QuardTropy: Detecting and Quantifying Unauthorized Information Leakage in Hardware Designs using g-entropy
Hasan Al Shaikh, Mohammad Bin Monjil, Kimia Zamiri Azar, Farimah Farahmandi, Mark Mohammad Tehranipoor, Fahim Rahman · 2023
Ensuring the safeguarding of sensitive information from unauthorized disclosure is a core aspect of secure hardware. In modern SoC designs, information flow security (IFS) may be compromised by designer mistakes or maliciously-inserted functions at RTL/gate-level design abstractions. Developing unified IFS verification solutions that are scalable across abstraction levels and threat models, however, faces numerous challenges. In this paper, we provide the first formulation of the generalized information theoretic metric ‘g-entropy’ for hardware designs which measures the vulnerability of a design asset to leakage. Additionally, we propose QuardTropy, a novel unified IFS verification and quantification framework, which uses g-entropy to model and quantify unauthorized information leakage instances. The experimental results show that QuardTropy can successfully detect such unauthorized leakage paths, by finding outlier values in g-entropy compared to those of nominal paths, in various hardware design benchmarks regardless of their structural features.