Temporal Thermal Covert Channels in Cloud FPGAs

Temporal Thermal Covert Channels in Cloud FPGAs
复制标题

DOI:
10.1145/3289602.3293920
复制
发表时间:
2019-02
期刊:
Proceedings of the 2019 ACM/SIGDA International Symposium on Field-Programmable Gate Arrays
影响因子:
--
通讯作者:
Shanquan Tian;Jakub Szefer
Shanquan Tian;Jakub Szefer
中科院分区:
其他
文献类型:
--
作者:
Shanquan Tian;Jakub Szefer

文献摘要

被引文献

相似文献

随着人们对云FPGA的兴趣越来越大,例如Amazon的EC2 F1实例或Microsoft的Azure with Catapult服务器,云计算基础设施中的FPGA可能会成为通过转换通道通信泄露信息的目标。云FPGA利用用户之间FPGA资源的临时共享。本文表明,一个用户产生的热量可以被后来使用同一FPGA的另一个用户观察到。通过简单的开关键控(OOK)可以实现隐蔽的数据传输,并且并行使用多个FPGA板显著提高了数据吞吐量。新的时间热隐蔽通道在微软的Catapult服务器上演示,FPGA在德克萨斯州高级计算中心(TACC)远程运行。文章最后给出了针对这种新的时间热隐蔽信道的一些防御措施。
With increasing interest in Cloud FPGAs, such as Amazon's EC2 F1 instances or Microsoft's Azure with Catapult servers, FPGAs in cloud computing infrastructures can become targets for information leakages via convert channel communication. Cloud FPGAs leverage temporal sharing of the FPGA resources between users. This paper shows that heat generated by one user can be observed by another user who later uses the same FPGA. The covert data transfer can be achieved through simple on-off keying (OOK) and use of multiple FPGA boards in parallel significantly improves data throughput. The new temporal thermal covert channel is demonstrated on Microsoft's Catapult servers with FPGAs running remotely in the Texas Advanced Computing Center (TACC). A number of defenses against the new temporal thermal covert channel are presented at the end of the paper.