Programmable Logic Device Security Gating via Non-Volatile Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing programmable logic devices lack effective security features to control access to volatile and non-volatile memories, leading to potential reverse engineering and hacking risks, with current solutions compromising boundary scan compliance.
Innovation Solution
Incorporating non-volatile memory to store security bits that gate instructions and control signals, allowing selective locking of instructions and control signals based on the state of these bits, ensuring secure operation without compromising compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If boundary scan port is completely disabled to prevent reverse engineering, then security is improved, but boundary scan compliance is lost
Solution Approach 1:
The boundary scan port's access control is made dynamic through gating logic that selectively enables or disables specific instructions based on security bit states. Instead of a static disablement, the system dynamically controls instruction execution flow, allowing compliance-maintaining instructions to pass while blocking security-risk instructions.
Solution Approach 2:
Gating logic is introduced as an intermediary component between the boundary scan port and the instruction execution path. This mediator selectively permits or blocks instructions based on security bit evaluations, enabling the system to maintain boundary scan compliance while preventing unauthorized access to sensitive operations.
2Reliability
If security features are added to control access to memories, then security is improved, but device complexity increases
Solution Approach 1:
The gating logic serves multiple functions: it evaluates security bits, determines instruction accessibility, and controls execution flow all within a single logical structure. This multi-functionality reduces the need for separate security management components, thereby limiting the increase in device complexity while maintaining comprehensive security control.
Solution Approach 2:
The security mechanism utilizes existing instruction register logic and control logic within the PLD, rather than requiring entirely separate security hardware. The system self-serves by leveraging its own internal resources for security enforcement, minimizing additional complexity while achieving secure memory access control.
Data Source
AI summary
Method and apparatus for providing secure programmable logic devices is described. One aspect of the invention relates to securing a programmable logic device having instruction register logic coupled to control logic via an instruction bus. A non-volatile memory is provided for storing at least one security bit for at least one instruction associated with the programmable logic device. Gating logic is provided in communication with the non-volatile memory and at least a portion of the instruction bus. The gating logic is configured to selectively gate decoded instructions transmitted from the instruction register logic towards the control logic based on state of the at least one security bit.


