Flexible security and its technology limits.
Viktor Fischer, Lionel Torres, Daniel Mesquita
Abstract
Viktor Fischer, Lionel Torres, Daniel Mesquita
Abstract
Abstract This paper presents an analysis of the needs of current information security systems and of the available technologies that constitute a basis for implementation of these systems in hardware. First, we present the term flexible security and we discuss, why the flexibility plays an important role in current information security systems. However, while reconfigurable logic devices represent a natural choice for flexible hardware security modules implementation, standard Field Programmable Gate Arrays (FPGAs) are not always suitable for such tasks. Therefore, we propose a new class of flexible security devices – Crypto-FPGAs, offering enhanced security features on different security levels. Finally, we present some examples of Crypto-FPGA architectures and we discuss main problems related to these architectures and their application. 1. INTRODUCTION Recent expansion of communication systems makes the information security more important. Implementation of cryptographic algorithms and other security tools in hardware increases the system security. It was believed that Application Specific Integrated Circuits (ASICs) are the best choice for cryptographic systems implementation, because they are secure, robust and resistant to cryptographic attacks. However, because of the lack of their flexibility, and for economic reasons, Field Programmable Logic Devices (FPGAs) are sometimes preferable [1]. The best example confirming the need of the flexibility in information security is the history of the Data Encryption Standard (DES). An attack published in January 1999 needed only 22 hours and 15 minutes to break the cipher. The standard had to be modified (so-called Triple DES has been proposed) or replaced (new Advanced Encryption Standard – AES – has been adopted). Because hardwired cryptographic tools do not permit algorithm upgrade, the whole security modules should be exchanged. Nevertheless, this operation could be very long and expensive. For this reason, even in a very attractive banking sector, the new encryption standard is not widely used, yet. Paradoxically, the primary aim of the application of ASICs in cryptographic modules – the security – is thus not always attained. P. Davies has introduced in [1] the term flexible security - the feature that enables reconfiguration or upgrading of information security product or systems. Flexible security can be provided by the means of software, or hardware [2]. While for security reasons the hardware solutions are preferable, the application of FPGAs seems to be the best choice. However, it has been shown in [3], that current FPGA families are not suitable for cryptographic applications. Our aim was to analyze the needs of the flexible security and to propose a solution for this problem. The paper starts with an analysis of the needs of the flexibility in information security systems. Next, it deals with security aspects of the employment of FPGAs in security applications. Following these two analyses we define some security module operating scenarios and a new class of FPGAs, targeted for data security applications – Crypto-FPGAs. Finally, we propose and discuss internal structure of these devices on both macro-architecture and micro-architecture levels.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Abstract This paper presents an analysis of the needs of current information security systems and of the available technologies that constitute a basis for implementation of these systems in hardware. First, we present the term flexible security and we discuss, why the flexibility plays an important role in current information security systems. However, while reconfigurable logic devices represent a natural choice for flexible hardware security modules implementation, standard Field Programmable Gate Arrays (FPGAs) are not always suitable for such tasks. Therefore, we propose a new class of flexible security devices – Crypto-FPGAs, offering enhanced security features on different security levels. Finally, we present some examples of Crypto-FPGA architectures and we discuss main problems related to these architectures and their application. 1. INTRODUCTION Recent expansion of communication systems makes the information security more important. Implementation of cryptographic algorithms and other security tools in hardware increases the system security. It was believed that Application Specific Integrated Circuits (ASICs) are the best choice for cryptographic systems implementation, because they are secure, robust and resistant to cryptographic attacks. However, because of the lack of their flexibility, and for economic reasons, Field Programmable Logic Devices (FPGAs) are sometimes preferable [1]. The best example confirming the need of the flexibility in information security is the history of the Data Encryption Standard (DES). An attack published in January 1999 needed only 22 hours and 15 minutes to break the cipher. The standard had to be modified (so-called Triple DES has been proposed) or replaced (new Advanced Encryption Standard – AES – has been adopted). Because hardwired cryptographic tools do not permit algorithm upgrade, the whole security modules should be exchanged. Nevertheless, this operation could be very long and expensive. For this reason, even in a very attractive banking sector, the new encryption standard is not widely used, yet. Paradoxically, the primary aim of the application of ASICs in cryptographic modules – the security – is thus not always attained. P. Davies has introduced in [1] the term flexible security - the feature that enables reconfiguration or upgrading of information security product or systems. Flexible security can be provided by the means of software, or hardware [2]. While for security reasons the hardware solutions are preferable, the application of FPGAs seems to be the best choice. However, it has been shown in [3], that current FPGA families are not suitable for cryptographic applications. Our aim was to analyze the needs of the flexible security and to propose a solution for this problem. The paper starts with an analysis of the needs of the flexibility in information security systems. Next, it deals with security aspects of the employment of FPGAs in security applications. Following these two analyses we define some security module operating scenarios and a new class of FPGAs, targeted for data security applications – Crypto-FPGAs. Finally, we propose and discuss internal structure of these devices on both macro-architecture and micro-architecture levels.
Key concepts: Computer science, Cryptography, Flexibility (engineering), Advanced Encryption Standard, Field-programmable gate array, Encryption, Embedded system, Computer security