FPGA Readout Disable Circuit for Permanent Data Access Lockout

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field programmable gate arrays (FPGAs) face challenges in securely protecting configuration and internal data from unauthorized access while allowing access for error correction and debugging, as existing methods are either insecure or costly to implement.

Innovation Solution

The integration of a disabling element that permanently sets access permissions for data reading, using mechanisms like fuses or one-time programmable memory to prevent data alteration and encryption, ensuring secure data protection without user-accessible changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration data is stored in accessible memory for debugging and error correction, then ease of operation is improved, but security is worsened due to unauthorized reading risk

Engineering Contradiction:
Improveaccess to data for debugging and error correctionVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the memory into multiple banks (first bank, second bank, third bank) with different access permissions. Some banks are configured to be readable while others are protected, allowing simultaneous debugging access and security protection for different data portions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security characteristics are applied to different regions of the memory system. The patent implements local quality by making specific memory banks readable for debugging purposes while keeping other banks protected, rather than applying a uniform security policy to the entire configuration data.

Inventive Principle:
Principle #3Local quality

2Reliability

If configuration data is protected from reading to prevent unauthorized access, then security is improved, but ease of operation is worsened due to inability to debug and correct errors

Engineering Contradiction:
Improvedata securityVSAvoidaccess to data for debugging and error correction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides configuration data into multiple banks, allowing selective protection. Critical data can be placed in protected banks while non-critical data remains in accessible banks, enabling both security and debugging functionality simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access permissions to different memory regions based on their security requirements. This allows the system to maintain high security for sensitive configuration data while permitting debugging access to other portions.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If a disabling element is made user-configurable to allow flexible access control, then adaptability is improved, but security is worsened due to potential user alteration

Engineering Contradiction:
Improveflexible access controlVSAvoidprotection setting stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by configuring the disabling element during manufacturing or initial setup to a default protected state. This preliminary configuration ensures security is enabled by default, and any changes require deliberate action, preventing accidental or unauthorized modifications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The disabling element acts as an intermediary between the user and the configuration data. It provides a controlled interface that allows legitimate access while preventing unauthorized changes, mediating between adaptability requirements and security stability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If extensive configuration data is stored to support complex FPGA functionality, then adaptability is improved, but loss of information is worsened due to increased reading vulnerability

Engineering Contradiction:
ImproveFPGA functionalityVSAvoidconfiguration data exposure
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent segments extensive configuration data into multiple banks, allowing selective protection of critical portions. This enables the system to maintain full functionality while protecting sensitive data segments from unauthorized reading.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security characteristics to different portions of the configuration data based on their sensitivity. Critical configuration data receives enhanced protection while non-critical data remains accessible, reducing overall information exposure risk.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8604823B1Selectively disabled output
Publication Date: 2013.12.10 ALTERA CORP
  • US8604823B1 patent drawing
  • US8604823B1 patent drawing
  • US8604823B1 patent drawing

AI summary

Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.