Trusted Boot for FPLC Cryptographic Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Field-programmable logic circuits (FPLCs) used in cryptographic processing face challenges in achieving high-security and assurance due to programmability, which can lead to malfunction and insecure functioning, especially when they enter error modes or lose keys, making it difficult to maintain secure operations.

Innovation Solution

A method for trusted booting of cryptographic processor systems is implemented, where a default image with an unclassified algorithm is loaded into FPLCs, and a multi-layered key is used to decrypt a protected image, allowing cryptographic processing with a classified algorithm, ensuring secure operation and preventing unauthorized data transfer between ports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If programmability is utilized in FPLCs for cryptographic processing, then adaptability and versatility are improved, but security and reliability deteriorate due to risk of malfunction and insecure functioning

Engineering Contradiction:
ImproveprogrammabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the cryptographic processing into distinct functional layers: a trusted default image layer that provides security foundations, and a programmable overlay layer that handles cryptographic operations. This segmentation isolates the security-critical functions from the programmable functions, allowing adaptability while maintaining reliability through the immutable default image.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-loading a trusted default image into the FPLC before any programmable content is loaded. This default image establishes the security baseline and cryptographic roots of trust in advance, ensuring that even if the programmable layer malfunctions, the system retains security through the pre-established trusted foundation.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If a default image with unclassified algorithm is loaded into FPLC, then ease of operation and initial functionality are improved, but cryptographic processing capability deteriorates

Engineering Contradiction:
Improveoperational software functionVSAvoidcryptographic processing
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies nesting by placing the unclassified default image inside the FPLC as a contained layer, with classified cryptographic algorithms and images nested within the programmable overlay. The default image serves as an inner layer that provides foundational functionality, while classified algorithms are layered on top for enhanced cryptographic processing capability.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent achieves multi-functionality by designing the FPLC to support both unclassified default operations and classified cryptographic processing through a unified architecture. The same hardware platform can execute simple operational software from the default image while also supporting advanced cryptographic algorithms when needed, making the system universally applicable across different security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multi-layered key is used for decrypting protected image, then security is improved, but device complexity increases

Engineering Contradiction:
Improvemulti-layered securityVSAvoidkey management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key into multiple independent layers or components, where each layer can be separately managed, stored, and protected. This segmentation allows the key to be divided into smaller manageable units that can be distributed across different locations and security domains, reducing the complexity of managing a single large key while enhancing overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces key layers as intermediary elements between the cryptographic algorithms and the actual encryption/decryption operations. These key layers act as mediators that simplify the key management process by providing structured access points and control mechanisms, making the complex multi-layered key structure more manageable while maintaining high security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If default image prevents FPLC from passing information between ports, then security is improved, but functionality deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddata transfer capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by transitioning from a static default image that blocks inter-port communication to a dynamic state where classified cryptographic algorithms enable controlled data transfer. The system can adapt its behavior based on the loaded image: blocking by default for security, then enabling controlled communication when authenticated cryptographic operations are required.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces cryptographic processing as an intermediary function between the default image's security restrictions and the need for data transfer. The classified algorithms act as intermediaries that mediate communication between ports, allowing data transfer only when protected by valid cryptographic keys and algorithms, thus maintaining security while enabling functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8166289B2Trusted boot
Publication Date: 2012.04.24 VIASAT INC
  • US8166289B2 patent drawing
  • US8166289B2 patent drawing
  • US8166289B2 patent drawing

AI summary

In one embodiment, a method for trusted booting of a cryptographic processor system is disclosed. Default image(s) is loaded into a field-programmable logic chip or circuit (FPLC). The default image(s) cannot perform cryptographic processing, but can perform a first algorithm that is unclassified. A processor, internal or external to the FPLC, can be used with the default image. A multi-layer or multi-part key has portions stored in two different places. A protected image is decrypted with the multi-layer key using the first algorithm and loaded into the FPLC. Cryptographic processing is performed using a second algorithm classified by the government.