【24h】

Securing Virtualized FPGAs for an Untrusted Cloud

机译:为不受信任的云保护虚拟化FPGA

获取原文

摘要

The business with cloud computing is steadily growing. More and more data center providers offer reconfigurable hardware to accelerate workloads in an energy efficiency way. Various frameworks for virtualization of these devices have been proposed, but security concerns of potential users have mostly been neglected. Other approaches focused on security, but did not provide the required virtualization capabilities. In this paper we extend an existing FPGA virtualization framework with crucial security features, including strong AES encryption and efficient elliptic curve cryptography. But only with the use of a TLS based protocol does this combination achieve a high level of security. It enables the confidential and secure transfer of sensitive data, including the configuration bitstreams of virtual FPGAs. They are decrypted by the FPGA hypervisor and checked for malicious modifications to protect other vFPGAs. This way the device can be virtualized while being secured and no sensible data is exposed to potentially vulnerable software.
机译:云计算的业务稳步增长。越来越多的数据中心提供商提供可重新配置的硬件,以通过能效方式加速工作负载。已经提出了这些设备虚拟化的各种框架,但潜在用户的安全问题主要被忽视。其他侧重于安全性的方法,但没有提供所需的虚拟化功能。在本文中,我们将现有的FPGA虚拟化框架扩展了具有重要安全性功能,包括强AES加密和高效的椭圆曲线密码学。但只有在使用基于TLS的协议的情况下,这种组合可以实现高水平的安全性。它能够机密和安全传输敏感数据,包括虚拟FPGA的配置比特流。它们由FPGA虚拟机管理程序解密,并检查了恶意修改以保护其他VFPGA。这样,设备可以在安全的同时虚拟化,并且没有明智的数据暴露于潜在的易受攻击的软件。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号