COSSEA: Context-based SoC Security Enforcement Architecture

Carsten Heinz, Andreas Koch · 2024

Modern embedded System-on-Chips (SoCs) increasingly rely on third-party Intellectual Property (IP) blocks to realize complex designs while meeting cost and time budgets. However, this IP integration from many vendors can adversely affect the SoC’s security when even a single IP originates from a malicious actor and then threatens the integrity of the entire SoC. In this work, we propose COSSEA, a global, context-based security architecture, to control communication on the SoC at a fine-grained level. COSSEA isolates IP from the central system interconnect with different access permissions based on dynamically adaptable context descriptions. A global state-machine coordinates the transition between these security contexts. COSSEA can scale to thousands of contexts using features such as a parametrizable policy directory. At run-time, the entire security architecture is managed independently of any CPU or peripheral, reducing the attack surface. COSSEA is already set up to be securely controlled by a hardware root-of-trust using authenticated and encrypted messages. We evaluate COSSEA for both FPGA and ASIC and observe hardware overheads of less than $2 \%$ for small SoCs typical of MCU-level embedded systems.

Read the paper · More papers on PaperTik