Patchable Hardware Security Module (PHaSM) for Extending FPGA Root-of-Trust Capabilities
Christopher Sozio, Zachary Jordan, Grant Skipper, Andrew Lukefahr, Adam R. Duncan · 2021
Field-Programmable Gate Arrays (FPGAs) are re-programmable hardware devices widely used in consumer and defense applications. Their specific functionality is determined by programming the FPGA with a configuration file, or bitstream, which often occurs at bootup. FPGAs rely on a hardware Root-of-Trust (RoT) to verify the authenticity of these (re)programming attempts. Any vulnerability in an FPGA’s RoT enables adversarial (re)programming, tampering, and information extraction from the FPGA. Unlike software, when hardware RoT vulnerabilities are exposed the FPGA cannot be patched, but remains forever vulnerable to exploit.This work assumes a hardware RoT on an FPGA will be compromised at some point by an adversary. We propose incorporating a second, patchable, layer of security to prevent adversarial attacks on FPGAs, even those with potentially compromised hardware RoT schemes. To accomplish this, we present Patchable Hardware Security Module (PHaSM), a patchable hybrid security framework that enables a secondary RoT. PHaSM implements a small bootloader in the FPGA’s reconfigurable fabric and incorporates user-defined authentication and decryption schemes. The bootloader loads an application configuration, PHaSM then decrypts and authenticates it using the user-defined schemes, and programs the application design into the remaining FPGA fabric using partial reconfiguration. Should the user-defined security scheme become vulnerable, a new security scheme can be incorporated without modifying the original application design.