Muhammed Kawser Ahmed

dblp:276/4113 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0001-7389-7232ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Multi-Tenant Cloud FPGA: A Survey on Security, Trust, and Privacy
abstract
With the growing demand for enhanced performance and scalability in cloud applications and systems, data center architectures are evolving to incorporate heterogeneous computing fabrics that leverage CPUs, GPUs, and FPGAs. Unlike traditional processing platforms like CPUs and GPUs, FPGAs offer the unique ability for hardware reconfiguration at runtime, enabling improved and tailored performance, flexibility, and acceleration. FPGAs excel at executing large-scale search optimization, acceleration, and signal processing tasks while consuming low power and minimizing latency. Major public cloud providers, such as Amazon, Huawei, Microsoft, Alibaba, and others, have already begun integrating FPGA-based cloud acceleration services into their offerings. Although FPGAs in cloud applications facilitate customized hardware acceleration, they also introduce new security challenges that demand attention. Granting cloud users the capability to reconfigure hardware designs after deployment may create potential vulnerabilities for malicious users, thereby jeopardizing entire cloud platforms. In particular, multi-tenant FPGA services, where a single FPGA is divided spatially among multiple users, are highly vulnerable to such attacks. This article examines the security concerns associated with multi-tenant cloud FPGAs, provides a comprehensive overview of the related security, privacy and trust issues, and discusses forthcoming challenges in this evolving field of study.
Muhammed Kawser Ahmed, Max Panoff, Joel Mandebi, Sujan Kumar Saha, Erman Nghonda, Peter Mbua, Christophe Bobda
ACM Trans. Reconfigurable Technol. Syst.1
2024 Ph.D. Project - IsoFPGA - A Novel CMOS Galvanic Isolation for Remote Physical Attacks in Multi-tenant Cloud FPGA
abstract
Although FPGAs in cloud applications facilitate customized hardware acceleration, they also introduce new security challenges that demand attention. Granting cloud users, the capability to reconfigure hardware designs after deployment may create potential vulnerabilities for malicious users, thereby jeopardizing entire cloud platforms. Multi-tenant FPGA services, where a single FPGA is divided spatially among multiple users, are highly vulnerable to such attacks such as remote power side channel attacks, Denial of Service (DoS) attacks and Fault Injection attacks. Security solutions are limited by the architectural design of existing FPGAs. We propose a novel power distribution network for cloud FPGA security using physical CMOS-based galvanic isolation. In this architecture, each tenant is isolated spatially, providing protection against voltage spikes, ground loops, and electrical noise, the key premises of remote physical attacks. The isolation technique is carried out by using reconfigurable MoM (Metal-over-Metal) capacitors and switch banks, along with Power Management and Configuration Controller Unit. By implementing a Custom Configuration Memory (CCM), we aim to provide a dynamic and customizable solution that allows FPGA designers to selectively interconnect or isolate groups of Configurable Logic Blocks (CLBs). This approach involves the formation of distinct regions within the FPGA, each capable of sourcing power either from a dedicated CMOS isolation power supply or the standard FPGA voltage power supply. Our approach, leveraging physical isolation, can successfully prevent such attacks and can be established as the first line of defense for cloud FPGA security.
Muhammed Kawser Ahmed, Christophe Bobda
FCCM1
2024 ISO-TENANT: Rethinking FPGA Power Distribution Network (PDN): A Hardware Based Solution for Remote Power Side Channel Attacks in FPGA
abstract
Although FPGAs in cloud applications facilitate customized hardware acceleration, they also introduce new security challenges that demand attention. Granting cloud users, the capability to reconfigure hardware designs after deployment may create potential vulnerabilities for malicious users, thereby jeopardizing entire cloud platforms. Multi-tenant FPGA services, where a single FPGA is divided spatially among multiple users, are highly vulnerable to such attacks such as remote power side channel attacks, Denial of Service (DoS) attacks and Fault Injection attacks. We propose a novel power distribution network for cloud FPGA security using physical CMOS-based galvanic isolation. In this architecture, each tenant is isolated spatially, providing protection against voltage spikes, ground loops, and electrical noise, the key premises of remote power side-channel attacks. The isolation technique is carried out by using reconfigurable MoM (Metal-over-Metal) capacitors and switch banks, along with Power Management and Configuration Controller Unit. By implementing a Custom Configuration Memory (CCM), we aim to provide a dynamic and customizable solution that allows FPGA designers to selectively interconnect or isolate groups of Configurable Logic Blocks (CLBs). This approach involves the formation of distinct regions within the FPGA, each capable of sourcing power either from a dedicated CMOS isolation power supply or the standard FPGA voltage power supply. Our approach, leveraging physical isolation, can successfully prevent such attacks and can be established as the first line of defense for cloud FPGA security.
Muhammed Kawser Ahmed, Christophe Bobda
FPGA1