Recently, eFPGA-based redaction has been proposed as a promising solution for hiding parts of a digital design from untrusted entities, where legitimate end-users can restore functionality by loading the withheld bitstream after fabrication. However, when deciding which parts of a design to redact, there are a number of practical issues that designers need to consider, including area and timing overheads, as well as security factors. Adapting an open-source FPGA fabric generation flow, we perform a case study to explore the trade-offs when redacting different modules of open-source intellectual property blocks (IPs) and explore how different parts of an eFPGA contribute to the security. We provide new insights into the feasibility and challenges of using eFPGA-based redaction as a security solution.
翻译:最近,有人提议通过基于eFPGA的编辑方式,将数字设计的某些部分隐藏在不受信任的实体手中,使合法最终用户能够通过在制造后加载被扣留的位流来恢复功能,这是一个大有希望的解决办法;然而,在决定编辑设计中的哪些部分时,设计者需要考虑一些实际问题,包括间接费用的面积和时间,以及安全因素;调整开放源码的FPGA结构生成流程,我们进行一项个案研究,探讨在重订开放源码知识产权区块的不同模块时的权衡,并探讨电子FPGA的不同部分如何有助于安全;我们就使用基于eFPGA的编辑方式作为安全解决办法的可行性和挑战提出了新的见解。