Design of Reconfigurable Hardware Security Module Based on Network Protocol Detection

Zohouri, Hamid Reza | 2014

1958 Viewed
  1. Type of Document: M.Sc. Thesis
  2. Language: Farsi
  3. Document No: 45569 (19)
  4. University: Sharif University of Technology
  5. Department: Computer Engineering
  6. Advisor(s): Jahangir, Amir Hossein
  7. Abstract:
  8. Nowadays, in the presence of different types of computer attacks and different methods of eavesdropping on network communications, nobody can deny the importance of cryptography. Hardware Security Modules that are specifically designed for this purpose are widely used as a fast and reliable tool for encrypting data in computer networks. In this project, using the common and well-known FPGA platform and by leveraging the reconfigurability feature of this platform and also by adding a network protocol detection module to the traditional architecture of Hardware Security Modules, a novel module has been designed and implemented that can encrypt and decrypt data in a communication network, at layer 2 of OSI network model, without causing any disruptions in the normal operation of the network.
    Results obtained from testing the module using standard network device testers show that the implemented module, apart from being able to work transparently and without the knowledge of the two sides of the communication and also without hampering the normal operation of the network, can encrypt data at the sending node and decrypt it at the receiving node using the well-known AES algorithm, at near line speed (1 Gbps) and with negligible latency. Apart from this, the module was designed in a way permitting to easily change the cryptographic policy of the designed module, based on detecting the communication protocol in layer 2 of the OSI network model, by utilizing the partial reconfiguration feature in modern FPGAs.
  9. Keywords:
  10. Reconfiguration ; Cryptography ; Network Protocol ; Reconfigurable Hardware ; Hardware Security Module

 Digital Object List


...see more