FPGA Root-of-Trust Updates Using Dual-Mode MTJ Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-Programmable Gate Arrays (FPGAs) face vulnerabilities in their Root-of-Trust, making it difficult to prevent malicious bitstream loading and update the security schemes, as existing solutions are either vulnerable to external attacks or lack effective mechanisms for internal reconfiguration and non-volatile updates.

Innovation Solution

The implementation of Magnetic Tunnel Junction (MTJ) memory bitcells that can operate in both multi-time-programmable (MTP) and one-time-programmable (OTP) modes, allowing for dynamic conversion of reconfigurable logic space to OTP space for secure Root-of-Trust updates, ensuring immutability and resilience against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the Root-of-Trust is implemented using traditional OTP or SRAM-based FPGAs, then the security against bitstream tampering is provided, but the ability to update or patch the Root-of-Trust is lost, requiring physical replacement of the FPGA

Engineering Contradiction:
ImprovesecurityVSAvoidupdatable
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic Root-of-Trust architecture where the security scheme can transition between different states (initial ROT, patched ROT, fallback ROT) based on operational needs. The system dynamically selects which security scheme to execute based on configuration bits stored in non-volatile memory, allowing the Root-of-Trust to adapt and update without physical replacement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the state parameters of the Root-of-Trust by storing configuration data in non-volatile memory cells that can be reprogrammed. By modifying the contents of these memory cells (changing the parameter), the system can update the Root-of-Trust security scheme while maintaining the same physical hardware, thus achieving updatable security without physical replacement.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multi-time-programmable memory is used for Root-of-Trust, then the ability to update security schemes is enabled, but the immutability and resistance to internal attacks may be compromised

Engineering Contradiction:
ImproveupdatableVSAvoidimmutability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the memory system into two distinct parts: non-volatile memory cells for storing Root-of-Trust configuration data and volatile SRAM for operational logic. This segmentation allows the non-volatile portion to provide persistent, updateable security parameters while the volatile portion provides operational flexibility, achieving both updatability and operational reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces configuration bits stored in non-volatile memory as an intermediary between the immutable security requirements and the need for updates. These configuration bits act as a mediator that controls which security scheme is executed, allowing updates to be applied without directly modifying the core security logic, thus maintaining immutability while enabling updatability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the FPGA logic space is converted to OTP space for security updates, then the immutability is ensured, but the reconfigurable logic space is lost

Engineering Contradiction:
ImproveimmutabilityVSAvoidreconfigurable logic space
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by implementing immutability only where needed (in the non-volatile memory cells storing Root-of-Trust configuration data) while leaving the majority of the FPGA logic space reconfigurable. This localized application of OTP characteristics ensures security without sacrificing the overall reconfigurability of the device.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent makes the non-volatile memory cells serve multiple functions: they store configuration data for the Root-of-Trust, provide updateable security parameters, and maintain reconfigurability when not in security-critical modes. This multi-functionality allows the same hardware resources to support both immutable security requirements and reconfigurable logic operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides a secure and updatable Root-of-Trust mechanism, enhancing the resilience of FPGAs against both external and internal attacks by enabling non-volatile, immutable updates, reducing the need for physical replacements and maintaining reconfigurable logic space, while ensuring high-security standards.

Implementation Method 1

Magnetic Tunnel Junction (MTJ) memory bitcells that can operate in both multi-time-programmable (MTP) and one-time-programmable (OTP) modes

Methodology Applied
Scientific EffectMagnetic Tunnel Junction: Magnetoresistance

Data Source

PatentUS11264991B2Field-programmable gate array with updatable security schemes
Publication Date: 2022.03.01 THE TRUSTEES OF INDIANA UNIV
  • US11264991B2 patent drawing
  • US11264991B2 patent drawing
  • US11264991B2 patent drawing

AI summary

A field-programmable gate array (FPGA) architecture capable of performing immutable hardware Root-of-Trust updates and patches. In embodiments, the architecture utilizes the dielectric breakdown mechanism of magneto tunnel junctions (MTJ) to operate both as: 1) multi-time programmable (MTP) configuration memory for reconfigurable FPGA designs, and 2) one-time programmable (OTP) memory for FPGA Root-of-Trust sections.