JTAG I/O Network Encryption for IC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current integrated circuits (ICs) lack protection for their input/output (I/O) pins, making them vulnerable to attacks such as satisfiability and key sensitization attacks, which can compromise the security of the IC's internal logic even when countermeasures like obfuscation are employed.
Innovation Solution
The proposed solution involves encrypting I/O data using a seeding key generated during the start-up phase, shared between ICs through a linear-feedback shift register and managed by a key management unit, with encryption and decryption handled by modules within the JTAG block, ensuring secure communication and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If I/O pins are left unprotected for ease of operation, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces an encryption module as an intermediary between the I/O pins and the external environment. This module encrypts data before it leaves the I/O pins and decrypts incoming data, allowing the I/O pins to remain easily accessible while protecting the internal logic through cryptographic transformation
Solution Approach 2:
The patent implements preliminary key generation and distribution before the IC becomes operational. A seeding key is generated during manufacturing and distributed to authorized systems in advance, enabling secure encryption to be immediately active when the IC starts operating without compromising security during setup
2Reliability
If encryption modules are added to protect I/O pins, then security is improved, but device complexity is worsened
Solution Approach 1:
The encryption module is designed to handle multiple I/O pins simultaneously using a single cryptographic engine. The same encryption/decryption logic serves all boundary scan chain cells and data paths, eliminating the need for separate encryption circuits for each pin and reducing overall device complexity
Solution Approach 2:
The patent uses parameter-based security where a single seeding key parameter controls the encryption state of multiple data paths. By changing the key parameter rather than restructuring the circuit, the system achieves high security with minimal additional hardware complexity
3Reliability
If key management procedures are implemented for secure communication, then security is improved, but loss of time is worsened
Solution Approach 1:
The seeding key is generated and distributed during the manufacturing or initialization phase, before the IC begins normal operation. This preliminary key establishment eliminates the need for time-consuming key exchange protocols during runtime, as the key is already in place when secure communication begins
Solution Approach 2:
The encryption module automatically uses the pre-loaded seeding key for all encryption operations without requiring external key management intervention. The system serves itself by autonomously applying the key to encrypt outgoing data and decrypt incoming data, eliminating delays associated with manual key management
Data Source
AI summary
An integrated circuit includes, in part, a key management unit configured to generate a seeding key during a start-up phase, an encryption module configured to encrypt data using the seeding key and deliver the encrypted data to a second integrated circuit, and an encoder configured to encode the seeding key and deliver the encoded seeding key to the second IC. The second integrated circuit includes, in part, a decoder configured to decode the seeding key. Each of the integrated circuits further includes, in part, a linear-feedback shift register that receives the same clock signals and loads the seeding key.


