Generating optimized gate level information flow tracking logic for enforcing multilevel security
- Authors: Tai Y.1, Hu W.1, Zhang H.1, Mu D.1, Huang X.1
-
Affiliations:
- Northwestern Polytechnical University
- Issue: Vol 50, No 5 (2016)
- Pages: 361-368
- Section: Article
- URL: https://journal-vniispk.ru/0146-4116/article/view/174451
- DOI: https://doi.org/10.3103/S0146411616050096
- ID: 174451
Cite item
Abstract
Vulnerabilities such as design flaws, malicious codes and covert channels residing in hardware design are known to expose hard-to-detect security holes. However, security hole detection methods based on functional testing and verification cannot guarantee test coverage or identify malicious code triggered under specific conditions and hardware-specific covert channels. As a complement approach to cipher algorithms and access control, information flow analysis techniques have been proved to be effective in detecting security vulnerabilities and preventing attacks through side channels. Recently, gate level information flow tracking (GLIFT) has been proposed to enforce bittight information flow security from the level of Boolean gates, which allows detection of hardware-specific security vulnerabilities. However, the inherent high complexity of GLIFT logic causes significant overheads in verification time for static analysis or area and performance for physical implementation, especially under multilevel security lattices. This paper proposes to reduce the complexity of GLIFT logic through state encoding and logic optimization techniques. Experimental results show that our methods can reduce the complexity of GLIFT logic significantly, which will allow the application of GLIFT for proving multilevel information flow security.
About the authors
Yu Tai
Northwestern Polytechnical University
Email: mudejun@mail.nwpu.edu.cn
China, Xi’an, Shaanxi, 710072
Wei Hu
Northwestern Polytechnical University
Email: mudejun@mail.nwpu.edu.cn
China, Xi’an, Shaanxi, 710072
Hui-Xiang Zhang
Northwestern Polytechnical University
Email: mudejun@mail.nwpu.edu.cn
China, Xi’an, Shaanxi, 710072
De-Jun Mu
Northwestern Polytechnical University
Author for correspondence.
Email: mudejun@mail.nwpu.edu.cn
China, Xi’an, Shaanxi, 710072
Xing-Li Huang
Northwestern Polytechnical University
Email: mudejun@mail.nwpu.edu.cn
China, Xi’an, Shaanxi, 710072
Supplementary files
