IP Library Granted Patent US 12,277,255
Granted Patent B2
US 12,277,255 · App. 17/907,020 · Granted Apr 15, 2025

Secure semiconductor and system design

Inventors: David D. Moser (Haymarket, VA); Daniel L. Stanley (Warrenton, VA); Joshua C. Schabel (Apex, NC); Tate J. Keegan (Merrimack, NH); Sheldon L. Grass (Chester, NH)
Assignee: BAE Systems Information and Electronic Systems Integration Inc.
G06F21/76G06F30/347
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,277,255
App. No.
17/907,020
Granted
Apr 15, 2025
Kind
B2
Abstract

A secure system includes a data port, a network on chip (NoC) module, a processor communicatively coupled to the NoC module, a communication interface operatively coupled to the processor and to the data port, an electronic field-programmable gate array (eFPGA) configuration module operatively coupled to the NoC module, and a clock operatively coupled to the NoC module. In a first modality, the communication interface is at least partially disabled. In a second modality, the communication interface is at least partially disabled, boundary scan operations are disabled, a RESET signal is held in a constant state, and/or redacted code is rendered inoperable. In a third modality, the communication interface is at least partially enabled to send and receive commands and data via the data port, the boundary scan operations are enabled, the RESET signal is not held in the constant state, and/or the redacted code is operable.

Claims (64)

1. A secure semiconductor device, comprising:

a data port;

a network on chip (NoC) module;

a processor communicatively coupled to the NoC module, the processor configured to generate an access key;

a communication interface operatively coupled to the processor and to the data port, the communication interface configured to

enable communication access to and from the NoC module via the data port in response to a presence of the access key, and

disable the communication access to and from the NoC module via the data port in response to an absence of the access key; and

an electronic field-programmable gate array (eFPGA) configuration module;

a programmable logic block configured to operate in a boundary scan mode; and

a clock configured to disable the boundary scan mode of the programmable logic block in response to an absence of FPGA configuration data stored in the eFPGA configuration module.

2. The device of claim 1 , further comprising:

an electronic field-programmable gate array (eFPGA) configuration module; and

a clock configured to assert a RESET signal in response to an absence of FPGA configuration data stored in the eFPGA configuration module, thereby disabling operation of the device.

3. The device of claim 1 , further comprising:

a programmable logic block configured to operate in a boundary scan mode;

an electronic field-programmable gate array (eFPGA) configuration module;

a non-volatile random-access memory (NVRAM) configured to store field-programmable gate array (FPGA) configuration data; and

a clock configured to

enable the boundary scan mode of the programmable logic block and/or to de-assert a reset signal to the programmable logic block in response to a presence of the FPGA configuration in the eFPGA configuration module, and

disable the boundary scan mode of the programmable logic block and/or to assert the reset signal to the programmable logic block in response to an absence of the FPGA configuration data in the eFPGA configuration module.

4. The device of claim 1 , wherein the communication interface includes a JTAG interface.

5. The device of claim 1 , further comprising an on-chip oscillator operatively coupled to the processor.

6. A secure semiconductor device, comprising:

a network on chip (NoC) module;

an electronic field-programmable gate array (eFPGA) configuration module;

a clock operatively coupled to the eFPGA configuration module via the NoC module, the clock configured to assert a RESET signal in response to an absence of FPGA configuration data stored in the eFPGA configuration module, thereby disabling operation of the device; and

a programmable logic block configured to operate in a boundary scan mode;

wherein the clock is configured to disable the boundary scan mode of the programmable logic block in response to an absence of FPGA configuration data stored in the eFPGA configuration module.

7. The device of claim 6 , further comprising:

a data port;

a processor communicatively coupled to the NoC module, the processor configured to generate an access key; and

a communication interface operatively coupled to the processor and to the data port, the communication interface configured to

enable communication access to and from the NoC module via the data port in response to a presence of the access key, and

disable the communication access to and from the NoC module via the data port in response to an absence of the access key.

8. The device of claim 7 , wherein the communication interface includes a JTAG interface.

9. The device of claim 6 , further comprising:

a programmable logic block configured to operate in a boundary scan mode; and

a non-volatile random-access memory (NVRAM) configured to store field-programmable gate array (FPGA) configuration data;

wherein the clock is configured to

enable the boundary scan mode of the programmable logic block and/or to de-assert a reset signal to the programmable logic block in response to a presence of the FPGA configuration in the eFPGA configuration module, and

disable the boundary scan mode of the programmable logic block and/or to assert the reset signal to the programmable logic block in response to an absence of the FPGA configuration data in the eFPGA configuration module.

