PLD Key Provisioning with Encrypted Configuration Unlock
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing programmable logic devices face challenges in securing configuration data and protecting against subversion, particularly in trusted computing applications, necessitating improved systems for manufacturing, protecting, and upgrading PLDs.
Innovation Solution
The implementation of secure programmable logic devices (PLDs) with integrated security engines and configuration management systems, including encryption, authentication, and key provisioning to ensure secure configuration and operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration data is stored in plaintext for easy programming, then programming ease is improved, but security against unauthorized access and subversion deteriorates
Solution Approach 1:
The patent applies preliminary action by encrypting configuration data before it is stored in the PLD. The configuration data is encrypted using a key derived from a secret value stored in OTP memory, so that when the device is powered on, the encrypted data is already in place and ready to be decrypted and executed, eliminating the need for plaintext storage while maintaining programming ease
Solution Approach 2:
The patent introduces an intermediary mechanism - a cryptographic key derivation system that uses a secret value from OTP memory to decrypt configuration data. This intermediary layer prevents direct access to plaintext configuration data while allowing authorized programming operations, thus resolving the contradiction between programming ease and security
2Reliability
If security engines and encryption systems are integrated into PLDs, then security is improved, but device complexity increases
Solution Approach 1:
The patent merges the security engine, OTP memory, and configuration data storage into a single integrated PLD structure. The security functions are combined with the programmable logic resources, creating a unified device that provides both computational functionality and security features without requiring separate security hardware components
Solution Approach 2:
The patent implements multi-functionality by designing the PLD to simultaneously serve as both a programmable logic device and a security device. The same device fabric is used for both user logic implementation and cryptographic operations, eliminating the need for dedicated security hardware and reducing overall system complexity
3Reliability
If configuration data is protected through encryption, then security is improved, but programming and configuration process complexity increases
Solution Approach 1:
The patent applies self-service by implementing automatic key derivation and decryption within the PLD. The device automatically derives the decryption key from the OTP-stored secret value and uses it to decrypt configuration data during the boot process, eliminating the need for external key management systems and simplifying the configuration process
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for provisioning secure programmable logic devices (PLDs) are disclosed. An example secure PLD provisioning system includes an external system comprising a processor and a memory and configured to be coupled to a secure PLD through a configuration input/output (I/O) of the secure PLD. The external system is configured to generate a locked PLD comprising the secure PLD based, at least in part, on a request from a secure PLD customer, wherein the request from the secure PLD customer comprises a customer public key; and to provide a secured unlock package for the locked secure PLD. The external system may also be configured to provide an authenticatable key manifest comprising a customer programming key token and a corresponding programming public key associated with the locked secure PLD, wherein the authenticatable key manifest is signed using a programming private key generated by the locked secure PLD.