Multi-Chip PLD Security Architecture for Secure Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing programmable logic devices (PLDs) face challenges in protecting configuration data from subversion and ensuring secure operation, particularly in trusted computing applications, where the need for robust security measures to prevent data theft, modification, and device tampering is paramount.

Innovation Solution

The implementation of multi-chip module systems with a PLD die and a separate die containing a security block, which includes a root of trust and cryptographic capabilities, provides secure boot mechanisms, dynamic reconfiguration, and multiple-boot capabilities to protect against unauthorized access and ensure secure firmware operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If configuration data is stored in PLD configuration memory, then programmable logic functionality is achieved, but security against data theft and subversion is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the PLD into multiple separate dies: a first die containing configuration memory and a second die containing security functionality. This segmentation isolates security-critical operations from the main programmable logic, preventing unauthorized access to configuration data while maintaining programmable functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure boot manager acts as an intermediary between the configuration data and the programmable logic resources. The secure boot manager verifies authentication tags and controls the loading of configuration data, mediating security checks before allowing access to the configuration memory contents.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security blocks are added to PLDs, then protection against subversion is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against subversionVSAvoidmulti-chip architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security functionality is segmented into a separate second die rather than being integrated into the main PLD die. This includes authentication tags, secure boot manager, and cryptographic operations on a dedicated security die, reducing complexity within the main programmable device while maintaining comprehensive security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security-critical components are extracted from the main PLD architecture and placed on separate dies. The authentication tags are stored in secure memory on the second die, and the secure boot manager operates independently, removing security complexity from the main programmable logic device.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication tags are implemented, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidboot process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication tags are generated and attached to configuration data during the manufacturing process before the device is deployed. This preliminary action allows the authentication information to be pre-computed and stored securely, eliminating the need for time-consuming authentication calculations during the boot process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex cryptographic verification mechanisms with simpler authentication tag checking. Instead of performing full cryptographic authentication during boot, the secure boot manager verifies pre-computed authentication tags, significantly reducing verification time while maintaining data integrity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If configuration data is protected, then security is improved, but ease of reconfiguration is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidreconfiguration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic reconfiguration capability where the secure boot manager can load different authenticated configuration data sets during operation. Multiple configuration images with their own authentication tags can be stored and selectively loaded, allowing the device to change functionality while maintaining security through authenticated access.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The secure boot manager provides universal security services for multiple configuration data sets and different reconfiguration scenarios. The same authentication mechanism protects various types of configuration data, and the system supports both initial boot and subsequent reconfiguration operations through a unified security framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12417319B2Multi-chip secure and programmable systems and methods
Publication Date: 2025.09.16 LATTICE SEMICON CORP
  • US12417319B2 patent drawing
  • US12417319B2 patent drawing
  • US12417319B2 patent drawing

AI summary

Various techniques are provided to implement multi-chip secure and programmable systems and methods. In one example, a multi-chip module system for providing an integrated programmable logic functionality and security functionality. The multi-chip module system includes a first die including a programmable logic device (PLD) configured to provide at least a portion of the programmable logic functionality. The multi-chip system further includes a second die including a security engine configured to perform at least a portion of the security functionality. The security engine is further configured to receive, from the first die, data associated with a first and second configuration image; perform a read operation on a memory for the second configuration image based on the data; and authenticate the second configuration image. The multi-chip system further includes a configuration engine configured to program the PLD according to the first configuration image. Related devices and methods are provided.