QTFlow: Quantitative Timing-Sensitive Information Flow for Security-Aware Hardware Design on RTL
作者:Lennart M. Reimann, Anshul Prashar, Chiara Ghinami, Rebecca Pelke, Dominik Šišejković, Farhad Merchant, Rainer Leupers · 年份:2024 · DOI:10.1109/vlsitsa60681.2024.10546389 · 被引用次数:5 · 研究领域:Security and Verification in Computing、Physical Unclonable Functions (PUFs) and Hardware Security、Advanced Malware Detection Techniques
In contemporary Electronic Design Automation (EDA) tools, security often takes a backseat to the primary goals of power, performance, and area optimization. Commonly, the security analysis is conducted by hand, leading to vulnerabilities in the design remaining unnoticed. Security-aware EDA tools assist the designer in the identification and removal of security threats while keeping performance and area in mind. Cutting-edge methods employ information flow analysis to identify inadvertent information leaks in design structures. Current information leakage detection methods use quantitative infor-mation flow analysis to quantify the leaks. However, handling sequential circuits poses challenges for state-of-the-art techniques due to their time-agnostic nature, overlooking timing channels, and introducing false positives. To address this, we introduce QTFlow, a timing-sensitive framework for quantifying hardware information leakages during the design phase. Illustrating its effectiveness on open-source benchmarks, QTFlow autonomously identifies timing channels and diminishes all false positives arising from time-agnostic analysis when contrasted with current state-of-the-art techniques.