분류
2024년 8월
작성일
2024.05.04
수정일
2024.07.25
작성자
김해용
조회수
147

Trust Guard Extension for Enhanced Security Features in Light-weight Embedded Environment

This dissertation presents a comprehensive study on the enhancement of unprivileged domain isolation in reduced instruction set computer (RISC)-V architectures, focusing on the design and implementation of the trust guard extension (TGX) framework. Embedded systems, essential parts of the evolving Internet of Things environment, are increasingly required to perform real-time complex tasks with limited computational resources. Robust security mechanisms are increasingly imperative as the role of these devices expands from controlling simple devices to managing complex, networked systems. However, traditional RISC-V techniques for memory isolation are unable to support the switching between a trusted execution environment without incurring a performance overhead.

This dissertation addresses the critical challenge of supporting domain isolation within RISC-V architectures. The primary challenge is to implement effective hardware-based memory protection mechanisms that operate efficiently within the constraints of embedded systems. Traditional software-based protections are reasonable, but they do not provide the necessary support for rapid memory permission changes. Furthermore, existing hardware-based solutions, such as Arm TrustZone, while effective, are not natively supported on RISC-V and have their own limitations.

A meticulous and structured approach was employed in implementing the TGX framework, beginning with a thorough analysis of the existing RISC-V architecture to identify key areas where domain isolation could be enhanced without significantly impacting performance. This analysis led to the development of two primary protection methods: Segment Level Memory Protection (SLMP) and Instruction Level Memory Protection (ILMP). SLMP extends the capabilities of Physical Memory Protection (PMP) by providing fine-grained, execution-oriented isolation. This allows for precise control over memory access based on execution segments, significantly reducing the risk of unauthorized access. ILMP complements this by offering dynamic, real-time access controls at the instruction level, adjusting memory access permissions based on the executing instructions to ensure compliance with security policies.

The TGX framework adopts a hybrid approach that combines inter-domain, execution-oriented isolation with intra-domain, instruction-level access controls. This approach leverages the strengths of existing technologies, such as MPK, while enhancing them with the unique capabilities of RISC-V. The framework ensures seamless and secure transitions between trust execution environment in user space without requiring software intervention at the privilege level.

This dissertation advances the state-of-the-art in domain isolation for RISC-V and provides a scalable and efficient solution for enhancing security in embedded systems. By employing a comprehensive methodology with a detailed evaluation of memory-protection features, their effectiveness, and hardware overhead implications, the dissertation offers significant contributions to the field of embedded system security. The research includes a practical hardware implementation evaluation and software overhead analysis, utilizing benchmarks such as Embench-iot to demonstrate the effectiveness of the proposed approach in real-world IoT environments. These findings and methodologies provide a foundation for future research directions aimed at further optimizing and expanding domain isolation technologies.

 

학위연월
2024년 8월
지도교수
김호원
키워드
RISC-V, Security, Cryptography, Hardware
소개 웹페이지
https://sites.google.com/view/pnu-tgx
첨부파일
첨부파일이(가) 없습니다.
다음글
다양한 도메인과 데이터 형식에 강건한 사전학습 언어모델 기반의 표 질의응답 방법
조상현 2024-10-09 13:03:45.703
이전글
Task-Specific Differential Private Data Publish Method for Privacy-Preserving Deep Learning
신진명 2024-04-09 18:00:17.46
RSS 2.0 132
게시물 검색
박사학위논문
번호 제목 작성자 작성일 첨부파일 조회수
132 확산 모델 기반 필기 이미지 생성에 관한 연구 홍동진 2025.04.10 0 68
131 연합 학습 기반 전기차 충전 인프라 최적 운영 및 전력망 안정을 위한 유연성 자원 활용 연 류준우 2025.04.09 0 64
130 Design and Analysis of Quantum Circuits for Inform 와다니 리니 위스누 2025.04.08 0 67
129 Towards computation - communication efficient and 응우옌 민 두옹 2025.04.08 0 66
128 Quantum Convolutional Neural Networks for Classifi 노대일 2025.04.08 0 69
127 Service Management for Reliable Distributed 6G IoT 응우옌 쑤언 둥 2025.04.08 0 55
126 Large Language Model for Penetration Testing Domai 데리 프라타마 2025.04.07 0 95
125 Discovery and Authentication of Marker Genes Using 프라타마 리안 다니스 아디 2025.04.07 0 79
124 산업 환경의 IEEE 802.15.4 TSCH 기반 네트워크에서 트래픽 처리량 향상을 위한 이희준 2025.04.07 0 93
123 Uncertainty-Based Hybrid Deep Learning Approach fo 멘가라 악셀 기드온 2024.12.10 0 119
122 Effective Deep Learning Primitives Design for Bina 황선진 2024.10.14 0 122
121 Toward Immersive Multiview Video Streaming through 탄중 디온 2024.10.14 0 88
120 A Low-cost Deep Learning Model for Real-time Low L 등 제강 2024.10.10 0 143
119 Enhancing Nested Entity Recognition Using Nested R 양홍진 2024.10.09 0 110
118 다양한 도메인과 데이터 형식에 강건한 사전학습 언어모델 기반의 표 질의응답 방법 조상현 2024.10.09 0 121
117 Trust Guard Extension for Enhanced Security Featur 김해용 2024.05.04 0 147
116 Task-Specific Differential Private Data Publish Me 신진명 2024.04.09 0 163
115 Advanced Defense Framework against Physical Advers 김용수 2024.04.08 0 188
114 한글 메신저 채팅의 크로스 텍스팅 탐지를 위한 저자 검증 모형 이다영 2024.04.05 0 162
113 상태 기반 테스트 시나리오 보강 방법 이선열 2023.10.17 0 240