Asset management systems and methods for programmable logic devices

US11914716B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11914716-B2
Application numberUS-202017093576-A
CountryUS
Kind codeB2
Filing dateNov 9, 2020
Priority dateMay 11, 2018
Publication dateFeb 27, 2024
Grant dateFeb 27, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for asset management for secure programmable logic devices (PLDs) are disclosed. An example system includes a secure PLD including programmable logic blocks (PLBs) arranged in PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in non-volatile memory (NVM) of the secure PLD and/or coupled through a configuration input/output (I/O) of the secure PLD. The secure PLD is configured to receive a secure PLD asset access request from the PLD fabric or an external system coupled to the secure PLD through the configuration I/O, and to perform a secure PLD asset update process corresponding to the secure PLD asset access request, where the performing the asset update process is based on a lock status associated with a secure PLD asset corresponding to the secure PLD asset access request.

First claim

Opening claim text (preview).

What is claimed is: 1. A secure programmable logic device (PLD) asset management system, comprising: a secure PLD, wherein the secure PLD comprises a plurality of programmable logic blocks (PLBs) arranged in a PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in a non-volatile memory (NVM) of the secure PLD and/or coupled through a configuration input/output (I/O) of the secure PLD to the configuration engine, wherein the secure PLD is configured to perform a computer-implemented method comprising: receiving a secure PLD asset access request from the PLD fabric or an external system coupled to the secure PLD through the configuration I/O; and performing a secure PLD asset update process corresponding to the secure PLD asset access request, wherein the performing the asset update process is based, at least in part, on a lock status associated with a secure PLD asset corresponding to the secure PLD asset access request. 2. The secure PLD asset management system of claim 1 , wherein the computer-implemented method further comprises: authenticating the received secure PLD asset access request prior to the performing the secure PLD asset update process, wherein the secure PLD asset access request is signed using a private key associated with a secure PLD customer for the secure PLD or a secure PLD manufacturer of the secure PLD, a corresponding public key is stored in the NVM, and the authenticating comprises using the public key to verify that the secure PLD asset access request is signed using the private key associated with the secure PLD customer or secure PLD manufacturer. 3. The secure PLD asset management system of claim 1 , wherein the computer-implemented method further comprises: authenticating the received secure PLD asset access request prior to the performing the secure PLD asset update process, wherein the secure PLD asset access request comprises a secure PLD asset access request trace ID, a trace ID associated the secure PLD is stored in the NVM, and the authenticating comprises comparing the secure PLD asset access request trace ID with the trace ID stored in the NVM. 4. The secure PLD asset management system of claim 1 , wherein the computer-implemented method further comprises: receiving a secure PLD asset unlock request, corresponding to the secure PLD asset, from the PLD fabric or the external system prior to the receiving the secure PLD asset access request; and receiving a secure PLD asset lock request, corresponding to the secure PLD asset, from the PLD fabric or the external system after the performing the secure PLD asset update process. 5. The secure PLD asset management system of claim 1 , wherein the computer-implemented method further comprises: authenticating the secure PLD asset unlock request after receiving the secure PLD asset unlock request; and/or authenticating the secure PLD asset lock request after receiving the secure PLD asset lock request. 6. The secure PLD asset management system of claim 1 , wherein the secure PLD asset comprises a configuration image sector of the NVM of the secure PLD, and wherein the performing the secure PLD asset update process comprises: determining a lock status associated with the configuration image sector of the NVM comprises a write enable and/or an erase enable lock status; and storing the configuration image in the configuration image sector of the NVM. 7. The secure PLD asset management system of claim 6 , wherein the performing the secure PLD asset update process further comprises: receiving a configuration image over the configuration I/O or a programmable I/O of the secure PLD; authenticating the configuration image; and storing the configuration image in the configuration image sector of the NVM with an authentication bit set to indicate the configuration is authenticated and bootable. 8. The secure PLD asset management system of claim 1 , wherein the secure PLD asset comprises a device keys sector of the NVM of the secure PLD, and wherein the performing the secure PLD asset update process comprises: determining a lock status associated with a configuration image sector of the NVM comprises a write enable and/or an erase enable lock status; storing the configuration image in the configuration image sector of the NVM; booting the configuration image by the PLD fabric; updating a lock status corresponding to the device keys sector to include a write enable and/or an erase enable lock status; receiving at least one device key over the configuration I/O or a programmable I/O of the secure PLD; storing the at least one device key in the device keys sector of the NVM; and updating the lock status corresponding to the device keys sector to include a write disable and/or an erase disable lock status. 9. The secure PLD asset management system of claim 1 , further comprising: the external system, wherein the external system comprises a processor and a memory and is configured to be coupled to the secure PLD through the configuration input/output (I/O) of the secure PLD, wherein the memory comprises machine-readable instructions which when executed by the processor of the external system are adapted to cause the external system to: provide a secure PLD asset unlock request, corresponding to the secure PLD asset, to the secure PLD over the configuration I/O; provide a configuration image for the PLD fabric to the secure PLD over the configuration I/O during the performing the secure PLD asset update process; and provide a secure PLD lock request, corresponding to the secure PLD asset, to the secure PLD over the configuration I/O. 10. The secure PLD asset management system of claim 1 , further comprising: the external system, wherein the external system comprises a processor and a memory and is configured to be coupled to the secure PLD through the configuration input/output (I/O) of the secure PLD, wherein the memory comprises machine-readable instructions which when executed by the processor of the external system are adapted to cause the external system to: provide a secure PLD asset unlock request, corresponding to the secure PLD asset, to the secure PLD over the configuration I/O; provide one or more device keys to the secure PLD over the configuration I/O during the performing the secure PLD asset update process; and provide a secure PLD lock request, corresponding to the secure PLD asset, to the secure PLD over the configuration I/O. 11. A secure programmable logic device (PLD) asset management system, comprising: an external system comprising a processor and a memory and configured to be coupled to a secure PLD through a configuration input/output (I/O) of the secure PLD, wherein the memory comprises machine-readable instructions which when executed by the processor of the external system are adapted to cause the external system to perform a computer-implemented method comprising: providing a secure PLD asset unlock request, corresponding to a secure PLD asset, to the secure PLD over the configuration I/O; providing one or more device keys and/or a configuration image for a PLD fabric of the secure PLD to the secure PLD over the configuration I/O; and providing a secure PLD lock request, corresponding to the secure PLD asset, to the secure PLD over the configuration I/O. 12. The secure PLD asset management system of claim 11 , further comprising: the secure PLD, wherein the secure PLD comprises a plurality of programmable logic blocks (PLBs) arranged in the PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configurati

Assignees

Inventors

Classifications

  • G06F21/575Primary

    Secure boot · CPC title

  • Updates (security arrangements therefor G06F21/57) · CPC title

  • Configuring for program initiating, e.g. using registry, configuration files · CPC title

  • using a specific debug interface · CPC title

  • in block erasable memory, e.g. flash memory · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11914716B2 cover?
Systems and methods for asset management for secure programmable logic devices (PLDs) are disclosed. An example system includes a secure PLD including programmable logic blocks (PLBs) arranged in PLD fabric of the secure PLD, and a configuration engine configured to program the PLD fabric according to a configuration image stored in non-volatile memory (NVM) of the secure PLD and/or coupled thr…
Who is the assignee on this patent?
Lattice Semiconductor Corp
What technology area does this patent fall under?
Primary CPC classification G06F21/575. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Feb 27 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).