Debug Port Controller Authentication for Semiconductor Memory Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Semiconductor memory debug ports pose a risk of internal function analysis by third parties, as they are not effectively secured before shipment, potentially allowing unauthorized access and data extraction.

Innovation Solution

A debug port controller is implemented within the semiconductor memory, which blocks communication paths unless an authentication request with a matching authentication code is received, using a communication blocker and timer to ensure secure operation by disabling the debug port until authentication is successful.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the debug port is provided to enable function verification during performance evaluation, then the verification capability is improved, but the security risk increases due to potential unauthorized access by third parties

Engineering Contradiction:
Improvefunction verification capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by implementing an authentication mechanism before enabling the debug port. The system performs authentication verification in advance (during power-on or reset) to determine whether the debug port should be enabled, thereby preventing unauthorized access while maintaining verification capability for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing an authentication code as a mediator between the debug port and external devices. The authentication code acts as a gatekeeper that verifies the identity of devices attempting to access the debug port, allowing function verification while blocking unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the debug port is disabled before shipment to prevent third-party analysis, then the security is improved, but the function verification capability is lost during development and evaluation phases

Engineering Contradiction:
Improvethird-party analysis preventionVSAvoidfunction verification capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the debug port's enabled/disabled state changeable based on authentication results. Instead of a fixed disabled state, the system dynamically adjusts the debug port's availability according to the authentication verification outcome, allowing it to be enabled for authorized devices during development and disabled for unauthorized access after shipment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent uses parameter changes by modifying the debug port's operational state based on authentication status. The system changes the enabled/disabled parameter of the debug port according to the authentication verification result, thereby adapting the verification capability to different usage scenarios while maintaining security.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If authentication verification is performed every time the semiconductor memory is activated, then the security is improved, but the time consumption increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies continuity of useful action by implementing authentication verification at multiple critical points (power-on and reset) to ensure continuous security protection. This repeated verification ensures that unauthorized access is prevented while maintaining efficient operation by verifying authentication status at key system activation moments.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20240094286A1Memory, memory system and method of controlling storage device
Publication Date: 2024.03.21 KIOXIA CORP
  • US20240094286A1 patent drawing
  • US20240094286A1 patent drawing
  • US20240094286A1 patent drawing

AI summary

A memory having a first authentication code includes a communication port configured to transmit information including debug data to or receive the information including debug data from the external device; and a debug port controller that is usable for blocking of a communication path connecting to the communication port. The debug port controller is configured to receive an authentication request including a second authentication code from an external device, determine whether the second authentication code matches the first authentication code, and block the communication path if the second authentication code is not determined to match the first authentication code. The communication port may be configured to be disabled until the second authentication code matches the first authentication code.