Non-Volatile Storage Security Circuit for Integrated Circuits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuits with non-volatile storage lack effective security measures to prevent unauthorized access and copying of proprietary program code, as current protection mechanisms can be bypassed through signal manipulation and trial-and-error attacks, and one-time fuses are limiting and difficult to debug.
Innovation Solution
A circuit that delays enabling access to non-volatile storage during initialization, checking for a lock prevent signal to determine if the storage should remain locked, using a predetermined time interval and internal lock state checks to disable read protocols via JTAG and serial port interfaces unless a valid unlock indication is received.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time fuses are used to block external access to NV storage, then security against external intrusion is improved, but debugging capability and re-programming flexibility are lost
Solution Approach 1:
The patent implements a dynamic security mechanism where the fuse can be selectively blown or preserved based on operational conditions. The fuse is not permanently activated but rather dynamically controlled through a control signal that can prevent the fuse from blowing during normal operation, allowing debugging access while maintaining security when needed.
Solution Approach 2:
The system performs preliminary actions by pre-configuring the fuse mechanism to be controllable. Before actual security threats arise, the system can prepare by controlling the fuse state based on anticipated needs for debugging or security, allowing flexible response to different operational scenarios.
2Reliability
If password/key matching techniques are employed to protect read interfaces, then access control is improved, but vulnerability to trial-and-error attacks increases
Solution Approach 1:
The system performs preliminary verification by checking the fuse state before allowing any password/key authentication attempts. If the fuse is intact, access is blocked at the hardware level before software authentication can occur, preventing trial-and-error attacks entirely. The fuse state is checked in advance to determine whether authentication mechanisms should even be activated.
Solution Approach 2:
The intact fuse serves as a preliminary anti-action mechanism that prevents authentication attempts before they can be mounted. By maintaining the fuse in an intact state, the system proactively blocks all access vectors including trial-and-error attacks, rather than merely responding to failed authentication attempts.
3Ease of operation
If access to NV storage is enabled during initialization, then programming and debugging are simplified, but security against unauthorized access is compromised
Solution Approach 1:
The system dynamically controls access based on the initialization phase and security requirements. During controlled programming operations, the fuse can be selectively blown to enable access. During normal operation, the fuse remains intact to prevent unauthorized access. This dynamic control allows the system to switch between secure and accessible states as needed.
Solution Approach 2:
The fuse acts as an intermediary mechanism between the programming interface and the NV storage. It mediates access by being selectively activated or deactivated based on whether programming operations are authorized. This intermediary provides a controlled pathway for legitimate programming while blocking unauthorized access attempts.
Data Source
AI summary
A method and apparatus for automatically securing non-volatile (NV) storage in an integrated circuit provides improved resistance to code copying and reverse-engineering attacks. External interfaces that provide read access to the NV storage are be disabled, for a predetermined time after a reset or other initialization signal is received. An internal lock state bit or key is checked as well as an external lock prevent indication. If the lock prevent indication is not received, or the internal lock state bit is already set, then the integrated circuit is operated under a locked condition, in which external access to the NV storage values is prevented. The lock prevent indication may be a signal provided during reset of the integrated circuit on a terminal that is used for another purpose after initialization of the integrated circuit.


