FPGA Bitstream Descrambling Using Key-Controlled Multiplexers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern Field Programmable Gate Arrays (FPGAs) face challenges in protecting configuration bitstreams from detection due to the complexity and resource-intensive nature of encryption circuitry, which increases costs and power dissipation.

Innovation Solution

The use of multiplexers controlled by a security key, stored on the integrated circuit, to descramble received configuration bitstreams, allowing for efficient protection without the need for complex encryption circuits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption circuitry is used to protect configuration bitstreams, then security against detection is improved, but device complexity and area consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from complex encryption circuitry and implements it using simple multiplexer-based selection logic. Instead of using dedicated encryption hardware, the invention uses multiplexers to select between different bitstream sources or versions based on security credentials, thereby achieving security protection while minimizing circuit complexity and area consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If encryption circuitry is used to protect configuration bitstreams, then security against detection is improved, but power dissipation increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower dissipation
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent removes power-intensive encryption circuitry and replaces it with low-power multiplexer-based security mechanisms. The multiplexers consume significantly less power than full encryption/decryption hardware, yet still provide effective security by controlling access to different bitstream versions or sources through simple credential verification.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If complex encryption circuits are used, then configuration bitstream protection is improved, but manufacturing cost increases

Engineering Contradiction:
ImproveprotectionVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the essential security function from complex encryption circuits and implements it using simple multiplexer logic that is cheaper to manufacture. The multiplexer-based approach requires fewer transistors and less sophisticated fabrication processes, thereby reducing manufacturing costs while maintaining protection against bitstream detection.

Inventive Principle:
Principle #2Taking out (Extraction)

4Device complexity

If simpler protection methods are used, then device complexity and cost are reduced, but security against detection may be weakened

Engineering Contradiction:
Improvecircuit complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic security where multiplexers can switch between different bitstream sources or versions based on runtime credential verification. This dynamic approach allows simple hardware to achieve sophisticated security by adapting its behavior based on security credentials, maintaining strong protection without requiring complex static encryption circuits.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8650409B1FPGA configuration data scrambling using input multiplexers
Publication Date: 2014.02.11 ALTERA CORP
  • US8650409B1 patent drawing
  • US8650409B1 patent drawing
  • US8650409B1 patent drawing

AI summary

Circuits, methods, and apparatus that provide for protection of configuration bitstreams from theft. One exemplary embodiment receives a scrambled configuration bitstream with an integrated circuit. The scrambled configuration bitstream is descrambled using a plurality of multiplexers under control of a security key. A configuration bitstream is received in portions. One specific embodiment uses a key stored in memory to control a bank of multiplexers that descramble each of the received portions of the configuration bitstream. Other embodiments store longer keys, and use portions of the keys to descramble one or more portions of their respective configuration bitstreams. The outputs of the multiplexers are then stored in configuration memory cells.