Critical 'starbleed' vulnerability in FPGA chips identified

Image

Author Name: Desrina R

Category Name: Science and Technology

FPGA chips can be found in many safety-critical applications today, from cloud data centers and mobile phone base stations to encrypted USB-sticks and industrial control systems. Their decisive advantage lies in their reprogrammability compared to conventional hardware chips with their fixed functionalities.

To overcome the encryption, the research team took advantage of the central property of the FPGAs: the possibility of reprogramming. This is done by an update and fallback feature in the FPGA itself, which revealed itself as a weakness and gateway. The scientists were able to manipulate the encrypted bitstream during the configuration process to redirect its decrypted content to the WBSTAR configuration register, which can be read out after a reset.

Thus, the advantage of individually reprogramming the chips turns into a disadvantage, as the scientists show in their research work -- with severe consequences: "If an attacker gains access to the bitstream, he also gains complete control over the FPGA. Intellectual properties included in the bitstream can be stolen. It is also possible to insert hardware Trojans into the FPGA by manipulating the bitstream. Since the security gap is located in the hardware itself, it can only be closed by replacing the chip," explains Christof Paar, adding: "Although detailed knowledge is required, an attack can eventually be carried out remotely, the attacker does not even have to have physical access to the FPGA."

A standard EDITORIAL TRACKING SYSTEM is utilized for manuscript submission, review, editorial processing and tracking which can be securely accessed by the authors, reviewers and editors for monitoring and tracking the article processing. Manuscripts can be uploaded online at Editorial Tracking System https://www.imedpub.com/submissions/american-computer-science-information-technology.html) or forwarded to the Editorial Office at computersci@peerjournal.com

Media Contact:

Desrina R
Journal Manager
American journal of computer science and information technology
Email: ajcsit@peerjournal.org