PhasePrint: Exposing Cloud FPGA Fingerprints by Inducing Timing Faults at Runtime
Jubayer Mahmod, Matthew Hicks
摘要
Cloud FPGAs, with their scalable and flexible nature, are rapidly gaining traction as go-to hardware acceleration platforms for compute-intensive workloads. However, their increasing adoption introduces unique security challenges. The hardware-level access that FPGAs provide leads to many vulnerabilities, including the leakage of sensitive information through data remanence and the creation of analog-domain covert channels among users. A foundational requirement in these scenarios is the ability to target an individual FPGA; knowing this, cloud vendors prevent FPGA localization by restricting access to low-level information of the underlying hardware. Beyond aiding adversaries, FPGA localization enables defenders to strategically rotate FPGA usage, preventing prolonged exposure that can lead to confidential data leakage due to long-term data remanence.
This paper introduces PhasePrint, a cloud FPGA localization approach using dynamic timing faults in functionally valid circuits. PhasePrint induces timing faults in a specially crafted circuit at runtime and infers delay characteristics from the resulting error pattern-without incorporating information sources blocked by cloud vendors. PhasePrint utilizes an FPGA's internal clock synthesizer to derive a clock pair with a strict phase relationship. By adjusting the phase relationship of these clocks, PhasePrint intentionally causes timing faults at runtime that reveal manufacturing variations among FPGA chips. We transform these fault locations into feature vectors to create device signatures and train a multiclass classifier on a dataset from 300 unique FPGAs across four AWS geographic regions. This entirely on-chip signature extraction method achieves >99% accuracy, operates 13× faster, and costs 92% less than the state-of-the-art.
- This work was completed while the author was at Virginia Tech and is independent of his current employment at AWS Security, Seattle, USA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 被引用 301 次
- C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit LeakageIlias Giechaskiel, Kasper Bonne Rasmussen, Jakub SzeferS&P 2020 · 被引用 74 次
- Pentimento: Data Remanence in Cloud FPGAsColin Drewes, Olivia Weng, Andres Meza, Alric Althoff 等ASPLOS 2024 · 被引用 2 次
相关 Paper
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou 等CCS 2023 · 被引用 4 次
- DeepStrike: Remotely-Guided Fault Injection Attacks on DNN Accelerator in Cloud-FPGAYukui Luo, Cheng Gongye, Yunsi Fei, Xiaolin XuDAC 2021 · 被引用 42 次
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang 等DAC 2022 · 被引用 8 次
- F3: An FPGA-accelerated FaaS FrameworkCharalampos Mainas, Martin Lambeck, Bruno Scheufler, Laurent Bindschaedler 等HPDC 2025 · 被引用 1 次
- Compiler-driven FPGA virtualization with SYNERGYJoshua Landgraf, Tiffany Yang, Will Lin, Christopher J. Rossbach 等ASPLOS 2021 · 被引用 22 次
