ACE: Confidential Computing for Embedded RISC-V Systems

By Wojciech Ozga 1, Guerney D.H. Hunt 2Michael V. Le 2Lennard Gäher 3Avraham Shinnar 2Elaine R. Palmer 2Hani Jamjoom 2Silvio Dragone 1
1 IBM Research — Zurich
2 IBM T.J. Watson Research Center
3 MPI-SWS, Germany

Confidential computing plays an important role in isolating sensitive applications from the vast amount of untrusted code commonly found in the modern cloud. We argue that it can also be leveraged to build safer and more secure mission-critical embedded systems. In this paper, we introduce the Assured Confidential Execution (ACE), an open-source and royalty-free confidential computing technology targeted for embedded RISC-V systems. We present a set of principles and a methodology that we used to build ACE and that might be applied for developing other embedded systems that require formal verification. An evaluation of our prototype on the first available RISC-V hardware supporting virtualization indicates that ACE is a viable candidate for our target systems.

To read the full article, click here

×
Semiconductor IP