Trusted IP Solution in Multi-tenant Cloud FPGA Platform

Trusted IP Solution in Multi-tenant Cloud FPGA Platform
复制标题

DOI:
10.1109/wf-iot54382.2022.10152167
复制
发表时间:
2022-09
期刊:
2022 IEEE 8th World Forum on Internet of Things (WF-IoT)
影响因子:
--
通讯作者:
M. Ahmed;S. Saha;C. Bobda
M. Ahmed;S. Saha;C. Bobda
中科院分区:
其他
文献类型:
--
作者:
M. Ahmed;S. Saha;C. Bobda

文献摘要

被引文献

相似文献

由于FPGA在每瓦性能和灵活性方面优于CPU和GPU等传统处理核心,因此它们越来越多地用于云和数据中心应用。随着对硬件加速需求的增加,人们越来越担心多租户共享带来的安全风险,并逐渐让位于云中的FPGA多租户。如果空间共享的FPGA可供许多云租户使用,则FPGA加速应用程序的机密性、完整性和可用性可能会受到影响。提出了一种基于信任根的可信执行机制TrustToken,以防止恶意的软件级攻击者获得未经授权的访问,从而危及系统的安全。通过安全的密钥创建和真正的随机源,TrustToken创建了一个安全块,作为基于信任的IP安全的基础。通过提供关键的安全特性,例如安全、隔离执行和可信用户交互,TrustToken仅允许在不可信的第三方IP和SoC环境的其余部分之间建立可信连接。建议的方法通过将第三方IP接口连接到TrustToken Controller并运行运行时检查IP授权(令牌)信号的正确性来实现这一点。我们强调针对未经授权访问和信息泄漏的基于软件的攻击,提供了一种高贵的硬件/软件架构,可在FPGA加速的云和数据中心中实现可信执行。
Because FPGAs outperform traditional processing cores like CPUs and GPUs in terms of performance per watt and flexibility, they are being used more and more in cloud and data center applications. There are growing worries about the security risks posed by multi-tenant sharing as the demand for hardware acceleration increases and gradually gives way to FPGA multi-tenancy in the cloud. The confidentiality, integrity, and availability of FPGA-accelerated applications may be compromised if space-shared FPGAs are made available to many cloud tenants. We propose a root of trust-based trusted execution mechanism called TrustToken to prevent harmful software-level attackers from getting unauthorized access and jeopardizing security. With safe key creation and truly random sources, TrustToken creates a security block that serves as the foundation of trust-based IP security. By offering crucial security characteristics, such as secure, isolated execution and trusted user interaction, TrustToken only permits trustworthy connection between the non-trusted third-party IP and the rest of the SoC environment. The suggested approach does this by connecting the third-party IP interface to the TrustToken Controller and running run-time checks on the correctness of the IP authorization(Token) signals. With an emphasis on software-based assaults targeting unauthorized access and information leakage, we offer a noble hardware/software architecture for trusted execution in FPGA-accelerated clouds and data centers.