security
39 TopicsUpdated .brd file for Stratix 10 GX dev kit
Referencing this post: EK-10M08E144 PCB .brd file corrupted | Altera Community - 302242 The .brd file that comes in the documentation at: https://www.altera.com/products/devkit/po-3028/stratix-10-gx-signal-integrity-development-kit-h-tile ...was done in Allegro, prior to version 16.6. The only available Allegro viewer gives an error because it was done prior to version 16.6, and you need the DB Doctor utility to update the file. The only way to get the DB Doctor utility is to install Allegro. If I had Allegro...I would not be installing the Allegro viewer. Altera: As mentioned in the post above (well over a year ago), it would make sense for you to update your files so customers can view the board of their $10K+ development board. How do we make that happen? Thanks!222Views0likes4CommentsWhy am I unable to run BKP operations with Quartus® Prime Pro Edition 26.1.1 on Windows*?
Description Due to a problem in the Quartus® Prime Pro Edition Software version 26.1.1, Black Key Provisioning (BKP) operations might fail on Windows* with the following error: Error: BKP PLUGIN: [3000] Http error: Could not use specified SSL cipher because Quartus has enabled the Windows SSP interface Schannel (Secure Channel) to work with the OpenSSL library. When using libcurl with the Schannel (Windows) backend, the option CURLOPT_SSL_CIPHER_LIST does not accept individual, specific cipher suites (for example TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384). Resolution To work around this problem in the Quartus® Prime Pro Edition Software version 26.1.1, build a patched bkpprog.dll and select it through the project configuration, as follows: 1. Clone the source repository: GitHub - altera-fpga/device-security-software-services: Device Security Software and Services source code for FPGA Device Onboarding, Attestation, Secure Session, Black Key Provisioning. 2. Prepare the Windows build environment. Follow the Windows Build instructions in the repository README. Install the listed prerequisites and prepare the repository dependencies exactly as documented there. 3. Modify network_wrapper.cpp. Open the following file in the cloned repository: bkpprogrammer/src/core/cpp/network/network_wrapper.cpp In CurlWrapper::CurlWrapper, locate the TLS version and cipher-list configuration: setCurlOptionWithErrorHandling( curlHandle, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2); setCurlOptionWithErrorHandling( curlHandle, CURLOPT_SSL_CIPHER_LIST, acceptedCiphers.c_str()); Replace it with: setCurlOptionWithErrorHandling( curlHandle, CURLOPT_SSLVERSION, CURL_SSLVERSION_TLSv1_2); 4. Build the patched plug-in. Return to the repository root and build by following the repository Windows Build instructions. Confirm that bkpprog.dll is regenerated after network_wrapper.cpp was modified. 5. Place the custom plug-in. Create the following directory under the BKPS project and copy the rebuilt bkpprog.dll into it. Do not replace the DLL inside the Quartus installation. <project>\cm_provisioning\bkp_plugin\bkpprog.dll 6. Create quartus.ini. Create a quartus.ini file directly under the project cm_provisioning directory with the following line: PGM_ALLOW_CUSTOM_BKP_PLUGIN=7S6Nh0s3@on 7. Update bkp_options.txt. Use the normal project-specific BKP values and add bkp_plugin with the path to the rebuilt DLL: bkp_cfg_id = <ID> bkp_ip = <IP> bkp_port = <PORT> bkp_tls_ca_cert = "<Path_To_bkps_ssl_cert.crt>" bkp_tls_prog_cert = "<Path_To_pro_cert>" bkp_device_opn = <OPN> bkp_plugin = "<Path_To_bkpprog.dll>" 8. Run Quartus Programmer where quartus.ini is located. Set the current working directory to the cm_provisioning directory that contains quartus.ini and bkp_options.txt. Quartus reads quartus.ini from its current working directory, so run the commands from here: quartus_pgm.exe -c 1 -m jtag --bkp_options=bkp_options.txt --bkp_prefetch Use the same working directory for Set Authority and Provision operations, so Quartus continues to load the custom plug-in setting from quartus.ini. This problem is scheduled to be resolved in a future release of the Quartus® Prime Pro Edition Software.6Views0likes0CommentsGeneral Question to your "Vulnerability Handling Process"
How can i subscribe to "Security Advisories"? Your link Manage Your Communication Preferences which i found on your Altera PSIRT Vulnerability Handling Process site does not work. Im not able write my email into the textbox.Solved295Views0likes1CommentQuartus Programmer 21.1: JTAG Server Error Code 82 – Port 1309 Cannot Be Bound
Hello Altera Community, I am working on an FPGA project using a Cyclone IV FPGA development board and an Altera USB-Blaster. I am currently unable to program the FPGA because Quartus Programmer cannot access the JTAG server. System details: - OS: Windows 11 64-bit - Software: Quartus Programmer 21.1 - Installation path: C:\intelFPGA\21.1\qprogrammer - Programmer: Altera USB-Blaster - FPGA: Cyclone IV development board The USB-Blaster is detected by Windows Device Manager and the driver is installed. The USB-Blaster also powers on normally. However, Quartus Programmer gives: "Attempted to access JTAG server -- internal error code 82 occurred" When I run: jtagconfig I get: Error when scanning hardware - Server error Sometimes it also hangs at: Connecting to server(s) [...] I checked the JTAG server using: jtagserver --status It reports: Installed JTAG server is 'C:\intelFPGA\21.1\qprogrammer\bin64\jtagserver.exe' Server is stopped Remote clients are disabled I tried reinstalling the