簡易檢索 / 詳目顯示

研究生: 紀閎耀
Chi, Hung-Yao
論文名稱: 應用於物聯網處理器之輕量化硬體記憶體保護機制
Lightweight Hardware-Based Memory Protection Mechanism on IoT Processors
指導教授: 李昆忠
Lee, Kuen-Jong
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 電機工程學系
Department of Electrical Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 英文
論文頁數: 39
中文關鍵詞: 記憶體保護硬體安全輕量化安全機制安全記憶體區域
外文關鍵詞: Memory protection, Hardware security, Lightweight security mechanism, Secure memory region
相關次數: 點閱:113下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著物聯網(IoT)系統變得越來越流行,生活中許多的設備都已連接到網路進行資料傳輸。在允許傳輸和交換大量信息的同時,物聯網中的敏感信息也容易受到洩漏的影響,因此,物聯網系統中每個設備和網絡的安全性已成為一個關鍵問題。現今的各種攻擊不只利用軟體漏洞,也會利用硬體的漏洞來進行攻擊,因此我們必須從硬體上根本的解決安全性的問題。此外,許多物聯網設備是用於日常用品的簡單設備,它們的成本不能太高,並且必須輕量化。這些設備通常由簡單的操作系統(OS)控制,有些是甚至在沒有OS的裸機環境中。在本論文中,我們提出了一種由硬體實現的輕量化記憶體保護機制。該機制將關鍵訊息放在安全區域中,並且只有在通過基於硬體的身份驗證過程之後,處理器才能訪問安全區域。我們的方法允許處理器在不依賴操作系統的情況下保持較高的安全性,因此,即使物聯網設備僅具有裸機環境,它仍可以低成本保護重要資訊。我們的保護機制也具有很高的靈活性。由於物聯網系統有很多不同的應用場景,我們的保護機制允許根據客戶的需求來擴展可選功能。最後在本論文實驗結果顯示,額外的延遲、面積消耗開銷非常小,並且完全不影響整個處理器系統原先的運作。我們以簡單的設計和低開銷來實現高安全性的保護。

    As the Internet of Things (IoT) systems become more and more popular, many devices around life are now connected to the internet. While allowing large amounts of information to be transmitted and exchanged, sensitive information in IoTs also becomes vulnerable to leakage. Therefore the security of each device and network in IoT systems has become a critical issue. Today’s various attacks use not only software vulnerabilities but also hardware vulnerabilities to attack. Therefore, we must fundamentally solve the security problem from the hardware. Besides, many IoT devices are simple devices used for daily supplies; they cannot cost too much and must be lightweight. These devices are often controlled by simple Operating Systems (OS), some even in bare-metal environments without OS. In this thesis, we propose a lightweight memory security mechanism implemented mainly by hardware. This mechanism puts critical data in secure regions, and the processor can access the secure regions only after passing a hardware-based authentication process. Our method allows the processor to maintain high security without relying on the OS; hence even if the IoT device only has a bare-metal environment, it still can protect important data at a low cost. Our protection mechanism has high flexibility. It allows extending optional functions according to the customer's needs since IoT systems have many applications. Finally, experimental results show that the extra delay and area consumptions are very small, and the protection mechanism would not affect the operation of the original processor system. We achieve high-security protection with a simple design and low overhead.

    口試證明書 IV 中文摘要 VIII 英文摘要 X 誌謝 XII 目錄 XIV 圖目錄 XVI 表目錄 XVII CHAPTER 1 INTRODUCTION 1 CHAPTER 2 BACKGROUND 4 2.1 MELTDOWN [1] AND SPECTRE [2] 4 2.2 CODE INSERT ATTACK AND CODE REUSE ATTACK 6 2.3 SECURITY ARCHITECTURES FOR PROCESSOR SYSTEMS 7 CHAPTER 3 MEMORY PROTECTION MECHANISM 9 3.1 DATA AND INSTRUCTIONS PROTECTIONS 10 3.1.1 DATA PROTECTION 10 3.1.2 INSTRUCTIONS PROTECTION 10 3.2 HARDWARE-BASED USER AUTHENTICATION MECHANISM 12 CHAPTER 4 SECURE REGION ACCESS MODULE (SRA MODULE) 13 4.1 AUTHENTICATION UNIT 14 4.1.1 USER KEY GENERATION 14 4.1.2 USER AUTHENTICATION 17 4.2 MEMORY ACCESS CHECK UNIT 18 4.3 ENCRYPTION/DECRYPTION UNIT 18 CHAPTER 5 INSTRUCTION EXTENSIONS 21 CHAPTER 6 OPTIONAL EXTENSIONS 22 6.1 LIGHTWEIGHT ENCRYPTION/DECRYPTION 23 6.2 PHYSICAL UNCLONABLE FUNCTIONS (PUF) 23 6.3 MULTIPLE USER SECURE REGIONS 24 6.4 CACHE 25 CHAPTER 7 EVALUATIONS 27 7.1 PERFORMANCE EVALUATION 29 7.2 CELL AREA EVALUATION 31 7.3 SECURITY EVALUATION 33 7.3.1 MALICIOUS BYPASS PERMISSION ATTACK (EX. MELTDOWN [1] AND SPECTRE [2]) 33 7.3.2 INSERTING EXTRA CODE ATTACK (EX. BUFFER OVERFLOW [6]) 34 7.3.3 HIJACKING PROGRAM CONTROL FLOW ATTACK (EX. RETURN-ORIENTED PROGRAMMING (ROP) [7]) 34 7.3.4 PHYSICAL MEMORY ATTACK (EX. MEMORY COLD-BOOT ATTACK [18]) 34 7.4 COMPARISON WITH RELATED WORKS 35 CHAPTER 8 CONCLUSIONS 36 REFERENCES 37

