FPGA Accelerated Embedded System Security Through Hardware Isolation

FPGA Accelerated Embedded System Security Through Hardware Isolation
复制标题

FPGA 通过硬件隔离加速嵌入式系统安全

DOI:
--
复制
发表时间:
2020
期刊:
Asian Hardware-Oriented Security and Trust Symposium
影响因子:
--
通讯作者:
C. Bobda
C. Bobda
中科院分区:
--
文献类型:
--
作者:
S. Saha;C. Bobda

文献摘要

被引文献

相似文献

现代嵌入式系统包括片上 FPGA 和处理器,通过为用户提供添加定制硬件加速器的灵活性来满足高计算需求。任何机密或敏感信息都可能由这些自定义加速器或硬件知识产权 (IP) 进行处理。嵌入式系统中现有的加速器使用模型无法防止对 IP 的非法访问,这可能会造成严重的安全漏洞。在本文中,我们提出了一种用于安全 FPGA 加速嵌入式系统设计的硬件-软件协同设计方法。我们提出的安全框架继承了基于强制访问控制 (MAC) 的身份验证策略,该策略在软件中运行到 FPGA 中的硬件加速器。它确保硬件中机密数据的安全处理,防止软件发起的对硬件 IP 的攻击和信息泄露。我们已经实现了所提出的框架的原型,这表明在设计具有自定义加速器 IP 的嵌入式系统时可以轻松集成该框架。实验结果表明,所提出的框架以可忽略的面积和性能开销建立了安全的硬件执行。
Modern embedded systems include on-chip FPGA along with processors to meet the high computation demand by providing flexibility to users to add custom hardware accelerators. Any confidential or sensitive information may be processed by those custom accelerators or hardware Intellectual Properties (IPs). Existing accelerator usage models in embedded systems do not prevent illegal access to the IPs, which can be a severe security breach. In this paper, we present a hardware-software co-design approach for secured FPGA accelerated embedded system design. Our proposed security framework inherits Mandatory Access Control (MAC) based authentication policies running at software down to hardware accelerators in FPGA. It ensures secured processing of confidential data in the hardware to prevent software originated attacks at hardware IPs and information leaks. We have implemented a prototype of our proposed framework, which shows that it can be easily integrated while designing an embedded system with custom accelerator IPs. The experimental results show that the proposed framework establishes secured hardware execution with a negligible amount of area and performance overhead.