首页> 外文会议>International Conference on Reconfigurable Computing and FPGAs >A single-chip solution for the secure remote configuration of FPGAs using bitstream compression
【24h】

A single-chip solution for the secure remote configuration of FPGAs using bitstream compression

机译:使用位流压缩实现FPGA的安全远程配置的单芯片解决方案

获取原文

摘要

This paper presents a system that allows the secure remote configuration of an FPGA, which is assumed to be the only device in the secure zone. This means that no security critical information passes over the borders of the FPGA chip, reducing the opportunities for an attacker to break the system. In particular, bitstream compression in combination with partial reconfiguration is used to avoid the use of an external memory for the storage of the bitstream. Additionally there is no need for an external processor for the transfer of the bitstream. Nevertheless, our solution contains a mechanism that verifies the integrity of the complete bitstream before starting the configuration. This prevents attempts to load unqualified bitstreams and reduces the downtime. The integrity check, the decryption, the authentication of the origin and the freshness check of the bitstream are performed inside the FPGA while its current configuration is still active. The contribution of this work is that it presents the first complete working system for the secure remote configuration of FPG As, consisting of a single FPGA chip and an initiating server, given that the integrity of the complete bitstream is verified before configuration. This paper gives details on the overall system and the FPGA architecture, which have been implemented and tested.
机译:本文提出了一种系统,该系统允许对FPGA进行安全的远程配置,该系统被认为是安全区域中的唯一设备。这意味着没有安全关键信息会越过FPGA芯片的边界,从而减少了攻击者破坏系统的机会。特别地,结合部分重新配置的比特流压缩被用于避免使用外部存储器来存储比特流。另外,不需要外部处理器来传输比特流。不过,我们的解决方案包含一种机制,可以在开始配置之前验证完整位流的完整性。这样可以防止尝试加载不合格的比特流,并减少停机时间。完整性检查,解密,源的身份验证和位流的新鲜度检查在FPGA内部执行,同时其当前配置仍处于活动状态。这项工作的贡献在于,它提出了用于FPG As的安全远程配置的第一个完整的工作系统,该系统由单个FPGA芯片和一个启动服务器组成,前提是完整的比特流的完整性在配置前已得到验证。本文详细介绍了已实现并经过测试的整个系统和FPGA架构。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号