{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/34511"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/34511","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Design and evaluation of information flow signature for secure computation of applications","abstract":"This thesis presents an architectural solution that provides secure and reliable execution of an application that computes critical data, in spite of potential hardware and software vulnerabilities. The technique does not require source code of or specifications about the malicious library function(s) called during execution of an application. The solution is based on the concept of Information Flow Signatures (IFS). The technique uses both a model-checker-based symbolic fault injection analysis tool called SymPLFIED to generate an IFS for an application or operating system, and runtime signature checking at the level of hardware to protect the integrity of critical data. The runtime checking is implemented in the IFS module. Reliable computation of data is ensured by the critical value re-computation (CVR) module. Prototype implementation of the signature checking and reliability module on a soft processor within an FPGA incurs no performance overhead and about 12% chip area overhead. The security module itself incurs about 7.5% chip area overhead. Performance evaluations indicate that the IFS module incurs as little as 3-4% overhead compared to 88-100% overhead when the runtime checking is implemented as a part of software. Preliminary testing indicates that the technique can provide 100% coverage for insider attacks that manifest as memory corruption and change the architectural state of the processor. Hence the IFS and CVR implementation offers a flexible, low-overhead, high-coverage method for ensuring reliable and secure computing.","abstract_html":"This thesis presents an architectural solution that provides secure and reliable execution of an application that computes critical data, in spite of potential hardware and software vulnerabilities. The technique does not require source code of or specifications about the malicious library function(s) called during execution of an application. The solution is based on the concept of Information Flow Signatures (IFS). The technique uses both a model-checker-based symbolic fault injection analysis tool called SymPLFIED to generate an IFS for an application or operating system, and runtime signature checking at the level of hardware to protect the integrity of critical data. The runtime checking is implemented in the IFS module. Reliable computation of data is ensured by the critical value re-computation (CVR) module. Prototype implementation of the signature checking and reliability module on a soft processor within an FPGA incurs no performance overhead and about 12% chip area overhead. The security module itself incurs about 7.5% chip area overhead. Performance evaluations indicate that the IFS module incurs as little as 3-4% overhead compared to 88-100% overhead when the runtime checking is implemented as a part of software. Preliminary testing indicates that the technique can provide 100% coverage for insider attacks that manifest as memory corruption and change the architectural state of the processor. Hence the IFS and CVR implementation offers a flexible, low-overhead, high-coverage method for ensuring reliable and secure computing.","abstract_has_math":false,"creators":["Patel, Prateek"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Iyer, Ravishankar K.","Kalbarczyk, Zbigniew T."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2012,"date_issued":"2012-09-18T21:20:48Z","date_published":"2012-09-18T21:20:48Z","updated_at":"2026-07-22T22:25:31Z","subjects":["Information Flow Signature (IFS)"],"languages":["en"],"rights":["Copyright 2012 Prateek Patel"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/34511","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Iyer, Ravishankar K.","Kalbarczyk, Zbigniew T."]},{"key":"dc:creator","label":"Author","values":["Patel, Prateek"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2012-09-18T21:20:48Z","2014-09-18T10:01:01Z","2012-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Information Flow Signature (IFS)"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2012 Prateek Patel"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/34511"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["This thesis presents an architectural solution that provides secure and reliable execution of an application that computes critical data, in spite of potential hardware and software vulnerabilities. The technique does not require source code of or specifications about the malicious library function(s) called during execution of an application. The solution is based on the concept of Information Flow Signatures (IFS). The technique uses both a model-checker-based symbolic fault injection analysis tool called SymPLFIED to generate