Single engine architecture for hardware root of trust
摘要
Their ubiquity and typically cost-driven design make platforms based on microcontroller units (MCUs) a preferred target for cyber attacks. While Hardware Roots of Trust (RoTs) aim to establish security services, such as confidentiality, integrity, and authentication, the abundance of mutually exclusive cryptographic algorithms taxes heavily on the MCUs’ limited resources. In the presented work, we leverage fundamental cryptographic implications to derive the necessary services from a single sponge-based algorithm’s engine coupled with a Physically Unclonable Function (PUF) for randomness. The proposed single engine can provide all required security services to build an HRoT. In particular, the sponge-based Ascon is chosen to realize Authenticated Encryption with Associated Data (AEAD) and hashing and, at the same time to establish all preconditions for required services like digital signatures or Message Authentication Codes (MACs). To demonstrate the practicality of our hardware RoT, we integrate it into a RISC-V-based System on Chip (SoC) as a memory-mapped peripheral. As proof of the concept, we implement the SoC on the AMD/Xilinx Artix-7 FPGA and synthesize it for the 130nm Open Source SkyWater PDK. The results show that our hardware RoT design adds 10.35% Look-Up Tables (LUTs) for the FPGA implementation and 0.76% area for the ASIC implementation. Our Ascon engine FPGA implementation incurs 2.33