COMA: Communication and Obfuscation Management Architecture

COMA: Communication and Obfuscation Management Architecture
复制标题

DOI:
--
复制
发表时间:
2019-09
期刊:
--
影响因子:
--
通讯作者:
K. Z. Azar;Farnoud Farahmand;Hadi Mardani Kamali;Shervin Roshanisefat;H. Homayoun;William Diehl;K. Gaj;Avesta Sasan
K. Z. Azar;Farnoud Farahmand;Hadi Mardani Kamali;Shervin Roshanisefat;H. Homayoun;William Diehl;K. Gaj;Avesta Sasan
中科院分区:
其他
文献类型:
--
作者:
K. Z. Azar;Farnoud Farahmand;Hadi Mardani Kamali;Shervin Roshanisefat;H. Homayoun;William Diehl;K. Gaj;Avesta Sasan

文献摘要

被引文献

相似文献

本文介绍了一种新的通信和混淆管理体系结构(COMA),用于处理混淆密钥的存储和保护来往于不可信但混淆的电路的通信。Coma解决了与混淆电路相关的三个挑战:第一,它消除了在不可信芯片上存储混淆解锁密钥的需要。其次,它实现了一种机制,通过该机制,用于解锁模糊电路的密钥在每次激活后都会更改(即使对于同一设备也是如此),从而将密钥转换为动态变化的许可证。第三,它保护与COMA保护的设备之间的通信,并另外引入了两种新的机制用于与COMA保护的体系结构之间的数据交换:(1)高度安全但缓慢的双重加密,用于交换密钥和敏感数据;(2)高性能、低能量但可泄露的加密,通过频繁的密钥更新来保护。我们证明,与最先进的密钥管理体系结构相比,COMA减少了14%的面积开销,同时允许其他功能,包括唯一的芯片身份验证,实现激活即服务(对于物联网设备),减少密钥管理体系结构上的侧信道威胁,以及提供两种新的与不可信芯片的安全通信方式。
In this paper, we introduce a novel Communication and Obfuscation Management Architecture (COMA) to handle the storage of the obfuscation key and to secure the communication to/from untrusted yet obfuscated circuits. COMA addresses three challenges related to the obfuscated circuits: First, it removes the need for the storage of the obfuscation unlock key at the untrusted chip. Second, it implements a mechanism by which the key sent for unlocking an obfuscated circuit changes after each activation (even for the same device), transforming the key into a dynamically changing license. Third, it protects the communication to/from the COMA protected device and additionally introduces two novel mechanisms for the exchange of data to/from COMA protected architectures: (1) a highly secure but slow double encryption, which is used for exchange of key and sensitive data (2) a high-performance and low-energy yet leaky encryption, secured by means of frequent key renewal. We demonstrate that compared to state-of-the-art key management architectures, COMA reduces the area overhead by 14%, while allowing additional features including unique chip authentication, enabling activation as a service (for IoT devices), reducing the side channel threats on key management architecture, and providing two new means of secure communication to/from an untrusted chip.