SoC JTAG Debug Control Architecture for Dynamic Runtime Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security architectures for system-on-chip (SoC) information handling systems are vulnerable to malicious attacks due to weaknesses in privilege-based isolation schemes and dedicated secure enclave subsystems, which can be compromised by privilege-escalation attacks and lack dynamic runtime isolation control.

Innovation Solution

A dynamic runtime isolation architecture is introduced, where a dedicated SoC control point entity creates and maintains programmable isolation barriers around each execution domain using a two-way control channel data stream, independent from execution domain processors and software, including privileged software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If privilege-based isolation schemes are used to protect processing subsystems, then isolation between processors is improved, but the system becomes vulnerable to privilege-escalation attacks that can compromise the entire security model

Engineering Contradiction:
Improveisolation between processorsVSAvoidvulnerability to privilege-escalation attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the SoC into multiple execution domains (secure, trusted, untrusted) with distinct privilege levels. Each domain has its own privilege mechanism independent of others, so a compromise in one domain cannot escalate to affect other domains. The secure execution domain is physically separated and cannot be accessed by privileged software in untrusted domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure execution domain acts as an intermediary between untrusted software and critical system resources. This intermediary domain enforces isolation policies and controls access to shared resources, preventing direct attacks from untrusted domains while maintaining system functionality. The intermediary cannot be compromised by privilege-escalation attacks from untrusted domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated secure enclave subsystems are used to provide runtime isolation control, then security during system boot is improved, but the physical interconnection infrastructure and CPUs remain unprotected

Engineering Contradiction:
Improvesecurity during system bootVSAvoidunprotected interconnect and CPUs
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges secure enclave functionality directly into each execution domain's privilege mechanism rather than using a separate dedicated subsystem. This integration ensures that each CPU and interconnect segment is protected by its own embedded secure execution domain, extending protection to all components including the physical interconnection infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system adds a new dimension of security by implementing isolation at the interconnect level rather than only at the CPU level. The privilege mechanism controls access to interconnect resources independently of CPU privilege levels, creating a layered isolation architecture that protects both CPUs and the interconnection infrastructure simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If address space control mechanisms are used to create isolation barriers, then control over address space is improved, but the physical interconnection infrastructure is left unprotected

Engineering Contradiction:
Improvecontrol over address spaceVSAvoidunprotected physical interconnection infrastructure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the address space control mechanism into two independent components: address space isolation control and interconnect access control. Each execution domain has its own isolated control registers and privilege levels for managing address space and interconnect access, preventing attacks that target the physical interconnection infrastructure while maintaining address space control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure execution domain acts as an intermediary between untrusted software and the physical interconnection infrastructure. It monitors and controls all interconnect transactions, blocking malicious access attempts while allowing legitimate communication. This intermediary layer protects the interconnect without interfering with normal address space operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12326474B2Multi-partition, multi-domain system-on-chip joint test action group (JTAG) debug control architecture and method
Publication Date: 2025.06.10 NXP USA INC
  • US12326474B2 patent drawing
  • US12326474B2 patent drawing
  • US12326474B2 patent drawing

AI summary

An SoC includes an execution domain processor for running an execution domain which hosts n partitions by accessing, for each partition, one or more SoC resources; a control point processor that generates control data with n debug enable signals corresponding to the n partitions for controlling access to the SoC resources by identifying at least a first SoC resource that each partition is allowed to access; and an access control circuit to provide, in response to the control data, a dynamic runtime isolation barrier which allows access by the debugging tool to only a specified partition running on the execution domain which has a debug enable signal set to a first active value and prevents access to the other n−1 partitions running on the execution domain, For the partition under debug, the dynamic runtime isolation barrier may block debugger access to selected memory regions accessible by the partition under debug.