A Cautionary Note on Building Multi-tenant Cloud-FPGA as a Secure Infrastructure

被引:0
|
作者
Luo, Yukui [1 ]
Zhang, Yuheng [1 ]
Duan, Shijin [1 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Dept Elect & Comp Engn, Boston, MA 02115 USA
关键词
Security; Cloud-FPGA; Fault Injection; Communication Protocol; Memory;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security concerns have been raised for multi-tenant cloud-FPGA in many recent works. While these existing works focused on studying the security of diverse cloud-FPGA applications, such as Advanced Encryption Standard (AES), the vulnerabilities associated with the inherent FPGA components are so far under-explored. For the first time, we investigate the robustness of a commonly used communication protocol for data exchange, Advanced eXtensible Interface (AXI), against fault injection attacks in a multi-tenant cloud-FPGA environment. We build an experimental setup with a commodity FPGA development kit and launch fault injection attacks on the shared power distribution network (PDN). To study the in-depth effects of such attacks, we characterize the voltage glitches of different attack patterns in a non-invasive manner, i.e., using electron magnetic measurement. We also mimic the real-world data transmissions using two crafted datasets with different statistical characteristics. The experimental results demonstrate the unique security vulnerabilities of the current AXI protocol in the context of a multi-tenant cloud-FPGA. Last, we discuss potential defense strategies against these vulnerabilities.
引用
收藏
页码:227 / 232
页数:6
相关论文
共 50 条
  • [31] Poster: Secure NFV Infrastructure based on Software Fault Isolation Considering Multi-Tenant Environment
    Koizumi, Soki
    Kondo, Takao
    Teraoka, Fumio
    PROCEEDINGS OF THE 2024 THE 22ND ANNUAL INTERNATIONAL CONFERENCE ON MOBILE SYSTEMS, APPLICATIONS AND SERVICES, MOBISYS 2024, 2024, : 650 - 651
  • [32] Multi-Tenant, Secure, Load Disseminated SaaS Architecture
    Pervez, Zeeshan
    Lee, Sungyoung
    Lee, Young-Koo
    12TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY: ICT FOR GREEN GROWTH AND SUSTAINABLE DEVELOPMENT, VOLS 1 AND 2, 2010, : 214 - 219
  • [33] Offloading data plane functions to the multi-tenant Cloud Infrastructure using P4
    Osinski, Tomasz
    Tarasiuk, Halina
    Picard, Roland
    2019 ACM/IEEE SYMPOSIUM ON ARCHITECTURES FOR NETWORKING AND COMMUNICATIONS SYSTEMS (ANCS), 2019,
  • [34] SS-AXI: Secure and Safe Access Control Mechanism for Multi-Tenant Cloud FPGAs
    Karabulut, Emre
    Awad, Amro
    Aysu, Aydin
    2023 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS, ISCAS, 2023,
  • [35] Towards Efficient and Secure Data Storage in Multi-Tenant Cloud-Based CRM Solutions
    Vuong, Julia
    Braun, Simone
    2015 IEEE/ACM 8TH INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING (UCC), 2015, : 612 - 617
  • [36] MULTI-TENANT ACCESS CONTROL MODEL FOR CLOUD MANUFACTURING
    Chen, Qianwen
    Zhou, Zude
    Zhang, Xiaomei
    Jiang, Xuemei
    PROCEEDINGS OF THE ASME 12TH INTERNATIONAL MANUFACTURING SCIENCE AND ENGINEERING CONFERENCE - 2017, VOL 3, 2017,
  • [37] Multi-Tenant services Monitoring for Accountability in Cloud Computing
    Masmoudi, Fatma
    Loulou, Monia
    Kacem, Ahmed Hadj
    2014 IEEE 6TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2014, : 620 - 625
  • [38] EdgeNet: A Multi-Tenant and Multi-Provider Edge Cloud
    Senel, Berat Can
    Mouchet, Maxime
    Cappos, Justin
    Fourmaux, Olivier
    Friedman, Timur
    McGeer, Rick
    PROCEEDINGS OF THE 4TH INTERNATIONAL WORKSHOP ON EDGE SYSTEMS, ANALYTICS AND NETWORKING (EDGESYS'21), 2021, : 49 - 54
  • [39] Addressing security compatibility for multi-tenant cloud services
    Khan, Khaled M.
    Erradi, Abdelkarim
    Alhazbi, Saleh
    Han, Jun
    INTERNATIONAL JOURNAL OF COMPUTER APPLICATIONS IN TECHNOLOGY, 2013, 47 (04) : 370 - 378
  • [40] Cloud Computing Architectures Based Multi-Tenant IDS
    Khalil, Elmahdi
    Enniari, Saad
    Zbakh, Mostapha
    2013 NATIONAL SECURITY DAYS (JNS3), 2013,