    [1] M. Lipp, M. Schwarz, and D. Gruss, "Meltdown: Reading kernel memory from user space," USENIX Security Symp., 2018, pp. 973-990.
    [2] P. Kocher, J. Horn, A. Fogh, D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y. Yarom, "Spectre attacks: Exploiting speculative execution," in Proc. IEEE Symp. Secur. Privacy, 2019, pp. 1-19.
    [3] RISC-V Foundation., Available: https://riscv.org
    [4] A. Waterman, K. Asanovic, and SiFive Inc. (2017, May 7). The RISC-V Instruction Set Manual, Volume I: User-Level ISA (2.2nd ed.) [Online]. Available: https://riscv.org/wp-content/uploads/2017/05/riscv-spec-v2.2.pdf.
    [5] A.Waterman, K. Asanovic, and SiFive Inc. (2017, May 7). The RISC-V instruction set manual, Volume II: Privileged Architecture (1.10nd ed.) [Online]. Available: https://riscv.org/wp-content/uploads/2017/05/riscv-privileged-v1.10.pdf
    [6] C. Cowan, F. Wagle, Calton Pu, S. Beattie, and J. Walpole, "Buffer overflows: attacks and defenses for the vulnerability of the decade," in Proc. DARPA Information Survivability Conference and Exposition, Jan. 2000, pp. 119-129.
    [7] R. Roemer, E. Buchanan, H. Shacham, and S. Savage, "Return-oriented programming: Systems, languages, and applications," ACM Trans. Inf. Syst. Secur., vol. 15, no. 1, pp. 2:1-2:34, March 2012.
    [8] V. Costan and S. Devadas, "Intel SGX explained," IACR Cryptology ePrint Archive, vol. 2016, no. 086, pp. 1-118, Feb. 2016.
    [9] ARM. (2009). Security technology building a secure system using TrustZone technology [Online]. Available: https://developer.arm.com/documentation/genc009492/c
    [10] J. Noorman, P. Agten, W. Daniels, R. Strackx, A. Van Herrewege, C. Huygens, B. Preneel, I. Verbauwhede, F. Piessens, and KU Leuven, "Sancus: Low-cost trustworthy extensible networked devices with a zero-software trusted computing base," in Proc. 22nd USENIX Secur. Symp., 2013, pp. 479–494.
    [11] J. Götzfried, T. Müller, R. de Clercq, P. Maene, F. Freiling and I. Verbauwhede, "Soteria: Offline software protection within low-cost embedded devices," in Proc. 31st Conf. Comput. Secur. Appl., 2015, pp. 241–250.
    [12] P. Koeberl, S. Schulz, A.-R. Sadeghi and V. Varadharajan, "TrustLite: A security architecture for tiny embedded devices," in Proc. 9th Eur. Conf. Comput. Syst., 2014.
    [13] Brasser, B. El Mahjoub, A.-R. Sadeghi, C. Wachsmann and P. Koeberl, "TyTAN: Tiny trust anchor for tiny devices," in Proc. 52nd Conf. Des. Autom., 2015, pp. 1–6.
    [14] P. Maene, J. Götzfried, R. de Clercq, T. Müller, F. Freiling and I. Verbauwhede, "Hardware-Based Trusted Computing Architectures for Isolation and Attestation," IEEE Trans. Computers, vol. 67, no. 3, pp. 361-374, Mar. 2018.
    [15] Syntacore. (2018). SCR1 [Online]. Available: https://github.com/syntacore/scr1
    [16] Risclite. (2019). SuperScalar-RISCV-CPU [Online]. Available: https://github.com/risclite/SuperScalar-RISCV-CPU
    [17] Xilinx, Inc., ZCU102 Evaluation Board User Guide, Version 2019.06.
    [18] J. Halderman, S. Schoen, N. Heninger, W. Clarkson, W. Paul, J. Calandrino, A. Feldman, J.Appelbaum, and E. Felten, "Lest We Remember: Cold Boot Attacks on Encryption Keys," in Proc. USENIX Security Symp., Jul. 2008, pp. 45-60.

    下載圖示
    2026-08-18公開
    QR CODE