Hardware-software co-design methods to unleash open hardware cybersecurity and trust in RISC-V architectures

Musa, Alberto (2026) Hardware-software co-design methods to unleash open hardware cybersecurity and trust in RISC-V architectures, [Dissertation thesis], Alma Mater Studiorum Università di Bologna. Dottorato di ricerca in Ingegneria elettronica, telecomunicazioni e tecnologie dell'informazione, 38 Ciclo.
Documenti full-text disponibili:
[thumbnail of musa_alberto_tesi.pdf] Documento PDF (English) - Richiede un lettore di PDF come Xpdf o Adobe Acrobat Reader
Disponibile con Licenza: Salvo eventuali più ampie autorizzazioni dell'autore, la tesi può essere liberamente consultata e può essere effettuato il salvataggio e la stampa di una copia per fini strettamente personali di studio, di ricerca e di insegnamento, con espresso divieto di qualunque utilizzo direttamente o indirettamente commerciale. Ogni altro diritto sul materiale è riservato.
Download (3MB)

Abstract

The rapid growth of the open-source RISC-V ecosystem and the increasing criticality of embedded systems demand robust defense mechanisms against software exploits, hardware attacks, and emerging quantum threats. OpenTitan, an open-source silicon Root-of-Trust (RoT), provides a secure foundation with features like secure boot, hardware isolation, and cryptographic accelerators. However, fully exploiting these capabilities is challenging due to a gap between advanced hardware and the maturity of software support. This thesis introduces TitanSSL, a holistic hardware-software co-design framework that bridges this gap, enabling secure, high-performance cryptographic operations on RISC-V System-on-Chips (SoCs). TitanSSL integrates three components: a custom OpenSSL engine, optimized OpenTitan firmware, and a Linux kernel driver. Together, they offload cryptographic workloads to OpenTitan accelerators while extending RoT benefits, including secure key storage and system integrity. A secure communication protocol coordinates memory protection, data exchange, and resource arbitration between the host processor and OpenTitan. Performance evaluation on a CVA6 core running Linux with OpenTitan on a Xilinx VCU118 FPGA shows significant speedups for large payloads (128 KiB), achieving 10.50x for SHA-256 and 2.96x for AES-256-CBC compared to software-only implementations. Early data movement limitations restricted accelerator utilization to 9.35%, prompting enhancements with Direct Memory Access (DMA) and Tightly Coupled Data Memory (TCDM). These improvements offload data transfers from the host processor and provide low-latency memory near accelerators, boosting throughput up to 2.2x over baseline TitanSSL and raising utilization to 20.56%. Beyond cryptographic acceleration, complementary contributions include TitanCFI, enforcing Control-Flow Integrity via OpenTitan’s RoT, and post-quantum cryptography (PQC) integration through OpenSSL providers for NIST-standardized schemes such as ML-KEM, accelerated via custom RISC-V instructions with up to 1.78x speedup. In summary, this research advances secure RISC-V SoC design by providing an integrated framework for cryptographic offloading, system integrity, and quantum readiness, establishing a foundation for high-performance, resilient embedded systems for research and industry.

Abstract
Tipologia del documento
Tesi di dottorato
Autore
Musa, Alberto
Supervisore
Co-supervisore
Dottorato di ricerca
Ciclo
38
Coordinatore
Settore disciplinare
Settore concorsuale
Parole chiave
RISC-V, OpenTitan, Cryptographic Acceleration, Hardware-Software Co-Design, Secure System-on-Chip, Root of Trust, Control-Flow Integrity, Post-Quantum Cryptography, Embedded System Security, Software Stack, Hardware Security
Data di discussione
30 Marzo 2026
URI

Altri metadati

Statistica sui download

Gestione del documento: Visualizza la tesi

^