Secure IP Core Exchange via Trusted Loader
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securely delivering and managing IP cores for programmable logic devices (PLDs) are inadequate, as they require pre-programming of vendor keys, expose secret keys to customers, lack mechanisms for key revocation, and incentivize IP vendors to focus on ASIC-centric designs, leading to suboptimal performance in PLDs.
Innovation Solution
A secure exchange framework using public/private key encryption, where IP vendors encrypt IP cores with the PLD's public key, and a trusted loader decrypts them within the PLD, preventing unauthorized access and allowing dynamic key management, enabling secure and efficient delivery of IP cores directly to PLDs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vendor keys are pre-programmed into PLD key registers, then secure IP core delivery is enabled, but key storage capacity is limited and key revocation is impossible
Solution Approach 1:
The patent transitions from static pre-programmed keys to dynamic key loading. The PLD receives vendor keys through a configuration channel at runtime rather than having them hard-coded during manufacturing. This allows the key set to be dynamically changed, enabling both secure delivery and flexible key management including revocation capabilities.
Solution Approach 2:
The patent introduces a configuration channel as an intermediary mechanism between the vendor and PLD. This channel serves as a trusted delivery path that allows secure key transmission without requiring physical access or exposing keys to external tools. The configuration channel mediates the key delivery process, enabling secure communication while maintaining vendor control.
2Ease of operation
If secret keys are exposed to EDA tools for bitstream generation, then IP core integration is enabled, but key security is compromised
Solution Approach 1:
The patent extracts the secret key from the EDA tool environment and places it exclusively within the PLD's configuration channel. The vendor key never leaves the secure configuration path and is not exposed to external tools. This separation ensures that EDA tools can perform their integration functions without accessing sensitive key material.
Solution Approach 2:
The configuration channel acts as a secure intermediary that enables IP core integration without exposing keys. It provides a trusted path for the PLD to receive and process vendor keys and IP cores, allowing EDA tools to work with encrypted representations rather than plaintext keys, thus maintaining both operational ease and key security.
3Ease of operation
If board vendors are given key programming capability, then PLD configuration is simplified, but key security is vulnerable to monitoring
Solution Approach 1:
The patent introduces a secure configuration channel as a trusted intermediary that eliminates the need for board vendors to have direct key programming capability. The configuration channel handles key delivery securely, allowing board vendors to perform PLD configuration without exposing them to key material. This maintains operational simplicity while removing the security vulnerability of key monitoring.
4Reliability
If IP vendors focus on ASIC-centric designs, then delivery security is simplified, but PLD performance is suboptimal
Solution Approach 1:
The secure configuration channel serves as a trusted intermediary that enables IP vendors to deliver optimized PLD designs without compromising security. It provides a safe delivery mechanism that allows vendors to focus on PLD-specific optimizations while maintaining robust security, removing the need to choose between security simplicity and performance optimization.
Data Source
AI summary
A method and system are disclosed. The system includes a trusted loader. The method includes downloading an IP core from a vendor to a target device. The IP core is received in an encrypted form at the target device, which can be, for example, a programmable logic device.


