OTP Memory Firmware Security for Integrated Circuits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System-on-a-chip (SoC) integrated circuits face security vulnerabilities due to test interfaces that can be exploited by attackers to access and modify firmware, leading to unauthorized access and data breaches, especially in devices like DVD players and hard disk drives.

Innovation Solution

Incorporating a processor with one-time-programmable (OTP) memories and a descrambler, where the boot code enables or disables the test interface and programmability based on OTP memory programming, and verifies digital signatures of firmware, ensuring secure loading and execution of firmware, even if the test interface is accessed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a test interface is provided for debugging and testing, then ease of operation is improved, but security is worsened due to potential unauthorized access

Engineering Contradiction:
Improvedebugging and testing capabilityVSAvoidunauthorized access to firmware
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by programming the OTP memory before the device is deployed to the field. This pre-programming establishes security credentials that will control test interface access in advance, preventing unauthorized access before it can occur. The security mechanism is prepared beforehand rather than reacting to threats after they arise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The OTP memory serves as an intermediary component between the test interface and the firmware. It acts as a security gatekeeper that verifies credentials before allowing the test interface to access or modify firmware, thus mediating the interaction and preventing direct unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If firmware is stored in external memory, then device complexity is reduced, but security is worsened due to potential monitoring and data theft

Engineering Contradiction:
Improveintegrated circuit structureVSAvoidfirmware monitoring and data theft
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The OTP memory acts as an intermediary security layer between the external memory and the processor. It controls and verifies access to the external memory, preventing unauthorized monitoring or data theft while still allowing the processor to access firmware when credentials are valid.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces physical security measures with cryptographic verification. Instead of relying on physical protection of external memory, it uses OTP-stored credentials and cryptographic verification mechanisms to secure firmware access, substituting mechanical/security hardware approaches with software-based security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Object-affected harmful factors

If OTP memory is programmed with security credentials, then security is improved, but ease of repair is worsened due to restricted test interface access

Engineering Contradiction:
Improveunauthorized firmware accessVSAvoidtest interface accessibility
Core Design Contradiction:
Object-affected harmful factorsVSEase of repair

Solution Approach 1:

The system dynamically controls test interface accessibility based on OTP credential verification. The test interface is not statically enabled or disabled, but rather its access rights are dynamically determined by whether valid credentials are presented, allowing flexibility between security and repair needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the access parameters of the test interface based on OTP verification results. When credentials are valid, the test interface operates with full access; when invalid, access is restricted. This parameter change approach allows the same interface to serve both security and repair functions under different conditions.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8751786B1Method and integrated circuit for loading and executing firmware based on programing of one-time programmable memory
Publication Date: 2014.06.10 MARVELL ASIA PTE LTD
  • US8751786B1 patent drawing
  • US8751786B1 patent drawing
  • US8751786B1 patent drawing

AI summary

An integrated circuit includes a first memory, a second memory, a processor, and a descrambler. The first memory is configured to store a key. The first memory is a one-time-programmable memory. The processor is configured to: determine whether the first memory has been programmed; and in response to the first memory not having been programmed, (i) load firmware from a third memory into the second memory, and (ii) execute the firmware. The third memory is separate from the integrated circuit. The processor is also configured to, in response to the first memory having been programmed, load the firmware from the third memory into the second memory. The descrambler is configured to, in response to the first memory having been programmed, descramble the firmware based on the key.