The rapid adoption of open-hardware RISC-V System-on- Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompati- ble third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V FormalI nterface(RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.

Security Auditing for RISC-V SoCs via Process Mining

Busi, Matteo;Focardi, Riccardo;Luccio, Flaminia;
In corso di stampa

Abstract

The rapid adoption of open-hardware RISC-V System-on- Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompati- ble third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V FormalI nterface(RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.
In corso di stampa
ARES 2026 EU Projects Symposium Workshops.
File in questo prodotto:
File Dimensione Formato  
paper_519.pdf

non disponibili

Tipologia: Documento in Pre-print
Licenza: Accesso chiuso-personale
Dimensione 589.55 kB
Formato Adobe PDF
589.55 kB Adobe PDF   Visualizza/Apri

I documenti in ARCA sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/10278/5124808
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact