TH65768B - Methods and devices for securing communication ports in electronic devices. - Google Patents

Methods and devices for securing communication ports in electronic devices.

Info

Publication number
TH65768B
TH65768B TH601003333A TH0601003333A TH65768B TH 65768 B TH65768 B TH 65768B TH 601003333 A TH601003333 A TH 601003333A TH 0601003333 A TH0601003333 A TH 0601003333A TH 65768 B TH65768 B TH 65768B
Authority
TH
Thailand
Prior art keywords
mode
port
access
firmware
drive
Prior art date
Application number
TH601003333A
Other languages
Thai (th)
Other versions
TH85838A (en
Inventor
จูเนียร์
เดวิด ทรานธัม นายจอน
วิลเลี่ยม ธีสเฟลด์ นายชาร์ลส
เพรสตัน แมทธิวส์ นายโดนัลด์
โรซิแนค บีเวอร์ นายโดนัลด์
เออารอน โฟรแฮนด์ นายมอนตี้
เวน มอส นายโรเบิร์ต
ฮาร์ส นายลาสซ์โล
เพรสตัน กู้ดวิลล์ นายวิลเลียม
Original Assignee
ซีเกท เทคโนโลยี แอลแอลซี
นางดารานีย์ วัจนะวุฒิวงศ์
นางดารานีย์ วัจนะวุฒิวงศ์ นางสาวสนธยา สังขพงศ์
นางสาวสนธยา สังขพงศ์
Filing date
Publication date
Application filed by ซีเกท เทคโนโลยี แอลแอลซี, นางดารานีย์ วัจนะวุฒิวงศ์, นางดารานีย์ วัจนะวุฒิวงศ์ นางสาวสนธยา สังขพงศ์, นางสาวสนธยา สังขพงศ์ filed Critical ซีเกท เทคโนโลยี แอลแอลซี
Publication of TH85838A publication Critical patent/TH85838A/en
Publication of TH65768B publication Critical patent/TH65768B/en

Links

Abstract

DC60 อุปกรณ์จะประกอบด้วยพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ต สำหรับเชื่อมต่อสัญญาณกับอุปกรณ์, ตัว เลือกโหมด สำหรับตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่อง และส่วนควบคุมพอร์ต สำหรับควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์ โดยผ่านพอร์ตตามโหมดที่เลือก นอกจากนี้ยังมี วิธีการสำหรับควบคุมการเข้าถึงพอร์ตด้วยThe DC60 device will include at least one port for signal connection to devices, a mode selector for setting the device to normal or debug mode, and a port controller for securely controlling data access on the device through the port according to the selected mode. Additionally, there are methods for controlling port access.

Claims (20)

