首页> 外文期刊>IEEE transactions on dependable and secure computing >A Secure Exception Mode for Fault-Attack-Resistant Processing
【24h】

A Secure Exception Mode for Fault-Attack-Resistant Processing

机译:防故障攻击处理的安全异常模式

获取原文
获取原文并翻译 | 示例

摘要

Fault attacks are a known threat to secure embedded implementations. We propose a generic technique to detect and react to fault attacks on embedded software. The countermeasure combines a micro-architecture extension in hardware with a secure trap in software. The combined extension leads to a secure exception mode to handle fault attacks. The microprocessor hardware uses a low-level hardware checkpointing mechanism to recover from fault injection. A high-level secure trap in software then enables an application-specific response. The trap is user-defined and can be co-developed with the application. The combination of hardware fault detection and recovery, with a high-level fault response policy in software leads to significantly lower overhead when compared to traditional redundancy-based techniques in hardware or software. We demonstrate a prototype implementation of the proposed secure exception mode. The prototype is based on a modified LEON3 processor and it is able to detect and respond to setup-time violation attacks. We have realized the design in a 180 nm standard cell ASIC with integrated memory. Using several driver application examples, we characterize the software and hardware overhead of the proposed solution, and we compare it to the conventional redundancy-based solutions. In our understanding this is the first proof-in-silicon processor to offer a comprehensive secure exception mode against fault-injection attacks.
机译:故障攻击是对嵌入式实现安全的已知威胁。我们提出了一种通用技术来检测嵌入式软件的故障攻击并对其做出反应。该对策将硬件中的微体系结构扩展与软件中的安全陷阱结合在一起。组合的扩展导致安全异常模式以处理故障攻击。微处理器硬件使用低级硬件检查点机制从故障注入中恢复。然后,软件中的高级安全陷阱将启用特定于应用程序的响应。陷阱是用户定义的,可以与应用程序一起开发。与传统的基于硬件或软件的基于冗余的技术相比,将硬件故障检测和恢复与软件中的高级故障响应策略相结合,可显着降低开销。我们演示了建议的安全异常模式的原型实现。该原型基于改良的LEON3处理器,能够检测并响应建立时间违规攻击。我们已经在具有集成存储器的180 nm标准单元ASIC中实现了该设计。通过使用几个驱动程序应用示例,我们描述了所提出解决方案的软件和硬件开销,并将其与传统的基于冗余的解决方案进行了比较。根据我们的理解,这是第一个提供全面的安全异常模式以防止故障注入攻击的硅证明处理器。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号