FONT SIZE : AAA
Traditionally, the deployment of secured, tamper-proof devices has mainly been of concern to applications under the purview of defence or security. More recently, however, with the growing trend of development and marketing of custom IP resources, the ability to deploy devices which offer the ability to securely protect the internal software and hardware IP has become an ever-increasing concern to markets such as avionics, automotive, broadcast, industrial and wired/wireless networking and communications [28].
Zynq-7000 devices provide a wide range of security features which offer protection of the internal functionality of your system, ranging from dedicated hardware support for multiple encryption standards, secure system boot facilities, and software execution protection.
In this section, the security features of Zynq will be briefly introduced. It is outwith the scope of this chapter to provide any great detail on the individual security aspects of Zynq, but instead relevant features will be introduced. Further information on theses features can be found in the cited references.
One of the main architectural points of note with Zynq-7000 devices is that the boot method is restricted to a single source — device boot must be driven by the processor. When the device is powered on or reset, the first core of the PS boots from external memories before going on to configure the PL [28]. By restricting the boot method to a single source, it ensures that the there is no manual way to load malicious software after the PL has been configured, and also no way to load a malicious image to the PL after the processor has initialised.
A number of features have been incorporated into Zynq-7000 devices which facilitate secure booting. One of these features is the boot ROM, which has been designed to handle various forms of security. Both asymmetric and symmetric authentication of the FirstStage Boot Loader (FSBL), U-Boot, PL bitstream and user software (OS and user applications) is supported. In the case of asymmetric authentication, RSA-2048 primary and secondary public keys are used, where as HMAC (SHA-256) is used for symmetric authentication. Further, encryption of the boot files mentioned above is supported with 256-bit AES/CBC key which can be either volatile (battery backed up) or non-volatile (eFuses).
One other feature which facilitates secure boot is the OCM, which has been provided to be large enough (256KB) to run the FSBL from an internal location which is immune to any external probing attack. The OCM is also large enough to securely store TrustZone® software routines (more on these in the Zynq-7000 and ARM TrustZone Technology subsection below).
All Zynq-7000 devices benefit from a host of hardware security IP, which are implemented either as hard IP blocks within the PS, or as soft IP in the PL. The functionality of these security IPs includes anti-tamper, trust and information assurance, to protect the system from power-on and through runtime [28].
Further to the available security IP, Zynq-7000 devices have a number of embedded blocks which can support the creation of secured systems. Such blocks include authentication, decryption engines, key storage and unique device identification possibilities.
Some of the features of Zynq devices which relate to security are listed as follows [28]:
• ARM TrustZone support (PS and PL)
• AES-256 encryption (BBRAM key and eFUSE key)
• Secure Configuration and Boot (PS and PL)
• HMAC bitstream authentication
• FSBL RSA-2048 Authentication
• Hardened readback disable
• JTAG disable/monitor
• SEU checker
The need for preventing unwanted access to the internal device data or memory doesn’t end after the boot process has completed, and as such there is a need to provide runtime security. By not employing runtime security on a device, confidential user or system data might be compromised, along with the stability and operation of the system. In order to prevent such compromise to your system, any malicious access to internal data, memory or peripherals must be obviated.
Runtime security can be split into three areas of protection, which are outlined as follows:
• Processing System to Programmable Logic — The prevention of software running on the Zynq PS from accessing hardware-based IP and slaves running in the PL. Zynq devices have two methods of implementing such protection: (i) a Zynq-specific implementation of ARM TrustZone technology (see the dedicated Zynq-7000 and ARM TrustZone Technology subsection below), and (ii) based on the monitoring of AXI port transaction from the master, and the corresponding slave address.
• Processing System to Processing System — Previous generations of embedded systems were made up of an amalgamation of various independent subsystems, which each, in turn, comprised of dedicated hardware, operating systems and software. This architecture was inherently secure, in terms of runtime security, because each subsystem made use of its own dedicated hardware (CPU, buses, memory and peripherals.). With todays embedded systems, such as those based on Zynq-7000 devices, making use of shared resources, such as the PS, PL and configurable interconnects, runtime security is of greater concern. It is therefore important to ensure that shared resources have sufficient security in place.
One such area which must have sufficient security is the MMU:
- Memory Management Unit Security — By configuring MMU Page Tables in a way that is security-aware, system security is improved by restricting the access of unauthorised software applications and hardware drivers to specific memory regions, devices, configuration registers and IP cores [28].
All members of the Zynq-7000 family have a dedicated MMU for each of the two Cortex-A9 processing cores. The Page Tables of each of the MMUs allows for fine grained access to be controlled for the DDR Memory, OCM, system level control registers, memory mapped blocks in the PS and memory mapped IP blocks within the PL.
• Programmable Logic to Processing System / Programmable Logic — One of the main advantages of the Zynq PL is the ability to easily instantiate multiple IP blocks which can act as AXI masters (a MicroBlaze processor, for example). Such AXI masters are subject to various levels of restriction which limits their access to slave devices which are associated with the PS (such as CAN, Ethernet, GPIO and USB), as well as other soft IP slaves instantiated in the PL [28].
Further to this, during system development, the developer has the freedom to control which slave addresses are accessible to any one master IP within the PL. This functionality reduces the chances of a compromised master IP from accessing restricted hardware.
One feature of Zynq devices which can prevent such venerabilities is the Zynq-specific implementation of ARM TrustZone technology [28]. The TrustZone architecture enables trusted computing within embedded systems by establishing a hardware architecture which is capable of spreading the security framework throughout the design of the system. This is accomplished by running specific subsystems in either a “normal world” or a “secure world”, rather than protecting the entirety of the systems assets in a single, dedicated hardware resource [34]. By operating in this manner, and combined with software which is capable of making full use of the offered advantages, TrustZone establishes a security solution which can operate from one end of a system to the other.
For Zynq devices, a normal world is defined as a subset of hardware comprising of memory and L2 cache regions, and specific AXI devices [34]. Non-trusted software can run in a normal world, but its access and awareness of additional hardware will be limited, as it may be dedicated to the TrustZone architecture in the secure world. Software applications which are classified as trusted will execute in the secure world, which is a separate, trusted environment isolated from the main OS to prevent any malicious access to the embedded system.
Manufacturer:Xilinx
Product Categories:
Lifecycle:Active Active
RoHS: -
Manufacturer:Xilinx
Product Categories: Memory - Configuration Proms for FPGA's
Lifecycle:Active Active
RoHS:
Manufacturer:Xilinx
Product Categories: FPGAs (Field Programmable Gate Array)
Lifecycle:Active Active
RoHS:
Manufacturer:Xilinx
Product Categories: FPGAs (Field Programmable Gate Array)
Lifecycle:Active Active
RoHS: No RoHS
Manufacturer:Xilinx
Product Categories:
Lifecycle:Active Active
RoHS: -
Support