Multi-Chip PLD Security Architecture for Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing programmable logic devices (PLDs) face challenges in protecting configuration data from subversion and ensuring secure operation, particularly in trusted computing applications, where the need for robust security measures to prevent data theft, modification, and device tampering is paramount.
Innovation Solution
The implementation of multi-chip module systems with a PLD die and a separate die containing a security block, which includes a root of trust and cryptographic capabilities, provides secure boot mechanisms, dynamic reconfiguration, and multiple-boot capabilities to protect against unauthorized access and ensure secure firmware operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If configuration data is stored in PLD configuration memory, then programmable logic functionality is achieved, but security against data theft and subversion is insufficient
Solution Approach 1:
The system divides the PLD into multiple separate dies: a first die containing configuration memory and a second die containing security functionality. This segmentation isolates security-critical operations from the main programmable logic, preventing unauthorized access to configuration data while maintaining programmable functionality.
Solution Approach 2:
A secure boot manager acts as an intermediary between the configuration data and the programmable logic resources. The secure boot manager verifies authentication tags and controls the loading of configuration data, mediating security checks before allowing access to the configuration memory contents.
2Reliability
If security blocks are added to PLDs, then protection against subversion is improved, but device complexity increases
Solution Approach 1:
Security functionality is segmented into a separate second die rather than being integrated into the main PLD die. This includes authentication tags, secure boot manager, and cryptographic operations on a dedicated security die, reducing complexity within the main programmable device while maintaining comprehensive security.
Solution Approach 2:
Security-critical components are extracted from the main PLD architecture and placed on separate dies. The authentication tags are stored in secure memory on the second die, and the secure boot manager operates independently, removing security complexity from the main programmable logic device.
3Reliability
If authentication tags are implemented, then data integrity is improved, but processing time increases
Solution Approach 1:
Authentication tags are generated and attached to configuration data during the manufacturing process before the device is deployed. This preliminary action allows the authentication information to be pre-computed and stored securely, eliminating the need for time-consuming authentication calculations during the boot process.
Solution Approach 2:
The patent replaces complex cryptographic verification mechanisms with simpler authentication tag checking. Instead of performing full cryptographic authentication during boot, the secure boot manager verifies pre-computed authentication tags, significantly reducing verification time while maintaining data integrity.
4Reliability
If configuration data is protected, then security is improved, but ease of reconfiguration is reduced
Solution Approach 1:
The system implements dynamic reconfiguration capability where the secure boot manager can load different authenticated configuration data sets during operation. Multiple configuration images with their own authentication tags can be stored and selectively loaded, allowing the device to change functionality while maintaining security through authenticated access.
Solution Approach 2:
The secure boot manager provides universal security services for multiple configuration data sets and different reconfiguration scenarios. The same authentication mechanism protects various types of configuration data, and the system supports both initial boot and subsequent reconfiguration operations through a unified security framework.
Data Source
AI summary
Various techniques are provided to implement multi-chip secure and programmable systems and methods. In one example, a multi-chip module system for providing an integrated programmable logic functionality and security functionality. The multi-chip module system includes a first die including a programmable logic device (PLD) configured to provide at least a portion of the programmable logic functionality. The multi-chip system further includes a second die including a security engine configured to perform at least a portion of the security functionality. The security engine is further configured to receive, from the first die, data associated with a first and second configuration image; perform a read operation on a memory for the second configuration image based on the data; and authenticate the second configuration image. The multi-chip system further includes a configuration engine configured to program the PLD according to the first configuration image. Related devices and methods are provided.


