Shared Cryptographic Engine for PLD Bitstream and User Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing programmable logic devices (PLDs) face challenges in securely configuring and protecting configuration data, as well as providing cryptographic security for both bitstream and user data, often requiring dedicated hardware that increases power consumption and chip area.
Innovation Solution
A PLD with a configuration engine, PLD fabric, and a shared security engine, facilitated by an interface integration logic circuit, which allows dynamic switching between bitstream and user security functions, enabling efficient use of cryptographic hardware for both configuration and user data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated cryptographic hardware is provided for both bitstream and user security functions, then security capability is improved, but power consumption and chip area increase
Solution Approach 1:
The patent combines bitstream security functions and user security functions into a single shared cryptographic hardware block. The interface integration logic circuit dynamically routes between these two functional areas, allowing one cryptographic engine to serve dual purposes. This merging eliminates the need for separate dedicated hardware for each security function, thereby reducing power consumption and chip area while maintaining comprehensive security coverage.
Solution Approach 2:
The cryptographic hardware block is designed with universal functionality to handle both bitstream security operations (during configuration) and user security operations (during runtime). The interface integration logic circuit enables this multi-functionality by dynamically connecting the cryptographic hardware to either the bitstream interface or user fabric based on operational mode, allowing a single hardware resource to perform multiple security roles.
2Reliability
If dedicated cryptographic hardware is provided for both bitstream and user security functions, then security capability is improved, but chip area increases
Solution Approach 1:
The patent merges bitstream security and user security hardware requirements into a single shared cryptographic engine. The interface integration logic circuit manages resource sharing between these two functional domains, allowing one cryptographic hardware instance to replace what would traditionally require two separate hardware blocks, thereby reducing chip area while preserving full security functionality.
Solution Approach 2:
The cryptographic hardware block implements universal security functions that can operate in both bitstream security mode and user security mode. The interface integration logic circuit enables this universality by dynamically routing operational control to the appropriate interface, allowing a single hardware block to fulfill multiple security roles that would otherwise require separate dedicated hardware.
3Productivity
If cryptographic hardware is shared between configuration engine and PLD fabric, then resource efficiency is improved, but access control complexity increases
Solution Approach 1:
The interface integration logic circuit serves as an intermediary layer between the shared cryptographic hardware and its two potential users: the configuration engine and the PLD fabric. This mediator manages access requests, determines appropriate routing based on operational context, and coordinates resource sharing. By introducing this intermediary control layer, the system achieves efficient resource sharing while maintaining clear access control boundaries.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Various techniques are provided to implement cryptographic hardware sharing systems and methods. In one example, a programmable logic device (PLD) includes a configuration engine configured to provide configuration data for processing using a first set of security functions. The PLD further includes a PLD fabric including an array of memory cells configured to operate upon being programmed using the configuration data and provide user data for processing using a second set of security functions. The PLD further includes a security engine including a cryptographic circuit and an interface integration logic circuit. The logic circuit is configured to selectively couple, based on an indicator, the configuration engine or PLD fabric to the cryptographic circuit. The cryptographic circuit is configured to perform the first set or second set of security functions when coupled to the configuration engine or PLD fabric, respectively, by the logic circuit. Related systems and methods are provided.