PLD Authentication via Identifier Transformation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized copying of configuration bitstreams for programmable logic devices (PLDs) and application code for embedded processors is a significant concern, as existing technologies lack effective means for authentication.

Innovation Solution

A system and method for authentication involving a memory coupled to a programmable logic device, which includes an array of memory cells with separate storage spaces for a first identifier and its transformation, used to configure and authenticate the device, employing authentication logic information and protection registers to ensure proper rights management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If configuration bitstream authentication is implemented, then intellectual property protection is improved, but device complexity increases

Engineering Contradiction:
ImproveIP protectionVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a first identifier stored in the PLD and a second identifier (transformation of the first) stored in memory, creating a copy-based authentication system where the configuration bitstream is authenticated against these identifier pairs without requiring complex cryptographic hardware

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary authentication process that mediates between the configuration bitstream and the PLD programming, using identifier transformations as a middle layer to verify authorization without exposing the full authentication mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication logic is embedded in configuration information, then security is improved, but configuration data size increases

Engineering Contradiction:
Improveauthentication securityVSAvoidconfiguration data
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The authentication logic is prepared in advance and embedded within the configuration information, allowing the PLD to perform authentication during the configuration loading process without requiring additional runtime overhead or separate authentication data structures

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7535249B1Authentication for information provided to an integrated circuit
Publication Date: 2009.05.19 XILINX INC
  • US7535249B1 patent drawing
  • US7535249B1 patent drawing
  • US7535249B1 patent drawing

AI summary

A system for authentication of information provided to an integrated circuit, a method for rights management of an integrated circuit, and a method for configuring a programmable logic device are described. A memory is coupled to a programmable logic device. The memory includes an array of memory cells and storage devices. The storage devices provide a first storage space and a second storage space. The first storage space is for storing a first identifier. The second storage space is for storing a second identifier, which is a transformation of the first identifier. The array of memory cells is for storing configuration information to configure programmable logic of the programmable logic device. The configuration information includes authentication logic information.