面向多厂商FPGA云部署的基于身份认证的安全聚合加密
Secure Aggregate Encryption with Identity-Based Authentication for Multi-Vendor FPGA Cloud Deployment
浏览论文内容
中文总结 AI 辅助
本文提出SAEID框架,将聚合授权、基于身份认证等功能集成,实现异构多厂商FPGA云的安全部署,性能可扩展且开销可控。
中文摘要 AI 辅助
在异构多厂商云基础设施中安全部署FPGA比特流,需要在整个部署生命周期内实现可扩展授权、设备访问认证以及比特流保护。现有方法通常通过独立机制实现这些功能,增加了协调和密钥管理需求。本文提出SAEID,一种安全FPGA部署框架,在基于配对的密码框架内集成聚合授权、无证书基于身份的设备认证以及身份绑定的比特流验证,使用对称密码进行会话绑定,并采用AES 256 GCM实现比特流保护。SAEID基于聚合加密方案AgEID构建,该方案支持授权FPGA设备的单独解密;SAEID通过支持多个FPGA厂商和IP提供商、感知能力的授权以及动态设备成员,将底层框架扩展到异构多厂商部署。SAEID可防止设备撤销后对未来部署的未授权访问,以及新注册设备对先前部署的未授权访问,同时在每个厂商域内保持恒定大小的聚合密文和单独解密。实验结果验证了SAEID的实际性能:基于身份的设备认证耗时约4.35毫秒,设备添加的成员更新耗时4.95至5.09微秒;聚合加密组件随设备集规模增大呈现可扩展行为;完整SAEID软件解密路径在物理ZC702 Cortex A9平台上验证,耗时191.126毫秒。这些结果表明,SAEID为安全多厂商FPGA部署提供了具有受限认证和动态成员开销的可扩展聚合授权。
英文摘要
Secure deployment of FPGA bitstreams in heterogeneous multi-vendor cloud infrastructures requires scalable authorization, authenticated device access, and bitstream protection throughout the deployment lifecycle. Existing approaches typically address these functions through separate mechanisms, increasing coordination and key management requirements. This paper presents SAEID, a secure FPGA deployment framework that integrates aggregate authorization, certificate-free identity-based device authentication, and identity bound bitstream verification within a pairing based cryptographic framework, with symmetric cryptography used for session binding and AES 256 GCM based bitstream protection. Building on AgEID, an aggregate encryption scheme that enables individual decryption for authorized FPGA devices, SAEID extends the underlying framework to heterogeneous multi vendor deployments by supporting multiple FPGA vendors and IP providers, capability-aware authorization, and dynamic device membership. SAEID provides protection against unauthorized access to future deployments after device revocation and to prior deployments by newly enrolled devices, while retaining constant-size aggregate ciphertexts within each vendor domain and individual decryption. Experimental results demonstrate the practical performance of SAEID, with identity-based device authentication completing in approximately 4.35 ms and device membership updates requiring 4.95 to 5.09 micro seconds for device addition. The aggregate-encryption component exhibits scalable behavior with increasing device-set size. The complete SAEID software decryption path was also validated on a physical ZC702 Cortex A9 platform, requiring 191.126 ms. These results demonstrate scalable aggregate authorization with bounded authentication and dynamic-membership overhead for secure multi-vendor FPGA deployment.
发表机构
- University of Calcutta(加尔各答大学)
- University College Cork(科克大学学院)
- Indian Statistical Institute(印度统计研究所)
机构由 AI 辅助整理,请以论文原文为准。