A Secure Boot Framework with Multi-security Features and Logic-Locking Applications for Reconfigurable Logic

A Secure Boot Framework with Multi-security Features and Logic-Locking Applications for Reconfigurable Logic
复制标题

DOI:
10.1007/s41635-021-00123-3
复制
发表时间:
2021-11
期刊:
Journal of Hardware and Systems Security
影响因子:
--
通讯作者:
Geraldine Shirley Nicholas;A. Siddiqui;Sam Reji Joseph;Gregory Williams;F. Saqib
Geraldine Shirley Nicholas;A. Siddiqui;Sam Reji Joseph;Gregory Williams;F. Saqib
中科院分区:
其他
文献类型:
--
作者:
Geraldine Shirley Nicholas;A. Siddiqui;Sam Reji Joseph;Gregory Williams;F. Saqib

文献摘要

被引文献

相似文献

现场可编程门阵列(FPGA)等可重构平台作为一种快速设计的优化平台被广泛使用。新的功能,如动态重新配置,使比特流容易受到克隆/修改攻击,提出了一个安全问题,在今天的异构计算架构。一个广泛采用的对策是通过提供一个安全的靴子机制作为信任根来验证未经修改的固件,以防止攻击者操纵it. In这项工作中,我们提出了一个自动化的安全意识的设计流程方案,通过集成的逻辑锁定方案,安全靴子在Xilinx FPGA。所提出的设计实现了基于FPGA的逻辑混淆,预引导现场设备认证方案,使用ARM TrustZone实现,并启用可信平台模块(TPM)密钥配置。该方案在设计过程中构造了能够保护IP地址的安全特征,并将原语与FPGA的安全靴子过程相结合,增强了比特流的安全性。
Reconfigurable platforms such as field-programmable gate arrays (FPGAs) are widely used as an optimized platform with fast design time. New features such as dynamic reconfiguration make the bitstream vulnerable to clone/modification attacks which raise a security concern in today’s heterogeneous computing architecture. A widely adopted countermeasure is by providing a secure boot mechanism as root-of-trust to authenticate the unmodified firmware to prevent attackers from manipulating it. In this work, we propose an automated security-aware design flow scheme by integrating the logic-locking scheme for secure boot in Xilinx FPGAs. The proposed design implements FPGA-based logic obfuscation, with a pre-boot in-field device authentication scheme implemented using ARM TrustZone enabled with Trusted Platform Modules (TPM) key provisioning. This scheme constructs security features that can protect the IPs during the design process and integrates the primitives with FPGAs secure boot process and enhances bitstream security.