One-Time Read Disable for FPGA Configuration Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field programmable gate arrays (FPGAs) face challenges in protecting configuration and internal data from unauthorized access while allowing access for error correction and debugging, as existing methods are either insecure or costly to implement.

Innovation Solution

Incorporating a disabling element that permanently sets access permissions for data reading, using encryption, and employing mechanisms like fuses or one-time programmable memory to prevent data access once set, ensuring secure and cost-effective protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration data is made accessible for error correction and debugging, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveaccess to dataVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a dynamic access control mechanism where a read protect bit can be set to either allow or prevent reading of configuration and internal data. This dynamic switching capability enables the system to adapt between debug mode (read access enabled) and secure operation mode (read access disabled), resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the state of a control parameter (read protect bit) to transition between secure and accessible modes. By modifying this binary parameter, the system can switch between allowing read access for debugging and preventing read access for security, thus resolving the contradiction through parameter state changes.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If security measures are strengthened to prevent data reading, then security is improved, but ease of operation is worsened

Engineering Contradiction:
Improvedata protectionVSAvoidaccess to data
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The read protect bit provides dynamic control over data accessibility, allowing the system to switch between secure (read disabled) and accessible (read enabled) states. This dynamic mechanism ensures that security can be strengthened when needed while maintaining operational ease when debugging or error correction is required.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If multiple access control mechanisms are implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improvedata protectionVSAvoidcircuit complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality into a separate, dedicated read protect bit that operates independently from the main configuration logic. This extraction simplifies the overall device architecture by isolating the security control mechanism, making it easier to implement and manage while maintaining strong security protections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The read protect bit serves multiple functions: it controls read access to configuration data, protects internal data from unauthorized reading, and enables secure operation modes. This multi-functionality reduces device complexity by consolidating security control into a single versatile mechanism rather than requiring separate control circuits for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7479798B1Selectively disabled output
Publication Date: 2009.01.20 ALTERA CORP
  • US7479798B1 patent drawing
  • US7479798B1 patent drawing
  • US7479798B1 patent drawing

AI summary

Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.