FPGA Cryptographic Processor Secure Dynamic Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems face challenges in providing secure communication and data integrity due to heat dissipation issues with physical security measures like meshes, which restrict the use of more powerful chip components and increase the risk of reliability problems, and lack redundancy in processor designs, making them vulnerable to attacks.

Innovation Solution

A single chip cryptographic processor architecture utilizing a field programmable gate array (FPGA) with secure programming and dual power supply, incorporating multiple cryptographic engines, and a secure memory partitioning system to ensure encrypted communication and tamper-resistance, meeting FIPS Level 4 security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical security measures like meshes are used to detect tampering, then security is improved, but heat dissipation is restricted and reliability problems increase

Engineering Contradiction:
ImprovesecurityVSAvoidheat dissipation
Core Design Contradiction:
ReliabilityVSTemperature

Solution Approach 1:

The patent replaces the mechanical/physical mesh structure with a field-programmable gate array (FPGA) that can detect tampering through logical and electrical means. The FPGA monitors security parameters and can respond to tampering attempts without requiring a physical mesh that would block heat dissipation, thus resolving the contradiction between security and heat management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Device complexity

If a single processor design is used to reduce complexity, then device complexity is reduced, but redundancy is lost making the system vulnerable to attacks

Engineering Contradiction:
Improveprocessor design complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic reconfiguration capability through the FPGA, allowing the processor architecture to change and adapt during operation. This enables the system to switch between different processor configurations and implement redundancy dynamically, maintaining security against attacks while avoiding the need for complex static multi-processor designs.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If FPGA programming is allowed from outside the chip, then flexibility and adaptability are improved, but security risks increase due to potential unauthorized modification

Engineering Contradiction:
ImproveFPGA programming flexibilityVSAvoidsecurity security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism where the FPGA verification process acts as a mediator between external programming attempts and the actual FPGA configuration. The system uses authenticated protocols to verify the identity and authority of programming sources, allowing flexible FPGA programming while preventing unauthorized modifications through cryptographic verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7818574B2System and method for providing dynamically authorized access to functionality present on an integrated circuit chip
Publication Date: 2010.10.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7818574B2 patent drawing
  • US7818574B2 patent drawing
  • US7818574B2 patent drawing

AI summary

A mechanism is provided in which access to the functionality present on an integrated circuit chip is controllable via an encrypted certificate of authority which includes time information indicating allowable periods of operation or allowable duration of operation. The chip includes at least one cryptographic engine and at least one processor. The chip also contains hard coded cryptographic keys including a chip private key, a chip public key and a third party's public key. The chip is also provided with a battery backed up volatile memory which contains information which is used to verify authority for operation. The certificate of authority is also used to control not only the temporal aspects of operation but is also usable to control access to certain functionality that may be present on the chip, such as access to some or all of the cryptographic features provided in conjunction with the presence of the cryptographic engine, such as key size.