3 ms·
You can easily replicate a 4000-transistor microprocessor with the lowest-end FPGA for a few dollars - cheaper than any 3D-printing process for silicon that I c
by yaakov34 10y ago
You can easily replicate a 4000-transistor microprocessor with the lowest-end FPGA for a few dollars - cheaper than any 3D-printing process for silicon that I can imagine. It would, of course, also be reprogrammable, making it very cheap for prototypes and experiments.
- kibwen 10y agoFrom a security perspective, how feasible is it for a state-level actor to usefully backdoor a FPGA? I imagine that part of the appeal of personally-fabricated hardware is that, if you validate the design, you have greater assurance about the code executing on your machine. Sort of like the difference between compiling from source and trusting a binary blob (though, just like compilers can be backdoored, I imagine there are theoretical attacks involving subverting the fab itself...).
- yaakov34 10y agoSure. FPGAs, or any IC, could contain subversive/backdoor hardware placed there by a sophisticated actor. For that matter, so could ostensibly passive components like connectors, ports, flat ribbon cables... now that we have sophisticated circuits that can be powered by stray magnetic waves (RFID and its advanced friends), so can components not connected to power, such as cases, clips, screws. It is a fascinating thing to think about, actually, and I don't see how 3D-printing every single thing around you is a realistic solution. And considering that regular color printers (inkjet and laser) have all been backdoored for ages - they print mostly invisible constellations of dots into every page which identify the individual printer - I would say that backdooring a "silicon printer" is also a definite possibility.
- colejohnson66 10y ago> now that we have sophisticated circuits that can be powered by stray magnetic waves (RFID and its advanced friends) The Soviets were doing that back in the 40s[0] [0]: https://en.wikipedia.org/wiki/The_Thing_(listening_device) https://en.wikipedia.org/wiki/The_Thing_(listening_device)
- Cyph0n 10y agoIt's quite feasible. State of the art FPGA chips are typically manufactured in third party fabs. These are primarily TSMC, GlobalFoundries, and UMC. I'm guessing Intel's acquisition of Altera will result in a more "trustworthy" FPGA. In a nutshell, if a state actor can access the fab, it can insert a backdoor. With circuit design, fully independent verification has not been solved yet. The primary reason is that fabrication, especially at lower process nodes, is extremely complex. So even if you had a "3D IC printer" at home, you still need to trust the manufacturer of that printer, as well as the manufacturer of the key components of the printer. Taking that even further, you need to trust that each of those components was manufactured by a trusted fab. It's turtles all the way down. If I were to design such a printer from scratch, I would have a consortium of known companies oversee the design of the first printer and all of its components in a closed environment with 24/7 surveillance. All circuits would be fabbed using a manual, low volume process. Once the initial printer is complete, all the circuits of subsequent printers would be fabbed using this root printer. There are shortcomings with this technique too, but it's probably the best way to go about doing it (with current tech).
- kibwen 10y agoI agree that trusting the manufacturer of the fab would constitute a potential attack vector, but if the fab was capable of reproducing itself (in conjunction with other tools, of course) then persistent subversion of the fab would be analogous to a trusting-trust attack. And just like trusting-trust attacks can be satisfactorily mitigated (e.g. via diverse compilation), so could a trusted hardware toolchain eventually be produced. The question then is just whether such a thing is worth the large effort. :)
- pjc50 10y agoBackdooring the device itself is equally hard/easy as any other form of IC. The question is, with what? Because it doesn't have a fixed function it's almost impossible to set up any specific subversive behaviour in advance without knowing what might be run on it. The most likely attack would be an override of the code protect/security fuse/anti-JTAG features. But that's only useful when the attacker has got hold of the device and is probing it.
- kibwen 10y ago> Because it doesn't have a fixed function it's almost impossible to set up any specific subversive behaviour in advance without knowing what might be run on it. This is precisely the essence of my question, given that I have little knowledge of FPGAs and have no real clue how much each reprogrammed circuit has in common with any other. :)
- pjc50 10y ago> how much each reprogrammed circuit has in common with any other Very little. An FPGA is a set of reprogrammable logic blocks (LUTs) of very small size, plus a number of special purpose peripherals. The "layout" process of assigning functions to LUTs is usually done with simulated annealing and random perturbation. The compiler won't necessarily give the same output from the same input, let alone slightly different input. The fixed-function blocks and any embedded processors (e.g. Nios) are more targetable. But you could also e.g. set up the clock PLL to leak the FPGA configuration slowly via spread-spectrum modulation.
- kibwen 10y agoI'm fascinated to hear that the process of programming a FPGA involves genetic algorithms! Where can I read more about that?
- prewett 10y agoSimulated annealing isn't technically a genetic algorithm (nor is random perturbation). Simulated annealing jiggles things randomly (in this case, probably locations of LUTs), with decreasing amplitude over time. The amplitude of the random perturbations is the "temperature," which decreases until the system has settled into a (hopefully global) optimum. So basically this system will start moving the LUTs around a lot, keeping the most optimal results, and gradually start moving them around less and less until the result doesn't change for a while. A genetic algorithm, by contrast, encodes the system into a "string" (like a DNA strand), and then swaps pieces of strings between two "organisms," just like genetic mating does. The most optimal descendants are kept, the least are discarded, and the process is repeated. This would be harder to implement for locations, as you would have to encode locations onto a string, and be able to swap pieces of strings while maintaining the functionality of the LUTs.