SYSTEM SECURITY MANAGER
In another embodiment, a method for securing a field-programmable logic chip or circuit (FPLC) is disclosed. Information is cryptographically processed within the FPLC. An error condition is detected outside of the FPLC and the error condition is communicated to the FPLC to disrupt an image(s) within the FPLC. Optionally, at least a portion of a key can be erased such that cryptographic processing is curtailed or eliminated.
1 . A method for providing system security for a field-programmable logic chip (FPLC), the method comprising:
cryptographically processing information within the FPLC;
detecting an error condition, wherein the detection is performed external to the FPLC;
conveying into the FPLC the error condition; and
disrupting an image in the FPLC for one or more soft cores loaded when the error condition is detected where the image cannot perform cryptographic processing after disruption even if keys are present.
2 . The method as recited in claim 1 , wherein the key is used to program the image into the FPLC.
3 . The method as recited in claim 1 , wherein the conveying is performed by disrupting programming of the FPLC.
4 . The method as recited in claim 1 , further comprising erasing at least a portion of a key used for the cryptographic processing.
5 . The method as recited in claim 1 , wherein the key is broken into portions stored in at least two different memories.
6 . The method as recited in claim 1 , wherein the disrupting the image includes writing a different image into the FPLC over at least part of the image.
7 . The method as recited in claim 1 , wherein the disrupting the image is performed by sate machine.
8 . The method as recited in claim 1 , further comprising detecting the error condition using circuitry that is redundantly implemented.
9 . A cryptographic processing system for providing system security for a field-programmable logic chip (FPLC), the cryptographic processing system comprising:
a cryptographic soft core at least partially within the FPLC that cryptographically processes information;
a system security manager that detects an error condition, wherein:
the detection is performed external to the FPLC,
the cryptographic soft core in the FPLC is disrupted when the error condition is detected where the image, and
the cryptographic soft core cannot perform cryptographic processing after disruption even if keys are present.
10 . The cryptographic processing system as recited in claim 9 , wherein the key is used to program the cryptographic soft core into the FPLC.
11 . The cryptographic processing system as recited in claim 9 , wherein at least a portion of a key used for the cryptographic processing is disrupted after detecting the error condition
12 . The cryptographic processing system as recited in claim 9 , wherein the key is broken into portions stored in at least two different memories.
13 . The cryptographic processing system as recited in claim 9 , further comprising a security manager programmable logic image (PLI) internal to the FPLC.
14 . The cryptographic processing system as recited in claim 9 , wherein the disrupting the image includes writing a different image into the FPLC.
15 . The cryptographic processing system as recited in claim 9 , wherein the disrupting the image is performed by sate machine.
16 . The cryptographic processing system as recited in claim 9 , further comprising detecting the error condition using circuitry that is redundantly implemented.
17 . A cryptographic processing system for providing system security for a field-programmable logic chip (FPLC), the cryptographic processing system comprising:
means for cryptographically processing information within the FPLC;
means for detecting an error condition, wherein the detection is performed external to the FPLC;
means for disrupting an image in the FPLC for one or more soft cores loaded when the error condition is detected where the image cannot perform cryptographic processing after disruption even if keys are present.
18 . The cryptographic processing system as recited in claim 17 , wherein the key is used to program the image into the FPLC.
19 . The cryptographic processing system as recited in claim 17 , further comprising means for erasing at least a portion of a key used for the cryptographic processing.
20 . The cryptographic processing system as recited in claim 17 , wherein the key is broken into portions stored in at least two different memories.
21 . The cryptographic processing system as recited in claim 17 , wherein the disrupting the image includes means for writing a different image into the FPLC.
22 . The cryptographic processing system as recited in claim 17 , wherein the disrupting the image is performed by sate machine.
23 . The cryptographic processing system as recited in claim 17 , wherein the means for detecting the error condition uses circuitry that is redundantly implemented.