Robust bitstream protection in FPGA-based systems through low-overhead obfuscation

Robust bitstream protection in FPGA-based systems through low-overhead obfuscation
复制标题

通过低开销混淆在基于 FPGA 的系统中提供强大的比特流保护

DOI:
10.1109/reconfig.2016.7857187
复制
发表时间:
2016
期刊:
2016 International Conference on ReConFigurable Computing and FPGAs (ReConFig)
影响因子:
--
通讯作者:
S. Bhunia
S. Bhunia
中科院分区:
--
文献类型:
--
作者:
Robert Karam;Tamzidul Hoque;S. Ray;M. Tehranipoor;S. Bhunia

文献摘要

被引文献

相似文献

可重构硬件,例如现场可编程门阵列(FPGA),正越来越多地应用于包括汽车系统、关键基础设施以及新兴的物联网(IoT)在内的不同应用领域,以实现定制化设计。然而,保护基于FPGA的设计免受盗版、逆向工程和篡改是具有挑战性的,特别是对于需要远程升级的系统而言。在许多情况下,基于位流加密的现有解决方案可能无法针对这些攻击提供足够的保护。在本文中,我们提出了一种新颖的混淆方法,能够以较低的开销对FPGA位流进行可证明的稳健保护,这种保护远远超出了位流加密所提供的保护。该方法适用于现有的FPGA架构和综合流程,并且可以与加密技术一起使用,或者对于功耗和面积受限的系统单独使用。它利用了“FPGA暗硅”——可配置逻辑块内未使用的资源——来有效地混淆真实功能。我们为该方法提供了详细的威胁模型和安全分析。我们已经开发了一个完整的应用映射框架,它与Altera Quartus II软件集成。使用这个CAD框架,对于一组基准电路以及商业FPGA上的几个大规模开源IP模块,我们针对FPGA位流的所有主要攻击实现了可证明的强大安全性,平均延迟为13%,总功耗开销为2%。
Reconfigurable hardware, such as Field Programmable Gate Arrays (FPGAs), are being increasingly deployed in diverse application areas including automotive systems, critical infrastructures, and the emerging Internet of Things (IoT), to implement customized designs. However, securing FPGA-based designs against piracy, reverse engineering, and tampering is challenging, especially for systems that require remote upgrade. In many cases, existing solutions based on bit-stream encryption may not provide sufficient protection against these attacks. In this paper, we present a novel obfuscation approach for provably robust protection of FPGA bitstreams at low overhead that goes well beyond the protection offered by bitstream encryption. The approach works with existing FPGA architectures and synthesis flows, and can be used with encryption techniques, or by itself for power and area-constrained systems. It leverages “FPGA dark silicon” — unused resources within the configurable logic blocks — to efficiently obfuscate the true functionality. We provide a detailed threat model and security analysis for the approach. We have developed a complete application mapping framework that integrates with the Altera Quartus II software. Using this CAD framework, we achieve provably strong security against all major attacks on FPGA bitstreams with an average 13% latency and 2% total power overhead for a set of benchmark circuits, as well as several large-scale open-source IP blocks on commercial FPGA.