The various benefits of multi-tenanting, such as higher device utilization and increased profit margin, intrigue the cloud field-programmable gate array (FPGA) servers to include multi-tenanting in their infrastructure. However, this property makes these servers vulnerable to power side-channel (PSC) attacks. Logic designs such as ring oscillator (RO) and time-to-digital converter (TDC) are used to measure the power consumed by security critical circuits, such as advanced encryption standard (AES). Firstly, the existing works require higher minimum traces for disclosure (MTD). Hence, in this work, we improve the sensitivity of the TDC-based sensors by manually placing the FPGA primitives inferring these sensors. This enhancement helps to determine the 128-bit AES key using 3.8K traces. Secondly, the existing defenses use ROs to defend against PSC attacks. However, cloud servers such as Amazon Web Services (AWS) block design with combinatorial loops. Hence, we propose a placement-based defense. We study the impact of (i) primitive-level placement on the AES design and (ii) additional logic that resides along with the AES on the correlation power analysis (CPA) attack results. Our results showcase that the AES along with filters and/or processors are sufficient to provide the same level or better security than the existing defenses.
翻译:多租户技术带来的高设备利用率和利润增长等优势,使得云端现场可编程门阵列(FPGA)服务器纷纷在其基础设施中引入多租户特性。然而,这一特性使得服务器面临功率侧信道(PSC)攻击的风险。环振(RO)和时间数字转换器(TDC)等逻辑设计被用于测量高级加密标准(AES)等安全关键电路的功耗。首先,现有方法需要较高的最小泄露追踪次数(MTD)。因此,本研究通过手动布局推断这些传感器的FPGA原语,提升了TDC传感器的灵敏度。这种优化使我们在3.8K次追踪下即可确定128位AES密钥。其次,现有防御方案采用环振来抵御功率侧信道攻击,但亚马逊云服务(AWS)等云服务器会阻断包含组合环路的电路设计。为此,我们提出一种基于布局的防御方案。我们分别研究了(i)原语级布局对AES设计的影响,以及(ii)与AES共存的其他逻辑对相关功耗分析(CPA)攻击结果的影响。实验结果表明,配合滤波器或处理器的AES设计能够提供与现有防御方案同等甚至更优的安全性。