FPGA Key Data Storage via Segmented Base Element Obfuscation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current programmable integrated circuits, such as FPGAs, lack a secure and cost-effective method for storing cryptographic key data permanently and securely, as existing solutions like external security chips, PUFs, battery-buffered memory, and flash-based components come with additional costs, complications, and susceptibility to errors or reverse engineering.
Innovation Solution
A method where cryptographic key data is divided into subblocks and stored in base elements of a programmable integrated circuit, with specific base element positions locked out in a lockout data element or constraint file, allowing key data to be assembled only at runtime, ensuring secure storage without permanent readable positions in the source code or configuration data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic key data is stored in external security chips, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines the security function with the existing FPGA fabric by utilizing base elements and configuration memory that are already present in the programmable logic device. This integration eliminates the need for separate external security chips while maintaining security through obfuscated storage of cryptographic key data across multiple distributed base elements.
Solution Approach 2:
The patent makes the base elements and configuration memory serve dual purposes: their primary function for implementing logic circuits and their secondary function for securely storing cryptographic key data. This multi-functionality allows the same hardware resources to provide both computational and security functions without adding dedicated security hardware.
2Duration of action of stationary object
If cryptographic key data is stored in battery-buffered memory, then permanent storage is achieved, but cost and power requirements increase
Solution Approach 1:
The patent uses the existing volatile configuration memory of the FPGA, which is already designed to store configuration data during operation. By obfuscating the storage location and content of cryptographic key data within this existing memory structure, the system achieves secure storage without requiring additional powered memory components or battery-buffered solutions.
3Duration of action of stationary object
If cryptographic key data is stored in flash-based components, then non-volatile storage is achieved, but susceptibility to reverse engineering increases
Solution Approach 1:
The patent divides the cryptographic key data into multiple segments stored across different base elements within the FPGA fabric. This segmentation disperses the key data throughout the programmable logic structure, making it extremely difficult to reconstruct the complete key through reverse engineering or physical inspection of any single location.
Solution Approach 2:
The patent introduces configuration data as an intermediary layer that obfuscates the actual location and content of cryptographic key data. The base elements store what appears to be normal configuration data, but within this obfuscated structure, the key data is hidden, requiring knowledge of the specific obfuscation scheme to access the actual cryptographic keys.
4Adaptability or versatility
If configuration data is made volatile in FPGAs, then reconfigurability is enabled, but permanent storage of key data becomes impossible
Solution Approach 1:
The patent performs preliminary obfuscation of the cryptographic key data during the configuration phase, embedding the key data within the configuration data structure before it is loaded into the volatile configuration memory. This preliminary action ensures that even though the storage is volatile, the key data remains protected and effectively permanent in terms of security, as it cannot be accessed or reconstructed without the obfuscation key.
Data Source
AI summary
A method for storing key data in an electronic component formed as an integrated programmable circuit, such as a field programmable gate array, which includes a base structure consisting of base elements, wherein configuration data is loaded, for each current program, onto the base elements and stored in a volatile matter, the key data is divided into key sub-data blocks, and a base element position is selected for each key sub-data block, where upon generating the configuration data for each current program or circuit function of the electronic component, selected base element positions of the key sub-data blocks are considered, while loading the configuration data, key sub-data blocks are stored in the base elements defined by selected base element positions, and after successfully programming the electronic component, the key sub-data blocks of base elements specified by selected base element positions are ascertained and assembled to form the key data.

