IP Library Granted Patent US 10,720,927
Granted Patent B1
US 10,720,927 · App. 15/400,833 · Granted Jul 21, 2020

Selectively disabled output

Inventor: Laura Reese (Campbell, CA)
Assignee: Altera Corporation
H03K19/17768H03K19/1776
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,720,927
App. No.
15/400,833
Granted
Jul 21, 2020
Kind
B1
Abstract

Circuits, methods, and apparatus are directed to an integrated circuit having a disabling element that can disable a reading of data from the circuit. Once the disabling element is set to not allow a reading of the data, the disabling element cannot be changed to allow a reading of the data. The data may be configuration data or internal data stored within the integrated circuit. Examples of the disabling element include a memory element, a break in a circuit line, and an input pad configuration.

Claims (58)

1. A programmable logic device, comprising:

a first logic block, wherein operation of the first logic block is programmable based at least in part on configuration data stored in configuration memory disposed on the programmable logic device;

a decoder communicatively coupled to the configuration memory, wherein the decoder:

receives encrypted data from a configuration device; and

determines the configuration data by decrypting the encrypted data using an encryption key;

a non-volatile memory communicatively coupled to the decoder, wherein the non-volatile memory is configured to store a plurality of bits using a plurality of fuses, and wherein each of the plurality of fuses is one-time programmable to store one bit of the encryption key;

an input pad configured to couple to a system high voltage or a system low voltage, wherein the configuration data cannot be read by a component of the programmable logic device from the configuration memory when the input pad is coupled to the system high voltage; and

a disabling fuse, wherein the programmable logic device selectably disables external access to the encryption key based at least in part on state of the disabling fuse.

2. The programmable logic device of claim 1 , wherein the programmable logic device:

provides an integrated circuit device external from the programmable logic device access to the plurality of fuses before the disabling fuse is switched to a blown state; and

blocks the integrated circuit device from accessing the encryption key from the programmable logic device after the disabling fuse is switched to the blown state.

3. The programmable logic device of claim 1 , wherein the programmable logic device disables reading the encryption key out from the programmable logic device to an external integrated circuit device when the disabling fuse is in a blown state.

4. The programmable logic device of claim 3 , wherein the programmable logic device disables reading the encryption key by blocking a read enable signal.

5. The programmable logic device of claim 1 , wherein the programmable logic device disables writing to the plurality of fuses when the disabling fuse is in a blown state.

6. The programmable logic device of claim 5 , wherein the programmable logic device disables writing to the plurality of fuses by blocking a write enable signal.

7. The programmable logic device of claim 1 , wherein:

the state of the disabling fuse is:

a first state when the disabling fuse is intact; and

a second state when the disabling fuse is blown; and

the programmable logic device:

enables external access to the plurality of fuses when the state of the disabling fuse is the first state; and

disables external access to the plurality of fuses when the state of the disabling fuse is the second state.

8. The programmable logic device of claim 1 , comprising a readout circuit communicatively coupled to the disabling fuse and an output port of the programmable logic device, wherein the readout circuit:

enables readout of the configuration data, internal data used in the programmable logic device, or both from the programmable logic device to an external integrated circuit device when the disabling fuse is in a first state; and

disables readout of the configuration data, the internal data, or both from the programmable logic device to the external integrated circuit device when the disabling fuse is in a second state.

9. The programmable logic device of claim 8 , wherein the internal data is indicative of an aspect of the programmable logic device intended to be kept secret.

10. The programmable logic device of claim 8 , comprising a second logic block that stores the internal data.

11. The programmable logic device of claim 1 , comprising a readout circuit communicatively coupled to the disabling fuse and an output port of the programmable logic device, wherein the readout circuit outputs data encrypted using the encryption key when the disabling fuse is in an intact state.

12. The programmable logic device of claim 1 , wherein the configuration device comprises a computer system, a digital system, a processing system, a digital signal processing system, or a digital switching network.

13. The programmable logic device of claim 1 , wherein each of the plurality of fuses is either left intact or blown to create a sequence that indicates the encryption key.

