IP Library Granted Patent US 12,547,698
Granted Patent B2
US 12,547,698 · App. 18/521,480 · Granted Feb 10, 2026

Host-device interface for debug authentication

Inventors: Xavier Chbani (Grenoble, FR); Nadia Van-Den-Bossche (Meylan, FR)
Assignee: STMicroelectronics International N.V.
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,698
App. No.
18/521,480
Granted
Feb 10, 2026
Kind
B2
Abstract

An electronic device includes a debug port providing a communications interface for debugging purposes, a plurality of processing unit access ports, an authentication interface circuit configured to authenticate the external device, and a further access port coupled between the debug port and the authentication interface circuit. The further access port is configured to be in an open state in which communications are relayed between the debug port and the authentication interface circuit. The authentication interface circuit has registers including a status register capable of being read by the external device via the debug port and the further access port, the status register being configured to store an indication of the open or closed state of each of the processing unit access ports.

Claims (67)

1 . An electronic device, comprising:

a debug port providing a communications interface for debugging purposes;

a first processing unit;

a plurality of processing unit access ports coupled to the debug port, a first processing unit access port of the plurality of processing unit access ports being coupled between the debug port and the first processing unit, each of the plurality of processing unit access ports being configured to be in one of an open state in which it relays communications to and from the debug port and a closed state in which it blocks communications to and from the debug port;

an authentication interface circuit configured to authenticate an external device; and

a further access port coupled between the debug port and the authentication interface circuit, the further access port being configured to be in an open state in which communications are relayed between the debug port and the authentication interface circuit, the authentication interface circuit comprising registers including a status register configured to be readable by the external device via the debug port and the further access port, the status register being further configured to store an indication of the open or closed state of each of the plurality of processing unit access ports.

2 . The electronic device of claim 1 , wherein the registers further include a host register configured to be readable by the first processing unit and to be writeable to by the external device via the debug port and the further access port.

3 . The electronic device of claim 1 , wherein the registers further include a device register configured to be readable by the external device via the debug port and the further access port and to be writeable to by the first processing unit.

4 . The electronic device of claim 3 , wherein the registers further include:

a host register configured to be readable by the first processing unit and to be writeable to by the external device via the debug port and the further access port; and

an acknowledge register configured to indicate when at least part of an electronic message is available to be read in the host register and when at least part of an electronic message is available to be read in the device register.

5 . The electronic device of claim 4 , wherein the acknowledge register is configured to be read-only for the first processing unit and for the external device.

6 . The electronic device of claim 4 , wherein the authentication interface circuit is configured to:

detect when at least part of an electronic message has been written to the host register, and in response thereto to set a host acknowledge bit in the acknowledge register; and

detect when the first processing unit reads the host register, and in response thereto reset the host acknowledge bit in the acknowledge register.

7 . The electronic device of claim 4 , wherein the authentication interface circuit is configured to:

detect when at least part of an electronic message has been written to the device register, and in response thereto set a device acknowledge bit in the acknowledge register; and

detect when the external device reads the device register, and in response thereto reset the device acknowledge bit in the acknowledge register.

8 . The electronic device of claim 4 , wherein the first processing unit is configured to:

read from the host register an authentication request from the external device;

authenticate the external device; and

set at least one of the plurality of processing unit access ports to an open state, thereby causing the indication of a state of the plurality of processing unit access ports to be updated in the status register.

9 . The electronic device of claim 8 , wherein the registers further include:

a host register configured to be readable by the first processing unit and to be writeable to by the external device via the debug port and the further access port; and

a device register configured to be readable by the external device via the debug port and the further access port and to be writeable to by the first processing unit;

wherein the first processing unit is configured to authenticate the external device by:

storing an authentication challenge or password request to the device register;

reading an authentication certificate or password from the host register; and

verifying the authentication certificate or password.

10 . The electronic device of claim 9 , further comprising a monotonic counter, wherein the first processing unit is further configured to read from the authentication certificate an indication of a count value from which debug functionality is authorized, and to execute a boot sequence comprising an incrementation of the monotonic counter, the debug functionality being authorized once the monotonic counter has reached said count value.

11 . The electronic device of claim 1 , wherein each processing unit access port of the plurality of processing unit access ports is coupled to an associated processing unit.

