Securing Access to Reconfigurable Scan Networks

Securing Access to Reconfigurable Scan Networks
复制标题

保护对可重新配置扫描网络的访问

DOI:
10.1109/ats.2013.61
复制
发表时间:
2013
期刊:
2013 22nd Asian Test Symposium
影响因子:
--
通讯作者:
H. Wunderlich
H. Wunderlich
中科院分区:
--
文献类型:
--
作者:
R. Baranowski;M. Kochte;H. Wunderlich

文献摘要

被引文献

相似文献

片上嵌入式基础设施对测试、重构和调试的可访问性提出了一个严重的安全问题。在设计和开发基于IEEE Std. 1149.1 (JTAG)、IEEE Std. 1500的扫描架构时需要特别注意,特别是在即将发布的IEEE P1687 (IJTAG)中允许的可重构扫描网络。传统上,扫描基础设施在制造测试后使用保险丝完全或部分禁用测试访问端口(TAP)来保护。如果TAP控制器的某些扫描链或指令被永久阻塞,则基于熔断器的方法是有效的。但是,如果需要细粒度的访问管理,这种方法的成本会变得很高,并且在可重构扫描网络中面临可伸缩性问题。本文提出了一种可扩展的可重构扫描网络多级访问管理方案。对受保护寄存器的访问在tap级受到序列过滤器的局部限制,该过滤器只允许预先计算的一组扫描访问序列。我们的方法不需要对扫描体系结构进行任何修改,也不会造成访问时间损失。对于复杂的可重构扫描网络的实验结果表明,区域开销主要取决于允许访问的数量,并且即使这个数量超过网络寄存器的计数也是边际的。
The accessibility of on-chip embedded infrastructure for test, reconfiguration, and debug poses a serious safety and security problem. Special care is required in the design and development of scan architectures based on IEEE Std. 1149.1 (JTAG), IEEE Std. 1500, and especially reconfigurable scan networks, as allowed by the upcoming IEEE P1687 (IJTAG). Traditionally, the scan infrastructure is secured after manufacturing test using fuses that disable the test access port (TAP) completely or partially. The fuse-based approach is efficient if some scan chains or instructions of the TAP controller are to be permanently blocked. However, this approach becomes costly if fine-grained access management is required, and it faces scalability issues in reconfigurable scan networks. In this paper, we propose a scalable solution for multi-level access management in reconfigurable scan networks. The access to protected registers is restricted locally at TAP-level by a sequence filter which allows only a precomputed set of scan-in access sequences. Our approach does not require any modification of the scan architecture and causes no access time penalty. Experimental results for complex reconfigurable scan networks show that the area overhead depends primarily on the number of allowed accesses, and is marginal even if this number exceeds the count of network's registers.