RISC-Based Secure Architecture for Data-Flow Integrity in Modern Embedded and Edge Systems
K. Kannaiah, Srinivasulu Jogi, B. Naresh Kumar ReddyModern embedded systems are vulnerable to complex data-oriented attacks that subvert not only existing control-flow integrity protections but also have dire implications on safety-critical applications. To overcome this challenge, this work proposes a secure RISC-based architecture that incorporates hardware-assisted Data-Flow Integrity (DFI) enforcement into the processor pipeline. The architecture uses tag-based metadata propagation, a Security Monitor Unit, and compiler support for static analysis in order to ensure the validity of dynamic data flows without affecting execution. A complete RTL prototype was designed and tested with MiBench and CoreMark. Results show an average performance overhead of 11.3% and a logic utilization increase of <9.2% on FPGAs, while achieving 100% detection of all attempted pointer corruption and data tampering attacks. These results indicate the efficacy of the lightweight security-aware RISC architecture as a feasible compromise between security, performance, and hardware expense in today’s embedded systems.