Trusted Boot for FPLC Cryptographic Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Field-programmable logic circuits (FPLCs) used in cryptographic processing face challenges in achieving high-security and assurance due to programmability, which can lead to malfunction and insecure functioning, especially when they enter error modes or lose keys, making it difficult to maintain secure operations.
Innovation Solution
A method for trusted booting of cryptographic processor systems is implemented, where a default image with an unclassified algorithm is loaded into FPLCs, and a multi-layered key is used to decrypt a protected image, allowing cryptographic processing with a classified algorithm, ensuring secure operation and preventing unauthorized data transfer between ports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If programmability is utilized in FPLCs for cryptographic processing, then adaptability and versatility are improved, but security and reliability deteriorate due to risk of malfunction and insecure functioning
Solution Approach 1:
The patent segments the cryptographic processing into distinct functional layers: a trusted default image layer that provides security foundations, and a programmable overlay layer that handles cryptographic operations. This segmentation isolates the security-critical functions from the programmable functions, allowing adaptability while maintaining reliability through the immutable default image.
Solution Approach 2:
The patent implements preliminary action by pre-loading a trusted default image into the FPLC before any programmable content is loaded. This default image establishes the security baseline and cryptographic roots of trust in advance, ensuring that even if the programmable layer malfunctions, the system retains security through the pre-established trusted foundation.
2Ease of operation
If a default image with unclassified algorithm is loaded into FPLC, then ease of operation and initial functionality are improved, but cryptographic processing capability deteriorates
Solution Approach 1:
The patent applies nesting by placing the unclassified default image inside the FPLC as a contained layer, with classified cryptographic algorithms and images nested within the programmable overlay. The default image serves as an inner layer that provides foundational functionality, while classified algorithms are layered on top for enhanced cryptographic processing capability.
Solution Approach 2:
The patent achieves multi-functionality by designing the FPLC to support both unclassified default operations and classified cryptographic processing through a unified architecture. The same hardware platform can execute simple operational software from the default image while also supporting advanced cryptographic algorithms when needed, making the system universally applicable across different security requirements.
3Reliability
If multi-layered key is used for decrypting protected image, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the key into multiple independent layers or components, where each layer can be separately managed, stored, and protected. This segmentation allows the key to be divided into smaller manageable units that can be distributed across different locations and security domains, reducing the complexity of managing a single large key while enhancing overall security.
Solution Approach 2:
The patent introduces key layers as intermediary elements between the cryptographic algorithms and the actual encryption/decryption operations. These key layers act as mediators that simplify the key management process by providing structured access points and control mechanisms, making the complex multi-layered key structure more manageable while maintaining high security.
4Reliability
If default image prevents FPLC from passing information between ports, then security is improved, but functionality deteriorates
Solution Approach 1:
The patent implements dynamics by transitioning from a static default image that blocks inter-port communication to a dynamic state where classified cryptographic algorithms enable controlled data transfer. The system can adapt its behavior based on the loaded image: blocking by default for security, then enabling controlled communication when authenticated cryptographic operations are required.
Solution Approach 2:
The patent introduces cryptographic processing as an intermediary function between the default image's security restrictions and the need for data transfer. The classified algorithms act as intermediaries that mediate communication between ports, allowing data transfer only when protected by valid cryptographic keys and algorithms, thus maintaining security while enabling functionality.
Data Source
AI summary
In one embodiment, a method for trusted booting of a cryptographic processor system is disclosed. Default image(s) is loaded into a field-programmable logic chip or circuit (FPLC). The default image(s) cannot perform cryptographic processing, but can perform a first algorithm that is unclassified. A processor, internal or external to the FPLC, can be used with the default image. A multi-layer or multi-part key has portions stored in two different places. A protected image is decrypted with the multi-layer key using the first algorithm and loaded into the FPLC. Cryptographic processing is performed using a second algorithm classified by the government.


