JTAG Port State Detection for Trusted Security Zone Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network-capable electronic devices are vulnerable to hacking attacks through enabled JTAG ports, which can lead to unauthorized access and data theft, as manufacturers often leave these ports enabled intentionally or accidentally, making it difficult for service providers and users to ensure device reliability.

Innovation Solution

A method is implemented to determine the state of the JTAG port on a portable electronic device, configuring a trusted security zone only if the port is disabled, and preventing configuration or execution of trusted applications if the port is enabled, thereby reducing vulnerability to hacking attacks by generating a JTAG port inspected certificate and storing it in secure memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the JTAG port is left enabled for debugging and manufacturing purposes, then ease of operation and manufacturing are improved, but device security and reliability deteriorate due to vulnerability to hacking attacks

Engineering Contradiction:
Improvedebugging accessVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary detection of the JTAG port state during device initialization or before executing sensitive operations. By checking whether the JTAG port is enabled beforehand, the system can proactively prevent potential security breaches by refusing to execute trusted applications or access sensitive functions when the port is found to be enabled, thus resolving the contradiction between maintaining debugging accessibility and ensuring device security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the JTAG port is disabled to improve security, then device security is improved, but ease of manufacture and debugging capability deteriorate

Engineering Contradiction:
Improvedevice securityVSAvoiddebugging access
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Rather than statically disabling the JTAG port, the system dynamically adjusts its behavior based on the detected JTAG port state. When the port is enabled, the system applies security restrictions; when disabled, normal operations proceed. This dynamic approach allows the device to maintain manufacturing and debugging capabilities when needed while automatically enforcing security when the port remains enabled, resolving the contradiction between security and manufacturability.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If trusted applications are allowed to execute on devices with enabled JTAG ports, then application functionality is improved, but vulnerability to hacking attacks increases

Engineering Contradiction:
Improveapplication executionVSAvoidhacking vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism that continuously monitors the JTAG port state and adjusts application execution permissions accordingly. Before executing trusted applications, the system checks the JTAG port status and provides feedback control by either allowing or blocking execution based on this status. This feedback loop ensures that applications can execute when the device is secure (JTAG disabled) while preventing execution when vulnerability exists (JTAG enabled), thus resolving the contradiction between functionality and security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9021585B1JTAG fuse vulnerability determination and protection using a trusted execution environment
Publication Date: 2015.04.28 T MOBILE INNOVATIONS LLC
  • US9021585B1 patent drawing
  • US9021585B1 patent drawing
  • US9021585B1 patent drawing

AI summary

A method of configuring a trusted security zone into a portable electronic device. The method comprises executing instructions on a processor of the portable electronic device that determine the state of a JTAG (JTAG) port of the portable electronic device, if the JTAG port is determined to be enabled, executing instructions on the processor preventing configuration of the trusted security zone into the portable electronic device, and if the JTAG port is determined to be disabled, configuring the trusted security zone into the portable electronic device, whereby a vulnerability to hacking the trusted security zone via an enabled JTAG port is reduced.