JTAG Lockout Processor Multi-Channel Unlock Sequence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current JTAG security designs for programmable devices rely on complex encryption methodologies and key management, which can be cumbersome and vulnerable to malicious access, especially in closed-box environments like aircraft systems.

Innovation Solution

A JTAG lockout assembly and method that utilize a multi-channel unlock sequence across two or more unlock channels, validated by a lockout processor, to allow or disallow JTAG communication, providing secure access without encryption, using a test interface connected via a communication bus and memory registers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex encryption methodologies are used for JTAG security, then security strength is improved, but device complexity and key management burden increase

Engineering Contradiction:
ImproveJTAG securityVSAvoidencryption configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security mechanism is segmented into multiple independent unlock channels (first unlock channel, second unlock channel, etc.), each capable of receiving and processing unlock sequences independently. This segmentation allows the system to achieve robust security through multiple pathways rather than relying on a single complex encryption scheme, thereby reducing configuration complexity while maintaining or enhancing security strength.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the security parameter from complex encryption algorithms to multi-channel unlock sequences with specific timing and channel combinations. By altering the fundamental parameter of security validation from cryptographic complexity to temporal and spatial (channel) diversity, the system reduces configuration burden while maintaining security effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-channel unlock sequence validation is implemented, then security against malicious access is improved, but communication protocol complexity increases

Engineering Contradiction:
Improveprotection against malicious accessVSAvoidunlock sequence validation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The lockout processor acts as an intermediary between the test interface and the programmable device. It validates unlock sequences received through multiple channels before granting JTAG access, thereby protecting against malicious access without requiring the test interface or programmable device to implement complex validation logic themselves. This intermediary approach distributes complexity appropriately.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs periodic unlock sequences transmitted across multiple channels at specific time intervals. The lockout processor validates these periodic signals to determine legitimate access attempts. This periodic action approach simplifies validation compared to continuous complex encryption verification, as it relies on temporal patterns and channel synchronization that are easier to validate.

Inventive Principle:
Principle #19Periodic action

3Reliability

If JTAG access is restricted through lockout processor, then security is improved, but programming flexibility during production is reduced

Engineering Contradiction:
ImproveJTAG access securityVSAvoidprogramming access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary validation of unlock sequences through the lockout processor before granting JTAG access. By pre-establishing multiple valid unlock channels and sequences, the system ensures that legitimate programming operations can proceed smoothly once the correct sequence is provided, while maintaining security restrictions. This preliminary validation approach balances security with operational ease.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The lockout processor is designed with multi-functionality, serving both as a security gatekeeper and as a facilitator of legitimate programming operations. By supporting multiple unlock channels and sequence types, it provides universal access methods that accommodate different programming scenarios while maintaining unified security validation, thereby improving ease of operation without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3385736B1JTAG lockout for embedded processors in programmable devices
Publication Date: 2022.03.23 HAMILTON SUNDSTRAND CORP
  • EP3385736B1 patent drawingFigure 1
  • EP3385736B1 patent drawingFigure 2
  • EP3385736B1 patent drawingFigure 3

AI summary

A Joint Test Action Group (JTAG) communication lockout processor is disclosed. The processor is configured to generate a multi-channel unlock sequence based on an operational mode change of an operably connected programmable device, and save the unlock sequence to one or more memory registers. The processor can also receive an execution of the multi-channel unlock sequence via two or more unlock channels, determine, via an unlock logic, whether the execution of the multi-channel unlock sequence is valid, and responsive to determining that the execution of the multi-channel unlock sequence is valid, allow or disallow the JTAG communication with an embedded processor.