Isadora: Automated Information Flow Property Generation for Hardware Designs

Isadora: Automated Information Flow Property Generation for Hardware Designs
复制标题

DOI:
10.1145/3474376.3487286
复制
发表时间:
2021-06
期刊:
Proceedings of the 5th Workshop on Attacks and Solutions in Hardware Security
影响因子:
--
通讯作者:
Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton
Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton
中科院分区:
其他
文献类型:
--
作者:
Calvin Deutschbein;Andres Meza;Francesco Restuccia;R. Kastner;C. Sturton

文献摘要

相似文献

Isadora是一种创建硬件设计信息流规范的方法。该方法结合了信息流跟踪和规范挖掘,产生了一组信息流属性,这些属性适合在安全验证过程中使用,并支持更好地理解设计的安全状态。Isadora是完全自动化的;用户只提供正在考虑的设计和测试台,不需要提供威胁模型或安全规范。我们在RISC-V处理器和两个与SoC访问控制相关的设计上对Isadora进行了评估。Isadora生成的安全属性与通用弱点枚举(CWE)建议的属性一致,并且在SoC设计的情况下,与安全专家手动编写的属性一致。
Isadora is a methodology for creating information flow specifications of hardware designs. The methodology combines information flow tracking and specification mining to produce a set of information flow properties that are suitable for use during the security validation process, and which support a better understanding of the security posture of the design. Isadora is fully automated; the user provides only the design under consideration and a testbench and need not supply a threat model nor security specifications. We evaluate Isadora on a RISC-V processor plus two designs related to SoC access control. Isadora generates security properties that align with those suggested by the Common Weakness Enumerations (CWEs), and in the case of the SoC designs, align with the properties written manually by security experts.