Multi-Tenant IC Peek and Poke Protection via Exclusion Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a multi-tenant usage model for programmable logic devices, the lack of trust among clients and the server leads to vulnerabilities in preventing peek and poke attacks, where unauthorized access or manipulation of configuration bits can occur.
Innovation Solution
The implementation of an exclusion configuration that extracts and sets configuration bits to prevent peek and poke attacks, achieved through static or dynamic partial reconfiguration and dynamic checks, ensuring that only authorized parties access and modify configuration bits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a multi-tenant usage model is implemented to support multiple clients on a single device, then device utilization and resource sharing are improved, but security vulnerabilities arise that allow unauthorized peek and poke attacks between tenants
Solution Approach 1:
The configuration space is segmented into multiple tenant-specific regions, with each tenant assigned to specific configuration bits and resources. This segmentation isolates tenants from each other, preventing unauthorized access while allowing each tenant to independently configure their allocated resources without affecting other tenants.
Solution Approach 2:
A configuration management intermediary is introduced that mediates between tenants and the configuration bits. This intermediary validates and controls the configuration process, ensuring that tenants can only access their authorized configuration space while preventing peek and poke attacks through enforced access control policies.
2Adaptability or versatility
If configuration bits are made accessible for dynamic reconfiguration to support client customization, then adaptability and functionality are improved, but vulnerability to malicious manipulation increases
Solution Approach 1:
Protective measures are taken in advance by establishing tenant-specific access control policies before reconfiguration occurs. The system pre-defines which configuration bits each tenant can access and implements validation mechanisms that prevent malicious manipulation before it can affect the system state.
Solution Approach 2:
The system implements feedback mechanisms that monitor configuration access and reconfiguration operations. When a reconfiguration attempt is detected, the system validates it against tenant policies and provides feedback by either allowing the operation if authorized or blocking it if it violates security policies, thereby preventing unauthorized manipulation.
3Reliability
If trust assumptions are removed among clients and server in a multi-tenant environment, then security posture is improved against insider threats, but system complexity and overhead increase
Solution Approach 1:
Trust validation is performed in advance during the configuration phase rather than requiring continuous verification during operation. The system establishes and validates tenant boundaries and access policies beforehand, creating a secure foundation that reduces the need for complex runtime trust verification mechanisms.
Data Source
AI summary
Methods and apparatus for extracting a setting of configuration bits to create an exclusion configuration for providing protection against peek and poke attacks in a multi-tenant usage model of a configurable device is provided. The device may host multiple parties that do not trust each other. Peek and poke attacks are orchestrated by tapping (peeking) and driving (poking) wires associated with other parties. Such attacks may be disabled by excluding the settings of configuration bits that would allow these attacks by other parties. This set of configuration bits that should be excluded for preventing all peek and poke attacks creates the exclusion configuration. Methods are described that disable a particular class of peek and/or poke attacks through the use of partial reconfiguration. Methods and apparatus are described to dynamically detect peek and/or poke attacks.