------04/12/2560------(OCR) หน้า 1 ของจำนวน 4 หน้า ข้อถือสิทธิ------04/12/2560------(OCR) Page 1 of 4 pages. Claims. 1. อุปกรณ์ซึ่งประกอบด้วย พอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตสำหรับเชื่อมต่อสัญญาณกับอุปกรณ์ ตัวเลือกโหมดดึงขื้น/ลงสำหรับตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่อง และ ส่วนควบคุมพอร์ตสำหรับควบคุมการเข้าถึงสารสนเทศที่ปลอดภัยในอุปกรณ์ผ่านพอร์ตตาม โหมดที่เลือก ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดแก้จุดบกพร่อง, การเข้าถึงรหัสตัวเลขที่เป็นรากจะถูกป้องกัน และรหัสตัวเลขที่เป็นทางเลือกจะสามารถเข้าถึงได้1. The device comprises at least one port for signal connection to other devices, a pull-up/down mode selector for setting the device into normal or debug mode, and a port controller for controlling access to secure information on the device through the port according to the selected mode. When the device is in debug mode, root access is prevented, and optional access is permitted. 2. อุปกรณ์ของข้อถือสิทธิ 1 ยังประกอบด้วย วงจรสำหรับการแลตช์สภาวะของตัวเลือกโหมดดึงขึ้น/ลงโดยตอบสนองต่อสัญญาณรีเซต2. The device of claim 1 also includes a circuit for latching the pull-up/down mode selector state in response to a reset signal. 3. อุปกรณ์ของข้อถือสิทธิ 1 ที่ซึ่งระดับที่แตกต่างกันของความสามารถเข้าถึงได้จะถูกจัดให้มีขึ้น โดยขึ้นอยู่กับหนึ่งอย่างหรือทั้งสองในลักษณะของพอร์ตและระดับของความเสี่ยงต่อความปลอดภัยที่ เกิดขึ้นโดยการเข้าใช้พอร์ตโดยไม่ได้รับอนุญาต3. The provisions of Claim 1 shall be provided for in which different levels of accessibility shall be provided depending on one or both the nature of the port and the level of security risk posed by unauthorized access to the port. 4. อุปกรณ์ของข้อถือสิทธิ 1 ที่ซึ่งอุปกรณ์ประกอบด้วย ดิสก์ไดรฟ์4. The device of claim 1, which includes a disk drive. 5. อุปกรณ์ซึ่งประกอบด้วย พอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตสำหรับเชื่อมต่อสัญญาณกับอุปกรณ์ ตัวเลือกโหมดสำหรับตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่อง และ ส่วนควบคุมพอร์ตสำหรับควบคุมการเข้าถึงสารสนเทศที่ปลอดภัยในอุปกรณ์ผ่านพอร์ตตาม โหมดที่เลือก ส่วนควบคุมพอร์ตจะยอมให้มีการดาวน์โหลดไดรฟ์เฟิร์มแวร์เท่านั้น ถ้าอุปกรณ์ไม่ได้มีส่วนที่ เป็นไดรฟ์เฟิร์มแวร์อยู่ตั้งแต่ต้น5. The device consists of at least one port for connecting signals to other devices, a mode selection option for setting the device to normal or debug mode, and a port controller for controlling secure access to information on the device through the port according to the selected mode. The port controller will only allow firmware downloads if the device does not originally contain a firmware drive component. 6. อุปกรณ์ของข้อถือสิทธิ 5 ที่ซึ่งอุปกรณ์จะจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลดลง เมื่อ อยู่ในโหมดแก้จุดบกพร่อง6. The device under claim 5, which provides an indication of decreased trust conditions when in debugging mode. 7. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่องโดยใช้ตัวเลือกโหมดดึงขึ้น/ลง หน้า 2 ของจำนวน 4 หน้า และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดโหมดแก้จุดบกพร่อง ขั้นตอนการควบคุมการเข้าถึงสารสนเทศที่ ปลอดภัยจะประกอบด้วย การป้องกันการเข้าถึงรหัสตัวเลขที่เป็นราก และการจัดให้มีการเข้าถึงรหัสตัวเลขที่เป็นทางเลือก7. Methods for controlling access to at least one port of the device. These methods include setting the device to normal or debug mode using the pull-up/down mode selector (page 2 of 4) and controlling secure data access on the device through the port according to the selected mode. When the device is in debug mode, the secure information access control procedures include preventing root access using numeric codes and providing alternative access using numeric codes. 8. วิธีการของข้อถือสิทธิ 7 ยังประกอบด้วย การแลตช์สภาวะของตัวเลือกโหมดดึงขึ้น/ลงโดยตอบสนองต่อสัญญาณรีเซต8. The method of claim 7 also involves latching the pull-up/down mode selector state in response to a reset signal. 