PUFMon: Security monitoring of FPGAs using physically unclonable functions

PUFMon: Security monitoring of FPGAs using physically unclonable functions
复制标题

PUFMon:使用物理上不可克隆的功能对 FPGA 进行安全监控

DOI:
10.1109/iolts.2017.8046216
复制
发表时间:
2017
期刊:
2017 IEEE 23rd International Symposium on On-Line Testing and Robust System Design (IOLTS)
影响因子:
--
通讯作者:
C. Boit
C. Boit
中科院分区:
--
文献类型:
--
作者:
Shahin Tajik;Julian Fietkau;Heiko Lohrke;Jean;C. Boit

文献摘要

被引文献

相似文献

主流FPGA和可编程SoC在配置和运行时采用不同的对策来减轻物理攻击。然而,它已被证明,先进的主动攻击技术,如激光电压探测,仍然可以绕过位流保护在配置阶段。另一方面,FPGA厂商提供的安全监控IP核虽然可以保证应用运行时的物理安全,但在配置时却无法检测到此类攻击。在这项工作中,我们提出了一种新的方法,使用PUF作为物理传感器来监控FPGA的完整性,以防止主动攻击。在现有的PUF架构的小修改,使我们能够设计一个基于PUF的安全方案,它可以部署在同一时间的完整性监测和认证/密钥生成。我们评估我们的框架对一系列强大的攻击,如光学探测和故障攻击的有效性。我们进一步讨论了如何在FPGA的部分重配置能力的比特流配置过程中,可以部署这个方案。
Mainstream FPGAs and programmable SoCs employ different countermeasures during configuration and runtime to mitigate physical attacks. However, it has been demonstrated that sophisticated active attack techniques, such as laser voltage probing, can still bypass the bitstream protections during the configuration phase. On the other hand, although the security monitoring IP cores provided by FPGA vendors can ensure the physical security during the runtime of applications, they are unable to detect such attacks during configuration. In this work, we propose a novel approach to using PUFs as physical sensors to monitor the integrity of FPGAs against active attacks. Small modifications in existing PUF architectures enable us to design a PUF-based security scheme, which can be deployed for integrity monitoring and authentication/key generation at the same time. We evaluate the effectiveness of our framework against a range of powerful attacks, such as optical probing and fault attacks. We further discuss how this scheme can be deployed during bitstream configuration in FPGAs with partial reconfiguration capability.