Root of Trust Chain for Programmable Logic Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional programmable logic devices (PLDs) face challenges in upgrading their security protocols after deployment, particularly due to advances in quantum computing, which can render existing security protocols obsolete or compromised.

Innovation Solution

The implementation of a root of trust chain for PLDs, where hardware components are configured with an inherently trusted default set of operations and security protocols stored in non-volatile memory. This allows for the authentication and updating of customer configuration bitstreams and security protocols, ensuring continuous security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols are implemented using fixed hardware and non-upgradable ROM in conventional PLDs, then security protection is provided during initial deployment, but the security protocols cannot be upgraded after deployment to counter new threats such as quantum computing advances

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity protocol upgradability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic security architecture where security protocols transition from static fixed hardware implementation to a flexible system that can be updated. The configuration memory is designed to accept updated security protocols after deployment, allowing the system to adapt to new cryptographic standards and quantum computing threats while maintaining the original root of trust for authentication.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent prepares the PLD architecture in advance with dedicated configuration memory and authentication mechanisms that enable future security protocol updates. The root of trust is established during manufacturing with preliminary authentication capabilities, creating a foundation that allows secure protocol upgrades without requiring physical device access or manufacturing intervention later.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If configuration bitstreams are encrypted with fixed security protocols, then protection against unauthorized access is achieved, but the ability to enhance security against emerging threats is lost

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidsecurity enhancement capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The encryption system is designed with dynamic update capability where the security protocols used to encrypt configuration bitstreams can be upgraded. The authentication mechanism verifies updated protocols against the immutable root of trust, allowing the system to maintain strong encryption protection while adapting to new cryptographic standards and quantum computing threats.

Inventive Principle:
Principle #15Dynamics

3Stability of the object's composition

If non-volatile memory is used to store security protocols, then security settings are preserved across power cycles, but the protocols become immutable and cannot be updated after deployment

Engineering Contradiction:
Improvesecurity protocol persistenceVSAvoidsecurity protocol updateability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The memory system is segmented into two distinct parts: an immutable root of trust stored in non-volatile memory that provides persistent authentication authority, and a separate configurable security protocol storage area that can be updated. This segmentation allows the system to maintain stable, persistent security foundations while enabling updates to security protocols to counter new threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The root of trust acts as an intermediary between the immutable authentication authority and the upgradable security protocols. It provides a stable reference point that verifies updated protocols, enabling the system to transition from static to dynamic security while maintaining persistence and reliability across power cycles.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250131081A1Root of trust chain and updatable security for programable logic devices, systems, and methods
Publication Date: 2025.04.24 LATTICE SEMICON CORP
  • US20250131081A1 patent drawing
  • US20250131081A1 patent drawing
  • US20250131081A1 patent drawing

AI summary

Various techniques are provided for providing a root of trust chain, updating security protocols, and generating trusted customer configuration bitstreams for a programmable logic device (PLD). In one example, a method includes configuring hardware components of a PLD with an inherently trusted default set of operations immutably stored in a non-volatile memory and comprising a first root of trust for the PLD. The method also includes authenticating, by the hardware components configured with the default set of operations, a customer configuration bitstream comprising an updated set of operations. The method also includes reconfiguring the hardware components to replace the default set of operations with the updated set of operations if the authenticating is successful, wherein the updated set of operations comprise a second root of trust for the PLD. Additional devices, systems and methods are also provided.