PLD Zeroization Circuit for Secure Configuration Memory Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Programmable logic devices (PLDs) using nonvolatile configuration memory face security risks as secure information can be compromised when the device is compromised or vulnerable, and existing technologies lack effective zeroization capabilities to erase cryptographic keys and security parameters.

Innovation Solution

Incorporating a security event detection circuit and an erase controller within PLDs to automatically detect and execute erase commands for configuration memory, preventing security information compromise by targeting specific memory areas for erasure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If nonvolatile configuration memory is used in PLDs to retain configuration data, then the device can maintain security information even when power is removed, but the security information becomes vulnerable to compromise when the device is compromised

Engineering Contradiction:
Improveconfiguration data retentionVSAvoidsecurity compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security risk by separating the configuration memory into volatile and nonvolatile portions, allowing selective erasure of only the nonvolatile portion containing security-critical data when a security event occurs, while preserving volatile configuration data that can be reloaded from external sources

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The PLD incorporates self-service security mechanisms through internal circuitry that automatically detects security events (such as voltage fluctuations, temperature changes, or unauthorized access attempts) and triggers automatic erasure of configuration memory without external intervention, enabling the device to protect itself

Inventive Principle:
Principle #25Self-service

2Reliability

If traditional ROM or programmable ROM is used off-chip for configuration storage, then the PLD can have nonvolatile configuration capability, but additional external configuration devices and interfaces are required

Engineering Contradiction:
Improvenonvolatile configuration storageVSAvoidexternal configuration devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the configuration memory functionality directly into the PLD chip by integrating both volatile configuration memory (for operational flexibility) and nonvolatile configuration memory (for persistence), eliminating the need for separate external ROM devices and simplifying the overall system architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The PLD achieves multi-functionality by combining the capabilities of volatile memory (fast access, reconfigurability) and nonvolatile memory (data retention) within a single device, allowing it to serve both as the logic device and its own configuration storage system

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If configuration memory is made re-programmable to allow design updates, then the PLD can be reconfigured with improved designs, but security information stored in the same memory becomes susceptible to unauthorized modification

Engineering Contradiction:
Improvedesign reconfigurabilityVSAvoidunauthorized modification risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the configuration memory into distinct portions: one portion stores security-critical data (cryptographic keys, authentication parameters) and another portion stores functional configuration data. This segmentation allows selective erasure of only the security portion when needed, while preserving the ability to reprogram the functional portion for design updates

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8621597B1Apparatus and method for automatic self-erasing of programmable logic devices
Publication Date: 2013.12.31 XILINX INC
  • US8621597B1 patent drawing
  • US8621597B1 patent drawing
  • US8621597B1 patent drawing

AI summary

Programmable logic devices (PLDs), programmable logic arrays (PLAs), complex programmable logic devices (CPLDs), and field programmable gate arrays (FPGAs), (collectively referred to as “PLDs”) can include circuitry for performing automatic erasing or “zeroization” of security information including data and programming. Such circuitry detects the occurrence of a possible security event, selects and/or forms one or more appropriate erase commands, and causes the command(s) to be executed against PLD memory. The circuitry prevents security information from being compromised under certain situations.