arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.15782cs.CRcs.AR

Vogls:用于硅前功率侧信道分析的快速交互式全时序模拟器

Vogls: a Fast Interactive Full-timing Simulator for Pre-silicon Power Side-Channel Analysis

Gijs Burghoorn, Ileana Buhan, Lejla Batina

AI总结:

研究针对侧信道分析中现有模拟器不足的问题,提出Vogls模拟器。它结合编译代码性能、全时序仿真及细粒度控制,有Python接口和高效跟踪收集工作流程,在案例研究中能在多抽象级别成功恢复密钥。

AI中文摘要:

设计抗侧信道攻击的硬件电路越来越依赖于在制造前通过仿真来预测设备泄漏。当前的功能验证模拟器是为长时间的正确性检查运行而设计的,不适用于生成大量带有轻微输入变体的短跟踪集合,而这是侧信道分析所需要的。我们提出了Vogls:一个为侧信道分析构建的开源Verilog模拟器,它是第一个结合编译代码性能、全时序仿真以及对仿真状态进行细粒度控制的模拟器。Vogls在模拟带时序注释的门级AES设计时比Icarus Verilog快5.9倍,在PicoRV32 RTL设计上比Verilator仅慢30%,同时还提供更精确的时序模型。Vogls提供了一个Python接口,允许在不修改硬件设计的情况下在感兴趣的点暂停、分叉、检查和变异仿真,从而保持时序和泄漏特性。此外,跟踪收集工作流程只需运行一次设置代码并在感兴趣的点分叉,无需为每个跟踪从复位重新仿真。一个案例研究展示了Vogls在差分功率分析攻击中的应用,它在RTL、GTL和全时序GTL抽象级别成功恢复了密钥。

英文摘要:

Designing hardware circuits resistant to side-channel attacks increasingly relies on simulation to predict device leakage before fabrication. Current functional verification simulators are designed for extended correctness-checking runs and are ill-suited for producing large numbers of short trace collections with slight input variants needed for side-channel analysis. We present Vogls: an open-source Verilog simulator built for side-channel analysis, that is the first simulator to combine compiled-code performance, full-timing simulation, and fine-grained control over the simulation state. Vogls simulates a timing annotated gate-level AES design 5.9 times faster than Icarus Verilog and is only 30% slower than Verilator on a PicoRV32 RTL design while also offering a more accurate timing model. Vogls provides a Python interface that allows simulations to be paused, forked, inspected, and mutated around points-of-interest without modifying the hardware design and thereby preserving timing and leakage characteristics. Furthermore, a trace-collection workflow runs setup code once and forks at the point-of-interest, eliminating the need to re-simulate from reset for every trace. A case study demonstrates Vogls on a differential power analysis attack that successfully recovers the key at RTL, GTL and full-timing GTL abstraction levels.

↑