Skip to main content
QUICK REVIEW

[논문 리뷰] Information Leakage Between FPGA Long Wires.

Ilias Giechaskiel, Ken Eguro|arXiv (Cornell University)|2016. 11. 27.
Physical Unclonable Functions (PUFs) and Hardware Security참고 문헌 13인용 수 9
한 줄 요약

이 논문은 FPGAs에서 인접하고 연결되지 않은 긴 배선 간의 교차 캐리터링에 의한 지연 변동을 이용하는 새로운 암호 채널을 제시한다. 여기서 논리적 '1'을 전송하는 배선은 인접한 배선의 지연을 감소시킨다. 저자들은 실용적이고 측정 가능한 채널을 입증하였으며, 인접한 배선 상태를 99%의 정확도로 추론할 수 있고, 최대 6 kbps의 대역폭을 달성하였다. 이는 여러 FPGA 패밀리에서 재현 가능하다.

ABSTRACT

Field-Programmable Gate Arrays (FPGAs) are integrated circuits that implement reconfigurable hardware. They are used in modern systems as they are well-suited for creating specialized, highly-optimized integrated circuits without the need to design and manufacture dedicated chips. As the capacity of FPGAs grows, it is increasingly common for designers to incorporate implementations of algorithms and protocols from a range of third-party sources. The monolithic nature of FPGAs means that all on-chip circuits, including third party black-box designs, must share common on-chip infrastructure, such as routing resources. In this paper, we present a covert channel based on a previously unexplored source of information leakage that occurs between adjacent but unconnected, so called wires, on the FPGA chip. We observe that a long wire carrying a logical 1 reduces the delay of nearby wires and that the delay decreases linearly with the length of wires used. This effect leads to a covert channel that can be used for both covert communication between circuits, and for exfiltration of secrets from the chip. We show that the effect is measurable for both static and dynamic signals, and that it can be detected using very small on-board circuits. In our prototype, we are able to correctly infer the logical state of an adjacent long wire over 99% of the time, even without error correction, and for signals that are maintained for as little as $82\mu s$. Using a simple encoding scheme, our covert channel bandwidth is as high as 6kbps. We characterize the covert channel in detail and show that it can be replicated on different generations and families of devices (Virtex 5, Virtex 6, and Artix 7), with different configurations, and is measurable even when multiple competing circuits are present.

연구 동기 및 목표

  • FPGAs에서 인접하고 연결되지 않은 긴 배선 간에 이전에 탐색되지 않은 정보 유출을 조사하기 위해.
  • 교차 캐리터링에 의한 지연 변동을 암호 통신의 근원으로 식별하고 활용하기 위해.
  • 기밀 유출 또는 FPGA 시스템 내 회로 간 통신을 위한 실용적이고 측정 가능한 암호 채널을 입증하기 위해.
  • 다양한 FPGA 장치 패밀리와 구성에서 채널의 강건성과 확장성 평가하기 위해.

제안 방법

  • 논리적 '1' 상태를 갖는 긴 배선에 의해 유도되는 인접한 배선의 지연 변동을 측정하며, 배선 길이와 지연 감소 간의 선형 관계를 활용한다.
  • 인접한 긴 배선에 의해 유도되는 지연 변화를 감지하고 복호화하기 위한 최소한의 온칩 회로를 설계한다.
  • 관측된 지연 변동을 기반으로 데이터를 변조하기 위한 단순한 인코딩 체계를 구현한다.
  • 다양한 구성과 경쟁 회로 부하 조건에서 여러 FPGA 패밀리(Virtex 5, Virtex 6, Artix 7)에서 채널을 검증한다.
  • 측정된 지연 이동을 바탕으로 통계 분석을 통해 인접한 배선의 논리 상태를 높은 정확도로 추론한다.

실험 결과

연구 질문

  • RQ1긴 배선에 의해 유도되는 지연 변동은 FPGA에서 암호 통신 채널로 활용될 수 있는가?
  • RQ2지연 측정을 통해 인접한 긴 배선의 논리 상태는 얼마나 정확하게 추론할 수 있는가?
  • RQ3실제 FPGA 하드웨어에서 이러한 암호 채널의 최대 구현 대역폭는 얼마인가?
  • RQ4이 효과는 다양한 FPGA 장치 패밀리와 동시에 작동하는 회로 활동 조건에서도 지속되는가?

주요 결과

  • 논리적 '1' 상태를 갖는 인접한 긴 배선의 길이가 길어질수록 인접한 배선의 지연이 선형적으로 감소한다.
  • 에러 보정 없이도 인접한 긴 배선의 상태를 99%의 정확도로 추론할 수 있다.
  • 신호가 82 μs 이상이면 측정 가능하여 일시적인 상태도 탐지할 수 있다.
  • 단순한 인코딩 체계를 사용하여 최대 6 kbps의 대역폭을 달성한 암호 채널을 확보하였다.
  • Virtex 5, Virtex 6, Artix 7를 포함한 여러 FPGA 패밀리에서 효과가 일관되게 측정 가능하다.
  • FPGA에 여러 경쟁 회로가 동시에 활성화되어 있어도 채널은 여전히 탐지 가능하다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.