{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:41:32Z","timestamp":1763458892553,"version":"3.45.0"},"reference-count":39,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2017,12,28]],"date-time":"2017-12-28T00:00:00Z","timestamp":1514419200000},"content-version":"vor","delay-in-days":365,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["0966187"],"award-info":[{"award-number":["0966187"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Des. Autom. Electron. Syst."],"published-print":{"date-parts":[[2017,4,30]]},"abstract":"<jats:p>This work tackles the conflict between enforcing security of a system-on-chip (SoC) and providing observability during trace-based debugging. On one hand, security objectives require that assets remain confidential at different stages of the SoC life cycle. On the other hand, the trace-based debug infrastructure exposes values of internal signals that can leak the assets to untrusted third parties. We propose a secure trace-based debug infrastructure to resolve this conflict. The secure infrastructure tags each asset to identify its owner (to whom it can be exposed during debug) and nonintrusively enforces the confidentiality of the assets during runtime debug. We implement a prototype of the enhanced infrastructure on an FPGA to validate its functional correctness. ASIC estimations show that our approach incurs practical area and power costs.<\/jats:p>","DOI":"10.1145\/2994601","type":"journal-article","created":{"date-parts":[[2016,12,28]],"date-time":"2016-12-28T08:20:40Z","timestamp":1482913240000},"page":"1-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Secure and Flexible Trace-Based Debugging of Systems-on-Chip"],"prefix":"10.1145","volume":"22","author":[{"given":"Jerry","family":"Backer","sequence":"first","affiliation":[{"name":"New York University, Brooklyn, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"David","family":"Hely","sequence":"additional","affiliation":[{"name":"University of Grenoble Alpes"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ramesh","family":"Karri","sequence":"additional","affiliation":[{"name":"New York University, Brooklyn, NY"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2016,12,28]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"ARM. 1999. AMBA Specifications (Rev 2.0). ARM Limited."},{"key":"e_1_2_1_2_1","unstructured":"ARM. 2006. AMBA 3 AHB-Lite Protocol (v1.0). ARM Limited."},{"key":"e_1_2_1_3_1","unstructured":"ARM. 2008. AMBA AHB Trace Macrocell Technical Reference Manual. ARM Limited."},{"key":"e_1_2_1_4_1","unstructured":"ARM. 2009. Security Technology Building a Secure System Using TrustZone Technology. ARM Technical White Paper."},{"key":"e_1_2_1_5_1","unstructured":"ARM. 2011. CoreSight Program Flow Trace PFTv1.0 and PFTv1.1: Architecture Specification. ARM Limited."},{"key":"e_1_2_1_6_1","unstructured":"ARM. 2013. ARM CoreSight Architecture Specification v2.0. ARM Limited."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC.2011.5766359"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2013.6522302"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2010.2089071"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/1086297.1086308"},{"volume-title":"Proceedings of the Design, Automation, and Test in Europe Conference Exhibition. 866--869","author":"Das A.","key":"e_1_2_1_11_1","unstructured":"A. Das, U. Kocabas, A. Sadeghi, and I. Verbauwhede. 2012. PUF-based secure test wrapper design for cryptographic SoC testing. In Proceedings of the Design, Automation, and Test in Europe Conference Exhibition. 866--869."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2012.2185930"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEST.2013.6651903"},{"key":"e_1_2_1_14_1","unstructured":"J. Gaisler E. Catovic M. Isomaki K. Glembo and S. Habinc. 2015b. GRLIB IP Core Users Manual. Gaisler Research Goteborg Sweden."},{"key":"e_1_2_1_15_1","unstructured":"J. Gaisler E. Catovic M. Isomaki K. Glembo and S. Habinc. 2015a. GRLIB IP Library Users Manual. Gaisler Research Goteborg Sweden."},{"volume-title":"Proceedings of the USENIX Conference on Offensive Technologies. 6.","author":"Goodspeed T.","key":"e_1_2_1_16_1","unstructured":"T. Goodspeed and A. Francillon. 2009. Half-blind attacks: Mask ROM bootloaders are dangerous. In Proceedings of the USENIX Conference on Offensive Technologies. 6."