SHIELD: A software hardware design methodology for security and reliability of MPSoCs

SHIELD: A software hardware design methodology for security and reliability of MPSoCs
复制标题

SHIELD:一种确保 MPSoC 安全性和可靠性的软件硬件设计方法

DOI:
10.1145/1391469.1391686
复制
发表时间:
2008
期刊:
2008 45th ACM/IEEE Design Automation Conference
影响因子:
--
通讯作者:
S. Parameswaran
S. Parameswaran
中科院分区:
--
文献类型:
--
作者:
K. Patel;S. Parameswaran

文献摘要

被引文献

相似文献

MPSoC的安全性是嵌入式系统中一个新兴的关注领域。代码注入攻击是最常见的软件攻击类型,其安全性受到危害。以前尝试检测MPSoC中的代码注入已经负担了显着的性能开销。在这项工作中,我们提出了一个硬件/软件的方法“盾牌”来检测MPSoC中的代码注入攻击。SHIELD检测MPSoC中应用处理器上运行的软件程序,并提取控制流和基本块执行时间信息用于运行时检查。我们采用了一个专用的安全处理器(监控处理器)来监督MPSoC上的应用处理器。定制硬件被设计并用于监视器和应用处理器。监视器处理器使用定制硬件在运行时快速分析从应用处理器传送到它的信息。我们已经实现了SHIELD的商业可扩展处理器(Xtensa LX 2),并测试了它的多处理器JPEG编码器程序。除了代码注入攻击外,该系统还能够检测到控制流指令中83%的位翻转错误。实验表明,SHIELD产生的系统运行时间比以前的解决方案至少快9倍。与非安全系统相比,SHIELD的运行时(时钟周期)性能开销仅为6.6%,面积开销为26.9%。
Security of MPSoCs is an emerging area of concern in embedded systems. Security is jeopardized by code injection attacks, which are the most common types of software attacks. Previous attempts to detect code injection in MPSoCs have been burdened with significant performance overheads. In this work, we present a hardware/software methodology "SHIELD" to detect code injection attacks in MPSoCs. SHIELD instruments the software programs running on application processors in the MPSoC and also extracts control flow and basic block execution time information for runtime checking. We employ a dedicated security processor (monitor processor) to supervise the application processors on the MPSoC. Custom hardware is designed and used in the monitor and application processors. The monitor processor uses the custom hardware to rapidly analyze information communicated to it from the application processors at runtime. We have implemented SHIELD on a commercial extensible processor (Xtensa LX2) and tested it on a multiprocessor JPEG encoder program. In addition to code injection attacks, the system is also able to detect 83% of bit flips errors in the control flow instructions. The experiments show that SHIELD produces systems with runtime which is at least 9 times faster than the previous solution. SHIELD incurs a runtime (clock cycles) performance overhead of only 6.6% and an area overhead of 26.9%, when compared to a non-secure system.