IP Library › Granted Patent US 11,893,115
Granted Patent B2
US 11,893,115 · App. 17/293,662 · Granted Feb 6, 2024

Method for providing a secret unique key for a volatile FPGA

Inventors: Kimmo Järvinen (Espoo, FI); Matti Tommiska (Espoo, FI)
Assignee: XIPHERA OY
G06F21/57G06F21/44G06F21/6218G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,893,115
App. No.
17/293,662
Granted
Feb 6, 2024
Kind
B2
Abstract

A method for providing a secret unique key for a volatile FPGA uses layers of encryption with different and independent keys and the possibility to store auxiliary data in the configuration memory. The configuration may be stored in a bit-file protected using hardwired bit-file encryption. The configuration includes a security block with an embedded group key used for protecting the auxiliary data. In the beginning, the auxiliary data may include a specific field with null identifier, which indicates that the device has not been initialized. During the initialization, the device generates a unique key and sets the field to specific identifier, which indicates that the device has been initialized, and replaces the original auxiliary data in the non-volatile configuration memory with a new auxiliary data constructed from these values. During normal operation this key is fetched from the auxiliary data and used to build a root-of-trust.

Claims (63)

1. A method for providing a secret unique key for a volatile FPGA, wherein the method comprises

programming the FPGA with a bit-file to implement a security IP block that embeds a value for a group key and a default value of an initialization state indicator, wherein

the bit-file has been encrypted with a bit-file encryption that is decrypted with a hardwired decryption module embedded on the FPGA,

and/or

the group key has been obfuscated within the bit-file, and

wherein the default value represents an uninitialized state where no secret unique key has been generated before; and,

with the security IP block implemented on the FPGA,

retrieving a value of a data record from a non-volatile memory, wherein the data record has been encrypted and authenticated with a key derived from the group key and represents values of the secret unique key and the initialization state indicator;

decrypting the value of the data record with the key derived from the group key;

determining an initialization status on the basis of the retrieved value of the initialization state indicator, the initialization status being selected from a list comprising at least the uninitialized state and an initialized state where a secret unique key has been generated before; and

if the determined initialization status represents the uninitialized state,

generating a new value for the secret unique key,

sending a specific value derived from the new value of the secret unique key to be received by an external validation system,

waiting to receive a validation signal for the specific value from the external validation system, wherein the validation signal indicates that the specific value has been successfully validated by the external validation system; and

if a signal validating the unique secret key is received, storing a new value of the data record to the non-volatile memory, wherein the said value represents the generated new value of the secret unique key and initialized state of the initialization state indicator, and wherein said value is encrypted and authenticated with the group key.

2. The method according to claim 1 , wherein the generating of the new value for the secret unique key comprises

generating the new value with a true random number generator (TRNG) programmed on the FPGA as a part of the security IP block.

3. The method according to claim 2 , wherein the bit-file is stored in a non-volatile configuration memory, and the stored value of the secret unique key is stored on the same non-volatile configuration memory.

4. The method according to claim 3 , wherein the FPGA and the non-volatile configuration memory implement an encrypted communications interface between each other, and the programming of the FPGA is performed via the encrypted communications interface.

5. The method according to claim 3 , wherein the FPGA and the non-volatile configuration memory implement a non-encrypted communications interface between each other, and wherein protection of the group key is based on obfuscation.

6. The method according to claim 3 , wherein the generating of the new value of the secret unique key comprises generating a plurality of new values for a plurality of secret unique keys.

7. The method according to claim 3 , wherein the method further comprises

encrypting and authenticating the specific value derived from new value of the secret unique key with a key derived from a shared secret key or a public key of the external validation system before sending the specific value to be received by the external validation system.

8. The method according to claim 3 , wherein the security IP block comprises a first block for initialization and a second block for normal operation after the initialization.

9. The method according to claim 3 , wherein the non-volatile memory further stores other cryptographic keys and/or other data.

10. The method according to claim 1 , wherein the bit-file is stored in a non-volatile configuration memory, and the stored value of the secret unique key is stored on the same non-volatile configuration memory.

11. The method according to claim 10 , wherein the FPGA and the non-volatile configuration memory implement an encrypted communications interface between each other, and the programming of the FPGA is performed via the encrypted communications interface.

