FPGA Readout Disable Circuit for Permanent Data Access Lockout
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field programmable gate arrays (FPGAs) face challenges in securely protecting configuration and internal data from unauthorized access while allowing access for error correction and debugging, as existing methods are either insecure or costly to implement.
Innovation Solution
The integration of a disabling element that permanently sets access permissions for data reading, using mechanisms like fuses or one-time programmable memory to prevent data alteration and encryption, ensuring secure data protection without user-accessible changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration data is stored in accessible memory for debugging and error correction, then ease of operation is improved, but security is worsened due to unauthorized reading risk
Solution Approach 1:
The patent segments the memory into multiple banks (first bank, second bank, third bank) with different access permissions. Some banks are configured to be readable while others are protected, allowing simultaneous debugging access and security protection for different data portions.
Solution Approach 2:
Different security characteristics are applied to different regions of the memory system. The patent implements local quality by making specific memory banks readable for debugging purposes while keeping other banks protected, rather than applying a uniform security policy to the entire configuration data.
2Reliability
If configuration data is protected from reading to prevent unauthorized access, then security is improved, but ease of operation is worsened due to inability to debug and correct errors
Solution Approach 1:
The patent divides configuration data into multiple banks, allowing selective protection. Critical data can be placed in protected banks while non-critical data remains in accessible banks, enabling both security and debugging functionality simultaneously.
Solution Approach 2:
The patent applies different access permissions to different memory regions based on their security requirements. This allows the system to maintain high security for sensitive configuration data while permitting debugging access to other portions.
3Adaptability or versatility
If a disabling element is made user-configurable to allow flexible access control, then adaptability is improved, but security is worsened due to potential user alteration
Solution Approach 1:
The patent implements preliminary action by configuring the disabling element during manufacturing or initial setup to a default protected state. This preliminary configuration ensures security is enabled by default, and any changes require deliberate action, preventing accidental or unauthorized modifications.
Solution Approach 2:
The disabling element acts as an intermediary between the user and the configuration data. It provides a controlled interface that allows legitimate access while preventing unauthorized changes, mediating between adaptability requirements and security stability.
4Adaptability or versatility
If extensive configuration data is stored to support complex FPGA functionality, then adaptability is improved, but loss of information is worsened due to increased reading vulnerability
Solution Approach 1:
The patent segments extensive configuration data into multiple banks, allowing selective protection of critical portions. This enables the system to maintain full functionality while protecting sensitive data segments from unauthorized reading.
Solution Approach 2:
The patent applies different security characteristics to different portions of the configuration data based on their sensitivity. Critical configuration data receives enhanced protection while non-critical data remains accessible, reducing overall information exposure risk.
Data Source
AI summary
Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.


