Secure acceleration on cloud-based FPGAs - FPGA enclaves

被引:8
|
作者
Englund, Hakan [1 ]
Lindskog, Niklas [1 ]
机构
[1] Ericsson Research, Lund, Sweden
关键词
Cloud security; Confidential computing; Enclaves; FPGA; Hardware security; System-on-chip;
D O I
10.1109/IPDPSW50202.2020.00026
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
FPGAs are becoming a common sight in cloud environments and new usage paradigms, such as FPGA-as-a-Service, have emerged. This development poses a challenge to traditional FPGA security models, as these are assuming trust between the user and the hardware owner. Currently, the user cannot keep bitstream nor data protected from the hardware owner in an FPGA-as-a-service setting. This paper proposes a security model where the chip manufacturer takes the role of root-of-trust to remedy these security problems. We suggest that the chip manufacturer creates a Public Key Infrastructure (PKI), used for user bitstream protection and data encryption, on each device. The chip manufacturer, rather than the hardware owner, also controls certain security-related peripherals. This allows the user to take control over a predefined part of the programmable logic and set up a protected enclave area. Hence, all user data can be provided in encrypted form and only be revealed inside the enclave area. In addition, our model enables secure and concurrent multi-tenant usage of remote FPGAs. To also consider the needs of the hardware owner, our solution includes bitstream certification and affirming that uploaded bitstreams have been vetted against maliciousness.
引用
收藏
页码:119 / 122
页数:4
相关论文
共 50 条
  • [31] Cloud-Based FPGA Custom Computing Machines for Streaming Applications
    Al-Aghbari, Amran A.
    Elrabaa, Muhammad E. S.
    IEEE ACCESS, 2019, 7 : 38009 - 38019
  • [32] Radiation exposure determination in a secure, cloud-based online environment
    Shirley, Ben C.
    Mucaki, Eliseos J.
    Knoll, Joan H. M.
    Rogan, Peter K.
    RADIATION PROTECTION DOSIMETRY, 2023, 199 (14) : 1465 - 1471
  • [33] Cloud-based Secure Smartcard Healthcare Monitoring and Tracking System
    Moudgil, Kartik
    Maheshwari, Ria
    Parekh, Harshal Bharatkumar
    Devadkar, Kailas
    PROCEEDINGS OF THE 2017 IEEE SECOND INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND COMMUNICATION TECHNOLOGIES (ICECCT), 2017,
  • [34] Secure access control for cloud-based tele medical system
    Gupta, Sunil
    Bansiya, Akansha
    Saini, Mansi
    Sidhu, Amuleek
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2022, 18 (03) : 232 - 239
  • [35] A Secure Cloud-Based NFC Payment Architecture for Small Traders
    El Madhoun, Nour
    Pujolle, Guy
    2016 3RD SMART CLOUD NETWORKS & SYSTEMS (SCNS), 2016,
  • [36] A Framework for Secure Logging in Precision Healthcare Cloud-based Services
    Moghaddam, Parisa
    Iqbal, Shahrear
    Traore, Issa
    2021 IEEE INTERNATIONAL CONFERENCE ON DIGITAL HEALTH (ICDH 2021), 2021, : 212 - 214
  • [37] Secure and Privacy Preserving Protocol for Cloud-Based Vehicular DTNs
    Zhou, Jun
    Dong, Xiaolei
    Cao, Zhenfu
    Vasilakos, Athanasios V.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2015, 10 (06) : 1299 - 1314
  • [38] Easy and Secure Handling of Sensors and Actuators as Cloud-Based Service
    Sanchez-Herrera, Reyes
    Marquez, Marco A.
    Andujar, Jose M.
    IEEE ACCESS, 2020, 8 : 10433 - 10442
  • [39] Multi-user Cloud-Based Secure Keyword Search
    Kermanshahi, Shabnam Kasra
    Liu, Joseph K.
    Steinfeld, Ron
    INFORMATION SECURITY AND PRIVACY, ACISP 2017, PT I, 2017, 10342 : 227 - 247
  • [40] WorkTrue: An Efficient and Secure Cloud-based Workflow Management System
    Fugkeaw, Somchart
    2021 29TH EUROMICRO INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING (PDP 2021), 2021, : 285 - 290