2011•Unpublished venueRequires access

On the Vulnerability of FPGA Bitstream Encryption against Power Analysis Attacks - Extracting Keys from Xilinx Virtex-II FPGAs.

Amir Moradi, Alessandro Barenghi, Timo Kasper, Christof Paar

Open publisher page 20 citations

Abstract

Over the last two decades FPGAs have become central com-ponents for many advanced digital systems, e.g., video signal processing, network routers, data acquisition and military systems. In order to protect the intellectual property and to prevent fraud, e.g., by cloning an FPGA or manipulat-ing its content, many current FPGAs employ a bitstream encryption feature. We develop a successful attack on the bitstream encryption engine integrated in the widespread Virtex-II Pro FPGAs from Xilinx, using side-channel anal-ysis. After measuring the power consumption of a single power-up of the device and a modest amount of off-line com-putation, we are able to recover all three different keys used by its triple DES module. Our method allows extracting secret keys from any real-world device where the bitstream encryption feature of Virtex-II Pro is enabled. As a conse-quence, the target product can be cloned and manipulated at will of the attacker. Also, more advanced attacks such as reverse engineering or the introduction of hardware Trojans become potential threats. As part of the side-channel attack, we were able to deduce certain internals of the hardware en-cryption engine. To our knowledge, this is the first attack against the bitstream encryption of a commercial FPGA re-ported in the open literature. 1.

About this research paper

What this paper is about

Over the last two decades FPGAs have become central com-ponents for many advanced digital systems, e.g., video signal processing, network routers, data acquisition and military systems. In order to protect the intellectual property and to prevent fraud, e.g., by cloning an FPGA or manipulat-ing its content, many current FPGAs employ a bitstream encryption feature. We develop a successful attack on the bitstream encryption engine integrated in the widespread Virtex-II Pro FPGAs from Xilinx, using side-channel anal-ysis. After measuring the power consumption of a single power-up of the device and a modest amount of off-line com-putation, we are able to recover all three different keys used by its triple DES module. Our method allows extracting secret keys from any real-world device where the bitstream encryption feature of Virtex-II Pro is enabled. As a conse-quence, the target product can be cloned and manipulated at will of the attacker. Also, more advanced attacks such as reverse engineering or the introduction of hardware Trojans become potential threats. As part of the side-channel attack, we were able to deduce certain internals of the hardware en-cryption engine. To our knowledge, this is the first attack against the bitstream encryption of a commercial FPGA re-ported in the open literature. 1.

Why it matters

OpenAlex reports 20 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Over the last two decades FPGAs have become central com-ponents for many advanced digital systems, e.g., video signal processing, network routers, data acquisition and military systems. In order to protect the intellectual property and to prevent fraud, e.g., by cloning an FPGA or manipulat-ing its content, many current FPGAs employ a bitstream encryption feature. We develop a successful attack on the bitstream encryption engine integrated in the widespread Virtex-II Pro FPGAs from Xilinx, using side-channel anal-ysis. After measuring the power consumption of a single power-up of the device and a modest amount of off-line com-putation, we are able to recover all three different keys used by its triple DES module. Our method allows extracting secret keys from any real-world device where the bitstream encryption feature of Virtex-II Pro is enabled. As a conse-quence, the target product can be cloned and manipulated at will of the attacker. Also, more advanced attacks such as reverse engineering or the introduction of hardware Trojans become potential threats. As part of the side-channel attack, we were able to deduce certain internals of the hardware en-cryption engine. To our knowledge, this is the first attack against the bitstream encryption of a commercial FPGA re-ported in the open literature. 1.

Key concepts: Bitstream, Computer science, Field-programmable gate array, Encryption, Embedded system, Virtex, Power analysis, Side channel attack

Related papers

Back to paper searchBrowse research topicsOriginal source
On the Vulnerability of FPGA Bitstream Encryption against Power Analysis Attacks - Extracting Keys from Xilinx Virtex-II FPGAs. — Research Paper | ScholarLens