Multi-Tenant IC Peek and Poke Protection via Exclusion Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a multi-tenant usage model for programmable logic devices, the lack of trust among clients and the server leads to vulnerabilities in preventing peek and poke attacks, where unauthorized access or manipulation of configuration bits can occur.

Innovation Solution

The implementation of an exclusion configuration that extracts and sets configuration bits to prevent peek and poke attacks, achieved through static or dynamic partial reconfiguration and dynamic checks, ensuring that only authorized parties access and modify configuration bits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a multi-tenant usage model is implemented to support multiple clients on a single device, then device utilization and resource sharing are improved, but security vulnerabilities arise that allow unauthorized peek and poke attacks between tenants

Engineering Contradiction:
Improvemulti-tenant usage modelVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The configuration space is segmented into multiple tenant-specific regions, with each tenant assigned to specific configuration bits and resources. This segmentation isolates tenants from each other, preventing unauthorized access while allowing each tenant to independently configure their allocated resources without affecting other tenants.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A configuration management intermediary is introduced that mediates between tenants and the configuration bits. This intermediary validates and controls the configuration process, ensuring that tenants can only access their authorized configuration space while preventing peek and poke attacks through enforced access control policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If configuration bits are made accessible for dynamic reconfiguration to support client customization, then adaptability and functionality are improved, but vulnerability to malicious manipulation increases

Engineering Contradiction:
Improvedynamic reconfigurationVSAvoidpeek and poke attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Protective measures are taken in advance by establishing tenant-specific access control policies before reconfiguration occurs. The system pre-defines which configuration bits each tenant can access and implements validation mechanisms that prevent malicious manipulation before it can affect the system state.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements feedback mechanisms that monitor configuration access and reconfiguration operations. When a reconfiguration attempt is detected, the system validates it against tenant policies and provides feedback by either allowing the operation if authorized or blocking it if it violates security policies, thereby preventing unauthorized manipulation.

Inventive Principle:
Principle #23Feedback

3Reliability

If trust assumptions are removed among clients and server in a multi-tenant environment, then security posture is improved against insider threats, but system complexity and overhead increase

Engineering Contradiction:
Improvetrust model securityVSAvoidprotection circuitry complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Trust validation is performed in advance during the configuration phase rather than requiring continuous verification during operation. The system establishes and validates tenant boundaries and access policies beforehand, creating a secure foundation that reduces the need for complex runtime trust verification mechanisms.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12265772B2Integrated circuit with peek and poke protection circuitry for multi-tenant usage model
Publication Date: 2025.04.01 ALTERA CORP
  • US12265772B2 patent drawing
  • US12265772B2 patent drawing
  • US12265772B2 patent drawing

AI summary

Methods and apparatus for extracting a setting of configuration bits to create an exclusion configuration for providing protection against peek and poke attacks in a multi-tenant usage model of a configurable device is provided. The device may host multiple parties that do not trust each other. Peek and poke attacks are orchestrated by tapping (peeking) and driving (poking) wires associated with other parties. Such attacks may be disabled by excluding the settings of configuration bits that would allow these attacks by other parties. This set of configuration bits that should be excluded for preventing all peek and poke attacks creates the exclusion configuration. Methods are described that disable a particular class of peek and/or poke attacks through the use of partial reconfiguration. Methods and apparatus are described to dynamically detect peek and/or poke attacks.