A Cautionary Note on Building Multi-tenant Cloud-FPGA as a Secure Infrastructure

被引:0
|
作者
Luo, Yukui [1 ]
Zhang, Yuheng [1 ]
Duan, Shijin [1 ]
Xu, Xiaolin [1 ]
机构
[1] Northeastern Univ, Dept Elect & Comp Engn, Boston, MA 02115 USA
关键词
Security; Cloud-FPGA; Fault Injection; Communication Protocol; Memory;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Security concerns have been raised for multi-tenant cloud-FPGA in many recent works. While these existing works focused on studying the security of diverse cloud-FPGA applications, such as Advanced Encryption Standard (AES), the vulnerabilities associated with the inherent FPGA components are so far under-explored. For the first time, we investigate the robustness of a commonly used communication protocol for data exchange, Advanced eXtensible Interface (AXI), against fault injection attacks in a multi-tenant cloud-FPGA environment. We build an experimental setup with a commodity FPGA development kit and launch fault injection attacks on the shared power distribution network (PDN). To study the in-depth effects of such attacks, we characterize the voltage glitches of different attack patterns in a non-invasive manner, i.e., using electron magnetic measurement. We also mimic the real-world data transmissions using two crafted datasets with different statistical characteristics. The experimental results demonstrate the unique security vulnerabilities of the current AXI protocol in the context of a multi-tenant cloud-FPGA. Last, we discuss potential defense strategies against these vulnerabilities.
引用
收藏
页码:227 / 232
页数:6
相关论文
共 50 条
  • [41] Multi-tenant Verification-as-a-Service (VaaS) in a cloud
    Hu, Kai
    Lei, Lei
    Tsai, Wei-Tek
    SIMULATION MODELLING PRACTICE AND THEORY, 2016, 60 : 122 - 143
  • [42] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    Wang, Haoyu
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2016, 27 (10) : 2851 - 2865
  • [43] Multipath Bandwidth Guarantees for Multi-Tenant Cloud Networking
    Wang, Wei
    Sun, Yi
    Uhlig, Steve
    Fang, Gengfa
    Wang, Nanshu
    Li, Zhongcheng
    2016 IEEE 41ST CONFERENCE ON LOCAL COMPUTER NETWORKS (LCN), 2016, : 442 - 450
  • [44] Deadline Guaranteed Service for Multi-Tenant Cloud Storage
    Liu, Guoxin
    Shen, Haiying
    2015 IEEE INTERNATIONAL CONFERENCE ON PEER-TO-PEER COMPUTING (P2P), 2015,
  • [45] Predictive elastic replication for multi-tenant databases in the cloud
    Sousa, Flavio R. C.
    Moreira, Leonardo O.
    Costa Filho, Jose S.
    Machado, Javam C.
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (16):
  • [46] Personalized Cache Management for Multi-Tenant Cloud Services
    Yuan, Yigui
    Jin, Peiquan
    Wan, Shouhong
    2022 IEEE 42ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2022), 2022, : 1326 - 1327
  • [47] A Multi-Tenant RBAC Model for Collaborative Cloud Services
    Tang, Bo
    Li, Qi
    Sandhu, Ravi
    2013 ELEVENTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2013, : 229 - 238
  • [48] A Scalable VPN Gateway for Multi-Tenant Cloud Services
    Arashloo, Mina Tahmasbi
    Shirshov, Pavel
    Gandhi, Rohan
    Lu, Guohan
    Yuan, Lihua
    Rexford, Jennifer
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2018, 48 (01) : 49 - 55
  • [49] A multi-tenant usage access model for cloud computing
    Liu Z.
    Yang Y.
    Gu W.
    Xia J.
    Computers, Materials and Continua, 2020, 64 (02): : 1233 - 1245
  • [50] Multi-Tenant Data Center and Cloud Networking Evolution
    Bitar, Nabil
    2013 OPTICAL FIBER COMMUNICATION CONFERENCE AND EXPOSITION AND THE NATIONAL FIBER OPTIC ENGINEERS CONFERENCE (OFC/NFOEC), 2013,