Self-Modifying FPGA Memory Sanitization for Anti-Tamper Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic systems, particularly those using FPGAs, face challenges in securely sanitizing configuration data stored in non-volatile memory devices to prevent unauthorized access and tampering, as traditional sanitization methods leave evidence or do not ensure complete removal of sensitive information.
Innovation Solution
A self-modifying FPGA system that includes a configuration memory device with dormant data, a configuration assist circuit, and a tamper detection system, which automatically replaces configuration data with dormant data upon detection of unauthorized access, ensuring thorough sanitization without leaving evidence and allowing the FPGA to reconfigure and mislead tamper attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If traditional sanitization methods are used to remove configuration data, then data removal is achieved, but evidence of sanitization remains and completeness cannot be ensured
Solution Approach 1:
The patent applies preliminary action by pre-storing dormant configuration data in the configuration memory device before any tamper event occurs. This dormant data is prepared in advance and remains inactive until needed, allowing the system to quickly replace sensitive configuration data with pre-prepared dormant data upon detecting a tamper event, ensuring both completeness and evidence-free sanitization
Solution Approach 2:
The patent uses copying by creating a dormant copy of configuration data that is stored in the configuration memory device alongside the active configuration data. This dormant copy serves as a replacement that can be loaded into the FPGA upon tamper detection, effectively copying the sanitization action to the configuration memory device itself rather than relying on external processing
2Duration of action of stationary object
If configuration data is stored in non-volatile memory for persistent functionality, then system functionality is maintained, but the system becomes vulnerable to tampering and unauthorized access
Solution Approach 1:
The patent applies local quality by dividing the configuration memory device into different functional regions: one region stores active configuration data for normal operation, while another region stores dormant configuration data for tamper response. This spatial separation of functions within the same memory device allows simultaneous persistence of configuration data and protection against tampering through localized dormant data storage
Solution Approach 2:
The patent implements preliminary anti-action by pre-positioning dormant configuration data in the configuration memory device that will automatically replace active configuration data upon tamper detection. This pre-prepared anti-action counteracts the harmful effect of tampering before it can compromise the system, as the dormant data is already in place and ready to be loaded into the FPGA
3Reliability
If multiple dormant configuration sets are stored for continuous cycling, then tamper protection is enhanced, but memory device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the configuration memory device into distinct segments or regions, each capable of storing different configuration data sets (active and dormant). This segmentation allows the memory device to hold multiple configuration sets independently, enabling continuous cycling between them for enhanced tamper protection while maintaining a relatively simple overall memory structure through organized regional division
Data Source
AI summary
A self-modifying FPGA system includes an FPGA and a configuration memory device coupled to the FPGA for providing the FPGA with configuration information. The configuration memory device is programmed with configuration data and dormant data. The FPGA system is also provided with a configuration assist circuit coupled to the FPGA and the configuration memory device for controlling loading of configuration information from the configuration memory device to the FPGA. A tamper detection system provides a tamper signal to the FPGA, wherein when a tamper signal is received by the FPGA the configuration data is replaced with the dormant data.