9. วิธีการของข้อถือสิทธิ 7 ที่ซึ่งขั้นตอนการป้องกันการเข้าถึงรหัสตัวเลขที่เป็นราก และการจัดให้ มีการเข้าถึงรหัสตัวเลขที่เป็นทางเลือก จะประกอบด้วย การสับเปลี่ยนเส้นทางรหัสตัวเลขที่เป็นรากไปยังเส้นทางรหัสตัวเลขที่เป็นทางเลือก9. The method of claim 7, where the procedure for protecting access to the root numeric code and providing access to the alternative numeric code, shall consist of rerouting the root numeric code to the alternative numeric code path. 10. วิธีการของข้อถือสิทธิ 7 ที่ซึ่งระดับที่แตกต่างกันของความสามารถเข้าถึงได้จะถูกจัดให้มีขึ้น โดยขึ้นอยู่กับในลักษณะของพอร์ตและ/หรือระดับของความเสี่ยงต่อความปลอดภัยที่เกิดขึ้นโดยการเข้าใช้ พอร์ตโดยไม่ได้รับอนุญาต10. Method of Claim 7 where different levels of accessibility are provided depending on the nature of the port and/or the level of security risk posed by unauthorized access to the port. 11. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่องโดยใช้ตัวเลือกโหมด และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก ส่วนควบคุมพอร์ตจะยอมให้มีการดาวน์โหลดไดรฟ์เฟิร์มแวร์เท่านั้น ถ้าอุปกรณ์ไม่ได้มีส่วนที่ เป็นไดรฟ์เฟิร์มแวร์อยู่ตั้งแต่ด้น11. Methods for controlling access to at least one port on the device include setting the device to normal or debug mode using the mode selector, and controlling secure data access on the device through the port according to the selected mode. The port controller will only allow firmware driver downloads if the device does not already have a firmware driver component. 12. วิธีการของข้อถือสิทธิ 11 ที่ซึ่งอุปกรณ์จะจัดให้มีการบ่ง ชี้สภาวะความน่าไว้วางใจที่ลดลงเมื่อ อยู่ในโหมดแก้จุดบกพร่อง12. Method of claim 11 where the device shall provide an indication of a decreased trust condition when in debugging mode. 13. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์ วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่องโดยใช้ตัวเลือกโหมด และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก หน้า3ของจำนวน4หน้า ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดปกติก็จะเริ่มต้นค่าพอร์ตแบบอนุกรมให้อยู่ในสภาวะที่ถูกปิดทาง และตรวจหาไดร์ฟเฟิร์มแวร์ที่ใช้ได้ในอุปกรณ์ จากนั้น ถ้าไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ในอุปกรณ์ ก็จะ ควบคุมพอร์ตแบบอนุกรมโดยใช้เฟิร์มแวร์ของไดร์ฟ และ เมื่ออุปกรณ์อยู่ในโหมดแก้อุดบกพร่อง ก็จะเปิดทางพอร์ตแบบอนุกรมสำหรับการดาวน์โหลด ไดรฟ์เฟิร์มแวร์เท่านั้น13. Method for controlling access to at least one port of the device. The method consists of setting the device to normal mode or debug mode using the mode selector, and controlling secure data access on the device through the port according to the selected mode. Page 3 of 4 shows that when the device is in normal mode, the serial port is initially set to a closed state and searches for a usable firmware drive on the device. Then, if a usable firmware drive is present on the device, the serial port is controlled using the drive's firmware. When the device is in debug mode, the serial port is opened only for downloading the firmware drive. 14. วิธีการของข้อถือสิทธิ 13 ยังประกอบด้วย การจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลดลง เมื่ออยู่ในโหมดแก้จุดบกพร่อง14. The methodology of claim 13 also includes providing an indication of decreased reliability when in debugging mode. 15. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์ วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้อุดบกพร่องโดยใช้ตัวเลือกโหมด และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดปกติ ไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ในอุปกรณ์ และพอร์ตแบบอนุกรมถูก เปิดทาง ก็จะยอมให้มีการดาวน์โหลดไดร์ฟเฟิร์มแวร์โดยผ่านพอร์ตอนุกรม, อินเตอร์เฟสแม่ข่าย หรือการ เข้าถึง JTAG ที่ถูกพิสูจน์ว่าเป็นตัวจริง15. Method for controlling access to at least one port of the device. The method consists of setting the device to normal mode or debug mode using the mode selector, and controlling secure data access on the device through the port according to the selected mode. When the device is in normal mode, the available firmware drive is on the device, and the serial port is open, allowing firmware download via the serial port, host interface, or authenticated JTAG access. 