an IFS for an application or operating system, and runtime signature checking at the level of hardware to protect the integrity of critical data. The runtime checking is implemented in the IFS module. Reliable computation of data is ensured by the critical value re-computation (CVR) module. Prototype implementation of the signature checking and reliability module on a soft processor within an FPGA incurs no performance overhead and about 12% chip area overhead. The security module itself incurs about 7.5% chip area overhead. Performance evaluations indicate that the IFS module incurs as little as 3-4% overhead compared to 88-100% overhead when the runtime checking is implemented as a part of software. Preliminary testing indicates that the technique can provide 100% coverage for insider attacks that manifest as memory corruption and change the architectural state of the processor. Hence the IFS and CVR implementation offers a flexible, low-overhead, high-coverage method for ensuring reliable and secure computing.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-06-20T15:13:02Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Patel_Prateek.pdf: 2826350 bytes, checksum: cbe9120013adee6f8ddc1ac7a43f4f5f (MD5)","Made available in DSpace on 2012-09-18T21:20:48Z (GMT). No. of bitstreams: 2 Patel_Prateek.pdf: 2826369 bytes, checksum: 2ad6e60b7165bd6a460d08a9a90d4d0f (MD5) license.txt: 4064 bytes, checksum: 089336ba246d962e3bcfdb60f8c448a1 (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (srobbins@illinois.edu) on 2012-09-18T21:21:22Z Item is restricted until 2014-09-18T21:21:01Z","Restriction data tranferred 2014-07-01T11:35:14-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2014-09-18 16:21:01 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 34785 on 2014-09-18T10:01:01Z."]},{"key":"dc:title","label":"Title","values":["Design and evaluation of information flow signature for secure computation of applications"]}]}],"canonical_facts":{"dc:contributor":["Iyer, Ravishankar K.","Kalbarczyk, Zbigniew T."],"dc:creator":["Patel, Prateek"],"dc:date":["2012-09-18T21:20:48Z","2014-09-18T10:01:01Z","2012-08"],"dc:description":["This thesis presents an architectural solution that provides secure and reliable execution of an application that computes critical data, in spite of potential hardware and software vulnerabilities. The technique does not require source code of or specifications about the malicious library function(s) called during execution of an application. The solution is based on the concept of Information Flow Signatures (IFS). The technique uses both a model-checker-based symbolic fault injection analysis tool called SymPLFIED to generate an IFS for an application or operating system, and runtime signature checking at the level of hardware to protect the integrity of critical data. The runtime checking is implemented in the IFS module. Reliable computation of data is ensured by the critical value re-computation (CVR) module. Prototype implementation of the signature checking and reliability module on a soft processor within an FPGA incurs no performance overhead and about 12% chip area overhead. The security module itself incurs about 7.5% chip area overhead. Performance evaluations indicate that the IFS module incurs as little as 3-4% overhead compared to 88-100% overhead when the runtime checking is implemented as a part of software. Preliminary testing indicates that the technique can provide 100% coverage for insider attacks that manifest as memory corruption and change the architectural state of the processor. Hence the IFS and CVR implementation offers a flexible, low-overhead, high-coverage method for ensuring reliable and secure computing.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2012-06-20T15:13:02Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Patel_Prateek.pdf: 2826350 bytes, checksum: cbe9120013adee6f8ddc1ac7a43f4f5f (MD5)","Made available in DSpace on 2012-09-18T21:20:48Z (GMT). No. of bitstreams: 2 Patel_Prateek.pdf: 2826369 bytes, checksum: 2ad6e60b7165bd6a460d08a9a90d4d0f (MD5) license.txt: 4064 bytes, checksum: 089336ba246d962e3bcfdb60f8c448a1 (MD5)","Item marked as restricted to the 'UIUC Users [automated]' Group (id=2) by Seth Robbins (srobbins@illinois.edu) on 2012-09-18T21:21:22Z Item is restricted until 2014-09-18T21:21:01Z","Restriction data tranferred 2014-07-01T11:35:14-05:00 Original Data Group with Access UIUC Users [automated] Release Date: 2014-09-18 16:21:01 UTC Reason: Author requested U of Illinois access only (OA after 2yrs) in Vireo ETD system","U of I Only Restriction Lifted for Item 34785 on 2014-09-18T10:01:01Z."],"dc:identifier":["http://hdl.handle.net/2142/34511"],"dc:language":["en"],"dc:rights":["Copyright 2012 Prateek Patel"],"dc:subject":["Information Flow Signature (IFS)"],"dc:title":["Design and evaluation of information flow signature for secure computation of applications"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:31Z"}