Domain Isolation in FPGA-Accelerated Cloud and Data Center Applications

Domain Isolation in FPGA-Accelerated Cloud and Data Center Applications
复制标题

FPGA 加速云和数据中心应用中的域隔离

DOI:
10.1145/3453688.3461527
复制
发表时间:
2021
期刊:
Proceedings of the 2021 on Great Lakes Symposium on VLSI. 2021
影响因子:
--
通讯作者:
Bobda, Christophe
Bobda, Christophe
中科院分区:
--
文献类型:
--
作者:
Mandebi Mbongue, Joel;Saha, Sujan Kumar;Bobda, Christophe

文献摘要

参考文献

相似文献

云和数据中心应用越来越多地利用FPGA,因为它们的性能/功耗优势和灵活性优于传统的处理核心,如CPU和GPU。随着对硬件加速需求的不断增长逐渐导致云中的FPGA多租户,人们越来越担心FPGA虚拟化带来的安全挑战。将空间共享的FPGA暴露给多个云租户可能会损害FPGA加速应用程序的机密性、完整性和可用性。在这项工作中,我们提出了一个硬件/软件架构的域隔离在FPGA加速的云和数据中心,重点是基于软件的攻击,旨在未经授权的访问和信息泄漏。我们提出的架构实现强制访问控制的安全策略,从软件到FPGA上的硬件加速器。我们的实验表明,所提出的架构可以防止这种攻击,以最小的面积和通信开销。
Cloud and data center applications increasingly leverage FPGAs because of their performance/watt benefits and flexibility advantages over traditional processing cores such as CPUs and GPUs. As the rising demand for hardware acceleration gradually leads to FPGA multi-tenancy in the cloud, there are rising concerns about the security challenges posed by FPGA virtualization. Exposing space-shared FPGAs to multiple cloud tenants may compromise the confidentiality, integrity, and availability of FPGA-accelerated applications. In this work, we present a hardware/software architecture for domain isolation in FPGA-accelerated clouds and data centers with a focus on software-based attacks aiming at unauthorized access and information leakage. Our proposed architecture implements Mandatory Access Control security policies from software down to the hardware accelerators on FPGA. Our experiments demonstrate that the proposed architecture protects against such attacks with minimal area and communication overhead.
HILL:针对多租户 FPGA 长线信息泄露的硬件隔离框架
DOI: 10.1109/icfpt47387.2019.00060
发表时间: 2019
期刊: 2019 International Conference on Field-Programmable Technology (ICFPT)
影响因子: --
作者:
Yukui Luo;Xiaolin Xu
通讯作者: Xiaolin Xu
检测瘦虚拟机​​管理程序中的恶意软件签名
DOI: --
发表时间: 2012
期刊: ACM Symposium on Applied Computing
影响因子: --
作者:
Y. Oyama;Tran Truong Duc Giang;Yosuke Chubachi;Takahiro Shinagawa;Kazuhiko Kato
通讯作者: Kazuhiko Kato
在硬件 IP 组件中继承软件安全策略
DOI: 10.1109/fccm.2018.00017
发表时间: 2018
期刊: 2018 IEEE 26th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM)
影响因子: --
作者:
Festus Hategekimana;Joel Mandebi Mbongue;Md Jubaer Hossain Pantho;C. Bobda
通讯作者: C. Bobda
CPU FPGA 异构云中的安全硬件内核执行
DOI: 10.1109/fpt.2018.00035
发表时间: 2018
期刊: 2018 International Conference on Field-Programmable Technology (FPT)
影响因子: --
作者:
Festus Hategekimana;Joel Mandebi Mbongue;Md Jubaer Hossain Pantho;C. Bobda
通讯作者: C. Bobda
FPGA 通过硬件隔离加速嵌入式系统安全
DOI: --
发表时间: 2020
期刊: Asian Hardware-Oriented Security and Trust Symposium
影响因子: --
作者:
S. Saha;C. Bobda
通讯作者: C. Bobda