IP Library › Granted Patent US 10,776,522
Granted Patent B1
US 10,776,522 · App. 15/900,380 · Granted Sep 15, 2020

Asymmetric protection of circuit designs

Inventors: Steven E. McNeil (Rio Rancho, NM); Jason J. Moore (Albuquerque, NM); Theodore A. Ennis (Fountain Hills, AZ)
Assignee: Xilinx, Inc.
G06F21/72H04L9/0822H04L9/0825H04L9/30H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,776,522
App. No.
15/900,380
Granted
Sep 15, 2020
Kind
B1
Abstract

Protecting circuit designs can include, in response to receiving a first encrypted public key, generating, using a hash circuit within the integrated circuit, a first hash of the first encrypted public key. The first hash can be compared with a second hash that was previously stored within a non-volatile memory of the integrated circuit. In response to determining that the first hash matches the second hash, the first encrypted public key is decrypted resulting in a first decrypted public key. A determination is made whether received configuration data for the device is authentic using the first decrypted public key.

Claims (34)

1. A method, comprising:

in response to receiving a first encrypted public key, generating, using a hash circuit within an integrated circuit, a first hash of the first encrypted public key, wherein the first encrypted public key is encrypted using a symmetric key;

wherein the symmetric key is a device symmetric key and includes a physically unclonable function corresponding to the integrated circuit or a metal key implemented within the integrated circuit;

comparing the first hash with a second hash using a comparison circuit implemented within the integrated circuit, wherein the second hash is stored within a non-volatile memory of the integrated circuit during a previously performed registration process;

in response to determining that the first hash matches the second hash, reading the symmetric key from within the integrated circuit and decrypting the first encrypted public key resulting in a first decrypted public key, wherein the decrypting is performed using the symmetric key, and wherein the reading and the decrypting are performed by a decryption circuit implemented within the integrated circuit; and

determining whether configuration data for the integrated circuit is authentic using the first decrypted public key.

2. The method of claim 1 , further comprising:

in response to receiving an unencrypted public key, encrypting, using an encryption circuit within the integrated circuit, the unencrypted public key using the symmetric key resulting in the first encrypted public key during the previously performed registration process.

3. The method of claim 1 , further comprising:

using a data processing system, encrypting an unencrypted public key using the symmetric key resulting in the first encrypted public key.

4. The method of claim 1 , further comprising:

initiating a lockdown mode within the integrated circuit in response to determining that the first hash does not match the second hash.

5. The method of claim 1 , further comprising:

initiating a lockdown mode within the integrated circuit in response to determining that the configuration data is not authentic.

6. The method of claim 1 , wherein the integrated circuit is a programmable integrated circuit.

7. The method of claim 6 , wherein the programmable integrated circuit is not configured with any configuration data prior to successfully authenticating the configuration data.

8. The method of claim 1 , wherein the first hash and the second hash are cryptographic hashes.

9. An integrated circuit, comprising:

a non-volatile memory configured to store a first hash of a first encrypted public key, wherein the first hash is stored within the non-volatile memory of the integrated circuit during a previously performed registration process;

a hash circuit configured to generate a second hash from a second encrypted public key received by the integrated circuit, wherein the second encrypted public key is encrypted using a symmetric key;

wherein the symmetric key is a device symmetric key and is a physically unclonable function corresponding to the integrated circuit or a metal key implemented within the integrated circuit;

a comparison circuit configured to compare the first hash with the second hash;

a decryption circuit configured to decrypt the second encrypted public key resulting in a second decrypted public key;

wherein the decryption circuit, in response to the comparison circuit determining a match between the first hash and the second hash, is configured to read the symmetric key from within the integrated circuit and decrypt the second encrypted public key using the symmetric key; and

an authentication circuit configured to authenticate configuration data for the integrated circuit using the second decrypted public key.

10. The integrated circuit of claim 9 , wherein the comparison circuit is configured to allow the decryption circuit to read the symmetric key in response to determining the match between the first hash and the second hash.

11. The integrated circuit of claim 9 , wherein the integrated circuit is a programmable integrated circuit and the authentication circuit, the hash circuit, the comparison circuit, the decryption circuit and the non-volatile memory are hardwired circuits.

12. The integrated circuit of claim 9 , wherein the comparison circuit is configured to initiate a lockdown mode in the integrated circuit in response to determining that the first hash does not match the second hash.

13. The integrated circuit of claim 9 , wherein the authentication circuit is configured to initiate a lock down mode in the integrated circuit in response to determining that the configuration data is not authentic.

14. The integrated circuit of claim 9 , wherein the first hash and the second hash are cryptographic hashes.

15. The integrated circuit of claim 9 , wherein the integrated circuit is a programmable integrated circuit.

16. The integrated circuit of claim 15 , wherein the integrated circuit is not configured with any configuration data prior to successfully authenticating the configuration data.

17. The integrated circuit of claim 9 , further comprising:

an encryption circuit configure to, in response to receiving an unencrypted public key, encrypting the unencrypted public key using the symmetric key resulting in the second encrypted public key during the previously performed registration process.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2018
From: MCNEIL, STEVEN E.; MOORE, JASON J.; ENNIS, THEODORE A.
To: XILINX, INC.
Reel/Frame 044980/0946 →
Cited By (2)
US 12,609,841 US 12,609,842