3 ms·
Which is why the interconnect fabric adds the source address based on who made the request. Even hardware IP blocks don't have the ability to send packets from
by azonenberg 5y ago
Which is why the interconnect fabric adds the source address based on who made the request.
Even hardware IP blocks don't have the ability to send packets from arbitrary addresses. You can send to anywhere you want, but you can't lie about who made the request. Which allows access control to be enforced at the receiving end.
That "something you are" as well as "something you know" factor prevents any capability from being spoofed, since the identity of the device initiating the request is part of the capability.
- bruiseralmighty 5y agoI guess I am not understanding something still about this spoof protection. What prevents me, an attacker, from making (or simulating) a bunch of hardware with different identities? Perhaps by setting up my hardware to run through multiple different 'self' identities and then trying to talk to other hardware with each disguise. If the address space is small and cheap, it seems that I could quickly map any decentralized hardware at low cost.
- azonenberg 5y agoThis is a SoC, addresses of on chip devices are fixed when the silicon is made. The source address is added to a packet by the on-chip router as it's received. You can send anything you want into a port, but you can't make it seem like it came from a different port without modifying the router. This model allows you to integrate IP cores from semi-untrusted third parties, or run untrusted code on a CPU, without allowing impersonation. Let me put it another way: I ran a SAT solver on the compiled gate-level netlist of the router and proved that it can't ever emit a packet with a source address other than the hard-wired address of the source port. Any packet coming from a peripheral into port X will have port X's address on it when it leaves the router, end of story.