Secure Semiconductor Design with Dynamic JTAG Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing semiconductor designs lack sufficient security measures to prevent unauthorized access, reverse engineering, and intellectual property theft, particularly during manufacturing and operation, due to vulnerabilities in JTAG interfaces and untrusted foundries.

Innovation Solution

A secure semiconductor system architecture that includes a communication interface configured to require a valid access key for operation, redacted code that requires proper FPGA configuration for functionality, and modalities to disable boundary scan operations and assert RESET signals to prevent unauthorized access and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If JTAG interface and boundary scan operations are enabled for testing and diagnostics, then ease of operation and manufacturing testability are improved, but security against unauthorized access and reverse engineering deteriorates

Engineering Contradiction:
ImprovetestabilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic control of the JTAG interface and boundary scan operations through a security management module that can enable or disable these features based on authentication status. The system transitions between secure and non-secure modes, allowing test functionality only when authorized, thus resolving the contradiction between ease of operation and security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication mechanism and security management module as an intermediary between the JTAG interface and the device logic. This intermediary verifies credentials before allowing access to test functions, blocking unauthorized access while maintaining legitimate testability, thus resolving the security-testability contradiction

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If communication interface is always enabled for diagnostics, then ease of operation is improved, but security against unauthorized access and intellectual property theft deteriorates

Engineering Contradiction:
ImprovediagnosticsVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The communication interface operates dynamically with adjustable security levels. The system can switch between secure mode (requiring authentication for all operations), partial secure mode (allowing limited operations), and non-secure mode (full access). This dynamic adjustment resolves the contradiction by providing diagnostics when needed while maintaining security when required

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security parameter of the communication interface based on authentication status and operational context. The interface can operate with different security configurations, allowing the system to optimize between ease of operation and security reliability by adjusting the authentication requirements and access permissions

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access controls and security measures are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security management module serves multiple functions: authentication verification, access control, mode switching, and interface management. By consolidating these security-related functions into a single multi-functional module, the patent improves security without proportionally increasing overall device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the authentication mechanism, access control logic, and communication interface management into an integrated security management module. This merging of functions reduces the complexity that would result from separate security components while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

4Manufacturing precision

If JTAG interface is accessible during manufacturing, then manufacturing precision and testing are improved, but security against overproduction and unauthorized use deteriorates

Engineering Contradiction:
ImprovetestingVSAvoidoverproduction
Core Design Contradiction:
Manufacturing precisionVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary authentication checks that prevent unauthorized operations before they can occur. The system verifies credentials and checks authorization status before allowing JTAG access, boundary scan operations, or configuration changes, thus preventing overproduction and unauthorized use while maintaining legitimate manufacturing testing

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The security management module provides feedback about authentication status and access permissions to the JTAG interface and boundary scan operations. This feedback mechanism ensures that manufacturing tests can proceed with proper authorization while automatically blocking unauthorized access, thus resolving the contradiction between testing capability and prevention of harmful activities

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12277255B2Secure semiconductor and system design
Publication Date: 2025.04.15 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US12277255B2 patent drawing
  • US12277255B2 patent drawing
  • US12277255B2 patent drawing

AI summary

A secure system includes a data port, a network on chip (NoC) module, a processor communicatively coupled to the NoC module, a communication interface operatively coupled to the processor and to the data port, an electronic field-programmable gate array (eFPGA) configuration module operatively coupled to the NoC module, and a clock operatively coupled to the NoC module. In a first modality, the communication interface is at least partially disabled. In a second modality, the communication interface is at least partially disabled, boundary scan operations are disabled, a RESET signal is held in a constant state, and/or redacted code is rendered inoperable. In a third modality, the communication interface is at least partially enabled to send and receive commands and data via the data port, the boundary scan operations are enabled, the RESET signal is not held in the constant state, and/or the redacted code is operable.