},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/WWC.2001.990739"},{"key":"e_1_2_1_18_1","first-page":"849","article-title":"Method for managing operability of on-chip debug capability","volume":"7","author":"Hardy D. A","year":"2010","unstructured":"D. A Hardy, F. Sydnor, and W. Oh. 2010. Method for managing operability of on-chip debug capability. United States Patent 7,849,315.","journal-title":"United States Patent"},{"volume-title":"Intel Trace Hub-Developer\u2019s Manual","key":"e_1_2_1_19_1","unstructured":"Intel. 2015. Intel Trace Hub-Developer\u2019s Manual. Intel, Santa Clara, CA."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC.2011.5766480"},{"key":"e_1_2_1_21_1","first-page":"645","article-title":"Secure remote credential provisioning","volume":"8","author":"Khosravi H.","year":"2014","unstructured":"H. Khosravi, P. Munguia, A. Pearson, S. Brown, and D. Schollmeyer. 2014. Secure remote credential provisioning. United States Patent 8,645,677.","journal-title":"United States Patent"},{"key":"e_1_2_1_22_1","first-page":"671","article-title":"Dynamic device identification for making a JTAG debug connection with a internet browser","volume":"8","author":"Lau S.","year":"2014","unstructured":"S. Lau and V. Varshney. 2014. Dynamic device identification for making a JTAG debug connection with a internet browser. United States Patent 8,671,319.","journal-title":"United States Patent"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/VTS.2006.7"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/1669112.1669172"},{"volume-title":"Proceedings of the Design Automation, and Test in Europe Conference Exhibition. 1338--1343","author":"Liu X.","key":"e_1_2_1_25_1","unstructured":"X. Liu and Q. Xu. 2009. Trace signal selection for visibility enhancement in post-silicon validation. In Proceedings of the Design Automation, and Test in Europe Conference Exhibition. 1338--1343."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/MM.2008.2"},{"key":"e_1_2_1_27_1","unstructured":"ODA. 2016. Online Disassembler. Retrieved November 6 2016 from https:\/\/www.onlinedisassembler.com\/ static\/home\/"},{"key":"e_1_2_1_28_1","unstructured":"W. Orme. 2008. Debug and Trace for Multicore SoCs. ARM White Paper."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2012.2208209"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CODES-ISSS.2013.6658991"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2744769.2754896"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/MDT.2010.9"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/VLSIC.2010.5560296"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSE.2007.44"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2008.19"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","unstructured":"B. Vermeulen and K. Goossens. 2014. Debugging Systems-on-Chip: Communication-Centric and Abstraction-Based Techniques. Springer. 10.1007\/978-3-319-06242-6","DOI":"10.1007\/978-3-319-06242-6"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOTCHIPS.2009.7478360"},{"volume-title":"Proceedings of the IEEE International Test Conference. 339--344","author":"Yang B.","key":"e_1_2_1_38_1","unstructured":"B. Yang, K. Wu, and R. Karri. 2004. Scan based side channel attack on dedicated hardware implementations of data encryption standard. In Proceedings of the IEEE International Test Conference. 339--344."},{"volume-title":"Proceedings of the ACM Workshop on Scalable Trusted Computing. 7--14","author":"Zhang X.","key":"e_1_2_1_39_1","unstructured":"X. Zhang, O. Aciicmez, and J. Seifert. 2007. A trusted mobile phone reference architecture via secure kernel. In Proceedings of the ACM Workshop on Scalable Trusted Computing. 7--14."}],"container-title":["ACM Transactions on Design Automation of Electronic Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2994601","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2994601","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2994601","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:37:41Z","timestamp":1763458661000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2994601"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,12,28]]},"references-count":39,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,4,30]]}},"alternative-id":["10.1145\/2994601"],"URL":"https:\/\/doi.org\/10.1145\/2994601","relation":{},"ISSN":["1084-4309","1557-7309"],"issn-type":[{"type":"print","value":"1084-4309"},{"type":"electronic","value":"1557-7309"}],"subject":[],"published":{"date-parts":[[2016,12,28]]},"assertion":[{"value":"2016-03-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-09-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2016-12-28","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}