5 ms·
Asynchronous computers are commercially available right now which have been shown to be fully reliable. Asynchronous design has been an area of research for a l
by mjbs 11y ago
Asynchronous computers are commercially available right now which have been shown to be fully reliable. Asynchronous design has been an area of research for a long time and many successful computers have been built.
Why is device variation a reason against asynchronous design? If anything I'd say that is a reason for it. Clocked designs must account for the worst case variation and reduce the clock speed accordingly. An asynchronous design on the other hand will run as fast as physically possible.
- javcasas 11y agoIf I understand it properly, asynchronous circuits also work at the slowest speed required, thus minimizing power usage. They are really fast when there is something to do, and they stop completely when there is nothing to do. Thus the "sleep mode" should be ludicrously low power, just the leakage current of the transistors: some nA for each gate.
- nraynaud 11y agotry to do a cryptographic circuit with that, it will be side channel party. Generally we count on inefficiencies and in particular the clock distribution network to mask the data from the input current.
- mjbs 11y agoI'm confused by this. Can you explain further or provide a link please?
- javcasas 11y agoWhen your processor does computations, it consumes power and radiates electromagnetic waves depending on many parameters, such as the kind of computation, the parameters, the amount of ones vs zeros in the registers and many other "silly" details. When you do crypto on such systems, part of the information that should be hidden is leaked in the form of EM waves, longer or shorter response times, and current consumption (among others). These leaks of information are called "side channels", and have been successfully used to hack some systems. Some of the current tricks of proper cryptography include things such as "always do the same amount of computation", "always take the same time", "always consume the same current" in order to try to hide this leak of information. It is tricky with standard "clocked" processors. So it will be even trickier with asynchronous processors.
- mjbs 11y agoMaybe, instead of taking precautions like trying to always take the same amount of time for some computation (which sounds like a pain!) we could take advantage of some unique properties of async chips. I'm thinking of something like randomly varying the voltage as the computations take place so that time differences will not correlate to data.
- babsa65 11y agoAlpha test test
- javcasas 11y agoWell, if you are able to predict that random voltage generator (we have seen recently some failures in pseudo-random generators that allow attackers to predict next numbers) we can correlate again time with data. So now you have to ensure your random generator is truly random, and not biased at all. For every weird property you try to use to obfuscate the computation, there is some kind of counter to try to de-obfuscate it. That's why crypto is really hard. If you really want to succeed, the only way is use as many tricks as possible, in order to make the attack really hard, hoping to discourage the attacker into doing something more productive with his life.
- Gankro 11y agoExcept if it's really random, after enough trials you'll have some clearly random distribution, with some distortion related to the actual cost. Figuring out the cost is just some statistical analysis away. See e.g. https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf for this principle applied to performing timing attacks on a remote server (so network latency serves as a handy-dandy rng).
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- mjbs 11y agoI think you are mostly right. They work at the fastest speed possible, the power usage is minimized by not doing anything when there is nothing to do. And from not having to propagate a clock signal all over the chip (maybe other reasons as well, I'm not an expert) If you are interested in real-world numbers, there is a comparison of between a GA144(an asynchronous multi-computer chip) and a MSP430(conventional low-power microprocessor) here: http://www.greenarraychips.com/home/documents/greg/WP003-100617-msp430.pdf http://www.greenarraychips.com/home/documents/greg/WP003-100... The GA144 can execute almost 4000x more instructions per second then MSP430 while consuming over 70x less power for the work done.
- akira2501 11y ago> The GA144 can execute almost 4000x more instructions per second then MSP430 while consuming over 70x less power for the work done. Yea, but the MSP430 actually has (a ton of) built in peripherals on it's own die, whereas the FA18 has none; so it's not the greatest comparison of J/MIPS.
- mjbs 11y agoYes, this only compares energy consumption to help show the difference between synchronous(with the explicit goal energy efficiency) and async designs. I don't think peripherals has anything to do with this comparison. There are obviously a ton of reasons why a MSP430 might make more sense for a given application. The GA144 is so radically different that any comparison to a conventional computer is difficult.