Prioritizing Information Flow Violations: Generation of Ranked Security Assertions for Hardware Designs

Avinash Ayalasomayajula, Nusrat Farzana, Debjit Pal, Farimah Farahmandi · 2024

In today's fast-evolving computing environment, hardware designs like System-on-Chips (SoCs) are ubiquitous due to their small form factor and ability to perform complex operations. These designs often compute using users' private information, necessitating rigorous security checks to prevent vulnerabilities that could expose sensitive data. In this work, we propose a novel approach for assertion generation tailored for checking information leakage in hardware designs. Leveraging static analysis and data mining techniques, we introduce SecMiner, a framework that automatically generates assertions capable of detecting potential information leakages in a hardware design. We develop a novel security label tracking algorithm to help track secure information flows within the design structure whose violation would indicate information leakage. Not all assertions may bear equal security implications; some might be critical in identifying critical vulnerabilities, while others could be simpler in capturing minor concerns. Hence, we introduce a security assertion ranking mechanism that mimics a domain expert to evaluate each assertion based on its relevance to the security of the design and ease of understanding. Our approach uniquely emphasizes identifying information flow within hardware designs, with a detailed and comprehensive ranking mechanism that enhances the depth and breadth of security analysis compared to previous methods. We evaluated our SecMiner framework on open-source hardware benchmarks such as cryptographic and security modules. The experimental results elucidate that our approach is fast, scalable, and computationally efficient with a reasonable memory footprint and can streamline the security validation process by prioritizing high-value assertions.

Read the paper · More papers on PaperTik