Title
Pro-Active Policing and Policy Enforcement Architecture for Securing MPSoCs
Abstract
Embedded multiprocessor system-on-chip (MPSoC) architectures allow implementation of mixed critical applications and provide security mechanisms to segregate and protect system resources such as ARM TrustZone. These architectures enforce strict security measures right from the powering on of the system, to prevent misuse and compromise. However, such security measures have been found vulnerable where security design practices are not considered or are poorly implemented, particularly at software and hardware stack boundaries. Also, the embedded solutions developed using these MPSoC platforms are vulnerable to single points of failure and do not contain active response or mitigations for circumstances where a compromise occurs. This paper proposes pro-active hardware based policing and policy enforcement approach, along with system architecture and its hardware components, to this research problem. The architecture is physically isolated from the rich computing resources which actively monitors communications of system resources on the ARM AMBA-AXI4 bus. It detects anomalous system behaviours such as policy violation or compromised bus communication responses, and responds with predefined active countermeasures, such as deletion of secret data or disabling of the device to tackle security vulnerabilities and attacks at runtime. This proposed solution complements existing embedded hardware and software security technologies and provides an additional layer of hardware security when a vulnerability is found and exploited. This contribution lends itself to the principle of least privilege, implemented in software-based access control solutions like SELinux to mitigate when other protections have failed. This paper presents a proof-of-concept work supported by preliminary synthesis results on Xilinx Zynq-7000 and Ultra-Scale+ MPSoC chips.
Year
DOI
Venue
2018
10.1109/SOCC.2018.8618531
2018 31st IEEE International System-on-Chip Conference (SOCC)
Keywords
Field
DocType
FPGA MPSoC,Zynq,ARM AMBA AXI4,ARM TrustZone,Hardware Trojan,Active policing
Hardware Trojan,Single point of failure,Hardware security module,Principle of least privilege,Software security assurance,Computer security,Computer science,Access control,Systems architecture,MPSoC
Conference
ISSN
ISBN
Citations 
2164-1676
978-1-5386-1492-1
2
PageRank 
References 
Authors
0.37
9
3
Name
Order
Citations
PageRank
Fahad Manzoor Siddiqui1113.63
Matthew Hagan242.10
Sakir Sezer3101084.22