16. วิธีการของข้อถือสิทธิ 15 ยังประกอบด้วย การจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลดลง เมื่ออยู่ในโหมดแก้อุดบกพร่อง16. The methodology of claim 15 also includes providing for an indication of reduced reliability when in correction mode. 17. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์ วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่องโดยใช้ตัวเลือกโหมด และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดปกติ ไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ในอุปกรณ์ และพอร์ตแบบอนุกรมถูก ปิดทาง ก็จะยอมให้มีการดาวน์โหลดไดร์ฟเฟิร์มแวร์โดยผ่านอินเตอร์เฟสแม่ข่าย หรือการเข้าถึง JTAG ที่ ถูกพิสูจน์ว่าเป็นตัวจริง17. Method for controlling access to at least one port of the device. The method consists of setting the device to normal mode or debug mode using the mode selector, and controlling secure data access on the device through the port according to the selected mode. When the device is in normal mode, the available firmware drive is on the device, and the serial port is closed, allowing firmware download via the host interface or authenticated JTAG access. 18. วิธีการของข้อถือสิทธิ 17 ยังประกอบด้วย การจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลดลง เมื่ออยู่ในโหมดแก้จุดบกพร่อง 19. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์ วิธีการประกอบด้วย การตั้งอุปกรณ์ให้อยู่ในโหมดปกติหรือโหมดแก้จุดบกพร่องโดยใช้ตัวเลือกโหมด และ หน้า4ของจำนวน4หน้า การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์โดยผ่านพอร์ตตามโหมดที่เลือก ที่ซึ่งเมื่ออุปกรณ์อยู่ในโหมดปกติ และไดร์ฟเฟิร์มแวร์ที่ใช้ได้ไม่อยู่ในอุปกรณ์ ก็จะเปิดทางพอร์ต แบบอนุกรมสำหรับการดาวน์โหลดไดรฟ์เฟิร์มแวร์เท่านั้น 20. วิธีการของข้อถือสิทธิ 19 ยังประกอบด้วย การปิดทางพอร์ต JTAG ในระหว่างการเปิดการทำงาน และเมื่ออุปกรณ์อยู่ในโหมดปกติ 21. วิธีการของข้อถือสิทธิ 19 ยังประกอบด้วย การเปิดทางพอร์ต JTAG ในหนึ่งในบรรดาโหมดปฏิบัติการหลายโหมด ------------ 1. อุปกรณ์ซึ่งมีส่วนประกอบดังต่อไปนี้ พอร์ตอย่างน้อยที่สุดหนึ่งพอร์ต สำหรับเชื่อมต่อ สัญญาณกับอุปกรณ์ ตัวเลือกโหมดสำหรับตั้งอุปกรณ์ให้อยู่ในโหมดปกติ หรือโหมดแก้จุดบกพร่อง และ ส่วนควบคุมพอร์ต สำหรับควบคุมการเข้าถึงสารสนเทศที่ปลอดภัยในอุปกรณ์ โดยผ่านพอร์ต ตามโหมดที่เลือก 2. อุปกรณ์ดังระบุในข้อถือสิทธิ 1 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดแก้จุดบกพร่อง การเข้าถึงรหัสตัว เลขที่เป็นรากจะถูกป้องกัน และรหัสตัวเลขที่เป็นทางเลือกจะสามารถเข้าถึงได้ 3. อุปกรณ์ดังระบุในข้อถือสิทธิ 1 โดยที่ส่วนควบคุมพอร์ตจะยอมให้มีการดาวน์โหลดไดรฟ์ เฟิร์มแวร์เท่านั้น ถ้าอุปกรณ์ไม่ได้มีส่วนที่เป็นไดรฟ์เฟิร์มแวร์อยู่ตั้งแต่ต้น 4. อุปกรณ์ดังระบุในข้อถือสิทธิ 1 โดยที่อุปกรณ์จะจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลด ลง เมื่ออยู่ในโหมดแก้จุดบกพร่อง 5. อุปกรณ์ดังระบุในข้อถือสิทธิ 1 โดยที่ระดับของความสามารถเข้าถึงได้ที่แตกต่างกัน จะถูกจัด ให้มีขึ้น โดยขึ้นอยู่กับลักษณะของพอร์ต และ/หรือ ระดับความเสี่ยงต่อความปลอดภัยที่เกิดขึ้นโดยการเข้า ใช้พอร์ตโดยไม่ได้รับอนุญาต 6. อุปกรณ์ดังระบุในข้อถือสิทธิ 1 โดยที่อุปกรณ์จะประกอบด้วยดิสก์ไดรฟ์ 7. วิธีการควบคุมการเข้าถึงพอร์ตอย่างน้อยที่สุดหนึ่งพอร์ตของอุปกรณ์ โดยที่วิธีการจะประกอบ ด้วยขั้นตอนดังต่อไปนี้ การตั้งอุปกรณ์ให้อยู่ในโหมดปกติ หรือโหมดแก้จุดบกพร่อง โดยใช้ตัวเลือกโหมด และ การควบคุมการเข้าถึงข้อมูลที่ปลอดภัยในอุปกรณ์ โดยผ่านพอร์ตตามโหมดที่เลือก 8. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดแก้จุดบกพร่อง ขั้นตอนการควบ คุมการเข้าถึงสารสนเทศที่ปลอดภัยจะประกอบด้วย การป้องกันการเข้าถึงรหัสตัวเลขที่เป็นราก และ การจัดให้มีการเข้าถึงรหัสตัวเลขที่เป็นทางเลือก 9. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ขั้นตอนการป้องกันการเข้าถึงรหัสตัวเลขที่เป็นราก และ การจัดให้มีการเข้าถึงรหัสตัวเลขที่เป็นทางเลือก จะประกอบด้วย การสับเปลี่ยนเส้นทางรหัสตัวเลขที่เป็นรากไปยังเส้นทางรหัสตัวเลขที่เป็นทางเลือก 10. