← 返回 JSSC 论文列表
📄 下载 JSSC 原文 PDF
JSSC 2021第8期Digital Circuits28nm/40nm

Jintide: Utilizing Low-Cos t Reconfigurable External Monitors to Substantially Enhance Hardware Security of Large-Scale CPU Clusters Jianfeng Zhu , Ao Luo, Guanhua Li, Bowei Zhang , Y ong Wang, Gang Shan, Yi Li , Jianfeng Pan

Jintide利用低成本可重构外部监视器增强CPU硬件安全性
28-/40-nm TSMC技术
硬件安全外部监视器CPU验证恶意行为检测分布式集群
采用可信外部监视器验证不可信CPU芯片
通过记录、回放和分析CPU的IO及内存行为检测威胁
支持分布式大规模集群部署以分摊运行开销
Abstract
Nowadays, hardware security has become a serious concern for modern CPUs. State-of-the-art detection approaches rely heavily on trustworthy and intimate internal states, incurring significant design/operation overheads and additional risks to security and intellectual property. This article proposes an archi- tecture called Jintide, which utilizes trusted external monitors to validate an untrusted CPU chip at runtime. This architecture records, replays, and analyzes the CPU’s IO and memory behavior with the architectural states. The Jintide simultaneously verifies whether the records are correctly replayed with the instruction set architecture and whether the records involve malicious behavior. Consequently, not only architectural but also micro-architectural threats can be detected. The Jintide adopts the states from the untrusted source because it has a built-in function to detect spurious states. The monitors comprise three types of chips (with 28-/40-nm TSMC technology): a tracer chip to record the behavior of IO ports, multiple tracer chips to record the behavior of DDR4 DIMMs, and a reconfigurable chip to verify these records with software states. As runtime external monitors, the Jintide would be especially suit able to constitute distributed large-scale clusters, which can amortize operation overheads. This scheme is effective in detecting pervasive hardware secu- rity issues, including vulnerabilities, backdoors, and hardware Trojans. The measured results show that a sy