The rapid adoption of open-hardware RISC-V System-on-Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompatible third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V Formal Interface (RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.
Security auditing for RISC-V SoCs via process mining / Bramante, S., Busi, M., Cilardo, A., Focardi, R., Luccio, F., Mazzocca, N., Vitale, F.. - 16903:(2027), pp. 589-604. (ARES 2026 EU Projects Symposium Workshops Linkoeping, Sweden 24-27/08/2026) [10.1007/978-3-032-37218-5_34].
Security auditing for RISC-V SoCs via process mining
Bramante Salvatore;
2027
Abstract
The rapid adoption of open-hardware RISC-V System-on-Chip (SoC) designs in security-sensitive embedded and edge scenarios is raising the bar on observability and assurance requirements for such platforms. In fact, unforeseen runtime misbehaviors due to incompatible third-party IPs, hardware trojans in peripherals, and compromised drivers can cause misbehaviors that core-level monitors, such as RISC-V Formal Interface (RVFI), cannot see. We introduce the Peripheral Formal Interface (PFI), a passive AXI-aware observation interface that extends the RVFI philosophy from the core to the peripherals. The PFI emits a structured event stream that off-chip auditors can consume without touching the functional path. On top of it, we define an auditing architecture that merges the peripheral-bus stream and the RVFI retirement stream into a single event log, and a process mining pipeline that turns this log into a Contract: a behavioral model with allowlist, count, and timing constraints. We validate the framework on Simply-V, an open-source reconfigurable soft-SoC, auditing representative workloads to localize injected firmware defects event by event.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


