Design and extension of open-source root-of-trust and SoC architectures for secure embedded systems

Ciani, Maicol (2026) Design and extension of open-source root-of-trust and SoC architectures for secure embedded systems, [Dissertation thesis], Alma Mater Studiorum Università di Bologna. Dottorato di ricerca in Ingegneria e tecnologia dell'informazione per il monitoraggio strutturale e ambientale e la gestione dei rischi - eit4semm, 38 Ciclo.
Documenti full-text disponibili:
[thumbnail of ciani_maicol_tesi.pdf] Documento PDF (English) - Accesso riservato fino a 2 Marzo 2028 - Richiede un lettore di PDF come Xpdf o Adobe Acrobat Reader
Disponibile con Licenza: Creative Commons: Attribuzione - Non Commerciale - Condividi allo Stesso Modo 4.0 (CC BY-NC-SA 4.0) .
Download (15MB) | Contatta l'autore

Abstract

The thesis is organized around the design, realization, and validation of a modular, open-source Root of Trust (RoT) derived from the OpenTitan project, targeting secure and heterogeneous SoC platforms. The first main chapter analyzes trusted computing foundations, including hardware-assisted security mechanisms and architectural requirements for modern Roots of Trust. This chapter establishes the design constraints and security objectives that guide the transformation of OpenTitan from a standalone SoC into a reusable and embeddable security subsystem. The second chapter focuses on the architectural redesign of OpenTitan. The Earl Grey architecture is extended with a flexible boot and lifecycle management system, synthesizable replacements for technology-dependent macros, and a standardized SCMI-compliant mailbox interface. To address performance and scalability, new architectural components are introduced, including a dedicated DMA engine, optimized TileLink interconnect, and a Tightly Coupled Data Memory, enabling efficient cryptographic offloading and management services. The third chapter presents the unified deployment and verification framework. By integrating OpenTitan’s flow with the PULP environment, the framework supports RTL simulation, FPGA emulation, and ASIC implementation. The RoT subsystem is physically realized through multiple tape-outs across GF22, GF12, and Intel16 technologies, with performance evaluations demonstrating significant cryptographic acceleration over the baseline OpenTitan design. The fourth chapter demonstrates system-level integration and applications. The RoT is embedded into heterogeneous SoCs, acting as both a secure enclave and cryptographic co-processor, enabling authenticated boot, secure communication, and fault tolerance. Further extensions show its use in autonomous drone platforms and runtime security monitoring with machine-learning-assisted policies. Together, these chapters establish a silicon-proven, high-performance, and fully open RoT suitable for broad SoC integration.

Abstract
Tipologia del documento
Tesi di dottorato
Autore
Ciani, Maicol
Supervisore
Co-supervisore
Dottorato di ricerca
Ciclo
38
Coordinatore
Settore disciplinare
Settore concorsuale
Parole chiave
Root-of-trust, SoC, hardware security
Data di discussione
27 Marzo 2026
URI

Altri metadati

Gestione del documento: Visualizza la tesi

^