论文标题

多租户云FPGA平台中的可信IP解决方案

Trusted IP solution in multi-tenant cloud FPGA platform

论文作者

Ahmed, Muhammed Kawser, Saha, Sujan Kumar, Bobda, Christophe

论文摘要

由于FPGA在每瓦和灵活性方面都优于CPU和GPU等传统处理核心,因此在云和数据中心应用程序中越来越多地使用它们。随着对硬件加速度的需求增加,并逐渐让位于云中的FPGA多租户时,多租户共享带来的安全风险越来越担心。如果空间共享的FPGA可用于许多云租户,则可能会损害FPGA加速应用程序的机密性,完整性和可用性。我们提出了一种基于信任的信任执行机制的根,称为\ textbf {trusttoken},以防止有害软件级攻击者获得未经授权的访问和危害安全性。通过安全的密钥创建和真正的随机来源,\ textbf {trusttoken}创建了一个安全块,可作为基于信任的IP安全性的基础。通过提供关键的安全特性,例如安全,孤立的执行和受信任的用户交互,\ textbf {trusttoken}仅允许在未经信任的第三方IP与其他SOC环境之间的信任连接。建议的方法通过将第三方IP接口连接到\ textBf {trusttoken}控制器以及运行运行时检查IP授权(Token)信号的正确性来实现此目的。在重点是针对未经授权访问和信息泄漏的基于软件的攻击中,我们为FPGA加速云和数据中心提供了高贵的硬件/软件体系结构。

Because FPGAs outperform traditional processing cores like CPUs and GPUs in terms of performance per watt and flexibility, they are being used more and more in cloud and data center applications. There are growing worries about the security risks posed by multi-tenant sharing as the demand for hardware acceleration increases and gradually gives way to FPGA multi-tenancy in the cloud. The confidentiality, integrity, and availability of FPGA-accelerated applications may be compromised if space-shared FPGAs are made available to many cloud tenants. We propose a root of trust-based trusted execution mechanism called \textbf{TrustToken} to prevent harmful software-level attackers from getting unauthorized access and jeopardizing security. With safe key creation and truly random sources, \textbf{TrustToken} creates a security block that serves as the foundation of trust-based IP security. By offering crucial security characteristics, such as secure, isolated execution and trusted user interaction, \textbf{TrustToken} only permits trustworthy connection between the non-trusted third-party IP and the rest of the SoC environment. The suggested approach does this by connecting the third-party IP interface to the \textbf{TrustToken} Controller and running run-time checks on the correctness of the IP authorization(Token) signals. With an emphasis on software-based assaults targeting unauthorized access and information leakage, we offer a noble hardware/software architecture for trusted execution in FPGA-accelerated clouds and data centers.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源