Shared Cryptographic Circuit for PLD Bitstream and User Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing programmable logic devices (PLDs) face challenges in protecting configuration data and user designs from subversion, with customers dedicating significant resources to secure operations and cryptographic hardware is often underutilized due to separate implementations for bitstream and user security.

Innovation Solution

A PLD architecture that integrates a configuration engine, PLD fabric, and security engine with an interface integration logic circuit to share cryptographic hardware, allowing dynamic switching between bitstream and user security functions, reducing power and chip area while enhancing cryptographic capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate cryptographic hardware implementations are used for bitstream security and user security, then security coverage is comprehensive, but device complexity and resource utilization are inefficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidhardware implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges separate cryptographic hardware implementations for bitstream security and user security into a single shared cryptographic hardware resource. The security engine includes a unified cryptographic circuit that can be dynamically allocated to perform either bitstream security functions (authentication, encryption of configuration data) or user security functions (cryptographic operations for user designs), eliminating the need for duplicate hardware instances and reducing overall device complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic circuit within the security engine is designed with multi-functionality to serve dual purposes: it can authenticate and encrypt configuration data (bitstream security) and perform cryptographic operations for user designs (user security). The interface integration logic circuit enables this universal functionality by dynamically routing and coupling the cryptographic circuit to the appropriate functional unit based on operational mode, allowing one hardware component to fulfill multiple security roles

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated cryptographic hardware is allocated for each security function, then security performance is optimized, but power consumption and chip area increase

Engineering Contradiction:
Improvesecurity performanceVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent consolidates cryptographic hardware resources into a single shared security engine that serves both bitstream and user security functions. By merging what would otherwise be separate cryptographic accelerators into one unified resource, the system achieves the same security performance through a single hardware instance, thereby reducing power consumption and chip area while maintaining optimized cryptographic operation performance for both security domains

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If advanced cryptographic functions are implemented for both configuration and user data, then security protection is enhanced, but hardware resource requirements increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidhardware resource requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic circuit in the security engine is designed as a universal resource capable of performing advanced cryptographic functions (authentication, encryption, hashing) for both configuration data and user data. The interface integration logic circuit enables this circuit to be dynamically coupled to either the configuration engine or PLD fabric based on operational needs, allowing advanced security protection for both data types while sharing the same hardware resources rather than requiring separate dedicated circuits for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12445132B2Cryptographic hardware sharing systems and methods
Publication Date: 2025.10.14 LATTICE SEMICON CORP
  • US12445132B2 patent drawing
  • US12445132B2 patent drawing
  • US12445132B2 patent drawing

AI summary

Various techniques are provided to implement cryptographic hardware sharing systems and methods. In one example, a programmable logic device (PLD) includes a configuration engine configured to provide configuration data for processing using a first set of security functions. The PLD further includes a PLD fabric including an array of memory cells configured to operate upon being programmed using the configuration data and provide user data for processing using a second set of security functions. The PLD further includes a security engine including a cryptographic circuit and an interface integration logic circuit. The logic circuit is configured to selectively couple, based on an indicator, the configuration engine or PLD fabric to the cryptographic circuit. The cryptographic circuit is configured to perform the first set or second set of security functions when coupled to the configuration engine or PLD fabric, respectively, by the logic circuit. Related systems and methods are provided.