JTAG Security Fuse Array for Integrated Circuit Tamper Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuits with programmable fuses face challenges in preventing unauthorized tampering and reconfiguration of features, as existing mechanisms allow unauthorized users to enable or disable security features using JTAG operations.

Innovation Solution

An apparatus and method within the integrated circuit that includes a JTAG control chain, feature fuse, level sensor, access controller, and blow controller to prevent unauthorized JTAG operations by monitoring external voltage signals and blowing fuses only when enabled, ensuring that extended JTAG operations are restricted unless authorized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If extended JTAG operations are enabled for field programmability, then ease of operation is improved, but security against unauthorized tampering deteriorates

Engineering Contradiction:
Improvefield programmabilityVSAvoidunauthorized tampering
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a security fuse that is blown in advance during manufacturing or initial setup to permanently disable extended JTAG operations. This preliminary action prevents unauthorized tampering before it can occur, while still allowing legitimate field programmability through standard JTAG operations. The security fuse creates an irreversible barrier that stops unauthorized users from reconfiguring security-critical features.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security fuse as an intermediary element between the JTAG interface and the fuse array. This intermediary component acts as a gatekeeper that controls access to extended JTAG operations. When the security fuse is intact, it blocks unauthorized access attempts; when blown (by authorized personnel), it allows legitimate reconfiguration. This intermediary mechanism resolves the contradiction by providing controlled access rather than complete openness or total closure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If security features are permanently disabled through fuse blowing, then security against unauthorized access is improved, but adaptability for authorized reconfiguration deteriorates

Engineering Contradiction:
Improveunauthorized accessVSAvoidauthorized reconfiguration
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent divides the fuse system into two distinct segments: security fuses and functional fuses. Security fuses are dedicated to preventing unauthorized access and, once blown, permanently disable extended JTAG operations. Functional fuses control individual features and can be reconfigured through standard JTAG operations. This segmentation allows the system to maintain both strong security (through irreversible security fuse blows) and adaptability (through reversible functional fuse operations).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a dynamic security model where the system transitions between different operational states based on the state of the security fuse. When the security fuse is intact, the system operates in a restricted mode with enhanced security. When the security fuse is blown by authorized personnel, the system transitions to a reconfiguration mode that allows temporary or permanent disabling of features. This dynamic approach enables the system to adapt its security posture and functionality based on authorized actions while maintaining protection against unauthorized access.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8429471B2Microprocessor apparatus and method for securing a programmable fuse array
Publication Date: 2013.04.23 VIA TECH INC
  • US8429471B2 patent drawing
  • US8429471B2 patent drawing
  • US8429471B2 patent drawing

AI summary

An apparatus for precluding the use of extended JTAG operations, including a JTAG control chain, a feature fuse, a level sensor, an access controller, and a blow controller. The JTAG control chain enables/disables the extended JTAG operations. The feature fuse indicates whether the extended JTAG features are to be disabled. The level sensor monitors an external voltage signal, and indicates that the external voltage signal is at a legal level. The access controller determines if the feature fuse is blown, and directs the JTAG control chain to disable the extended JTAG operations if the feature fuse is blown, and directs the JTAG control chain to disable the extended JTAG operations if the external voltage signal is at an illegal level regardless of whether the feature fuse is blown. The blow controller receives a voltage, and blows a selected fuse within a fuse array responsive to a valve of the voltage.