FPGA Bitstream Verification via Cryptographic Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for monitoring the integrity of field programmable gate arrays (FPGAs) are vulnerable to attacks, such as man-in-the-middle and replay attacks, as they rely on transmitting configuration settings for comparison, which can be intercepted and manipulated.

Innovation Solution

Incorporating a verification circuit within the FPGA that uses a shared cryptographic key and feedback registers to verify the configuration integrity in real-time without reading the configuration from memory, ensuring that any alterations to the FPGA's state can be detected by synchronizing and comparing the states between the FPGA and a verification component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If configuration settings are transmitted from FPGA to monitoring system for comparison, then reconfiguration detection is enabled, but the system becomes vulnerable to man-in-the-middle and replay attacks

Engineering Contradiction:
Improvereconfiguration detection capabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A verification circuit is introduced as an intermediary component within the FPGA that generates verification signals based on the configuration settings. These verification signals are transmitted to the monitoring system instead of the raw configuration settings themselves. The verification circuit acts as a mediator that protects the configuration data while enabling detection functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the conventional mechanical transmission of configuration data with a cryptographic verification mechanism. The verification circuit uses cryptographic functions to generate verification signals that cannot be intercepted or replayed, substituting the vulnerable direct transmission mechanism with a secure cryptographic system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If configuration settings are read from FPGA memory for transmission and comparison, then reconfiguration detection is achieved, but system integrity is compromised due to potential data interception

Engineering Contradiction:
Improveconfiguration monitoring capabilityVSAvoidexposure of configuration data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential verification information from the full configuration settings through the verification circuit. Instead of transmitting the complete configuration data, only the verified configuration information is extracted and transmitted to the monitoring system. This extraction process maintains monitoring capability while minimizing data exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification circuit creates a verified copy of the configuration information that maintains the necessary monitoring functionality without exposing the original configuration data. The verification signals are essentially encrypted or transformed copies that can be transmitted safely without revealing the underlying configuration settings.

Inventive Principle:
Principle #26Copying

3Object-affected harmful factors

If real-time verification is performed without reading configuration from memory, then security is enhanced, but verification complexity increases

Engineering Contradiction:
Improvesecurity against attacksVSAvoidverification circuit complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The verification circuit performs preliminary actions by pre-computing and storing verification parameters within the FPGA before runtime monitoring is needed. The circuit is pre-configured with the necessary cryptographic functions and verification logic, so that during operation it can quickly generate verification signals without complex real-time computation or memory access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10262098B1Field programmable gate array bitstream verification
Publication Date: 2019.04.16 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US10262098B1 patent drawing
  • US10262098B1 patent drawing
  • US10262098B1 patent drawing

AI summary

Described herein are various technologies pertaining to confirming an integrity of a FPGA. A verifier circuit is placed into an FPGA bitstream to enable external verification of the FPGA configuration in real time without requiring readout of the FPGA configuration itself. Number generators are utilized to generate a key which is shared between the FPGA and an external verification component (VC). The key is utilized to configure an initial state of sequence registers respectively located on both the FPGA and the VC. When the FPGA is operating with an approved configuration, output from the sequence registers at the FPGA and the VC are the same.