IP Library Granted Patent US 11,436,382
Granted Patent B2
US 11,436,382 · App. 16/794,003 · Granted Sep 6, 2022

Systems and methods for detecting and mitigating programmable logic device tampering

Inventor: Bruce B. Pedersen (Sunnyvale, CA)
Assignee: Altera Corporation
G06F21/86G06F21/76H03K19/17768
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,382
App. No.
16/794,003
Granted
Sep 6, 2022
Kind
B2
Abstract

Systems and methods are disclosed for preventing tampering of a programmable integrated circuit device. Generally, programmable devices, such as FPGAs, have two stages of operation; a configuration stage and a user mode stage. To prevent tampering and/or reverse engineering of a programmable device, various anti-tampering techniques may be employed during either stage of operation to disable the device and/or erase sensitive information stored on the device once tampering is suspected. One type of tampering involves bombarding the device with a number of false configuration attempts in order to decipher encrypted data. By utilizing a dirty bit and a sticky error counter, the device can keep track of the number of failed configuration attempts that have occurred and initiate anti-tampering operations when tampering is suspected while the device is still in the configuration stage of operation.

Claims (32)

1. Control circuitry of a logic device configured to prevent tampering of programmable logic circuitry of a core of the logic device, wherein the control circuitry is configured to:

receive configuration data configured to configure the programmable logic circuitry;

determine that a configuration attempt of the programmable logic circuitry is valid based at least in part on an authentication bit asserting a first logical state, wherein the configuration attempt is associated with an unauthorized bitstream configured to program a second function of the programmable logic circuitry, and wherein the authentication bit is asserted before decryption of the unauthorized bitstream;

adjust a counter value of a counter in response to the configuration attempt being invalid wherein the configuration attempt is determined to be invalid in response to the authentication bit asserting a second logical state different than the first logical state based on the configuration attempt failing to configure the programmable logic circuitry; and

clear a configuration memory by zeroing an encryption key associated with decrypting the configuration data associated with the programmable logic circuitry in response to the counter reaching a threshold value, wherein clearing the configuration memory resets at least some of a plurality of logic array blocks and a plurality of logical connections of the programmable logic circuitry implementing a user design.

2. The control circuitry of claim 1 , wherein the control circuitry is configured to adjust the counter value by decrementing the counter value in response to the configuration data being invalid.

3. The control circuitry of claim 1 , wherein the encryption key is backed up by a battery of the logic device.

4. The control circuitry of claim 1 , wherein the counter is backed up by a battery of the logic device.

5. The control circuitry of claim 1 , wherein the control circuitry is configured to clear the configuration memory by zeroing the configuration data associated with the programmable logic circuitry.

6. The control circuitry of claim 1 , wherein the control circuitry is configured to increment the counter based on a successful configuration of the programmable logic circuitry of the logic device.

7. A logic device configured to prevent tampering, comprising:

programmable logic circuitry programmed to perform a first function, wherein the programmable logic circuitry comprises a configuration memory; and

control circuitry coupled to the programmable logic circuitry, wherein the control circuitry is configured to:

receive configuration data configured to configure the programmable logic circuitry;

determine that a configuration attempt of the programmable logic circuitry is valid based at least in part on an authentication bit asserting a first logical state, wherein the configuration attempt is associated with an unauthorized bitstream configured to program a second function of the programmable logic circuitry, and wherein the authentication bit is asserted before decryption of the unauthorized bitstream;

adjust a counter in response to the configuration attempt being invalid, wherein the configuration attempt is determined to be invalid in response to the authentication bit asserting a second logical state different than the first logical state based on the configuration attempt failing to configure the programmable logic circuitry; and

clear the configuration memory by zeroing an encryption key associated with decrypting the configuration data associated with the programmable logic circuitry in response to the counter reaching a threshold value, wherein clearing the configuration memory resets at least some of a plurality of logic array blocks and a plurality of logical connections of the programmable logic circuitry implementing a user design.

8. The logic device of claim 7 , wherein the control circuitry is configured to adjust the counter based on a successful configuration of the programmable logic circuitry.

9. The logic device of claim 8 , wherein the control circuitry is configured to adjust the counter by incrementing the counter based on the successful configuration.

10. The logic device of claim 7 , wherein the configuration memory is configured to store values configured to cause the programmable logic circuitry to be programmed to perform the first function.

11. The logic device of claim 10 , wherein the counter is stored in a memory device and is backed up by a battery.

12. The logic device of claim 7 , wherein the counter is configured to enable a user to set an initial value.

13. The logic device of claim 7 , wherein the threshold value is zero.

14. The logic device of claim 7 , wherein the control circuitry is configured to decrement the counter when adjusting the counter in response to determining that the configuration attempt is invalid.

15. The logic device of claim 7 , comprising a memory device coupled to the control circuitry, wherein the memory device comprises a battery configured to back up at least a portion of the memory device, wherein the programmable logic circuitry comprises a plurality of logic array blocks, the plurality of logical connections, and the configuration memory, and wherein the programmable logic circuitry is configured to implement the user design of the plurality of the logic array blocks and the plurality of logical connections based on values stored in the configuration memory to program the programmable logic circuitry to perform the first function.

16. A method for preventing tampering of a logic device, comprising:

receiving configuration data configured to configure programmable logic circuitry;

determining, via control circuitry of the logic device, that a configuration attempt of programmable logic circuitry of a core of the logic device is valid based at least in part on an authentication bit asserting a first logical state, wherein the configuration attempt is associated with an unauthorized bitstream configured to program a different function of the programmable logic circuitry, and wherein the authentication bit is asserted before decryption of the unauthorized bitstream;

adjusting, via the control circuitry, a counter value of a counter in response to the configuration attempt being invalid, wherein the configuration attempt is determined to be invalid in response to the authentication bit asserting a second logical state different than the first logical state based on the configuration attempt failing to configure the programmable logic circuitry; and

clearing, via the control circuitry, a configuration memory at least in part by zeroing an encryption key associated with decrypting the configuration data associated with the programmable logic circuitry in response to the counter reaching a threshold value, wherein clearing the configuration memory resets at least some of a plurality of logic array blocks and a plurality of logical connections of the programmable logic circuitry implementing a user design.

17. The method of claim 16 , wherein adjusting, via the control circuitry, the counter value comprises decrementing the counter value.

18. The method of claim 16 , comprising enabling an initial value of the counter value to be set by a user.

Assignments (1)
SECURITY INTEREST Recorded Sep 12, 2025
From: ALTERA CORPORATION
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 073431/0309 →
Continuity (4)
Continuation 15799690 · Oct 31, 2017
Continuation 14218455 · Mar 18, 2014
Continuation 13098074 · Apr 29, 2011
Related Publication 20200184118A1 · Jun 11, 2020