Polymorphic FPGA Engine With Dynamic Pin Reassignment for Hardware Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital computer systems are vulnerable to attacks that disrupt communications, alter or access data, or issue false commands, leading to potential service outages, damage, or loss of life, and existing countermeasures are ineffective in preventing these threats due to latency and reversibility issues.

Innovation Solution

The implementation of a polymorphic hardware engine using dynamic pin reassignment (DPR) in field programmable gate arrays (FPGAs), which constantly changes signal mappings and uses multiple seeds to secure circuit configurations, making it difficult to reverse-engineer or predict the internal states of chips.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional static hardware configurations are used, then manufacturing and deployment are simple, but security against reverse engineering and attacks is weak

Engineering Contradiction:
ImprovesecurityVSAvoidhardware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic pin reassignment where the hardware engine continuously changes its internal configuration and pin mappings during operation. This dynamic reconfiguration prevents attackers from reverse-engineering the system since the hardware state is constantly changing, directly addressing the security weakness of static configurations while accepting increased operational complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes physical parameters of the hardware engine including pin assignments, signal mappings, and internal connectivity. By dynamically altering these physical parameters during operation, the system achieves security against reverse engineering while maintaining functional equivalence through controlled parameter transformations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If polymorphic reconfiguration is implemented continuously, then security against reverse engineering is enhanced, but latency and processing delays increase

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic reconfiguration where the hardware engine changes its configuration at regular intervals rather than continuously. This periodic approach maintains security by preventing reverse engineering while reducing latency compared to continuous reconfiguration, as the system remains stable during each configuration period before transitioning to the next state.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system performs reconfiguration actions in advance of potential attacks or threats. By proactively changing configurations before attacks occur, the system maintains security without needing to respond with time-consuming reconfiguration delays when under attack, thus reducing operational latency.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If custom hardware designs are developed for security, then security is improved, but development time and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a universal polymorphic hardware engine that can be implemented on standard FPGA platforms and applied to multiple different security applications. This multi-functional design achieves high security through polymorphic reconfiguration while maintaining productivity by using off-the-shelf FPGA boards rather than requiring custom hardware development for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses software-configurable logic to create virtual copies of hardware functionality on standard FPGAs. This approach achieves custom hardware-level security without the development costs and time of physical custom hardware design, as the security functionality is implemented through programmable logic that can be rapidly deployed and modified.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9178514B1Polymorphic hardware engine
Publication Date: 2015.11.03 SIDECHANNEL INC
  • US9178514B1 patent drawing
  • US9178514B1 patent drawing
  • US9178514B1 patent drawing

AI summary

The invention uses a new process called dynamic pin reassignment (DPR) to alter the circuitry. The system assigns input and output signals to buses that lead to a central distribution point, the crossbar, in the circuit. At the crossbar, signals are routed to the appropriate destination over one of the bus wires to the correct chip from the crossbar. At irregular intervals, the signal mapping for each in/out function is changed. The assignments or mappings, comprise the state of the circuit at any time. The period that a state is valid is determined by applying a reseeding function to a portion of a randomized stream that calculates the next state and the duration of validity. Multiple seeds or keys are used to create the states. Because each key changes independently of the other keys and without notice, the time interval for a valid state is greatly reduced, complicating any effort to reveal the internal states of chips.