IP Library Granted Patent US 12,499,284
Granted Patent B2
US 12,499,284 · App. 18/327,909 · Granted Dec 16, 2025

Tool security system

Inventors: Albrecht Mayer (Waakirchen, DE); Gasper Skvarc Bozic (Unterhaching, DE)
Assignee: Infineon Technologies AG
G06F21/85H04L12/40019
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,284
App. No.
18/327,909
Granted
Dec 16, 2025
Kind
B2
Abstract

Systems, methods, and circuitries are disclosed for providing security for tool access in a device. In one example, a device includes a bus master, a memory protection unit, and protection agent circuitry. The bus master is configured to store, in a first range of memory locations, request messages received from a tool interface of the device, each request message encapsulating a tool-related command. The memory protection unit is configured to prevent the bus master from accessing memory locations outside of the first range of memory locations. The protection agent circuitry is configured to access the first range of memory locations to identify one or more request messages, and send each respective request message to one of a plurality of component circuitries based on a component circuitry identified by the request message.

Claims (46)

1 . A device, comprising:

a plurality of component circuitries;

a bus master configured to store, in a first range of memory locations, request messages received from a tool interface of the device, each request message encapsulating a tool-related command;

a memory protection unit configured to prevent the bus master from accessing memory locations outside of the first range of memory locations; and

protection agent circuitry configured to

access the first range of memory locations to identify one or more request messages, and

send respective request messages to one of a plurality of component circuitries based on a component circuitry identified by the request message,

wherein each component circuitry is configured to

receive a request message from the protection agent circuitry;

execute the tool-related command encapsulated by the request message; and

store a response message encapsulating results of the tool-related command in the first range of memory addresses.

2 . The device of claim 1 , wherein the protection agent circuitry is configured to control a range of memory locations protected by the memory protection unit.

3 . The device of claim 1 , wherein the bus master is configured to

access the first range of memory locations to identify one or more response messages, and

provide the one or more response messages to the tool interface of the device.

4 . The device of claim 1 , wherein the protection agent circuitry accesses the first range of memory periodically according to a polling schedule.

5 . The device of claim 1 , wherein the protection agent circuitry accesses the first range of memory in response to an interrupt signal.

6 . The device of claim 1 , wherein at least one request message is encrypted using a key known by a component circuitry identified in the request message.

7 . The device of claim 1 , wherein at least one request message is encrypted with a session key that indicates an authenticated identity of a source of the request message.

8 . The device of claim 1 , wherein at least one component circuitry is configured to decrypt a received request message using a key known by a tool associated with the component circuitry or encrypt a response message using a key known by a tool associated with the component circuitry.

9 . The device of claim 1 , wherein the protection agent circuitry is configured to, in response to an attack notification signal, control the memory protection unit to prevent the bus master from accessing any memory locations.

10 . A method, comprising:

with a bus master,

receiving a request messages from a tool interface, each request message encapsulating a tool-related command, and

storing the request messages in a first range of memory locations; and

with protection agent circuitry,

accessing the first range of memory locations to identify one or more request messages, and

sending respective request messages to one of a plurality of component circuitries based on a component circuitry identified by the request message; and

with a component circuitry,

receiving a request message from the protection agent circuitry;

executing the tool-related command encapsulated by the request message; and

storing a response message encapsulating results of the tool-related command in the first range of memory addresses.

11 . The method of claim 10 , comprising, with the protection agent circuitry, configuring the bus master to prevent the bus master from accessing memory locations outside of the first range of memory locations.

12 . The method of claim 11 , comprising, in response to receiving an attack notification signal, with the protection agent circuitry, configuring the bus master to prevent the bus master from accessing any memory locations.

13 . The method of claim 10 , comprising accessing the first range of memory periodically according to a polling schedule.

14 . The method of claim 10 , comprising accessing the first range of memory in response to an interrupt signal.

15 . The method of claim 10 , wherein at least one request message is encrypted using a key known by a component circuitry identified in a header of the request message or a session key that indicates an authenticated source of the request message.

16 . A non-transitory computer-readable medium having computer-executable instructions stored thereon that when executed by a processor, cause the processor to perform corresponding operations, the operations comprising:

configuring a bus master to prevent the bus master from accessing memory locations outside of a first range of memory locations, the bus master coupled to a tool hardware interface of a device;

accessing the first range of memory locations to identify one or more request messages;

sending each request message to one of a plurality of component circuitries based on a component circuitry identified in a header of the request message; and

in response to receiving an attack notification signal, configure the bus master to prevent the bus master from accessing any memory locations.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions include instructions that cause the processor to access the first range of memory periodically according to a polling schedule.

18 . The non-transitory computer-readable medium of claim 16 , wherein the instructions include instructions that cause the processor to access the first range of memory in response to an interrupt signal.

19 . The non-transitory computer-readable medium of claim 16 , wherein the instructions include instructions that cause the processor to send each request message to the one of the plurality of component circuitries without reading a payload of the request message.

20 . The non-transitory computer-readable medium of claim 16 , wherein the instructions include instructions that cause the processor to copy each request message into a queue associated with the one of the plurality of component circuitries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2023
From: MAYER, ALBRECHT; SKVARC BOZIC, GASPER
To: INFINEON TECHNOLOGIES AG
Reel/Frame 063835/0784 →
Continuity (1)
Related Publication 20240403497A1 · Dec 5, 2024
References Cited (8)
US 6934817B2 · Ellison · 2005 [cited by examiner]
US 7120771B2 · Dahan · 2006 [cited by examiner]
US 8521969B2 · Dixon · 2013 [cited by examiner]
US 9495111B2 · Hars · 2016 [cited by examiner]
US 10223290B2 · Depeyrot · 2019 [cited by examiner]
US 20090204823A1 · Giordano · 2009 [cited by examiner]
C166S On Chip Debug Support, User's Manual, V 1.1, Aug. 2001. Published by Infineon Technologies AG. [cited by applicant]
XMC(tm) and AURIX(tm)—industrial microcontrollers portfolio, document No. B158-110087-V5-7600-EU-EC-P. Published by Infineon Technologies AG in 2020. [cited by applicant]