FPGA Readout Disable Circuit for Secure Configuration Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field programmable gate arrays (FPGAs) face challenges in securely protecting configuration and internal data from unauthorized access while allowing access for error correction and debugging, as existing methods are either insecure or costly to implement.

Innovation Solution

Incorporating a disabling element that permanently sets a state to prevent data reading, using encryption, and employing a break in a circuit line or a one-time programmable memory to inhibit read access, ensuring that once set, the disabling element cannot be changed to allow data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration data is stored in accessible memory for debugging and error correction, then ease of operation is improved, but security is worsened due to unauthorized access risk

Engineering Contradiction:
Improveaccess to data for debugging and error correctionVSAvoidunauthorized access to configuration data
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the memory system into multiple banks (first bank, second bank, third bank) with different access control characteristics. Some banks are configured to be readable while others are protected, allowing simultaneous debugging access and security protection by distributing data across segmented storage regions with differentiated permission levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the configuration data are assigned different security properties. The patent implements local quality by making certain memory banks readable for debugging purposes while other banks remain protected, allowing the system to have both secure and accessible regions within the same memory structure based on local security requirements.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If readout circuit is always enabled for debugging access, then ease of operation is improved, but security is worsened due to potential data theft

Engineering Contradiction:
Improvedebugging access to internal dataVSAvoidprotection of proprietary design
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access control where the readout circuit's accessibility is not fixed but can be selectively enabled or disabled. Control logic dynamically manages which memory banks are readable at any given time, allowing the system to switch between debugging mode (readable) and security mode (protected) based on operational requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces control logic as an intermediary between the readout circuit and memory banks. This intermediary layer manages access requests, determining whether to grant or deny read access based on security policies, thereby mediating between debugging needs and security protection without requiring direct user access to all data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate manufacturing processes are used for secure and non-secure devices, then security is improved, but device complexity and cost are worsened

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanufacturing process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal memory architecture that serves multiple functions within a single device. The same memory banks can operate in different security modes (readable or protected) depending on configuration, eliminating the need for separate manufacturing processes for secure and non-secure devices while maintaining both debugging capability and security protection in one unified structure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges security protection and debugging accessibility features into a single integrated memory system. By combining controlled-access memory banks with standard readable memory banks in one device, the patent eliminates the need for separate secure and non-secure manufacturing processes, reducing complexity while maintaining both security and debuggability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10720927B1Selectively disabled output
Publication Date: 2020.07.21 ALTERA CORP
  • US10720927B1 patent drawing
  • US10720927B1 patent drawing
  • US10720927B1 patent drawing

AI summary

Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.