FPGA Key Data Storage via Segmented Base Element Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current programmable integrated circuits, such as FPGAs, lack a secure and cost-effective method for storing cryptographic key data permanently and securely, as existing solutions like external security chips, PUFs, battery-buffered memory, and flash-based components come with additional costs, complications, and susceptibility to errors or reverse engineering.

Innovation Solution

A method where cryptographic key data is divided into subblocks and stored in base elements of a programmable integrated circuit, with specific base element positions locked out in a lockout data element or constraint file, allowing key data to be assembled only at runtime, ensuring secure storage without permanent readable positions in the source code or configuration data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic key data is stored in external security chips, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the security function with the existing FPGA fabric by utilizing base elements and configuration memory that are already present in the programmable logic device. This integration eliminates the need for separate external security chips while maintaining security through obfuscated storage of cryptographic key data across multiple distributed base elements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes the base elements and configuration memory serve dual purposes: their primary function for implementing logic circuits and their secondary function for securely storing cryptographic key data. This multi-functionality allows the same hardware resources to provide both computational and security functions without adding dedicated security hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Duration of action of stationary object

If cryptographic key data is stored in battery-buffered memory, then permanent storage is achieved, but cost and power requirements increase

Engineering Contradiction:
Improvepermanent storageVSAvoidcost
Core Design Contradiction:
Duration of action of stationary objectVSEase of manufacture

Solution Approach 1:

The patent uses the existing volatile configuration memory of the FPGA, which is already designed to store configuration data during operation. By obfuscating the storage location and content of cryptographic key data within this existing memory structure, the system achieves secure storage without requiring additional powered memory components or battery-buffered solutions.

Inventive Principle:
Principle #25Self-service

3Duration of action of stationary object

If cryptographic key data is stored in flash-based components, then non-volatile storage is achieved, but susceptibility to reverse engineering increases

Engineering Contradiction:
Improvenon-volatile storageVSAvoidreverse engineering
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent divides the cryptographic key data into multiple segments stored across different base elements within the FPGA fabric. This segmentation disperses the key data throughout the programmable logic structure, making it extremely difficult to reconstruct the complete key through reverse engineering or physical inspection of any single location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces configuration data as an intermediary layer that obfuscates the actual location and content of cryptographic key data. The base elements store what appears to be normal configuration data, but within this obfuscated structure, the key data is hidden, requiring knowledge of the specific obfuscation scheme to access the actual cryptographic keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If configuration data is made volatile in FPGAs, then reconfigurability is enabled, but permanent storage of key data becomes impossible

Engineering Contradiction:
ImprovereconfigurabilityVSAvoidpermanent storage
Core Design Contradiction:
Adaptability or versatilityVSDuration of action of stationary object

Solution Approach 1:

The patent performs preliminary obfuscation of the cryptographic key data during the configuration phase, embedding the key data within the configuration data structure before it is loaded into the volatile configuration memory. This preliminary action ensures that even though the storage is volatile, the key data remains protected and effectively permanent in terms of security, as it cannot be accessed or reconstructed without the obfuscation key.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12058254B2Method for storing key data in an electronic component
Publication Date: 2024.08.06 SIEMENS AG
  • US12058254B2 patent drawing
  • US12058254B2 patent drawing

AI summary

A method for storing key data in an electronic component formed as an integrated programmable circuit, such as a field programmable gate array, which includes a base structure consisting of base elements, wherein configuration data is loaded, for each current program, onto the base elements and stored in a volatile matter, the key data is divided into key sub-data blocks, and a base element position is selected for each key sub-data block, where upon generating the configuration data for each current program or circuit function of the electronic component, selected base element positions of the key sub-data blocks are considered, while loading the configuration data, key sub-data blocks are stored in the base elements defined by selected base element positions, and after successfully programming the electronic component, the key sub-data blocks of base elements specified by selected base element positions are ascertained and assembled to form the key data.