Test Mode Circuitry for Programmable Tamper Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a mechanism to ensure that a programmable integrated circuit is properly identified for its intended customer and to prevent unauthorized access to its data, especially when in test mode, as existing technologies lack effective methods to differentiate between custom-programmed threshold voltages and customer-specific data.

Innovation Solution

The integrated circuit includes programmable multi-bit registers for customer identification and threshold data, with circuitry that performs parallel-to-serial conversion and drives these data through output pads, and a tamper detection circuit that generates an alarm signal, selectively coupling it to output pads based on the circuit's test mode status to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the integrated circuit allows access to customer identification data and threshold data during test mode, then manufacturing testing and verification can be performed, but unauthorized access to sensitive data by tamperers is enabled

Engineering Contradiction:
Improveaccess to data during testingVSAvoidunauthorized access by tamperers
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by differentiating the accessibility of different data types based on their sensitivity. Customer identification data and threshold data are made accessible during test mode for manufacturing verification, while other sensitive data remains protected. The circuit selectively couples different output pads to different data sources based on test mode status, allowing localized access where needed while maintaining security elsewhere.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses an intermediary mechanism - a selective coupling circuit - that mediates between the internal data stores and external output pads. This intermediary selectively connects customer identification data and threshold data to output pads during test mode, while blocking access to other sensitive data. The intermediary acts as a gatekeeper that enables authorized testing while preventing unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the integrated circuit provides selective output based on test mode status, then data security can be maintained during normal operation, but circuit complexity increases

Engineering Contradiction:
Improvedata security during normal operationVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing a multi-functional selective coupling circuit that handles multiple data types (customer identification data, threshold data, and other sensitive data) through a single integrated mechanism. The same circuit infrastructure - including the test mode detection logic and selective coupling switches - is used to manage different data sources, reducing overall system complexity compared to separate security mechanisms for each data type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses dynamics by implementing a reconfigurable output structure that changes its connectivity based on test mode status. During normal operation, the circuit selectively couples sensitive data to appropriate output pads for security. During test mode, the same circuit reconfigures to allow access to customer identification data and threshold data. This dynamic reconfiguration is achieved through controlled switches that respond to test mode signals, providing adaptability without requiring separate static circuits for each mode.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the integrated circuit uses separate output pads for different data types, then data security can be enhanced, but the number of output pins increases

Engineering Contradiction:
Improvedata securityVSAvoidnumber of output pins
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent applies merging by combining multiple data output functions into a single shared output pad infrastructure. Instead of having separate dedicated output pins for customer identification data, threshold data, and other sensitive data, the patent uses a unified set of output pads that can be selectively coupled to different data sources based on test mode status. This merging reduces the total number of output pins while maintaining security through selective coupling.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses parameter changes by dynamically altering the connectivity parameters of the output pads based on test mode status. During normal operation, the coupling parameters are configured to connect sensitive data to secure output paths. During test mode, the parameters change to allow access to customer identification data and threshold data through the same output pads. This parameter-based control enables multiple functions to share the same physical outputs without compromising security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8827165B2Test mode circuitry for a programmable tamper detection circuit
Publication Date: 2014.09.09 STMICROELECTRONICS INT NV
  • US8827165B2 patent drawing
  • US8827165B2 patent drawing
  • US8827165B2 patent drawing

AI summary

An integrated circuit includes an output pad, an alarm output pad, and a test mode output pad. A first multi-bit register is programmable to store programmable data such as data that identifies a customer for whom the integrated circuit has been manufactured. A second multi-bit register is programmable to store customer specified threshold data. A first circuit selectively couples the first and second multi-bit registers to the output pad. The first circuit is operable responsive to the integrated circuit being placed into a test mode to perform parallel-to-serial conversion of either the customer identification data stored in the first multi-bit register or the customer specified threshold data stored in the second multi-bit register and drive the converted data for output through the output pad. The integrated circuit further includes a tamper detection circuit operable responsive to the customer specified threshold data to generate a tamper alarm signal. A second circuit selectively couples the tamper alarm signal to the alarm output pad and test mode output pad depending on whether the integrated circuit is in a test mode. More specifically, the second circuit operates to drive the alarm output pad with the tamper alarm signal when the integrated circuit is not in test mode and drive the test mode output pad with the tamper alarm signal when the integrated circuit is in test mode (with the alarm output pad driven to a known state).