Bitstream Decryptor Permanent (eFUSE) Disable (Prevention/Response/Penalty) - Bitstream Decryptor Permanent (eFUSE) Disable (Prevention/Response/Penalty) - XAPP1098

Developing Tamper-Resistant Designs with UltraScale and UltraScale+ FPGAs (XAPP1098)

Document ID
XAPP1098
Release Date
2025-05-22
Revision
1.5.1 English

To prevent an attacker from collecting any side-channel information, an eFUSE can be programmed that permanently disables the AES-GCM decryptor. This eFUSE can be programmed via the external JTAG port or the internal MASTER_JTAG. Contact your local AMD FAE for additional details on how to program eFUSE bits from within the device via MASTER_JTAG. This feature can be used as a tamper response or to simply create a one-time encrypted configurable device. If the cfg_aes_only eFUSE bit is also programmed, it prevents the device from getting configured again (that is, “brick” the device).