Fuse Programming Security Against Side-Channel Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-programmable gate arrays (FPGAs) are vulnerable to side-channel attacks that can reveal configuration bitstream data values and encryption keys during programming, especially due to power consumption patterns, which can compromise security and require expensive secure configuration environments.

Innovation Solution

Implementing methods such as shuffling the fuse programming order, introducing variable wait times between programming each fuse, and avoiding programming of fuses that already hold values to obscure power consumption patterns, thereby reducing the effectiveness of side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If configuration bitstream data is secured using encryption keys stored in internal nonvolatile memory, then security of the configuration bitstream is improved, but the device becomes vulnerable to side-channel attacks that can reveal encryption keys through power consumption monitoring

Engineering Contradiction:
Improvesecurity of configuration bitstreamVSAvoidvulnerability to side-channel attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing fuse shuffling and variable wait time insertion before the actual encryption key programming occurs. These preparatory steps modify the programming sequence and timing characteristics in advance, so that when power consumption monitoring is performed during attack, the observed patterns no longer directly correspond to the encryption key bits being programmed, thereby preventing side-channel attacks before they can succeed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies dynamics by introducing variable wait times between programming operations on different fuses. Instead of using fixed, predictable timing, the wait times are dynamically adjusted based on random or pseudo-random values. This dynamic timing variation causes power consumption patterns to become unpredictable and uncorrelated with the encryption key data, rendering side-channel attacks ineffective

Inventive Principle:
Principle #15Dynamics

2Reliability

If secure configuration environments are used to prevent side-channel attacks during programming, then security is improved, but cost and flexibility for in-field configuration are reduced

Engineering Contradiction:
Improvesecurity during programmingVSAvoidcost and flexibility of configuration
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent applies self-service by implementing security measures directly within the programmable device's internal programming architecture. The fuse shuffling and variable wait time mechanisms are built into the device's programming logic, allowing it to protect its own configuration process against side-channel attacks without requiring external secure environment infrastructure. This enables standard, cost-effective configuration environments to be used while maintaining high security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the security function from the external configuration environment and relocates it into the device's internal programming process. By taking out the security requirements from the environment and embedding them in the device's own fuse programming sequence through shuffling and timing variation, the system eliminates the need for expensive secure configuration facilities while maintaining equivalent or superior security

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11281383B2Side-channel attack resistant fuse programming
Publication Date: 2022.03.22 ALTERA CORP
  • US11281383B2 patent drawing
  • US11281383B2 patent drawing
  • US11281383B2 patent drawing

AI summary

The disclosed systems and methods may secure the fuse programming process in programmable devices to reduce or eliminate malicious discovery of data (e.g., the encryption key, the configuration bitstream) stored in nonvolatile memory via side-channel attacks. A processor may generate a randomized fuse list and the fuses may be blown in the randomized order. Additionally or alternatively, the processor may randomize the wait time between programming of each fuse. Further, the processor may generate a simplified fuse list including only fuses to be blown. The disclosed security systems and methods may be used individually or in combination to prevent determination of sensitive data, such as the encryption key, by monitoring, for example, power consumption in side-channel attacks.