Secure PLD Failure Characterization Through Selective NVM Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for systems and methods to securely characterize and repair failures in programmable logic devices (PLDs) used in trusted computing applications without risking customer data loss or unauthorized use, as existing technologies lack effective methods for securely erasing and debugging PLDs while protecting configuration data.
Innovation Solution
The implementation of secure PLD systems that allow for the secure erasure and failure characterization of locked secure PLDs, enabling debugging and repair without exposing customer data, by using techniques such as secure configuration, key provisioning, and failure characterization processes that ensure the PLD's secure operation and data protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PLDs are locked to customer-defined configurations for security, then security and data protection are improved, but the ability to debug and repair failures is worsened
Solution Approach 1:
The patent segments the PLD configuration into multiple image sectors (first configuration image sector, second configuration image sector, etc.) that can be independently erased and managed. This allows selective erasure of configuration data to enable debugging while maintaining security for other sectors, resolving the contradiction between security and repairability.
Solution Approach 2:
The patent implements preliminary actions by erasing specific configuration image sectors before debugging operations. The system prepares the PLD for debugging by selectively clearing configuration data in advance, allowing debug access without compromising overall security architecture.
2Loss of information
If configuration data is protected and locked in PLDs, then data loss prevention is improved, but the ability to characterize and mitigate failures is worsened
Solution Approach 1:
The configuration memory is divided into multiple separable image sectors that can be independently manipulated. This segmentation enables the system to erase only the necessary sectors for failure characterization while preserving other configuration data, thus allowing failure detection without compromising customer data protection.
Solution Approach 2:
The patent introduces an intermediary erasure process that acts as a mediator between the locked configuration state and the debugging state. By using controlled erasure of specific image sectors, the system transitions the PLD from a secure locked state to a debuggable state without direct exposure of protected data.
3Object-affected harmful factors
If PLDs are securely locked to prevent unauthorized use, then unauthorized access prevention is improved, but device reusability and re-provisioning are worsened
Solution Approach 1:
The patent segments the configuration into multiple image sectors that can be selectively erased. This allows the PLD to be re-provisioned by erasing only the necessary sectors while maintaining security for other parts, thereby improving device reusability without compromising unauthorized access prevention.
Solution Approach 2:
The system discards (erases) specific configuration image sectors when re-provisioning is needed, and recovers the PLD's functionality through re-programming. This selective discarding approach enables device reusability while maintaining security by only clearing necessary configuration data.
Data Source
AI summary
Systems and methods for failure characterization of secure programmable logic devices (PLDs) are disclosed. An example system includes a secure PLD including programmable logic blocks (PLBs) arranged in PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in non-volatile memory (NVM) of the secure PLD and/or coupled through a configuration input/output (I/O) of the secure PLD. The secure PLD is configured to receive a failure characterization (FC) command from the PLD fabric or an external system coupled to the secure PLD through the configuration I/O, and to execute the FC command to, at least in part, erase and/or nullify portions of the NVM. The secure PLD may also be configured to boot a debug configuration for the PLD fabric that identifies and/or characterizes operational failures of the secure PLD.


