Hardware Based Detection, Recovery, and Tamper Evident Concept to Protect from Control Flow Violations in Embedded Processing

Patrick R. DaSilva, Paul Fortier · 2019

The ubiquitous presence of embedded devices coupled with their low processing power and finite energy creates unique challenges in the security of embedded systems. Software attacks targeted at maliciously modifying the control flow of an executing embedded program negatively affect real-time response. Hardware-based control flow violation detectors have been researched and tested, but still lack the means to recover from control flow attacks and provide meaningful data for post cyber-incident analysis. Proposed is a hardware-based system on a chip (SoC) concept to protect low-end embedded processors from control flow attacks. The concept provides an end-to-end protection combination of detection, response, recovery, and tamper evident techniques against control flow violations in the presence of interrupts, real-time operating systems, and exceptional functions. The implemented detection portion of the solution shows promise to detect most CRAs on low-end embedded systems without added cycle latency at the cost of increased area.

Read the paper · More papers on PaperTik