FPGA chip with protected JTAG interface
The FPGA chip integrates control and detection logic to secure the JTAG interface, preventing unauthorized access and ensuring secure testing by dynamically enabling/disabling the interface and detecting abnormal signals, enhancing security in network switching equipment.
Patent Information
- Application Number
- DE102022109122
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-09-23
- Filing Date
- 2022-04-13
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2042-04-13
AI Technical Summary
Existing FPGA chips face vulnerabilities in their JTAG interfaces, making them susceptible to unauthorized access and manipulation, which can compromise the security of network switching equipment during testing and debugging, necessitating physical removal of the JTAG header and causing maintenance issues.
Implementing a control logic block and detection logic block within the FPGA chip to dynamically enable or disable the JTAG interface via an I/O pin, coupled with external control, and monitoring JTAGEN and TCK signals for abnormal activities to prevent unauthorized access, coupled with circuit board design features to secure the detection logic.
The solution effectively protects the JTAG interface from unauthorized access, maintaining system security without physical removal, allowing controlled access for legitimate testing and debugging while detecting and responding to intrusion attempts.
Smart Images

Figure 00000000_0000_ABST
Abstract
Claims
[1] A field-programmable gate array (FPGA) chip (102, 502) mounted on a printed circuit board (PCB) (100, 500), comprising: a Joint Test Action Group (JTAG) interface (104) comprising a number of input / output (I / O) pins (134, 136) and an enable pin (132); a control logic block (112) coupled to the enable pin of the JTAG interface, the control logic block being operable to receive a control signal from an off-chip control unit and to control a logical value of the enable pin based on the received control signal, thereby enabling the off-chip control unit to lock or unlock the JTAG interface; and a detection logic block (106) for detecting unauthorized access to the FPGA chip, wherein an input of the detection logic is coupled to the enable pin, and wherein a conductive trace (514) coupling the input of the detection logic block and the enable pin is located on an inner layer of the circuit board, wherein an output of the control logic block and the enable pin are coupled via a conductive trace (510) located on an upper layer of the circuit board, and wherein the conductive trace comprises a removable resistor (512) to enable the control logic block to be decoupled from the FPGA chip during development of the FPGA chip. [2] The FPGA chip of claim 1, further comprising a second detection logic block (108), wherein an input of the second detection logic block is coupled to at least one I / O pin of the JTAG interface, thereby enabling detection of an abnormal signal at the at least one I / O pin. [3] The FPGA chip of claim 2, wherein the at least one I / O pin comprises a test clock (TCK) pin, and wherein the second detection logic block is configured to generate an alarm signal in response to detecting an unexpected pulse at the TCK pin. [4] The FPGA chip of claim 1, wherein the detection logic block (106) is configured to generate an alarm signal in response to detecting an unexpected transition at the enable pin. [5] The FPGA chip of claim 1, wherein the off-chip control unit is a central processing unit (CPU) and wherein the control signal includes an access key. [6] The FPGA chip of claim 5, wherein the control logic block further comprises: a comparator (408) configured to compare the access key contained in the control signal with an access key (414) stored in a memory (410) within the FPGA chip; and a logic gate (418) configured to: in response to the comparator determining that the access key contained in the control signal matches the access key stored in memory, outputting an enable signal to the enable pin to enable the JTAG interface; and in response to the comparator detecting that the access key contained in the control signal does not match the access key stored in memory, outputs a disable signal to the enable pin to disable the JTAG interface. [7] The FPGA chip of claim 6, wherein the control logic further comprises a timer (420), the timer being started in response to the comparator determining that the access key contained in the control signal matches the access key stored in the memory, and the logic gate being configured to output a disable signal to the enable pin to disable the JTAG interface in response to the timer expiring. [8] The FPGA chip of claim 1, wherein the control logic block is configured to perform one or more actions when the detection logic block detects unauthorized access to the FPGA chip. [9] The FPGA chip of claim 8, wherein the one or more actions comprise: Logging and reporting of unauthorized access; Sending a control signal to turn off one or more peripheral devices (122) coupled to the FPGA chip; Deleting an internal memory of the FPGA chip; and Turning off the FPGA chip. [10] A method for protecting a field programmable gate array (FPGA) chip (102, 502) mounted on a printed circuit board (PCB) (100, 500), comprising: Configuring the FPGA chip to include a control logic block (112) and a detection logic block (106); coupling an output of the control logic block to an enable pin (132) of a Joint Test Action Group (JTAG) interface (104) of the FPGA chip to enable the control logic block to receive a control signal from an off-chip control unit and to control a logical value of the enable pin based on the received control signal, thereby enabling the off-chip control unit to lock or unlock the JTAG interface; and Coupling an input of the detection logic block to the enable pin to detect unauthorized access to the FPGA chip, wherein a trace coupling the input of the detection logic block and the enable pin is located on an inner layer of the circuit board, wherein an output of the control logic block and the enable pin are coupled via a conductive trace (510, 514) located on an upper layer of the circuit board, the conductive trace comprising a removable resistor (512), and wherein the method further comprises removing the resistor during development of the FPGA chip to decouple the control logic block from the FPGA chip. [11] The method of claim 10, further comprising: Configuring a second detection logic block (108); and coupling an input of the second detection logic block to at least one I / O pin (134, 136) of the JTAG interface, thereby enabling detection of an abnormal signal on the at least one I / O pin. [12] The method of claim 11, wherein the at least one I / O pin comprises a test clock (TCK) pin, and wherein the method further comprises generating an alarm signal in response to the second detection logic detecting an unexpected pulse at the TCK pin. [13] The method of claim 10, further comprising generating an alarm signal in response to the detection logic block detecting an unexpected transition at the enable pin. [14] The method of claim 10, wherein the off-chip control unit is a central processing unit (CPU) and wherein receiving the control signal includes receiving an access key (414). [15] The method of claim 14, further comprising: Comparing the access key contained in the control signal with an access key stored in a memory (410) within the FPGA chip, in response to determining that the access key contained in the control signal matches the access key stored in memory, sending an enable signal to the enable pin to enable the JTAG interface; and in response to the detection that the access key contained in the control signal does not match the access key stored in the memory, generating an alarm signal. [16] The method of claim 15, further comprising: in response to determining that the access key contained in the control signal matches the access key stored in the memory, starting a timer (420); and In response to the timer expiration, send a disable signal to the enable pin to disable the JTAG interface. [17] The method of claim 10, further comprising performing one or more actions in response to the detection logic block detecting unauthorized access to the FPGA chip. [18] The method of claim 17, wherein the one or more actions comprise: Logging and reporting of unauthorized access; Sending a control signal to turn off one or more peripherals coupled to the FPGA chip; Deleting an internal memory of the FPGA chip; and Turning off the FPGA chip.
Citation Information
Patent Citations
Apparatus and method for override access to a secured programmable fuse array
US20110316583A1
Invoking and supporting device testing through audio connectors
US20130108063A1
System and apparatus for trusted and secure test ports of integrated circuit devices
US20170176530A1