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ส่วนควบคุมพอร์ตจะยอมให้มีการดาวน์โหลดไดรฟ์ เฟิร์มแวร์เท่านั้น ถ้าอุปกรณ์ไม่ได้มีส่วนที่เป็นไดรฟ์เฟิร์มแวร์อยู่ตั้งแต่ต้น 11. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่อุปกรณ์จะจัดให้มีการบ่งชี้สภาวะความน่าไว้วางใจที่ลด ลง เมื่ออยู่ในโหมดแก้จุดบกพร่อง 12. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ระดับของความสามารถเข้าถึงได้ที่แตกต่างกัน จะถูกจัด ให้มีขึ้น โดยขึ้นอยู่กับลักษณะของพอร์ต และ/หรือ ระดับความเสี่ยงต่อความปลอดภัยที่เกิดขึ้น โดยการเข้า ใช้พอร์ตโดยไม่ได้รับอนุญาต 13. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดปกติก็จะเริ่มต้นค่าพอร์ตแบบอนุกรมให้อยู่ในสภาวะที่ถูกปิดทาง และ ตรวจหาไดร์ฟเฟิร์มแวร์ที่ใช้ได้ในอุปกรณ์ จากนั้น ถ้าไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ในอุปกรณ์ ก็จะควบคุม พอร์ตแบบอนุกรม โดยใช้เฟิร์มแวร์ของไดร์ฟ และ ถ้าอุปกรณ์อยู่ในโหมดแก้จุดบกพร่อง ก็จะเปิดทางพอร์ตแบบอนุกรมสำหรับการดาวน์โหลด ไดรฟ์เฟิร์มแวร์เท่านั้น 14. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดปกติ ไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ ในอุปกรณ์ และพอร์ตแบบอนุกรมถูกเปิดทาง ก็จะยอมให้มีการดาวน์โหลดไดร์ฟเฟิร์มแวร์ โดยผ่าน พอร์ตอนุกรม, อินเตอร์เฟสแม่ข่าย หรือการเข้าถึง JTAG ที่ถูกพิสูจน์ว่าเป็นตัวจริง 15. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดปกติ ไดร์ฟเฟิร์มแวร์ที่ใช้ได้อยู่ ในอุปกรณ์ และพอร์ตแบบอนุกรมถูกปิดทาง ก็จะยอมให้มีการดาวน์โหลดไดร์ฟเฟิร์มแวร์ โดยผ่านอิน เตอร์เฟสแม่ข่าย หรือการเข้าถึง JTAGที่ถูกพิสูจน์ว่าเป็นตัวจริง 16. วิธีการดังระบุในข้อถือสิทธิ 7 โดยที่ ถ้าอุปกรณ์อยู่ในโหมดปกติ และไดร์ฟเฟิร์มแวร์ที่ใช้ได้ ไม่ได้อยู่ในอุปกรณ์ ก็จะเปิดทางพอร์ตแบบอนุกรมสำหรับการดาวน์โหลดไดรฟ์เฟิร์มแวร์เท่านั้น 17. วิธีการดังระบุในข้อถือสิทธิ 7 ซึ่งยังประกอบด้วย การปิดทางพอร์ต JTAG ในระหว่างการเปิดการทำงาน และเมื่ออุปกรณ์อยู่ในโหมดปกติ 18. วิธีการดังระบุในข้อถือสิทธิ 7 ซึ่งยังประกอบด้วย การเปิดทางพอร์ต JTAG ในหนึ่งในบรรดาโหมดปฏิบัติการหลายโหมด18. The method of Claim 17 also includes providing an indication of a degraded trust condition when in debug mode. 19. The method of controlling access to at least one port of the device includes setting the device to normal or debug mode using a mode selector, and page 4 of 4, controlling secure access to information on the device through the port according to the selected mode, where when the device is in normal mode and no usable firmware drive is present on the device, only the serial port is open for downloading the firmware drive. 20. The method of Claim 19 also includes closing the JTAG port during power-on and when the device is in normal mode. 21. The method of Claim 19 also includes opening the JTAG port in one of several operating modes. ------------ 1. A device having the following components: at least one port for connecting signals to the device; a mode selector for setting the device to normal or debug mode; and a port controller for controlling access to secure information on the device through the port according to the selected mode. 2. A device as described in Claim 1, where if the device is in debug mode, root access is prevented. and an optional numeric code will be accessible. 3. The device as specified in Claim 1 where the port controller will only allow the download of the firmware drive if the device does not have a firmware drive component from the outset. 4. The device as specified in Claim 1 where the device will provide an indication of a reduced trust condition when in debugging mode. 5. The device as specified in Claim 1 where different levels of access will be provided depending on the nature of the port and/or the level of security risk posed by unauthorized access to the port. 6. The device as specified in Claim 1 where the device will contain a disk drive. 