Central Authentication Control for Multi-Port SoC Debug Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems on a chip (SoC) are vulnerable to tool falsification attacks after a one-time authentication process, allowing unauthorized access to SoC internals when a legitimate development tool is swapped with a hacking device.
Innovation Solution
Implementing a central controller that manages authentication exchanges between development tools and a security subsystem through dedicated and static password exchange mailboxes, ensuring independent and repeated authentication of each development port, and providing an access-granted signal only when all authentication protocols are satisfied.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If a one-time authentication process is used for development ports, then authentication speed is improved, but security reliability deteriorates because the SoC remains vulnerable after authentication
Solution Approach 1:
The patent implements repeated authentication exchanges at predetermined intervals instead of a single one-time authentication. The security subsystem periodically challenges development tools to re-authenticate, ensuring continuous security validation. This periodic action maintains security reliability while managing authentication speed through efficient challenge-response protocols.
Solution Approach 2:
The patent establishes a feedback mechanism where the security subsystem continuously monitors authentication status and can de-assert access-granted signals when authentication fails or intervals expire. This feedback loop ensures that security reliability is maintained by dynamically responding to authentication states, preventing unauthorized access even after initial authentication.
2Reliability
If separate authentication is implemented for each development port, then security reliability is improved, but device complexity increases due to multiple authentication exchanges
Solution Approach 1:
The patent employs a universal authentication protocol that can be applied across multiple development ports simultaneously. The same security subsystem and challenge-response mechanism serve all ports, reducing overall system complexity while maintaining independent authentication for each port. This multi-functional approach allows the system to handle multiple ports without proportionally increasing complexity.
Solution Approach 2:
The patent combines multiple authentication exchanges into a unified security subsystem that manages all development ports centrally. By merging the authentication logic into a single security subsystem rather than distributing separate authentication units per port, the system achieves independent port authentication while avoiding the complexity of fully distributed authentication systems.
3Reliability
If repeated authentication is performed at predetermined intervals, then security reliability is improved, but loss of time increases due to continuous authentication exchanges
Solution Approach 1:
The patent schedules authentication exchanges at predetermined intervals, allowing normal operations to proceed without constant authentication interruptions. This periodic timing balances security reliability with operational efficiency, minimizing time loss by only requiring authentication at specific intervals rather than continuously.
Solution Approach 2:
The patent performs authentication exchanges in advance at scheduled intervals before potential security breaches can occur. By proactively re-authenticating at predetermined times, the system maintains security reliability without requiring continuous real-time authentication, thus reducing overall time overhead while ensuring security is validated before access is granted.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system on a chip including a first-port controller (106) for a first development port (102) configured to receive a first development tool and a second-port controller (108) for a second development port (104) configured to receive a second development tool. The system on a chip further including a central controller (110) in communication with the first-port controller (106), the second-port controller (108), and a security subsystem (112). The central controller (110) being configured to manage authentication exchanges between the security subsystem (112) and the first development tool and authentication exchanges between the security subsystem (112) and the second development tool.