Boot Logic Erases Storage to Block JTAG Exploits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices are vulnerable to malicious attacks through their test and functional modes, as existing security measures fail to adequately prevent unauthorized access and data exploitation.
Innovation Solution
A system that determines the type of boot performed by the device and erases or invalidates storage and deactivates interfaces if it's a functional boot, using hardware and software techniques to prevent malicious access by restricting mode switches and disabling JTAG interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the device operates in test mode for manufacturing purposes, then the device can be thoroughly tested and validated, but the device becomes vulnerable to malicious attacks and unauthorized access
Solution Approach 1:
The patent segments the device operation into distinct modes (test mode and functional mode) with separate access control mechanisms. The test mode is activated only during manufacturing through specific boot sequences, while the functional mode operates with security measures in place. This segmentation prevents malicious entities from exploiting test mode vulnerabilities during normal operation.
Solution Approach 2:
The patent implements preliminary security measures by erasing or invalidating predetermined portions of storage and deactivating interfaces before allowing functional mode operation. This preliminary action ensures that even if test mode was previously accessed, no malicious data can persist in the storage system, thereby preventing attacks before they can occur.
2Adaptability or versatility
If the device allows mode switching between test and functional modes, then the device provides operational flexibility, but it enables unauthorized access and data exploitation
Solution Approach 1:
The patent implements dynamic control over mode switching based on the boot type detected. During functional boot, the system dynamically erases storage portions and deactivates interfaces to prevent unauthorized mode switching. This dynamic adjustment of access rights ensures that mode switching capability exists but is restricted under specific conditions to maintain data security.
3Ease of operation
If the device maintains test mode accessibility for debugging purposes, then developers can diagnose issues, but hackers can exploit this access to launch attacks
Solution Approach 1:
The patent introduces an intermediary security mechanism that detects boot types and mediates access to test mode. During functional boot, the intermediary layer (processing logic) prevents direct access to test mode by erasing storage and deactivating interfaces. This intermediary ensures that legitimate debugging during manufacturing is preserved while blocking unauthorized access during functional operation.
4Ease of manufacture
If the device uses existing test mechanisms for manufacturing testing, then the device can be validated, but these mechanisms can be exploited by malicious entities
Solution Approach 1:
The patent extracts and isolates the test mode functionality from the functional operation mode. By detecting boot type and conditionally erasing storage portions and deactivating interfaces, the system separates the testing phase from the operational phase. This extraction ensures that test mechanisms remain available for manufacturing validation but are removed or neutralized during functional operation to prevent exploitation by malicious entities.
Data Source
AI summary
A system comprising processing logic adapted to determine a type of boot performed by the system and a storage coupled to the processing logic. The processing logic is configured to erase or invalidate a predetermined portion of the storage, and to activate or deactivate an interface by which the system is accessed, if the type of boot comprises a functional boot.


