Secure Microcontroller FPGA Reconfiguration Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field programmable gate arrays (FPGAs) and other reconfigurable devices lack a root of trust during their lifecycle, leading to insecure manufacturing environments and inadequate encryption, which poses risks of attacks and lacks monitoring functions.

Innovation Solution

A system and method where encrypted data is decrypted and re-encrypted using different encryption schemes, utilizing a secure microcontroller to establish a trusted communication channel for secure reconfiguration and upgrading of FPGAs, ensuring integrity through digital signatures and secure storage of encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is enabled and keys are programmed into FPGA during manufacturing, then security and trustworthiness are improved, but the manufacturing environment becomes more complex and requires additional monitoring functions

Engineering Contradiction:
ImprovetrustworthinessVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing a root of trust and enabling encryption keys during the manufacturing process itself, rather than attempting to add these security features later. The secure microcontroller is configured with encryption capabilities and keys before the FPGA is deployed, ensuring security is built-in from the start of the device lifecycle.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure microcontroller as an intermediary component that manages encryption keys and security functions separately from the main FPGA logic. This mediator handles the complex security operations, allowing the FPGA to focus on its primary function while the microcontroller provides the necessary security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If reconfiguration data is stored in untrusted environment, then ease of operation is improved, but security and data integrity are worsened due to potential attacks

Engineering Contradiction:
Improvereconfiguration capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the security-critical functions (key storage, decryption, verification) from the untrusted FPGA environment and places them in a trusted secure microcontroller. The reconfiguration data remains in the untrusted environment for ease of operation, but the sensitive operations are performed in the trusted microcontroller, separating security functions from general-purpose functions.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary action by pre-establishing a trusted communication channel between the secure microcontroller and the external system before reconfiguration operations. Digital signatures are verified and encryption keys are established in advance, creating a secure foundation that allows safe reconfiguration even when data temporarily resides in untrusted storage.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If monitoring functions and audit mechanisms are added to FPGA, then security is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure microcontroller as an intermediary that handles all monitoring and audit functions externally to the main FPGA device. This separate monitoring entity can track reconfiguration operations, verify data integrity, and audit security events without adding complex monitoring circuitry to the FPGA itself, thus improving security while minimizing added complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9183413B2Method and system for controlling a device
Publication Date: 2015.11.10 INFINEON TECHNOLOGIES AG
  • US9183413B2 patent drawing
  • US9183413B2 patent drawing
  • US9183413B2 patent drawing

AI summary

A system and method for controlling a device. Data that was encrypted using a first encryption scheme is decrypted, then re-encrypted using a second encryption scheme. The re-encrypted data is then decrypted.