Double Encrypted Vendor Key for Logic Core Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IEEE 1735 V2 standard for protecting logic cores from unauthorized access has vulnerabilities that can lead to theft or corruption of designs, such as through Trojan horse injection, which are not adequately addressed by existing methods.

Innovation Solution

A method involving double encryption of the vendor private key, using user and vendor public-private key pairs, and pass phrases to create a protected package that includes a session key, allowing secure decryption and implementation of electronic designs, while also enabling tracing of unauthorized package distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the IEEE 1735 V2 standard encryption method is used to protect logic cores, then the security protection is provided, but vulnerabilities exist that can lead to theft or corruption of designs through Trojan horse injection

Engineering Contradiction:
Improvesecurity protectionVSAvoidTrojan horse injection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption process into multiple independent stages: first encrypting the design data with a symmetric key, then encrypting that symmetric key with the vendor's public key, and finally encrypting the vendor's private key with the user's public key. This multi-layer segmentation ensures that compromise of one layer does not expose the underlying data, directly addressing the vulnerability to Trojan horse injection by preventing single-point failures in the encryption scheme.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-encrypting the vendor's private key with the user's public key before delivering it to the user. This creates a secure envelope that can only be opened by the intended user, preventing unauthorized access or injection of malicious code during key exchange. The double encryption structure is established in advance, eliminating security gaps that could be exploited by Trojan horses.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If double encryption of vendor private key is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidencryption process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces symmetric keys as intermediaries between the asymmetric key pairs. The symmetric key serves as a mediator that simplifies the encryption of large design data, while the asymmetric keys (vendor and user key pairs) act as intermediaries for secure key exchange. This intermediary approach maintains high security through multiple encryption layers while managing complexity by using well-established cryptographic primitives in a structured sequence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies the nested doll principle by creating nested encryption layers: the design data is encrypted with a symmetric key, which is then encrypted with the vendor's public key, and the vendor's private key is encrypted with the user's public key. Each encryption layer is nested within the previous one, forming a secure envelope structure. This nesting organizes the complexity hierarchically, making the multi-step process more manageable while enhancing security at each layer.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If multiple key pairs and pass phrases are used for encryption, then unauthorized access is reduced, but ease of operation decreases

Engineering Contradiction:
Improveunauthorized access protectionVSAvoiddecryption process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the user to autonomously decrypt the vendor's private key using their own private key and the embedded vendor pass phrase. The system is designed so that the user's private key automatically decrypts the vendor's encrypted private key, and the embedded pass phrase automatically decrypts the session key. This self-service mechanism reduces operational complexity by eliminating manual intervention while maintaining strong security through multiple authentication factors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback by embedding the vendor pass phrase within the encrypted package, which provides automatic verification and decryption capability. When the user attempts decryption, the system uses the embedded pass phrase to verify authenticity and automatically decrypt the session key and design data. This feedback mechanism streamlines the decryption process by providing automatic error detection and correction, reducing the operational burden on users while maintaining security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11232219B1Protection of electronic designs
Publication Date: 2022.01.25 XILINX INC
  • US11232219B1 patent drawing
  • US11232219B1 patent drawing
  • US11232219B1 patent drawing

AI summary

Removing protections on a session-key protected design include receiving a double encrypted vendor private key and an encrypted session key. The double encrypted vendor private key is decrypted into a single encrypted vendor-private key using a user private key, and the single encrypted vendor-private key is decrypted into a vendor private key using a vendor pass phrase. The encrypted session key is decrypted into a session key using the vendor private key, and the session-key protected design is decrypted into a plain design using the session key.