Score
Designs, implements, and evaluates low-level security building blocks, including cryptographic algorithms and primitives as well as operating-system primitives such as kernel security modules, capabilities, and secure system-call interfaces. This work covers specification and implementation, formal and empirical analysis of security properties and threat models, and measurement of correctness, performance, and resistance to side channels and implementation attacks.
Modern SoC hardware semantics are typically specified in informal English documentation, impeding precise definition and formal verification of security properties and thus hindering system-level security assurance. Method: We propose HDLang, a domain-specific language enabling automatic extraction of hardware semantics, software assumptions, and security properties from SoC reference manuals, and generating machine-readable, formally verifiable specifications. Contribution/Results: Using HDLang, we construct unified security models for eight mainstream SoCs and perform the first full-chip formal verification of memory confidentiality and integrity via theorem proving and static analysis. Our approach uncovers multiple ambiguities and contradictions in vendor documentation and identifies an undisclosed privilege-escalation vulnerability in a commercial server SoC. This work establishes a systematic methodology for transforming unstructured hardware documentation into rigorously verifiable security models.
Emerging hardware security threats—including cache, power, electromagnetic, and voltage side-channel attacks, as well as fault injection—pose severe risks to cloud, IoT, and smart devices. Current defenses—memory protection, trusted boot, PUFs, key management, and RISC-V security extensions—exhibit systemic limitations. Method: This project establishes the first unified framework integrating multi-dimensional attack modeling with cross-layer defense strategies, proposes a hardware security assessment methodology for heterogeneous architectures, and empirically analyzes Spectre/Meltdown, DPA, EMA, voltage glitching, cryptographic ISA extensions, and secure boot mechanisms. Contribution/Results: It uncovers unique challenges in root-of-trust construction within the RISC-V ecosystem and constructs the most comprehensive hardware security knowledge graph to date. The outcomes provide industry with systematic guidelines for developing side-channel-resistant processors and offer academia scalable technical pathways for innovating next-generation hardware security mechanisms.
This work addresses the breakdown of kernel ASLR under speculative execution and side-channel attacks in the Spectre era, revealing its inconsistency with Abadi et al.’s shared-memory assumption and highlighting prevalent isolated memory models and system-call communication channels in practice. We propose three verifiable secure execution mechanisms, formally defining— for the first time—the security boundary of ASLR within kernel memory isolation models. Furthermore, we design the first Spectre-era system-call speculation-resilience framework, enabling verifiable kernel-level side-channel immunity. Implemented and evaluated on Linux, our solution integrates retpoline, IBRS, and user-space access blocking; it incurs an average performance overhead of <3.2%, maintains bounded latency increases for critical system calls, and empirically demonstrates a feasible security–performance trade-off.
This study addresses the urgent need to enhance the security of information systems as critical societal infrastructure. Adopting the reference monitor architecture as a theoretical framework, this work systematically reviews three core technologies: virtualization, formal verification of operating systems, and fine-grained access control. It provides an in-depth analysis of their technical prospects and evolutionary challenges within security requirements analysis. Furthermore, this research constructs a comprehensive landscape of the operating system security domain, delineating integration pathways and future development directions for these technologies. By doing so, it establishes a solid theoretical foundation and a clear technical roadmap for overcoming existing bottlenecks in system security.
本文分析了硬件模糊测试在不同抽象层的效率与效果,指出了现有方法的不足,并提出了结合AI等技术的未来研究方向以提高验证解决方案。
本文分析了52个硬件模糊测试工具,提出一个框架来重新思考指导和输入生成方法,以解决硬件安全验证问题。
本文通过开放硬件黑客竞赛,采用多策略漏洞分析方法(包括模拟验证、形式验证等),研究SoC安全验证,总结了对预硅片安全验证的实用经验。
This work addresses the inefficiency of manual VCD file analysis in hardware security research, where practitioners often laboriously inspect waveform traces to identify software-hardware interface vulnerabilities. To overcome this bottleneck, the paper introduces RTL-Arrow, a novel framework that automatically transforms VCD execution traces—generated from hardware simulation—into cloud-ready, structured data frames compatible with modern data science workflows. RTL-Arrow integrates VCD parsing, structured data frame construction, and cloud-native format encapsulation, complemented by an automated compilation pipeline that produces a high-performance toolchain. Released as an open-source library, RTL-Arrow substantially lowers the barrier to hardware-software co-verification, significantly enhancing the efficiency and scalability of cross-layer vulnerability detection and analysis.
研究提出SURF类CPU木马,无需执行任意代码即可激活,利用高级语言整数操作映射到微架构副作用,实现对终端设备的长期威胁。
This work addresses the long-standing lack of systematic validation for processor specifications, which can lead to distorted program behavior and security vulnerabilities. It presents the first automated differential testing framework tailored for open-source SLEIGH specifications, automatically generating decodable instructions and initial execution states by parsing specification structures, and systematically validating them against multiple hardware reference implementations across architectures. Applied to x86-64 and AArch64, the approach uncovered 38,920 semantic discrepancies, identified 125 unique defects—many of which were subsequently fixed—and significantly improved specification fidelity. Furthermore, it exposed inconsistencies across vendor implementations and led to eight concrete recommendations, establishing a new paradigm for ensuring the reliability of instruction set architecture specifications.