C3APSULe: Cross-FPGA Covert-Channel Attacks through Power Supply Unit Leakage
Ilias Giechaskiel, Kasper Bonne Rasmussen, Jakub Szefer
摘要
Field-Programmable Gate Arrays (FPGAs) are versatile, reconfigurable integrated circuits that can be used as hardware accelerators to process highly-sensitive data. Leaking this data and associated cryptographic keys, however, can undermine a system’s security. To prevent potentially unintentional interactions that could break separation of privilege between different data center tenants, FPGAs in cloud environments are currently dedicated on a per-user basis. Nevertheless, while the FPGAs themselves are not shared among different users, other parts of the data center infrastructure are. This paper specifically shows for the first time that powering FPGAs, CPUs, and GPUs through the same power supply unit (PSU) can be exploited in FPGA-to-FPGA, CPU-to-FPGA, and GPU-to-FPGA covert channels between independent boards. These covert channels can operate remotely, without the need for physical access to, or modifications of, the boards. To demonstrate the attacks, this paper uses a novel combination of "sensing" and "stressing" ring oscillators as receivers on the sink FPGA. Further, ring oscillators are used as transmitters on the source FPGA. The transmitting and receiving circuits are used to determine the presence of the leakage on off-the-shelf Xilinx boards containing Artix 7 and Kintex 7 FPGA chips. Experiments are conducted with PSUs by two vendors, as well as CPUs and GPUs of different generations. Moreover, different sizes and types of ring oscillators are also tested. In addition, this work discusses potential countermeasures to mitigate the impact of the cross-board leakage. The results of this paper highlight the dangers of shared power supply units in local and cloud FPGAs, and therefore a fundamental need to re-think FPGA security for shared infrastructures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Securing Reset Operations in NISQ Quantum ComputersAllen Mi, Shuwen Deng, Jakub SzeferCCS 2022 · 被引用 23 次
- IChannels: Exploiting Current Management Mechanisms to Create Covert Channels in Modern ProcessorsJawad Haj-Yahya, Lois Orosa, Jeremie S. Kim, Juan Gómez-Luna 等ISCA 2021 · 被引用 19 次
- Classifying Computations on Multi-Tenant FPGAsMustafa S. Gobulukoglu, Colin Drewes, William Hunter, Ryan Kastner 等DAC 2021 · 被引用 13 次
- Models on the Move: Towards Feasible Embedded AI for Intrusion Detection on Vehicular CAN BusHe Xu, Di Wu, Yufeng Lu, Jiwu Lu 等USENIX ATC 2024 · 被引用 4 次
- AmpereBleed: Exploiting On-chip Current Sensors for Circuit-Free Attacks on ARM-FPGA SoCsXin Zhang, Yi Yang, Jiajun Zou, Qingni Shen 等DAC 2025 · 被引用 2 次
它引用的顶会 Paper5
- FPGA-Based Remote Power Side-Channel AttacksMark Zhao, G. Edward SuhS&P 2018 · 被引用 301 次
- Exploiting a Thermal Side Channel for Power Attacks in Multi-Tenant Data CentersMohammad A. Islam, Shaolei Ren, Adam WiermanCCS 2017 · 被引用 53 次
- Reduced Cooling Redundancy: A New Security Vulnerability in a Hot Data CenterXing Gao, Zhang Xu, Haining Wang, Li Li 等NDSS 2018 · 被引用 32 次
- Ohm's Law in Data Centers: A Voltage Side Channel for Timing Power AttacksMohammad A. Islam, Shaolei RenCCS 2018 · 被引用 27 次
- CLKSCREW: Exposing the Perils of Security-Oblivious Energy ManagementAdrian Tang, Simha Sethumadhavan, Salvatore J. StolfoUSENIX Security 2017
相关 Paper
- Gotcha! I Know What You Are Doing on the FPGA Cloud: Fingerprinting Co-Located Cloud FPGA Accelerators via Measuring Communication LinksChongzhou Fang, Ning Miao, Han Wang, Jiacheng Zhou 等CCS 2023 · 被引用 4 次
- DARPT: defense against remote physical attack based on TDC in multi-tenant scenarioFan Zhang, Zhiyong Wang, Haoting Shen, Bolin Yang 等DAC 2022 · 被引用 8 次
- Veiled Pathways: Investigating Covert and Side Channels Within GPU UncoreYuanqing Miao, Yingtian Zhang, Dinghao Wu, Danfeng Zhang 等MICRO 2024 · 被引用 8 次
- LeakyDSP: Exploiting Digital Signal Processing Blocks to Sense Voltage Fluctuations in FPGAsXin Zhang, Jiajun Zou, Yi Yang, Qingni Shen 等DAC 2025
- Leaky Buddies: Cross-Component Covert Channels on Integrated CPU-GPU SystemsSankha Baran Dutta, Hoda Naghibijouybari, Nael B. Abu-Ghazaleh, Andres Marquez 等ISCA 2021 · 被引用 36 次
