The advent of Industry 4.0 and increasing digitalization have exposed industrial control networks to complex cyber threats. The Modbus protocol, a standard for communication in this field, was conceived for isolated systems and inherently lacks security mechanisms. The absence of encryption, authentication, and anti-replay controls leaves operational data and commands vulnerable to critical risks, making infrastructures susceptible to interception and tampering. To address these vulnerabilities, this thesis presents the hardware design and implementation of a cryptographic accelerator based on the AES-128 standard, specifically tailored to protect Modbus RTU serial communications. The primary objective is to introduce a robust security layer that is transparent to the existing infrastructure, while simultaneously ensuring compliance with the strict real-time constraints of the protocol and maintaining the high energy efficiency required by edge computing devices. The efficiency of inline encryption processes is closely tied to the adopted hardware architecture. Since purely software-based execution on low-power microcontrollers introduces unacceptable latencies for industrial protocols, the proposed system exploits the potential of FPGAs (Field-Programmable Gate Arrays). Developed on a Tang Nano 9K board using the Verilog language, the project integrates a RISC-V soft-core processor (PicoRV32) which, through the native PCPI interface, delegates the heavy cryptographic workload to the dedicated hardware module, overcoming the bottlenecks of sequential execution. Conducted tests demonstrate that the custom accelerator fully satisfies the operational requirements. The hardware is capable of completing encryption operations in extremely short times, keeping the latency well below the critical network failure threshold (the Modbus t1.5 constraint). This ensures a temporal determinism that traditional software implementations fail to provide, avoiding the delays that would otherwise cause the collapse of industrial communication. In addition to great temporal performance, the implementation distinguishes itself with a very low energy cost, proving to be a highly sustainable and competitive solution compared to high-frequency commercial processors. In conclusion, the work confirms the technical feasibility of seamlessly integrating security into legacy edge networks and lays the foundation for future developments focused on authenticated encryption and dynamic key management.
L'avvento dell'Industria 4.0 e la crescente digitalizzazione hanno esposto le reti di controllo industriale a minacce informatiche sempre più complesse. Il protocollo Modbus, standard di fatto per la comunicazione in questo settore, è stato concepito per sistemi isolati e risulta strutturalmente privo di meccanismi di sicurezza. L'assenza di crittografia, di autenticazione e di controlli anti-replay espone i dati e i comandi operativi a vulnerabilità critiche, rendendo le infrastrutture suscettibili a intercettazioni e manomissioni. Per rispondere a queste criticità, questo lavoro di tesi presenta la progettazione e l'implementazione hardware di un acceleratore crittografico basato sullo standard AES-128, specificamente concepito per proteggere le comunicazioni seriali Modbus RTU. L'obiettivo primario è introdurre un robusto livello di sicurezza (layer crittografico) che sia trasparente per l'infrastruttura esistente, garantendo contemporaneamente il rispetto dei rigorosi vincoli temporali (real-time) del protocollo e mantenendo un'elevata efficienza energetica, fondamentale per i dispositivi edge. L'efficienza dei processi di cifratura inline è strettamente legata all'architettura hardware adottata. Poiché l'elaborazione puramente software a bassa frequenza introduce latenze inaccettabili per i protocolli industriali, il sistema proposto sfrutta le potenzialità delle FPGA (Field-Programmable Gate Arrays). Sviluppato su una scheda Tang Nano 9K in linguaggio Verilog, il progetto integra un processore soft-core RISC-V (PicoRV32) che, tramite l'interfaccia nativa PCPI, delega il pesante carico crittografico al modulo hardware dedicato, superando i colli di bottiglia dell'esecuzione sequenziale. I test condotti dimostrano che l'acceleratore personalizzato soddisfa pienamente i requisiti operativi. L'hardware è in grado di completare le operazioni di cifratura in tempi estremamente ridotti, mantenendo la latenza ben al di sotto della soglia critica di fallimento della rete (il vincolo t1.5) del protocollo Modbus). Questo garantisce un determinismo temporale che le tradizionali implementazioni software non riescono ad assicurare, evitando i ritardi che causerebbero il collasso della comunicazione industriale. Oltre alle ottime prestazioni temporali, l'implementazione si distingue per un costo energetico estremamente contenuto, dimostrandosi una soluzione altamente sostenibile e competitiva rispetto ai processori commerciali ad alta frequenza. In conclusione, il lavoro conferma la fattibilità tecnica di integrare la sicurezza nei sistemi edge in modo trasparente e pone le basi per futuri sviluppi, orientati verso la crittografia autenticata e la gestione dinamica delle chiavi.
Progettazione e implementazione hardware di un modulo AES in Verilog su FPGA Tang Nano 9K per la protezione di comunicazioni Modbus
BADIALI, FEDERICO
2025/2026
Abstract
The advent of Industry 4.0 and increasing digitalization have exposed industrial control networks to complex cyber threats. The Modbus protocol, a standard for communication in this field, was conceived for isolated systems and inherently lacks security mechanisms. The absence of encryption, authentication, and anti-replay controls leaves operational data and commands vulnerable to critical risks, making infrastructures susceptible to interception and tampering. To address these vulnerabilities, this thesis presents the hardware design and implementation of a cryptographic accelerator based on the AES-128 standard, specifically tailored to protect Modbus RTU serial communications. The primary objective is to introduce a robust security layer that is transparent to the existing infrastructure, while simultaneously ensuring compliance with the strict real-time constraints of the protocol and maintaining the high energy efficiency required by edge computing devices. The efficiency of inline encryption processes is closely tied to the adopted hardware architecture. Since purely software-based execution on low-power microcontrollers introduces unacceptable latencies for industrial protocols, the proposed system exploits the potential of FPGAs (Field-Programmable Gate Arrays). Developed on a Tang Nano 9K board using the Verilog language, the project integrates a RISC-V soft-core processor (PicoRV32) which, through the native PCPI interface, delegates the heavy cryptographic workload to the dedicated hardware module, overcoming the bottlenecks of sequential execution. Conducted tests demonstrate that the custom accelerator fully satisfies the operational requirements. The hardware is capable of completing encryption operations in extremely short times, keeping the latency well below the critical network failure threshold (the Modbus t1.5 constraint). This ensures a temporal determinism that traditional software implementations fail to provide, avoiding the delays that would otherwise cause the collapse of industrial communication. In addition to great temporal performance, the implementation distinguishes itself with a very low energy cost, proving to be a highly sustainable and competitive solution compared to high-frequency commercial processors. In conclusion, the work confirms the technical feasibility of seamlessly integrating security into legacy edge networks and lays the foundation for future developments focused on authenticated encryption and dynamic key management.| File | Dimensione | Formato | |
|---|---|---|---|
|
Tesi_Badiali_Federico.pdf
accesso aperto
Descrizione: Documento di tesi
Dimensione
7.56 MB
Formato
Adobe PDF
|
7.56 MB | Adobe PDF | Visualizza/Apri |
I documenti in UNITESI sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/20.500.12075/27272