Mind Chasers Inc.
Mind Chasers Inc.

Private Island: Open Source FPGA-Based Network Processor for Privacy, Security, and Control

Overview of the Private Island project including highlights, goals, and a brief description of the development board.



Private Island is an open source FPGA-based project for Gigabit Ethernet networking. It's primary purpose is for building an open, trustworthy, and extensible foundation for packet processing, IoT, and control (e.g., sensors, motors, etc.)

When the FPGA filters certain addresses, ports, and / or protocols, we are able to confirm at the hardware layer that this has been accomplished. This is in stark contrast to off-the-shelf SoC implementations, which require developers & users to make assumptions of multiple layers (typically opaque) being free of bugs, back doors, and resident spies / spyware.

The open FPGA-based architecture supports numerous, highly parallel functions implemented at Ethernet line rate (125 MHz x 8-bit). Our Darsena development board, which is Arduino form factor and pin out compatible supports Ethernet connectivity via two on-board Gigabit Ethernet PHYs and integrates an ARM micro controller, debuggers, and also offers expansion via Arduino-style connectors.

Private Island Conceptual Block Diagram
Private Island System Concept

Project Highlights

Soft Gigabit / 100 Mbit Ethernet switch

Real-time packet filtering, inspection, and mirroring

Gigabit Ethernet MAC controller for external micro controller

Customizable metrics. Stream them to the host of your choice.

Dozens of expansion I/O

It's an FPGA and open source, so the applications are endless.

The figure below shows a block diagram of the FPGA Verilog modules comprising a typical Private Island instantiation. Note that the SERDES/PCS functionality is currently provided by a hard macrocell inside the Latthce ECP5UM. The receive (rx) path is into the soft Ethernet switch, and the transmit path is out of the switch.

The source code, which had been hosted on Github, is moving here on mindchasers.com using CGit. We plan to have it back on line during the month of March, 2019.

development block diagram
Private Island FPGA Modular Architecture

Project Goals

Strive for modularity and simplicity

Support multiple FPGAs using both SGMII and RGMII (Lattice ECP5 is first instance)

Limited number of dependencies and only when necessary

Enable connecting new modules for new applications

Deterministic packet visibility from inside and outside the FPGA

Never compromise the integrity of the data

Our Development Board: Darsena

  • Arduino form-factor compatible with dozens of I/O for expansion and shield support
  • Lattice ECP5UM FPGA (45K LUTs with integrated PCS/SERDES)
  • Two Texas Instruments DP83867 Gigabit PHYs
  • NXP Kinetis K02 Microcontroller with ARM Cortex M4 core
  • Micron SPI ROM
Darsena image
development block diagram

The figure below shows the Lattice Diamond IDE with the Physical Viewer window enabled. This viewer shows the routing of an instantiation of Private Island with one of the wires of the Ethernet rx_data bus highlighted.

Diamond IDE showing Physical Viewer
Lattice Diamond IDE showing Physical Viewer

The next figure shows the Lattice Diamond Reveal Analyzer active with a trace of the Ethernet receive path. This gives new meaning to the concept of packet inspection and enables developers to see packets within their FPGA as it traverses their device.

Diamond IDE showing Physical Viewer
Lattice Diamond Reveal Logic Analyzer

Didn't find an answer to your question? Post your issue below or in our new FORUM, and we'll try our best to help you find a solution.

And please note that we update our site daily with new content related to our open source approach to network security and system design. If you would like to be notified about these changes, then please follow us on Twitter and join our mailing list.

subscribe to mailing list:

Please help us improve this article by adding your comment or question:

For enhanced features and capabilities, please sign in or authenticate using a popular third party

your email address will be kept private

to upload an image

previous month
next month