PLD Key Provisioning with Encrypted Configuration Unlock

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing programmable logic devices face challenges in securing configuration data and protecting against subversion, particularly in trusted computing applications, necessitating improved systems for manufacturing, protecting, and upgrading PLDs.

Innovation Solution

The implementation of secure programmable logic devices (PLDs) with integrated security engines and configuration management systems, including encryption, authentication, and key provisioning to ensure secure configuration and operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If configuration data is stored in plaintext for easy programming, then programming ease is improved, but security against unauthorized access and subversion deteriorates

Engineering Contradiction:
Improveprogramming easeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting configuration data before it is stored in the PLD. The configuration data is encrypted using a key derived from a secret value stored in OTP memory, so that when the device is powered on, the encrypted data is already in place and ready to be decrypted and executed, eliminating the need for plaintext storage while maintaining programming ease

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism - a cryptographic key derivation system that uses a secret value from OTP memory to decrypt configuration data. This intermediary layer prevents direct access to plaintext configuration data while allowing authorized programming operations, thus resolving the contradiction between programming ease and security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security engines and encryption systems are integrated into PLDs, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security engine, OTP memory, and configuration data storage into a single integrated PLD structure. The security functions are combined with the programmable logic resources, creating a unified device that provides both computational functionality and security features without requiring separate security hardware components

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements multi-functionality by designing the PLD to simultaneously serve as both a programmable logic device and a security device. The same device fabric is used for both user logic implementation and cryptographic operations, eliminating the need for dedicated security hardware and reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If configuration data is protected through encryption, then security is improved, but programming and configuration process complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing automatic key derivation and decryption within the PLD. The device automatically derives the decryption key from the OTP-stored secret value and uses it to decrypt configuration data during the boot process, eliminating the need for external key management systems and simplifying the configuration process

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3791305B1Key provisioning systems and methods for programmable logic devices
Publication Date: 2026.03.18 LATTICE SEMICON CORP
  • EP3791305B1 patent drawingFigure 1
  • EP3791305B1 patent drawingFigure 2
  • EP3791305B1 patent drawingFigure 3

AI summary

Systems and methods for provisioning secure programmable logic devices (PLDs) are disclosed. An example secure PLD provisioning system includes an external system comprising a processor and a memory and configured to be coupled to a secure PLD through a configuration input/output (I/O) of the secure PLD. The external system is configured to generate a locked PLD comprising the secure PLD based, at least in part, on a request from a secure PLD customer, wherein the request from the secure PLD customer comprises a customer public key; and to provide a secured unlock package for the locked secure PLD. The external system may also be configured to provide an authenticatable key manifest comprising a customer programming key token and a corresponding programming public key associated with the locked secure PLD, wherein the authenticatable key manifest is signed using a programming private key generated by the locked secure PLD.