Leaky Wires: Information Leakage and Covert Communication Between FPGA Long Wires

Leaky Wires: Information Leakage and Covert Communication Between FPGA Long Wires
复制标题

漏线:FPGA 长线之间的信息泄露和隐蔽通信

DOI:
10.1145/3196494.3196518
复制
发表时间:
2016
期刊:
Proceedings of the 2018 on Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Ken Eguro
Ken Eguro
中科院分区:
--
文献类型:
--
作者:
Ilias Giechaskiel;Kasper Bonne Rasmussen;Ken Eguro

文献摘要

参考文献

被引文献

相似文献

现场编程的门阵列(FPGA)是实现可重构硬件的集成电路。它们用于现代系统,创建了专业,高度优化的集成电路,而无需设计和制造专用的芯片。随着FPGA的能力的增长,设计人员越来越普遍地结合来自一系列第三方来源的算法和协议的实现。 FPGA的整体性质意味着所有芯片电路(包括第三方黑盒设计)都必须共享芯片上共同的芯片基础架构,例如路由资源。在本文中,我们观察到,携带逻辑1的“长”路由线减少了FPGA互连中其他相邻但未连接的长电线的传播延迟,从而泄漏了有关其状态的信息。我们利用了这种效果,并提出了一个通信通道,该通信通道可用于电路之间的秘密传播,并用于从芯片中删除秘密。我们表明,对于静态和动态信号,效果都是可测量的,并且可以使用非常小的板电路来检测。在我们的原型中,我们能够在99%的时间内正确地推断相邻长线的逻辑状态,即使没有误差校正,也可以正确地推断出维持在82US的信号。使用曼彻斯特编码方案,我们的通道带宽高达6kbps。我们详细表征了该通道,并表明即使存在多个竞争电路,也可以在Xilinx设备的不同世代和家族中复制(Virtex 5,Virtex 6和Artix 7)。最后,我们提出的对策可以由系统和工具设计人员部署,以减少此信息泄漏的影响。
Field-Programmable Gate Arrays (FPGAs) are integrated circuits that implement reconfigurable hardware. They are used in modern systems, creating specialized, highly-optimized integrated circuits without the need to design and manufacture dedicated chips. As the capacity of FPGAs grows, it is increasingly common for designers to incorporate implementations of algorithms and protocols from a range of third-party sources. The monolithic nature of FPGAs means that all on-chip circuits, including third party black-box designs, must share common on-chip infrastructure, such as routing resources. In this paper, we observe that a "long" routing wire carrying a logical 1 reduces the propagation delay of other adjacent but unconnected long wires in the FPGA interconnect, thereby leaking information about its state. We exploit this effect and propose a communication channel that can be used for both covert transmissions between circuits, and for exfiltration of secrets from the chip. We show that the effect is measurable for both static and dynamic signals, and that it can be detected using very small on-board circuits. In our prototype, we are able to correctly infer the logical state of an adjacent long wire over 99% of the time, even without error correction, and for signals that are maintained for as little as 82us. Using a Manchester encoding scheme, our channel bandwidth is as high as 6kbps. We characterize the channel in detail and show that it is measurable even when multiple competing circuits are present and can be replicated on different generations and families of Xilinx devices (Virtex 5, Virtex 6, and Artix 7). Finally, we propose countermeasures that can be deployed by systems and tools designers to reduce the impact of this information leakage.
DOI: 10.1109/fccm.2011.36
发表时间: 2011
期刊: 2011 IEEE 19th Annual International Symposium on Field-Programmable Custom Computing Machines
影响因子: --
作者:
Koester;Hagemeyer;Porrmann;Santambrogio;Rueckert
通讯作者: Rueckert