HACSP FPGA Bitstream Integrity Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Root of Trust (RoT) technologies for FPGAs are inadequate in providing continuous real-time integrity measurements and secure bitstream authentication during operation, as they rely on static integrity measurements that can be misleading, especially against dynamically triggered malware.

Innovation Solution

The High Assurance Configuration Security Processor (HACSP) performs real-time integrity measurements and secure attestation of bitstream performance, implementing continuous monitoring and secure update mechanisms within a Trusted Execution Environment (TEE) to ensure reliable evidence of trustworthiness without stopping operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static integrity measurement approaches are used for FPGA bitstream verification, then device complexity is reduced and ease of operation is improved, but measurement precision deteriorates and reliability worsens due to inability to detect dynamic malware

Engineering Contradiction:
Improveintegrity measurement precisionVSAvoidsecurity processor complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security processor is segmented into distinct functional modules: a measurement module that collects integrity data, a hashing module that processes the data, and a reporting module that outputs results. This segmentation allows each module to specialize in specific tasks, improving measurement precision while managing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary hashing function as a mediator between the raw integrity measurements and the final verification results. The hashing module processes measurement data through cryptographic hash functions, providing a reliable intermediary layer that enhances measurement precision without requiring direct complex comparisons of raw device states.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If continuous real-time integrity monitoring is implemented, then reliability of trustworthiness verification is improved, but use of energy and device complexity increase

Engineering Contradiction:
Improvetrustworthiness verification reliabilityVSAvoidenergy consumption of security processor
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security processor implements periodic integrity monitoring rather than truly continuous monitoring. The measurement module collects integrity data at scheduled intervals, processes measurements periodically through the hashing module, and generates reports at defined frequencies. This periodic approach maintains reliable trustworthiness verification while significantly reducing energy consumption compared to continuous monitoring.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If comprehensive integrity measurements are performed during operation, then measurement precision and reliability are improved, but productivity decreases due to processing overhead

Engineering Contradiction:
Improvebitstream integrity measurement precisionVSAvoidFPGA operational productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The security processor implements partial monitoring by focusing measurements on critical bitstream regions and key operational parameters rather than comprehensively monitoring every device state. The measurement module selectively collects integrity data from essential components, and the hashing module processes only these partial measurements. This approach maintains sufficient measurement precision for security verification while minimizing processing overhead and preserving FPGA productivity.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If secure decryption and authentication of bitstream are performed within FPGA, then security against adversaries is improved, but device complexity and difficulty of manufacture increase

Engineering Contradiction:
Improvesecurity against adversariesVSAvoidFPGA configuration ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security processor performs preliminary authentication and verification actions before the FPGA is fully configured and operational. The measurement module collects integrity measurements during the configuration loading process, and the hashing module processes these measurements before the bitstream is fully instantiated. This preliminary security verification establishes trust early in the boot process, enhancing security against adversaries while simplifying manufacture by integrating security checks into the existing configuration flow rather than requiring separate complex security subsystems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10402566B2High assurance configuration security processor (HACSP) for computing devices
Publication Date: 2019.09.03 AEROSPACE CORP
  • US10402566B2 patent drawing
  • US10402566B2 patent drawing
  • US10402566B2 patent drawing

AI summary

A High Assurance Configuration Security Processor (HACSP) for a computing device may perform real-time integrity measurements of an actual bitstream run-time performance against what is expected. The HACSP may be self-contained and have a relatively small footprint. The HACSP may be vendor-agnostic, and may be a trusted system application for the computing device. The HACSP may ensure the security of user application bitstream load and update during device configuration, and may implement security mechanisms for independent secure trusted attestation and integrity measurement mechanisms to report and provide reliable evidence about the "trustworthiness" of the system during user bitstream execution.