arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.01736cs.CR

部分重配置的致命弱点:7系列ICAP上的光学侧信道泄漏

The Achilles' Heel of Partial Reconfiguration: Optical Side-Channel Leakage on the 7-Series ICAP

Antonio Saavedra, Jan Caspar Marx, Lars Renkes, Jean-Pierre Seifert

AI总结:

针对FPGA部分重配置,提出并演示了基于光学侧信道(光子发射显微镜与电光探测)的攻击,能从ICAP接口非接触提取明文配置数据,证明高级加密方案仍受威胁。

AI中文摘要:

主流FPGA制造商已采用比特流加密来保护敏感配置数据。然而,对于最广泛使用的FPGA系列,针对设备中硬连线且无法修补的保护方案的多种攻击可以绕过或完全破解这些方案,这使得可修补方案变得可取。在本工作中,我们提出了一个AMD提出的用于7系列FPGA比特流保护的非对称密钥加密方案的概念验证实现,该实现使用来自可编程逻辑的部分重配置。我们分析了该实现的安全影响和硬件开销。随后,我们提出并演示了一种光学侧信道攻击,该攻击能够在动态重配置过程中恢复明文配置数据。此攻击利用光子发射显微镜和电光探测技术,首先定位然后非接触式地从ICAP接口提取明文数据,该接口在内部连接可编程逻辑与配置逻辑。我们在AMD XC7A200T器件中定位了ICAP总线,并展示了通过电光探测可以提取其上的数据。我们声称,即使是利用部分重配置和自定义加密引擎的高级加密方案也容易受到光学攻击,因为重配置只能通过硬连线的、易受攻击的配置接口进行。

英文摘要:

Major FPGA manufacturers have incorporated bitstream encryption to protect sensitive configuration data. However, for the most widely used FPGA families, multiple attacks against unpatchable protection schemes hard-wired into the devices can bypass or fully break them, making patchable schemes desirable. In this work, we present a proof-of-concept implementation of an AMD-proposed asymmetric key encryption scheme for bitstream protection for 7-Series FPGAs, using partial reconfiguration from the Programmable Logic. We analyze the security implications and hardware overhead of this implementation. We then propose and demonstrate an optical side-channel attack that is able to recover plain-text configuration data during the dynamic reconfiguration process. This attack leverages Photon Emission Microscopy and Electro-Optical Probing to first locate and then contactlessly extract the plain-text data from the ICAP interface, which internally connects the Programmable Logic with the configuration logic. We located the ICAP buses in an AMD XC7A200T device and show that the data on it can be extracted with Electro-Optical Probing. We claim that even advanced encryption schemes utilizing Partial Reconfiguration and custom cryptographic engines are vulnerable to optical attacks, as reconfiguration is only possible via hard-wired, vulnerable configuration interfaces.

补充信息

↑