FPGA-Based State Evolution Architecture for Tamper Detection in Embedded Systems
Abstract
Reliable state continuity is essential for embedded and Internet of Things (IoT) devices that generate security-relevant events, audit records, and runtime status information. If an adversary can modify stored records, replay previous events, reorder updates, or roll back the device to a previously valid state, verifying the trustworthiness of the device’s current state becomes challenging. Existing log management guidance emphasizes collection, retention, monitoring, and protection of logs. However, it does not define a lightweight, hardware-enforced method for cryptographic state continuity in constrained devices. This paper presents a Field-Programmable Gate Array (FPGA)-based state evolution architecture that provides hardware-enforced one-way state updates, runtime tamper detection, and fail-secure containment. For each accepted event, this architecture cryptographically binds the previous protected state, event data, sequence counter, and associated metadata to form a tamper-evident continuity chain. The protected state and counter are managed by a finite-state machine and cannot be directly modified by untrusted firmware. Although the proposed architecture is hash function independent, this work uses Ascon-Hash256, a National Institute of Standards and Technology (NIST) standardized cryptographic algorithm for constrained devices. FPGA implementation and attack-oriented simulation scenarios demonstrate that the proposed architecture provides a low footprint hardware anchor to maintain trusted state evolution in embedded and IoT systems.