Secure Aggregate Encryption with Identity-Based Authentication for Multi-Vendor FPGA Cloud Deployment

📅 2026-10-08
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the key management challenges in multi-vendor FPGA clouds arising from fragmented authorization, authentication, and bitstream protection mechanisms by proposing the SAEID security framework. The framework introduces AgEID, a novel aggregated encryption scheme supporting dynamic membership management and capability-aware authorization, which achieves forward and backward access control under constant ciphertext size. By integrating certificateless authentication with AES-256-GCM bitstream verification, it ensures secure deployment across heterogeneous environments. Experimental evaluations on the ZC702 platform demonstrate that authentication requires only 4.35 milliseconds, device updates are completed within microseconds, and the full decryption path takes 191 milliseconds, thereby validating the practicality and scalability of the proposed approach.
📝 Abstract
Secure deployment of FPGA bitstreams in heterogeneous multi-vendor cloud infrastructures requires scalable authorization, authenticated device access, and bitstream protection throughout the deployment lifecycle. Existing approaches typically address these functions through separate mechanisms, increasing coordination and key management requirements. This paper presents SAEID, a secure FPGA deployment framework that integrates aggregate authorization, certificate-free identity-based device authentication, and identity bound bitstream verification within a pairing based cryptographic framework, with symmetric cryptography used for session binding and AES 256 GCM based bitstream protection. Building on AgEID, an aggregate encryption scheme that enables individual decryption for authorized FPGA devices, SAEID extends the underlying framework to heterogeneous multi vendor deployments by supporting multiple FPGA vendors and IP providers, capability-aware authorization, and dynamic device membership. SAEID provides protection against unauthorized access to future deployments after device revocation and to prior deployments by newly enrolled devices, while retaining constant-size aggregate ciphertexts within each vendor domain and individual decryption. Experimental results demonstrate the practical performance of SAEID, with identity-based device authentication completing in approximately 4.35 ms and device membership updates requiring 4.95 to 5.09 micro seconds for device addition. The aggregate-encryption component exhibits scalable behavior with increasing device-set size. The complete SAEID software decryption path was also validated on a physical ZC702 Cortex A9 platform, requiring 191.126 ms. These results demonstrate scalable aggregate authorization with bounded authentication and dynamic-membership overhead for secure multi-vendor FPGA deployment.
Problem

Research questions and friction points this paper is trying to address.

FPGA cloud security
multi-vendor deployment
bitstream protection
device authentication
aggregate authorization
Innovation

Methods, ideas, or system contributions that make the work stand out.

Aggregate Encryption
Identity-Based Authentication
Multi-Vendor FPGA Cloud
Dynamic Device Membership
Bitstream Protection
🔎 Similar Papers
No similar papers found.