The present invention relates generally to programmable logic devices and, more particularly, to secure management of memory, communication interfaces, and/or other assets of such devices.
Programmable logic devices (PLDs) (e.g., field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), field programmable systems on a chip (FPSCs), or other types of programmable devices) may be configured with various user designs to implement desired functionality. Typically, user designs are synthesized and mapped into configurable resources (e.g., programmable logic gates, look-up tables (LUTs), embedded hardware, or other types of resources) and interconnections available in particular PLDs. Physical placement and routing for the synthesized and mapped user designs may then be determined to generate configuration data for the particular PLDs.
Customers for PLDs often dedicate considerable resources to developing configurations for their chosen PLD type and/or capability, and protecting the configuration data and protecting against subversion of a desired operation or capability tied to the chosen PLD and/or developed configuration is of paramount importance to many customers for PLDs. Thus, there is a need in the art for systems and methods to manufacture, protect, distribute, upgrade, and test PLDs and PLD configurations, particularly in the context of trusted computing applications and trusted computing architectures.
Embodiments of the present disclosure and their advantages are best understood by referring to the detailed description that follows. It should be appreciated that like reference numerals are used to identify like elements illustrated in one or more of the figures, wherein showings therein are for purposes of illustrating embodiments of the present disclosure and not for purposes of limiting the same.
The present disclosure provides systems and methods for managing lock policies regarding internal and external access to assets (e.g., buses, ports, and/or memory sectors) of a locked secure programmable logic device (PLD) for use in trusted computing applications and architectures, as described herein. For example, embodiments provide systems and methods for assigning lock statuses to individual assets and/or groupings of assets by setting corresponding lock status bits stored in a securable memory of a secure PLD, which may itself be locked to a customer defined configuration and/or operating context, to help reduce or eliminate risk of loss or extraction of the customer's or a manufacturer's data, or reprogramming of such data, without need to secure or limit distribution of locked secure PLDs (e.g., which may otherwise be programmed with non-customer data and potentially be used to subvert various security operations for a trusted platform, for example, including securely configuring and/or booting such platform/user device, as described herein).
In accordance with embodiments set forth herein, techniques are provided to securely implement user designs in programmable logic devices (PLDs). In various embodiments, a user design may be converted into and/or represented by a set of PLD components (e.g., configured for logic, arithmetic, or other hardware functions) and their associated interconnections available in a PLD. For example, a PLD may include a number of programmable logic blocks (PLBs), each PLB including a number of logic cells, and configurable routing resources that may be used to interconnect the PLBs and/or logic cells. In some embodiments, each PLB may be implemented with between 2 and 16 or between 2 and 32 logic cells.
In general, a PLD (e.g., an FPGA) fabric includes one or more routing structures and an array of similarly arranged logic cells arranged within programmable function blocks (e.g., PFBs and/or PLBs). The purpose of the routing structures is to programmably connect the ports of the logic cells/PLBs to one another in such combinations as necessary to achieve an intended functionality. A secure PLD may include various additional “hard” engines or modules configured to provide a range of security functionality that may be linked to operation of the PLD fabric to provide configurable trusted computing functionality and/or architectures. Routing flexibility and configurable function embedding may be used when synthesizing, mapping, placing, and/or routing a user design into a number of PLD components. As a result of various user design optimization processes, which can incur significant design time and cost, a user design can be implemented relatively efficiently, thereby freeing up configurable PLD components that would otherwise be occupied by additional operations and routing resources. In some embodiments, an optimized user design may be represented by a netlist that identifies various types of components provided by the PLD and their associated signals. In embodiments that produce a netlist of the converted user design, the optimization process may be performed on such a netlist. Once optimized, such configuration may be encrypted and signed and/or otherwise secured for distribution to a secured PLD, and such process may include one or more key provisioning processes, as described herein.
Referring now to the drawings,
I/O blocks 102 provide I/O functionality (e.g., to support one or more I/O and/or memory interface standards) for PLD 100, while programmable logic blocks 104 provide logic functionality (e.g., LUT-based logic or logic gate array-based logic) for PLD 100. Additional I/O functionality may be provided by serializer/deserializer (SERDES) blocks 150 and physical coding sublayer (PCS) blocks 152. PLD 100 may also include hard intellectual property core (IP) blocks 160 to provide additional functionality (e.g., substantially predetermined functionality provided in hardware which may be configured with less programming than logic blocks 104).
PLD 100 may also include blocks of memory 106 (e.g., blocks of EEPROM, block SRAM, and/or flash memory), clock-related circuitry 108 (e.g., clock sources, PLL circuits, and/or DLL circuits), and/or various routing resources 180 (e.g., interconnect and appropriate switching logic to provide paths for routing signals throughout PLD 100, such as for clock signals, data signals, or others) as appropriate. In general, the various elements of PLD 100 may be used to perform their intended functions for desired applications, as would be understood by one skilled in the art.
For example, certain I/O blocks 102 may be used for programming memory 106 or transferring information (e.g., various types of user data and/or control signals) to/from PLD 100. Other I/O blocks 102 include a first programming port (which may represent a central processing unit (CPU) port, a peripheral data port, an SPI interface, and/or a sysCONFIG programming port) and/or a second programming port such as a joint test action group (JTAG) port (e.g., by employing standards such as Institute of Electrical and Electronics Engineers (IEEE) 1149.1 or 1532 standards). In various embodiments, I/O blocks 102 may be included to receive configuration data and commands (e.g., over one or more connections 140) to configure PLD 100 for its intended use and to support serial or parallel device configuration and information transfer with SERDES blocks 150, PCS blocks 152, hard IP blocks 160, and/or logic blocks 104 as appropriate.
It should be understood that the number and placement of the various elements are not limiting and may depend upon the desired application. For example, various elements may not be required for a desired application or design specification (e.g., for the type of programmable device selected).
Furthermore, it should be understood that the elements are illustrated in block form for clarity and that various elements would typically be distributed throughout PLD 100, such as in and between logic blocks 104, hard IP blocks 160, and routing resources (e.g., routing resources 180 of
An external system 130 may be used to create a desired user configuration or design of PLD 100 and generate corresponding configuration data to program (e.g., configure) PLD 100. For example, system 130 may provide such configuration data to one or more I/O blocks 102, SERDES blocks 150, and/or other portions of PLD 100. As a result, programmable logic blocks 104, various routing resources, and any other appropriate components of PLD 100 may be configured to operate in accordance with user-specified applications.
In the illustrated embodiment, system 130 is implemented as a computer system. In this regard, system 130 includes, for example, one or more processors 132 which may be configured to execute instructions, such as software instructions, provided in one or more memories 134 and/or stored in non-transitory form in one or more non-transitory machine readable mediums 136 (e.g., which may be internal or external to system 130). For example, in some embodiments, system 130 may run PLD configuration software, such as Lattice Diamond System Planner software available from Lattice Semiconductor Corporation to permit a user to create a desired configuration and generate corresponding configuration data to program PLD 100.
System 130 also includes, for example, a user interface 135 (e.g., a screen or display) to display information to a user, and one or more user input devices 137 (e.g., a keyboard, mouse, trackball, touchscreen, and/or other device) to receive user commands or design entry to prepare a desired configuration of PLD 100.
An output signal 222 from LUT 202 and/or mode logic 204 may in some embodiments be passed through register 206 to provide an output signal 233 of logic cell 200. In various embodiments, an output signal 223 from LUT 202 and/or mode logic 204 may be passed to output 223 directly, as shown. Depending on the configuration of multiplexers 210-214 and/or mode logic 204, output signal 222 may be temporarily stored (e.g., latched) in latch 206 according to control signals 230. In some embodiments, configuration data for PLD 100 may configure output 223 and/or 233 of logic cell 200 to be provided as one or more inputs of another logic cell 200 (e.g., in another logic block or the same logic block) in a staged or cascaded arrangement (e.g., comprising multiple levels) to configure logic operations that cannot be implemented in a single logic cell 200 (e.g., logic operations that have too many inputs to be implemented by a single LUT 202). Moreover, logic cells 200 may be implemented with multiple outputs and/or interconnections to facilitate selectable modes of operation, as described herein.
Mode logic circuit 204 may be utilized for some configurations of PLD 100 to efficiently implement arithmetic operations such as adders, subtractors, comparators, counters, or other operations, to efficiently form some extended logic operations (e.g., higher order LUTs, working on multiple bit data), to efficiently implement a relatively small RAM, and/or to allow for selection between logic, arithmetic, extended logic, and/or other selectable modes of operation. In this regard, mode logic circuits 204, across multiple logic cells 202, may be chained together to pass carry-in signals 205 and carry-out signals 207, and/or other signals (e.g., output signals 222) between adjacent logic cells 202, as described herein. In the example of
Logic cell 200 illustrated in
As further described herein, portions of a user design may be adjusted to occupy fewer logic cells 200, fewer logic blocks 104, and/or with less burden on routing resources 180 when PLD 100 is configured to implement the user design. Such adjustments according to various embodiments may identify certain logic, arithmetic, and/or extended logic operations, to be implemented in an arrangement occupying multiple embodiments of logic cells 200 and/or logic blocks 104. As further described herein, an optimization process may route various signal connections associated with the arithmetic/logic operations described herein, such that a logic, ripple arithmetic, or extended logic operation may be implemented into one or more logic cells 200 and/or logic blocks 104 to be associated with the preceding arithmetic/logic operations.
