Secure PLD Asset Lock Policies for Configuration Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure management of programmable logic devices (PLDs) to protect configuration data and prevent subversion in trusted computing applications, as existing systems lack effective methods to securely manufacture, distribute, upgrade, and test PLDs while maintaining data integrity.

Innovation Solution

The implementation of a secure PLD system that manages lock policies for internal and external access to assets, using lock status bits stored in a securable memory, and includes a security engine and configuration engine to securely configure and boot the device, ensuring only authorized access and preventing data extraction or reprogramming.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If lock policies are implemented to secure PLD assets, then security and data protection are improved, but device complexity increases due to additional security engines and management mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security engine is integrated within the PLD device structure, with security features nested within the fabric and configuration memory hierarchy. Lock policies are implemented as layered protection mechanisms where configuration memory sectors can be individually locked, providing security without requiring a completely separate external security system.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The security engine performs multiple functions including authentication, encryption, and lock policy management within a single integrated unit. The configuration memory serves dual purposes as both program storage and security credential storage, reducing the need for separate dedicated security components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If granular access control is implemented for configuration memory, then data extraction prevention is improved, but manufacturing and programming complexity worsens due to sector-by-sector lock management

Engineering Contradiction:
Improvedata extraction preventionVSAvoidmanufacturing ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The configuration memory is divided into multiple independently lockable sectors, allowing selective protection of different configuration regions. This segmentation enables manufacturers to lock only critical sectors while leaving others accessible for debugging or updates, simplifying the manufacturing process compared to locking the entire memory.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Lock policies are established during the manufacturing and configuration phase before deployment. Configuration memory sectors are pre-locked with security credentials embedded during fabrication, eliminating the need for complex post-manufacturing security configuration and reducing manufacturing complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security credentials are stored in configuration memory, then authentication capability is improved, but vulnerability to physical attacks worsens as credentials may be extracted from memory

Engineering Contradiction:
Improveauthentication capabilityVSAvoidphysical attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements preemptive security measures by locking configuration memory sectors and encrypting credentials before they can be extracted. The security engine monitors and controls all access attempts to configuration memory, preventing physical extraction attacks before they can compromise authentication credentials.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The security engine acts as an intermediary layer between the configuration memory and external access points. It mediates all read operations, decrypting credentials only when proper authentication occurs, thereby protecting stored credentials from direct physical extraction while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If lock status bits are stored in securable memory, then access control precision is improved, but manufacturing precision requirements worsen due to reliable bit storage demands

Engineering Contradiction:
Improveaccess control precisionVSAvoidmanufacturing precision
Core Design Contradiction:
Measurement precisionVSManufacturing precision

Solution Approach 1:

Lock status bits are combined with the configuration memory structure itself, using the same secure storage infrastructure that holds configuration data. This merging approach leverages the existing manufacturing precision requirements for configuration memory without adding separate high-precision storage components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The configuration memory structure provides self-service security by incorporating lock status bits and security credentials within its own architecture. The memory cells that store configuration data also maintain lock states, eliminating the need for separate high-precision lock storage elements and reducing manufacturing precision requirements.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11914716B2Asset management systems and methods for programmable logic devices
Publication Date: 2024.02.27 LATTICE SEMICON CORP
  • US11914716B2 patent drawing
  • US11914716B2 patent drawing
  • US11914716B2 patent drawing

AI summary

Systems and methods for asset management for secure programmable logic devices (PLDs) are disclosed. An example system includes a secure PLD including programmable logic blocks (PLBs) arranged in PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in non-volatile memory (NVM) of the secure PLD and/or coupled through a configuration input/output (I/O) of the secure PLD. The secure PLD is configured to receive a secure PLD asset access request from the PLD fabric or an external system coupled to the secure PLD through the configuration I/O, and to perform a secure PLD asset update process corresponding to the secure PLD asset access request, where the performing the asset update process is based on a lock status associated with a secure PLD asset corresponding to the secure PLD asset access request.