Formal verification of correctness and information flow security for an in-order pipelined processor
File(s)ning.pdf (431.96 KB)
Published version
Author(s)
Dong, Ning
Guanciale, Roberto
Dam, Mads
Loow, Axel
Type
Conference Paper
Abstract
We present an in-order pipelined processor and its
verification in the HOL4 interactive theorem prover. The processor implements the RISC ISA Silver and features a general 5-stage pipeline. The correctness of the processor is proved by exhibiting a refinement relation between the traces of the pipelined circuit and the Silver ISA. The processor is constructed by using a HOL4 Verilog library for formally verified hardware, and its correctness is guaranteed down to the Verilog implementation. Additionally, we analyze the information flow properties of the processor by utilizing the refinement relation. The notion of conditional noninterference formulates that a processor should
not leak more information via its timing channel than what is expected by a leakage model expressed at the ISA level. We establish the conditional noninterference for our processor and demonstrate the adaptability of the information flow methodology to accommodate various processor designs, attacker models, and environments. Our approach to verify processor implementations and enable information flow analysis at the circuit level is suitable
for ISAs beyond Silver.
verification in the HOL4 interactive theorem prover. The processor implements the RISC ISA Silver and features a general 5-stage pipeline. The correctness of the processor is proved by exhibiting a refinement relation between the traces of the pipelined circuit and the Silver ISA. The processor is constructed by using a HOL4 Verilog library for formally verified hardware, and its correctness is guaranteed down to the Verilog implementation. Additionally, we analyze the information flow properties of the processor by utilizing the refinement relation. The notion of conditional noninterference formulates that a processor should
not leak more information via its timing channel than what is expected by a leakage model expressed at the ISA level. We establish the conditional noninterference for our processor and demonstrate the adaptability of the information flow methodology to accommodate various processor designs, attacker models, and environments. Our approach to verify processor implementations and enable information flow analysis at the circuit level is suitable
for ISAs beyond Silver.
Date Issued
2023-10-01
Date Acceptance
2023-07-08
Citation
Proceedings of the 23rd Conference on Formal Methods in Computer-Aided Design – FMCAD, 2023, pp.247-256
ISBN
978-3-85448-060-0
Publisher
TU Wien Academic Press
Start Page
247
End Page
256
Journal / Book Title
Proceedings of the 23rd Conference on Formal Methods in Computer-Aided Design – FMCAD
Copyright Statement
© 2023 The Author(s). This work is licensed under a Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/).
License URL
Source
FMCAD 2023
Publication Status
Published
Start Date
2023-10-23
Finish Date
2023-10-27
Coverage Spatial
Ames, Iowa, USA