Xilinx Offers Security in FPGA
October 31, 2012, ARM TechCom, Santa Clara, CA—Xilinx announced a new version of their Zinq, all programmable FPGAs. The applications focus for the new families are in security and safety, driven by increased interest and more software in security.
We talked with David Beal and Stephane Monboisset about the customer-driven additions to the FPGA platforms. The Zinq family offers a total hardware-software set of security functions including vertical–specific development systems and fully configured DIMM modules. In addition, there are use-case specific daughter boards and support for all the major OS’s.
Although the original requirements for security and safety were in the mil-aero and defense sectors, now almost any critical function needs protection. So industries like automotive, factory automation, medical and medical imaging, and even consumer products are including cryptography as a part of the product.
The new parts have features for security and safety to protect the internal IP in the design, and to harden the total device. As a result, the silicon and software are both protected. The hardware is only accessed after a safe system boot sequence and the software runtime executive is then allowed to access other areas in the system.
Programmable SoCs have greater challenges compared with hard wired designs. The programmable nature of the FPGA leaves it open for hacking and configuration data snooping. To address these issues, the new Zynq parts have the capability to isolate security-sensitive data and can execute real-time and general purpose tasks concurrently. The chips support safe and secure RTOS.
The FPGAs use the ARM TrustZone processes with isolated security accelerators and IP cores. This is a hardware subset of the SoC in which the software can run. Software on the subset cannot access the SoC hardware outside that subset. The chips can detect IP changes to protect the hardware, and have other anti-tamper functions. On boot, the trusted bootloader only uses a trusted software image and has a fallback boot option. The security includes authentication and encryption to keep outsiders out, and can be used with certified hypervisors like Sysgo, Openkernel Labs, and Sierraware.
Much of the technology is integrated into the logic, so it is harder to hack. In addition, key and configuration memory are capable of remote clearing, and the secure monitor code can detect most intrusion events. Secure key storage helps to keep access points enclosed within the chip, making intrusion more difficult. IP cores add to the security by monitoring security and mitigating soft errors. The large internal memory, 256 KB, allows full programs to reside within the chip, eliminating external memory accesses. On-chip temperature and voltage monitoring provide better power management and device efficiency. The software can address an advanced boot ROM and first stage boot loader before the software authentication (pre-run).
This total solution addresses the critical needs of a merged system and integrates the security elements into a fully programmable array of logic elements, I/O, and now security functions. Development boards and software development tools are available. For more information, go to www.xilinx.com


