IP Library Granted Patent US 9,323,942
Granted Patent B2
US 9,323,942 · App. 14/591,138 · Granted Apr 26, 2016

Protecting information processing system secrets from debug attacks

Inventors: Vedvyas Shanbhogue (Austin, TX); Jason W. Brandt (Austin, TX); Jeff Wiedemeier (Austin, TX)
Assignee: Intel Corporation
G06F21/62G01R31/3177G01R31/31719G01R31/318588G06F11/0727G06F11/3656G06F21/71G06F21/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,323,942
App. No.
14/591,138
Granted
Apr 26, 2016
Kind
B2
Abstract

Embodiments of an invention for protecting information processing system secrets from debug attacks are disclosed. In one embodiment, a processor includes storage, a debug unit, and a test access port. The debug unit is to receive a policy from a debug aggregator. The policy is based on a value of a first fuse and has a production mode corresponding to a production value of the first fuse and a debug mode corresponding to a debug value of the fuse. The test access port is to provide access to the storage using a debug command in the debug mode and to prevent access to the storage using the debug command in the production mode.

Claims (19)

1. A processor comprising:

storage;

a debug unit to receive a policy from a debug aggregator, the policy based on a value of a first fuse, the policy having a production mode corresponding to a production value of the first fuse and a debug mode corresponding to a debug value of the fuse;

a test access port to provide access to the storage using a debug command in the debug mode and to prevent access to the storage using the debug command in the production mode;

wherein the policy is also based on the value of an unlock signal, the unlock signal indicating the use of an authenticated debugger, the policy also having a locked mode corresponding to a locked value of the unlock signal, the test access port also to prevent access to the storage using the debug command in the locked mode;

wherein the debug mode also corresponds to an unlocked value of the unlock signal.

2. The processor of claim 1 , wherein the policy is also based on the value of a second fuse, the policy also having a manufacturing mode corresponding to a manufacturing value of the second fuse, the test access port also to provide access to the storage using the debug command in the manufacturing mode.

3. The processor of claim 1 , further comprising an indicator to allow the test access port to provide access to the storage using the debug command in the production mode.

4. The processor of claim 3 , wherein the indicator is writable by microcode during a reset.

5. The processor of claim 1 , wherein the storage is cleared by an unlock signal indicating the use of an authenticated debugger.

6. The processor of claim 1 , further comprising a secure enclave unit to store secrets in the storage.

7. A system comprising:

a processor having storage and a test access port;

a first fuse having a production value and a debug value;

a debug aggregator to authenticate a debugger and to send a policy to the test access port, the policy having a production mode corresponding to the production value of the first fuse and a debug mode corresponding to the debug value of the first fuse, wherein the test access port is to provide access to the storage using a debug command in the debug mode and to prevent access to the storage using the debug command in the production mode;

wherein the policy is also based on the value of an unlock signal, the unlock signal indicating the use of an authenticated debugger, the policy also having a locked mode corresponding to a locked value of the unlock signal, the test access port also to prevent access to the storage using the debug command in the locked mode;

wherein the debug mode also corresponds to an unlocked value of the unlock signal.

8. The system of claim 7 , further comprising a debug bus, wherein the policy is sent from the debug aggregator to the test access port on the debug bus.

9. The system of claim 7 , further comprising a second fuse having a manufacturing value, the policy also having a manufacturing mode corresponding to the manufacturing value of the second fuse, wherein the test access port is to provide access to the storage using the debug command in the manufacturing mode.

Continuity (2)
Continuation 13929945 · Jun 28, 2013
Related Publication 20150161408A1 · Jun 11, 2015