A high-security circuit for FPGA

By designing a high-security circuit in the FPGA, and using the instruction signal after authentication failure to control the read permissions of the readback bus and WBSTAR registers, the problem that existing FPGA technology cannot effectively protect against malicious code stream injection is solved, and the high security of user design information is achieved.

CN116203886BActive Publication Date: 2025-05-16BEIJING MXTRONICS CORP +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310250901.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-15
Publication Date
2025-05-16
Estimated Expiration
2043-03-15

AI Technical Summary

Technical Problem

The existing FPGA technology cannot effectively protect the security of malicious code stream injection and user design information after authentication failure.

Method used

A high-security FPGA circuit is designed to perform logical operations through the indication signal after authentication failure, control the read permissions of the readback bus and WBSTAR registers, and prevent the injection and theft of malicious code streams.

Benefits of technology

It effectively protects the malicious code stream injection and user design information during use, ensuring the security of code streams and user control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116203886B_ABST
    Figure CN116203886B_ABST
Patent Text Reader

Abstract

The present invention provides a high-security circuit design applied to FPGA, including three modules: an authentication circuit, a readback decoding circuit, and a register control circuit. The authentication circuit will authenticate the encrypted code stream of the FPGA. If the authentication fails, the value read out of the WBSTAR register will be controlled to be a preset value through logical operations; or after the authentication fails, the address decoding process for the readback of the WBSTAR register will be destroyed to make the readback address wrong. The present invention performs a high-security design based on the FPGA configuration and the readback process, controls the readback address decoding process or the read permission of the WBSTAR register with the authentication result, protects the encrypted code stream and data of the FPGA, and effectively prevents malicious code stream injection and backdoor problems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of integrated circuits, and in particular to a high-security circuit applied to FPGA. Background Art

[0002] Field Programmable Gate Array (FPGA) is a chip that contains a large amount of programmable logic resources. It implements different logic functions by configuring the code stream converted from the user's design. FPGA can be repeatedly burned and programmed, and has great flexibility in application. It is particularly suitable for the special requirements of aerospace engineering for a variety of electronic devices and small batches.

[0003] When users are designing and developing, they can use encryption, authentication and other methods to protect the bitstream files in order to protect their design information and IP core usage. Encryption is to use a specific algorithm to process the bitstream files and convert them into ciphertext. Authentication is to authenticate the identity of the bitstream files to prevent tampering and deletion.

[0004] Encryption and authentication are two mechanisms for protecting FPGA code streams. Once the FPGA is injected with malicious code streams or breached by a backdoor vulnerability, the user will lose control of the FPGA chip, and the internal code stream of the FPGA chip will be stolen for reverse engineering; or the FPGA may be injected with a Trojan virus, causing system functions to become paralyzed.

[0005] Therefore, a high-security circuit design method is needed for FPGA configuration and authentication processes to protect FPGA from malicious code injection, backdoor and other problems encountered during use. Summary of the invention

[0006] The technical problem solved by the present invention is: to overcome the shortcomings of the prior art and provide a high-security circuit design for FPGA, to perform logical operations and control the readback bus according to the indication signal generated after the FPGA authentication fails, to shut down the WBSTAR register read permission, and to prevent the correct decoding of the readback instruction, thereby effectively preventing the injection of malicious code streams and ensuring the security of user design.

[0007] In a first aspect, an FPGA is provided, comprising:

[0008] Destination register;

[0009] An authentication circuit, used for performing authentication operations on code stream data;

[0010] A read-back decoding circuit is used to output an address according to the authentication result of the authentication operation; wherein,

[0011] When the authentication result is successful, the read-back decoding circuit is used to output the address indicated by the code stream data;

[0012] When the authentication result is authentication failure, the read-back decoding circuit is used to output data that is unrelated to the address of the target register.

[0013] In combination with the first aspect, in some implementations of the first aspect, the readback decoding circuit is used to output an address according to the code stream data and the authentication result of the authentication operation; wherein,

[0014] When the authentication result is successful, or when the authentication result is failed and the address indicated by the code stream data is not the address of the target register, the read-back decoding circuit is used to output the address indicated by the code stream data;

[0015] When the authentication result is authentication failure and the address indicated by the code stream data is the address of the target register, the read-back decoding circuit is used to output data that is unrelated to the address of the target register.

[0016] In combination with the first aspect, in certain implementations of the first aspect, the readback decoding circuit includes an address decoding module and a target register decoding control module, the address decoding module is used to output the address indicated by the code stream data, and the target register decoding control module is used to control the output of the address according to the authentication result.

