节点文献
高能效可重构密码处理器架构及其抗物理攻击技术研究
Energy Efficient Architecture and Physical Attack Countermeasures for Reconfigurable Cryptographic Processors
【作者】 王博;
【导师】 刘雷波;
【作者基本信息】 清华大学 , 电子科学与技术, 2018, 博士
【摘要】 可重构密码处理器是可重构计算形式在密码领域的应用。相比于传统的专用集成电路与指令集结构处理器,可重构密码处理器能够为密码应用在灵活性、能量效率(性能功耗比)与安全性方面的综合需求提供更好的解决方案。然而,可重构密码处理器仍面临许多问题有待解决,这主要体现在两个方面。一方面,如何在保证灵活性的前提下进一步提高能量效率,缩小与专用计算的差距。另一方面,如何充分发掘可重构计算形式的特点以提高其硬件安全性,即抵抗物理攻击的能力。而就安全性对于密码应用的核心意义而言,后一方面更是尤为重要。本论文研究可重构密码处理器高能量效率架构设计方法与其抗物理攻击关键技术。相比于对冗杂的架构设计与抗攻击方法进行全面的覆盖,本文着眼于对核心技术点进行创新性探索。在架构设计方面,区别于传统的将可重构数据通路作为研究重点的方法,本论文将重点放在影响能量效率的核心部件可重构控制器上。针对配置控制方法与配置信息组织两个技术难点,结合密码算法的特点分别提出令牌式控制链技术和配置分层与压缩技术,进而从提高计算资源利用率与降低配置延时两个角度提高处理器的能量效率。在抗物理攻击技术方面,针对当前大部分研究仅着眼于将传统抗攻击方法实现在可重构架构上这一问题,本论文重点研究如何利用可重构密码处理器硬件架构与计算形式的特殊优势抵抗物理攻击。对于可重构计算的局部动态重构与多元化计算资源两个根本属性,本文提出了随机动态重构抗物理攻击与可重构计算资源抗物理攻击两个思路,并结合对可重构密码处理器有较大威胁性的故障攻击建立了具体的安全评估方法与抗攻击方法。本论文中提出的两种高能效架构设计方法以流片验证的方式在一款可重构密码处理器上实现。相比于其他先进的可重构密码处理器,其平均能量效率提升达到16.5倍。就抗物理攻击方法而言,以故障攻击为实例进行验证,本文提出的抗攻击措施可以在30%以内的开销下达到高至四个数量级的抗故障攻击能力提升。并且,对于传统抗攻击方法无法抵御的新型双故障与多故障攻击,随机动态重构抗攻击方法仍具有很好的防御效果。
【Abstract】 Reconfigurable cryptographic processor is an application example of the reconfigurable computing concept to the cryptographic area.Compared to traditional ASIC(application specific integrated circuit)or ISAP(instruction set architecture processor)solutions,reconfigurable cryptographic processors can maintain the three requirements of cryptographic applications at the same time,i.e.,flexibility,energy efficiency(throughput/power)and security.However,there are still many open problems for the reconfigurable cryptographic processor design,which mainly fall into two aspects.On one hand,how to further improve the energy efficiency to bridge the gap between application-specific computing and reconfigurable computing while maintaining enough algorithm flexibility at the same time;on the other hand,how to increase the hardware security level represented by physical attack resistance utilizing the characteristics of reconfigurable computing style.Due to the fundamental significance of security to cryptographic applications,the later problem is even more important for reconfigurable cryptographic processors.This dissertation studies the architecture design methods of high energy efficient reconfigurable cryptographic processors and countermeasures against physical attacks.The research aims to explore new solutions of key technical points rather than cover all the details of processor design.As for the architecture design part,compared to the traditional design methods which pay more attention to the reconfigurable datapath,this research mainly focuses on the design of the reconfigurable controller which has a more significant influence on energy efficiency.Two strategies,i.e.,the Token-Driven Control Chain technique and the Configuration Context Layering and Compression technique,are proposed based on the characteristics of cryptographic algorithms to deal with the configuration control problem and the configuration context organization problem which seen as the major problems for the reconfigurable controller design.These two techniques can enhance the energy efficiency by increasing the computing resource utilization and reducing the configuration delay respectively.As for the countermeasure design against physical attacks,most of the current researches only focus on how to implement the mature countermeasures onto the reconfigurable architecture.This dissertation explores how to take advantage of the hardware architecture and computing paradigm of reconfigurable cryptographic processors to design new countermeasures.Based on the two fundamental properties of reconfigurable computing,i.e.,the dynamic and partial reconfigurability and the diverse computing resources,this research proposes two novel countermeasure solutions: randomized dynamic and partial reconfiguration against physical attacks and reconfigurable computing resource against physical attacks.Taking fault attacks which are becoming an emerging threat to reconfigurable cryptographic processors as the example,these two solutions are actually implemented by designing a series of specific countermeasures as well as security evaluation methods to against fault attacks.The two energy efficient architecture design methods proposed are implemented on a reconfigurable cryptographic chip.Compared to the state-of-art reconfigurable cryptographic processors,the proposed architecture achieves(average)16.5x higher energy efficiency.As for the physical attack countermeasures,the proposed methods can increase the fault attack resistance up to four orders of magnitude with the overhead controlled within 30%.What is more,the proposed countermeasures based on randomized dynamic and partial reconfiguration can also resist against novel double fault attacks as well as multiple fault attacks which can not be efficiently resisted by traditional countermeasures.
【Key words】 reconfigurable cryptographic processor; energy efficiency; physical attack; fault attack;