IP Checker Circuit Locks Kernel Logic to Licensed Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data centers, existing technologies lack effective methods to securely lock the execution of intellectual property (IP) cores to licensed programmable devices, preventing unauthorized use and potential attacks such as device spoofing or unauthorized deployment.

Innovation Solution

A hardware accelerator with kernel logic and an IP checker circuit that obtains and verifies a device identifier against a signed whitelist, ensuring the IP core is only enabled on authorized devices by comparing the device ID against a list and verifying the signature, thereby preventing unauthorized execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IP cores are licensed on a project basis allowing use on any number of programmable devices, then system integrators have flexibility in deploying IP, but IP owners cannot prevent unauthorized use in data center environments

Engineering Contradiction:
ImproveIP deployment flexibilityVSAvoidIP authorization control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring kernel logic with authorization checking capabilities and pre-establishing licensing mechanisms within the programmable device. The kernel logic is configured during device initialization to verify IP usage rights before execution, preventing unauthorized deployment in advance rather than reacting to violations afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces kernel logic as an intermediary component between the IP core and the programmable fabric. This kernel logic acts as a mediator that checks authorization credentials and controls whether IP cores can be instantiated, thereby enabling fine-grained control over IP deployment without affecting the underlying hardware architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IP checker circuit is integrated into kernel logic, then unauthorized device execution is prevented, but device complexity increases

Engineering Contradiction:
ImproveIP authorization controlVSAvoidkernel logic complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the IP checker circuit functionality directly into the kernel logic unit, combining authorization verification capabilities with the existing kernel management functions. This integration eliminates the need for separate dedicated authorization hardware, reducing overall device complexity while maintaining security control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The kernel logic is designed to serve multiple functions: managing kernel lifecycles, handling device resource allocation, and performing IP authorization verification. By making the kernel logic universal and multi-functional, the patent avoids adding dedicated specialized circuits for each function, thereby controlling device complexity while achieving comprehensive control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If third party developers license IP to system integrators without device-specific restrictions, then IP can be widely deployed, but data centers cannot prevent massive unauthorized deployments

Engineering Contradiction:
ImproveIP deployment scaleVSAvoidunauthorized deployment attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authorization verification mechanisms that proactively prevent unauthorized IP deployments before they can occur. The kernel logic checks device credentials and IP licensing status in advance, blocking potentially harmful unauthorized deployments while allowing legitimate scaled deployments to proceed.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where the kernel logic continuously monitors and verifies IP usage rights during device operation. The system provides feedback about authorization status to control IP instantiation, enabling dynamic adjustment of deployment permissions based on verified licensing conditions, thus preventing unauthorized scale-out deployments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11443018B2Locking execution of cores to licensed programmable devices in a data center
Publication Date: 2022.09.13 XILINX INC
  • US11443018B2 patent drawing
  • US11443018B2 patent drawing
  • US11443018B2 patent drawing

AI summary

An example hardware accelerator for a computer system includes a programmable device and further includes kernel logic configured in a programmable fabric of the programmable device, and an intellectual property (IP) checker circuit in the kernel logic. The IP checker circuit is configured to obtain a device identifier (ID) of the programmable device and a signed whitelist, the signed whitelist including a list of device IDs and a signature, verify the signature of the signed whitelist, compare the device ID against the list of device IDs, and selectively assert or deassert an enable of the kernel logic in response to presence or absence, respectively, of the device ID in the list of device IDs and verification of the signature.