Systems and Methods for Bitstream Authentication
A method includes receiving a bitstream including a signature associated with a private key, and detecting a first watermark of the bitstream, wherein the first watermark is associated with a first public key. The method also includes loading the bitstream based on determining that the first public key corresponds to a second public key and the private key and that the first public key is validated based on a validation value.
1 . An integrated circuit device comprising:
programmable logic circuitry; and
a controller comprising a memory, the controller configurable to:
receive a bitstream;
verify a digital signature of the bitstream based on a private key;
detect a first watermark and a second watermark of the bitstream based on the verification, wherein the first watermark is associated with a first public key and the second watermark is associated with a validation value stored in one-time programmable memory on the integrated circuit device;
determine that the first public key corresponds to a second public key stored in the memory of the controller;
determine that the first public key of the bitstream is validated based on the validation value; and
load the bitstream into the programmable logic circuitry based on determining that the first public key corresponds to the second public key and that the first public key is validated.
2 . The integrated circuit device of claim 1 , wherein the controller is configurable to store the second public key in the memory by entering a provisioning mode to provision the public key.
3 . The integrated circuit device of claim 2 , wherein the controller, while operating in the provisioning mode, is configurable to:
generate a random nonce; and
transmit the random nonce for signature with the private key.
4 . The integrated circuit device of claim 3 , wherein the controller, while operating in the provisioning mode, is configurable to:
receive the signed random nonce; and
verify the signed random nonce based on the second public key corresponding to the private key.
5 . The integrated circuit device of claim 3 , wherein the controller, while operating in the provisioning mode, is configurable to generate the random nonce as part of a challenge response protocol, wherein the challenge response protocol facilitates secure provisioning.
6 . The integrated circuit device of claim 1 , wherein the controller is configurable to verify the digital signature of the bitstream based on determining that the second public key corresponds to the private key associated with the digital signature.
7 . The integrated circuit device of claim 1 , wherein the controller is configurable to determine that the first public key corresponds to the second public key based on determining that a hash of the first public key matches a hash of the second public key.
8 . The integrated circuit device of claim 1 , wherein the second watermark is indicative of a condition that the first public key is validated prior to loading the bitstream into the programmable logic circuitry.
9 . One or more tangible, non-transitory, machine-readable media comprising instructions that, when executed by a data processing system, enable the data processing system to perform operations to generate a system design for an integrated circuit device comprising:
receiving a random nonce;
signing the random nonce based on a private key;
transmitting the signed random nonce for verification with a public key;
encode a first watermark and a second watermark into a bitstream, wherein the first watermark is associated with the public key and the second watermark is associated with a validation value; and
transmit the bitstream.
10 . The one or more tangible, non-transitory, machine-readable media of claim 9 , wherein the instructions, when executed by the data processing system, enable the data processing system to perform operations to cause the integrated circuit device to enter a provisioning mode to provision the public key.
11 . The one or more tangible, non-transitory, machine-readable media of claim 10 , wherein the instructions, when executed by the data processing system, enable the data processing system to perform operations to receive the random nonce based on the integrated circuit device entering the provision mode.
12 . The one or more tangible, non-transitory, machine-readable media of claim 9 , wherein the instructions, when executed by the data processing system, enable the data processing system to perform operations to sign the bitstream with a digital signature based on the private key.
13 . The one or more tangible, non-transitory, machine-readable media of claim 9 , wherein the first watermark comprises a transformation of the public key.
14 . The one or more tangible, non-transitory, machine-readable media of claim 9 , wherein the validation value is indicative of a condition that the public key is validated.
15 . A method comprising:
receiving a bitstream comprising a signature associated with a private key;
detecting a first watermark of the bitstream, wherein the first watermark is associated with a first public key; and
loading the bitstream based on determining that the first public key corresponds to a second public key and the private key and that the first public key is validated based on a validation value.
16 . The method of claim 15 , comprising detecting a second watermark of the bitstream, wherein the second watermark is associated with the validation value.
17 . The method of claim 15 , comprising storing the second public key by entering a provisioning mode to provision the public key.
18 . The method of claim 17 , comprising:
generating a random nonce in response to entering the provisioning mode; and
transmitting the random nonce for the signature associated with the private key.
19 . The method of claim 15 , comprising verifying a digital signature of the bitstream by determining that the second public key corresponds to the private key.
20 . The method of claim 15 , comprising determining that the first public key corresponds to the second public key by determining that a hash of the first public key matches a hash of the second public key.