Semiconductor Redacted Logic Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing semiconductor devices lack adequate security measures to prevent unauthorized access, reverse engineering, and intellectual property theft during manufacturing and post-manufacturing stages, particularly through JTAG interfaces.
Innovation Solution
The semiconductor device incorporates redacted logic, including manufacturing test logic, which is initially inoperable and inaccessible. This is achieved by using a processor to assert a configuration isolation signal, isolating the data port from the programmable logic block, and loading the necessary logic at a trusted facility, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If JTAG interface and test logic are implemented for manufacturing testing, then testability and manufacturing validation are improved, but security against unauthorized access and reverse engineering deteriorates
Solution Approach 1:
The patent extracts the test logic functionality into a separate, isolated programmable logic block that is physically and logically separated from the main device logic. This extracted test logic can be independently configured and accessed only through controlled interfaces, allowing manufacturing testing while preventing unauthorized access to the main device intellectual property.
Solution Approach 2:
The device is segmented into distinct functional regions: main logic blocks, test logic blocks, and configuration interfaces. The test logic is further segmented into configurable functional units that can be independently activated. This segmentation allows test functionality to be provided without exposing the entire device architecture to potential attackers.
2Ease of operation
If test registers and communication interfaces are provided for diagnostics, then fault isolation and maintenance capabilities are improved, but vulnerability to side-channel attacks and IP theft increases
Solution Approach 1:
The patent introduces an intermediary configuration interface that mediates all access to test logic and device functionality. This interface acts as a gatekeeper, validating access requests and controlling what information can be read or written. The intermediary layer prevents direct access to sensitive registers and logic, blocking side-channel attack vectors while maintaining diagnostic capabilities.
Solution Approach 2:
The test logic and communication interfaces are designed to be dynamically configurable rather than statically fixed. The device can change its accessibility characteristics based on operational state, security context, and configuration settings. This dynamic behavior allows the device to present different interface configurations to different users or systems, enabling maintenance access when needed while preventing unauthorized access during normal operation.
Data Source
AI summary
A semiconductor device includes a data port, a programmable logic block for executing a manufacturer test, and a processor operatively coupled to the data port. The processor is configured to assert, in a first modality, a configuration isolation signal to the data port. The data port is configured to be communicatively isolated from the programmable logic block while the configuration isolation signal is asserted. The processor is configured to de-assert, in a second modality, the configuration isolation signal from the data port. The data port is configured to be communicatively coupled to the programmable logic block while the configuration isolation signal is de-asserted. In some examples, the semiconductor device includes a communication interface communicatively coupled to the programmable logic block, wherein the processor is further configured to cause, in the first modality, data to be loaded into the programmable logic block from a first-in-first-out (FIFO) buffer of the communication interface.


