FAST: A Frequency-Aware Skewed Merkle Tree for FPGA-Secured Embedded Systems

FAST: A Frequency-Aware Skewed Merkle Tree for FPGA-Secured Embedded Systems
复制标题

FAST:用于 FPGA 安全嵌入式系统的频率感知倾斜 Merkle 树

DOI:
--
复制
发表时间:
2019
期刊:
IEEE Computer Society Annual Symposium on VLSI
影响因子:
--
通讯作者:
Mingjie Lin
Mingjie Lin
中科院分区:
--
文献类型:
--
作者:
Yu Zou;Mingjie Lin

文献摘要

被引文献

相似文献

当攻击者能够获得对外部存储器总线的物理访问时,保护外部存储器非常重要。与通用系统相比,嵌入式系统的可移植性使其更容易受到物理攻击。其中一种攻击是重播攻击,攻击者记录通过内存总线发送的数据,并伪装成授权用户进行重播。传统上,重放攻击使用完整、平衡的Merkle树来保护。针对一般情况下的性能和通用系统,Merkle树的遍历和验证在每次内存访问中都会产生巨大的延迟开销。与通用系统不同,嵌入式系统通常是特定于应用程序的,程序行为和存储器访问模式是确定性的。除此之外,我们还观察到,在给定程序的情况下,并不是所有的内存位置都被同等频繁地访问。基于这两点,我们提出了一种FAST,一种适用于特定应用的嵌入式系统的频率感知倾斜Merkle树。在没有任何重放攻击保护的情况下,在模拟环境中剖析程序后,我们得到了内存访问频率分布。然后,我们设计了一种自动和系统的方法来生成特定于特定应用的最优倾斜Merkle树。我们提出了一种高效的硬件结构来加速在现场可编程门阵列上的速度,并且通过在五个真实基准上的测试,我们的倾斜Merkle树的实现比使用全平衡Merkle树的基准算法的性能高达3倍。
Protection of external memory is important when an attacker could get physical accesses to the external memory bus. Compared to general-purpose systems, embedded systems are more vulnerable to physical attacks due to the portability. One of the attacks is a replay attack, which an attacker records data sent over a memory bus and replays it to pretend to be an authorized user. Traditionally, the replay attack is protected using a full, balanced Merkle Tree. Focusing on average-case performance and general-purpose systems, traversal and verification of Merkle Tree incur a huge latency overhead to each memory access. In contrast to general-purpose systems, embedded systems are normally application-specific, and program behaviors and memory access patterns are deterministic. Besides that, we also observed that not all memory locations are accessed equally frequently given a program. Based on these two observations, we propose FAST, a Frequency-Aware Skewed merkle Tree for application-specific embedded systems. After profiling a program in a simulation environment without involving any replay attack protection, we get a memory access frequency distribution. Afterward, we design an automatic and systematic approach to generate an application-specific optimal skewed Merkle Tree accordingly. We propose an efficient hardware architecture to accelerate FAST on FPGA, and by experimenting on five real-world benchmarks, our skewed Merkle Tree implementation outperforms baseline which uses a full balanced Merkle Tree by up to 3 times.