7. A method for controlling access to at least one port of the device where the method will consist of the following steps: setting the device to normal or debugging mode using the mode selector, and controlling secure access to data on the device through the port according to the selected mode. 8. The method as specified in Claim 7 where, if the device is in debugging mode, the procedure for controlling secure access to information will consist of: 9. The method described in Claim 7, whereby the root access protection and alternative access provisioning procedures shall involve rerouting the root access code to an alternative access path. 10. The method described in Claim 7, whereby the port controller shall only allow firmware drive downloads if the device does not have a firmware drive component from the outset. 11. The method described in Claim 7, whereby the device shall provide an indication of a decreased trust state when in debugging mode. 12. The method described in Claim 7, whereby different levels of accessibility shall be provided depending on the nature of the port and/or the level of security risk posed by unauthorized port access. 13. The method described in Claim 7, whereby if the device is in normal mode, the serial port shall be initially set to a closed state and search for an available firmware drive on the device. Then, if an available firmware drive is present on the device, the serial port shall be controlled using the drive's firmware. If the device is in debugging mode, the serial port shall be opened for download. 14. The method specified in Claim 7, whereby if the device is in normal mode, an available firmware drive is present in the device, and the serial port is open, allows firmware drive download via the serial port, host interface, or authenticated JTAG access. 15. The method specified in Claim 7, whereby if the device is in normal mode, an available firmware drive is present in the device, and the serial port is closed, allows firmware drive download via the host interface or authenticated JTAG access. 16. The method specified in Claim 7, whereby if the device is in normal mode and an available firmware drive is not present in the device, allows the serial port to be open only for firmware drive download. 17. The method specified in Claim 7, which also includes closing the JTAG port during power-on and when the device is in normal mode. 18. The method specified in Claim 7, which also includes opening the JTAG port in one of several operating modes. 19. วิธีการทดสอบขอบเขต ซึ่งประกอบด้วย การตรวจจับสัญญาณรีเซ็ต การลบล้างเนื้อหาขององค์ประกอบหน่วยจัดเก็บของอุปกรณ์ในการตอบสนองต่อสัญญาณรีเซ็ต การจัดวางอุปกรณ์ในโหมดการทดสอบด้วยการสแกน และการดำเนินการทดสอบด้วยการสแกน บนส่วนประกอบของอุปกรณ์ และ การลบล้างเนื้อหาขององค์ประกอบในการจัดเก็บของอุปกรณ์ ก่อนออกจากโหมดการทดสอบ ด้วยการสแกน19. The boundary testing method comprises: detecting a reset signal; erasing the contents of the device's storage components in response to a reset signal; placing the device in scan test mode; performing scan tests on the device components; and erasing the contents of the device's storage components before exiting scan test mode. 20. อุปกรณ์ซึ่งมีส่วนประกอบดังต่อไปนี้ โมดูลสกัดกั้นสัญญาณสแกน สำหรับรับสัญญาณให้อำนาจโหมดสแกนระบบ และสำหรับตรวจ จับสัญญาณรีเซ็ตระบบ เพื่อลบล้างเนื้อหาขององค์ประกอบหน่วยจัดเก็บของอุปกรณ์ เพื่อจัดวางอุปกรณ์ ในโหมดการทดสอบด้วยการสแกน และเพื่อลบล้างเนื้อหาขององค์ประกอบหน่วยจัดเก็บของอุปกรณ์ ก่อนออกจากโหมดการทดสอบด้วยการสแกน20. A device comprising the following components: a scan signal interception module for receiving the signal to authorize system scan mode and for detecting the system reset signal to erase the contents of the device's storage components, to place the device in scan test mode, and to erase the contents of the device's storage components before exiting scan test mode.
TH601003333A 2006-07-14 Methods and devices for securing communication ports in electronic devices. TH65768B (en)

