OTP Bit Access Control for Secure IC Debug Re-Enablement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuit devices face challenges in securely enabling and disabling development and troubleshooting features after deployment to facilitate post-deployment testing and evaluation while preventing unauthorized access.
Innovation Solution
The use of multiple one-time programmable (OTP) bits, decode logic, and a control element to control access to protected resources, allowing for multiple instances of enabling and disabling access to evaluation and testing components, including trace capabilities, Built In Self Test (BIST), JTAG, and custom hardware features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple OTP bits are used to control access to evaluation and testing components, then the ability to re-enable debugging features post-deployment is improved, but the device complexity increases
Solution Approach 1:
The access control mechanism is segmented into multiple independent OTP bits (at least two bits) that can be individually programmed. Each bit represents a discrete control element that can be set to different states (0 or 1), allowing for multiple access states (enabled, disabled, re-enabled) without requiring a single complex control structure. This segmentation enables flexible post-deployment debugging while maintaining a relatively simple overall device architecture.
2Reliability
If OTP bits are used to guard evaluation and testing components, then security against unauthorized access is improved, but the ease of operation for legitimate debugging is reduced
Solution Approach 1:
The access control system transitions from a static single-state control to a dynamic multi-state control using multiple OTP bits. The system can dynamically switch between different access states (enabled, disabled, re-enabled) by programming different combinations of OTP bits. This dynamic approach maintains strong security through OTP's one-time programming nature while enabling legitimate debugging operations when needed by authorized users.
Solution Approach 2:
The system changes the parameter of access control from a binary enabled/disabled state to a multi-state system using at least two OTP bits. By varying the combination of OTP bit values (0 or 1), the system creates multiple distinct access states. This parameter expansion allows the system to maintain security (through OTP's irreversible programming) while providing operational flexibility for legitimate debugging scenarios.
3Reliability
If development and troubleshooting features are permanently disabled after deployment, then security is improved, but the ability to perform post-deployment testing and evaluation is lost
Solution Approach 1:
The system performs preliminary action by pre-configuring multiple OTP bits in a specific state pattern that enables post-deployment debugging capability. During manufacturing or initial setup, the OTP bits are programmed with a pattern (e.g., specific combinations of 0s and 1s) that allows authorized users to later re-enable debugging features when needed. This preliminary configuration maintains security during normal operation while preserving the ability to perform post-deployment testing and evaluation.
Data Source
AI summary
An integrated circuit device that utilizes multiple OTP bits to enable and re-enable access to evaluation and testing components comprises a set of multiple one-time programmable (OTP) bits, a programming module operable to trigger a change in each bit of the set of multiple OTP bits, decode logic to determine a value for a collective state of the set of multiple OTP bits, and a control element to control access to at least one resource of the integrated circuit device based on a value of the collective state for the set of multiple OTP bits.

