4.2 Description of the First Documented Facts …
297
4.2.2 Features and Critical Points of the ProASIC3 Chip
Security Structure
It is generally known that more complex integrated circuits are more difficult to
test. As a rule, at the stage of inspection of the first (experimental) prototypes of
microcircuits, the developers need to perform standard design inspection for compliance with the initial technical assignment and eliminate the inevitable mistakes. For
this purpose, most modern manufactures use JTAG interface as a standard port for
additional IC testing.
In early 2000, the JTAG specification was distributed among potential buyers
along with programming characteristics and security rules to meet the requirements
of the FPGA market competition. However, before chip manufacturers started widely
(even if silently) using possibilities of extended JTAG protocols, they usually referred
to the IEEE 1149.x standard. Of course, this extension wasn’t officially standardized
and remained secret for most chips. However, it allowed chip manufacturers to use
standard libraries for utilization of the JTAG protocol without affecting security of
their chips for a long time. It is clear that it was convenient for all manufacturers
to use such undocumented (hidden) commands to ensure their own online access to
JTAG or a test interface, since some of such chips still provide the possibility of direct
access to the contents of the internal memory, which theoretically allows unlimited
access to any intellectual property (IP) of the end user, as well as other secret data
[112–114].
As is well known, the JTAG functionality is ensured by standard TAPs (test access
ports) that fully control the state machine (Fig. 4.16). It is necessary to remember
that there are two registers here: IR (instructor register) and DR (data register), in
which all serial data of a signal are recorded and subsequently actively used. In other
words, at first, the necessary IR registers are selected; then, depending on the type of
the command, specific data are sent to the RD register. Of course, the length of the IR
register varies from one chip to another and usually lies within 4 or 32 bits. Certain
commands are not even connected to the DR register; for others, its length may reach
many thousand bits: it depends both on the specific engineer responsible for design
of this chip and on the sphere of responsibility of the planned use of microcircuit.
Of course, as noted above, for most modern microcontrollers and FGPAs, specific
codes of commands and data of JTAG registers are usually unavailable to the end user
of microcircuits due to security reasons. However, an experienced intruder can easily
obtain the necessary information even from standard development kits if they are
accessed. For example, in the examined case [110], the task of collecting information
on JTAG commands in FPGA kits was solved by using the special high-level testing
language Standard Test and Programming Language (STAPL) [113]. Here, all fields
of commands and data in the programming file, which are compiled with the help
of standard CAD tools, can be easily identified by multiple subprograms available
even on the Internet.
However, it needs to be said that even good knowledge of all standard JTAG
commands is by far not enough to find deliberately embedded Trojans and backdoors.
Précédent

- 316/839

Suivant