Time-Varying Code Generator for Secure IC Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern integrated circuits (ICs) face security risks due to unmanaged access through test and debug ports, which can be exploited for illicit purposes, and existing security solutions are costly, complex, and not suitable for common automatic test equipment (ATE), lacking effective metrics for security protection.

Innovation Solution

Implementing a security-managed access system using standard test and debug structures with time-varying code-generators, code comparators, and scan-segment locking mechanisms across the test and debug architecture, minimizing hot spots and obscuring relationships between hardware elements, to ensure authorized access and protect sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If test and debug ports are made accessible for standard testing and debugging operations, then ease of operation and testability are improved, but security vulnerability increases allowing illicit access to sensitive data and functions

Engineering Contradiction:
ImprovetestabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary security mechanism between the test/debug ports and the embedded instruments. This includes security management logic that intercepts and validates access requests, preventing direct access to sensitive data while allowing legitimate testing operations through proper authentication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the access paths to embedded instruments by creating separate security management channels. Different access modes (testing, debugging, illicit) are routed through different paths with appropriate security controls, allowing legitimate operations while blocking unauthorized access.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If encryption solutions such as RSA and AES are implemented to protect sensitive data, then security protection is improved, but device complexity and cost increase making them unsuitable for common automatic test equipment

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent employs lightweight security mechanisms that are computationally efficient and suitable for resource-constrained environments. Rather than implementing full RSA/AES encryption suites, the patent uses simplified security management logic that provides adequate protection for test and debug operations without requiring complex cryptographic hardware or software.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent changes the security approach from complex cryptographic parameter-based protection to simpler access control parameters. Security is managed through control signals, access permissions, and operational states rather than through mathematical encryption parameters, reducing overall system complexity.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If existing security solutions are implemented, then security protection is improved, but ease of operation deteriorates as they are not suitable for common automatic test equipment

Engineering Contradiction:
Improvesecurity protectionVSAvoidcompatibility with ATE
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent designs a security management system that serves multiple functions within the test and debug architecture. The same security mechanisms protect against illicit access while simultaneously enabling legitimate testing and debugging operations, making the system compatible with standard automatic test equipment without requiring specialized security hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11693052B2Using embedded time-varying code generator to provide secure access to embedded content in an on-chip access architecture
Publication Date: 2023.07.04 SILICONAID SOLUTIONS INC
  • US11693052B2 patent drawing
  • US11693052B2 patent drawing
  • US11693052B2 patent drawing

AI summary

A network of storage units has a data path, which is at least a portion of the network. The network also has a dynamic time-varying or cycle-varying code generation unit and a code comparator unit that together make up an unlock signal generation unit; and a gateway storage unit. If the gateway storage unit does not store an unlock signal or the unlock signal generation unit does not generate and transmit an unlock signal, the gateway storage unit does not insert a data path segment in the data path. If the unlock signal generation unit is operated such that it generates an unlock signal, and it transmits that unlock signal to a gateway storage unit, and the gateway storage unit stores the unlock signal value, then the gateway storage unit inserts a data path segment into the data path.