{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,6]],"date-time":"2025-10-06T05:54:07Z","timestamp":1759730047852,"version":"3.37.3"},"reference-count":36,"publisher":"Walter de Gruyter GmbH","issue":"1","funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung","doi-asserted-by":"publisher","award":["16KIS0821K","16K1S0606K","16ES0656"],"award-info":[{"award-number":["16KIS0821K","16K1S0606K","16ES0656"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["276397488 \u2013 SFB 1232"],"award-info":[{"award-number":["276397488 \u2013 SFB 1232"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,2,25]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Modern <jats:italic>System-on-Chips<\/jats:italic> (SoCs) are notoriously insecure. Hence, the fundamental security feature of IP isolation is heavily used, e.\u2009g., secured Memory Mapped IOs (MMIOs), or secured address ranges in case of memories, are marked as non-accessible. One way to provide strong assurance of security is to define isolation as information flow policy in hardware using the notion of non-interference. Since, an insecure hardware opens up the door for attacks across the entire system stack (from software down to hardware), the security validation process should start as early as possible in the SoC design cycle, i.\u2009e. at <jats:italic>Electronic System Level<\/jats:italic> (ESL). Hence, in this paper we propose the first dynamic information flow analysis at ESL. Our approach allows to validate the run-time behavior of a given SoC implemented using <jats:italic>Virtual Prototypes<\/jats:italic> (VPs) against security threat models, such as information leakage (confidentiality) and unauthorized access to data in a memory (integrity). Experiments show the applicability and efficacy of the proposed method on various VPs including a real-world system.<\/jats:p>","DOI":"10.1515\/itit-2018-0027","type":"journal-article","created":{"date-parts":[[2019,1,18]],"date-time":"2019-01-18T09:22:20Z","timestamp":1547803340000},"page":"45-58","source":"Crossref","is-referenced-by-count":14,"title":["Security validation of VP-based SoCs using dynamic information flow tracking"],"prefix":"10.1515","volume":"61","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1256-4140","authenticated-orcid":false,"given":"Mehran","family":"Goli","sequence":"first","affiliation":[{"name":"DFKI Bremen and University of Bremen , Bremen , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad","family":"Hassan","sequence":"additional","affiliation":[{"name":"DFKI Bremen and University of Bremen , Bremen , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Gro\u00dfe","sequence":"additional","affiliation":[{"name":"DFKI Bremen and University of Bremen , Bremen , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rolf","family":"Drechsler","sequence":"additional","affiliation":[{"name":"DFKI Bremen and University of Bremen , Bremen , Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"374","published-online":{"date-parts":[[2019,1,18]]},"reference":[{"key":"2023033119301492593_j_itit-2018-0027_ref_001_w2aab3b7d326b1b6b1ab2ab1Aa","unstructured":"Accellera Systems Initiative. http:\/\/www.accellera.org\/downloads\/standards\/systemc, 2016."},{"key":"2023033119301492593_j_itit-2018-0027_ref_002_w2aab3b7d326b1b6b1ab2ab2Aa","doi-asserted-by":"crossref","unstructured":"A. Ardeshiricham, W. Hu, J. Marxen, and R. Kastner. Register transfer level information flow tracking for provably secure hardware design. In DATE, pages 1691\u20131696. IEEE, 2017.","DOI":"10.23919\/DATE.2017.7927266"},{"key":"2023033119301492593_j_itit-2018-0027_ref_003_w2aab3b7d326b1b6b1ab2ab3Aa","unstructured":"I.\u2009S. Association et al.IEEE standard for standard SystemC language reference manual. IEEE Computer Society, 2012."