IP Checker Circuit for Secure Hardware Accelerator Licensing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data centers, existing technologies lack effective methods to securely lock the execution of intellectual property (IP) cores to licensed programmable devices, preventing unauthorized use and potential attacks such as device spoofing or unauthorized deployment of acceleration circuits.

Innovation Solution

A hardware accelerator with an integrated IP checker circuit that verifies device identifiers against a signed whitelist, ensuring only authorized devices can execute the IP cores by comparing device IDs and validating signatures, thereby selectively enabling or disabling kernel logic operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If IP cores are licensed on a project basis allowing use on any number of programmable devices, then the system integrator gains flexibility and ease of operation, but the IP owner loses control over authorized device execution and security

Engineering Contradiction:
Improveflexibility of IP usageVSAvoidsecurity control of IP execution
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the licensing control by separating the whitelist of authorized device IDs from the IP core execution. The IP checker circuit independently verifies device IDs against the whitelist, creating a segmented security layer that allows flexible licensing while maintaining execution control. This segmentation enables the IP to be licensed on a project basis while still restricting execution to specific authorized devices through the separate verification mechanism.

Inventive Principle:
Principle #1Segmentation

2Reliability

If IP execution is locked to specific programmable devices using verification circuits, then security control and reliability are improved, but device complexity and manufacturing complexity increase

Engineering Contradiction:
Improvesecurity control of IP executionVSAvoidcomplexity of hardware accelerator
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The IP checker circuit is nested within the kernel logic of the hardware accelerator, creating a layered security structure. The verification functionality is embedded as an integral part of the kernel rather than being a separate external component. This nesting reduces overall system complexity by consolidating security functions within the existing kernel architecture while maintaining the required security control.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Adaptability or versatility

If traditional licensing allows IP to be used on any programmable device, then adaptability and versatility are improved, but unauthorized use and security vulnerabilities worsen

Engineering Contradiction:
Improveversatility of IP deploymentVSAvoidunauthorized use and device spoofing
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-populating a whitelist of authorized device IDs before IP execution begins. The IP checker circuit verifies the device ID against this pre-established whitelist, preventing unauthorized devices from executing the IP core. This preliminary authorization mechanism maintains adaptability for legitimate devices while blocking harmful unauthorized access and device spoofing attempts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11294992B2Locking execution of cores to licensed programmable devices in a data center
Publication Date: 2022.04.05 XILINX INC
  • US11294992B2 patent drawing
  • US11294992B2 patent drawing
  • US11294992B2 patent drawing

AI summary

An example hardware accelerator for a computer system includes a programmable device and further includes kernel logic configured in a first programmable fabric of the programmable device, a shell circuit configured in a second programmable fabric of the programmable device, the shell circuit configured to provide an interface between a computer system and the kernel logic, and an intellectual property (IP) checker circuit in the kernel logic The IP checker circuit is configured to obtain a device identifier (ID) from the first programmable fabric and a signed whitelist, the signed whitelist including a list of device IDs and a signature, verify the signature of the signed whitelist, compare the device ID against the list of device IDs, and selectively assert or deassert an enable of the kernel logic in response to presence or absence, respectively, of the device ID in the list of device IDs and verification of the signature.