PROCESSES AND APPARATUS FOR ESTABLISHING A SECURED CONNECTION WITH A JOINT TEST ACTION GROUP PORT
Processes and apparatus for establishing a secure joint test action group port on a chip are disclosed herein.
1 . A system for performing JTAG connection authentication, comprising:
an access module coupled to a test interface of a TAP port on a chip; and
an authentication module coupled to the TAP port on the chip, wherein the access module and the authentication module include local private keys K and K′ for the authentication, respectively.
2 . The system of claim 1 wherein one of the access module and the authentication module originates an authentication request while the other generates a random number RN, and wherein the access module calculates a first authentication code X′ based on RN using the local private key K′, and sends X′ to the authentication module, and wherein the authentication module calculates a second authentication code X based on RN using the local private key K and compares X to X′, and decides whether to enable the TAP port based on the comparison.
3 . The system of claim 2 wherein the access module originates the authentication request to the authentication module and the authentication module, after receiving the authentication request, generates the RN, and sends the generated RN to the access module.
4 . The system of claim 2 wherein the authentication module originates the authentication request to the access module and the access module generates the RN after receiving the authentication request.
5 . The method for authenticating access to a JTAG port in a chip, comprising:
starting an authentication request by one of an access module and an authentication module while the other generates a random number RN;
calculating a first authentication code X′ based on RN using the local private key K′ at the access module and sending X′ to the authentication module;
calculating a second authentication code X based on RN using the local private key K at the authentication module;
comparing the first authentication code X′ to the second authentication code X;
determining whether to enable the JTAG port based on the comparison; and
returning the authentication result to the access module.
6 . The method of claim 5 wherein starting an authentication request further includes:
starting the authentication request at the access module before sending the authentication request to the authentication module; and
after receiving the authentication request, generating the RN and sending the generated RN to the access module at the authentication module.
7 . The method of claim 5 wherein starting an authentication request further includes:
starting the authentication request at the authentication module and sending the authentication request to the access module; and
generating the RN after receiving the authentication request at the access module.