FPGAhammer: Remote Voltage Fault Attacks on Shared FPGAs, suitable for DFA on AES

FPGAhammer: Remote Voltage Fault Attacks on Shared FPGAs, suitable for DFA on AES
复制标题

FPGAhammer:对共享 FPGA 的远程电压故障攻击,适用于 AES 上的 DFA

DOI:
10.13154/tches.v2018.i3.44-68
复制
发表时间:
2018
期刊:
IACR Trans. Cryptogr. Hardw. Embed. Syst.
影响因子:
--
通讯作者:
M. Tahoori
M. Tahoori
中科院分区:
--
文献类型:
--
作者:
Jonas Krautter;Dennis R. E. Gnad;M. Tahoori

文献摘要

被引文献

相似文献

随着每次新技术的生成,现场可编程门阵列上的可用资源增加,使其对多个用户的部分访问更具吸引力。它们越来越多地被用作各种应用程序域中的加速器,嵌入在芯片或远程云服务上的共享系统中。因此,最近的一些作品已经探索了拒绝服务和侧渠道攻击,其中有多个用户共享FPGA面料。在这项工作中,我们仅通过软件提供的bitstreams来展示如何在FPGA内发射故障攻击。可以从映射到FPGA的合法逻辑中产生过多的电压下降,从而导致正时故障,从一个空间和逻辑隔离的分区到另一个用户到FPGA织物的另一个用户。为了导致这种电压降,我们首先显示如何激活环形振荡器的特定模式在各种FPGA板上的简单测试设计中会导致计时故障。随后,我们为高级加密标准分析并调整了现有的故障模型,以匹配我们的故障攻击的准确性。在相同的多用户方案中,我们显示为概念概念的证明,如何在AES模块上进行成功的差异故障分析攻击。我们对同一模型的三个FPGA板进行实验,并确认攻击适应所有系统,并且在过程变化下成功,但对故障的敏感性不同。该论文是通过验证对另一个平台的攻击,并基于定时分析分析漏洞的结论,证明了对不同设备的适用性。
With each new technology generation, the available resources on Field Programmable Gate Arrays increase, making them more attractive for partial access from multiple users. They get increasingly adopted as accelerators in various application domains, embedded in shared Systems on Chip or remote cloud services. Thus, some recent works have already explored Denial-of-Service and side-channel attacks, where an FPGA fabric is shared among multiple users. In this work, we show how fault attacks can be launched within an FPGA, through software-provided bitstreams alone. Excessive voltage drops can be generated from legitimate logic mapped into the FPGA to cause timing faults, reaching from spatially and logically isolated partitions of one to another user of the FPGA fabric. To cause this voltage drop, we first show how specific patterns to activate Ring Oscillators can cause timing failures in simple test designs on various FPGA boards. Subsequently, we analyze and adapt an existing fault model for the Advanced Encryption Standard to match the accuracy of our fault attack. In the same multi-user scenario, we show as a proof-of-concept how a successful Differential Fault Analysis attack on an AES module can be launched. We perform experiments on three FPGA boards of the same model and confirm that the attack adapts to all systems and is successful under process variation, but with different susceptibility to faults. The paper is concluded by validating the attack on another platform, and analyzing the vulnerability based on a timing analysis, proving the applicability to different devices.