[0017] In combination with the first aspect, in certain implementations of the first aspect, the target register decoding control module includes a first-stage two-to-one multiplexer and a second-stage two-to-one multiplexer;

[0018] In the case where the address indicated by the code stream data is not the address of the target register, the first-stage two-to-one multiplexer is used to transfer the address indicated by the code stream data to the second-stage two-to-one multiplexer;

[0019] In the case where the address indicated by the code stream data is the address of the target register, the first-stage two-to-one multiplexer is used to transfer data irrelevant to the address of the target register to the second-stage two-to-one multiplexer;

[0020] When the authentication result is successful, the second-stage two-to-one multiplexer is used to output the address indicated by the code stream data;

[0021] When the authentication result is authentication failure, the second-stage two-to-one multiplexer is used to output the data output by the first-stage two-to-one multiplexer.

[0022] In combination with the first aspect, in certain implementations of the first aspect, the target register decoding control module includes a first-stage two-to-one multiplexer and a second-stage two-to-one multiplexer;

[0023] When the authentication result is successful, the first-level two-to-one multiplexer is used to transfer the address indicated by the code stream data to the second-level two-to-one multiplexer;

[0024] When the authentication result is authentication failure, the first-stage two-to-one multiplexer is used to transfer data irrelevant to the address of the target register to the second-stage two-to-one multiplexer;

[0025] In the case where the address indicated by the code stream data is not the address of the target register, the second-stage two-to-one multiplexer is used to output the address indicated by the code stream data;

[0026] In the case where the address indicated by the code stream data is the address of the target register, the second-stage two-to-one multiplexer is used to output the data output by the first-stage two-to-one multiplexer.

[0027] In combination with the first aspect, in certain implementations of the first aspect, the target register address includes M 1 bits and N 0 bits, the target register decoding control module also includes an input AND gate and N NOT gates, the N NOT gates correspond one-to-one to the N 0 bits, the N NOT gates are used to perform a negation operation on the corresponding address bit according to the address output by the address decoding module, the N address bits output by the N NOT gates after the negation operation are input to the input AND gate together with the M 1 bits, and the result output by the input AND gate is used to indicate whether the address corresponding to the code stream data is the target register address.

[0028] In combination with the first aspect, in certain implementations of the first aspect, the target register is a WBSTAR register.

[0029] In a second aspect, an FPGA is provided, including:

[0030] An authentication circuit, used for performing authentication operations on code stream data;

[0031] A register control circuit, used to control the read permission of the target register according to the authentication result of the authentication operation,

[0032] When the authentication result is successful, the read permission of the target register is on;

[0033] When the authentication result is authentication failure, the read permission of the target register is off.

[0034] In conjunction with the second aspect, in some implementations of the second aspect, the register control circuit includes the target register and a control module;

[0035] The target register is used to input the output value to the control module;

[0036] The control module is used to output the output value when the authentication result is a successful authentication; and output the set value when the authentication result is a failed authentication.

[0037] In combination with the second aspect, in some implementations of the second aspect, the target register includes K storage units, the control module includes K two-to-one multiplexers, and the K storage units correspond to the K two-to-one multiplexers in a one-to-one manner;

[0038] When the authentication result is successful, the authentication circuit is used to output 0 to the two-to-one multiplexer;

[0039] When the authentication result is an authentication failure, the authentication circuit is used to output 1 to the two-to-one multiplexer;

[0040] The 0-bit selection input terminal of the two-to-one multiplexer is connected to the corresponding storage unit, the 1-bit selection input terminal of the two-to-one multiplexer is grounded, and the output terminal of the two-to-one multiplexer is the output terminal of the register control circuit.

[0041] In combination with the first aspect and the second aspect, in certain implementations of the first aspect and the second aspect, the target register is a WBSTAR register.

[0042] In a third aspect, an electronic device is provided, wherein the electronic device comprises the FPGA as described in any one of the implementations of the first to second aspects above.

[0043] The beneficial effects of the present invention compared with the prior art are:

[0044] When the high-security FPGA circuit design of the present invention is used to configure the encrypted code stream, the read permission of the WBSTAR register will be closed after the authentication fails, preventing the injection of external malicious code streams and the theft of the code stream information stored in the WBSTAR register, thereby effectively protecting the user's design information.