In operation 310, system 130 receives a user design that specifies the desired functionality of PLD 100. For example, the user may interact with system 130 (e.g., through user input device 137 and hardware description language (HDL) code representing the design) to identify various features of the user design (e.g., high level logic operations, hardware configurations, and/or other features). In some embodiments, the user design may be provided in a register transfer level (RTL) description (e.g., a gate level description). System 130 may perform one or more rule checks to confirm that the user design describes a valid configuration of PLD 100. For example, system 130 may reject invalid configurations and/or request the user to provide new design information as appropriate.
In operation 320, system 130 synthesizes the design to create a netlist (e.g., a synthesized RTL description) identifying an abstract logic implementation of the user design as a plurality of logic components (e.g., also referred to as netlist components), which may include both programmable components and hard IP components of PLD 100. In some embodiments, the netlist may be stored in Electronic Design Interchange Format (EDIF) in a Native Generic Database (NGD) file.
In some embodiments, synthesizing the design into a netlist in operation 320 may involve converting (e.g., translating) the high-level description of logic operations, hardware configurations, and/or other features in the user design into a set of PLD components (e.g., logic blocks 104, logic cells 200, and other components of PLD 100 configured for logic, arithmetic, or other hardware functions to implement the user design) and their associated interconnections or signals. Depending on embodiments, the converted user design may be represented as a netlist.
In some embodiments, synthesizing the design into a netlist in operation 320 may further involve performing an optimization process on the user design (e.g., the user design converted/translated into a set of PLD components and their associated interconnections or signals) to reduce propagation delays, consumption of PLD resources and routing resources, and/or otherwise optimize the performance of the PLD when configured to implement the user design. Depending on embodiments, the optimization process may be performed on a netlist representing the converted/translated user design. Depending on embodiments, the optimization process may represent the optimized user design in a netlist (e.g., to produce an optimized netlist).
In some embodiments, the optimization process may include optimizing certain instances of a logic function operation, a ripple arithmetic operation, and/or an extended logic function operation which, when a PLD is configured to implement the user design, would occupy a plurality of configurable PLD components (e.g., logic cells 200, logic blocks 104, and/or routing resources 180). For example, the optimization process may include detecting multiple mode or configurable logic cells implementing logic function operations, ripple arithmetic operations, extended logic function operations, and/or corresponding routing resources in the user design, interchanging operational modes of logic cells implementing the various operations to reduce the number of PLD components and/or routing resources used to implement the operations and/or to reduce the propagation delay associated with the operations, and/or reprogramming corresponding LUTs and/or mode logic to account for the interchanged operational modes.
In another example, the optimization process may include detecting extended logic function operations and/or corresponding routing resources in the user design, implementing the extended logic operations into multiple mode or convertible logic cells with single physical logic cell outputs, routing or coupling the logic cell outputs of a first set of logic cells to the inputs of a second set of logic cells to reduce the number of PLD components used to implement the extended logic operations and/or routing resources and/or to reduce the propagation delay associated with the extended logic operations, and/or programming corresponding LUTs and/or mode logic to implement the extended logic function operations with at least the first and second sets of logic cells.
In another example, the optimization process may include detecting multiple mode or configurable logic cells implementing logic function operations, ripple arithmetic operations, extended logic function operations, and/or corresponding routing resources in the user design, interchanging operational modes of logic cells implementing the various operations to provide a programmable register along a signal path within the PLD to reduce propagation delay associated with the signal path, and reprogramming corresponding LUTs, mode logic, and/or other logic cell control bits/registers to account for the interchanged operational modes and/or to program the programmable register to store or latch a signal on the signal path.
In operation 330, system 130 performs a mapping process that identifies components of PLD 100 that may be used to implement the user design. In this regard, system 130 may map the optimized netlist (e.g., stored in operation 320 as a result of the optimization process) to various types of components provided by PLD 100 (e.g., logic blocks 104, logic cells 200, embedded hardware, and/or other portions of PLD 100) and their associated signals (e.g., in a logical fashion, but without yet specifying placement or routing). In some embodiments, the mapping may be performed on one or more previously-stored NGD files, with the mapping results stored as a physical design file (e.g., also referred to as an NCD file). In some embodiments, the mapping process may be performed as part of the synthesis process in operation 320 to produce a netlist that is mapped to PLD components.
In operation 340, system 130 performs a placement process to assign the mapped netlist components to particular physical components residing at specific physical locations of the PLD 100 (e.g., assigned to particular logic cells 200, logic blocks 104, routing resources 180, and/or other physical components of PLD 100), and thus determine a layout for the PLD 100. In some embodiments, the placement may be performed on one or more previously-stored NCD files, with the placement results stored as another physical design file.
In operation 350, system 130 performs a routing process to route connections (e.g., using routing resources 180) among the components of PLD 100 based on the placement layout determined in operation 340 to realize the physical interconnections among the placed components. In some embodiments, the routing may be performed on one or more previously-stored NCD files, with the routing results stored as another physical design file.
In various embodiments, routing the connections in operation 350 may further involve performing an optimization process on the user design to reduce propagation delays, consumption of PLD resources and/or routing resources, and/or otherwise optimize the performance of the PLD when configured to implement the user design. The optimization process may in some embodiments be performed on a physical design file representing the converted/translated user design, and the optimization process may represent the optimized user design in the physical design file (e.g., to produce an optimized physical design file).
In some embodiments, the optimization process may include optimizing certain instances of a logic function operation, a ripple arithmetic operation, and/or an extended logic function operation which, when a PLD is configured to implement the user design, would occupy a plurality of configurable PLD components (e.g., logic cells 200, logic blocks 104, and/or routing resources 180). For example, the optimization process may include detecting multiple mode or configurable logic cells implementing logic function operations, ripple arithmetic operations, extended logic function operations, and/or corresponding routing resources in the user design, interchanging operational modes of logic cells implementing the various operations to reduce the number of PLD components and/or routing resources used to implement the operations and/or to reduce the propagation delay associated with the operations, and/or reprogramming corresponding LUTs and/or mode logic to account for the interchanged operational modes.
In another example, the optimization process may include detecting extended logic function operations and/or corresponding routing resources in the user design, implementing the extended logic operations into multiple mode or convertible logic cells with single physical logic cell outputs, routing or coupling the logic cell outputs of a first set of logic cells to the inputs of a second set of logic cells to reduce the number of PLD components used to implement the extended logic operations and/or routing resources and/or to reduce the propagation delay associated with the extended logic operations, and/or programming corresponding LUTs and/or mode logic to implement the extended logic function operations with at least the first and second sets of logic cells.
In another example, the optimization process may include detecting multiple mode or configurable logic cells implementing logic function operations, ripple arithmetic operations, extended logic function operations, and/or corresponding routing resources in the user design, interchanging operational modes of logic cells implementing the various operations to provide a programmable register along a signal path within the PLD to reduce propagation delay associated with the signal path, and reprogramming corresponding LUTs, mode logic, and/or other logic cell control bits/registers to account for the interchanged operational modes and/or to program the programmable register to store or latch a signal on the signal path.
Changes in the routing may be propagated back to prior operations, such as synthesis, mapping, and/or placement, to further optimize various aspects of the user design.
Thus, following operation 350, one or more physical design files may be provided which specify the user design after it has been synthesized (e.g., converted and optimized), mapped, placed, and routed (e.g., further optimized) for PLD 100 (e.g., by combining the results of the corresponding previous operations). In operation 360, system 130 generates configuration data for the synthesized, mapped, placed, and routed user design. In various embodiments, such configuration data may be encrypted and/or otherwise secured as part of such generation process, as described more fully herein. In operation 370, system 130 configures PLD 100 with the configuration data by, for example, loading a configuration data bitstream (e.g., a “configuration”) into PLD 100 over connection 140. Such configuration may be provided in an encrypted, signed, or unsecured/unauthenticated form, for example, and PLD 100 may be configured to treat secured and unsecured configurations differently, as described herein.
Security engine 420 may be implemented as a hard IP resource configured to provide various security functions for use by PLD fabric 400 and/or configuration engine 440. In the embodiment shown in
Configuration engine 440 may be implemented as a hard IP resource configured to manage the configurations of and/or communications amongst the various elements of secure PLD 410. For example, configuration engine 440 may be configured to receive an encrypted/secured configuration of PLD fabric 400 from external system 130/machine readable medium 136 over configuration I/O 448, use security functions of security engine 420 to authenticate and/or decrypt such configuration, store the authenticated and/or decrypted configuration in NVM 450, soft or hard lock the portions of NVM 450 corresponding to the stored configuration, tag the stored configuration as authenticated and/or verified bootable, and/or program PLD fabric 400 according to the authenticated, decrypted, verified, and/or locked configuration, as described herein. In further embodiments, configuration engine 440 may be configured to configure at least a portion of programmable I/O 404 (e.g., to enable and/or disable at least portions of programmable I/O 404) over configuration port 444, as shown.
More generally, configuration engine 440 may be configured to manage or control configurations of elements of secure PLD 410, lock statuses of elements of secure PLD 410, boot of PLD fabric 400, and flow control throughout secure PLD 410. For example, configuration engine 440 may be configured to soft lock or unlock or hard lock any one or portion of buses 408, 442, 443, 446, for example, and/or to soft lock or unlock or hard lock any portion or sector of NVM 450. In a default unlocked configuration, buses 408, 442, and 446 may be implemented as secure buses similar in function to secure bus 446. External access bus 443 to configuration I/O 448 may be implemented according to one or more of a JTAG, I2C, SPI, and/or other external access bus or protocol, for example, configured to provide lockable/unlockable access to and/or from external system 130/machine readable medium 136. In a particular embodiment, secure bus 408 may be implemented according to a wishbone bus/interface.
