Secure PLD Tamper Detection via Lock Status Bits

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure management systems and methods to protect and distribute programmable logic device (PLD) configurations, particularly in trusted computing applications, to prevent subversion and data loss or extraction.

Innovation Solution

The implementation of a secure PLD provisioning system that assigns lock statuses to assets using lock status bits stored in a securable memory, allowing for secure configuration and booting while preventing unauthorized access or reprogramming, through a combination of encryption, key provisioning, and tamper detection mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If tamper detection mechanisms are implemented in PLDs, then security and data protection are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds multiple levels of security mechanisms within the PLD structure, including fuse arrays, OTP memory cells, and cryptographic logic nested within the fabric. These nested security features provide comprehensive protection while integrating seamlessly into the device architecture, minimizing the impact of added complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent introduces intermediary security elements such as isolation cells, guard rings, and cryptographic processors that act as mediators between sensitive resources and potential threats. These intermediaries detect and respond to tampering attempts without requiring complete redesign of the entire device, thus managing complexity effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If lock status bits are stored in securable memory, then access control is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidmanufacturing complexity
Core Design Contradiction:
Ease of operationVSEase of manufacture

Solution Approach 1:

The patent divides the security management function into discrete lock status bits stored in securable memory locations. Each bit or group of bits controls access to specific resources, allowing independent configuration and management. This segmentation enables flexible access control policies without requiring complex centralized security logic, simplifying both operation and manufacturing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses configurable parameters such as lock status bits, key values, and access policies stored in memory that can be programmed during manufacturing or field operation. These parameter-based control mechanisms allow the same hardware structure to enforce different security policies, reducing manufacturing complexity while maintaining operational flexibility.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption and key provisioning are implemented, then data protection is improved, but processing overhead increases

Engineering Contradiction:
Improvedata protectionVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs cryptographic key generation, encryption, and provisioning operations during the manufacturing and initialization phases before the device enters normal operation. Critical security parameters are pre-computed and stored in secure memory, reducing the computational overhead during runtime while maintaining strong data protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service cryptographic functions within the PLD, where the device generates its own keys, performs self-authentication, and manages its own security state without requiring continuous external intervention. This reduces processing overhead by eliminating repeated authentication handshakes and external key management operations.

Inventive Principle:
Principle #25Self-service

4Reliability

If tamper detection systems are added to PLDs, then security monitoring is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges tamper detection functionality with existing device components such as I/O blocks, configuration logic, and security engines. By combining multiple security functions into unified hardware modules, the patent achieves comprehensive monitoring capability while reducing the overall device complexity compared to implementing separate dedicated tamper detection systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240232439A1Tamper detection systems and methods for programmable logic devices
Publication Date: 2024.07.11 LATTICE SEMICON CORP
  • US20240232439A1 patent drawing
  • US20240232439A1 patent drawing
  • US20240232439A1 patent drawing

AI summary

Systems and methods for asset tamper detection management for secure programmable logic devices (PLDs) are disclosed. An example system includes a secure PLD including programmable logic blocks (PLBs) arranged in a PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in a non-volatile memory (NVM) of the secure PLD and/or coupled through a configuration input/output (I/O) of the secure PLD to the configuration engine. The secure PLD is configured to detect an asset tamper attempt on a targeted asset of the secure PLD, and to lock a securable asset associated with the detected asset tamper attempt, where the securable asset includes the targeted asset, the configuration I/O, and/or a communication bus of the secure PLD.