Evaluating security requirements in a general-purpose processor by combining assertion checkers with code coverage
Evaluating security requirements in a general-purpose processor by combining assertion checkers with code coverage
复制标题
通过将断言检查器与代码覆盖率相结合来评估通用处理器中的安全要求
DOI:
10.1109/hst.2012.6224318
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
T. Levin
中科院分区:
文献类型:
--
作者:
Michael Bilzor;Ted Huffmire;C. Irvine;T. Levin
The problem of malicious inclusions in hardware is an emerging threat, and detecting them is a difficult challenge. In this research, we enhance an existing method for creating assertion-based dynamic checkers, and demonstrate how behavioral security requirements can be derived from a processor's architectural specification, then converted into security checkers that are part of the processor's design. The novel contributions of this research are: - We demonstrate the method using a set of assertions, derived from the architectural specification, on a full-scale open-source general-purpose processor design, called OpenRISC. Previous work used only a single assertion on a toy processor design. - We demonstrate the use of our checker-generator tool, called psl2hdl, which was created for this research. - We illustrate how the method can be used in concert with code coverage techniques, to either detect malicious inclusions or greatly narrow the search for malicious inclusions that use rare-event triggers.