NVM 450 may be implemented as a hard IP resource configured to provide securable non-volatile storage of data used to facilitate secure operation of secure PLD 410. For example, NVM 450 may include lock policy sector 460 corresponding to memory locations in NVM 460 indicating a lock status of data stored in NVM 450. The contents of lock policy sector 460 may be transferred to shadow registers within configuration engine 440 upon power on of secure PLD 410, for example, to allow such contents to be modified dynamically by configuration engine 440 and/or PLD fabric 400, depending on settings/lock statuses in lock policy sector 460. In general, the lock status of a particular resource indicates read, write/program, and/or erase access for that resource, as against PLD fabric 400, configuration I/O 448/external access bus 443, and/or other elements of secure PLD 410.
As described herein, “soft” lock refers to a read, write, and/or erase access status of a bus/port or memory location in NVM 450 that can be programmatically enabled or disabled by PLD fabric 400 and/or across external access bus 443 to granularly allow or disallow read, write, and/or erase access to the corresponding resource. “Hard” lock refers to a read, write, and/or erase access status of a bus/port or memory location in NVM 450 that can be programmatically enabled across external access bus 443, but that cannot be enabled or disabled by PLD fabric 400 and that cannot be disabled across external access bus 443. In various embodiments, assertion of a hard lock is generally one-way and eliminates the ability of PLD fabric 400 and/or external access bus 443 to further modify the lock status of all secured resources within secure PLD 410. In some embodiments, such locking scheme may be implemented by four bits for each resource (e.g., bus/port or sector of memory within NVM 450), one bit each for hard lock enable, read lock enable, write lock enable, and erase lock enable.
As shown in the embodiment illustrated by
Programmable I/O 404 may be implemented as at least partially configurable resources configured to provide or support a communication link between PLD fabric 400 and an external controller, memory, and/or other device, for example, across bus 402 (e.g., a bus configured to link portions of PLD fabric 400 to programmable I/O 404. In some embodiments, bus 402 and/or programmable I/O 404 may be integrated with PLD fabric 400. Configuration I/O 448 may be implemented as hard IP resources configured to support one or more external bus interfaces and/or protocols 449 to support communications with external system 130/machine readable medium 136, as described herein. In some embodiments, configuration I/O 448 and/or bus 443 may be integrated with configuration engine 440. More generally, one or more elements of secure PLD 410 shown as separate in
As shown in
Secure PLD programmer 530 may deliver the programmed and locked secure PLDs 410 to optional user device assembler 540 (e.g., a motherboard assembler, a smart phone assembler, and/or other user device/embedded device assembler/manufacturer), which integrates the programmed and locked secure PLDs 410 with the user device and provides the integrated user device to downstream customer 550, all without secure PLD programmer 530 and downstream customer 550 being able to determine the unencrypted contents of the device-specific encrypted configurations or to reprogram the locked secure PLDs with alternative configurations. Secure PLD customer 510 may then audit the programmed and locked secure PLDs 410 in the corresponding user devices at downstream customer 550 without divulging the unencrypted contents of the device-specific encrypted configurations or unlocking the secure PLDs 410. Although shown in
In the embodiment shown in
In general operation, secure PLD customer 510 may provide a request for a number of locked secure PLDs 410 to HSM 526 that includes a customer public key of a customer public/private key pair (e.g., generated within secure PLD customer 510, such as by its own HSM). HSM 526 may generate a customer-specific programming public/private key pair (e.g., used to encrypt, decrypt, and/or authenticate configurations for locked secure PLDs 410, such as to lock secure PLD 410 and unlock secure PLD 410 for programming) and a programming secret (e.g., a 256-bit random number word to further authenticate provided configurations) and provide the programming private key, the programming secret, and a factory public key to external system 130 for loading into and locking a blank or unlocked secure PLD 410. HSM 526 may be configured to generate the factory public/private key pair locally and/or retrieve such factory keys from memory 134, for example, and such factory keys may be factory-specific and/or customer-specific. Configuration engine 440 may receive a device-specific trace ID (e.g., which may identify a manufacturing batch, wafer, and wafer location corresponding to a fabrication process for secure PLD 410), the programming private key, the programming secret, the factory public key, and an initial programming image (IPI) configuration for PLD fabric 400, which may all be stored in one or more sectors of NVM 450 to lock secure PLD 410.
Configuration engine 440 may then store the trace ID in MFG trim 456 of NVM 450 and/or within device ID 422 of security engine 420 and generate a device unique seed by appending a random number (e.g., generated by TRNG 424) to the end of the trace ID, and such device unique seed may be stored within MFG trim 456 and/or used to seed generation of a device public/private key pair (e.g., generated by P/PKG 430 of security engine 420), which may be stored within device keys sector 458 of NVM 450. Configuration engine 440 may then provide the resulting device public key and trace ID to external system 130, which may relay the device public key and trace ID to HSM 526 to be added to a locked PLD manifest including a line item for each locked secure PLD 410 requested by secure PLD customer 510, where each line item includes the device-specific trace ID and device public key. HSM 526 may then encrypt and sign the programming secret using the customer public key and the programming private key, and the resulting encrypted programming packet may be provided to secure PLD customer 510 and accompanied by the programming public key (e.g., to help generate an encrypted and signed configuration for PLD fabric 400 of secure PLD 410). Once completed with entries for all locked secure PLDs 410 requested by secure PLD customer 510, HSM 526 may sign the locked PLD manifest using the programming private key and provide the signed locked PLD manifest to secure PLD customer 510, which can then use the locked PLD manifest, the programming secret, and the programming public key to manage programming of locked secure PLDs 410 by secure PLD programmer 530, as described herein.
In some embodiments, HSM 526 may be configured to generate a customer programming key token corresponding to a particular secure PLD customer 510 and/or the particular request for locked secure PLDs 410 received from secure PLD customer 510. Such customer programming key token may be used to reference (e.g., within a customer database stored in HSM 526) all information stored with respect to secure PLD customer 510 and/or the request for locked secure PLDs 410 received from secure PLD customer 510. Such stored information may include the programming public/private key pair, the programming secret, the factory public/private key pair, the locked PLD manifest, and/or other information or subsets of information associated with operation of secure PLD provisioning system 502 and/or 500. In embodiments where PLD stock 524 includes one or more previously locked secure PLDs 410 slated for retargeting (e.g., locking to a different secure PLD customer or different secure PLD request), HSM 526 may be configured to use a prior customer programming key token to retrieve the information used to lock the locked secure PLD, provide new information to secure PLD 410 (e.g., through external system 130) that is signed using the previous factory private key, and provide a retargeting command to secure PLD 410 (e.g., to be executed by secure PLD 410), where the retargeting command is executed by PLD fabric 400 and/or configuration engine 440 to authenticate the new information with the previous factory public key stored in NVM 450 and replace the previous information stored in NVM 450 (e.g., the device public/private key pair, the programming private key, the programming secret, the factory public key, and/or the IPI) with corresponding new or updated information.
Secure PLD 410 may be configured to extract the temporary session key from the first encrypted package provided by controller 620 (e.g., using the temporary private key), to encrypt a controller application image decryptor 663 using the session key, and provide the resulting second encrypted package to controller 620 over bus 604. Execution engine 624 of controller 620 may be configured to extract controller application image decryptor 663 from the second encrypted package upon receiving it from secure PLD 410, which may configure execution engine 624 to retrieve, authenticate, and decrypt a controller application image 632 stored in NVM 630 (e.g., over buses 602 and 604), store the authenticated and decrypted controller application image 632 in VM 622, and execute the authenticated and decrypted controller application image 632. In addition, secure PLD 410 and controller 620 may be configured to register a secure communication path with each other.
In another embodiment, secure PLD 410 may be configured to verify a configuration used to program PLD fabric 400 of secure PLD 410, using controller 620. For example, secure PLD 410 may be configured to use P/PKG 430 of security engine 420 to generate a temporary public/private key pair and provide the temporary public key to controller 620. Execution engine 624 of controller 620 may be configured to generate a temporary session key, encrypt the temporary session key using the temporary public key provided by secure PLD 410 and a cryptographic salt, and to provide the resulting third encrypted package to secure PLD 410 over bus 604. Controller 620 may also be configured to use the session key to encrypt a request to extract identifying data from one or more configuration images stored in NVM 450 of secure PLD 410, for example, and to send the resulting fourth encrypted package to secure PLD 410 over bus 604.
Secure PLD 410 may be configured to extract the temporary session key from the third encrypted package provided by controller 620, use the temporary session key to extract the request from the fourth encrypted package, to extract the requested identifying data from the one or more configuration images stored in NVM 450 of secure PLD 410, to encrypt the requested identifying data using the temporary session key, and to provide the resulting fifth encrypted package to controller 620 over bus 604. Upon receipt, controller 620 may be configured to verify a version, release date, and/or other characteristics of the one or more configuration images stored in NVM 450 by comparison to a database of such characteristics residing in user device 610 (e.g., in NVM 630 or VM 622) and/or accessible over or retrieved from a network (e.g., communications network 514, accessed via other user device modules 680, which may include a network interface device). In further alternative embodiments, secure PLD 410 may take the place of controller 620 and be used to control operation of user device 600.
In block 710, a logic device receives a request for a locked PLD. For example, a network communications device (e.g., external system 130, HSM 526) of secure PLD manufacturer 520 may be configured to receive a request for a locked secure PLD 410 from a network communications device (e.g., external system 130, HSM 526) of secure PLD customer 510. Such request may be transmitted over communication links 512 and/or through communications network 514, for example, and may include a customer public key of a corresponding customer public/private key pair, along with the number of devices requested and any specific model or other identifying information associated with a particular desired secure PLD 410.
