Secure acceleration on cloud-based FPGAs - FPGA enclaves

被引:8
|
作者
Englund, Hakan [1 ]
Lindskog, Niklas [1 ]
机构
[1] Ericsson Research, Lund, Sweden
关键词
Cloud security; Confidential computing; Enclaves; FPGA; Hardware security; System-on-chip;
D O I
10.1109/IPDPSW50202.2020.00026
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
FPGAs are becoming a common sight in cloud environments and new usage paradigms, such as FPGA-as-a-Service, have emerged. This development poses a challenge to traditional FPGA security models, as these are assuming trust between the user and the hardware owner. Currently, the user cannot keep bitstream nor data protected from the hardware owner in an FPGA-as-a-service setting. This paper proposes a security model where the chip manufacturer takes the role of root-of-trust to remedy these security problems. We suggest that the chip manufacturer creates a Public Key Infrastructure (PKI), used for user bitstream protection and data encryption, on each device. The chip manufacturer, rather than the hardware owner, also controls certain security-related peripherals. This allows the user to take control over a predefined part of the programmable logic and set up a protected enclave area. Hence, all user data can be provided in encrypted form and only be revealed inside the enclave area. In addition, our model enables secure and concurrent multi-tenant usage of remote FPGAs. To also consider the needs of the hardware owner, our solution includes bitstream certification and affirming that uploaded bitstreams have been vetted against maliciousness.
引用
收藏
页码:119 / 122
页数:4
相关论文
共 50 条
  • [1] Secure Computing Enclaves Using FPGAs
    Elrabaa, M. E. S.
    Al-Asli, M.
    Abu-Amara, M.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2021, 18 (02) : 593 - 604
  • [2] DGCNN on FPGA: Acceleration of the Point Cloud Classifier Using FPGAs
    Jamali Golzar, Saleh
    Karimian, Ghader
    Shoaran, Maryam
    Fattahi Sani, Mohammad
    CIRCUITS SYSTEMS AND SIGNAL PROCESSING, 2023, 42 (02) : 748 - 779
  • [3] DGCNN on FPGA: Acceleration of the Point Cloud Classifier Using FPGAs
    Saleh Jamali Golzar
    Ghader Karimian
    Maryam Shoaran
    Mohammad Fattahi Sani
    Circuits, Systems, and Signal Processing, 2023, 42 : 748 - 779
  • [4] ShEF: Shielded Enclaves for Cloud FPGAs
    Zhao, Mark
    Gao, Mingyu
    Kozyrakis, Christos
    ASPLOS '22: PROCEEDINGS OF THE 27TH ACM INTERNATIONAL CONFERENCE ON ARCHITECTURAL SUPPORT FOR PROGRAMMING LANGUAGES AND OPERATING SYSTEMS, 2022, : 1070 - 1085
  • [5] Fight periodontitis with secure cloud-based
    不详
    BRITISH DENTAL JOURNAL, 2018, 225 (04) : 367 - 367
  • [6] Fight periodontitis with secure cloud-based
    British Dental Journal, 2018, 225 : 367 - 367
  • [7] Cloud-based Secure Logger For Medical Devices
    Hung Nguyen
    Acharya, Bipeen
    Ivanov, Radoslav
    Haeberlen, Andreas
    Phan, Linh T. X.
    Sokolsky, Oleg
    Walker, Jesse
    Weimer, James
    Hanson, William
    Lee, Insup
    2016 IEEE FIRST INTERNATIONAL CONFERENCE ON CONNECTED HEALTH: APPLICATIONS, SYSTEMS AND ENGINEERING TECHNOLOGIES (CHASE), 2016, : 89 - 94
  • [8] SECURE CLOUD-BASED SOLUTIONS FOR A TELECARDIOLOGY SERVICE
    de la Torre, I.
    Gongora-Alonso, S.
    Lopez-Coronado, M.
    Herreros, J.
    BRITISH JOURNAL OF SURGERY, 2019, 106 : 14 - 14
  • [9] LUT based Secure Cloud Computing - an Implementation using FPGAs
    Xu, Lei
    Khoa, Pham Dang
    Kim, Seung Hun
    Ro, Won Woo
    Shi, Weidong
    2014 INTERNATIONAL CONFERENCE ON RECONFIGURABLE COMPUTING AND FPGAS (RECONFIG), 2014,
  • [10] A Secure Cloud-Based Nfc Mobile Payment Protocol
    Pourghomi, Pardis
    Saeed, Muhammad Qasim
    Ghinea, Gheorghita
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2014, 5 (10) : 24 - 31