IP Library Patent Application 19445400
Patent Application
App. No. 19/445,400

FLEXIBLE BITSTREAM VERIFICATION AND INTEGRITY CHECKING FOR PROGRAMABLE LOGIC DEVICES, SYSTEMS, AND METHODS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/445,400
Abstract

Various techniques are disclosed for providing improved and flexible security for configuration bitstreams to be used with programmable logic devices (PLDs). For example, a configuration bitstream may be encrypted with a key in a manner that generates one or more tags. The key and the tags may be provided to the PLD in a communication using a signature that may be verified by the PLD. When the encrypted configuration bitstream is subsequently received and decrypted by the PLD using the key, new tags generated by the decryption operation may be compared with the previously received tags to perform an integrity check on the decrypted configuration bitstream. The signature verification and integrity check operations may be separately performed by configured logic and dedicated hardware, respectively. Additional devices, systems and methods are also provided.

Claims (59)

1 . A method comprising:

receiving an encryption key for an encrypted configuration bitstream for a programmable logic device (PLD);

receiving a first set of tags for the encrypted configuration bitstream;

receiving the encrypted configuration bitstream separately from the encryption key and the first set of tags;

decrypting the encrypted configuration bitstream using the encryption key to generate a second set of tags; and

comparing the first and second sets of tags to perform an integrity check for the encrypted configuration bitstream.

2 . The method of claim 1 , further comprising authenticating the encryption key and the first set of tags.

3 . The method of claim 2 , wherein:

the authenticating is performed by configured logic blocks of the PLD; and

the decrypting and the comparing are performed by dedicated hardware of the PLD.

4 . The method of claim 2 , wherein the authenticating comprises verifying a security signature associated with the encryption key and the first set of tags.

5 . The method of claim 4 , wherein the encryption key and the first set of tags are received by the PLD in a data structure comprising the security signature.

6 . The method of claim 1 , wherein one or more of the encryption key, the first set of tags, and/or the encrypted configuration bitstream are received by the PLD from an external system and/or a storage device associated with the PLD.

7 . The method of claim 1 , wherein the first set of tags are generated during an encryption operation that provides the encrypted configuration bitstream.

8 . The method of claim 7 , wherein:

the encryption operation is an Advanced Encryption Standard with Galois/Counter Mode (AES-GCM) encryption operation; and

the first set of tags are GCM tags.

9 . The method of claim 1 , further comprising configuring the PLD with a decrypted configuration bitstream in response to the comparing of the first and second tags.

10 . The method of claim 1 , wherein:

the encryption key and the first set of tags are uniquely associated with the encrypted configuration bitstream;

the encrypted configuration bitstream is a first encrypted configuration bitstream;

the encryption key is a first encryption key; and

the method further comprises:

receiving a second encryption key for a second encrypted configuration bitstream for the PLD,

receiving a third set of tags for the second encrypted configuration bitstream,

wherein the second encryption key and the third set of tags are uniquely associated with the second encrypted configuration bitstream,

receiving the second encrypted configuration bitstream separately from the second encryption key and the third set of tags,

decrypting the second encrypted configuration bitstream using the second encryption key to generate a fourth set of tags, and

comparing the third and fourth sets of tags to perform an integrity check for the second encrypted configuration bitstream.

11 . A programmable logic device (PLD) comprising:

a plurality of logic blocks configured to:

receive an encryption key for an encrypted configuration bitstream for the PLD,

receive a first set of tags for the encrypted configuration bitstream,

receive the encrypted configuration bitstream separately from the encryption key and the first set of tags; and

dedicated hardware blocks implemented to:

decrypt the encrypted configuration bitstream using the encryption key to generate a second set of tags, and

compare the first and second sets of tags to perform an integrity check for the encrypted configuration bitstream.

12 . The PLD of claim 11 , wherein the logic blocks are configured to authenticate the encryption key and the first set of tags.

13 . The PLD of claim 12 , wherein the logic blocks are configured to verify a security signature associated with the encryption key and the first set of tags to authenticate the encryption key and the first set of tags.

14 . The PLD of claim 13 , wherein the encryption key and the first set of tags are received by the PLD in a data structure comprising the security signature.

15 . The PLD of claim 11 , wherein the logic blocks are configured to receive one or more of the encryption key, the first set of tags, and/or the encrypted configuration bitstream from an external system and/or a storage device associated with the PLD.

16 . The PLD of claim 15 , wherein the logic blocks are configured to establish a secure communication channel with the external system, wherein the encryption key and the first set of tags are received over the secure communication channel.

17 . The PLD of claim 11 , wherein the first set of tags are generated during an encryption operation that provides the encrypted configuration bitstream.

18 . The PLD of claim 17 , wherein:

the encryption operation is an Advanced Encryption Standard with Galois/Counter Mode (AES-GCM) encryption operation; and

the first set of tags are GCM tags.

19 . The PLD of claim 11 , further comprising a configuration engine implemented to configure the logic blocks with a decrypted configuration bitstream in response to the comparing of the first and second tags.

20 . The PLD of claim 11 , wherein:

the encryption key and the first set of tags are uniquely associated with the encrypted configuration bitstream;

the encrypted configuration bitstream is a first encrypted configuration bitstream;

the encryption key is a first encryption key;

the logic blocks are configured to:

receive a second encryption key for a second encrypted configuration bitstream for the PLD,

receive a third set of tags for the second encrypted configuration bitstream,

wherein the second encryption key and the third set of tags are uniquely associated with the second encrypted configuration bitstream, and

receive the second encrypted configuration bitstream separately from the second encryption key and the third set of tags; and

the dedicated hardware blocks are implemented to:

decrypt the second encrypted configuration bitstream using the second encryption key to generate a fourth set of tags, and

compare the third and fourth sets of tags to perform an integrity check for the second encrypted configuration bitstream.

Assignments (2)
SECURITY INTEREST Recorded Jul 2, 2026
From: LATTICE SEMICONDUCTOR CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 075892/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2026
From: RAHMATIAN, MEHRYAR; VOGT, TIM; GUPTA, MAMTA; SIVERTSON, ERIC; CORONA, CUAUHTEMOC CHAVEZ; ANDERSON, JORDAN
To: LATTICE SEMICONDUCTOR CORPORATION
Reel/Frame 074335/0699 →