MPSoC FPGA Secure Boot With Fabric Change Watchdog Reset
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current MPSOC FPGAs face security challenges due to the vulnerability of hard core processors to malicious attacks, leading to reluctance in using them for high assurance applications, as they lack effective mechanisms to prevent unauthorized changes and maintain a secure state.
Innovation Solution
Implementing internal monitoring hardware, firmware, and software coupled with external watchdog logic to enforce a fail-secure scenario by forcing a hard reset of the hard core processor upon detecting unauthorized changes to the FPGA fabric, ensuring the system cannot recover without power cycling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If hard core processors are used in MPSOC FPGA, then processing performance is improved, but security vulnerability increases
Solution Approach 1:
The system separates monitoring functions from the hard core processor by implementing independent monitoring logic (hardware, firmware, or software) that operates autonomously to detect fabric changes and trigger watchdog resets, isolating the security-critical monitoring function from the vulnerable processor
Solution Approach 2:
The patent introduces external watchdog logic as an intermediary component that sits between the FPGA fabric and the hard core processor. This watchdog acts as a security gatekeeper that can force the processor into a reset state when unauthorized changes are detected, preventing direct access to the processor's security-critical functions
2Reliability
If monitoring logic is implemented to detect fabric changes, then security is improved, but device complexity increases
Solution Approach 1:
The monitoring logic is designed to be multi-functional, capable of operating as hardware, firmware, or software depending on the specific security requirements. This universal approach allows the same monitoring capability to be implemented at different abstraction levels without requiring completely separate systems for each level
Solution Approach 2:
The system implements continuous feedback loops where monitoring logic constantly watches for fabric changes and provides real-time feedback to the external watchdog. When unauthorized changes are detected, the feedback triggers an automatic reset response, creating a closed-loop security mechanism that operates autonomously
3Reliability
If external watchdog logic is used to force hard reset, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The external watchdog logic is pre-configured with the authority to force hard resets of the hard core processor when security violations are detected. This preliminary authorization allows the watchdog to immediately counteract unauthorized fabric changes without requiring additional approval or intervention, preventing potential security breaches before they can cause harm
Data Source
AI summary
A system and method for securing a system-on-chip (SoC) field programmable gate array (FPGA) is provided, wherein the SoC FPGA includes an FPGA fabric, a soft core processor hosted within the FPGA fabric, a hard core processor, and a secure boot environment for the SOC FPGA. Monitoring logic monitors for a change in the FPGA fabric. External watchdog logic is configured to receive a trigger signal from the monitoring logic, and force the hard core processor(s) of the SoC FPGA into a reset state with no ability to recover unless power is cycled when a change has been made to the FPGA fabric, so as to provide a “fail secure” scenario. The monitoring logic may be firmware hosted on the FPGA fabric, software hosted on the soft core, software hosted on the hard core, and/or external hard logic.


