Secure IP Core Exchange via Trusted Loader

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely delivering and managing IP cores for programmable logic devices (PLDs) are inadequate, as they require pre-programming of vendor keys, expose secret keys to customers, lack mechanisms for key revocation, and incentivize IP vendors to focus on ASIC-centric designs, leading to suboptimal performance in PLDs.

Innovation Solution

A secure exchange framework using public/private key encryption, where IP vendors encrypt IP cores with the PLD's public key, and a trusted loader decrypts them within the PLD, preventing unauthorized access and allowing dynamic key management, enabling secure and efficient delivery of IP cores directly to PLDs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vendor keys are pre-programmed into PLD key registers, then secure IP core delivery is enabled, but key storage capacity is limited and key revocation is impossible

Engineering Contradiction:
Improvesecure IP core deliveryVSAvoidkey management flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from static pre-programmed keys to dynamic key loading. The PLD receives vendor keys through a configuration channel at runtime rather than having them hard-coded during manufacturing. This allows the key set to be dynamically changed, enabling both secure delivery and flexible key management including revocation capabilities.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces a configuration channel as an intermediary mechanism between the vendor and PLD. This channel serves as a trusted delivery path that allows secure key transmission without requiring physical access or exposing keys to external tools. The configuration channel mediates the key delivery process, enabling secure communication while maintaining vendor control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If secret keys are exposed to EDA tools for bitstream generation, then IP core integration is enabled, but key security is compromised

Engineering Contradiction:
ImproveIP core integrationVSAvoidkey confidentiality
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts the secret key from the EDA tool environment and places it exclusively within the PLD's configuration channel. The vendor key never leaves the secure configuration path and is not exposed to external tools. This separation ensures that EDA tools can perform their integration functions without accessing sensitive key material.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The configuration channel acts as a secure intermediary that enables IP core integration without exposing keys. It provides a trusted path for the PLD to receive and process vendor keys and IP cores, allowing EDA tools to work with encrypted representations rather than plaintext keys, thus maintaining both operational ease and key security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If board vendors are given key programming capability, then PLD configuration is simplified, but key security is vulnerable to monitoring

Engineering Contradiction:
ImprovePLD configurationVSAvoidkey monitoring risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure configuration channel as a trusted intermediary that eliminates the need for board vendors to have direct key programming capability. The configuration channel handles key delivery securely, allowing board vendors to perform PLD configuration without exposing them to key material. This maintains operational simplicity while removing the security vulnerability of key monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If IP vendors focus on ASIC-centric designs, then delivery security is simplified, but PLD performance is suboptimal

Engineering Contradiction:
Improvedelivery securityVSAvoidPLD performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The secure configuration channel serves as a trusted intermediary that enables IP vendors to deliver optimized PLD designs without compromising security. It provides a safe delivery mechanism that allows vendors to focus on PLD-specific optimizations while maintaining robust security, removing the need to choose between security simplicity and performance optimization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7788502B1Method and system for secure exchange of IP cores
Publication Date: 2010.08.31 XILINX INC
  • US7788502B1 patent drawing
  • US7788502B1 patent drawing
  • US7788502B1 patent drawing

AI summary

A method and system are disclosed. The system includes a trusted loader. The method includes downloading an IP core from a vendor to a target device. The IP core is received in an encrypted form at the target device, which can be, for example, a programmable logic device.