Programmable Logic Security Settings via Non-Volatile Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing programmable logic devices (PLDs) face challenges in securely configuring security features, as they are typically fixed in silicon at manufacture, requiring multiple device variants for different security levels and complicating export and distribution, while also being vulnerable to reverse engineering and tampering.
Innovation Solution
Implementing a system where security features can be selectively enabled by users through software during device configuration via a test access port or configuration port, using non-volatile memory to store security settings, allowing a single silicon device to be used with different software packages for varying security levels, shifting security responsibility from hardware to software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features are fixed in silicon at manufacture, then device security is ensured, but device complexity increases and manufacturing becomes more difficult
Solution Approach 1:
The patent implements dynamic security configuration by storing security feature settings in configurable memory rather than hardwiring them in silicon. The control circuitry reads security configuration data from memory and dynamically enables or disables security features based on the stored values, allowing security settings to be changed without manufacturing new devices.
Solution Approach 2:
The patent changes the state parameters of security features from fixed physical implementations to software-configurable parameters. By storing security feature enable/disable states in memory and reading these values during operation, the system can modify security parameters without altering the physical device structure.
2Reliability
If multiple device variants are produced for different security levels, then security requirements are met, but manufacturing precision and production efficiency decrease
Solution Approach 1:
The patent creates a universal device platform that can fulfill multiple security requirements through software configuration. A single device design with configurable memory can be adapted to meet different security levels by loading appropriate configuration data, eliminating the need to manufacture separate device variants for each security requirement.
Solution Approach 2:
The system enables dynamic adaptation to different security requirements by reading security configuration data from memory at runtime. The control circuitry can enable or disable specific security features based on the configured values, allowing one device type to serve multiple security purposes without requiring precision manufacturing of different hardware variants.
3Reliability
If security features are hardwired in silicon, then security is guaranteed, but adaptability and ease of operation are reduced
Solution Approach 1:
The patent implements dynamic security feature configuration through memory-based storage and runtime reading of security settings. The control circuitry can enable or disable security features by reading different configuration values from memory, providing adaptability while maintaining security guarantees through controlled access and verification.
Solution Approach 2:
The system allows security parameters to be changed by modifying the configuration data stored in memory rather than altering physical silicon structures. This enables flexible adaptation of security features to different application requirements while maintaining the same hardware platform.
4Reliability
If different device variants are manufactured for different security levels, then security needs are met, but loss of time and distribution complexity increase
Solution Approach 1:
The patent creates a universal device that can be configured for different security levels through software, eliminating the need to manufacture, stock, and distribute multiple hardware variants. This reduces the time required for device provisioning and simplifies distribution logistics while still meeting diverse security needs.
Data Source
AI summary
Systems and methods are disclosed for allowing security features to be selectively enabled during device configuration. For example, a programmable integrated circuit device is provided that receives configuration data and security requirement data. Control circuitry compares enabled security features in the device against the security requirements, and can configure the programmable integrated circuit device with the configuration data or prevent such configuration. Control circuitry may also use the security requirement data to set security features within the device.