Publications (2)

Publication Number Publication Date
TH85838A TH85838A (en) 2007-08-10
TH65768B true TH65768B (en) 2018-10-22

Family

ID=

Similar Documents

Publication Publication Date Title
US8156317B2 (en) Integrated circuit with secure boot from a debug access port and method therefor
US7363564B2 (en) Method and apparatus for securing communications ports in an electronic device
CN101620656B (en) Safety JTAG module and method for protecting safety of information inside chip
EP1817595B1 (en) Integrated circuit and a method for secure testing
US7849315B2 (en) Method for managing operability of on-chip debug capability
EP2583112B1 (en) Method and apparatus for providing scan chain security
EP3287800A1 (en) Jtag debug apparatus and jtag debug method
KR100961807B1 (en) Method and device for preventing hardware hacking through internal register interface
KR101301022B1 (en) Apparatus for protecting against external attack for processor based on arm core and method using the same
EP4318284A1 (en) Secure boot device and method
US7809934B2 (en) Security measures for preventing attacks that use test mechanisms
CA2799932A1 (en) Computer motherboard having peripheral security functions
US20110185110A1 (en) Method and device for protecting information contained in an integrated circuit
KR20080050216A (en) Secure Boot Device and Method of Mobile Platform using TPM
US7822995B2 (en) Apparatus and method for protecting diagnostic ports of secure devices
TH85838A (en) Methods and devices for securing communication ports in electronic devices.
Goodspeed Practical Attacks against the MSP430 BSL
US12117487B2 (en) Protection of the content of a fuse memory
CN117744042A (en) Kernel code protection method, device, equipment and storage medium
CN100363857C (en) System bootrom security access method
US20250370911A1 (en) System-on-chip including a processor having debugging functionality and a tamper circuit, and corresponding tamper protection method
US9891654B2 (en) Secure clock switch circuit
CN111651381A (en) Semiconductor device and data protection method
CN119226152A (en) Security strategy construction method, device, equipment and vehicle for vehicle system
CN117216749A (en) Chip debugging authority control method and related equipment