JTAG I/O Network Encryption for IC Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current integrated circuits (ICs) lack protection for their input/output (I/O) pins, making them vulnerable to attacks such as satisfiability and key sensitization attacks, which can compromise the security of the IC's internal logic even when countermeasures like obfuscation are employed.

Innovation Solution

The proposed solution involves encrypting I/O data using a seeding key generated during the start-up phase, shared between ICs through a linear-feedback shift register and managed by a key management unit, with encryption and decryption handled by modules within the JTAG block, ensuring secure communication and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If I/O pins are left unprotected for ease of operation, then ease of operation is improved, but security is worsened

Engineering Contradiction:
ImproveI/O pin accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an encryption module as an intermediary between the I/O pins and the external environment. This module encrypts data before it leaves the I/O pins and decrypts incoming data, allowing the I/O pins to remain easily accessible while protecting the internal logic through cryptographic transformation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary key generation and distribution before the IC becomes operational. A seeding key is generated during manufacturing and distributed to authorized systems in advance, enabling secure encryption to be immediately active when the IC starts operating without compromising security during setup

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption modules are added to protect I/O pins, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption module is designed to handle multiple I/O pins simultaneously using a single cryptographic engine. The same encryption/decryption logic serves all boundary scan chain cells and data paths, eliminating the need for separate encryption circuits for each pin and reducing overall device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses parameter-based security where a single seeding key parameter controls the encryption state of multiple data paths. By changing the key parameter rather than restructuring the circuit, the system achieves high security with minimal additional hardware complexity

Inventive Principle:
Principle #35Parameter changes

3Reliability

If key management procedures are implemented for secure communication, then security is improved, but loss of time is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidkey synchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The seeding key is generated and distributed during the manufacturing or initialization phase, before the IC begins normal operation. This preliminary key establishment eliminates the need for time-consuming key exchange protocols during runtime, as the key is already in place when secure communication begins

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption module automatically uses the pre-loaded seeding key for all encryption operations without requiring external key management intervention. The system serves itself by autonomously applying the key to encrypt outgoing data and decrypt incoming data, eliminating delays associated with manual key management

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11856096B2Defense of JTAG I/O network
Publication Date: 2023.12.26 UNIV OF FLORIDA RESEARCH FOUNDATION INC
  • US11856096B2 patent drawing
  • US11856096B2 patent drawing
  • US11856096B2 patent drawing

AI summary

An integrated circuit includes, in part, a key management unit configured to generate a seeding key during a start-up phase, an encryption module configured to encrypt data using the seeding key and deliver the encrypted data to a second integrated circuit, and an encoder configured to encode the seeding key and deliver the encoded seeding key to the second IC. The second integrated circuit includes, in part, a decoder configured to decode the seeding key. Each of the integrated circuits further includes, in part, a linear-feedback shift register that receives the same clock signals and loads the seeding key.