12 . The electronic device of claim 1 , further comprising:

a peripheral interface; and

a peripheral interface access port coupled between the debug port and the peripheral interface, the peripheral interface access port being configured to be in one of an open state in which it relays communications to and from the debug port and a closed state in which it blocks communications to and from the debug port, wherein the status register is configured to store an indication of the open or closed state of the peripheral interface access port.

13 . A method for managing communications in an electronic device, the method comprising:

providing a communications interface for debugging purposes via a debug port;

coupling a first processing unit to the debug port via a first processing unit access port of a plurality of processing unit access ports;

selectively setting each of the plurality of processing unit access ports to one of:

an open state wherein communications to and from the debug port are relayed; and

a closed state wherein communications to and from the debug port are blocked;

authenticating an external device using an authentication interface circuit;

coupling the debug port to the authentication interface circuit via a further access port, wherein in an open state communications are relayed between the debug port and the authentication interface circuit;

reading, by the external device, a status register in the authentication interface circuit via the debug port and the further access port;

storing, in the status register, an indication of the open or closed state of each of the plurality of processing unit access ports;

reading, by the external device via the debug port and the further access port, states of each of the plurality of processing unit access ports stored by the status register; and

initiating, by the external device, the debug of one or more of the plurality of processing unit access ports that is in the open state.

14 . The method of claim 13 , further comprising:

reading, by the external device via the debug port and the further access port, a device register in the authentication interface circuit; and

writing, by the first processing unit, to the device register.

15 . The method of claim 14 , further comprising:

reading, by the first processing unit, a host register in the authentication interface circuit;

writing, by the external device via the debug port and the further access port, to the host register; and

indicating, via an acknowledge register, availability of an electronic message in the host register and the device register.

16 . The method of claim 15 , wherein the acknowledge register is accessed in a read-only mode by the first processing unit and the external device.

17 . The method of claim 15 , further comprising:

detecting, by the authentication interface circuit, a written electronic message in the host register;

setting a host acknowledge bit in the acknowledge register; and

resetting the host acknowledge bit upon the host register being read by the first processing unit or the external device.

18 . The method of claim 15 , further comprising:

reading, by the first processing unit, an authentication request from the host register;

authenticating the external device;

setting at least one of the plurality of processing unit access ports to an open state, thereby updating the indication of a state of the plurality of processing unit access ports in the status register;

storing, by the first processing unit, an authentication challenge or password request in the device register;

reading an authentication certificate or password from the host register;

verifying the authentication certificate or password;

reading, by the first processing unit, a count value from an authentication certificate from which debug functionality is authorized; and

executing a boot sequence that includes incrementing a monotonic counter, where the debug functionality is authorized once the monotonic counter reaches the count value.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2024
From: STMICROELECTRONICS (ALPS) SAS
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 068113/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2024
From: STMICROELECTRONICS (GRENOBLE 2) SAS
To: STMICROELECTRONICS INTERNATIONAL N.V.
Reel/Frame 068113/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: CHBANI, XAVIER
To: STMICROELECTRONICS (ALPS) SAS
Reel/Frame 065686/0502 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2023
From: VAN-DEN-BOSSCHE, NADIA
To: STMICROELECTRONICS (GRENOBLE 2) SAS
Reel/Frame 065686/0604 →
Priority Claims (1)
FR 2212575 · Nov 30, 2022 · national
Continuity (1)
Related Publication 20240176864A1 · May 30, 2024
References Cited (8)
US 20110066835A1 · Kothari et al. · 2011 [cited by applicant]
US 20170139008A1 · Lim · 2017 [cited by examiner]
US 20190361073A1 · Trantham · 2019 [cited by applicant]
US 20220317184A1 · Albesa et al. · 2022 [cited by applicant]
WO WO2020002441A1 · 2020 [cited by examiner]
WO WO2023030947A1 · 2023 [cited by examiner]
INPI Search Report and Written Opinion for priority application, FR Appl. 2212575, report dated Aug. 12, 2023, 9 pgs. [cited by applicant]
NXP: UM11126 LPC55S6x User Manual, Rev. 1.3, May 10, 2019, 1148 pgs., See Debug Section, Chapter 51, 22 pgs. [cited by applicant]