The rapid adoption of open-hardware RISC-V System-on- Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompati- ble third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V FormalI nterface(RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.
Security Auditing for RISC-V SoCs via Process Mining
Busi, Matteo;Focardi, Riccardo;Luccio, Flaminia;
In corso di stampa
Abstract
The rapid adoption of open-hardware RISC-V System-on- Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompati- ble third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V FormalI nterface(RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.| File | Dimensione | Formato | |
|---|---|---|---|
|
paper_519.pdf
non disponibili
Tipologia:
Documento in Pre-print
Licenza:
Accesso chiuso-personale
Dimensione
589.55 kB
Formato
Adobe PDF
|
589.55 kB | Adobe PDF | Visualizza/Apri |
I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



