Remote Access Controller JTAG Reset State Unauthorized Debug Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) face difficulties in detecting and preventing unauthorized access to debugging interfaces, such as JTAG, which can be exploited by malicious actors to access protected information or install malicious software, making it challenging to secure these systems.

Innovation Solution

Implementing a remote access controller that maintains the debugging interface in a reset state until authorized, using updated firmware to release the reset state and signal an authorized debugging session, thereby preventing unauthorized access and initiating remediation procedures if unauthorized activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the debugging interface is made accessible for diagnostic purposes, then the ease of operation for administrators is improved, but the system becomes vulnerable to unauthorized access and security breaches

Engineering Contradiction:
Improveease of debugging accessVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The remote access controller performs preliminary actions by maintaining the debugging interface in a reset state during initialization, before any diagnostic tools or malicious actors can access it. This preliminary securing action prevents unauthorized access while still allowing legitimate debugging when properly authorized through firmware updates.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remote access controller acts as an intermediary between the debugging interface and external diagnostic tools. It mediates access by controlling the reset state of the debugging interface, allowing administrators to securely enable debugging functionality only when authorized, thus preventing direct unauthorized access while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the debugging interface is kept in a reset state for security, then system security is improved, but the availability for legitimate debugging is reduced

Engineering Contradiction:
Improvesystem securityVSAvoiddebugging availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The debugging interface dynamically transitions between reset and non-reset states based on authorization. The remote access controller enables administrators to update firmware to release the reset state when debugging is needed, creating a dynamic security mechanism that adapts to operational requirements while maintaining security by default.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the operational parameter of the debugging interface (reset state) based on security requirements. By controlling whether the debugging interface is in reset or operational state through firmware updates, the system maintains security while allowing legitimate debugging access when properly authorized.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11782089B2Detecting and remediating unauthorized debug sessions
Publication Date: 2023.10.10 DELL PROD LP
  • US11782089B2 patent drawing
  • US11782089B2 patent drawing

AI summary

IHSs (Information Handling Systems) may include connectors, such as an XDP connector, that support couplings by diagnostic tools that utilize a debugging interface that is supported by the IHS, such as JTAG interface. These connectors provide a useful debugging mechanism but may be exploited to access protected information and to install malicious software. Detecting when these debugging capabilities have been compromised is very difficult. In embodiments, a remote access controller of the IHS disables the JTAG interface prior to initialization of the IHS processor by maintaining the interface in reset state. The remote access controller does not include instructions necessary for releasing the JTAG interface from this reset state until its firmware has been updated. If the remote access controller detects debugging activity while the JTAG interface is still in a reset state, the remote access controller signals an attempt to conduct an unauthorized debug session.