MPSoC FPGA Secure Boot With Fabric Change Watchdog Reset

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current MPSOC FPGAs face security challenges due to the vulnerability of hard core processors to malicious attacks, leading to reluctance in using them for high assurance applications, as they lack effective mechanisms to prevent unauthorized changes and maintain a secure state.

Innovation Solution

Implementing internal monitoring hardware, firmware, and software coupled with external watchdog logic to enforce a fail-secure scenario by forcing a hard reset of the hard core processor upon detecting unauthorized changes to the FPGA fabric, ensuring the system cannot recover without power cycling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hard core processors are used in MPSOC FPGA, then processing performance is improved, but security vulnerability increases

Engineering Contradiction:
Improveprocessing performanceVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system separates monitoring functions from the hard core processor by implementing independent monitoring logic (hardware, firmware, or software) that operates autonomously to detect fabric changes and trigger watchdog resets, isolating the security-critical monitoring function from the vulnerable processor

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces external watchdog logic as an intermediary component that sits between the FPGA fabric and the hard core processor. This watchdog acts as a security gatekeeper that can force the processor into a reset state when unauthorized changes are detected, preventing direct access to the processor's security-critical functions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If monitoring logic is implemented to detect fabric changes, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring logic is designed to be multi-functional, capable of operating as hardware, firmware, or software depending on the specific security requirements. This universal approach allows the same monitoring capability to be implemented at different abstraction levels without requiring completely separate systems for each level

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements continuous feedback loops where monitoring logic constantly watches for fabric changes and provides real-time feedback to the external watchdog. When unauthorized changes are detected, the feedback triggers an automatic reset response, creating a closed-loop security mechanism that operates autonomously

Inventive Principle:
Principle #23Feedback

3Reliability

If external watchdog logic is used to force hard reset, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The external watchdog logic is pre-configured with the authority to force hard resets of the hard core processor when security violations are detected. This preliminary authorization allows the watchdog to immediately counteract unauthorized fabric changes without requiring additional approval or intervention, preventing potential security breaches before they can cause harm

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20260044605A1Secure MPSoC FPGA With Embedded Hard Core Processor System and Method
Publication Date: 2026.02.12 ROCKWELL COLLINS INC
  • US20260044605A1 patent drawing
  • US20260044605A1 patent drawing
  • US20260044605A1 patent drawing

AI summary

A system and method for securing a system-on-chip (SoC) field programmable gate array (FPGA) is provided, wherein the SoC FPGA includes an FPGA fabric, a soft core processor hosted within the FPGA fabric, a hard core processor, and a secure boot environment for the SOC FPGA. Monitoring logic monitors for a change in the FPGA fabric. External watchdog logic is configured to receive a trigger signal from the monitoring logic, and force the hard core processor(s) of the SoC FPGA into a reset state with no ability to recover unless power is cycled when a change has been made to the FPGA fabric, so as to provide a “fail secure” scenario. The monitoring logic may be firmware hosted on the FPGA fabric, software hosted on the soft core, software hosted on the hard core, and/or external hard logic.