eFPGA-Enabled Dynamic Access Control for Secure IEEE 1687 (IJTAG) Networks
Modern System on Chip (SoC) designs integrate numerous embedded instruments for testing, debugging, postsilicon validation, and in-field monitoring. The IEEE 1687 (IJTAG) standard provides scalable access through a reconfigurable scan network of Segment Insertion Bits (SIBs), but this flexibility exposes internal resources to unauthorized access through the test infrastructure. Existing protection approaches rely on fixed hardware mechanisms, limiting adaptability across device lifecycle phases. This work proposes a secure IJTAG architecture integrating an eFPGA between the TAP and the IJTAG network as a reconfigurable security layer that controls instrument cluster connectivity through authenticated configuration, enabling lifecycle-aware isolation while preserving IJTAG flexibility. The architecture is evaluated on IJTAG benchmark networks to assess scalability.