A Framework for Design, Verification, and Management of SoC Access Control Systems

A Framework for Design, Verification, and Management of SoC Access Control Systems
复制标题

SoC 访问控制系统的设计、验证和管理框架

DOI:
10.1109/tc.2022.3209923
复制
发表时间:
2023
影响因子:
3.7
通讯作者:
J. Oberg
J. Oberg
中科院分区:
计算机科学2区
文献类型:
--
作者:
Francesco Restuccia;Andres Meza;R. Kastner;J. Oberg

文献摘要

参考文献

被引文献

相似文献

片上系统(SoC)体系结构是微处理器、定制加速器、存储器、接口、外围设备和其他资源的异类混合。这些资源使用复杂的片上互连网络进行通信,这些网络试图快速有效地仲裁存储器事务,这些存储器事务的行为可以根据当前的操作模式和系统操作状态而有很大的变化。安全和安全关键型应用程序需要定义这些资源如何交互的访问控制策略,以确保不会发生恶意和不安全行为。AKER是一个用于片上访问控制的设计和验证框架。AKER的核心是访问控制包装(ACW),这是一个高性能但高效的硬件模块,可以动态仲裁片上通信。AKER在整个SoC中分配ACW,并对其进行编程以执行本地访问控制。AKER提供固件生成工具和属性驱动的安全验证方法,以确保正确集成和配置ACW。AKER安全验证确认ACW在IP级别运行正常。它验证信任固件的硬件根是否正确配置了ACW。并评估由于共享资源之间的交互而造成的系统级安全威胁。AKER在Xilinx UltraScale+可编程SoC上进行了实验验证。此外,AKER访问控制系统被集成到使用OpenTitan硬件信任根进行固件配置的OpenPULP多核体系结构中。
System-on-chip (SoC) architectures are a heterogeneous mix of microprocessors, custom accelerators, memories, interfaces, peripherals, and other resources. These resources communicate using complex on-chip interconnect networks that attempt to quickly and efficiently arbitrate memory transactions whose behaviors can vary drastically depending on the current mode of operation and system operating state. Security- and safety-critical applications require access control policies that define how these resources interact to ensure that malicious and unsafe behaviors do not occur. Aker is a design and verification framework for on-chip access control. The core of Aker is the access control wrapper (ACW)–a high-performance yet efficient hardware module that dynamically arbitrates on-chip communications. Aker distributes ACWs across the SoC and programs them to perform local access control. Aker provides a firmware generation tool and a property-driven security verification methodology to ensure that the ACWs are properly integrated and configured. Aker security verification confirms that the ACW behaves properly at IP level. It verifies the hardware root of trust firmware configures the ACW correctly. And it evaluates system-level security threats due to interactions between shared resources. Aker is experimentally validated on a Xilinx UltraScale+ programmable SoC. Additionally, an Aker access control system is integrated into the OpenPULP multicore archtiecture that uses OpenTitan hardware root-of-trust for firmware configuration.
Aker:安全可靠的 SoC 访问控制的设计和验证框架
DOI: --
发表时间: 2021
期刊: International Conference on Computer Aided Design
影响因子: --
作者:
Restuccia, Francesco;Meza, Andres;Kastner, Ryan
通讯作者: Kastner, Ryan