Differential power analysis resistant encryption and decryption functions
Abstract
Circuits, methods, and systems are provided for securing an integrated circuit device against Differential Power Analysis (DPA) attacks. Plaintext (e.g., configuration data for a programmable device) may be encrypted in an encryption system using a cryptographic algorithm. Ciphertext may be decrypted in a decryption system using the cryptographic algorithm. The encryption and/or decryption systems may obfuscate the plaintext, the ciphertext, and/or the substitution tables used by the cryptographic algorithm. The encryption and/or decryption systems may also generate cryptographic key schedules by using different keys for encrypting/decrypting different blocks and/or by expanding round keys between encryption/decryption blocks. These techniques may help mitigate or altogether eliminate the vulnerability of cryptographic elements revealing power consumption information to learn the value of secret information, e.g., through DPA.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A system, comprising:
an electronic device to generate an encrypted bitstream to configure a field programmable gate array (FPGA), wherein the electronic device is operable to:
encrypt a first block of an unencrypted bitstream based on a first key to generate a first encrypted block of the encrypted bitstream;
encrypt a second block of the unencrypted bitstream based on a second key to generate a second encrypted block of the encrypted bitstream; and
encrypt a third block of the unencrypted bitstream based on a third key to generate a third encrypted block of the encrypted bitstream; and
the FPGA, wherein the FPGA is operable to receive the encrypted bitstream and use an internal decryption engine to:
decrypt the first encrypted block based on the first key;
obtain the second key based on the decryption of the first encrypted block;
decrypt the second encrypted block based on the second key;
obtain the third key based on the decryption of the second encrypted block; and
decrypt the third encrypted block based on the third key.
22 . The system of claim 21 , wherein the encrypted bitstream is stored in an off-chip memory prior to sending the encrypted bitstream to the FPGA.
23 . The system of claim 21 , wherein the FPGA stores the first key in an on-chip memory of the FPGA.
24 . The system of claim 21 , wherein the internal decryption engine decrypts using an Advanced Encryption Standard (AES) algorithm.
25 . The system of claim 21 , wherein the first key, the second key, and the third key are different from one another.
26 . The system of claim 21 , wherein the encrypted bitstream results in a disabled readback of configuration.
27 . The system of claim 21 , wherein the first key comprises a user-supplied key.
28 . The system of claim 21 , wherein the first key is obfuscated.
29 . The system of claim 21 , wherein the decrypted first block, the decrypted second block, the decrypted third block, or a combination thereof, are stored as configuration data in configuration memory of the FPGA.
30 . The system of claim 29 , wherein the configuration data is used to configure the FPGA.
31 . The system of claim 21 , wherein the first key is a symmetric key enabling access to the encrypted bitstream.
32 . A field programmable gate array (FPGA) configured to receive a plurality of blocks of an encrypted bitstream, the FPGA comprising:
a plurality of configurable logic blocks; a decryption engine configured to:
decrypt a first block of the plurality of blocks, wherein decrypting the first block is based on a first key; and
decrypt successive blocks of the plurality of blocks using successive keys, wherein the successive keys are determined based on a previously decrypted block of the plurality of blocks; and
configuration memory configured to store at least part of the decrypted first block, the decrypted successive blocks, or some combination thereof, as configuration data, wherein the configuration data configures the plurality of configurable logic blocks of the FPGA.
33 . The FPGA of claim 32 , wherein the plurality of blocks are stored in an external memory device separate from the FPGA before decryption by the decryption engine.
34 . The FPGA of claim 32 , wherein the first key is stored on an on-chip memory of the FPGA.
35 . The FPGA of claim 32 , wherein the decrypting comprises using an Advanced Encryption Standard (AES) algorithm.
36 . The FPGA of claim 32 , wherein the successive keys are unique keys.
37 . A method for configuring a field programmable gate array (FPGA) with an encrypted bitstream, comprising:
partitioning an unencrypted bitstream into a plurality of blocks; encrypting a first block of the plurality of blocks based on a first key; encrypting successive blocks of the plurality of blocks based on successive keys; transmitting the encrypted plurality of blocks to a decryption engine to decrypt the encrypted plurality of blocks; direct a decryption of the first block based on the first key; and direct a decryption of the successive blocks based on the successive keys, wherein the successive keys are determined based on a decryption of a previously encrypted block of the successive blocks.
38 . The method of claim 37 , wherein the first key is stored in an on-chip memory of the FPGA.
39 . The method of claim 37 , wherein the decrypted first block, the decrypted successive blocks, or a combination thereof, are stored as configuration data in configuration memory of the FPGA.
40 . The method of claim 39 , wherein the configuration data is used to configure the FPGA.Join the waitlist — get patent alerts
Track US2020244434A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.