[0045] Through the control of the readback decoding circuit, when the authentication fails, an error address is fed back to the readback bus, realizing the closure of the WBSTAR register reading function after the authentication fails, thereby protecting the user's code stream security and effectively preventing the injection of malicious code streams and theft of code streams in the FPGA. In addition, the readback decoding circuit can also output the addresses of other registers normally when the authentication fails.

[0046] Through the control of the register control circuit, the WBSTAR register reading function is turned off after authentication fails, thereby protecting the user's code stream security and effectively preventing the injection of malicious FPGA code streams and the theft of code streams. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is a schematic diagram of the traditional FPGA circuit structure.

[0048] Figure 2 This is a schematic diagram of the traditional FPGA authentication workflow.

[0049] Figure 3 A schematic diagram of a high-security FPGA circuit structure provided in an embodiment of the present application.

[0050] Figure 4 A schematic diagram of an authentication workflow for a high-security FPGA circuit provided in an embodiment of the present application.

[0051] Figure 5 It is a schematic structural diagram of a readback decoding circuit provided in an embodiment of the present application.

[0052] Figure 6 It is a schematic structural diagram of a WBSTAR register decoding control module provided in an embodiment of the present application.

[0053] Figure 7 A schematic diagram of the structure of a high-security FPGA circuit provided in an embodiment of the present application.

[0054] Figure 8 A schematic diagram of an authentication workflow for a high-security FPGA circuit provided in an embodiment of the present application.

[0055] Fig. 9 It is a schematic structural diagram of a register control circuit provided in an embodiment of the present application.

[0056] Fig.10 It is a schematic structural diagram of a register control circuit provided in an embodiment of the present application. DETAILED DESCRIPTION

[0057] The present application is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0058] like Figure 1 As shown, the traditional FPGA partial configuration readback circuit structure includes: authentication circuit, startup circuit, readback bus, etc.

[0059] like Figure 2 As shown in the figure, the working process steps of the traditional FPGA configuration encryption code flow are as follows:

[0060] FPGA reads the encrypted code stream from the external interface according to the timing, and the encrypted code stream data is authenticated after being written into the authentication circuit. After the authentication is completed, the authentication result is compared with the correct result. If the authentication is successful, the FPGA is started through the indication signal, and the FPGA enters the working state. If the authentication fails, the configuration interface of the FPGA is locked to prevent the external code stream from continuing to be written, but the read permission of the WBSTAR register is not closed. Specifically, after receiving the indication signal of authentication failure, the FALLBACK circuit will trigger the FALLBACK mechanism of the FPGA, and the chip will generate an FPGA reset signal, reset the FPGA startup process, reconfigure the FPGA, and retain the data in the WBSTAR register without resetting it. At this time, by forging and loading a section of attack code stream, the FPGA can decrypt the code stream and store it in the WBSTAR register. Reading the value of the WBSTAR register through instructions can steal part of the code stream data. Repeating the above process repeatedly can achieve the theft of all code stream data.

[0061] In order to prevent the code stream data from being stolen, the embodiment of the present application provides a FPGA high-security circuit structure. The structure may include an authentication circuit, a startup circuit, a readback bus, a configuration state machine, and a readback decoding circuit. Figure 3 Compared with the traditional FPGA, the embodiment of the present application improves the readback decoding circuit. Figure 4 As shown, the working process of the FPGA using the circuit designed by the present invention is as follows.

[0062] FPGA reads the encrypted code stream from the external interface according to the timing, and performs authentication after the encrypted code stream data is written into the authentication circuit. The input of the authentication circuit is the encrypted configuration code stream stored in the external storage medium read by the FPGA, and the output is the authentication indication signal, which is connected to the startup circuit, configuration state machine and readback decoding circuit. The authentication circuit is a circuit module that FPGA uses to authenticate the encrypted code stream during the configuration process. It uses the SHA-256 algorithm for data processing. After the authentication operation, it determines whether the authentication is correct by comparing the actual calculation result with the standard result, and outputs an indication signal to indicate the success or failure of the authentication.

[0063] If the authentication is successful, the indication signal instructs the startup circuit to execute the FPGA startup, and the FPGA enters the working state. The readback bus is the channel for the FPGA to read back data. After adding the instruction to read the corresponding register in the code stream, the readback decoding circuit decodes according to the instruction, and then the readback bus reads the value of the corresponding register, loads the value stored in the specific register to the readback bus, and outputs it to the specific interface of the FPGA to complete the readback operation.

