IP Library Granted Patent US 12,730,898
Granted Patent B2
US 12,730,898 · App. 18/152,809 · Granted Sep 8, 2026

Testing of security systems in integrated circuits

Inventors: Neha Srivastava (New Delhi, IN); Gautam Tikoo (Noida, IN)
Assignee: NXP B.V.
G06F21/577G01R31/2851G06F11/27G06F21/6218G06F21/72G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,898
App. No.
18/152,809
Filed
Jan 11, 2023
Granted
Sep 8, 2026
Kind
B2
Art Unit
2457
USPC
726/1
Abstract

An integrated circuit includes a secure asset, a security system, and an efficacy decoder. The security system is triggered to operate in one of its functional states. Further, the security system receives various test requests for an access to the secure asset, and determines, based on the triggered functional state thereof, one or more test requests authorized to access the secure asset. The efficacy decoder similarly receives the test requests and determines one or more allowable requests for the triggered functional state of the security system. Further, the efficacy decoder determines an efficacy value for the security system based on a comparison between the test requests authorized by the security system and the allowable requests associated with the triggered functional state. The efficacy value is indicative of a security level of the security system operating in the triggered functional state.

Claims (20)

1 . An integrated circuit (IC), comprising:

a secure asset having a secure memory to store security data;

a security system coupled to the secure asset, wherein the security system including a circuit that is configured to (i) receive a plurality of test requests for access to the secure asset and (ii) determine a set of test requests of the plurality of test requests that is authorized by the security system to access the secure asset, the determination being based on state data indicating a first functional state of the security system,

a gating circuit coupled between the security system and the secure asset, and configured to control access to the secure asset based on the set of test requests;

an efficacy decoder coupled to the security system, wherein the efficacy decoder includes a circuit that is configured to (i) determine a set of allowable requests for the first functional state, the set of allowable requests being requests authorized by the security system to access the secure asset when the security system operates at a predetermined security level, wherein the set of allowable requests determined from the plurality of test requests based on the state data indicating the first functional state, and (ii) determine an efficacy value for the security system based on a ratio of the set of test requests that is authorized by the security system and the set of allowable requests, wherein the efficacy value is indicative of a security level of the security system operating in the first functional state; and

a system controller, the system controller including a circuit that is configured to perform a reset of at least a portion of the IC to gate access to the secure asset, based on the efficacy value being less than a threshold amount

wherein the gating circuit is arranged to receive the set of test requests and to gate the set of test requests to prevent access to the secure asset, and wherein the gating circuit is not arranged to receive the set of allowable requests.

2 . The IC of claim 1 , wherein the security system is further configured to receive a trigger signal indicative of the first functional state, and wherein based on the trigger signal, the security system is further configured to operate in the first functional state.

3 . The IC of claim 2 , wherein the system controller coupled to the security system, and the system controller is configured to generate the trigger signal and provide the trigger signal to the security system to trigger the security system to operate in the first functional state based on determining the security level of the security system is in the first functional state.

4 . The IC of claim 1 , wherein the access to the secure asset corresponds to an access to the security data stored in the secure memory.

5 . A testing method, comprising:

receiving, by a security system, a plurality of test requests for an access to a secure asset having a secure memory to store security data, the security system coupled to the secure asset and access to the secure asset is controlled by a gating circuit coupled between the security system and the secure asset;

determining, by the security system, a set of test requests of the plurality of test requests that the security system authorizes to access the secure asset based on state data indicating a first functional state of the security system, wherein the gating circuit controls the authorized access based on the set of test requests;

determining, by an efficacy decoder, a set of allowable requests for the first functional state, the set of allowable requests being requests authorized by the security system to access the secure asset when the security system operates at a predetermined security level, wherein the set of allowable requests determined from the plurality of test requests based on the state data indicating the first functional state;

determining, by the efficacy decoder, an efficacy value for the security system based on a ratio of the set of test requests that is authorized by the security system and the set of allowable requests, wherein the efficacy value is indicative of a security level of the security system operating in the first functional state; and

performing, by a system controller, a reset of at least a portion of an integrated circuit (IC) to gate access to the secure asset based on the efficacy value being less than a threshold amount,

wherein the gating circuit is arranged to receive the set of test requests and to gate the set of test requests to prevent access to the secure asset, and wherein the gating circuit is not arranged to receive the set of allowable requests.

6 . The testing method of claim 5 , further comprising:

receiving, by the security system, a trigger signal indicative of the first functional state; and

operating, by the security system, based on the trigger signal, in the first functional state.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2023
From: SRIVASTAVA, NEHA; TIKOO, GAUTAM
To: NXP B.V.
Reel/Frame 062352/0068 →
Priority Claims (1)
IN 202221065531 · Nov 16, 2022 · national
Continuity (1)
Related Publication 20240160745A1 · May 16, 2024
References Cited (23)
US 5239262A · Grutzner et al. · 1993 [cited by applicant]
US 5554941A · Kesel · 1996 [cited by applicant]
US 5655071A · Habbe et al. · 1997 [cited by applicant]
US 6510530B1 · Wu et al. · 2003 [cited by applicant]
US 6701476B2 · Pouya et al. · 2004 [cited by applicant]
US 7594206B2 · Yoshida et al. · 2009 [cited by applicant]
US 7757133B1 · Parulkar · 2010 [cited by applicant]
US 7818645B2 · Gedamu et al. · 2010 [cited by applicant]
US 7840865B2 · Lai et al. · 2010 [cited by applicant]
US 8736299B1 · Pedersen · 2014 [cited by examiner]
US 8769355B2 · Scott et al. · 2014 [cited by applicant]
US 10495691B2 · Sun et al. · 2019 [cited by applicant]
US 10585738B2 · Marinet et al. · 2020 [cited by applicant]
US 11165783B1 · Eiers · 2021 [cited by examiner]
US 20080022396A1 · Kado · 2008 [cited by examiner]
US 20140140512A1 · Hadley · 2014 [cited by examiner]
US 20140230055A1 · Boehl · 2014 [cited by applicant]
US 20180137309A1 · Shapira et al. · 2018 [cited by applicant]
US 20190033374A1 · Bhagwat · 2019 [cited by examiner]
US 20190268382A1 · Hu et al. · 2019 [cited by applicant]
CN 109870463A · 2020 [cited by applicant]
CN 111337780A · 2020 [cited by applicant]
RU 2725783C1 · 2020 [cited by applicant]