Trusted Boot Component Securing JTAG Scan Chains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

JTAG-enabled systems and components face security threats from attackers who can exploit the JTAG scan chain infrastructure to access protected data, alter system states, and perform unauthorized operations, posing risks to safety and security properties, especially in military and consumer products.

Innovation Solution

A trusted boot component is used to provide authorized JTAG testing, with a watchdog period that encrypts all protected data at rest and disables JTAG I/O GPIO pins initially, transitioning to a secure state only after authentication and continuous monitoring for unauthorized activity, employing configurable multiplexor circuitry and watchdog timer circuitry to secure JTAG paths and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If JTAG scan chain infrastructure is enabled for testing and debugging, then accessibility and ease of operation are improved, but security and protection of protected data deteriorate

Engineering Contradiction:
ImproveJTAG accessibilityVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions by encrypting protected data at rest before any JTAG access occurs, and by establishing authentication mechanisms and authorization checks before enabling JTAG functionality. The system performs security initialization during power-up or reset, setting up encrypted storage of protected data and configuring security states before JTAG can be accessed, thereby preventing attackers from exploiting unsecured JTAG interfaces.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary security mechanisms between the JTAG interface and protected data, including authentication modules that verify attacker identity, authorization checks that control access permissions, and encryption layers that mediate data protection. These intermediaries act as security gatekeepers that must be satisfied before JTAG can access protected resources, transforming the direct access path into a controlled multi-stage verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If embedded die modifications are added to secure JTAG components (such as TAP lock, key registers, authentication circuitry), then security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidcircuit modifications
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements universal security mechanisms that can be applied across multiple JTAG-enabled devices through standardized authentication protocols and encryption algorithms. Rather than requiring custom security circuitry for each device, the system uses multi-functional security modules that can handle authentication, authorization, and data protection across different JTAG implementations, reducing overall device complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes security parameters through software-based authentication credentials, encryption keys, and authorization levels rather than requiring permanent hardware modifications. By using parameter-based security (stored credentials, configurable permissions, selectable encryption algorithms) instead of fixed hardware security features, the system achieves strong security protection without adding complex embedded die modifications to each component.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If JTAG functionality is disabled or access is removed by open-circuiting security fuses, then security is improved, but ease of operation and ability to perform testing deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoidtesting capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements dynamic JTAG security that can transition between different operational states (secure mode, testing mode, debug mode) based on authentication results and system conditions. Rather than statically disabling JTAG with open-circuit fuses, the system dynamically enables or disables JTAG functionality through controlled signal paths and configurable security states, allowing flexible switching between security protection and testing capability as needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements preliminary anti-action by detecting unauthorized JTAG access attempts and responding with protective measures such as latching off JTAG ports, clearing protected data, or transitioning to secure states before attackers can exploit the interface. This preemptive security response actively counteracts potential attacks while preserving legitimate testing capability through proper authentication, rather than permanently disabling JTAG functionality.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9810736B2System and apparatus for trusted and secure test ports of integrated circuit devices
Publication Date: 2017.11.07 RAYTHEON CO
  • US9810736B2 patent drawing
  • US9810736B2 patent drawing
  • US9810736B2 patent drawing

AI summary

A trusted boot device secures JTAG scan chains of integrated circuit components on a circuit card assembly without necessarily modifying the integrated circuit components. Component JTAG port I/O scan chain signal pins are independently routed to FPGA fabric on the trusted boot device. The trusted boot device monitors the JTAG paths and triggers a security event if unauthorized activity is detected on a JTAG path. JTAG paths on the secure trusted boot device are latch disabled by default and upon detection of a security event. JTAG paths are only enabled for a predefined length of time. To prevent JTAG access when protected data is exposed, a watchdog timer latch disables the JTAG paths when the predefined time has expired and may trigger a security event if activity is detected after the time has expired. A power cycle is then used to re-enable authenticated JTAG enable requests.