Special Session: CAD for Hardware Security - Promising Directions for Automation of Security Assurance

Special Session: CAD for Hardware Security - Promising Directions for Automation of Security Assurance
复制标题

DOI:
10.1109/vts56346.2023.10140100
复制
发表时间:
2023-04
期刊:
2023 IEEE 41st VLSI Test Symposium (VTS)
影响因子:
--
通讯作者:
Sohrab Aftabjahani;M. Tehranipoor;Farimah Farahmandi;Bulbul Ahmed;R. Kastner;Francesco Restuccia;Andres Meza;Kaki Ryan;Nicole Fern;J. V. Woudenberg;Rajesh Velegalati;Cees-Bart Breunesse;C. Sturton;Calvin Deutschbein
Sohrab Aftabjahani;M. Tehranipoor;Farimah Farahmandi;Bulbul Ahmed;R. Kastner;Francesco Restuccia;Andres Meza;Kaki Ryan;Nicole Fern;J. V. Woudenberg;Rajesh Velegalati;Cees-Bart Breunesse;C. Sturton;Calvin Deutschbein
中科院分区:
其他
文献类型:
--
作者:
Sohrab Aftabjahani;M. Tehranipoor;Farimah Farahmandi;Bulbul Ahmed;R. Kastner;Francesco Restuccia;Andres Meza;Kaki Ryan;Nicole Fern;J. V. Woudenberg;Rajesh Velegalati;Cees-Bart Breunesse;C. Sturton;Calvin Deutschbein

文献摘要

相似文献

硬件安全为现代生活中使用的系统和应用程序的安全可靠运行创建了基于硬件的安全基础。如今,许多大型半导体设计和制造公司的产品生命周期中存在安全设计、安全保证和通用安全设计生命周期实践,这表明硬件安全的重要性在业界得到了很好的体现。然而,由于使用许多手动流程,在设计中构建安全性并确保其安全性所需的高成本、时间和精力仍然是安全产品开发经济性的重要障碍。本文提出了安全设计自动化和安全保证实践的几个有前途的方向,以减少安全产品开发的总体时间和成本。首先,我们提出了 SoC 的安全验证挑战、将一个抽象级别的设计模型映射到其较低级别的工具可能无意中引入的可能的漏洞,以及我们通过自动将安全属性从一个级别映射到其较低级别并结合属性扩展和扩展技术来解决问题的方案。然后,我们讨论了进一步自动化设计的正式安全分析所需的基础,方法是将威胁模型和常见安全漏洞合并到硬件模型的中间表示中,用于自动确定是否存在直接或间接信息流损害安全资产的机密性或完整性的机会。最后,我们讨论了一种基于硅前的框架,用于实用且节省时间和成本的电源侧通道泄漏分析,通过使用自动生成的电路节点泄漏曲线来找出侧通道泄漏的根源,通过解决高泄漏节点来提供减轻侧通道泄漏的见解,并通过重新分析泄漏以证明其可接受的消除水平来确保缓解的有效性。我们希望与安全研究社区分享这些努力和想法,能够加速安全感知 CAD 工具的发展,这些工具旨在设计安全和安全保证,从而丰富生态系统,让来自多个供应商的工具具有更多功能和更高性能。
Hardware security creates a hardware-based security foundation for secure and reliable operation of systems and applications used in our modern life. The presence of design for security, security assurance, and general security design life cycle practices in product life cycle of many large semiconductor design and manufacturing companies these days indicates that the importance of hardware security has been very well observed in industry. However, the high cost, time, and effort for building security into designs and assuring their security - due to using many manual processes - is still an important obstacle for economy of secure product development. This paper presents several promising directions for automation of design for security and security assurance practices to reduce the overall time and cost of secure product development. First, we present security verification challenges of SoCs, possible vulnerabilities that could be introduced inadvertently by tools mapping a design model in one level of abstraction to its lower level, and our solution to the problem by automatically mapping security properties from one level to its lower level incorporating techniques for extension and expansion of the properties. Then, we discuss the foundation necessary for further automation of formal security analysis of a design by incorporating threat model and common security vulnerabilities into an intermediate representation of a hardware model to be used to automatically determine if there is a chance for direct or indirect flow of information to compromise confidentiality or integrity of security assets. Finally, we discuss a pre-silicon-based framework for practical and time-and-cost effective power-side channel leakage analysis, root-causing the side-channel leakage by using the automatically generated leakage profile of circuit nodes, providing insight to mitigate the side-channel leakage by addressing the high leakage nodes, and assuring the effectiveness of the mitigation by reprofiling the leakage to prove its acceptable level of elimination. We hope that sharing these efforts and ideas with the security research community can accelerate the evolution of security-aware CAD tools targeted to design for security and security assurance to enrich the ecosystem to have tools from multiple vendors with more capabilities and higher performance.