[0064] If the authentication fails, the failure indication signal is input to the configuration state machine and the readback decoding circuit. The configuration state machine executes the FPGA configuration interface lock according to the authentication failure signal. The readback decoding circuit performs a logical operation based on the authentication result and feeds back an error address to the readback bus, so that the readback bus cannot obtain the correct address of the WBSTAR register, and thus the readback bus cannot read the stored code stream data from the WBSTAR register. Through the control of the readback decoding circuit, the WBSTAR register reading function is turned off after the authentication fails, thereby protecting the user's code stream security and effectively preventing the injection of malicious code streams and the theft of code streams in the FPGA.

[0065] Figure 5 1 is a schematic structural diagram of a readback decoding circuit provided in an embodiment of the present application. The readback decoding circuit may include an address decoding module and a WBSTAR register decoding control module. The address decoding module is used to output a corresponding register address according to the input code stream data. The WBSTAR register decoding control module is used to control the readback decoding process of the FPGA chip. Specifically, the WBSTAR register decoding control module is used to determine whether to directly output the address output by the address decoding module according to the authentication result and the address type.

[0066] The input signals of the readback decoding circuit include the authentication result indication signal and the readback code stream instruction, and the output signal is the readback address output signal. The authentication result indication is generated by the authentication module, indicating the success or failure of the authentication process, which controls the address output selection end. The input readback code stream instruction is the code stream input by the user or attacker, which controls the FPGA readback process. The address decoding module will decode according to the input instruction information to generate a 5-bit address signal, indicating the register address to be read back, and input it into the WBSTAR register decoding control module for the next step of operation.

[0067] If the authentication is successful, the WBSTAR register decoding control module can directly output the address output by the address decoding module so that the readback bus can read the data of the corresponding register according to the address. In the case of authentication failure, other registers except the WBSTAR register can be read. Therefore, if the authentication fails, the WBSTAR register decoding control module can determine whether the address output by the address decoding module is the address of the WBSTAR register. If yes, the WBSTAR register decoding control module can output the wrong address so that the readback bus cannot read the data of the WBSTAR register according to the address. If not, the WBSTAR register decoding control module can directly output the address output by the address decoding module so that the readback bus can read the data of the corresponding register according to the address. In other embodiments, the authentication result and the judgment order of whether the address is the address of the WBSTAR register can be exchanged.

[0068] Figure 6 A schematic structural diagram of a WBSTAR register decoding control module provided in an embodiment of the present application is shown.

[0069] The WBSTAR register decoding control module may include a five-input AND gate and two two-to-one multiplexers. The input signal of the WBSTAR register decoding control module includes the 5-bit address output by the address decoding module and the authentication result indication signal, and the output signal is the read-back address output.

[0070] Assuming that the address of the WBSTAR register is 5'b10000, the signal of the lower four bits of the address is inverted according to the logical relationship, and then input into the five-input AND gate with the highest bit address [4] to perform digital logic operation. The operation result is used as the selection end of the first-level two-to-one multiplexer to select the address. If the result is 0, the address obtained by normal decoding is passed to the next stage. If the result is 1, an address 5'b01111 that does not correspond to any register is passed to the next stage. The input end of the second-level two-to-one multiplexer is the authentication result indication signal. If the authentication is successful, the address obtained by normal decoding is passed to the next stage; if the authentication fails, the output of the previous stage is passed to the next stage as the address output of the WBSTAR register decoding control module.

[0071] Working process: If the authentication is successful and the verification code stream file is correct, the second-level two-to-one multiplexer of the decoding control circuit will directly output the address output by the address decoding circuit according to the correct authentication result, thereby ensuring that the chip's own readback process is not affected when the verification is passed. If the authentication fails, it indicates that the code stream file is incorrect and there may be a risk of data leakage. The second-level two-to-one multiplexer passes the output of the first-level two-to-one multiplexer to the next stage according to the authentication error indication; the five-input NAND gate performs a logical operation on the decoded read-back address. If the address is 5'b10000, it indicates that the user or attacker expects to read back the WBSTAR register, then the WBSTAR address confirmation signal is 1, and the first-level two-to-one multiplexer passes the address 5'b01111 without any register corresponding to it to the next stage and outputs it; if the address is not 5'b10000, it indicates that the user or attacker expects to read back a register other than the WBSTAR register, then the read-back process should not be affected, and the first-level two-to-one multiplexer still passes the decoded address [4:0] to the next stage and outputs it, which does not affect the read-back operation.

