Interface Port for Electrically Programmable Fuses in PLDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting configuration data in programmable logic devices (PLDs) from unauthorized duplication and reverse-engineering are costly and logistically challenging, as they require encryption/decryption functionality and secure devices, which incur additional hardware and management costs, and may still be vulnerable to key reverse-engineering.

Innovation Solution

Incorporating electrically programmable fuses with identifiers that are programmed into the PLD during manufacturing, which are used to generate an authentication key by serially shifting bits through a shift register, allowing for secure authentication without external keys or batteries, and optionally augmenting the identifier with extra data to deter counterfeiting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption/decryption functionality is used to protect configuration data, then security against unauthorized duplication is improved, but hardware cost and logistical complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from complex encryption/decryption hardware and relocates it to simple electrically programmable fuses containing unique identifiers. The authentication logic is separated into two parts: the identifier stored in the PLD fuses and the authentication key stored externally, eliminating the need for complex on-chip encryption hardware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces expensive, complex encryption hardware with inexpensive electrically programmable fuses that store unique identifiers. These fuses are programmed once during manufacturing and then serve as the security foundation, providing a cost-effective alternative to ongoing encryption key management infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If encryption keys are stored in volatile memory with external batteries, then authentication capability is provided, but additional external components and management overhead are required

Engineering Contradiction:
Improveauthentication capabilityVSAvoidexternal components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication credential from volatile memory and external battery systems and relocates it to electrically programmable fuses. The unique identifier is stored permanently in the fuse structure itself, eliminating the need for external power sources and volatile memory management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The electrically programmable fuses provide self-contained authentication capability without requiring external batteries or volatile memory management. The identifier is permanently stored in the fuse structure and can be read out through the existing configuration interface, making the system self-sufficient.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If configuration data is transmitted through external buses, then programming capability is enabled, but vulnerability to interception increases

Engineering Contradiction:
Improveprogramming capabilityVSAvoidinterception vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary authentication by comparing the unique identifier from the fuses with an authentication key before allowing configuration data to be loaded. This pre-authentication step prevents unauthorized configuration data from being transmitted or executed, even if intercepted.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication key as an intermediary between the unique identifier and the configuration data loading process. This intermediary layer verifies authenticity before allowing configuration data to be transmitted through the external bus, adding a security checkpoint without blocking legitimate programming operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7550324B1Interface port for electrically programmed fuses in a programmable logic device
Publication Date: 2009.06.23 XILINX INC
  • US7550324B1 patent drawing
  • US7550324B1 patent drawing
  • US7550324B1 patent drawing

AI summary

A programmable logic device (PLD) includes electrically programmable fuses that may be programmed with an identifier of the PLD. The PLD also includes programmable tiles and an interface port that is coupled to a shift register and a subset of the programmable tiles. The interface port includes a control port and a first and second serial data signals. The shift register has a parallel input port to load the identifier from the set of electrically programmable fuses in response to a read command of the control port. The shift register serially shifts by one bit in response to a shift command of the control port, including shifting a bit from the subset of the programmable tiles to the shift register via the first serial data signal and shifting a bit from the shift register to the subset of the programmable tiles via the second serial data signal.