PLD Key Provisioning for Secure Configuration Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure systems and methods to protect and manage programmable logic devices (PLDs) from unauthorized configuration changes and subversion, particularly in trusted computing applications, where existing solutions fail to adequately ensure the integrity and security of configuration data.
Innovation Solution
The implementation of a locked secure programmable logic device (PLD) with key provisioning systems that encrypt and sign configuration data, utilizing a security engine and configuration engine to verify and authenticate configurations, ensuring only authorized changes can be made to the PLD's configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration data is stored in plaintext for easy programming, then ease of operation is improved, but security and reliability deteriorate due to unauthorized access and configuration changes
Solution Approach 1:
The patent creates a secure copy of the configuration data by encrypting it with a customer-specific key before storage. The encrypted configuration data can be freely distributed and programmed into the PLD, while the original plaintext remains secure. This allows ease of operation with encrypted data while maintaining security through the cryptographic copy mechanism.
Solution Approach 2:
The patent introduces a cryptographic key as an intermediary between the configuration data and the PLD programming process. The key provisioning system acts as a mediator that securely generates, distributes, and manages the encryption keys. This intermediary layer enables secure configuration programming by verifying authentication tokens before allowing configuration updates.
2Reliability
If security measures are strengthened to protect against unauthorized access, then reliability is improved, but device complexity increases due to additional security engines and key management systems
Solution Approach 1:
The patent implements a universal key provisioning system that handles multiple security functions through a single integrated mechanism. The same cryptographic infrastructure supports key generation, encryption, authentication, and secure configuration updates. This multi-functional approach strengthens security while minimizing the addition of separate complex security subsystems.
Solution Approach 2:
The PLD includes self-service security capabilities where the device automatically generates authentication tokens and verifies configuration data using its embedded cryptographic keys. The security engine performs self-validation of configuration integrity without requiring external security infrastructure, reducing overall system complexity while maintaining strong security.
3Reliability
If configuration data is encrypted to prevent unauthorized changes, then security is improved, but ease of operation deteriorates due to additional encryption and decryption steps
Solution Approach 1:
The patent performs preliminary encryption of the configuration data before it is programmed into the PLD. The configuration is encrypted with the customer-specific key during the key provisioning phase, so that subsequent programming operations work with already-encrypted data. This preliminary action eliminates the need for real-time encryption/decryption during normal operation, maintaining ease of use while ensuring security.
Solution Approach 2:
The encrypted configuration data serves as a secure copy that can be freely distributed and programmed without additional processing. Once encrypted, the configuration data behaves like a simple binary file that can be programmed using standard PLD programming tools, eliminating operational complexity while maintaining security through the cryptographic transformation.
4Reliability
If key provisioning systems are implemented to secure PLD configurations, then reliability is improved, but manufacturing complexity increases due to additional provisioning steps
Solution Approach 1:
The patent merges the key provisioning process with the existing PLD manufacturing and programming workflow. The cryptographic key generation and configuration encryption are integrated into the standard configuration flow, allowing security to be added without creating separate manufacturing lines or processes. The same programming tools and infrastructure handle both secure and non-secure configurations.
Data Source
AI summary
Systems and methods for provisioning secure programmable logic devices (PLDs) are disclosed. An example secure PLD provisioning system includes an external system comprising a processor and a memory and configured to be coupled to a secure PLD through a configuration input/output (I/O) of the secure PLD. The external system is configured to generate a locked PLD comprising the secure PLD based, at least in part, on a request from a secure PLD customer, wherein the request from the secure PLD customer comprises a customer public key; and to provide a secured unlock package for the locked secure PLD. The external system may also be configured to provide an authenticatable key manifest comprising a customer programming key token and a corresponding programming public key associated with the locked secure PLD, wherein the authenticatable key manifest is signed using a programming private key generated by the locked secure PLD.


