Flexible and low-cost HSM based on non-volatile FPGAs
Diogo Parrinha, Ricardo Chaves · 2017
Embedded systems supported on FPGAs are increasingly playing a bigger role on safety-critical areas. A particular example of a safety-critical system is a Hardware Security Module, providing private key management and usage in a secure and reliable way. However, commercially available systems are too expensive and limited in the provided functionality. On the other hand, existing volatile FPGA solutions do not adequately provide the needed security features. Herein, an open-source, low-cost and highly flexible re-configurable Hardware Security Module is proposed, supported by a System-on-Chip with a non-volatile FPGA. The presented solution operates as a versatile certification system that provides key management, digital signature services and is able to issue trustworthy certificates. The solution can be used, for example, in IT security applications through an integration with the included PKCS#11 interface. To further illustrate the flexibility of the proposed solution, a Log-Chain certification use-case is also presented. Experimental results suggest that the system is able to compute up to 2 sign/certification operations per second with a low cost, adaptable, and secure approach.