the configuration bit information of the first embedded register; A second AND gate, whose first input terminal receives the updated data of the current configuration cycle of the first segment insertion bit unit, and whose second input terminal receives the updated data of the current configuration cycle of the fourth segment insertion bit unit, and outputs the configuration bit information of the second embedded register; A data selector, whose input terminal 0 accesses the shifted data of the current configuration cycle of the third segment insertion bit unit, whose input terminal 1 accesses the shifted data of the current configuration cycle of the fourth segment insertion bit unit, and whose data selection terminal accesses the updated data of the current configuration cycle of the scan multiplexer control bit unit; A scan multiplexer control bit unit, which shifts and updates the output data of the data selector; A second segment insertion bit unit, which captures, shifts, and updates the shifted data of the current configuration cycle of the first segment insertion bit unit or the shifted data of the current configuration cycle of the fifth segment insertion bit unit. The shifted data of its current configuration cycle serves as the test data output by the scan network provided by the configuration information generation unit, and the updated data of its current configuration cycle is output as the configuration bit information of the third embedded register; A fifth segment insertion bit unit, when the updated data of the current configuration cycle of the first segment insertion bit unit is 0 and the updated data of the current configuration cycle of the second segment insertion bit unit is 1, captures, shifts, and updates the shifted data of the current configuration cycle of the first segment insertion bit unit, and transmits the shifted data of its current configuration cycle to the second segment insertion bit unit; and, A third AND gate, whose first input terminal receives the configuration bit information of the third embedded register, and whose second input terminal accesses the updated data of the current configuration cycle of the fifth segment insertion bit unit, and outputs the configuration bit information of the fourth embedded register.
4. The IJTAG security circuit according to claim 3, characterized in that, The control signal output unit includes: The first to fourth embedded instrument configuration registers, which are used to store the configuration bit information of the first to fourth embedded registers respectively; A counter, which is used to record the length of the test data register read and written by the embedded instrument in the selected test data transmission path, and controls the data transmission cycle; and, A state machine, which is used to sequentially traverse the configuration bit information corresponding to the selected test data transmission paths when at least two test data transmission paths are selected, and generate the control signals and test data output signals corresponding to the selected test data transmission paths in sequence.
5. The IJTAG security circuit according to claim 4, wherein The sequential traversal of the configuration bit information corresponding to the selected test data transmission paths by the state machine and output is specifically: for the configuration registers with all configuration bit information being 1, traverse the configuration bit information and output it in the order from the highest to the lowest configuration register address.
6. An integrated circuit chip, characterized in that, For secure data transmission during chip testing, debugging, and normal operation, it includes the IJTAG security circuit described in any one of claims 1 to 5.
7. An electronic device, characterized in that, An integrated circuit chip including the integrated circuit chip described in claim 6, and the electronic device includes but is not limited to smartphones, tablet computers, industrial control devices, automotive electronic devices, and aerospace devices.