Hidden Scan Path Segment for Proprietary Embedded Instrument Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access mechanisms for embedded instruments in ICs, such as those based on the IEEE 1149.1 and 1687 standards, do not effectively hide private instruments from unauthorized access, as the documentation of these instruments can attract attention and curiosity, leading to potential exploitation of undocumented bits and functions.

Innovation Solution

A network of storage units with a data path, gateway storage unit, and key storage units is implemented, where key signals unlock data path segments, and trap storage units prevent unauthorized access by locking the gateway storage unit, using locked SIB gateways, key bit-cells, and trap bit-cells to create a hidden scan path segment for private instruments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If private instruments are documented in the access network, then ease of operation is improved, but security is worsened as unauthorized access becomes possible

Engineering Contradiction:
Improveaccess to instrumentsVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The access network is segmented into public and private portions. Private instruments are placed in a hidden scan path segment that is separated from the main accessible network. This segmentation allows public instruments to remain accessible while private instruments are isolated and protected from unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A gateway storage unit acts as an intermediary between the public access network and private instruments. The gateway controls access to the hidden scan path segment by validating key signals from key storage units. This intermediary mechanism enables authorized access while blocking unauthorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If key storage units and gateway mechanisms are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidaccess network structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The private instruments are nested within the existing JTAG scan path architecture. The hidden scan path segment is inserted into the data path using the existing TAP controller infrastructure. This nesting approach allows the security mechanism to be integrated within the standard access network rather than requiring a completely separate system.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The gateway storage unit and key storage units serve multiple functions: they control access to private instruments, validate authorization, and integrate with the existing JTAG protocol. The key signals are transmitted through the standard data path, allowing the security mechanism to reuse existing infrastructure rather than requiring dedicated separate channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If hidden scan path segments are created for private instruments, then security is improved, but ease of operation is worsened as access requires specific key values

Engineering Contradiction:
Improveprivate instrument protectionVSAvoidaccess procedure
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system provides self-service authentication where the key storage units automatically provide key signals to the gateway when the correct key values are present. The gateway automatically validates these keys and controls the insertion of the hidden scan path segment without requiring manual intervention or complex authentication procedures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8881301B2Protection of proprietary embedded instruments
Publication Date: 2014.11.04 ASSET INTERTECH
  • US8881301B2 patent drawing
  • US8881301B2 patent drawing
  • US8881301B2 patent drawing

AI summary

A network of storage units has a data path which is at least a portion of the network. The network also has a key storage unit and a gateway storage unit. If the key storage unit stores a key value, the key storage unit transmits a key signal to the gateway storage unit. If the gateway storage unit does not store a gateway value or the key signal is not transmitted to the gateway storage unit, the gateway storage unit does not insert a data path segment in the data path. If the gateway storage unit stores a gateway value and the key signal is transmitted to the gateway storage unit, the gateway storage unit inserts the data path segment.