Optionally, key data written and stored into an UltraScale or UltraScale+ FPGA’s eFUSE array or BBRAM (via JTAG) can be obfuscated. The key data is encrypted using a fixed family key that is identical for all UltraScale FPGAs and all UltraScale+ FPGAs, and is known only to AMD. (The UltraScale FPGA family key is different from the UltraScale+ FPGA family key). This provides for an increased level of security in commercial production situations (for example, secret red key protection at a contract manufacturer). The internally stored obfuscated key is decrypted at the beginning of an encrypted bitstream load and then used to decrypt the bitstream that follows it. This feature is enabled by a control bit in the FUSE_SEC control register (eFUSE-based key) or by control bits written into the BBRAM (BBRAM-based key). The following figure provides a high-level summary of this operation.
Note:
AMD does not provide
the family key as part of the Vivado tools. Customers
must send a request for the family key to secure.solutions@xilinx.com. It will then be distributed to qualified
customers through the Product Licensing site on
www.amd.com.
Note: The use of obfuscated key storage is not compatible
with the configuration counting DPA countermeasure for BBRAM key storage.
Figure 1. Summary of Obfuscated Key Loading and Storage