},{"key":"2023033119301492593_j_itit-2018-0027_ref_004_w2aab3b7d326b1b6b1ab2ab4Aa","unstructured":"J. Aynsley. TLM-2.0 base protocol checker. https:\/\/www.doulos.com\/knowhow\/systemc\/tlm2. Accessed: 2018-01-30."},{"key":"2023033119301492593_j_itit-2018-0027_ref_005_w2aab3b7d326b1b6b1ab2ab5Aa","unstructured":"J. Aynsley, editor. OSCI TLM-2.0 Language Reference Manual. Open SystemC Initiative (OSCI), 2009."},{"key":"2023033119301492593_j_itit-2018-0027_ref_006_w2aab3b7d326b1b6b1ab2ab6Aa","doi-asserted-by":"crossref","unstructured":"M.-M. Bidmeshki and Y. Makris. Toward automatic proof generation for information flow policies in third-party hardware ip. In HOST, pages 163\u2013168. IEEE, 2015.","DOI":"10.1109\/HST.2015.7140256"},{"key":"2023033119301492593_j_itit-2018-0027_ref_007_w2aab3b7d326b1b6b1ab2ab7Aa","doi-asserted-by":"crossref","unstructured":"E. Bosman, A. Slowinska, and H. Bos. Minemu: The world\u2019s fastest taint tracker. In RAID, pages 1\u201320. Springer, 2011.","DOI":"10.1007\/978-3-642-23644-0_1"},{"key":"2023033119301492593_j_itit-2018-0027_ref_008_w2aab3b7d326b1b6b1ab2ab8Aa","doi-asserted-by":"crossref","unstructured":"J. Clause, W. Li, and A. Orso. Dytan: a generic dynamic taint analysis framework. In ISSTA, pages 196\u2013206. ACM, 2007.","DOI":"10.1145\/1273463.1273490"},{"key":"2023033119301492593_j_itit-2018-0027_ref_009_w2aab3b7d326b1b6b1ab2ab9Aa","doi-asserted-by":"crossref","unstructured":"S. Drzevitzky, U. Kastens, and M. Platzner. Proof-carrying hardware: Towards runtime verification of reconfigurable modules. In ReConFig, pages 189\u2013194. IEEE, 2009.","DOI":"10.1109\/ReConFig.2009.31"},{"key":"2023033119301492593_j_itit-2018-0027_ref_010_w2aab3b7d326b1b6b1ab2ac10Aa","doi-asserted-by":"crossref","unstructured":"S. Drzevitzky and M. Platzner. Achieving hardware security for reconfigurable systems on chip by a proof-carrying code approach. In ReCoSoC, pages 1\u20138. IEEE, 2011.","DOI":"10.1109\/ReCoSoC.2011.5981499"},{"key":"2023033119301492593_j_itit-2018-0027_ref_011_w2aab3b7d326b1b6b1ab2ac11Aa","doi-asserted-by":"crossref","unstructured":"A. Ferraiuolo, R. Xu, D. Zhang, A.\u2009C. Myers, and G.\u2009E. Suh. Verification of a practical hardware security architecture through static information flow analysis. SIGOPS Oper. Syst. Rev., pages 555\u2013568, 2017.","DOI":"10.1145\/3093315.3037739"},{"key":"2023033119301492593_j_itit-2018-0027_ref_012_w2aab3b7d326b1b6b1ab2ac12Aa","doi-asserted-by":"crossref","unstructured":"V. Ganesh, T. Leek, and M. Rinard. Taint-based directed whitebox fuzzing. In ICSE, pages 474\u2013484. IEEE Computer Society, 2009.","DOI":"10.1109\/ICSE.2009.5070546"},{"key":"2023033119301492593_j_itit-2018-0027_ref_013_w2aab3b7d326b1b6b1ab2ac13Aa","doi-asserted-by":"crossref","unstructured":"M. Goli, J. Stoppe, and R. Drechsler. Automatic protocol compliance checking of SystemC TLM-2.0 simulation behavior using timed automata. In ICCD, 2017.","DOI":"10.1109\/ICCD.2017.65"},{"key":"2023033119301492593_j_itit-2018-0027_ref_014_w2aab3b7d326b1b6b1ab2ac14Aa","doi-asserted-by":"crossref","unstructured":"D. Gro\u00dfe and R. Drechsler. Quality-Driven SystemC Design. Springer, 2010.","DOI":"10.1007\/978-90-481-3631-5"},{"key":"2023033119301492593_j_itit-2018-0027_ref_015_w2aab3b7d326b1b6b1ab2ac15Aa","doi-asserted-by":"crossref","unstructured":"X. Guo, R.\u2009G. Dutta, and Y. Jin. Eliminating the hardware-software boundary: A proof-carrying approach for trust evaluation on computer systems. TIFS, 12(2):405\u2013417, 2017.","DOI":"10.1109\/TIFS.2016.2621999"},{"key":"2023033119301492593_j_itit-2018-0027_ref_016_w2aab3b7d326b1b6b1ab2ac16Aa","doi-asserted-by":"crossref","unstructured":"M. Hassan, V. Herdt, H.\u2009M. Le, M. Chen, D. Gro\u00dfe, and R. Drechsler. Data flow testing for virtual prototypes. In DATE, pages 380\u2013385, 2017.","DOI":"10.23919\/DATE.2017.7927020"},{"key":"2023033119301492593_j_itit-2018-0027_ref_017_w2aab3b7d326b1b6b1ab2ac17Aa","doi-asserted-by":"crossref","unstructured":"M. Hassan, V. Herdt, H.