HISA: hardware isolation-based secure architecture for CPU-FPGA embedded systems
HISA: hardware isolation-based secure architecture for CPU-FPGA embedded systems
复制标题
HISA:CPU-FPGA嵌入式系统基于硬件隔离的安全架构
DOI:
10.1145/3240765.3240814
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Wei, Sheng
中科院分区:
文献类型:
--
作者:
Ye, Mengmei;Feng, Xianglong;Wei, Sheng
Heterogeneous CPU-FPGA systems have been shown to achieve significant performance gains in domain-specific computing. However, contrary to the huge efforts invested on the performance acceleration, the community has not yet investigated the security consequences due to incorporating FPGA into the traditional CPU-based architecture. In fact, the interplay between CPU and FPGA in such a heterogeneous system may introduce brand new attack surfaces if not well controlled. We propose a hardware isolation-based secure architecture, namely HISA, to mitigate the identified new threats. HISA extends the CPU-based hardware isolation primitive to the heterogeneous FPGA components and achieves security guarantees by enforcing two types of security policies in the isolated secure environment, namely the access control policy and the output verification policy. We evaluate HISA using four reference FPGA IP cores together with a variety of reference security policies targeting representative CPU-FPGA attacks. Our implementation and experiments on real hardware prove that HISA is an effective security complement to the existing CPU-only and FPGA-only secure architectures.