JTAG Interface Security for Microcontroller Digital Quantities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
JTAG interfaces in microcontrollers pose a security risk by allowing potential access to sensitive digital quantities like encryption keys, as they provide a pathway for external access to internal data, and existing solutions require significant hardware resources or can be bypassed by unauthorized users.
Innovation Solution
Implementing a protection mechanism that makes digital quantities stored in microcontrollers dependent on a parameter accessible only when the JTAG interface is not in use, using a multiplexer to select between a hidden and a debilitated key value based on the JTAG interface's operating mode, ensuring secure key generation and access control without modifying the JTAG interface's functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a JTAG interface is provided for testing and access, then ease of operation and testing capability are improved, but security against unauthorized access to digital quantities deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism (the dependency relationship between the digital quantity and the parameter) that mediates between the JTAG interface access and the protected digital quantity. The parameter acts as a gatekeeper that must have correct values for the digital quantity to be accessible, thereby preventing direct unauthorized access while allowing legitimate testing through proper authentication of the parameter values.
Solution Approach 2:
The patent changes the state or value of the parameter based on the operational mode (normal operation versus test mode). During normal operation, the parameter has values that enable access to the digital quantity, while during test mode, the parameter values are changed to prevent access, thus dynamically adjusting security based on operational context.
2Object-affected harmful factors
If existing protection mechanisms are implemented, then security is improved, but device complexity and hardware resources increase
Solution Approach 1:
The patent makes the existing parameter serve multiple functions: it continues to control the operational mode (normal vs. test mode) while simultaneously providing security protection for the digital quantity. This multi-functionality avoids the need for separate dedicated security hardware, thereby maintaining simplicity while improving security.
Solution Approach 2:
The system uses its own existing parameter and operational structure to provide security protection, rather than requiring external or additional dedicated security mechanisms. The parameter's inherent role in controlling operational modes is leveraged to also control access to digital quantities, making the system self-protecting without additional hardware overhead.
Data Source
AI summary
A method and a circuit for protecting a digital quantity stored in a microcontroller including a JTAG interface, including the step of making the digital quantity dependent from a value stored in non-volatile fashion in the microcontroller and made inaccessible if signals are present at the input of the JTAG interface.


