OpenTitan based Multi-Level Security in FPGA System-on-Chips
Sujan Kumar Saha, Abigail Butka, Muhammed Kawser Ahmed, Christophe Bobda · 2023
This article proposes a design methodology for integrating the OpenTitan-based security subsystem that enables Multi-level Security in FPGA SoCs. OpenTitan uses a light version of RISC-V and a set of crypto-accelerators. We extend the capabilities of OpenTitan to host the Mandatory Access Control (MAC) based policies as well as enforce the policies in hardware IPs in the SoCs. We implemented a hardware policy server, integrated it into the OpenTitan subsystem using the provided toolchain, and integrated the subsystem into an FPGA SoC. The experimental analysis shows the use case scenario of this security extension and the corresponding low overheads.