In block 720, a logic device generates a locked PLD. For example, secure PLD manufacturer 520 may be configured to generate a locked secure PLD 410. In some embodiments, secure PLD manufacturer 520 may use an IC fabrication system to fabricate secure PLD 410, for example, which may include programming or storing or otherwise embedding device ID 422 in security engine 420 and/or MFG trim 456 of NVM 450. Secure PLD manufacturer 520 may also use external system 130 to lock secure PLD 410, as described herein. In one embodiment, secure PLD locking system 522 of secure PLD manufacturer 520 may be configured to assign a customer ID to secure PLD customer 510 and/or the request received in block 710, which may then be combined with device ID 422 and/or a device ordering part number (e.g., generated at manufacture) to provide a customer specific ordering part number that may be used to reference or identify secure PLD 410, such as in an unencrypted database stored in HSM 526.
HSM 526 may also be configured to generate a customer programming key token corresponding to secure PLD customer 510 and/or the customer public key in the request received in block 710 by generating a corresponding random and unique customer programming key token and/or a customer specific ordering part number and referencing all stored information related to generating locked secure PLDs referenced to such token or number. HSM 526 may also be configured to generate a programming public/private key pair and a programming secret, all specific to secure PLD customer 510 and/or the request received in block 710, all of which may be stored in HSM 526. HSM 526 may additionally be configured to generate a factory public/private key pair, which may be specific to secure PLD manufacturer 520, secure PLD customer 510, and/or the request received in block 710, which may also be stored in HSM 526.
HSM 526 may be configured to provide the factory public key, the programming private key, and the programming secret to external system 130 for programming/locking of secure PLD 410, for example, and to receive device-specific trace IDs and device public keys in return. HSM 526 may also be configured to encrypt and sign the programming secret using the customer public key and the programming private key, and the resulting encrypted programming packet may be provided to secure PLD customer 510 and accompanied by the programming public key (e.g., to help secure PLD customer 510 generate an encrypted and signed configuration for PLD fabric 400 of secure PLD 410). Secure PLD 410 may be configured to use TRNG 424 of security engine 420 to generate a device unique seed based on the trace ID stored in MFG trim 456 and/or device ID 422, and to use the device unique seed and/or P/PKG 430 of security engine 420 to generate a device public/private key pair, all specific to secure PLD 410, and all of which may be stored in NVM 450 (e.g., along with the programming private key, programming secret, factory public key, and/or an IPI configuration provided by external system 130 and/or HSM 526).
In another embodiment, HSM 526 may be configured to use the customer programming key token to retrieve the programming private key, the programming secret, and the device public key from a securely stored database and provide them to external system 130. External system 130 may then be configured to use the programming private key, the programming secret, and/or the device public key to provide an IPI configuration to secure PLD 410 and program PLD fabric 400 with the IPI. This programming may constitute an unsecure write operation and so may require a secure environment (e.g., taking place entirely within secure PLD manufacturer 520). In further embodiments, HSM 526 may be configured to receive a locked PLD manifest entry from external system 130 including a trace ID corresponding to secure PLD 410 and a corresponding device public key, to generate a complete locked PLD manifest corresponding to the request received in block 710, to sign the locked PLD manifest with the programming private key, and to provide the signed locked PLD manifest to secure PLD customer 510.
In additional embodiments, it may be useful to retarget an already programmed and locked secure PLD to a different customer or application (e.g., with a different programming key pair, programming secret, and public device key). Typically, an already programmed IPI need not be reprogrammed (e.g., the same IPI configuration for PLD fabric 400 may be used). For example, HSM 526 may be configured to use a customer programming key token and/or a trace ID to retrieve prior information (e.g., the original programming private key, programming secret, and device public key stored in HSM 526) used to lock secure PLD 410. HSM 526 may then be configured to use external system 130 to provide new information to secure PLD 410 that is signed using the previous factory private key, and provide a retargeting command to secure PLD 410 (e.g., to be executed by secure PLD 410), where the retargeting command may be executed by PLD fabric 400 and/or configuration engine 440 to authenticate the new information with the previous factory public key stored in NVM 450 and replace the previous information stored in NVM 450 (e.g., the device public/private key pair, the programming private key, the programming secret, the factory public key, and/or the IPI) with corresponding new or updated or retargeted information, as described herein.
In block 730, a logic device provides a secured unlock package for a locked PLD. For example, HSM 526 of secure PLD manufacturer 520 may be configured to provide a secured unlock package for the locked secure PLD 410 generated in block 720 to secure PLD customer 510. In one embodiment, HSM 526 may be configured to provide the encrypted programming packet, the programming public key, and/or the customer programming key token generated in block 720 to secure PLD customer 510. Such information may be used by secure PLD customer 510 to generate a protected configuration for secured PLD 410, as locked in block 720.
In block 740, a logic device provides an authenticatable manifest identifying a locked PLD. For example, secure PLD manufacturer 520 may be configured to provide an authenticatable locked PLD manifest identifying the locked secure PLD 410 generated in block 720. In one embodiment, HSM 526 may be configured to generate a manifest of trace IDs and device public keys (e.g., a manifest of device public keys referenced by trace ID), to sign the locked PLD manifest using the programming private key generated in block 720, and provide the signed locked PLD manifest to secure PLD customer 510. Such information may be used by secure PLD customer 510 to audit a selection of deployed and/or locked secured PLDs 410.
In block 750, a logic device generates a protected configuration for a locked PLD. For example, an external system 130 of secure PLD customer 510 may be configured to generate a protected configuration for the locked secure PLD 410 generated in block 720. In one embodiment, external system 130 may be configured to generate an unprotected configuration for PLD fabric 400 of secure PLD 410 using a process similar to process 300 discussed with reference to
In various embodiments, external system 130 and/or an HSM 526 of secure PLD customer 510 may be configured to generate an application public/private key pair, an application encryption key (e.g., an AES encryption key), and a programming packet public/private key pair. External system 130 may be configured to sign the application and feature configurations using the application private key and to encrypt the signed application and feature configurations using the application encryption key. External system 130 may also be configured to generate a programming key digest by signing a combination/list of the application public key, the application encryption key, and the programming secret (e.g., extracted from the encrypted programming packet of the secured unlock package provided in block 730) with the application private key, deriving an encryption key based on the programming public key and the programming packet private key (e.g., using an elliptic-curve Diffie-Hellman key derivation function), encrypting the signed combination of keys using the derived encryption key, and combining the encrypted and signed combination of keys with the programming packet public key (e.g., appending the programming packet public key to the encrypted and signed combination of keys) to create the programming key digest. External system 130 may also be configured to sign a locked PLD manifest (e.g., received in block 740) with the packet private key for authenticated delivery to a downstream secure PLD programmer 530, user device assembler 540, and/or downstream customer 550. External system 130 may be configured to generate a protected configuration for secure PLD 410 by combining the encrypted application and feature configurations with the programming key digest to create a single protected packet of information.
In block 760, a logic device provides a locked PLD to a configuration programmer. For example, secure PLD manufacturer 520 may be configured to provide the locked secure PLD 410 generated in block 720 to secure PLD programmer 530, as described herein.
In block 770, a logic device programs a locked PLD according to a protected configuration. For example, an external device 130 of secure PLD programmer 530 may be configured to program the locked secure PLD 410 generated in block 720 according to the protected configuration generated in block 750 and provided by secure PLD customer 510. In one embodiment, an external system 130 of secure PLD programmer 530 may be configured to provide the protected configuration/packet generated in block 750 to secure PLD 410, which may be configured to boot according to the IPI provided to secure PLD 410 in block 720. Secure PLD 410 may then validate the protected configuration and program elements of secure PLD 410, including PLD fabric 400 and portions of NVM 450, through one or more buses of secure PLD 410. More particularly, secure PLD 410 may be configured to decrypt the encrypted keys in the programming key digest using the programming private key stored in NVM 450 in block 720 and the packet public key generated in block 750. Secure PLD 410 may also be configured to authenticate the decrypted key digest with the application public key and verify that the programming secret in the programming key digest matches the programming secret stored in NVM 450 in block 720. If both checks pass, secure PLD 410 may store the application public key and application encryption key from the key digest in NVM 450.
Once the application public key and application encryption key from the key digest are stored in NVM 450, secure PLD 410 may then decrypt the application and feature configurations and authenticate the decrypted application and feature configurations. For example, the application and feature configurations may only be programmed into secure PLD 410 if the bitstreams are successfully decrypted and authenticated using the application encryption key and the application public key. In the event the application configuration is successfully authenticated, secure PLD 410 may be configured to program/store the application configuration into one of configuration image sectors 452 or 454, to set a pre-authentication bit for the appropriate image, to erase the IPI from PLD fabric 400, and/or to program PLD fabric 400 according to the stored application configuration. The feature configuration may be programmed into one or more portions of NVM 450. Other security checks to be performed prior to programming secure PLD 410 may include validating the locked PLD manifest, checking trace ID matching within the locked PLD manifest, and/or other security checks, as described herein.
In block 780, a logic device assembles a user device including a locked and programmed PLD. For example, a pick and place system of user device assembler 540 may be configured to assemble user device 610 including the locked secure PLD 410 generated in block 720 and programmed in block 770.
