Knowledge Base Article

Why am I unable to run BKP operations with Quartus® Prime Pro Edition 26.1.1 on Windows*?

Description

Due to a problem in the Quartus® Prime Pro Edition Software version 26.1.1, Black Key Provisioning (BKP) operations might fail on Windows* with the following error:

Error: BKP PLUGIN: [3000] Http error: Could not use specified SSL cipher

because Quartus has enabled the Windows SSP interface Schannel (Secure Channel) to work with the OpenSSL library. When using libcurl with the Schannel (Windows) backend, the option CURLOPT_SSL_CIPHER_LIST does not accept individual, specific cipher suites (for example TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384).

Resolution

To work around this problem in the Quartus® Prime Pro Edition Software version 26.1.1, build a patched bkpprog.dll and select it through the project configuration, as follows:

1. Clone the source repository: GitHub - altera-fpga/device-security-software-services: Device Security Software and Services source code for FPGA Device Onboarding, Attestation, Secure Session, Black Key Provisioning.

2. Prepare the Windows build environment. Follow the Windows Build instructions in the repository README. Install the listed prerequisites and prepare the repository dependencies exactly as documented there.

3. Modify network_wrapper.cpp. Open the following file in the cloned repository: bkpprogrammer/src/core/cpp/network/network_wrapper.cpp

In CurlWrapper::CurlWrapper, locate the TLS version and cipher-list configuration:

setCurlOptionWithErrorHandling(  
curlHandle,

CURLOPT_SSLVERSION,

CURL_SSLVERSION_TLSv1_2);

setCurlOptionWithErrorHandling(
curlHandle,

CURLOPT_SSL_CIPHER_LIST,

acceptedCiphers.c_str());

Replace it with:

setCurlOptionWithErrorHandling(  
curlHandle,

CURLOPT_SSLVERSION,

CURL_SSLVERSION_TLSv1_2);

4. Build the patched plug-in. Return to the repository root and build by following the repository Windows Build instructions. Confirm that bkpprog.dll is regenerated after network_wrapper.cpp was modified.

5. Place the custom plug-in. Create the following directory under the BKPS project and copy the rebuilt bkpprog.dll into it. Do not replace the DLL inside the Quartus installation. <project>\cm_provisioning\bkp_plugin\bkpprog.dll

6. Create quartus.ini. Create a quartus.ini file directly under the project cm_provisioning directory with the following line: PGM_ALLOW_CUSTOM_BKP_PLUGIN=7S6Nh0s3@on

7. Update bkp_options.txt. Use the normal project-specific BKP values and add bkp_plugin with the path to the rebuilt DLL:

bkp_cfg_id = <ID> 
bkp_ip = <IP>
bkp_port = <PORT>
bkp_tls_ca_cert = "<Path_To_bkps_ssl_cert.crt>"
bkp_tls_prog_cert = "<Path_To_pro_cert>"
bkp_device_opn = <OPN>
bkp_plugin = "<Path_To_bkpprog.dll>"

8. Run Quartus Programmer where quartus.ini is located. Set the current working directory to the cm_provisioning directory that contains quartus.ini and bkp_options.txt. Quartus reads quartus.ini from its current working directory, so run the commands from here: quartus_pgm.exe -c 1 -m jtag --bkp_options=bkp_options.txt --bkp_prefetch

Use the same working directory for Set Authority and Provision operations, so Quartus continues to load the custom plug-in setting from quartus.ini.

This problem is scheduled to be resolved in a future release of the Quartus® Prime Pro Edition Software.

Updated 20 hours ago
Version 2.0
No CommentsBe the first to comment