Another method to erase the BBRAM key is via an external shunt to ground on the VBATT line. This method can be used to erase the key when main power (VCCINT and VCCAUX) to the FPGA is not applied because active features, such as KEYCLEARB, can be used only after the FPGA is powered up and configured. For instance, if a system-level tamper event is detected prior to the FPGA having its main power applied (perhaps a tamper switch becomes activated), the external battery power line to the FPGA’s VBATT pin can be opened and the VBATT pin driven to ground with some sort of transistor shunt. Care must be taken that the circuit is designed to open the battery connection before shunting the VBATT pin to ground. Another option is to connect the battery to the VBATT pin via a resistor. (The VBATT pin maximum input current is 150 nA.) By choosing the appropriate resistance value, the VBATT pin can be shunted to ground directly without causing excessive current flow out of the battery.
If an FPGA is not powered up (no VCCINT, VCCAUX, or other voltages except for VBATT), it would take a worst-case maximum time of 50 ms for the AES key stored in BBRAM to become erased if a user was to properly shunt the VBATT pin to ground at –55°C.
- Kintex UltraScale FPGAs Data Sheet: DC and AC Switching Characteristics (DS892)
- Virtex UltraScale FPGAs Data Sheet: DC and AC Switching Characteristics (DS893)
- Kintex UltraScale+ FPGAs Data Sheet: DC and AC Switching Characteristics (DS922)
- Virtex UltraScale+ FPGA Data Sheet: DC and AC Switching Characteristics (DS923)