A field-programmable gate array (FPGA) is a type of general-purpose programmable integrated circuit that consists of electronic components that can be used in a more flexible way than other chips . Often, even large data centers dedicated to cloud services resort to FPGAs.
Until recently, their use was considered quite safe. However, a report published in the journal IACR by researchers from the Karlsruhe Institute of Technology (KIT) recently found that there are some gateways that could be exploited by malicious hackers.
Unlike conventional computer chips, which perform a very specific task, FPGAs take on almost every function of any other chip. That's why they're preferred when creating new devices and systems.
“FPGAs are integrated into the first batch of a new device and can be modified later, unlike other chips,” says Dennis Gnad, an engineer at KIT.
Thus, FPGAs are applied in many areas: smartphones, networks, the Internet, medicine, vehicle electronics, and aerospace.
FPGAs are ideal for server farms managed by cloud. Another advantage of these programmable chips is that they can be separated.
“The top half of the FPGA can be allocated to one customer and the bottom half to a second one,” says Jonas Krautter, another KIT member. This is seen as very useful in cloud services.
Attacks
The researchers noted that the use of FPGAs could allow hackers to carry out attacks. Specifically, Gnad said: “The simultaneous use of an FPGA chip by multiple users could allow malicious attacks to be carried out.”.
The distinguishing feature of FPGA chips, flexibility, is essentially what hackers exploit to carry out so-called side-channel attacks. Side-channel attacks allow hackers to retrieve information using the chip's energy. The information that hackers obtain allows them to break the chip's encryption. A cloud service user with malicious intentions can exploit this to spy on another user.
With these attacks, hackers can compromise other users' data or even destroy the chip, causing data loss. Of course, this risk also exists in other chips, especially those implemented in IoT systems, such as smart heating control or lighting systems.
The researchers suggest that user access to FPGAs should be restricted. However, what needs to be achieved is the removal of malicious users, not all of them.
