Programmable Logic Device Security Gating via Non-Volatile Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing programmable logic devices lack effective security features to control access to volatile and non-volatile memories, leading to potential reverse engineering and hacking risks, with current solutions compromising boundary scan compliance.

Innovation Solution

Incorporating non-volatile memory to store security bits that gate instructions and control signals, allowing selective locking of instructions and control signals based on the state of these bits, ensuring secure operation without compromising compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If boundary scan port is completely disabled to prevent reverse engineering, then security is improved, but boundary scan compliance is lost

Engineering Contradiction:
ImprovesecurityVSAvoidboundary scan compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The boundary scan port's access control is made dynamic through gating logic that selectively enables or disables specific instructions based on security bit states. Instead of a static disablement, the system dynamically controls instruction execution flow, allowing compliance-maintaining instructions to pass while blocking security-risk instructions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Gating logic is introduced as an intermediary component between the boundary scan port and the instruction execution path. This mediator selectively permits or blocks instructions based on security bit evaluations, enabling the system to maintain boundary scan compliance while preventing unauthorized access to sensitive operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security features are added to control access to memories, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gating logic serves multiple functions: it evaluates security bits, determines instruction accessibility, and controls execution flow all within a single logical structure. This multi-functionality reduces the need for separate security management components, thereby limiting the increase in device complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security mechanism utilizes existing instruction register logic and control logic within the PLD, rather than requiring entirely separate security hardware. The system self-serves by leveraging its own internal resources for security enforcement, minimizing additional complexity while achieving secure memory access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7536559B1Method and apparatus for providing secure programmable logic devices
Publication Date: 2009.05.19 XILINX INC
  • US7536559B1 patent drawing
  • US7536559B1 patent drawing
  • US7536559B1 patent drawing

AI summary

Method and apparatus for providing secure programmable logic devices is described. One aspect of the invention relates to securing a programmable logic device having instruction register logic coupled to control logic via an instruction bus. A non-volatile memory is provided for storing at least one security bit for at least one instruction associated with the programmable logic device. Gating logic is provided in communication with the non-volatile memory and at least a portion of the instruction bus. The gating logic is configured to selectively gate decoded instructions transmitted from the instruction register logic towards the control logic based on state of the at least one security bit.