Remote dynamic partial reconfiguration: A threat to Internet-of-Things and embedded security applications

被引:11
|
作者
Johnson, Anju P. [1 ]
Patranabis, Sikhar [2 ]
Chakraborty, Rajat Subhra [2 ]
Mukhopadhyay, Debdeep [2 ]
机构
[1] Univ York, Dept Elect Engn, York YO10 5DD, N Yorkshire, England
[2] Indian Inst Technol, Dept Comp Sci & Engn, Kharagpur 721302, W Bengal, India
关键词
Internet of things; Dynamic Partial Reconfiguration; Field Programmable Gate Array; Hardware Trojan Horse; Hardware security; FAULT;
D O I
10.1016/j.micpro.2017.06.005
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The advent of the Internet of Things has motivated the use of Field Programmable Gate Array (FPGA) devices with Dynamic Partial Reconfiguration (DPR) capabilities for dynamic non-invasive modifications to circuits implemented on the FPGA. In particular, the ability to perform DPR over the network is essential in the context of a growing number of Internet of Things (IoT)-based and embedded security applications. However, the use of remote DPR brings with it a number of security threats that could lead to potentially catastrophic consequences in practical scenarios. In this paper, we demonstrate four examples where the remote DPR capability of the FPGA may be exploited by an adversary to launch Hardware Trojan Horse (HTH) attacks on commonly used security applications. We substantiate the threat by demonstrating remotely-launched attacks on Xilinx FPGA-based hardware implementations of a cryptographic algorithm, a true random number generator, and two processor based security applications - namely, a software implementation of a cryptographic algorithm and a cash dispensing scheme. The attacks are launched by on-the-fly transfer of malicious FPGA configuration bitstreams over an Ethernet connection to perform DPR and leak sensitive information. Finally, we comment on plausible countermeasures to prevent such attacks. (C) 2017 Elsevier B.V. All rights reserved.
引用
收藏
页码:131 / 144
页数:14
相关论文
共 50 条
  • [1] Remote dynamic partial reconfiguration: A threat to Internet-of-Things and embedded security applications
    Johnson, Anju P.
    Patranabis, Sikhar
    Chakraborty, Rajat Subhra
    Mukhopadhyay, Debdeep
    [J]. Microprocessors and Microsystems, 2017, 52 : 131 - 144
  • [2] Remote Dynamic Clock Reconfiguration based Attacks on Internet of Things Applications
    Johnson, Anju P.
    Patranabis, Sikhar
    Chakraborty, Rajat Subhra
    Mukhopadhyay, Debdeep
    [J]. 19TH EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD 2016), 2016, : 431 - 438
  • [3] Dynamic Reconfiguration of Network Protocols for Constrained Internet-of-Things Devices
    Ruckebusch, Peter
    Van Damme, Jo
    De Poorter, Eli
    Moerman, Ingrid
    [J]. INTERNET OF THINGS: IOT INFRASTRUCTURES, IOT 360, PT II, 2016, 170 : 269 - 281
  • [4] Modelling Dynamic Risks in Internet-of-Things Applications
    Samad, Javeria
    Loke, Seng W.
    Reed, Karl
    [J]. PROCEEDINGS OF THE 14TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2017), 2017, : 533 - 534
  • [5] A DYNAMIC PACKING APPROACH FOR INTERNET-OF-THINGS AND LOGISTICS APPLICATIONS
    Eliiyi, Ugur
    Nasibov, Efendi
    [J]. TWMS JOURNAL OF PURE AND APPLIED MATHEMATICS, 2023, 14 (01): : 69 - 90
  • [6] An Embedded Cloud Design for Internet-of-Things
    Laukkarinen, Teemu
    Suhonen, Jukka
    Hannikainen, Andmarko
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2013,
  • [7] Security Testbed for Internet-of-Things Devices
    Siboni, Shachar
    Sachidananda, Vinay
    Meidan, Yair
    Bohadana, Michael
    Mathov, Yael
    Bhairav, Suhas
    Shabtai, Asaf
    Elovici, Yuval
    [J]. IEEE TRANSACTIONS ON RELIABILITY, 2019, 68 (01) : 23 - 44
  • [8] Energy-Adaptive Lightweight Hardware Security Module using Partial Dynamic Reconfiguration for Energy Limited Internet of Things Applications
    Samir, Nagham
    Gamal, Yousef
    E-Zeiny, Ahmed N.
    Mahmoud, Omar
    Shawky, Ahmed
    Saeed, AbdelRahman
    Mostafa, Hassan
    [J]. 2019 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2019,
  • [9] Biometrics for Internet-of-Things Security: A Review
    Yang, Wencheng
    Wang, Song
    Sahri, Nor Masri
    Karie, Nickson M.
    Ahmed, Mohiuddin
    Valli, Craig
    [J]. SENSORS, 2021, 21 (18)
  • [10] Integrating Machine Learning in Embedded Sensor Systems for Internet-of-Things Applications
    Lee, Jongmin
    Stanley, Michael
    Spanias, Andreas
    Tepedelenlioglu, Cihan
    [J]. 2016 IEEE INTERNATIONAL SYMPOSIUM ON SIGNAL PROCESSING AND INFORMATION TECHNOLOGY (ISSPIT), 2016, : 290 - 294