Kill Switch for Programmable Logic Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Programmable logic devices using SRAM for configuration data face security threats as nonvolatile storage can be monitored by competitors, and existing security features can be circumvented, allowing unauthorized access to sensitive information.

Innovation Solution

Implementing a kill switch mechanism, such as a kill fuse or volatile battery-backed memory, that resets or disables parts of the device upon detecting a security threat, including executing a user-defined kill sequence to clear configuration data and decryption keys, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If nonvolatile storage is used to retain configuration data, then data retention during power loss is improved, but security against competitor monitoring is worsened

Engineering Contradiction:
Improvedata retention durationVSAvoidsecurity vulnerability
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security function from the storage mechanism by introducing a separate kill switch that can independently disable the device. The kill switch is implemented as a dedicated security component that can be triggered by security events, separating the data retention function (nonvolatile storage) from the security protection function (kill switch mechanism).

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The kill switch implements preliminary anti-action by being pre-configured to disable the device before any unauthorized access can occur. When a security threat is detected (such as unauthorized monitoring of configuration data), the kill switch is activated to immediately reset or disable the programmable logic device, preventing the competitor from accessing or analyzing the configuration data.

Inventive Principle:
Principle #9Preliminary anti-action

2Object-affected harmful factors

If encryption/decryption security features are implemented, then protection of sensitive data is improved, but vulnerability to circumvention is worsened

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsecurity feature reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The kill switch acts as an intermediary security mechanism between the encryption/decryption features and the potential attacker. Even if encryption is circumvented, the kill switch provides an additional layer of protection by being able to detect the circumvention attempt and immediately disable the device, preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The kill switch provides beforehand cushioning by being pre-programmed with security event detection capabilities. When unauthorized access attempts are detected (such as attempts to read configuration data or circumvent encryption), the kill switch is activated in advance to disable the device, cushioning against the effectiveness of any encryption circumvention techniques.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Ease of operation

If configuration data is made accessible for monitoring, then debugging and verification are improved, but unauthorized access and data theft are enabled

Engineering Contradiction:
Improvedebugging accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The kill switch introduces dynamic security control to the otherwise static accessibility of configuration data. The system can dynamically transition between two states: a normal state where configuration data is accessible for legitimate debugging and verification, and a secured state where the kill switch is activated to prevent any monitoring or access by unauthorized parties.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9111121B2Method and apparatus for securing a programmable device using a kill switch
Publication Date: 2015.08.18 ALTERA CORP
  • US9111121B2 patent drawing
  • US9111121B2 patent drawing
  • US9111121B2 patent drawing

AI summary

A kill switch is provided that, when triggered, may cause the programmable logic device (PLD) to become at least partially reset, disabled, or both. The kill switch may be implemented as a fuse or a volatile battery-backed memory bit. When, for example, a security threat is detected, the switch may be blown, and a reconfiguration of the device initiated in order to zero or clear some or all of the memory and programmable logic of the PLD.