低延迟 DAE:用于物联网实时 NVM 保护的可配置轻量级混合数据和地址加密引擎

IF 8.9 1区 计算机科学 Q1 COMPUTER SCIENCE, INFORMATION SYSTEMS IEEE Internet of Things Journal Pub Date : 2024-11-18 DOI:10.1109/JIOT.2024.3500781
Xuewen He;Li Du;Yuan Du
{"title":"低延迟 DAE:用于物联网实时 NVM 保护的可配置轻量级混合数据和地址加密引擎","authors":"Xuewen He;Li Du;Yuan Du","doi":"10.1109/JIOT.2024.3500781","DOIUrl":null,"url":null,"abstract":"In Internet of Things (IoT) real-time systems and edge computing applications, memory encryption engines (MEEs) are used for real-time memory encryption to protect program code and sensitive data in nonvolatile memories (NVMs) and mitigate some side-channel attacks. However, for resource-constrained devices, it is a considerable challenge to realize a lightweight solution with low-hardware overhead, high security, and flexible bit-width. This article presents a lightweight full-MEE, called data&address encryption (DAE), which employs hybrid data and address encryption to protect NVMs on-the-fly with low-logic latency, flexible width adaptation, and enhanced security in some aspects. The security analyses show that DAE performs effective mitigation in some side-channel attacks, such as Remanence attack, and provides better security than data-only ciphers in resisting the brute-force attack, etc. Evaluated with TSMC’s 40-nm standard CMOS technology, 128-bit DAE has a lightweight feature of 8.703 KGates, which is only 5.46% of 128-bit advanced encryption standard (AES-128), and performs a <inline-formula> <tex-math>$5.8\\times $ </tex-math></inline-formula> throughput, a <inline-formula> <tex-math>$105.9\\times $ </tex-math></inline-formula> area efficiency, and a <inline-formula> <tex-math>$48.1\\times $ </tex-math></inline-formula> energy efficiency. In the experiments on SoC simulation and field programmable gate array platform with an embedded RISC-V core, the results show that DAE causes little or no loss of system frequency and throughput.","PeriodicalId":54347,"journal":{"name":"IEEE Internet of Things Journal","volume":"12 7","pages":"8438-8452"},"PeriodicalIF":8.9000,"publicationDate":"2024-11-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Low-Latency DAE: A Configurable Lightweight Hybrid Data and Address Encryption Engine for IoT Real-Time NVM Protection\",\"authors\":\"Xuewen He;Li Du;Yuan Du\",\"doi\":\"10.1109/JIOT.2024.3500781\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In Internet of Things (IoT) real-time systems and edge computing applications, memory encryption engines (MEEs) are used for real-time memory encryption to protect program code and sensitive data in nonvolatile memories (NVMs) and mitigate some side-channel attacks. However, for resource-constrained devices, it is a considerable challenge to realize a lightweight solution with low-hardware overhead, high security, and flexible bit-width. This article presents a lightweight full-MEE, called data&address encryption (DAE), which employs hybrid data and address encryption to protect NVMs on-the-fly with low-logic latency, flexible width adaptation, and enhanced security in some aspects. The security analyses show that DAE performs effective mitigation in some side-channel attacks, such as Remanence attack, and provides better security than data-only ciphers in resisting the brute-force attack, etc. Evaluated with TSMC’s 40-nm standard CMOS technology, 128-bit DAE has a lightweight feature of 8.703 KGates, which is only 5.46% of 128-bit advanced encryption standard (AES-128), and performs a <inline-formula> <tex-math>$5.8\\\\times $ </tex-math></inline-formula> throughput, a <inline-formula> <tex-math>$105.9\\\\times $ </tex-math></inline-formula> area efficiency, and a <inline-formula> <tex-math>$48.1\\\\times $ </tex-math></inline-formula> energy efficiency. In the experiments on SoC simulation and field programmable gate array platform with an embedded RISC-V core, the results show that DAE causes little or no loss of system frequency and throughput.\",\"PeriodicalId\":54347,\"journal\":{\"name\":\"IEEE Internet of Things Journal\",\"volume\":\"12 7\",\"pages\":\"8438-8452\"},\"PeriodicalIF\":8.9000,\"publicationDate\":\"2024-11-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Internet of Things Journal\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10755043/\",\"RegionNum\":1,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Internet of Things Journal","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10755043/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

