Secure integration of non-trusted IPs in SoCs
Festus Hategekimana, Taylor JL Whitaker, Md Jubaer Hossain Pantho, Christophe Bobda · 2017
This paper explores the use of hardware sand-boxes, conceptually similar to software sandboxes, for secure integration of non-trusted IPs in systems-on-chip (SoC) designs. Our approach is based on a general assumption that malicious components hidden in IPs pose no harm to the system as long as they don't manifest. Thus, the goal of the hardware sandbox is to only allow permissible interactions between the IP and the rest of the system. The proposed hardware sandbox design achieves this by exposing the IP interface to isolated virtual resources and checking IP signals' “correctness” at run-time. We evaluated the hardware sandbox through a real world design implementation. Our sandbox can detect a majority of Trust-Hub.org Trojan benchmarks with a negligible increase in resource overhead.