Kaspar Matas

dblp:259/3963 · also Kaspar Mätas · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
4since 2021 · last 2022
0000-0001-8001-0548ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 10 · 5 first-author · 4 since 2021
YearPublicationVenuePosition
2022 FPL Demo: Runtime Stream Processing with Resource-Elastic Pipelines on FPGAs
abstract
FPGAs are efficient at dataflow applications, as demonstrated in various application domains, including machine learning, communication, and image processing. In this demo, we accelerate database management operations transparently to the user by stitching together partially reconfigurable stream processing modules that implement database operators. Our runtime system orchestrates this, which builds custom pipelines according to runtime conditions. This demo will showcase an acceleration of SQL queries using our dynamic stream processing system running on a ZCU102 FPGA board.
Kaspar Matas, Kristiyan Manev, Joseph Powell, Dirk Koch
FPL1
2022 FPL Demo: FPGA Bitstream Virus Scanning
abstract
The expansion of the FPGA into complex market sectors imposes new demands on the security model of the devices. This demonstration shows off a series of tools developed to decode and scan the contents of a bitstream for malicious designs.
Joseph Powell, Kaspar Matas, Kristiyan Manev, Dirk Koch
FPL2
2022 byteman: A Bitstream Manipulation Framework
abstract
From better resource pooling for FPGA cloud providers to building dynamic execution pipelines at runtime, the capabilities of partial reconfiguration (PR) are waiting to be fully explored. However, the community still fails to materialize PR at scale, and FPGAs are only used as updatable ASICs, hence, omitting the opportunities offered by dynamically reconfiguring FPGAs at runtime. This work proposes a resourceful FPGA bitstream manipulation framework. The proposed tool provides means for parsing, modification, and generation of bitstream files, and it has been open-sourced and demonstrated in a working system. As a distinguished feature, it supports multidie FPGAs (among the 106 Xilinx 7 Series, UltraScale, and UltraScale+ devices), and enables datacenter FPGAs to be used for relocatable PR. Using the versatile tool's built-in (dis)assembler allows for manual bitstream manipulations. Bundled with an efficient bitstream manipulation core, the efficacy is demonstrated by two case studies where we observe 58 - 377x higher bitstream merging throughput than a current state-of-art tool.
Kristiyan Manev, Joseph Powell, Kaspar Matas, Dirk Koch
FPT3
2022 Automated Generation and Orchestration of Stream Processing Pipelines on FPGAs
abstract
FPGAs have demonstrated substantial performance and energy efficiency advantages for workloads that fit a stream processing model with direct module-to-module communication. However, when the dataflow processing system is required to adapt to runtime conditions, current static acceleration solutions are limited. To better use FPGAs in dynamic scenarios, this paper proposes using partial reconfiguration to stitch together different physically implemented operator modules on-the-fly. Rather than using designated module slots, our system places all modules and routing wires into a shared region with more placement options to minimize fragmentation. Furthermore, we use a module library that provides different resource and performance trade-offs for faster execution while considering the configuration cost. Our system finds the optimal set of modules while scheduling multiple acceleration requests and managing all constraints transparently to the end-user. We demonstrate that the middleware is fast enough to compose accelerator pipelines at runtime with end-to- end execution times equal to hand-crafted static systems when processing small datasets. For large datasets, we found up to 7.2 x faster execution over static systems when using our runtime methods. We exemplified our approach for database acceleration, where the whole dynamic FPGA acceleration is inferred by directly executing SQL queries.
Kaspar Matas, Kristiyan Manev, Joseph Powell, Dirk Koch
FPT1
2020 Power-hammering through Glitch Amplification - Attacks and Mitigation
abstract
Recent work on FPGA hardware security showed a substantial potential risk through power-hammering, which uses high switching activity in order to create excessive dynamic power loads. Virtually all present power-hammering attack scenarios are based on some kind of ring oscillators for which mitigation strategies exist. In this paper, we use a different strategy to create excessive dynamic power consumption: glitch amplification. By carefully designing XOR trees, fast switching wires can be implemented that, while driving high fan-out nets, can draw enough power to crash an FPGA. In addition to the attack (which is crashing an Ultra96 board), we will present a scanner for detecting malicious glitch amplifying FPGA designs.
