HERA: A Substrate-Level Covert Channel Detector for Heterogeneous Chiplet Systems
Abstract
Modern computing systems are transitioning from large-scale monolithic SoCs toward modular heterogeneous chiplet systems. The smaller chiplets are integrated on a substrate/interposer and connected using a Network-on-Package. Chiplet-based integration brings several new advantages such as performance improvement and cost reduction through yield benefits, heterogeneity, and reuse. Despite these advantages, heterogeneity also brings new security challenges. As more mutually untrusted chiplets are integrated into a shared substrate, complex cross-component attacks (e.g., a covert channel between CPU/GPU) are rising. The main insight of this paper is that the Network-on-Package (NoP) offers a unique opportunity to develop a comprehensive and cost-effective monitoring framework to address increasing security concerns in heterogeneous systems. This new component can specifically monitor the communication packets exchanged among various chiplets, such as the CPU, GPU, and memory, to detect different attacks. Specifically, by integrating this security feature, the system can protect against unauthorized or malicious communication between components, helping to reduce the risk of emerging cross-component attacks, such as covert channels. Our main contribution is to design and implement this security component called the HEterogeneous secuRity Analyzer (HERA). We carefully design various aspects of our system to balance security and overhead.