论文标题

硬件的定量信息流:推进攻击格局

Quantitative Information Flow for Hardware: Advancing the Attack Landscape

论文作者

Reimann, Lennart M., Erdönmez, Sarp, Sisejkovic, Dominik, Leupers, Rainer

论文摘要

安全仍然是现代电子设计自动化(EDA)工具的事后想法,该工具仅着重于增强性能和降低芯片尺寸。通常,安全分析是手工进行的,导致设计中的脆弱性尚未引起注意。安全意识的EDA工具协助设计师识别和删除安全威胁,同时牢记性能和领域。最先进的方法利用信息流分析发现设计结构中的意外信息泄漏。但是,这种威胁的分类是二进制的,导致列出了可忽略的泄漏。一种新颖的定量分析允许应用度量来确定泄漏的数值。但是,量化泄漏的当前近似值仍然容易忽略泄漏。这项工作中引入的数学模型2D-QMODEL旨在克服这一缺点。此外,由于以前的工作仅包括有限的威胁模型,因此可以使用提供的方法应用多个威胁模型。开源基准用于显示2D QMODEL的功能,以识别设计中的硬件木马,同时忽略微不足道的泄漏。

Security still remains an afterthought in modern Electronic Design Automation (EDA) tools, which solely focus on enhancing performance and reducing the chip size. Typically, the security analysis is conducted by hand, leading to vulnerabilities in the design remaining unnoticed. Security-aware EDA tools assist the designer in the identification and removal of security threats while keeping performance and area in mind. State-of-the-art approaches utilize information flow analysis to spot unintended information leakages in design structures. However, the classification of such threats is binary, resulting in negligible leakages being listed as well. A novel quantitative analysis allows the application of a metric to determine a numeric value for a leakage. Nonetheless, current approximations to quantify the leakage are still prone to overlooking leakages. The mathematical model 2D-QModel introduced in this work aims to overcome this shortcoming. Additionally, as previous work only includes a limited threat model, multiple threat models can be applied using the provided approach. Open-source benchmarks are used to show the capabilities of 2D-QModel to identify hardware Trojans in the design while ignoring insignificant leakages.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源