Kaspar Matas, Tuan Minh La, Khoa Dang Pham, Dirk Koch
FCCM1
2020 Invited Tutorial: FPGA Hardware Security for Datacenters and Beyond
abstract
Since FPGAs are now available in datacenters to accelerate applications, providing FPGA hardware security is a high priority. FPGA security is becoming more serious with the transition to FPGA-as-a-Service where users can upload their own bitstreams. Full control over FPGA hardware through the bitstream enables attacks to weaken an FPGA-based system. These include physically damaging the FPGA equipment and leaking of sensitive information such as the secret keys of crypto algorithms. While there is no known attacks in the commercial settings so far, it is not so much a question of if but more of when? The tutorial will show concrete attacks applicable on datacenter FPGAs. The goal of this tutorial is to prepare the FPGA community to impending security issues in order to pave way for a proactive security. First, we will give a tour through the FPGA hardware security jungle surveying practical attacks and potential threats. We will reinforce this with live demos of denial of service attacks. Less than 10% of the logic resources on an FPGA can draw enough dynamic power to crash a datacenter FPGA card. In the second part of the tutorial, we will show different mitigations that are either vendor supported or proposed by the academic community. In summary, the tutorial will communicate that while FPGA hardware security is complicated to bring about, there are acceptable solutions for known FPGA security problems.
Kaspar Matas, Tuan La, Nikola Grunchevski, Khoa Dang Pham, Dirk Koch
FPGA1
2020 Securing FPGA Accelerators at the Electrical Level for Multi-tenant Platforms
abstract
As FPGAs are now offered on the cloud, this exposes many potential security issues. This PhD project investigates current security issues and challenges when deploying FPGAs in the cloud as well as using FPGAs in a multi-tenancy scenario. By addressing practical threats, and most importantly, proposing feasible countermeasures, this paper shows preliminary results on protecting FPGAs for multi-tenant scenarios.
Tuan La, Kaspar Matas, Khoa Dang Pham, Dirk Koch
FPL2
2020 Demo: A Closer Look at Malicious Bitstreams
abstract
As FPGAs are now offered on the cloud and widely used in critical applications (infrastructure, military, medical), this exposes many potential security issues in which attackers can deploy attacks remotely. This demo will take a closer look at malicious bitstreams and demo our FPGA bitstream virus scanner FPGADefender that can scan for signatures relating to malicious circuits and many forms of bitstream manipulations. Additionally, we show a deny-of-service power-hammering attack, which can serve as a template for hardware Trojans.
Tuan La, Kaspar Matas, Joseph Powell, Khoa Dang Pham, Dirk Koch
FPL2
2020 Transparent Integration of a Dynamic FPGA Database Acceleration System
abstract
A substantial amount of recent work has been conducted on accelerating different database operators or database management systems (DBMS) as a whole, both in proprietary and open-source services. The missing piece of work in this field is to transparently accelerate a widely-used open-source database on an FPGA without substantial changes to the core database code. This PhD project aims to use a partially reconfigurable stream processing architecture to compose different database operators into a pipeline orchestrated automatically by the database query optimizer and query planner. This way, the database users do not have to change any of the existing database management system code while allowing a runtime system to optimize queries with information known only during runtime.
Kaspar Matas, Dirk Koch
FPL1
2020 FPGADefender: Malicious Self-oscillator Scanning for Xilinx UltraScale + FPGAs
abstract
Sharing configuration bitstreams rather than netlists is a very desirable feature to protect IP or to share IP without longer CAD tool processing times. Furthermore, an increasing number of systems could hugely benefit from serving multiple users on the same FPGA, for example, for resource pooling in cloud infrastructures. This article researches the threat that a malicious application can impose on an FPGA-based system in a multi-tenancy scenario from a hardware security point of view. In particular, this article evaluates the risk systematically for FPGA power-hammering through short-circuits and self-oscillating circuits, which potentially may cause harm to a system. This risk includes implementing, tuning, and evaluating all FPGA self-oscillators known from the literature but also developing a large number of new power-hammering designs that have not been considered before. Our experiments demonstrate that malicious circuits can be tuned to the point that just 3% of the logic available on an Ultra96 FPGA board can draw the power budget of the entire FPGA board. This fact suggests a waste power potential for datacenter FPGAs in the range of kilowatts. In addition to carefully analyzing FPGA hardware security threats, we present the FPGA virus scanner FPGAD efender , which can detect (possibly) any self-oscillating FPGA circuit, as well as detecting short-circuits, high fanout nets, and a tapping onto signals outside the scope of a module for protecting data center FPGAs, such as Xilinx UltraScale+ devices at the bitstream level.
Tuan Minh La, Kaspar Matas, Nikola Grunchevski, Khoa Dang Pham, Dirk Koch
ACM Trans. Reconfigurable Technol. Syst.2