FPGA Readout Disable Circuit for Secure Configuration Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field programmable gate arrays (FPGAs) face challenges in securely protecting configuration and internal data from unauthorized access while allowing access for error correction and debugging, as existing methods are either insecure or costly to implement.
Innovation Solution
Incorporating a disabling element that permanently sets a state to prevent data reading, using encryption, and employing a break in a circuit line or a one-time programmable memory to inhibit read access, ensuring that once set, the disabling element cannot be changed to allow data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration data is stored in accessible memory for debugging and error correction, then ease of operation is improved, but security is worsened due to unauthorized access risk
Solution Approach 1:
The patent segments the memory system into multiple banks (first bank, second bank, third bank) with different access control characteristics. Some banks are configured to be readable while others are protected, allowing simultaneous debugging access and security protection by distributing data across segmented storage regions with differentiated permission levels.
Solution Approach 2:
Different portions of the configuration data are assigned different security properties. The patent implements local quality by making certain memory banks readable for debugging purposes while other banks remain protected, allowing the system to have both secure and accessible regions within the same memory structure based on local security requirements.
2Ease of operation
If readout circuit is always enabled for debugging access, then ease of operation is improved, but security is worsened due to potential data theft
Solution Approach 1:
The patent implements dynamic access control where the readout circuit's accessibility is not fixed but can be selectively enabled or disabled. Control logic dynamically manages which memory banks are readable at any given time, allowing the system to switch between debugging mode (readable) and security mode (protected) based on operational requirements.
Solution Approach 2:
The patent introduces control logic as an intermediary between the readout circuit and memory banks. This intermediary layer manages access requests, determining whether to grant or deny read access based on security policies, thereby mediating between debugging needs and security protection without requiring direct user access to all data.
3Reliability
If separate manufacturing processes are used for secure and non-secure devices, then security is improved, but device complexity and cost are worsened
Solution Approach 1:
The patent implements a universal memory architecture that serves multiple functions within a single device. The same memory banks can operate in different security modes (readable or protected) depending on configuration, eliminating the need for separate manufacturing processes for secure and non-secure devices while maintaining both debugging capability and security protection in one unified structure.
Solution Approach 2:
The patent merges security protection and debugging accessibility features into a single integrated memory system. By combining controlled-access memory banks with standard readable memory banks in one device, the patent eliminates the need for separate secure and non-secure manufacturing processes, reducing complexity while maintaining both security and debuggability.
Data Source
AI summary
Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.


