OTP Bit Access Control for Secure IC Debug Re-Enablement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrated circuit devices face challenges in securely enabling and disabling development and troubleshooting features after deployment to facilitate post-deployment testing and evaluation while preventing unauthorized access.

Innovation Solution

The use of multiple one-time programmable (OTP) bits, decode logic, and a control element to control access to protected resources, allowing for multiple instances of enabling and disabling access to evaluation and testing components, including trace capabilities, Built In Self Test (BIST), JTAG, and custom hardware features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple OTP bits are used to control access to evaluation and testing components, then the ability to re-enable debugging features post-deployment is improved, but the device complexity increases

Engineering Contradiction:
Improveability to re-enable debugging featuresVSAvoidcontrol mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control mechanism is segmented into multiple independent OTP bits (at least two bits) that can be individually programmed. Each bit represents a discrete control element that can be set to different states (0 or 1), allowing for multiple access states (enabled, disabled, re-enabled) without requiring a single complex control structure. This segmentation enables flexible post-deployment debugging while maintaining a relatively simple overall device architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If OTP bits are used to guard evaluation and testing components, then security against unauthorized access is improved, but the ease of operation for legitimate debugging is reduced

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidaccess control for debugging
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The access control system transitions from a static single-state control to a dynamic multi-state control using multiple OTP bits. The system can dynamically switch between different access states (enabled, disabled, re-enabled) by programming different combinations of OTP bits. This dynamic approach maintains strong security through OTP's one-time programming nature while enabling legitimate debugging operations when needed by authorized users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of access control from a binary enabled/disabled state to a multi-state system using at least two OTP bits. By varying the combination of OTP bit values (0 or 1), the system creates multiple distinct access states. This parameter expansion allows the system to maintain security (through OTP's irreversible programming) while providing operational flexibility for legitimate debugging scenarios.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If development and troubleshooting features are permanently disabled after deployment, then security is improved, but the ability to perform post-deployment testing and evaluation is lost

Engineering Contradiction:
Improvesecurity of deployed deviceVSAvoidpost-deployment testing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary action by pre-configuring multiple OTP bits in a specific state pattern that enables post-deployment debugging capability. During manufacturing or initial setup, the OTP bits are programmed with a pattern (e.g., specific combinations of 0s and 1s) that allows authorized users to later re-enable debugging features when needed. This preliminary configuration maintains security during normal operation while preserving the ability to perform post-deployment testing and evaluation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10424389B2Integrated circuit device using multiple one-time programmable bits to control access to a resource
Publication Date: 2019.09.24 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US10424389B2 patent drawing
  • US10424389B2 patent drawing

AI summary

An integrated circuit device that utilizes multiple OTP bits to enable and re-enable access to evaluation and testing components comprises a set of multiple one-time programmable (OTP) bits, a programming module operable to trigger a change in each bit of the set of multiple OTP bits, decode logic to determine a value for a collective state of the set of multiple OTP bits, and a control element to control access to at least one resource of the integrated circuit device based on a value of the collective state for the set of multiple OTP bits.