Self-Modifying FPGA Memory Sanitization for Anti-Tamper Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems, particularly those using FPGAs, face challenges in securely sanitizing configuration data stored in non-volatile memory devices to prevent unauthorized access and tampering, as traditional sanitization methods leave evidence or do not ensure complete removal of sensitive information.

Innovation Solution

A self-modifying FPGA system that includes a configuration memory device with dormant data, a configuration assist circuit, and a tamper detection system, which automatically replaces configuration data with dormant data upon detection of unauthorized access, ensuring thorough sanitization without leaving evidence and allowing the FPGA to reconfigure and mislead tamper attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If traditional sanitization methods are used to remove configuration data, then data removal is achieved, but evidence of sanitization remains and completeness cannot be ensured

Engineering Contradiction:
Improveconfiguration data removalVSAvoidsanitization completeness and evidence-free
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-storing dormant configuration data in the configuration memory device before any tamper event occurs. This dormant data is prepared in advance and remains inactive until needed, allowing the system to quickly replace sensitive configuration data with pre-prepared dormant data upon detecting a tamper event, ensuring both completeness and evidence-free sanitization

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating a dormant copy of configuration data that is stored in the configuration memory device alongside the active configuration data. This dormant copy serves as a replacement that can be loaded into the FPGA upon tamper detection, effectively copying the sanitization action to the configuration memory device itself rather than relying on external processing

Inventive Principle:
Principle #26Copying

2Duration of action of stationary object

If configuration data is stored in non-volatile memory for persistent functionality, then system functionality is maintained, but the system becomes vulnerable to tampering and unauthorized access

Engineering Contradiction:
Improveconfiguration data persistenceVSAvoidtamper vulnerability
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by dividing the configuration memory device into different functional regions: one region stores active configuration data for normal operation, while another region stores dormant configuration data for tamper response. This spatial separation of functions within the same memory device allows simultaneous persistence of configuration data and protection against tampering through localized dormant data storage

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary anti-action by pre-positioning dormant configuration data in the configuration memory device that will automatically replace active configuration data upon tamper detection. This pre-prepared anti-action counteracts the harmful effect of tampering before it can compromise the system, as the dormant data is already in place and ready to be loaded into the FPGA

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If multiple dormant configuration sets are stored for continuous cycling, then tamper protection is enhanced, but memory device complexity increases

Engineering Contradiction:
Improvetamper protection effectivenessVSAvoidconfiguration memory structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the configuration memory device into distinct segments or regions, each capable of storing different configuration data sets (active and dormant). This segmentation allows the memory device to hold multiple configuration sets independently, enabling continuous cycling between them for enhanced tamper protection while maintaining a relatively simple overall memory structure through organized regional division

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8159259B1Self-modifying FPGA for anti-tamper applications
Publication Date: 2012.04.17 MERCURY SISTEMS INC
  • US8159259B1 patent drawing
  • US8159259B1 patent drawing
  • US8159259B1 patent drawing

AI summary

A self-modifying FPGA system includes an FPGA and a configuration memory device coupled to the FPGA for providing the FPGA with configuration information. The configuration memory device is programmed with configuration data and dormant data. The FPGA system is also provided with a configuration assist circuit coupled to the FPGA and the configuration memory device for controlling loading of configuration information from the configuration memory device to the FPGA. A tamper detection system provides a tamper signal to the FPGA, wherein when a tamper signal is received by the FPGA the configuration data is replaced with the dormant data.