A Formal Approach to Confidentiality Verification in SoCs at the Register Transfer Level
Johannes Müller, Mohammad Rahmani Fadiheh, Anna Lena Duque Antón, Thomas Eisenbarth, Dominik Stoffel, Wolfgang Kunz
Abstract
We propose a formal verification methodology to detect security-critical bugs in the hardware (HW) and in the hardware/firmware interface of SoCs. Our approach extends Unique Program Execution Checking (UPEC), originally proposed for detecting transient execution side channels, to also detect all functional design bugs that cause confidentiality violations, and to cover not only the processor but also its peripherals. The proposed methodology is particularly effective in capturing security vulnerabilities that are introduced based on cross-modular effects (integration and communication issues) or poorly understood hardware/firmware interaction. Such bugs are known to be hard to detect by previous methods.We demonstrate a compositional approach where vulnerabilities discovered by our method can be used to create restrictions for the software (SW). This supports design fixes not only at the HW but also at the SW level. We present experiments for the Pulpissimo platform (v4.0) where several security-critical bugs were identified (and confirmed), as well as for RocketChip.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5a6c773d-1375-4b15-800d-6df053a38c61Cited by top-tier papers4
- MCU-Wide Timing Side Channels and Their DetectionJohannes Müller, Anna Lena Duque Antón, Lucas Deutschmann, Dino Mehmedagic et al.DAC 2024 · 1 citation
- Sockeye: Bug-finding and proofs for platform configurations and hardware based on reference manualsBen Fiedler, Sedan Abdelgawad, Teymour Aldridge, Viktor Fukala et al.SOSP 2026
- μUSB: Practical and Safe USB Driver Reuse for Arm TrustZoneXuankai Zhang, Sijin Li, Pei Meng, Meng Wang et al.OSDI 2026
- Design of Access Control Mechanisms in Systems-on-Chip with Formal Integrity GuaranteesDino Mehmedagic, Mohammad Rahmani Fadiheh, Johannes Müller, Anna Lena Duque Antón et al.USENIX Security 2023
Related papers
- A Formal Approach for Detecting Vulnerabilities to Transient Execution Attacks in Out-of-Order ProcessorsMohammad Rahmani Fadiheh, Johannes Müller, Raik Brinkmann, Subhasish Mitra et al.DAC 2020 · 38 citations
- SymbFuzz: Symbolic Execution Guided Hardware FuzzingSamit Shahnawaz Miftah, Amisha Srivastava, Hyunmin Kim, Shiyi Wei et al.MICRO 2025 · 4 citations
- HardFails: Insights into Software-Exploitable Hardware BugsGhada Dessouky, David Gens, Patrick Haney, Garrett Persyn et al.USENIX Security 2019 · 149 citations
- InterConFuzz: A Fuzzing-based Comprehensive NoC Verification FrameworkSamit Shahnawaz Miftah, Hyunmin Kim, Kanad BasuDAC 2025
- HyPFuzz: Formal-Assisted Processor FuzzingChen Chen, Rahul Kande, Nathan Nguyen, Flemming Andersen et al.USENIX Security 2023