In block 790, a logic device audits a locked and programmed PLD based on an authenticatable manifest. For example, secure PLD customer 510 may be configured to audit the locked secure PLD generated in block 720 and programmed in block 770 based on the authenticatable locked PLD manifest provided in block 740. In one embodiment, an external system 130 of secure PLD customer 510 or downstream customer 550 may be configured to authenticate the locked PLD manifest provided by secure PLD manufacturer 520 or secure PLD customer 510 in block 740, query secure PLD 410 for its trace ID and/or device public key and compare to the trace ID and device public key in the locked PLD manifest, and to challenge secure PLD 410 using the device public key, such as by encrypting a random number using the device public key, providing the resulting encrypted package to secure PLD 410 in a device key challenge, and comparing the returned result to the original random number (e.g., a matching result indicates a successful audit of an operating secure PLD 410). Such auditing may in some embodiments take place prior to erasing the IPI configuration in block 770. Successful auditing indicates a functioning locked secure PLD 410.
Thus, by employing the systems and methods described herein, embodiments of the present disclosure are able to provide flexible and secure key provisioning and configuration of a secure PLD across a customer order of secure PLDs. A protected configuration of one customer cannot be used to program another customer personalized secure PLD or a blank secure PLD. Protected configurations may be programmed in-system or using an external device. Application keys may be decrypted only within a secure PLD. A customer may employ a key manifest to prevent device and/or application spoofing or over building. In various embodiments, programming keys and manifests are managed by one or more HSMs 526 of secure PLD manufacturer 520 and/or secure PLD customer 510.
To help reduce or eliminate risk of loss or extraction of a customer's or a manufacturer's PLD fabric configurations/images, keys, and/or other secured data from a locked or unlocked secure PLD 410, or reprogramming of such data, secure PLD 410 may implement one or more lock policy management methodologies according to a lock policy plan and/or other secure asset arrangement, for example, that may be used by PLD fabric 400, configuration engine 440, and/or other elements of secure PLD 410 to manage read, write, and/or erase access and enforce lock statuses with respect to assets of secure PLD 410. In the most general sense, secure PLD 410 may be configured to assign lock statuses to various assets of secure PLD 410, such as ports of configuration I/O 448 and/or sectors of NVM 450, and/or to groups of such assets, to protect locked and/or unlocked operation of secure PLD 410, as described herein. For example, access to such assets may be locked against external access (e.g., via configuration I/O 448), internal access (e.g., via PLD fabric 400), both external and internal access, and/or locked against any further access regardless of access type. Such access may be controlled granularly, such as providing read, write, and/or erase access per asset associated with NVM 450, for example, or read and/or write access (e.g., data communication access) across configuration I/O 448. Lock statuses associated with assets or groups of assets may be implemented by lock status bits configured to manage, store, or represent the read, write, and/or erase access according to a particular lock policy plan or arrangement, for example, which can be modified to provide a particular desired granularity of secure asset management for secure PLD 410.
For example, in the embodiment shown in
Each lock status may be implemented by one or more registers within shadow registers 860 of configuration engine 440, for example, that are configured to shadow corresponding lock statuses stored within lock policy sector 460 of NVM 450. In various embodiments, upon power up of secure PLD 410, configuration engine 440 may be configured to access lock policy 460, retrieve the various lock statuses from lock policy 460, and shadow the lock statuses within shadow registers 860 and according to lock policy plan 802 to allow the various lock statuses to be accessed and/or modified dynamically by configuration engine 440 and/or PLD fabric 400, depending on the settings/lock statuses in lock policy sector 460. In particular, configuration I/O lock status 848 may be configured to store or represent or indicate the read and/or write access status or statuses corresponding to one or more ports of configuration I/O 448 (e.g., JTAG, SSPI, I2C, and/or other ports or protocols supported by configuration I/O 448), which can be used to lock or unlock the individual ports to receive and/or provide data across configuration I/O 448 and/or external access bus 443. Lock policy lock status 861 may be configured to store or represent or indicate the read, write, and/or erase access status corresponding to lock policy sector 460 (e.g., which can act to lock or unlock access to all lock statuses stored in lock policy sector 460, such as a super group lock status). UFM 462 may include multiple individual and/or differentiated sectors or subsectors, for example, and so UFM lock status 862 may be configured to provide granular local lock statuses for each sector or subsector of UFM 462, and user security lock status 841 may be configured to provide a group lock status for user data lock status group 894, as described herein.
Read, write, and/or erase access and/or other lock statuses may be configured to provide interrelated access to sectors of NVM 450 to help provide secure access to such assets without risk of leakage of data within such assets. For example, a lock status bit may allow a sector of NVM 450 to be (1) erased but not read or written, (2) written or erased but not read, (3) read but not written or erased, or (4) neither read, written, nor erased, for example, or various combinations of these. For example, a particular lock status may allow a public or private key or an encryption key to be written but not read, or a configuration image sector to be erased but not read or updated and/or erased but not read, to help ensure customer and/or manufacturer data security and integrity. Each of these types of accesses may be set and/or controlled differently relative to or against external or internal access, as described herein.
Access table 904 of
Access table 906 of
As can be seen in access table 906, when the external soft lock is enabled (e.g., fabric WB bit is disabled), external access over configuration I/O 448/external bus 443 may be allowed or disallowed by setting one or more group and/or local lock status bits in configuration image lock statuses 852 and 854 and/or configuration security lock status 840, and PLD fabric 400 has free and open access to configuration image sectors 452 and 454. When the general soft lock is enabled (e.g., fabric WB bit is enabled), external access over configuration I/O 448/external bus 443, and internal access by PLD fabric 400, may be allowed or disallowed by setting one or more group and/or local lock status bits in configuration image lock statuses 852 and 854 and/or configuration security lock status 840, as shown. As with access tables 902 and 904, once hard lock for configuration image lock statuses 852 and 854 and configuration security lock status 840 is enabled, no further modification of the hard lock bit is allowed over configuration I/O 448/external bus 443 or by PLD fabric 400, and the status of the fabric WB bit no longer results in changes in lock statuses of configuration image sectors 452 and 454.
Access table 908 of
For example, in one embodiment, PLD fabric 400 may be configured to receive a new configuration image over programmable I/O 404, decrypt and/or authenticate the new configuration image using a device key stored in device keys sector 458, and store the new configuration image in one of configuration image sectors 452 or 454 (and setting the authentication bit to indicate the stored new configuration image is bootable without necessitating another authentication process) and/or boot the new configuration image. Upon booting the new configuration image, PLD fabric 400 may be configured to set device keys lock status 858 to allow write and/or erase access to device keys sector 458 and/or UFM sector 462, to download new keys through a secure channel (e.g., established by PLD fabric 400 over programmable I/O 404), to write the new keys to UFM sector 462, to erase device keys sector 458, to copy the new keys from UFM sector 462 into device keys sector 458, to download an additional configuration image for PLD fabric 400, to decrypt and/or authenticate the additional new configuration image using the new keys, and to store the additional new configuration image in one of configuration image sectors 452 or 454 (and including setting the authentication bit to indicate the stored additional new configuration image is bootable without necessitating another authentication process) and/or boot the new configuration image. Such process allows embodiments to update keys and configuration images securely as part of a single or unified methodology.
In another embodiment, one “golden” configuration image for PLD fabric 400 may be stored permanently in configuration image sector 452 (e.g., as a known-good backup configuration for PLD fabric 400, with the corresponding hard lock enabled in configuration image lock status 852), and an updateable configuration image for PLD fabric 400 may be stored in configuration image sector 452 (e.g., with the corresponding hard lock disabled in configuration image lock status 854). For example, configuration image lock status 852 may be hard locked according to policy 9 in
In a further embodiment, both configuration image sector 452 and configuration image sector 454 can be updated with new configuration images provided by external system 130. For example, PLD fabric 400 may be configured to determine one configuration image sector to lock against external access (e.g., a most recent authenticated configuration image) and one configuration image sector to unlock for external access (e.g., a less recent and/or unauthenticated configuration image), for example, or external system 130 may be configured to provide selection criteria along with an unlock request to PLD fabric 400, all of which may be validated and/or authenticated by PLD fabric 400 before being acted upon. PLD fabric 400 may then allow update of the determine/selected configuration sector with an updated configuration image, authenticate the updated configuration image, and/or boot the authenticated updated configuration image. PLD fabric 400 may receive a lock request and proceed to hard or soft lock the appropriate configuration image sector against further external and/or internal read, write, and/or erase access after storage and authentication of the updated configuration image. In various embodiments, other lock statuses may be requested and/or selected for any of configuration image sectors 452 and 454, for example, and such selection may be sourced externally or internally relative to secure PLD 410.
In a further embodiment, secure PLD 410 may be implemented according to a lock policy plan designed to prevent in-transit attacks seeking to extraction or manipulation of data stored in NVM 450. For example, configuration image sectors 452 and 454 may both be locked against all external access but be configured to allow internal access, generally according to policy 3 as shown in
In optional block 1010, a logic device receives an asset unlock request. For example, configuration engine 440 of a locked and/or programmed secure PLD 410 may be configured to receive a secure PLD asset unlock request issued by an external system 130 of secure PLD customer 510 or secure PLD manufacturer 520 coupled to secure PLD 410 over configuration I/O 448, for example, or issued by PLD fabric 400 running a customer or manufacturer configuration programmed into secure PLD 410 (e.g., using a process similar to that described with respect to process 700 of
In various embodiments, such secure PLD asset unlock request may be signed, encrypted, and/or include additional information so as to enable secure PLD 410 to authenticate the secure PLD asset unlock request. In a specific embodiment, such secure PLD asset unlock request may include the trace ID of the specific secure PLD 410 being characterized (e.g., extracted from a locked PLD manifest provided by secure PLD manufacturer 520), and an external system 130 and/or HSM 526 of secure PLD customer 510 may be configured to sign such secure PLD asset unlock request using its application private key or a different private key, as described herein.
