US2016248588A1PendingUtilityA1
Security ram block with multiple partitions
Est. expirySep 7, 2026(~0.1 yrs left)· nominal 20-yr term from priority
Inventors:Martin Langhammer
G06F 12/1416G06F 2212/1052G09C 1/00H04L 9/3242H04L 63/0428H04L 9/0631G06F 2221/2143G06F 21/6218
49
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Circuits, methods, and apparatus for storing application data, keys, authorization codes, or other information in a volatile memory on an FPGA. A field programmable gate array (FPGA) can include multiple memory blocks and partition those blocks among multiple independent reconfigurable regions. Access to the memory blocks can then be restricted so that only authorized regions have access to particular memory partitions. In addition, each partition can store multiple message authentication codes (MACs) for further controlling access to data in each partition.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An apparatus for storing data, the apparatus comprising:
programmable circuitry including first and second independently reconfigurable regions; a memory block configured to store data; and a configuration controller configured to:
partition the memory block to allocate a first memory partition to the first independently reconfigurable region and a second memory partition to the second independently reconfigurable region;
receive requests from the first and second independently reconfigurable regions to access the memory block; and
control access to the memory block to prevent the first independently reconfigurable region from accessing the second memory partition and to prevent the second independently reconfigurable region from accessing the first memory partition.
2 . The apparatus of claim 1 , wherein the configuration controller is further configured to:
determine whether to the first independently reconfigurable region should be granted access to the second memory partition based on a stored bit; and control access to the memory block to allow the first independently reconfigurable region to access the second memory partition in response to determining that the first independently reconfigurable region should be granted access to the second memory partition; wherein the configuration controller is configured to control access to the memory block to prevent the first independently reconfigurable region from accessing the second memory partition in response to determining that the first independently reconfigurable region should not be granted access to the second memory partition.
3 . The apparatus of claim 2 , wherein the configuration controller is further configured to:
determine, based on the stored bit, whether the first independently reconfigurable region should be granted read access and write access to the second memory partition; in response to a read-only determination, control access to the memory block to allow the first independently reconfigurable region to read data stored in the second memory partition and to prevent the first independently reconfigurable region writing data to the second memory partition; in response to a write-only determination, control access to the memory block to allow the first independently reconfigurable region to write data to the second memory partition and to prevent the first independently reconfigurable region reading data from the second memory partition; and in response to a read and write determination, control access to the memory block to allow the first independently reconfigurable region to both read data from and write data to the second memory partition.
4 . The apparatus of claim 1 further comprising n memory blocks and m independently reconfigurable regions, where m>n, wherein the configuration controller is further configured to:
partition the n memory blocks over m independently reconfigurable regions; and
control access to the n memory blocks to prevent any given one of the m independently reconfigurable regions from accessing memory partitions allocated to another one of the m independently reconfigurable regions.
5 . The apparatus of claim 4 , wherein the memory block is partitioned at the first configuration.
6 . The apparatus of claim 4 , wherein each memory partition stores multiple message authentication codes.
7 . The apparatus of claim 6 , wherein the configuration controller is further configured to:
generate a message authentication code for a received configuration stream; compare the generated message authentication code with each of the stored message authentication codes; and determine that the received configuration stream is an authorized configuration stream when any of the stored message authentication codes match the generated message authentication code.
8 . The apparatus of claim 7 , wherein the apparatus further comprises:
a message authentication code (MAC) generator configured to input the received configuration stream and output the generated message authentication code, wherein the MAC generator is implemented as a combination of hard logic and soft logic.
9 . The apparatus of claim 8 , wherein the MAC generator retrieves one of a plurality of keys from the memory block for use in generating message authentication codes.
10 . The apparatus of claim 8 , wherein a key is embedded in a soft logic portion of the MAC generator during a first configuration of the programmable circuitry, and wherein the key is used for generating message authentication codes.
11 . The apparatus of claim 1 , wherein the configuration controller is further configured to overwrite all data stored in the second memory partition with zero values in response to determining that the first independently reconfigurable region is attempting to access the second memory partition.
12 . The apparatus of claim 1 further comprising an encryption circuit, wherein the encryption circuit is configured to decrypt data stored in a given memory partition in response to the configuration controller determining an authorized access request.
13 . The apparatus of claim 1 , wherein the configuration controller is automatically authorized to read data from any partition of the memory block.
14 . An apparatus for storing data, the apparatus comprising:
programmable circuitry including m independently reconfigurable regions; n memory blocks for storing data, where m>n; a message authentication code (MAC) generator configured to generate a message authentication code for a received configuration stream; and a configuration controller configured to:
partition the n memory blocks over m independently reconfigurable regions;
store a plurality of message authentication codes in at least one of the memory partitions;
compare the generated message authentication code with each of the stored plurality of message authentication codes; and
determine that the received configuration stream is an authorized configuration stream when any of the stored plurality of message authentication codes match the generated message authentication code
15 . The apparatus of claim 14 , wherein the MAC generator is further configured to retrieve at least one of a plurality of keys from the n memory blocks for use in generating message authentication codes.
16 . The apparatus of claim 14 , wherein the configuration controller is further configured to:
control access to the n memory blocks to prevent at least one of the m independently reconfigurable regions from accessing a memory partition allocated to another one of the m independently reconfigurable regions.
17 . A method of controlling memory access in a field programmable gate array (FPGA) having n memory blocks and m independently reconfigurable regions, the method comprising:
partitioning the n memory blocks over the m independently reconfigurable regions; storing a plurality of message authentication codes in at least one of the memory partitions; generating a message authentication code for a received configuration stream; comparing the generated message authentication code with each of the stored plurality of message authentication codes; and determining that the received configuration stream is an authorized configuration stream when any of the stored plurality of message authentication codes match the generated message authentication code.
18 . The method of claim 17 further comprising:
retrieving at least one of a plurality of keys from the n memory blocks for use in generating the message authentication code.
19 . The method of claim 17 further comprising:
controlling access to the n memory blocks to prevent at least one of the m independently reconfigurable regions from accessing a memory partition allocated to another one of the m independently reconfigurable regions.
20 . The method of claim 19 further comprising:
controlling access to the n memory blocks to prevent any of the m independently reconfigurable regions from accessing a memory partition allocated to another one of the m independently reconfigurable regions.Join the waitlist — get patent alerts
Track US2016248588A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.