Secure Partitioning Integrated Circuit Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In server virtualization, existing technologies face challenges in securely partitioning integrated circuits to allow independent operation of different circuit designs while preventing data access and ensuring secure authentication and resource management across multiple users.

Innovation Solution

Implementing a computer system with programmable integrated circuits that securely partition resources into distinct portions, using interconnects to prevent data access between circuit designs and employing authentication mechanisms to ensure secure operation and resource allocation, with a global control circuit managing local control circuits to enforce secure partitions and independent operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If integrated circuit resources are partitioned into smaller portions for virtualization, then more functionality can be implemented per unit area and resource utilization increases, but security risks increase and data access control becomes more complex

Engineering Contradiction:
Improvefunctionality per unit areaVSAvoiddata access security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the integrated circuit into multiple secure partitions, each capable of independently implementing circuit designs from different owners. Each partition is isolated with controlled access through authentication mechanisms, allowing multiple virtual servers to operate simultaneously while maintaining security boundaries. This segmentation enables both high functionality per unit area and data access security.

Inventive Principle:
Principle #1Segmentation

2Productivity

If multiple circuit designs from different owners operate simultaneously on the same integrated circuit, then resource utilization and productivity increase, but the complexity of access control and authentication mechanisms increases

Engineering Contradiction:
Improveresource utilizationVSAvoidaccess control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces control circuits as intermediary components between different circuit design implementations. These control circuits manage authentication, decryption of configuration data, and access control signals, simplifying the overall system by centralizing security management rather than embedding complex control logic in each partition. This enables high productivity while managing access control complexity through dedicated intermediary components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If configuration data is stored in memory elements for circuit design implementation, then circuit functionality and adaptability improve, but security vulnerabilities increase due to potential unauthorized access to configuration data

Engineering Contradiction:
Improvecircuit functionalityVSAvoidunauthorized data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication mechanisms before configuration data is accessed or used. Control circuits verify authorization credentials before allowing access to configuration data stored in memory elements, and decryption is performed only after successful authentication. This prevents unauthorized access before it can occur, maintaining both circuit functionality and security.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9946826B1Circuit design implementations in secure partitions of an integrated circuit
Publication Date: 2018.04.17 ALTERA CORP
  • US9946826B1 patent drawing
  • US9946826B1 patent drawing
  • US9946826B1 patent drawing

AI summary

In server virtualization, the resources of an integrated circuit are partitioned into smaller portions, and each of these smaller portions is then operated independently. Software is used to represent the smaller portions as virtual environments. For the purpose of server virtualization, an integrated circuit may include several different circuit designs, each implemented in a secure partition in the integrated circuit. The operation of the circuit design implementations in the integrated circuit may require that each circuit design implementation can be verified as un-altered and from the respective user or owner and as having been approved by the integrated circuit owner and/or the circuit design implementation owner. The operation of the circuit design implementations in the integrated circuit may require that each circuit design implementation can be operated securely and independently of the other circuit design implementations in the integrated circuit.