LoopBreaker: Disabling Interconnects to Mitigate Voltage-Based Attacks in Multi-Tenant FPGAs

LoopBreaker: Disabling Interconnects to Mitigate Voltage-Based Attacks in Multi-Tenant FPGAs
复制标题

LoopBreaker:禁用互连以减轻多租户 FPGA 中基于电压的攻击

DOI:
--
复制
发表时间:
2021
期刊:
2021 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
通讯作者:
J. Henkel
J. Henkel
中科院分区:
--
文献类型:
--
作者:
Hassan Nassar;Hanna AlZughbi;Dennis R. E. Gnad;L. Bauer;M. Tahoori;J. Henkel

文献摘要

被引文献

相似文献

FPGA在云中作为加速器资源提供,可以在多个用户(即租户)之间共享。最近,各种方法已经表明,从一个租户区域向另一个租户区域发起的故障攻击是可能的,导致FPGA的时序故障或崩溃。因此,限制恶意租户造成此类安全问题的能力非常重要。到目前为止,针对这种攻击的现有对策在配置比特流被重新配置之前对其进行检查。这种离线方法具有各种实际限制,例如它们可能迫使租户公开其设计秘密。在本文中,我们提出了LoopBreaker,这是一种新型的运行时解决方案,可以禁用恶意租户区域的整个活动,以便在导致崩溃(即拒绝服务)之前快速阻止潜在的攻击。我们实施并测试了多种攻击类型,发现实际攻击至少需要12-26 µs才能成功。在我们的实际实现中,覆盖恶意租户区域的部分重新配置需要200 µs,这太慢了,无法防止攻击导致崩溃。相反,我们提出的LoopBreaker方法只需要1.5 µs就可以阻止恶意租户,这使得它成为第一个可以成功阻止具有挑战性的基于电压降的攻击导致崩溃的在线方法。
FPGAs are being offered in the cloud as accelerator resources that can be shared among multiple users (i.e. tenants). Recently, various approaches have shown that fault attacks launched from one tenant region to another are possible, leading to timing faults or crashes of the FPGA. It is, therefore, important that malicious tenants are limited in their ability to cause such security problems. So far, the existing countermeasures against such attacks check the configuration bitstreams before they are reconfigured. Such offline approaches have various practical limitations, e.g. they may force the tenants to unveil their design secrets. In this paper, we present LoopBreaker, a novel runtime solution that can disable the entire activity of a malicious tenant region, in order to rapidly stop a potential attack before it results in a crash (i.e. Denial-of-Service). We implemented and tested multiple attack types and found that realistic attacks demand at least 12–26 µs to be successful. A partial reconfiguration to overwrite the malicious tenant region demands 200 µs in our realworld implementation, which is too slow to prevent the attack from leading to a crash. Instead, our proposed LoopBreaker method only needs 1.5 µs to stop a malicious tenant, which makes it the first online approach that can successfully stop challenging voltage drop-based attacks from causing a crash.