Hardware-software co-design methods to unleash open hardware cybersecurity and trust in RISC-V architectures
Alberto Musa · AMS Dottorato Institutional Doctoral Theses Repository (University of Bologna) · 2026
The rapid growth of the open-source RISC-V ecosystem and the increasing criticality of embedded systems demand robust defense mechanisms against software exploits, hardware attacks, and emerging quantum threats. OpenTitan, an open-source silicon Root-of-Trust (RoT), provides a secure foundation with features like secure boot, hardware isolation, and cryptographic accelerators. However, fully exploiting these capabilities is challenging due to a gap between advanced hardware and the maturity of software support. This thesis introduces TitanSSL, a holistic hardware-software co-design framework that bridges this gap, enabling secure, high-performance cryptographic operations on RISC-V System-on-Chips (SoCs). TitanSSL integrates three components: a custom OpenSSL engine, optimized OpenTitan firmware, and a Linux kernel driver. Together, they offload cryptographic workloads to OpenTitan accelerators while extending RoT benefits, including secure key storage and system integrity. A secure communication protocol coordinates memory protection, data exchange, and resource arbitration between the host processor and OpenTitan. Performance evaluation on a CVA6 core running Linux with OpenTitan on a Xilinx VCU118 FPGA shows significant speedups for large payloads (128 KiB), achieving 10.50x for SHA-256 and 2.96x for AES-256-CBC compared to software-only implementations. Early data movement limitations restricted accelerator utilization to 9.35%, prompting enhancements with Direct Memory Access (DMA) and Tightly Coupled Data Memory (TCDM). These improvements offload data transfers from the host processor and provide low-latency memory near accelerators, boosting throughput up to 2.2x over baseline TitanSSL and raising utilization to 20.56%. Beyond cryptographic acceleration, complementary contributions include TitanCFI, enforcing Control-Flow Integrity via OpenTitan’s RoT, and post-quantum cryptography (PQC) integration through OpenSSL providers for NIST-standardized schemes such as ML-KEM, accelerated via custom RISC-V instructions with up to 1.78x speedup. In summary, this research advances secure RISC-V SoC design by providing an integrated framework for cryptographic offloading, system integrity, and quantum readiness, establishing a foundation for high-performance, resilient embedded systems for research and industry.