[0072] Figure 6The two two-to-one multiplexers shown can be swapped in order. That is, the input end of the first-stage two-to-one multiplexer is the authentication result indication signal. If the authentication is successful, the address obtained by normal decoding is passed to the next stage; if the authentication fails, an address 5'b01111 that does not correspond to any register is passed to the next stage. The input end of the second-stage two-to-one multiplexer is the operation result of the five-input AND gate. If the result is 0, the address obtained by normal decoding is passed to the next stage and output. If the result is 1, the output of the previous stage is passed to the next stage as the address output of the WBSTAR register decoding control module.

[0073] exist Figure 6 In the illustrated embodiment, it is assumed that the address of the WBSTAR register itself is 5'b10000. In order to make the WBSTAR address confirmation result output as 1, the WBSTAR register decoding control module may include four NOT gates. When the address output by the address decoding module is 5'b10000, the four NOT gates may perform an inversion operation on the last 4 bits of 0, so that the WBSTAR address confirmation result is 1. In other words, the number of NOT gates and the corresponding positions of the WBSTAR register decoding control module may be set according to the address of the WBSTAR register itself. If the address of the WBSTAR register itself is 5'b11111, the WBSTAR register decoding control module may not set a NOT gate. The address bit on which the NOT gate performs the inversion operation may correspond to the 0 bit of the WBSTAR address. Thus, the WBSTAR address confirmation result may indicate whether the address output by the address decoding module is the address of the WBSTAR register itself.

[0074] The present application also provides a high-security FPGA circuit structure. The structure may include an authentication circuit, a startup circuit, a readback bus, a configuration state machine, and a register control circuit. Figure 7 Compared with the traditional FPGA, the embodiment of the present application has made improvements in the register control circuit. Figure 8 As shown, the working process of the FPGA using the circuit designed by the present invention is as follows.

[0075] FPGA reads the encrypted code stream from the external interface according to the timing, and the encrypted code stream data is authenticated after being written into the authentication circuit. After the authentication is completed, the authentication result is compared with the correct result. If the authentication is successful, the indication signal instructs the startup circuit to execute the FPGA startup, and the FPGA enters the working state. If the authentication fails, the failure indication signal is input into the configuration state machine and the register control circuit. The configuration state machine executes the FPGA configuration interface lock according to the authentication failure signal. After receiving the authentication failure signal, the register control circuit generates a signal to control the read permission of the WBSTAR register through logical operation, closes the read permission of the readback bus to the WBSTAR register, and makes it impossible for external instructions to read the code stream data in the WBSTAR register. Through the control of the register control circuit, the WBSTAR register read function is turned off after the authentication fails, thereby protecting the user's code stream security and effectively preventing the injection of malicious code streams and theft of code streams in the FPGA.

[0076] Fig. 9 It is a schematic structural diagram of a register control circuit provided in an embodiment of the present application.

[0077] The register control circuit mainly controls the read permission of the WBSTAR register. The register control circuit may include a WBSTAR register and a WBSTAR control module. The input signal of the register control circuit includes a WBSTAR register write data signal, a clock signal CLK and an authentication failure indication signal, and the output signal is the output value of the WBSTAR register. The WBSTAR register can be shifted into the WBSTAR register according to the WBSTAR write data signal under the action of the clock signal CLK to complete the update and storage of the data in the register. The value read from the WBSTAR register is stored on the read data signal line and enters the controller together with the authentication failure indication signal for logical operation. If the authentication is successful, the value stored in the WBSTAR register. If the authentication fails, no output or input error value.

[0078] Fig.10 It is a schematic structural diagram of a register control circuit provided in an embodiment of the present application.

[0079] The WBSTAR register may include 32 storage cells and 32 two-to-one multiplexers corresponding to each other. The input of each storage cell is a 1-bit write data signal and a clock signal CLK. The write data signal line can be used as an input data port when WBSTAR writes a new data value. The data stored in each storage cell can be read by a two-to-one multiplexer. The selection end of the two-to-one multiplexer is an authentication indication signal. If the authentication indication signal is 0, it can be used to indicate that the authentication is successful, and if the authentication indication signal is 1, it can be used to indicate that the authentication fails. The 0-bit selection end of the two-to-one multiplexer can be connected to the corresponding WBSTAR register as an input end, and the 1-bit selection end of the two-to-one multiplexer can be grounded as an input end to provide a 0 potential. The output of the two-to-one multiplexer is the WBSTAR register output under the register control circuit. In other embodiments, for various reasons, the number of settings of the two-to-one multiplexer can be slightly less than the number of storage cells, but the number should not be so small that it cannot hinder data theft.