In some embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to authenticate the secure PLD asset unlock request received in block 1010. In one embodiment, secure PLD 410 may be configured to authenticate a secure PLD asset unlock request signed by an application or other private key using an application or other public key stored in NVM 450 during a locking, programming, or other provisioning step in a provisioning process, as described herein. In another embodiment, secure PLD 410 may be configured to authenticate such secure PLD asset unlock request by comparing a secure PLD asset unlock request trace ID in the secure PLD asset unlock request with a trace ID stored in MFG trim sector 456 and/or other sector of NVM 450 or with device ID 422 of security engine 420, such that a matching trace ID in the secure PLD asset unlock request indicates an authenticated secure PLD asset unlock request. In further embodiments, such authentication process may include decrypting the secure PLD asset unlock request using a public key stored in NVM 450, as described herein.
In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to unlock the secure PLD asset corresponding to the secure PLD asset unlock request after the secure PLD asset unlock request is received and/or authenticated. For example, configuration engine 440 and/or PLD fabric 400 may be configured to unlock the secure PLD asset by adjusting or updating a lock status in shadow registers 860 of configuration engine 440, which may then be stored in lock policy 460 of NVM 450, depending on the contents of corresponding lock policy lock status 861.
In block 1020, a logic device receives an asset access request. For example, configuration engine 440 and/or PLD fabric 400 of a locked and/or programmed secure PLD 410 may be configured to receive a secure PLD asset access request issued by an external system 130 of secure PLD customer 510 or secure PLD manufacturer 520 coupled to secure PLD 410 over configuration I/O 448, for example, or issued by PLD fabric 400 running a customer or manufacturer configuration programmed into secure PLD 410. In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to authenticate such secure PLD asset access request prior to proceeding to block 1030.
In block 1030, a logic device performs an asset update process. For example, configuration engine 440 and/or PLD fabric 400 of a locked and/or programmed secure PLD 410 may be configured to perform a secure PLD asset update process corresponding to the secure PLD asset access request received in block 1020 and/or the secure PLD asset unlock request received in block 1010. In various embodiments, the performing the secure PLD asset update process may be based, at least in part, on a lock status associated with a secure PLD asset (e.g., one or more ports of configuration I/O 448 and/or sectors of NVM 450) corresponding to the secure PLD asset access request received in block 1020 and/or the secure PLD asset unlock request received in block 1010.
In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to update one or more configuration images stored in configuration image sectors 452 and 454, for example, and/or UFM sector 462. In one embodiment, configuration engine 440 and/or PLD fabric 400 may be configured to receive a new configuration image over configuration I/O 448 (e.g., through configuration engine 440) and/or programmable I/O 404, to decrypt and/or authenticate the new configuration image using a device key stored in device keys sector 458, to determine a lock status associated with one of configuration image sectors 452 or 454 includes a write enable and/or an erase enable lock status, and to store the new configuration image in one of configuration image sectors 452 or 454 (e.g., while setting an authentication bit to indicate the stored new configuration image is bootable without necessitating an additional authentication process) and/or to boot the new configuration image.
Upon booting the new configuration image, PLD fabric 400 may be configured to set or update device keys lock status 858 to allow write and/or erase access to device keys sector 458 and/or UFM sector 462, to download/receive new keys through a secure channel (e.g., established by PLD fabric 400 over programmable I/O 404), to write the new keys to UFM sector 462, to erase device keys sector 458, to copy the new keys from UFM sector 462 into device keys sector 458, to download an additional configuration image for PLD fabric 400, to decrypt and/or authenticate the additional new configuration image using the new keys, and to store the additional new configuration image in one of configuration image sectors 452 or 454 (and including setting the authentication bit to indicate the stored additional new configuration image is bootable without necessitating another authentication process) and/or boot the new configuration image. In various embodiments, device keys lock status 858 may be updated to include a write disable and/or an erase disable lock status as against configuration I/O 448 and/or PLD fabric 400. Such process allows embodiments to update keys and configuration images securely as part of a single or unified methodology.
In another embodiment, configuration engine 440 and/or PLD fabric 400 may be configured to receive, validate, and/or authenticate an unlock request for a particular configuration image sector, and to unlock the particular configuration image sector for programming by external system 130 and/or by PLD fabric 400 according to an updated configuration image provided by external system 130. Configuration engine 440 and/or PLD fabric 400 may also be configured to receive a lock request (e.g., identifying the updated configuration image stored in configuration image sector 454) from external system 130 over configuration I/O 448 and through configuration engine 440, and configuration engine 440 and/or PLD fabric 400 may be configured to receive, validate, and/or authenticate the lock request, and to hard or soft lock configuration image sector 454 against further external access, as described herein.
In various embodiments, other securable assets of secure PLD 410 may be securely updated using similar techniques. For example, configuration engine 440 and/or PLD fabric 400 of secure PLD 410 may be configured to receive an updated MFG trim, trace ID, device keys, an IPI, and/or other data (e.g., issued/generated by an external system 130 and/or HSM 526 of secure PLD customer 510 or secure PLD manufacturer 520 coupled to secure PLD 410 over configuration I/O 448, for example, or over programmable I/O 404) configured to re-provision secure PLD 410 and/or place secure PLD 410 in condition to be re-provisioned using a process similar to provisioning process 700 of
In optional block 1040, a logic device receives an asset lock request. For example, configuration engine 440 and/or PLD fabric 400 of a secure PLD 410 may be configured to receive a secure PLD asset lock request issued by an external system 130 of secure PLD customer 510 or secure PLD manufacturer 520 coupled to secure PLD 410 over configuration I/O 448, for example, or issued by PLD fabric 400 running a customer configuration programmed into secure PLD 410. In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to authenticate such secure PLD asset lock request prior to locking the asset according to a lock status included in the secure PLD asset lock request. For example, configuration engine 440 and/or PLD fabric 400 may be configured to lock the secure PLD asset by adjusting or updating a lock status in shadow registers 860 of configuration engine 440, which may then be stored in lock policy 460 of NVM 450, depending on the contents of corresponding lock policy lock status 861, as described herein.
In general, various blocks of process 1000 may be performed entirely by or within secure PLD customer 510, secure PLD manufacturer 510, and/or other elements of secure PLD provisioning system 500 and/or 502. In a specific embodiment, block 1030 may be performed by downstream customer 550 to update various elements of NVM 450 in-situ, such as while integrated with user device 610. More generally, block 1030 may be performed by secure PLD customer 510, secure PLD manufacturer 520, secure PLD programmer 530, user device assembler 540, and/or downstream customer 550 at any time during the operational lifetime of secure PLD 410 and/or user device 610.
Thus, by employing the systems and methods described herein, embodiments of the present disclosure are able to provide flexible and secure asset management for a secure PLD. A customer locked and/or otherwise provisioned secure PLD may be securely erased and/or updated without risking exposure of customer data. Moreover, the secure PLD may be securely re-provisioned according to updated customer data, for example, or according to a new customer application, without requiring the secure PLD be orphaned or otherwise destroyed.
To further reduce or eliminate risk of loss or extraction of a customer's or a manufacturer's PLD fabric configurations/images, keys, and/or other secured data from a locked or unlocked secure PLD 410, or reprogramming of such data, secure PLD 410 may implement one or more tamper detection methodologies that leverage a lock policy plan and/or other secure asset arrangement, for example, (e.g., used by PLD fabric 400, configuration engine 440, security engine 420, and/or other elements of secure PLD 410) to detect a variety of different types of attempts to tamper with operation of secure PLD 410 and/or access assets of secure PLD 410 without proper authentication, such as through brute force dictionary and/or fuzzing/pseudorandom input type attacks attempted on various externally accessible ports of secure PLD 410, including configuration I/O 448, programmable I/O 404, and/or other communication or configuration ports of secure PLD 410. Secure PLD 410 may then automatically lock the appropriate assets associated with the detected asset tamper attempt dynamically via management and enforcement of read, write, and/or erase access and lock statuses with respect to assets of secure PLD 410, as described herein at least with respect to
By implementing such tamper detection management (e.g., detection and defense), embodiments are able to block adversaries from attempting to search or exploit hardware or configuration weaknesses in secure PLD 410 and/or a user device including one or more secure PLDs 410. For example, various elements of secure PLD 410 may include critical information/data, such as dual boot images, ECDSA keys, AES keys, and user data, and each asset or portion of the asset may be subject to various types of configurable protections (e.g., read, write, erase). If access to an asset is attempted with an illegal operation, secure PLD 410 may flag the attempt by generating a tamper detection assertion, set an appropriate tamper detection status, and implement an appropriate tamper defense (e.g., by locking the asset and/or access to the asset via one or more buses or ports of secure PLD 410).
In the most general sense, secure PLD 410 may be configured to detect an asset tamper attempt, such as an attempt to access a securable asset or group of assets without proper authentication (e.g., ports of configuration I/O 448 and/or sectors of NVM 450), to lock an asset associated with the detected asset tamper attempt (e.g., the asset itself or ports used to access the asset, via a lock policy plan and/or process similar to those described with reference to
Secure PLD 410 may be configured to manage tamper detection associated with secure PLD 410 by assigning tamper detection statuses to various assets of secure PLD 410, such as ports of configuration I/O 448 and/or sectors of NVM 450, and/or to groups of such assets, and then locking and/or unlocking such assets based, at least in part, on such tamper detection statuses, as described herein. Such tamper detection statuses may be controlled granularly, so as to indicate tamper type and tamper source, such as unauthorized read, write, and/or erase access attempts associated with NVM 450, for example, or unauthorized read and/or write access (e.g., data communication access) across configuration I/O 448, programmable I/O 404, and/or other buses shown in
Secure PLD 410 may be configured to lock and unlock assets associated with a detected asset tamper attempt by assigning lock statuses to various assets of secure PLD 410, as is described herein with reference to
In the embodiment depicted in
As shown in
In some embodiments, tamper detection status register 1164 may be implemented within shadow registers 860 of configuration engine 440, for example, that are configured to shadow corresponding tamper detection statuses stored within tamper detection policy sector 1160 of NVM 450. Upon power up of secure PLD 410, configuration engine 440 may be configured to access tamper detection policy sector 1160, retrieve the various tamper detection statuses from tamper detection policy sector 1160, and shadow the tamper detection statuses within tamper detection status register 1164 of shadow registers 860 and according to tamper detection policy plan 1102 to allow the various tamper detection statuses to be accessed and/or modified dynamically by configuration engine 440 and/or PLD fabric 400. In other embodiments, tamper detection status register 1164 may be implemented within configuration engine 440 (e.g., via non-volatile registers of configuration engine 440) and secure PLD 410 may omit a separate and shadowed tamper detection policy sector 1160.
