A Bandwidth-Aware Authentication Scheme for Packet-Integrity Attack Detection on Trojan Infected NoC
Mubashir Hussain, Hui Guo · 2018
Bandwidth is a fundamental issue in the NoC (Network on Chip) design and increasing use of the third-party NoC IPs adds the security as another design concern. The third-party NoC may have hardware Trojans that can break the confidentiality and integrity of the data transferred over the NoC, thereafter exposing the system to varied attacks. Basically, encryption can be applied to protect the data confidentiality; For the data integrity, authentication is often used. A general authentication approach for network communication is using a tag to identify the data; The tag is attached to the data at the source and the data is verified against the tag at the destination. For the effectiveness of the authentication, a large tag size is desired. But large tags, when transferred over the NoC, will consume considerable network bandwidth, potentially conflicting with the system performance requirement. In this paper, we propose a progressive packet data authentication scheme, where a packet is progressively authenticated against a set of small tag segments such that the authentication overhead is low yet the effective tag size is large. The experiments in our case study of 2D mesh NoC demonstrate that our design can achieve savings about 36% on bandwidth and 56% on implementation area cost as compared to the baseline design with the traditional non-progressive authentication scheme.