\u2009M. Le, D. Gro\u00dfe, and R. Drechsler. Early SoC security validation by VP-based static information flow analysis. In ICCAD, pages 400\u2013407, 2017.","DOI":"10.1109\/ICCAD.2017.8203805"},{"key":"2023033119301492593_j_itit-2018-0027_ref_018_w2aab3b7d326b1b6b1ab2ac18Aa","doi-asserted-by":"crossref","unstructured":"V. Herdt, D. Gro\u00dfe, H.\u2009M. Le, and R. Drechsler. Extensible and configurable RISC-V based virtual prototype. In FDL, pages 5\u201316, 2018.","DOI":"10.1109\/FDL.2018.8524047"},{"key":"2023033119301492593_j_itit-2018-0027_ref_019_w2aab3b7d326b1b6b1ab2ac19Aa","doi-asserted-by":"crossref","unstructured":"W. Hu, J. Oberg, A. Irturk, M. Tiwari, T. Sherwood, D. Mu, and R. Kastner. Theoretical fundamentals of gate level information flow tracking. TCAD, 30(8):1128\u20131140, 2011.","DOI":"10.1109\/TCAD.2011.2120970"},{"key":"2023033119301492593_j_itit-2018-0027_ref_020_w2aab3b7d326b1b6b1ab2ac20Aa","doi-asserted-by":"crossref","unstructured":"Y. Jin, B. Yang, and Y. Makris. Cycle-accurate information assurance by proof-carrying based signal sensitivity tracing. In HOST, pages 99\u2013106. IEEE, 2013.","DOI":"10.1109\/HST.2013.6581573"},{"key":"2023033119301492593_j_itit-2018-0027_ref_021_w2aab3b7d326b1b6b1ab2ac21Aa","doi-asserted-by":"crossref","unstructured":"V.\u2009P. Kemerlis, G. Portokalidis, K. Jee, and A.\u2009D. Keromytis. libdft: Practical dynamic data flow tracking for commodity systems. In Acm Sigplan Notices, volume 47, pages 121\u2013132. ACM, 2012.","DOI":"10.1145\/2365864.2151042"},{"key":"2023033119301492593_j_itit-2018-0027_ref_022_w2aab3b7d326b1b6b1ab2ac22Aa","doi-asserted-by":"crossref","unstructured":"H. Khattri, N.\u2009K.\u2009V. Mangipudi, and S. Mandujano. Hsdl: A security development lifecycle for hardware technologies. In HOST, pages 116\u2013121. IEEE, 2012.","DOI":"10.1109\/HST.2012.6224330"},{"key":"2023033119301492593_j_itit-2018-0027_ref_023_w2aab3b7d326b1b6b1ab2ac23Aa","doi-asserted-by":"crossref","unstructured":"P. Kocher, D. Genkin, D. Gruss, W. Haas, M. Hamburg, M. Lipp, S. Mangard, T. Prescher, M. Schwarz, and Y. Yarom. Spectre attacks: Exploiting speculative execution. arXiv preprint arXiv:1801.01203, 2018.","DOI":"10.1109\/SP.2019.00002"},{"key":"2023033119301492593_j_itit-2018-0027_ref_024_w2aab3b7d326b1b6b1ab2ac24Aa","doi-asserted-by":"crossref","unstructured":"X. Li, V. Kashyap, J.\u2009K. Oberg, M. Tiwari, V.\u2009R. Rajarathinam, R. Kastner, T. Sherwood, B. Hardekopf, and F.\u2009T. Chong. Sapper: A language for hardware-level security policy enforcement. ACM SIGARCH Computer Architecture News, 42(1):97\u2013112, 2014.","DOI":"10.1145\/2654822.2541947"},{"key":"2023033119301492593_j_itit-2018-0027_ref_025_w2aab3b7d326b1b6b1ab2ac25Aa","doi-asserted-by":"crossref","unstructured":"X. Li, M. Tiwari, J.\u2009K. Oberg, V. Kashyap, F.\u2009T. Chong, T. Sherwood, and B. Hardekopf. Caisson: a hardware description language for secure information flow. In ACM SIGPLAN Notices, volume 46, pages 109\u2013120. ACM, 2011.","DOI":"10.1145\/1993316.1993512"},{"key":"2023033119301492593_j_itit-2018-0027_ref_026_w2aab3b7d326b1b6b1ab2ac26Aa","unstructured":"M. Lipp, M. Schwarz, D. Gruss, T. Prescher, W. Haas, S. Mangard, P. Kocher, D. Genkin, Y. Yarom, and M. Hamburg. Meltdown. CoRR, abs\/1801.01207, 2018."},{"key":"2023033119301492593_j_itit-2018-0027_ref_027_w2aab3b7d326b1b6b1ab2ac27Aa","doi-asserted-by":"crossref","unstructured":"E. Love, Y. Jin, and Y. Makris. Proof-carrying hardware intellectual property: A pathway to trusted module acquisition. TIFS, 7(1):25\u201340, 2012.","DOI":"10.1109\/TIFS.2011.2160627"},{"key":"2023033119301492593_j_itit-2018-0027_ref_028_w2aab3b7d326b1b6b1ab2ac28Aa","doi-asserted-by":"crossref","unstructured":"F. Qin, C. Wang, Z. Li, H.