TY - GEN
T1 - Real-Time Instruction Execution Monitoring with Hardware-Assisted Security Monitoring Unit in RISC-V Embedded Systems
AU - Zhang, Zhun
AU - Hao, Qiang
AU - Xu, Dongdong
AU - Wang, Jiqing
AU - Ma, Jinhui
AU - Zhang, Jinlei
AU - Liu, Jiakang
AU - Wang, Xiang
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022
Y1 - 2022
N2 - Embedded systems involve an integration of a large number of intellectual property (IP) blocks to shorten chip's time to market, in which, many IPs are acquired from the untrusted third-party suppliers. However, existing IP trust verification techniques cannot provide an adequate security assurance that no hardware Trojan was implanted inside the untrusted IPs. Hardware Trojans in untrusted IPs may cause processor program execution failures by tampering instruction code and return address. Therefore, this paper presents a secure RISC-V embedded system by integrating a Security Monitoring Unit (SMU), in which, instruction integrity monitoring by the fine-grained program basic blocks and function return address monitoring by the shadow stack are implemented, respectively. The hardware-assisted SMU is tested and validated that while CPU executes a CoreMark program, the SMU does not incur significant performance overhead on providing instruction security monitoring. And the proposed RISC-V embedded system satisfies good balance between performance overhead and resource consumption.
AB - Embedded systems involve an integration of a large number of intellectual property (IP) blocks to shorten chip's time to market, in which, many IPs are acquired from the untrusted third-party suppliers. However, existing IP trust verification techniques cannot provide an adequate security assurance that no hardware Trojan was implanted inside the untrusted IPs. Hardware Trojans in untrusted IPs may cause processor program execution failures by tampering instruction code and return address. Therefore, this paper presents a secure RISC-V embedded system by integrating a Security Monitoring Unit (SMU), in which, instruction integrity monitoring by the fine-grained program basic blocks and function return address monitoring by the shadow stack are implemented, respectively. The hardware-assisted SMU is tested and validated that while CPU executes a CoreMark program, the SMU does not incur significant performance overhead on providing instruction security monitoring. And the proposed RISC-V embedded system satisfies good balance between performance overhead and resource consumption.
KW - Embedded system
KW - RISC-V
KW - Security Monitoring Unit (SMU)
KW - hardware Trojan attack
KW - hardware security
UR - https://www.scopus.com/pages/publications/85149439057
U2 - 10.1109/ICNISC57059.2022.00048
DO - 10.1109/ICNISC57059.2022.00048
M3 - 会议稿件
AN - SCOPUS:85149439057
T3 - Proceedings - 2022 8th Annual International Conference on Network and Information Systems for Computers, ICNISC 2022
SP - 192
EP - 196
BT - Proceedings - 2022 8th Annual International Conference on Network and Information Systems for Computers, ICNISC 2022
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 8th Annual International Conference on Network and Information Systems for Computers, ICNISC 2022
Y2 - 16 September 2022 through 19 September 2022
ER -