Systems Engineering and Electronics ›› 2026, Vol. 48 ›› Issue (6): 1913-1924.doi: 10.12305/j.issn.1001-506X.2026.06.13

• Systems Engineering • Previous Articles     Next Articles

A model-based method for chip vulnerability analysis in IoT device

Hu PAN1, Zhouchen HUANG2,3, ZhaoRui YANG4,*, Yi ZHANG2,3, Bo CHEN2,3   

  1. 1. School of Reliability and Systems Engineering,Beihang University,Beijing 100191,China
    2. Aerospace Science & Industry Defense Technology Research and Test Center,Beijing 100854,China
    3. Innovation Center for Components Application Verification Technology,Beijing 100854,China
    4. School of Information and Communication Engineering,University of Electronic Science and Technology of China,Chengdu 611731,China
  • Received:2025-01-10 Revised:2025-05-18 Online:2026-06-25 Published:2026-03-16
  • Contact: ZhaoRui YANG

Abstract:

With the widespread deployment of internet of things (IoT) devices, chip vulnerabilities become critical threats to device security. Existing approaches primarily focus on detecting vulnerabilities, while overlooking validating the exploitability of vulnerability, resulting in the problem of false positives. To address this problem, this paper proposes a model-based method for chip vulnerability analysis. The method integrates device models with vulnerability detection data to uncover potential attack chains, and constructs hybrid state machine models representing both device and attacker behaviors to simulate real-world attack scenarios according to kombination of architecture model specificAtion (KARMA). By conducting behavioral simulation, the method evaluates whether the system exhibits abnormal behavior to determine the exploitability of the detected vulnerability. Experiments using a smart home system as a case study demonstrate the exploitability of the global positioning system (GPS) chip vulnerability in the phone within the system. Furthermore, the vulnerability is successfully exploited in a real-world environment to crash the mobile device, verifying the effectiveness of the proposed method.

Key words: vulnerability validation, hybrid automata, model simulation, kombination of architecture model specificAtion (KARMA)

CLC Number: 

[an error occurred while processing this directive]