10. The device of claim 6 , further comprising an on-chip oscillator operatively coupled to the clock.

11. A secure system, comprising:

a data port;

a network on chip (NoC) module;

a processor communicatively coupled to the NoC module;

a communication interface operatively coupled to the processor and to the data port;

an electronic field-programmable gate array (eFPGA) configuration module operatively coupled to the NoC module; and

a clock operatively coupled to the NoC module;

wherein in a first modality, the communication interface is at least partially disabled;

wherein in a second modality, the communication interface is at least partially disabled, boundary scan operations are disabled, a RESET signal is held in a constant state, and/or redacted code is rendered inoperable;

wherein in a third modality, the communication interface is at least partially enabled to send and receive commands and data via the data port, the boundary scan operations are enabled, the RESET signal is not held in the constant state, and/or the redacted code is operable; and

wherein, in the second modality, the clock is configured to disable the boundary scan mode of the programmable logic block in response to an absence of FPGA configuration data stored in the eFPGA configuration module.

12. The system of claim 11 , further comprising an on-chip oscillator operatively coupled to the clock.

13. The system of claim 11 , wherein the communication interface includes a JTAG interface.

14. The system of claim 11 , wherein in the first modality or the second modality, the communication interface is configured to:

enable communication access to and from the NoC module via the data port in response to a presence of an access key; and

disable the communication access to and from the NoC module via the data port in response to an absence of the access key.

15. The system of claim 11 , wherein, in the second modality, the clock is configured to assert a RESET signal in response to an absence of FPGA configuration data stored in the eFPGA configuration module.

16. The system of claim 11 , further comprising:

a programmable logic block configured to operate in a boundary scan mode; and

a non-volatile random-access memory (NVRAM) configured to store field-programmable gate array (FPGA) configuration data;

wherein, in the second modality, the clock is configured to disable the boundary scan mode of the programmable logic block and/or to assert the reset signal to the programmable logic block in response to an absence of the FPGA configuration data in the eFPGA configuration module.

17. The system of claim 16 , wherein, in the second modality, the clock is further configured to enable the boundary scan mode of the programmable logic block and/or to de-assert a reset signal to the programmable logic block in response to a presence of the FPGA configuration in the eFPGA configuration module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2022
From: MOSER, DAVID D.; STANLEY, DANIEL L.; SCHABEL, JOSHUA C.; KEEGAN, TATE J.; GRASS, SHELDON L.
To: BAE SYSTEMS INFORMATION AND ELECTRONIC SYSTEMS INTEGRATION INC.
Reel/Frame 061185/0427 →
Continuity (1)
Related Publication 20240202375A1 · Jun 20, 2024
References Cited (29)
US 5898776A · Apland · 1999 [cited by examiner]
US 7398441B1 · Gee · 2008 [cited by examiner]
US 9946826B1 · Atsatt · 2018 [cited by examiner]
US 10608640B1 · Orthner · 2020 [cited by examiner]
US 11280829B1 · Poolla · 2022 [cited by examiner]
US 11442844B1 · Peattie · 2022 [cited by examiner]
US 12047504B2 · Ishikawa · 2024 [cited by examiner]
US 20050203988A1 · Nollet · 2005 [cited by examiner]
US 20050242924A1 · Yosim · 2005 [cited by examiner]
US 20070033454A1 · Moss · 2007 [cited by examiner]
US 20140344960A1 · Adams · 2014 [cited by examiner]
US 20150288531A1 · Kumar · 2015 [cited by examiner]
US 20160018465A1 · Bockelkamp · 2016 [cited by examiner]
US 20170176530A1 · Cottrell · 2017 [cited by examiner]
US 20190129870A1 · Atsatt · 2019 [cited by examiner]
US 20190258796A1 · Paczkowski · 2019 [cited by examiner]
US 20190303268A1 · Ansari · 2019 [cited by examiner]
US 20190347401A1 · Chen · 2019 [cited by examiner]
US 20200380121A1 · Pasricha · 2020 [cited by examiner]
US 20210124711A1 · Ansari · 2021 [cited by examiner]
US 20210148977A1 · Bhunia · 2021 [cited by examiner]
US 20210149837A1 · Mishra · 2021 [cited by examiner]
US 20210313988A1 · Weber · 2021 [cited by examiner]
US 20230090760A1 · Liew · 2023 [cited by examiner]
US 20230133385A1 · Goyal · 2023 [cited by examiner]
US 20230169251A1 · Riepe · 2023 [cited by examiner]
A. Khan, M. k. Sharma, G. Ganesh, S. D. Dhodapkar, B. B. Biswas and R. K. Patil, “A cryptographic primitive based authentication scheme for run-time software of embedded systems,” (ICRESH), Mumbai, India, 2010, pp. 500-… [cited by examiner]
S. Ray, E. Peeters, M. M. Tehranipoor and S. Bhunia, “System-on-Chip Platform Security Assurance: Architecture and Validation,” in Proceedings of the IEEE, vol. 106, No. 1, pp. 21-37, Jan. 2018, doi: 10.1109/JPROC.2017.… [cited by examiner]
International Search Report and Written Opinion received for PCT/US/2022/021750, mailed Jul. 18, 2022. 8 pages. [cited by applicant]