IP Checker Circuit Locks Kernel Logic to Licensed Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data centers, existing technologies lack effective methods to securely lock the execution of intellectual property (IP) cores to licensed programmable devices, preventing unauthorized use and potential attacks such as device spoofing or unauthorized deployment.
Innovation Solution
A hardware accelerator with kernel logic and an IP checker circuit that obtains and verifies a device identifier against a signed whitelist, ensuring the IP core is only enabled on authorized devices by comparing the device ID against a list and verifying the signature, thereby preventing unauthorized execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IP cores are licensed on a project basis allowing use on any number of programmable devices, then system integrators have flexibility in deploying IP, but IP owners cannot prevent unauthorized use in data center environments
Solution Approach 1:
The patent applies preliminary action by pre-configuring kernel logic with authorization checking capabilities and pre-establishing licensing mechanisms within the programmable device. The kernel logic is configured during device initialization to verify IP usage rights before execution, preventing unauthorized deployment in advance rather than reacting to violations afterward.
Solution Approach 2:
The patent introduces kernel logic as an intermediary component between the IP core and the programmable fabric. This kernel logic acts as a mediator that checks authorization credentials and controls whether IP cores can be instantiated, thereby enabling fine-grained control over IP deployment without affecting the underlying hardware architecture.
2Reliability
If IP checker circuit is integrated into kernel logic, then unauthorized device execution is prevented, but device complexity increases
Solution Approach 1:
The patent merges the IP checker circuit functionality directly into the kernel logic unit, combining authorization verification capabilities with the existing kernel management functions. This integration eliminates the need for separate dedicated authorization hardware, reducing overall device complexity while maintaining security control.
Solution Approach 2:
The kernel logic is designed to serve multiple functions: managing kernel lifecycles, handling device resource allocation, and performing IP authorization verification. By making the kernel logic universal and multi-functional, the patent avoids adding dedicated specialized circuits for each function, thereby controlling device complexity while achieving comprehensive control.
3Productivity
If third party developers license IP to system integrators without device-specific restrictions, then IP can be widely deployed, but data centers cannot prevent massive unauthorized deployments
Solution Approach 1:
The patent applies preliminary anti-action by implementing authorization verification mechanisms that proactively prevent unauthorized IP deployments before they can occur. The kernel logic checks device credentials and IP licensing status in advance, blocking potentially harmful unauthorized deployments while allowing legitimate scaled deployments to proceed.
Solution Approach 2:
The patent implements feedback mechanisms where the kernel logic continuously monitors and verifies IP usage rights during device operation. The system provides feedback about authorization status to control IP instantiation, enabling dynamic adjustment of deployment permissions based on verified licensing conditions, thus preventing unauthorized scale-out deployments.
Data Source
AI summary
An example hardware accelerator for a computer system includes a programmable device and further includes kernel logic configured in a programmable fabric of the programmable device, and an intellectual property (IP) checker circuit in the kernel logic. The IP checker circuit is configured to obtain a device identifier (ID) of the programmable device and a signed whitelist, the signed whitelist including a list of device IDs and a signature, verify the signature of the signed whitelist, compare the device ID against the list of device IDs, and selectively assert or deassert an enable of the kernel logic in response to presence or absence, respectively, of the device ID in the list of device IDs and verification of the signature.


