Boot Device Controls Unidirectional State Transition for Secure IC Diagnosis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuit devices deployed with proprietary or confidential software face challenges in diagnosis and repair, as enabling access to programming circuitry for diagnosis risks unauthorized access and security vulnerabilities, such as 'break once, read everywhere' attacks.

Innovation Solution

A programmable integrated circuit device with a one-time programmable memory module and a boot device that controls life cycle states, allowing authorized unidirectional advancement from an operational state to an inspection state, using authenticated credentials and unique identifiers to prevent unauthorized access, and employing a secure boot mechanism to lock and unlock access during specific time intervals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If access to programming circuitry is enabled for diagnosis, then diagnostic capability is improved, but security is worsened due to risk of unauthorized access and 'break once, read everywhere' attacks

Engineering Contradiction:
Improvediagnostic capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication and authorization actions before enabling diagnostic access. The boot device verifies credentials and authorizes state transitions in advance, ensuring that only authenticated entities can access programming resources during the inspection state.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a boot device as an intermediary between the diagnostic entity and the programming resources. This boot device controls the life cycle state transitions and mediates access requests, preventing direct unauthorized access to programming circuitry while enabling controlled diagnostic access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If programming resources are locked in operational state, then security is improved, but diagnostic access is worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoiddiagnostic access
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The system dynamically transitions between operational state and inspection state based on authenticated requests. The lock control circuit responds to control signals from the boot device to authorize unidirectional advancement from operational to inspection state, providing conditional access rather than static locking.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The boot device outputs control signals during specific time intervals (boot cycles) to authorize state transitions. The time interval may be coterminous with the boot cycle or offset by predetermined times, creating periodic windows for authorized diagnostic access.

Inventive Principle:
Principle #19Periodic action

3Ease of repair

If unidirectional state advancement is authorized, then diagnostic access is improved, but permanent state change risk is worsened

Engineering Contradiction:
Improveinspection accessVSAvoidstate control
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The lock control circuit provides feedback by monitoring control signals from the boot device and responding by authorizing or denying state transitions. This feedback mechanism ensures that state advancements are properly authorized and tracked, maintaining reliability while enabling inspection access.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11698974B1Method and apparatus for authorizing unlocking of a device
Publication Date: 2023.07.11 MARVELL ASIA PTE LTD
  • US11698974B1 patent drawing
  • US11698974B1 patent drawing
  • US11698974B1 patent drawing

AI summary

A programmable integrated circuit device includes a programmable core, a boot device configured to boot up the programmable core, and a one-time programmable memory module controlling life cycle states of the programmable integrated circuit device, including (i) an operational state during which programming resources of the programmable device are locked, and (ii) an inspection state in which the programming resources of the programmable device are accessible. The one-time programmable memory module is configured to allow unidirectional advance from the operational state to the inspection state, when authorized by a lock control circuit responsive to control signals from the boot device to authorize the unidirectional advance from the operational state to the inspection state. Authorization of the unidirectional advance may be limited to a time interval during a boot cycle of the programmable device. The unidirectional advance may be based on receipt of an authenticated request from a requester.