This application note provides anti-tamper (AT) guidance and practical examples to help protect the intellectual property (IP) and sensitive data that might exist within a system enabled by AMD UltraScale™ and AMD UltraScale+™ FPGAs. This protection (in the form of tamper resistance) needs to be effective before, during, and after the FPGA has been configured by a bitstream. Sensitive data can include the configuration data that sets up the functionality of the FPGA logic, critical data and/or parameters that might be included in the bitstream (for example, initial block RAM contents and initial state of flip-flops). It also includes external data that is dynamically brought in and out of the FPGA during post-configuration normal operation.
This document summarizes the silicon AT features available in UltraScale and UltraScale+ FPGAs, explains why these features exist, and provides use cases and implementation details for each feature. This document also provides guidance on various other methods that can be used to provide additional tamper resistance.
By following this application note, you can be assured that you are following the best AT practices available with UltraScale and UltraScale+ FPGAs. These best practices broadly apply whether the goal is to simply prevent cloning/overbuilding of a commercial design, prevent reverse engineering of a military system’s valuable critical technology (CT), or anything in-between.
This application note assumes that you are somewhat knowledgeable and proficient in AMD FPGA architecture (see Zynq UltraScale+ MPSoC: Embedded Design Tutorial (UG1209)) and design, as well as the AMD Vivado™ tools flow methodology (see AMD Vivado Design Suite) and configuration (see UltraScale Architecture Configuration User Guide (UG570)). Solving Today's Design Security Concerns (WP365) and Developing Tamper Resistant Designs with Virtex 6 and 7 Series FPGAs (XAPP1084) provide a good background on the various security threats and solutions for FPGAs.