14. A configuration device comprising a memory unit that stores instructions executable by one or more processors to:

instruct a programmable logic device communicatively coupled to the configuration device to activate a one-time programmable fuse in the programmable logic device to disable external access to an encryption key stored in nonvolatile one-time programmable memory in the programmable logic device; and

communicate encrypted data from the configuration device to the programmable logic device to enable:

a decoder in the programmable logic device to determine configuration data by decrypting the encrypted data using the encryption key; and

the programmable logic device to configure functionality of one or more logic block in the programmable logic device based at least in part on the configuration data, wherein the configuration data is stored in configuration data memory disposed on the programmable logic device, and wherein an input pad configured to couple to a system high voltage or a system low voltage causes the configuration data to not be read by a component of the programmable logic device from the configuration memory when the input pad is coupled to the system high voltage.

15. The configuration device of claim 14 , wherein the memory unit stores instructions executable by the one or more processors to communicate the encryption key from the configuration device to the programmable logic device to enable the programmable logic device to store each bit of the encryption key in a corresponding one of a plurality of fuses.

16. The configuration device of claim 14 , wherein the memory unit stores instructions executable by the one or more processors to instruct the programmable logic device to activate the one-time programmable fuse after the encryption key is stored in the nonvolatile one-time programmable memory.

17. The configuration device of claim 14 , wherein the configuration device comprises a computer system, a digital system, a processing system, a digital signal processing system, or a digital switching network.

18. The configuration device of claim 14 , wherein:

the configuration device instructs the programmable logic device to activate the one-time programmable fuse by blowing the one-time programmable fuse;

the memory unit comprises random access memory, read only memory, a fixed disk medium, a flexible disk medium, flash memory, tape memory, or any combination thereof that stores a program comprising the instructions; and

the one or more processors comprises a central processing unit, a floating point coprocessor, a graphics coprocessor, a hardware controller, a microcontroller, another programmable logic device, or any combination thereof.

19. A method for operating a programmable logic device, comprising:

storing, in a non-volatile memory comprising a plurality of one-time programmable fuses, an encryption key to be used by a decoder in the programmable logic device to determine configuration data by decrypting encrypted data received from an external source, wherein the configuration data is used to program functionality of one or more logic blocks in the programmable logic device, wherein an input pad configured to couple to a system high voltage or a system low voltage causes the configuration data to not be read by a component of the programmable logic device from configuration memory disposed on the programmable logic device when the input pad is coupled to the system high voltage; and

activating a disabling fuse communicatively coupled to a readout circuit in the programmable logic device to disable access to the encryption key from the programmable logic device.

20. The method of claim 19 , wherein:

storing the encryption key in the plurality of one-time programmable fuses comprises:

storing a first bit of the encryption key in a first fuse by blowing the first fuse; and

storing a second bit of the encryption key in a second fuse by leaving the second fuse intact; and

activating the disabling fuse comprises blowing the disabling fuse.

21. A programmable logic device, comprising:

a first logic block, wherein operation of the first logic block is programmable based at least in part on configuration data stored in configuration memory disposed on the programmable logic device;

a decoder communicatively coupled to the configuration memory, wherein the decoder:

receives encrypted data from a configuration device; and

determines the configuration data by decrypting the encrypted data using an encryption key;

a non-volatile memory communicatively coupled to the decoder, wherein the non-volatile memory is one-time programmable and configured to store one or more bits of the encryption key;

an input pad configured to couple to a system high voltage or a system low voltage, wherein the configuration data cannot be read by a component of the programmable logic device from the configuration memory when the input pad is coupled to the system high voltage; and

a disabling fuse, wherein the programmable logic device selectably disables write access to the encryption key based at least in part on state of the disabling fuse.

Assignments (1)
SECURITY INTEREST Recorded Sep 12, 2025
From: ALTERA CORPORATION
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 073431/0309 →
Continuity (4)
Continuation 15184921 · Jun 16, 2016
Continuation 14089364 · Nov 25, 2013
Division 12332789 · Dec 11, 2008
Division 11435416 · May 16, 2006