A Cautionary Note on Building Multi-tenant Cloud-FPGA as a Secure Infrastructure

被引:0
|
作者
Luo, Yukui [1 ]
Zhang, Yuheng [1 ]
Duan, Shijin [1 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Dept Elect & Comp Engn, Boston, MA 02115 USA
关键词
Security; Cloud-FPGA; Fault Injection; Communication Protocol; Memory;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security concerns have been raised for multi-tenant cloud-FPGA in many recent works. While these existing works focused on studying the security of diverse cloud-FPGA applications, such as Advanced Encryption Standard (AES), the vulnerabilities associated with the inherent FPGA components are so far under-explored. For the first time, we investigate the robustness of a commonly used communication protocol for data exchange, Advanced eXtensible Interface (AXI), against fault injection attacks in a multi-tenant cloud-FPGA environment. We build an experimental setup with a commodity FPGA development kit and launch fault injection attacks on the shared power distribution network (PDN). To study the in-depth effects of such attacks, we characterize the voltage glitches of different attack patterns in a non-invasive manner, i.e., using electron magnetic measurement. We also mimic the real-world data transmissions using two crafted datasets with different statistical characteristics. The experimental results demonstrate the unique security vulnerabilities of the current AXI protocol in the context of a multi-tenant cloud-FPGA. Last, we discuss potential defense strategies against these vulnerabilities.
引用
收藏
页码:227 / 232
页数:6
相关论文
共 50 条
  • [21] Building a multi-tenant cloud service from legacy code with Docker containers
    Slominski, Aleksander
    Muthusamy, Vinod
    Khalaf, Rania
    2015 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2015), 2015, : 394 - 396
  • [22] Quasi-optimal Data Placement for Secure Multi-tenant Data Federation on the Cloud
    Kang, Qi
    Liu, Ji
    Yang, Sijia
    Xiong, Haoyi
    An, Haozhe
    Li, Xingjian
    Feng, Zhi
    Wang, Licheng
    Dou, Dejing
    2020 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2020, : 1954 - 1963
  • [23] Analyzing Multi-Tenant Cloud Services' Accountability
    Masmoudi, Fatma
    Sellami, Mohamed
    Loulou, Monia
    Kacem, Ahmed Hadj
    2015 IEEE 12TH INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2015, : 239 - 244
  • [24] Performance Study of Multi-tenant Cloud FPGAs
    Mbongue, Joel Mandebi
    Saha, Sujan Kumar
    Bobda, Christophe
    2021 IEEE INTERNATIONAL PARALLEL AND DISTRIBUTED PROCESSING SYMPOSIUM WORKSHOPS (IPDPSW), 2021, : 168 - 171
  • [25] Accountability management for multi-tenant cloud services
    Masmoudi, Fatma
    Sellami, Mohamed
    Loulou, Monia
    Kacem, Ahmed Hadj
    INTERNATIONAL JOURNAL OF GRID AND UTILITY COMPUTING, 2019, 10 (02) : 141 - 158
  • [26] Framework for Management of Multi-tenant Cloud Environments
    Beranek, Marek
    Kovar, Vladimir
    Feuerlicht, George
    CLOUD COMPUTING - CLOUD 2018, 2018, 10967 : 309 - 322
  • [27] Elastic Scaling in the Cloud: A Multi-Tenant Perspective
    Rameshan, Navaneeth
    Liu, Ying
    Navarro, Leandro
    Vlassov, Vladimir
    2016 IEEE 36TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS WORKSHOPS (ICDCSW 2016), 2016, : 25 - 30
  • [28] Network Function Virtualization in the Multi-Tenant Cloud
    Yu, Ruozhou
    Xue, Guoliang
    Kilari, Vishnu Teja
    Zhang, Xiang
    IEEE NETWORK, 2015, 29 (03): : 42 - 47
  • [29] A Multi-Tenant Framework for Cloud Container Services
    Zheng, Chao
    Zhuang, Qinghui
    Guo, Fei
    2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 359 - 369
  • [30] Mitigating Electrical-level Attacks towards Secure Multi-Tenant FPGAs in the Cloud
    Krautter, Jonas
    Gnad, Dennis R. E.
    Tahoori, Mehdi B.
    ACM TRANSACTIONS ON RECONFIGURABLE TECHNOLOGY AND SYSTEMS, 2019, 12 (03)