In various embodiments, tamper detection status register 1164 may be configured to store or represent or indicate an unauthorized read, write, and/or erase access attempt of a particular asset of secure PLD 410 (e.g., both the asset and the type of access constituting a detected tamper attempt), such as one or more ports of configuration I/O 448 (e.g., JTAG, SSPI, I2C, and/or other ports or protocols supported by configuration I/O 448), one or more ports of programmable I/O 404, one or more sectors of NVM 450, one or more lock statuses of shadow registers 860, one or more secure buses of secure PLD 410, and/or one or more security functions and/or other elements of security engine 420.
For example, in some embodiments, configuration engine 440 may be configured to detect a particular asset tamper attempt on an asset of secure PLD 410, generate and provide a tamper detection interrupt assertion (e.g., an improper configuration command assertion) to PLD fabric 400 via tamper detection interrupt bus 1108, and/or set tamper detection status register 1164 to indicate the type of detected asset tamper attempt and the corresponding targeted asset. In other embodiments, PLD fabric 400 may be configured to detect a particular asset tamper attempt on an asset of secure PLD 410, generate and provide a tamper detection interrupt assertion (e.g., a configuration port lock assertion) to configuration engine 440 via tamper detection interrupt bus 1108, and/or set tamper detection status register 1164 to indicate the type of detected asset tamper attempt and the corresponding targeted asset. PLD fabric 400 and/or configuration engine 440 may be configured to read tamper detection status register 1164 (e.g., which may clear the tamper detection interrupt assertion on tamper detection interrupt bus 1108) and lock an asset of secure PLD 410 associated with the detected asset tamper attempt, such as the asset itself or a communication bus or port used to access the asset.
When locking an asset, read, write, and/or erase access and/or other lock statuses may be configured to provide interrelated access to sectors of NVM 450 to help provide secure access to such assets without risk of leakage of data within such assets. For example, a lock status bit may allow a sector of NVM 450 to be (1) erased but not read or written, (2) written or erased but not read, (3) read but not written or erased, or (4) neither read, written, nor erased, for example, or various combinations of these. For example, a particular lock status may allow a public or private key or an encryption key to be written but not read, or a configuration image sector to be erased but not read or updated and/or erased but not read, to help ensure customer and/or manufacturer data security and integrity. Each of these types of accesses may also be set and/or controlled differently relative to or against external or internal access, as described herein.
In block 1210, a logic device detects an asset tamper attempt. For example, configuration engine 440 and/or PLD fabric 400 (e.g., of a locked and/or programmed secure PLD 410) may be configured to detect an asset tamper attempt on a targeted asset of secure PLD 410. In some embodiments, configuration engine 440 may be configured to detect an asset tamper attempt including improper commands provided to configuration engine 440 (e.g., the targeted asset) via configuration I/O 448 and/or other buses of secure PLD 410. Such improper commands may include illegal or reserved configuration commands, for example, such as an unauthenticated command attempting to access a locked asset (e.g., including SRAM readback) (e.g., via violation of security clearances, including a failed password authentication or clearance) such as an unauthenticated asset access request, an unauthenticated command attempting to enter a manufacturer mode or load a configuration for secure PLD 410, an unauthenticated command attempting to assert one or more manufacturer commands, an unauthenticated command attempting to access an illegal memory address (e.g., via a read, write, or erase command to a locked sector and/or targeting an out of bound memory address), any undefined command (e.g., from a command decoder implemented by configuration engine 440), and/or other improper commands (e.g., which may be listed or otherwise defined within tamper detection policy sector 1160, for example). In particular, such illegal or reserved configuration commands may also include various JTAG-related commands and protocols, including attempting to provide a programming instruction while JTAG boundary scanning (BSCAN) is permitted but programming (via the JTAG bus or port) is blocked, or attempting to provide a programming instruction while programming is permitted but JTAG BSCAN is blocked. In other embodiments, PLD fabric 400 may be configured to detect any of such improper commands, as relayed by configuration engine 440 and/or detected as provided to programmable I/O 404 and/or other buses of secure PLD 410. More generally, any element of secure PLD 410 may be configured to detect such improper commands provided to any other element of secure PLD 410.
In various embodiments, upon detection of any type of asset tamper attempt against any asset of secure PLD 410, configuration engine 440 and/or PLD fabric 400 may be configured to generate a tamper detection interrupt assertion associated with the asset tamper attempt, provide the tamper detection interrupt assertion to other elements of secure PLD 410, and/or set tamper detection status register 1164 to indicate a targeted asset and a type of asset tamper (e.g., read, write, erase) corresponding to the detected asset tamper attempt. For example, where configuration engine 440 detects the asset tamper attempt, configuration engine 440 may be configured to generate a tamper detection interrupt assertion including an improper configuration command assertion and provide it to PLD fabric 400 via tamper detection interrupt bus 1108 and/or secure bus 408. Configuration engine 440 may then set tamper detection status register 1164 accordingly. Where PLD fabric 400 detects the asset tamper attempt, PLD fabric 400 may be configured generate a tamper detection interrupt assertion including a configuration port lock assertion and provide it to configuration engine 440 via tamper detection interrupt bus 1108 and/or secure bus 408. PLD fabric 400 may then set tamper detection status register 1164 accordingly via a tamper detection status set command provided to configuration engine 440 via secure bus 408.
In additional embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to detect an asset tamper attempt including a physical anomaly, such as an anomalous voltage bias, fluctuation, or fluctuation pattern detected on one or more communication buses of secure PLD 410 during operation of secure PLD 410 (e.g., associated with a bus probe or other physical intrusion), for example, or a temperature excursion, fluctuation, or fluctuation pattern detected within secure PLD 410 and/or one of the elements of secure PLD 410 during operation of secure PLD 410 (e.g., associated with an attempted disassembly or other physical intrusion), which may be detected by corresponding physical anomaly sensors (e.g., a voltage and/or temperature sensor implemented by other IC modules 480).
In block 1220, a logic device locks an asset associated with an asset tamper attempt. For example, configuration engine 440 and/or PLD fabric 400 (e.g., of a locked and/or programmed secure PLD 410) may be configured to lock a secure PLD asset associated with the asset tamper attempt detected in block 1210. In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to lock the secure PLD asset by adjusting or updating a lock status in shadow registers 860 of configuration engine 440, which may then be stored in lock policy 460 of NVM 450, depending on the contents of corresponding lock policy lock status 861.
In some embodiments, configuration engine 440 may be configured to receive a tamper detection interrupt assertion including a configuration port lock assertion generated by PLD fabric 400 in block 1210, to read tamper detection status register 1164, and/or to lock all external configuration port access (e.g., JTAG, I2C, SPI, MSPI) to configuration engine 440 (e.g., lock configuration I/O 448 and/or bus 443, for example, or other buses of secure PLD 410) using a process similar to that described with reference to
In other embodiments, PLD fabric 400 may be configured to receive a tamper detection interrupt assertion including an improper configuration command assertion generated by configuration engine 440 in block 1210, to read tamper detection status register 1164, and/or to lock one or more individual secure PLD assets (e.g., including individual configuration port access) according to the assets and/or tamper types identified within tamper detection status register 1164, via control commands provided to configuration engine 440. In further embodiments, PLD fabric 400 may be configured to receive a first tamper detection interrupt assertion including an improper configuration command assertion generated by configuration engine 440 in block 1210 and to generate a second tamper detection interrupt assertion including a configuration port lock assertion that is then provided back to configuration engine 440. In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to discontinue the tamper detection interrupt assertion upon reading tamper detection status register 1164.
In optional block 1230, a logic device reports an asset tamper attempt. For example, configuration engine 440 and/or PLD fabric 400 (e.g., of a locked and/or programmed secure PLD 410) may be configured to provide an asset tamper attempt report of the asset tamper attempt detected in block 1210 to any one of secure PLD customer 510, secure PLD manufacturer 520, secure PLD programmer 530, user device assembler 540, and/or downstream customer 550 via communications network 514 of
In block 1240, a logic device unlocks an asset associated with an asset tamper attempt. For example, configuration engine 440 and/or PLD fabric 400 (e.g., of a locked and/or programmed secure PLD 410) may be configured to unlock the secure PLD asset associated with the asset tamper attempt detected in block 1210 and locked in block 1220. In various embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to unlock the secure PLD asset by adjusting or updating a lock status in shadow registers 860 of configuration engine 440, which may then be stored in lock policy 460 of NVM 450, depending on the contents of corresponding lock policy lock status 861.