[0080] Working process:

[0081] If the authentication is successful and the verification code stream file is correct, the authentication failure signal is 0, and the 32 two-to-one multiplexers uniformly select the original output end of the WBSTAR register and output it to ensure that the circuit reads back the register correctly without affecting the circuit operation. If the authentication fails, it means that the code stream file is incorrect and there may be a risk of data leakage. At this time, the authentication failure signal is 1, and the 32 two-to-one multiplexers uniformly select the grounded signal to output. When the attacker expects to read the WBSTAR register, it returns 32 bits of 0, causing the value in the WBSTAR register to fail to be read back, thereby protecting the code stream from being stolen.

[0082] Although the present invention is disclosed as above in the form of a preferred embodiment, it is not intended to limit the present invention. Any person skilled in the art may make possible changes and modifications without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention shall be based on the scope defined by the claims of the present invention.

Claims

1. An FPGA, characterized in that: include: Destination register; An authentication circuit, used for performing authentication operations on code stream data; A read-back decoding circuit is used to output an address according to the authentication result of the authentication operation; wherein, The read-back decoding circuit includes an address decoding module and a target register decoding control module, wherein the address decoding module is used to output the address indicated by the code stream data, and the target register decoding control module is used to control the output of the address according to the authentication result; The target register decoding control module includes a first-stage two-to-one multiplexer and a second-stage two-to-one multiplexer; when the address indicated by the code stream data is not the address of the target register, the first-stage two-to-one multiplexer is used to transfer the address indicated by the code stream data to the second-stage two-to-one multiplexer; In the case where the address indicated by the code stream data is the address of the target register, the first-stage two-to-one multiplexer is used to transfer data irrelevant to the address of the target register to the second-stage two-to-one multiplexer; When the authentication result is successful, the second-stage two-to-one multiplexer is used to output the address indicated by the code stream data; When the authentication result is authentication failure, the second-stage two-to-one multiplexer is used to output the data output by the first-stage two-to-one multiplexer.

2. The FPGA according to claim 1, characterized in that: The target register address includes M 1 bits and N 0 bits. The target register decoding control module also includes an input AND gate and N NOT gates. The N NOT gates correspond to the N 0 bits one by one. The N NOT gates are used to perform a negation operation on the corresponding address bit according to the address output by the address decoding module. The N address bits output by the N NOT gates and subjected to the negation operation are input to the input AND gate together with the M 1 bits. The result output by the input AND gate is used to indicate whether the address corresponding to the code stream data is the target register address.

3. The FPGA according to claim 1, characterized in that: The target register is the WBSTAR register.

4. An FPGA, characterized in that: include: Destination register; An authentication circuit, used for performing authentication operations on code stream data; A read-back decoding circuit is used to output an address according to the authentication result of the authentication operation; wherein, The read-back decoding circuit includes an address decoding module and a target register decoding control module, wherein the address decoding module is used to output the address indicated by the code stream data, and the target register decoding control module is used to control the output of the address according to the authentication result; The target register decoding control module includes a first-level two-to-one multiplexer and a second-level two-to-one multiplexer; when the authentication result is successful, the first-level two-to-one multiplexer is used to transfer the address indicated by the code stream data to the second-level two-to-one multiplexer; When the authentication result is authentication failure, the first-stage two-to-one multiplexer is used to transfer data irrelevant to the address of the target register to the second-stage two-to-one multiplexer; In the case where the address indicated by the code stream data is not the address of the target register, the second-stage two-to-one multiplexer is used to output the address indicated by the code stream data; In the case where the address indicated by the code stream data is the address of the target register, the second-stage two-to-one multiplexer is used to output the data output by the first-stage two-to-one multiplexer.

5. The FPGA according to claim 4, characterized in that: The target register address includes M 1 bits and N 0 bits. The target register decoding control module also includes an input AND gate and N NOT gates. The N NOT gates correspond to the N 0 bits one by one. The N NOT gates are used to perform a negation operation on the corresponding address bit according to the address output by the address decoding module. The N address bits output by the N NOT gates and subjected to the negation operation are input to the input AND gate together with the M 1 bits. The result output by the input AND gate is used to indicate whether the address corresponding to the code stream data is the target register address.

6. The FPGA according to claim 4, characterized in that: The target register is the WBSTAR register.

7. An electronic device, characterized in that: The electronic device comprises the FPGA according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Cloud-based FPGA (Field Programmable Gate Array) management control system and method and electronic equipment

    CN114691157A

  • Preventing system for breakage of memory cell in shared memory pool

    JP1991132845A