错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Fingerprinting and Mapping Cloud FPGA Infrastructures

  • Shanquan Tian,
  • Ilias Giechaskiel,
  • Wenjie Xiong,
  • Jakub Szefer

摘要

In recent years, multiple public cloud FPGA providers have emerged, increasing interest in the FPGA acceleration of cryptographic, financial, and other algorithms. This chapter focuses on the security of the cloud FPGA infrastructure itself and investigates what adversaries can learn about the infrastructure without attacking it or damaging it. The chapter first explores how unique features of FPGAs can be exploited to instantiate physical unclonable functions (PUFs) that can distinguish between otherwise-identical FPGA boards and then further demonstrates how to reverse-engineer the co-location of FPGA boards inside a cloud FPGA server. Specifically, the chapter introduces two ways of fingerprinting cloud FPGAs, one by measuring the decay rate of the DRAM modules on the FPGA boards and the other by instantiating ring oscillators (ROs) inside the FPGA chip that bypass the design rule checks imposed by cloud providers. The co-location of FPGA boards, along with the non-uniform memory access (NUMA) locality of FPGA boards within a server, is deduced by analyzing their mutual PCIe contention during simultaneous use of the PCIe bus. Overall, this chapter thus shows that it is possible to fingerprint and map cloud FPGAs and highlights a need for defense mechanisms that can protect the infrastructures themselves.