Hidden Scan Path Segment for Proprietary Embedded Instrument Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access mechanisms for embedded instruments in ICs, such as those based on the IEEE 1149.1 and 1687 standards, do not effectively hide private instruments from unauthorized access, as the documentation of these instruments can attract attention and curiosity, leading to potential exploitation of undocumented bits and functions.
Innovation Solution
A network of storage units with a data path, gateway storage unit, and key storage units is implemented, where key signals unlock data path segments, and trap storage units prevent unauthorized access by locking the gateway storage unit, using locked SIB gateways, key bit-cells, and trap bit-cells to create a hidden scan path segment for private instruments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If private instruments are documented in the access network, then ease of operation is improved, but security is worsened as unauthorized access becomes possible
Solution Approach 1:
The access network is segmented into public and private portions. Private instruments are placed in a hidden scan path segment that is separated from the main accessible network. This segmentation allows public instruments to remain accessible while private instruments are isolated and protected from unauthorized access.
Solution Approach 2:
A gateway storage unit acts as an intermediary between the public access network and private instruments. The gateway controls access to the hidden scan path segment by validating key signals from key storage units. This intermediary mechanism enables authorized access while blocking unauthorized users.
2Object-affected harmful factors
If key storage units and gateway mechanisms are implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The private instruments are nested within the existing JTAG scan path architecture. The hidden scan path segment is inserted into the data path using the existing TAP controller infrastructure. This nesting approach allows the security mechanism to be integrated within the standard access network rather than requiring a completely separate system.
Solution Approach 2:
The gateway storage unit and key storage units serve multiple functions: they control access to private instruments, validate authorization, and integrate with the existing JTAG protocol. The key signals are transmitted through the standard data path, allowing the security mechanism to reuse existing infrastructure rather than requiring dedicated separate channels.
3Object-affected harmful factors
If hidden scan path segments are created for private instruments, then security is improved, but ease of operation is worsened as access requires specific key values
Solution Approach 1:
The system provides self-service authentication where the key storage units automatically provide key signals to the gateway when the correct key values are present. The gateway automatically validates these keys and controls the insertion of the hidden scan path segment without requiring manual intervention or complex authentication procedures.
Data Source
AI summary
A network of storage units has a data path which is at least a portion of the network. The network also has a key storage unit and a gateway storage unit. If the key storage unit stores a key value, the key storage unit transmits a key signal to the gateway storage unit. If the gateway storage unit does not store a gateway value or the key signal is not transmitted to the gateway storage unit, the gateway storage unit does not insert a data path segment in the data path. If the gateway storage unit stores a gateway value and the key signal is transmitted to the gateway storage unit, the gateway storage unit inserts the data path segment.