12. The method according to claim 10 , wherein the FPGA and the non-volatile configuration memory implement a non-encrypted communications interface between each other, and wherein protection of the group key is based on obfuscation.

13. The method according to claim 10 , wherein the non-volatile configuration memory is integrated to the FPGA.

14. The method according to claim 1 , wherein the initialization state indicator is in the form of a separate indicator field within the data record.

15. The method according to claim 1 , wherein the generating of the new value of the secret unique key comprises generating a plurality of new values for a plurality of secret unique keys.

16. The method according to claim 1 , wherein the method further comprises

encrypting and authenticating the specific value derived from new value of the secret unique key with a key derived from a shared secret key or a public key of the external validation system before sending the specific value to be received by the external validation system.

17. The method according to claim 1 , wherein the security IP block comprises a first block for initialization and a second block for normal operation after the initialization.

18. The method according to claim 1 , wherein the non-volatile memory further stores other cryptographic keys and/or other data.

19. A non-volatile configuration memory for configuring a volatile FPGA, wherein the non-volatile memory contains a bit-file, wherein the bit-file is configured to program the FPGA to implement a security IP block that embeds a value for a group key and a default value of an initialization state indicator, wherein

the bit-file is encrypted with bit-file encryption that is configured to be decrypted with a hardwired decryption module embedded on the FPGA,

and/or

the group key is obfuscated within the bit-file, and

wherein the default value represents an uninitialized state where no secret unique key has been generated before, and

wherein the security IP block is further configured to:

retrieve a value of a data record from a non-volatile memory, wherein the data record has been encrypted and authenticated with a key derived from the group key and represents values of the secret unique key and the initialization state indicator;

decrypt the value of the data record with the key derived from the group key;

determine an initialization status on the basis of the retrieved value of the initialization state indicator, the initialization status being selected from a list comprising at least the uninitialized state and an initialized state where a secret unique key has been generated before; and

if the determined initialization status represents the uninitialized state,

generate a new value for the secret unique key,

send a specific value derived from the new value of the secret unique key to be received by an external validation system,

wait to receive a validation signal for the specific value from the external validation system, wherein the validation signal indicates that the specific value has been successfully validated by the external validation system; and

if a signal validating the unique secret key is received, store a new value of the data record to the non-volatile memory, wherein the said value represents the generated new value of the secret unique key and initialized state of the initialization state indicator, and wherein said value is encrypted and authenticated with the group key.

20. A device comprising a volatile FPGA and a non-volatile configuration memory according to claim 19 , wherein the FPGA is configured to receive the FPGA's configuration from the configuration memory.

21. A non-transitory computer-readable medium on which is stored a configuration program comprising a bit-file that is configured to program a volatile FPGA to implement a security IP block that embeds a value for a group key and a default value of an initialization state indicator, wherein

the bit-file is encrypted with a bit-file encryption that is configured to be decrypted with a hardwired decryption module embedded on the FPGA,

and/or

the group key is obfuscated within the bit-file, and

wherein the default value represents an uninitialized state where no secret unique key has been generated before, and wherein the security IP block is further configured to:

retrieve a value of a data record from a non-volatile memory, wherein the data record has been encrypted and authenticated with a key derived from the group key and represents values of the secret unique key and the initialization state indicator;

decrypting the value of the data record with the key derived from the group key;

determine an initialization status on the basis of the retrieved value of the initialization state indicator, the initialization status being selected from a list comprising at least the uninitialized state and an initialized state where a secret unique key has been generated before; and

if the determined initialization status represents the uninitialized state,

generate a new value for the secret unique key,

send a specific value derived from the new value of the secret unique key to be received by an external validation system,

wait to receive a validation signal for the specific value from the external validation system, wherein the validation signal indicates that the specific value has been successfully validated by the external validation system; and

if a signal validating the unique secret key is received, store a new value of the data record to the non-volatile memory, wherein the said value represents the generated new value of the secret unique key and initialized state of the initialization state indicator, and wherein said value is encrypted and authenticated with the group key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2021
From: JÄRVINEN, KIMMO; TOMMISKA, MATTI
To: XIPHERA OY
Reel/Frame 056231/0609 →
Priority Claims (1)
FI 20185962 · Nov 14, 2018 · national
Continuity (1)
Related Publication 20220012338A1 · Jan 13, 2022
Cited By (4)
US 12,299,179 US 12,301,549 US 12,682,121 US 12,689,617