A low-power FSM-based hardware intrusion detection system with lightweight decoy logic for secure SoC architectures
摘要
The growing use of third-party Intellectual Property (IP) cores and dependence on offshore manufacturing have dramatically increased the likelihood of hardware Trojan insertion in today’s System-on-Chip (SoC) designs. Traditional security techniques, such as cryptographic primitives or software Intrusion Detection Systems (IDS), are typically not applicable to resource-limited embedded systems due to their excessive computational overhead, dependence on off-chip observation, and processor-centric operation. This work introduces a low-power, entirely hardware-implemented IDS architecture that combines Finite State Machine (FSM)-regulated control logic and decoy memory redirection for intrusion detection in real-time. Designed in Verilog HDL and synthesized on a Xilinx Artix-7 FPGA, the IDS, under its 32-bit implementation, utilizes only 252 LUTs and 103 flip-flops, resulting in virtually low hardware overhead. The design consumes only 0.349W of overall power and has a detection-to-response latency of 8.48ns, supporting sub-cycle countermeasures. Other features include dynamic power minimization through event-driven clock gating and instruction-set independence for broad platform support. Results from the comparative evaluation against five state-of-the-art IDS frameworks show the proposed scheme achieves better area efficiency, energy responsiveness, and real-time response. This validates the IDS as a next-generation solution for edge devices and embedded SoC environments, which is scalable, secure, and energy-efficient.