In some embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to detect the asset tamper attempt detected in block 1210 has ceased before resuming an operational state of secure PLD 410 prior to block 1210 (e.g., before the asset tamper attempt was detected). For example, configuration engine 440 and/or PLD fabric 400 may be configured to unlock the asset locked in block 1220 (e.g., in the case of locked communication ports, secure PLD 410 typically must unlock a communication port before being able to detect tamper activity on the communication port), monitor secure PLD 410 for an updated asset tamper attempt status (e.g., for the same or a different asset tamper attempt type targeting the same asset or a different asset), and selectively resume a prior operational state of secure PLD 410 based on the updated asset tamper attempt status. Configuration engine 440 and/or PLD fabric 400 may be configured to wait a preselected tamper delay time period (e.g., stored within tamper detection policy sector 1160) after locking the asset, as in block 1220, and before attempting to detect the asset tamper attempt in block 1210 has ceased, for example, or to wait such preselected tamper delay time period repeatedly as the asset tamper attempt detected in block 1210 continues and/or a different asset tamper attempt is detected in block 1240.
In other embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to unlock the secure PLD asset associated with the asset tamper attempt detected in block 1210 and locked in block 1220 after first detecting authenticated access to an asset of secure PLD 410. For example, configuration engine 440 and/or PLD fabric 400 may be configured to detect an asset tamper recovery command provided to configuration engine 440 via configuration I/O 448 and/or other buses of secure PLD 410. Such asset tamper recovery command may include various legal configuration commands, for example, such as a command attempting to access a locked asset with authentication (e.g., via an authenticated security clearance, including a successful password authentication or clearance) such as an authenticated asset access request, an authenticated command attempting to enter a manufacturer mode or configuration for secure PLD 410, an authenticated command attempting to assert one or more manufacturer commands, and/or other authorized commands (e.g., which may be listed or otherwise defined within tamper detection policy sector 1160, for example).
In further embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to receive an asset unlock request and/or a new configuration/boot image (e.g., designed to mitigate the detected asset tamper attempt) from any one of secure PLD customer 510, secure PLD manufacturer 520, secure PLD programmer 530, user device assembler 540, and/or downstream customer 550 via communications network 514 of
In some embodiments, configuration engine 440 and/or PLD fabric 400 may be configured to authenticate the secure PLD asset unlock request and/or new configuration image. In one embodiment, secure PLD 410 may be configured to authenticate a secure PLD asset unlock request signed by an application or other private key using an application or other public key stored in NVM 450 during a locking, programming, or other provisioning step in a provisioning process, as described herein. In another embodiment, secure PLD 410 may be configured to authenticate such secure PLD asset unlock request and/or new configuration image by comparing a secure PLD asset unlock request and/or new configuration image trace ID in the secure PLD asset unlock request and/or new configuration image with a trace ID stored in MFG trim sector 456 and/or other sector of NVM 450 or with device ID 422 of security engine 420, such that a matching trace ID in the secure PLD asset unlock request and/or new configuration image indicates an authenticated secure PLD asset unlock request and/or new configuration image. In further embodiments, such authentication process may include decrypting the secure PLD asset unlock request and/or new configuration image using a public key stored in NVM 450, as described herein.
Thus, by employing the systems and methods described herein, embodiments of the present disclosure are able to provide flexible and secure asset tamper detection management for a secure PLD. A customer locked and/or otherwise provisioned secure PLD may be monitored for external tampering attempts and securely locked, erased, and/or updated without risking exposure of customer data. Moreover, the secure PLD may be securely unlocked, re-provisioned according to updated customer data or according to a new customer application, and/or otherwise put back into operation after an asset tamper attempt has ceased, without requiring the secure PLD be orphaned or otherwise destroyed.
Where applicable, various embodiments provided by the present disclosure can be implemented using hardware, software, or combinations of hardware and software. Also where applicable, the various hardware components and/or software components set forth herein can be combined into composite components comprising software, hardware, and/or both without departing from the spirit of the present disclosure. Where applicable, the various hardware components and/or software components set forth herein can be separated into sub-components comprising software, hardware, or both without departing from the spirit of the present disclosure. In addition, where applicable, it is contemplated that software components can be implemented as hardware components, and vice-versa.
Software in accordance with the present disclosure, such as non-transitory instructions, program code, and/or data, can be stored on one or more non-transitory machine-readable mediums. It is also contemplated that software identified herein can be implemented using one or more general purpose or specific purpose computers and/or computer systems, networked and/or otherwise. Where applicable, the ordering of various steps described herein can be changed, combined into composite steps, and/or separated into sub-steps to provide features described herein.
Embodiments described above illustrate but do not limit the invention. It should also be understood that numerous modifications and variations are possible in accordance with the principles of the present invention. Accordingly, the scope of the invention is defined only by the following claims.
This application is a continuation-in-part of U.S. patent application Ser. No. 17/093,572 filed Nov. 9, 2020 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. U.S. patent application Ser. No. 17/093,572 is a continuation of International Patent Application No. PCT/US2019/031875 filed May 10, 2019 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. International Patent Application No. PCT/US2019/031875 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/846,365 filed May 10, 2019 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031875 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,021 filed Nov. 5, 2018 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031875 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,001 filed Nov. 5, 2018 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031875 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,015 filed Nov. 5, 2018 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031875 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/670,487 filed May 11, 2018 and entitled “DEVICES WITH PROGRAMMABLE LOGIC AND SECURITY FEATURES AND METHODS OF USING,” which is hereby incorporated by reference in its entirety. This application is a continuation-in-part of U.S. patent application Ser. No. 17/093,576 filed Nov. 9, 2020 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. U.S. patent application Ser. No. 17/093,576 is a continuation of International Patent Application No. PCT/US2019/031883 filed May 10, 2019 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. International Patent Application No. PCT/US2019/031883 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/846,365 filed May 10, 2019 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031883 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,021 filed Nov. 5, 2018 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031883 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,001 filed Nov. 5, 2018 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031883 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,015 filed Nov. 5, 2018 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031883 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/670,487 filed May 11, 2018 and entitled “DEVICES WITH PROGRAMMABLE LOGIC AND SECURITY FEATURES AND METHODS OF USING,” which is hereby incorporated by reference in its entirety. This application is a continuation-in-part of U.S. patent application Ser. No. 17/093,578 filed Nov. 9, 2020 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR ERASING AND DEBUGGING PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. U.S. patent application Ser. No. 17/093,578 is a continuation of International Patent Application No. PCT/US2019/031881 filed May 10, 2019 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. International Patent Application No. PCT/US2019/031881 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/846,365 filed May 10, 2019 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031881 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,021 filed Nov. 5, 2018 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031881 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,001 filed Nov. 5, 2018 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031881 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,015 filed Nov. 5, 2018 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031881 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/670,487 filed May 11, 2018 and entitled “DEVICES WITH PROGRAMMABLE LOGIC AND SECURITY FEATURES AND METHODS OF USING,” which is hereby incorporated by reference in its entirety. This application is a continuation-in-part of U.S. patent application Ser. No. 17/093,582 filed Nov. 9, 2020 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. U.S. patent application Ser. No. 17/093,582 is a continuation of International Patent Application No. PCT/US2019/031886 filed May 10, 2019 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is incorporated herein by reference in its entirety. International Patent Application No. PCT/US2019/031886 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/846,365 filed May 10, 2019 and entitled “SECURE BOOT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031886 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,021 filed Nov. 5, 2018 and entitled “ASSET MANAGEMENT SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031886 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,001 filed Nov. 5, 2018 and entitled “KEY PROVISIONING SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031886 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/756,015 filed Nov. 5, 2018 and entitled “FAILURE CHARACTERIZATION SYSTEMS AND METHODS FOR PROGRAMMABLE LOGIC DEVICES,” which is hereby incorporated by reference in its entirety. International Patent Application No. PCT/US2019/031886 filed May 10, 2019 claims priority to and the benefit of U.S. Provisional Patent Application No. 62/670,487 filed May 11, 2018 and entitled “DEVICES WITH PROGRAMMABLE LOGIC AND SECURITY FEATURES AND METHODS OF USING,” which is hereby incorporated by reference in its entirety.
Number | Date | Country | |
---|---|---|---|
62846365 | May 2019 | US | |
62756021 | Nov 2018 | US | |
62756001 | Nov 2018 | US | |
62756015 | Nov 2018 | US | |
62670487 | May 2018 | US | |
62846365 | May 2019 | US | |
62756021 | Nov 2018 | US | |
62756001 | Nov 2018 | US | |
62756015 | Nov 2018 | US | |
62670487 | May 2018 | US | |
62846365 | May 2019 | US | |
62756021 | Nov 2018 | US | |
62756001 | Nov 2018 | US | |
62756015 | Nov 2018 | US | |
62670487 | May 2018 | US | |
62846365 | May 2019 | US | |
62756021 | Nov 2018 | US | |
62756001 | Nov 2018 | US | |
62756015 | Nov 2018 | US | |
62670487 | May 2018 | US |
Number | Date | Country | |
---|---|---|---|
Parent | PCT/US2019/031875 | May 2019 | WO |
Child | 17093572 | US | |
Parent | PCT/US2019/031883 | May 2019 | WO |
Child | 17093576 | US | |
Parent | PCT/US2019/031881 | May 2019 | WO |
Child | 17093578 | US | |
Parent | PCT/US2019/031886 | May 2019 | WO |
Child | 17093582 | US |
Number | Date | Country | |
---|---|---|---|
Parent | 17093572 | Nov 2020 | US |
Child | 18584894 | US | |
Parent | 17093576 | Nov 2020 | US |
Child | 18584894 | US | |
Parent | 17093578 | Nov 2020 | US |
Child | 18584894 | US | |
Parent | 17093582 | Nov 2020 | US |
Child | 18584894 | US |