HISA: hardware isolation-based secure architecture for CPU-FPGA embedded systems

HISA: hardware isolation-based secure architecture for CPU-FPGA embedded systems
复制标题

HISA:CPU-FPGA嵌入式系统基于硬件隔离的安全架构

DOI:
10.1145/3240765.3240814
复制
发表时间:
2018
期刊:
Proceedings of the International Conference on Computer-Aided Design (ICCAD
影响因子:
--
通讯作者:
Wei, Sheng
Wei, Sheng
中科院分区:
--
文献类型:
--
作者:
Ye, Mengmei;Feng, Xianglong;Wei, Sheng

文献摘要

相似文献

异构CPU-FPGA系统已被证明可以在特定领域的计算中实现显着的性能增益。然而,与在性能加速上投入的巨大努力相反,社区尚未调查将FPGA纳入传统基于CPU的架构所带来的安全后果。事实上,在这样一个异构系统中,CPU和FPGA之间的相互作用如果不加以控制,可能会引入全新的攻击面。我们提出了一个基于硬件隔离的安全架构,即HISA,以减轻识别的新威胁。HISA将基于CPU的硬件隔离原语扩展到异构的FPGA组件,并通过在隔离的安全环境中实施两种安全策略,即访问控制策略和输出验证策略,来实现安全保证。我们使用四个参考FPGA IP核以及针对代表性CPU-FPGA攻击的各种参考安全策略来评估HISA。我们的实施和实验真实的硬件证明,HISA是一个有效的安全补充现有的CPU和FPGA的安全架构。
Heterogeneous CPU-FPGA systems have been shown to achieve significant performance gains in domain-specific computing. However, contrary to the huge efforts invested on the performance acceleration, the community has not yet investigated the security consequences due to incorporating FPGA into the traditional CPU-based architecture. In fact, the interplay between CPU and FPGA in such a heterogeneous system may introduce brand new attack surfaces if not well controlled. We propose a hardware isolation-based secure architecture, namely HISA, to mitigate the identified new threats. HISA extends the CPU-based hardware isolation primitive to the heterogeneous FPGA components and achieves security guarantees by enforcing two types of security policies in the isolated secure environment, namely the access control policy and the output verification policy. We evaluate HISA using four reference FPGA IP cores together with a variety of reference security policies targeting representative CPU-FPGA attacks. Our implementation and experiments on real hardware prove that HISA is an effective security complement to the existing CPU-only and FPGA-only secure architectures.