Testing of security systems in integrated circuits
An integrated circuit includes a secure asset, a security system, and an efficacy decoder. The security system is triggered to operate in one of its functional states. Further, the security system receives various test requests for an access to the secure asset, and determines, based on the triggered functional state thereof, one or more test requests authorized to access the secure asset. The efficacy decoder similarly receives the test requests and determines one or more allowable requests for the triggered functional state of the security system. Further, the efficacy decoder determines an efficacy value for the security system based on a comparison between the test requests authorized by the security system and the allowable requests associated with the triggered functional state. The efficacy value is indicative of a security level of the security system operating in the triggered functional state.
1 . An integrated circuit (IC), comprising:
a secure asset having a secure memory to store security data;
a security system coupled to the secure asset, wherein the security system including a circuit that is configured to (i) receive a plurality of test requests for access to the secure asset and (ii) determine a set of test requests of the plurality of test requests that is authorized by the security system to access the secure asset, the determination being based on state data indicating a first functional state of the security system,
a gating circuit coupled between the security system and the secure asset, and configured to control access to the secure asset based on the set of test requests;
an efficacy decoder coupled to the security system, wherein the efficacy decoder includes a circuit that is configured to (i) determine a set of allowable requests for the first functional state, the set of allowable requests being requests authorized by the security system to access the secure asset when the security system operates at a predetermined security level, wherein the set of allowable requests determined from the plurality of test requests based on the state data indicating the first functional state, and (ii) determine an efficacy value for the security system based on a ratio of the set of test requests that is authorized by the security system and the set of allowable requests, wherein the efficacy value is indicative of a security level of the security system operating in the first functional state; and
a system controller, the system controller including a circuit that is configured to perform a reset of at least a portion of the IC to gate access to the secure asset, based on the efficacy value being less than a threshold amount
wherein the gating circuit is arranged to receive the set of test requests and to gate the set of test requests to prevent access to the secure asset, and wherein the gating circuit is not arranged to receive the set of allowable requests.
2 . The IC of claim 1 , wherein the security system is further configured to receive a trigger signal indicative of the first functional state, and wherein based on the trigger signal, the security system is further configured to operate in the first functional state.
3 . The IC of claim 2 , wherein the system controller coupled to the security system, and the system controller is configured to generate the trigger signal and provide the trigger signal to the security system to trigger the security system to operate in the first functional state based on determining the security level of the security system is in the first functional state.
4 . The IC of claim 1 , wherein the access to the secure asset corresponds to an access to the security data stored in the secure memory.
5 . A testing method, comprising:
receiving, by a security system, a plurality of test requests for an access to a secure asset having a secure memory to store security data, the security system coupled to the secure asset and access to the secure asset is controlled by a gating circuit coupled between the security system and the secure asset;
determining, by the security system, a set of test requests of the plurality of test requests that the security system authorizes to access the secure asset based on state data indicating a first functional state of the security system, wherein the gating circuit controls the authorized access based on the set of test requests;
determining, by an efficacy decoder, a set of allowable requests for the first functional state, the set of allowable requests being requests authorized by the security system to access the secure asset when the security system operates at a predetermined security level, wherein the set of allowable requests determined from the plurality of test requests based on the state data indicating the first functional state;
determining, by the efficacy decoder, an efficacy value for the security system based on a ratio of the set of test requests that is authorized by the security system and the set of allowable requests, wherein the efficacy value is indicative of a security level of the security system operating in the first functional state; and
performing, by a system controller, a reset of at least a portion of an integrated circuit (IC) to gate access to the secure asset based on the efficacy value being less than a threshold amount,
wherein the gating circuit is arranged to receive the set of test requests and to gate the set of test requests to prevent access to the secure asset, and wherein the gating circuit is not arranged to receive the set of allowable requests.
6 . The testing method of claim 5 , further comprising:
receiving, by the security system, a trigger signal indicative of the first functional state; and
operating, by the security system, based on the trigger signal, in the first functional state.