Active Fences against Voltage-based Side Channels in Multi-Tenant FPGAs

Active Fences against Voltage-based Side Channels in Multi-Tenant FPGAs
复制标题

针对多租户 FPGA 中基于电压的侧通道的有源围栏

DOI:
--
复制
发表时间:
2019
期刊:
2019 IEEE/ACM International Conference on Computer-Aided Design (ICCAD)
影响因子:
--
通讯作者:
M. Tahoori
M. Tahoori
中科院分区:
--
文献类型:
--
作者:
Jonas Krautter;Dennis R. E. Gnad;Falk Schellenberg;A. Moradi;M. Tahoori

文献摘要

被引文献

相似文献

动态和局部重构以及硬件并行性使得fpga作为虚拟化加速器具有吸引力。然而,最近有研究表明,多租户fpga容易受到来自恶意用户的远程侧信道攻击(SCA),允许他们在没有与受害者核心的逻辑连接的情况下提取密钥。针对此类攻击的典型缓解措施是隐藏和屏蔽方案,以增加攻击者在侧信道测量方面的努力。然而,它们需要为特定的算法、硬件实现和映射进行大量的努力和裁剪。在本文中,我们展示了一种针对基于电压的SCA的隐藏对策,该对策可以集成到任何实现中,而无需对受保护模块进行修改或裁剪。我们在受害者和攻击者电路之间放置了一个适当映射的环形振荡器有源围栏,作为基于fpga的传感器的反馈,从而减少了侧通道泄漏。我们基于Lattice ECP5 FPGA和AES-128模块的实验结果表明,成功的密钥恢复需要两个数量级以上的迹线,而不需要修改底层加密模块。
Dynamic and partial reconfiguration together with hardware parallelism make FPGAs attractive as virtualized accelerators. However, recently it has been shown that multi-tenant FPGAs are vulnerable to remote side-channel attacks (SCA) from malicious users, allowing them to extract secret keys without a logical connection to the victim core. Typical mitigations against such attacks are hiding and masking schemes, to increase attackers' efforts in terms of side-channel measurements. However, they require significant efforts and tailoring for a specific algorithm, hardware implementation and mapping. In this paper, we show a hiding countermeasure against voltage-based SCA that can be integrated into any implementation, without requiring modifications or tailoring to the protected module. We place a properly mapped Active Fence of ring oscillators between victim and attacker circuit, enabled as a feedback of an FPGA-based sensor, leading to reduced side-channel leakage. Our experimental results based on a Lattice ECP5 FPGA and an AES-128 module show that two orders of magnitude more traces are needed for a successful key recovery, while no modifications to the underlying cryptographic module are necessary.