JTAG server: jtagserver --install jtagserver --start But the server immediately stops. I also tried: net start "Altera JTAG Server" The result was: The Altera JTAG Server service could not be started. The service did not report an error. NET HELPMSG 3534. I then ran: jtagserver.exe --foreground and received: Unable to bind changedetect socket: 10048 Can't bind to TCP port 1309 - exiting I checked the port using: netstat -ano | findstr 1309 and found that TCP port 1309 was being used/listened to by another process, for example PID 12888. I tried terminating the process using: taskkill /F /PID 12888 but Windows reported: ERROR: The process with PID 12888 could not be terminated. Reason: There is no running instance of the task. I also tried stopping the JTAG server, reinstalling it, and restarting it. In addition, I already tried the following: 1. Disabled PCI Express → Link State Power Management. 2. Disabled USB Root Hub power saving ("Allow the computer to turn off this device to save power"). 3. Stopped the Print Spooler service. 4. Closed Quartus/Programmer-related applications. 5. Reinstalled the JTAG Server. 6. Restarted the computer. 7. Tried starting the JTAG server manually. 8. Checked TCP port 1309 using netstat. The problem still remains. My main questions are: 1. Why is Quartus Programmer 21.1 unable to start the JTAG Server? 2. What is causing TCP port 1309 to remain occupied? 3. Is there a known issue with Quartus Programmer 21.1 and Windows 11? 4. Is there a recommended patch, driver, or newer Quartus Programmer version for this problem? 5. Is it possible to configure the JTAG server to use another TCP port? 6. What is the correct way to completely remove and reinstall the JTAG Server on Windows 11? 7. Is there anything else I should check before reinstalling Quartus Programmer? I would appreciate any guidance on how to get the JTAG Server running so that jtagconfig can detect my USB-Blaster and FPGA. Thank you.186Views0likes5CommentsCyclon 5 tampering protection bit
I have a cyclone V with an AS scheme. I have generated an key-file (ekp) with tampering protection bit set according to AN556 Then I open it in the programmer programmer and generate a jam-file now in the jam-file the procedure DO_KEY_SECURE is optional which means I have to enable that procedure manualy with "-e DO_KEY_SECURE" in the command, for example: quartus_jli -c <n> keys.jam -e DO_KEY_SECURE -a <action> is it possible to make this procedure non-optional so it will program the tampering bit by default when programming the key?138Views0likes8CommentsModelSim-Intel FPGA Starter Edition 18.1 exits with code 211 when pressing Restart button
Hello, I am using ModelSim-Intel FPGA Starter Edition included with Quartus Prime Lite Edition 18.1. When I press the Restart button in the ModelSim GUI after running RTL simulation, ModelSim exits with the following message: "ModelSim is exiting with code 211. Check the transcript file for more information on the fatal error." Environment: - Quartus Prime Lite Edition 18.1 - ModelSim-Intel FPGA Starter Edition 18.1 - Windows PC - ModelSim path: C:\intelFPGA_lite\18.1\modelsim_ase\win32aloem 確認したこと: - Quartus / ModelSim は再インストールされました。 - 環境変数とPATH設定を確認しました。 - 同じプロジェクトが別のPCで正しく再起動できる場合。 - このPCではGUIの再起動ボタンを押すと問題が発生します。 - PCにはTrend Micro Apex Oneがインストールされています。 - リアルタイムスキャンからIntel FPGA / ModelSimフォルダを除外した後、ModelSimは正しく動作しました。 質問: GUIの再起動ボタンを使う場合、ModelSim-Intel FPGA Starter Edition 18.1で既知の問題として、終了コード211はありますか? また、この問題はウイルス対策ソフトやエンドポイントセキュリティソフトに関係している可能性はありますか? この問題に対するおすすめの設定や回避策はありますか? ありがとうございます。1.3KViews0likes21CommentsRSU: How to handle FACTORY_IMAGE signing and trust validation?
Hi, I have a technical question based on a customer's experiments with Remote System Update (RSU). For RSU, a SOF file is required for the FACTORY_IMAGE, as quartus_pfg rejects the RBF file. However, quartus_sign does not support SOF files for signing. Is it possible to use a signed image as the FACTORY_IMAGE? If not, what is the recommended method to ensure the integrity and authenticity of the FACTORY_IMAGE? How can the FACTORY_IMAGE be trusted in a secure RSU design? Thank you.Solved121Views0likes2CommentsArria 10SX current drawn during non-volatile key programming
Hi, we are using in our design an Arria10 SX (precisely the 10AS027E4F29E3SG) device. The design had been successfully manufactured for approx. 100 units. For one customer we decided to use design security and started to program a non-volatile key into the FPGA and use encrypted bitstreams later on. It turned out that appox every tenth unit failed now because the power manager found either an excessive current on the global supply or the VCCPT (1.8V) was degraded while programming the non-volatile key. Note, the supply driving the VCCPT had been designed to provide +70% current as calculated by the Quartus power analyzer (by the way it did not help that this support had been removed for Arria 10 from Quartus Pro, I did not check which versions actually support it, 18.1 works, 23.2 fails). Thus there is a reserve of approx 550mA at the supply. It obviously comes to its limits during the non-volatie key programming. I searched (again) for a specification in the Altera Arria 10 documentation (mainly datasheet, handbook and AN556) which current is drawn on which supply while programming the non-volatile key. I did not find any information on that. Can you please point me to the documentation where I can find this specification or can you provide me the numbers? Even an estimate will help. Thank you! Gerhard175Views0likes8Comments