Compass: Navigating the Design Space of Taint Schemes for RTL Security Verification
Yuheng Yang, Qinhan Tan, Thomas Bourgeat, Sharad Malik, Mengjia Yan
Abstract
Hardware information flow tracking (IFT) using taint analysis provides a methodology to check whether a hardware design satisfies certain security properties. Previous work has shown a broad trade-off space between precision and complexity when using different taint analysis schemes. A careful investigation of this space has led to the insight that applying different taint schemes to different components of a hardware design can improve overall efficiency.
We present Compass, a systematic framework to guide users in designing appropriate taint schemes that are as lightweight as possible while still sufficient to accomplish their security verification goals. We first establish a unified terminology to comprehensively capture existing taint schemes. We then apply counterexample-guided abstraction refinement (CEGAR) for taint refinement to iteratively improve the taint scheme. We evaluated Compass on a set of open-source RISCV processors to verify the information flow properties for speculative execution vulnerabilities, and demonstrate that Compass significantly improves both simulation speed and formal-verification scalability of taint analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- Hardware-Software Contracts for Secure SpeculationMarco Guarnieri, Boris Köpf, Jan Reineke, Pepe VilaS&P 2021 · 111 citations
- IODINE: Verifying Constant-Time Execution of HardwareKlaus von Gleissenthall, Rami Gökhan Kici, Deian Stefan, Ranjit JhalaUSENIX Security 2019 · 45 citations
- High-Assurance Cryptography in the Spectre EraGilles Barthe, Sunjay Cauligi, Benjamin Grégoire, Adrien Koutsos et al.S&P 2021 · 42 citations
Related papers
- Validation of Side-Channel Models via Observation RefinementPablo Buiras, Hamed Nemati, Andreas Lindner, Roberto GuancialeMICRO 2021 · 18 citations
- μCFI: Formal Verification of Microarchitectural Control-flow IntegrityKatharina Ceesay-Seitz, Flavien Solt, Kaveh RazaviCCS 2024 · 3 citations
- Lost and Found in Speculation: Hybrid Speculative Vulnerability DetectionMohamadreza Rostami, Shaza Zeitouni, Rahul Kande, Chen Chen et al.DAC 2024 · 6 citations
- CellIFT: Leveraging Cells for Scalable and Precise Dynamic Information Flow Tracking in RTLFlavien Solt, Ben Gras, Kaveh RazaviUSENIX Security 2022
- VeriSketch: Synthesizing Secure Hardware Designs with Timing-Sensitive Information Flow PropertiesArmaiti Ardeshiricham, Yoshiki Takashima, Sicun Gao, Ryan KastnerCCS 2019 · 19 citations