-s.Kim, Y. Zhou, and Y. Wu. Lift: A low-overhead practical information flow tracking system for detecting security attacks. In MICRO, pages 135\u2013148. IEEE, 2006.","DOI":"10.1109\/MICRO.2006.29"},{"key":"2023033119301492593_j_itit-2018-0027_ref_029_w2aab3b7d326b1b6b1ab2ac29Aa","doi-asserted-by":"crossref","unstructured":"B.\u2009C. Schafer and A. Mahapatra. S2CBench: Synthesizable SystemC benchmark suite for high-level. IEEE Embedded Systems Letters, (3):53\u201356, 2014.","DOI":"10.1109\/LES.2014.2320556"},{"key":"2023033119301492593_j_itit-2018-0027_ref_030_w2aab3b7d326b1b6b1ab2ac30Aa","doi-asserted-by":"crossref","unstructured":"T. Schuster, R. Meyer, R. Buchty, L. Fossati, and M. Berekovic. Socrocket \u2013 A virtual platform for the European space agency\u2019s soc development. In ReCoSoC, pages 1\u20137, 2014, available at http:\/\/github.com\/socrocket.","DOI":"10.1109\/ReCoSoC.2014.6860690"},{"key":"2023033119301492593_j_itit-2018-0027_ref_031_w2aab3b7d326b1b6b1ab2ac31Aa","doi-asserted-by":"crossref","unstructured":"S. Skorobogatov and C. Woods. Breakthrough silicon scanning discovers backdoor in military chip. In CHES, pages 23\u201340. Springer, 2012.","DOI":"10.1007\/978-3-642-33027-8_2"},{"key":"2023033119301492593_j_itit-2018-0027_ref_032_w2aab3b7d326b1b6b1ab2ac32Aa","doi-asserted-by":"crossref","unstructured":"G.\u2009E. Suh, J.\u2009W. Lee, D. Zhang, and S. Devadas. Secure program execution via dynamic information flow tracking. In ACM Sigplan Notices, volume 39, pages 85\u201396. ACM, 2004.","DOI":"10.1145\/1037187.1024404"},{"key":"2023033119301492593_j_itit-2018-0027_ref_033_w2aab3b7d326b1b6b1ab2ac33Aa","doi-asserted-by":"crossref","unstructured":"M. Tiwari, H.\u2009M. Wassel, B. Mazloom, S. Mysore, F.\u2009T. Chong, and T. Sherwood. Complete information flow tracking from the gates up. In ACM Sigplan Notices, volume 44, pages 109\u2013120. ACM, 2009.","DOI":"10.1145\/1508284.1508258"},{"key":"2023033119301492593_j_itit-2018-0027_ref_034_w2aab3b7d326b1b6b1ab2ac34Aa","unstructured":"N. Vachharajani, M.\u2009J. Bridges, J. Chang, R. Rangan, G. Ottoni, J.\u2009A. Blome, G.\u2009A. Reis, M. Vachharajani, and D.\u2009I. August. Rifle: An architectural framework for user-centric information-flow security. In MICRO, pages 243\u2013254. IEEE, 2004."},{"key":"2023033119301492593_j_itit-2018-0027_ref_035_w2aab3b7d326b1b6b1ab2ac35Aa","unstructured":"W. Xu, S. Bhatkar, and R. Sekar. Taint-enhanced policy enforcement: A practical approach to defeat a wide range of attacks. In USENIX Security Symposium, pages 121\u2013136, 2006."},{"key":"2023033119301492593_j_itit-2018-0027_ref_036_w2aab3b7d326b1b6b1ab2ac36Aa","doi-asserted-by":"crossref","unstructured":"D. Zhang, Y. Wang, G.\u2009E. Suh, and A.\u2009C. Myers. A hardware design language for timing-sensitive information-flow security. ACM SIGPLAN Notices, 50(4):503\u2013516, 2015.","DOI":"10.1145\/2775054.2694372"}],"container-title":["it - Information Technology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.degruyter.com\/view\/j\/itit.2019.61.issue-1\/itit-2018-0027\/itit-2018-0027.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2018-0027\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2018-0027\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,4,1]],"date-time":"2023-04-01T06:46:26Z","timestamp":1680331586000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyter.com\/document\/doi\/10.1515\/itit-2018-0027\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,1,18]]},"references-count":36,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2019,2,20]]},"published-print":{"date-parts":[[2019,2,25]]}},"alternative-id":["10.1515\/itit-2018-0027"],"URL":"https:\/\/doi.org\/10.1515\/itit-2018-0027","relation":{},"ISSN":["2196-7032","1611-2776"],"issn-type":[{"type":"electronic","value":"2196-7032"},{"type":"print","value":"1611-2776"}],"subject":[],"published":{"date-parts":[[2019,1,18]]}}}