首页> 外文会议>Advances in Information and Computer Security >Bitstream Encryption and Authentication Using AES-GCM in Dynamically Reconfigurable Systems
【24h】

Bitstream Encryption and Authentication Using AES-GCM in Dynamically Reconfigurable Systems

机译:动态可重配置系统中使用AES-GCM进行比特流加密和身份验证

获取原文
获取原文并翻译 | 示例

摘要

A secure and dependable dynamic partial reconfiguration (DPR) system based on the AES-GCM cipher is developed, where the reconfigurable IP cores are protected by encrypting and authenticating their bitstreams with AES-GCM. rnIn DPR systems, bitstream authentication is essential for avoiding fatal damage caused by inadvertent bitstreams. Although encryption-only systems can prevent bitstream cloning and reverse engineering, they cannot prevent erroneous or malicious bitstreams from being accepted as valid. If a bitstream error is detected after the system has already been partly configured, the system must be reconfigured with an errorless bitstream or at worst rebooted since the DPR changes the hardware architecture itself and the system cannot recover itself to the initial state by asserting a reset signal. In this regard, our system can recover from configuration errors without rebooting. To the authors' best knowledge, this is the first DPR system featuring both bitstream protection and error recovery mechanisms. Additionally, we clarify the relationship between the computation time and the bitstream block size, and derive the optimal internal memory size necessary to achieve the highest throughput. Furthermore, we implemented an AES-GCM-based DPR system targeting the Virtex-5 device on an off-the-shelf board, and demonstrated that all functions of bitstream decryption, verification, configuration, and error recovery work correctly. This paper clarifies the throughput, the hardware utilization, and the optimal memory configuration of said DPR system.
机译:开发了基于AES-GCM密码的安全可靠的动态部分重配置(DPR)系统,其中可重配置IP内核通过使用AES-GCM对其比特流进行加密和身份验证得到保护。在DPR系统中,比特流身份验证对于避免因疏忽大意的比特流而造成的致命损害至关重要。尽管仅加密系统可以防止比特流克隆和逆向工程,但是它们不能防止错误或恶意的比特流被视为有效。如果在部分配置系统后检测到比特流错误,则必须使用无错误的比特流重新配置系统,或者在最坏的情况下重新启动系统,因为DPR更改了硬件体系结构本身,并且系统无法通过断言复位将自身恢复到初始状态信号。在这方面,我们的系统无需重新启动即可从配置错误中恢复。据作者所知,这是第一个同时具有比特流保护和错误恢复机制的DPR系统。此外,我们阐明了计算时间与位流块大小之间的关系,并得出了实现最高吞吐量所需的最佳内部存储器大小。此外,我们在现成的板上针对Virtex-5器件实施了基于AES-GCM的DPR系统,并演示了比特流解密,验证,配置和错误恢复的所有功能均正常工作。本文阐明了所述DPR系统的吞吐量,硬件利用率和最佳内存配置。

著录项

  • 来源
  • 会议地点 Kagawa(JP);Kagawa(JP)
  • 作者单位

    National Institute of Advanced Industrial Science and Technology (AIST) 1-1-1 Umezono, Tsukuba-shi, Ibaraki 305-8568, Japan;

    National Institute of Advanced Industrial Science and Technology (AIST) 1-1-1 Umezono, Tsukuba-shi, Ibaraki 305-8568, Japan;

    National Institute of Advanced Industrial Science and Technology (AIST) 1-1-1 Umezono, Tsukuba-shi, Ibaraki 305-8568, Japan;

    National Institute of Advanced Industrial Science and Technology (AIST) 1-1-1 Umezono, Tsukuba-shi, Ibaraki 305-8568, Japan;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 计算机网络;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号