在物联网(IoT)实时系统和边缘计算应用中,内存加密引擎(MEEs)用于实时内存加密,以保护非易失性存储器(nvm)中的程序代码和敏感数据,并减轻一些侧信道攻击。然而,对于资源受限的设备,实现低硬件开销、高安全性和灵活位宽的轻量级解决方案是一个相当大的挑战。本文提出了一种轻量级的全mee,称为数据和地址加密(data&address encryption, DAE),它采用混合数据和地址加密来动态保护nvm,具有低逻辑延迟、灵活的宽度适应以及在某些方面增强的安全性。安全性分析表明,DAE对残余攻击等侧信道攻击有较好的缓解效果,在抗暴力攻击等方面具有比纯数据密码更好的安全性。采用台积电40纳米标准CMOS技术进行评估,128位DAE具有8.703 KGates的轻量级特性,仅为128位高级加密标准(AES-128)的5.46%,吞吐量为5.8美元,面积效率为105.9美元,能效为48.1美元。在SoC仿真和嵌入式RISC-V内核的现场可编程门阵列平台上进行的实验表明,DAE对系统频率和吞吐量的影响很小或没有影响。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Low-Latency DAE: A Configurable Lightweight Hybrid Data and Address Encryption Engine for IoT Real-Time NVM Protection
In Internet of Things (IoT) real-time systems and edge computing applications, memory encryption engines (MEEs) are used for real-time memory encryption to protect program code and sensitive data in nonvolatile memories (NVMs) and mitigate some side-channel attacks. However, for resource-constrained devices, it is a considerable challenge to realize a lightweight solution with low-hardware overhead, high security, and flexible bit-width. This article presents a lightweight full-MEE, called data&address encryption (DAE), which employs hybrid data and address encryption to protect NVMs on-the-fly with low-logic latency, flexible width adaptation, and enhanced security in some aspects. The security analyses show that DAE performs effective mitigation in some side-channel attacks, such as Remanence attack, and provides better security than data-only ciphers in resisting the brute-force attack, etc. Evaluated with TSMC’s 40-nm standard CMOS technology, 128-bit DAE has a lightweight feature of 8.703 KGates, which is only 5.46% of 128-bit advanced encryption standard (AES-128), and performs a $5.8\times $ throughput, a $105.9\times $ area efficiency, and a $48.1\times $ energy efficiency. In the experiments on SoC simulation and field programmable gate array platform with an embedded RISC-V core, the results show that DAE causes little or no loss of system frequency and throughput.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
IEEE Internet of Things Journal
IEEE Internet of Things Journal Computer Science-Information Systems
CiteScore
17.60
自引率
13.20%
发文量
1982
期刊介绍: The EEE Internet of Things (IoT) Journal publishes articles and review articles covering various aspects of IoT, including IoT system architecture, IoT enabling technologies, IoT communication and networking protocols such as network coding, and IoT services and applications. Topics encompass IoT's impacts on sensor technologies, big data management, and future internet design for applications like smart cities and smart homes. Fields of interest include IoT architecture such as things-centric, data-centric, service-oriented IoT architecture; IoT enabling technologies and systematic integration such as sensor technologies, big sensor data management, and future Internet design for IoT; IoT services, applications, and test-beds such as IoT service middleware, IoT application programming interface (API), IoT application design, and IoT trials/experiments; IoT standardization activities and technology development in different standard development organizations (SDO) such as IEEE, IETF, ITU, 3GPP, ETSI, etc.
期刊最新文献
Multistable ReLU-Type Memristive Heterogeneous Neuron Model With Multiscroll Firing Dynamics and Application in Image Secure Communication Blind Interference Suppression for IRS-Aided Robust Wireless Communications Quadratic Estimation for 2-D Non-Gaussian Systems With Network-Based Deception Attacks and Quantization Effects HBQS: Lightweight Post-Quantum Secure Authentication for Satellite Networks Leveraging Hardware TRNG and PUFs LBCM: A Scalable and DDoS-Resistant Cross-Domain Authentication Protocol for IIoT Using Chaotic Maps and Merkle Tree
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1