FPGA Bitstream Descrambling Using Key-Controlled Multiplexers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern Field Programmable Gate Arrays (FPGAs) face challenges in protecting configuration bitstreams from detection due to the complexity and resource-intensive nature of encryption circuitry, which increases costs and power dissipation.
Innovation Solution
The use of multiplexers controlled by a security key, stored on the integrated circuit, to descramble received configuration bitstreams, allowing for efficient protection without the need for complex encryption circuits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption circuitry is used to protect configuration bitstreams, then security against detection is improved, but device complexity and area consumption increase
Solution Approach 1:
The patent extracts the security function from complex encryption circuitry and implements it using simple multiplexer-based selection logic. Instead of using dedicated encryption hardware, the invention uses multiplexers to select between different bitstream sources or versions based on security credentials, thereby achieving security protection while minimizing circuit complexity and area consumption.
2Reliability
If encryption circuitry is used to protect configuration bitstreams, then security against detection is improved, but power dissipation increases
Solution Approach 1:
The patent removes power-intensive encryption circuitry and replaces it with low-power multiplexer-based security mechanisms. The multiplexers consume significantly less power than full encryption/decryption hardware, yet still provide effective security by controlling access to different bitstream versions or sources through simple credential verification.
3Reliability
If complex encryption circuits are used, then configuration bitstream protection is improved, but manufacturing cost increases
Solution Approach 1:
The patent extracts the essential security function from complex encryption circuits and implements it using simple multiplexer logic that is cheaper to manufacture. The multiplexer-based approach requires fewer transistors and less sophisticated fabrication processes, thereby reducing manufacturing costs while maintaining protection against bitstream detection.
4Device complexity
If simpler protection methods are used, then device complexity and cost are reduced, but security against detection may be weakened
Solution Approach 1:
The patent implements dynamic security where multiplexers can switch between different bitstream sources or versions based on runtime credential verification. This dynamic approach allows simple hardware to achieve sophisticated security by adapting its behavior based on security credentials, maintaining strong protection without requiring complex static encryption circuits.
Data Source
AI summary
Circuits, methods, and apparatus that provide for protection of configuration bitstreams from theft. One exemplary embodiment receives a scrambled configuration bitstream with an integrated circuit. The scrambled configuration bitstream is descrambled using a plurality of multiplexers under control of a security key. A configuration bitstream is received in portions. One specific embodiment uses a key stored in memory to control a bank of multiplexers that descramble each of the received portions of the configuration bitstream. Other embodiments store longer keys, and use portions of the keys to descramble one or more portions of their respective configuration bitstreams. The outputs of the multiplexers are then stored in configuration memory cells.


