Invited Tutorial: FPGA Hardware Security for Datacenters and Beyond

Invited Tutorial: FPGA Hardware Security for Datacenters and Beyond
复制标题

特邀教程:数据中心及其他领域的 FPGA 硬件安全

DOI:
--
复制
发表时间:
2020
期刊:
Symposium on Field Programmable Gate Arrays
影响因子:
--
通讯作者:
Dirk Koch
Dirk Koch
中科院分区:
--
文献类型:
--
作者:
Kaspar Matas;T. La;Nikola Grunchevski;K. Pham;Dirk Koch

文献摘要

参考文献

被引文献

相似文献

由于FPGA现在可用于加速应用程序,因此提供FPGA硬件安全性是一个高度优先事项。随着向FPGA即服务(用户可以上传自己的比特流)的过渡,FPGA安全性变得更加重要。通过比特流对FPGA硬件的完全控制使得攻击能够削弱基于FPGA的系统。这些包括物理损坏FPGA设备和泄漏敏感信息,如加密算法的密钥。虽然到目前为止,在商业环境中还没有已知的攻击,但这不是一个是否会发生的问题,而是什么时候发生的问题。本教程将展示适用于数据中心FPGA的具体攻击。本教程的目标是让FPGA社区为即将到来的安全问题做好准备,以便为主动安全铺平道路。首先,我们将介绍FPGA硬件安全丛林,调查实际攻击和潜在威胁。我们将通过拒绝服务攻击的现场演示来加强这一点。FPGA上不到10%的逻辑资源可以汲取足够的动态功率来使数据中心FPGA卡崩溃。在本教程的第二部分中,我们将展示不同的缓解措施,这些缓解措施要么是供应商支持的,要么是学术界提出的。总之,本教程将说明,虽然FPGA硬件安全性很复杂,但对于已知的FPGA安全问题,有可接受的解决方案。
Since FPGAs are now available in datacenters to accelerate applications, providing FPGA hardware security is a high priority. FPGA security is becoming more serious with the transition to FPGA-as-a-Service where users can upload their own bitstreams. Full control over FPGA hardware through the bitstream enables attacks to weaken an FPGA-based system. These include physically damaging the FPGA equipment and leaking of sensitive information such as the secret keys of crypto algorithms. While there is no known attacks in the commercial settings so far, it is not so much a question of if but more of when? The tutorial will show concrete attacks applicable on datacenter FPGAs. The goal of this tutorial is to prepare the FPGA community to impending security issues in order to pave way for a proactive security. First, we will give a tour through the FPGA hardware security jungle surveying practical attacks and potential threats. We will reinforce this with live demos of denial of service attacks. Less than 10% of the logic resources on an FPGA can draw enough dynamic power to crash a datacenter FPGA card. In the second part of the tutorial, we will show different mitigations that are either vendor supported or proposed by the academic community. In summary, the tutorial will communicate that while FPGA hardware security is complicated to bring about, there are acceptable solutions for known FPGA security problems.
使用云 FPGA 中的环形振荡器测量长线泄漏
DOI: 10.1109/fpl.2019.00017
发表时间: 2019
期刊: International Conference on Field-Programmable Logic and Applications
影响因子: --
作者:
Giechaskiel, Ilias;Rasmussen, Kasper Bonne;Szefer, Jakub
通讯作者: Szefer, Jakub