Circuit Design Protection via Multi-Layer IP Core Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing CAD tools for integrated circuits lack effective protection mechanisms for circuit designs and session keys, making them vulnerable to unauthorized access and exploitation.

Innovation Solution

The method involves generating a key block by encrypting a session key used by a computer-based design tool, dividing it into sub-blocks, and encrypting each sub-block with a different key corresponding to IP cores within the circuit design, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single encryption key is used to protect the circuit design, then the encryption process is simple and fast, but the security level is insufficient and vulnerable to unauthorized access

Engineering Contradiction:
Improvesecurity levelVSAvoidencryption structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The single encryption key is divided into multiple key components, each associated with different IP cores. The key block is segmented into sub-blocks that are encrypted separately with different keys, creating a multi-layered security structure where compromise of one key does not endanger the entire design

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption structure implements nested layers where the key block containing the session key is divided into sub-blocks, each encrypted with different IP core keys. This creates a nested encryption hierarchy where multiple encryption layers protect the same underlying data, requiring penetration of all layers to access the circuit design

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If the key block is divided into multiple sub-blocks and encrypted with different keys, then the security is enhanced, but the complexity of key management and decryption increases

Engineering Contradiction:
Improveprotection levelVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The CAD tool is designed with multi-functional capabilities to handle the complex key management automatically. It can generate key blocks, divide them into sub-blocks, encrypt with multiple keys, and later decrypt by reversing the process. This universal tool approach hides the operational complexity from users while maintaining high security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The key block structure serves as an intermediary mechanism that manages multiple encryption keys systematically. Instead of directly managing numerous individual keys, the system uses the key block as a mediator that organizes and controls access to multiple IP cores, simplifying the overall key management process

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple encryption keys corresponding to IP cores are used, then unauthorized access is prevented, but the decryption process becomes more time-consuming

Engineering Contradiction:
Improveaccess controlVSAvoiddecryption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key block and its sub-blocks are pre-encrypted with multiple keys during the design phase. This preliminary encryption action ensures that when the circuit design needs to be accessed or protected, the multi-layer security is already in place, and the decryption process can proceed systematically without ad-hoc key management delays

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250156585A1Protection of a circuit design within a design container
Publication Date: 2025.05.15 XILINX INC
  • US20250156585A1 patent drawing
  • US20250156585A1 patent drawing
  • US20250156585A1 patent drawing

AI summary

A key block can be generated from a session key used by a computer-based design tool for a circuit design by encrypting the session key using computer hardware. The key block can be divided, by the computer hardware, into a plurality of sub-blocks. A plurality of enhanced sub-blocks can be generated by the computer hardware by encrypting each sub-block of the plurality of sub-blocks with a different key of a plurality of keys corresponding to a plurality of Intellectual Property (IP) cores of the circuit design. The plurality of enhanced sub-blocks can be stored in a memory.