Pietro Fara

dblp:258/8086 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0002-6290-9231ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2025 A Design Flow to Securely Isolate FPGA Bus Transactions in Heterogeneous SoCs
abstract
Embedded computing systems are becoming increasingly complex. Modern system-on-chips come with heterogeneous designs that integrate diverse processing systems and a large variety of peripherals. When considering software with mixed and independent security and criticality levels, the heterogeneity of modern computing platforms poses considerable challenges in achieving strong isolation between execution domains. Tackling these challenges is even more difficult in platforms that integrate Field-Programmable Gate Array (FPGA) fabrics, which, due to their wide flexibility, introduce new security- and safety-related threats that can jeopardize isolation. As a matter of fact, if no proper countermeasures are in place, hardware accelerators (HAs) deployed on FPGA can be exploited to break the isolation capabilities implemented in a system by issuing dangerous bus transactions. This research proposes a design flow for heterogeneous platforms to strongly isolate bus transactions issued by HAs. The design flow is then specialized for the AMD Zynq UltraScale+ platform, leveraging the virtualizationrelated features of the Arm System Memory Management Unit (SMMU). The proposed solution jointly combines two new IPs for enforcing information transported by the AXI bus, a tool to verify the FPGA design, a principled configuration of the SMMU driver, and a secure boot flow. The proposal is evaluated with an industry-relevant use case related to embedded machine learning applied for the railway domain, in which isolation is established between two AMD Deep Learning Processor Units (DPU) and a set of FPGA HAs dedicated to a real-time critical application.
Niko Salamini, Sara Alonso Salazar, Gabriele Serra, Giorgiomaria Cicero, Pietro Fara, Federico Aromolo, Alessandro Biondi 0001
RTAS5
2023 Bounded transmission latency in real-time edge computing: a scheduling analysis
abstract
With the recent advancements in computing power and energy efficiency, embedded system platforms have become capable of providing services that previously required compu-tational support from cloud infrastructures. Accordingly, the edge computing paradigm is becoming increasingly relevant, as it allows, among other advantages, to foster security and privacy preservation by processing data at its origin. On the other hand, these systems demand predictability across the IoT-edge-cloud continuum. Regardless of the communication link, real-time tasks at the edge send data on the network, employing one or more transmission queues. For a system designer, analyzing the timing behavior of a task becomes challenging when each task has to wait for a variable amount of time before sending a packet. This paper analyzes the transmission behavior of a network of nodes regarding the latency introduced when dealing with a communication interface. The proposed analysis provides necessary conditions under which the data traffic is guaranteed not to exceed the transmission queue limit, thus avoiding unbounded waiting times on task execution, while a response time analysis technique is provided to ensure the schedulability of periodic tasks executing in each node of the network. An experimental campaign was carried out to evaluate the schedulability performance obtained with different system configurations when the proposed analysis was applied.
Pietro Fara, Gabriele Serra, Federico Aromolo
DSD1
2023 Enhancing the Availability of Web Services in the IoT-to-Edge-to-Cloud Compute Continuum: A WordPress Case Study
abstract
The IoT-to-Edge-to-Cloud compute continuum presents vast opportunities for innovative applications, including crowdsensing, which leverages interconnected devices to gather real-time data. In domains like autonomous driving, crowdsensing enables traffic information sharing through web services. In this context, web services, like those based on Content Management Systems (CMS), are often used by drivers and passengers to share data about user experience, traffic congestion, and high-definition maps. However, ensuring high availability becomes crucial to maintain accessibility and reliability against usage peaks. This paper proposes a modern WordPress deployment approach that takes advantage of cloud-based to realize a cost-effective horizontal scalable architecture, leveraging Amazon AWS. The architecture suggested was implemented to test the effectiveness and released as a set of architecture-ready-to-use templates. Experimental results are provided to measure per-request response times under different autoscaling policies and bootstrap times.
Gabriele Serra, Pietro Fara, Daniel Casini
DSD2
2022 PAC-PL: Enabling Control-Flow Integrity with Pointer Authentication in FPGA SoC Platforms
abstract
Control-flow integrity (CFI) is an effective technique to enhance the security of software systems. Processor designers recently started to provide hardware-based support to efficiently implement CFI, such as the pointer authentication (PA) feature provided by ARM starting from ARMv8.3-A processor architectures. These CFI mechanisms are also accompanied by support in the mainline codebase of popular compilers (such as GCC and LLVM) and the Linux operating system. As such, they are expected to establish as widespread security mechanisms. Nevertheless, many commercial chips still do not support hardware-assisted CFI, even some of the ones that just entered the market. This paper presents PAC-PL, a solution to enable hardware-assisted CFI on heterogeneous platforms that include a field-programmable gate array (FPGA) fabric, such as the Xilinx Ultrascale+ and Versal. PAC-PL comes with compiler-and OS-level support, is compatible with ARM’s PA, and enables advanced key management and attack detection strategies. A timing analysis for PAC-PL is also presented. PAC-PL was experimentally evaluated with state-of-the-art benchmarks in terms of run-time overhead, memory footprint, and FPGA resource consumption, resulting in a practical solution for implementing CFI.
Gabriele Serra, Pietro Fara, Giorgiomaria Cicero, Francesco Restuccia 0002, Alessandro Biondi 0001
RTAS2
2021 Scheduling Replica Voting in Fixed-Priority Real-Time Systems
abstract
Reliability and safety are mandatory requirements for safety-critical embedded systems. The design of a fault-tolerant system is required in many fields (e.g., railway, automotive, avionics) and redundancy helps in achieving this goal. Redundant systems typically leverage voting techniques applied to the outputs produced by tasks to detect and even tolerate failures. This paper studies the integration of distributed voting protocols in fixed-priority real-time systems from a scheduling perspective. It analyzes two scheduling strategies for implementing voting. One is attractive and friendly for software developers and based on suspending the task execution until the replica provides the data to be voted. The other one is inspired by the Logical Execution Time (LET) paradigm and requires introducing additional tasks in the system to accomplish voting-related activities. Queuing and delays introduced by inter-replica communication interfaces are also analyzed. Experimental results are finally presented to compare the two strategies, showing that LET-inspired voting is much more predictable and hence more suitable than the other strategy for fixed-priority real-time systems.
Pietro Fara, Gabriele Serra, Alessandro Biondi 0001, Ciro Donnarumma
ECRTS1
2021 ReTiF: A declarative real-time scheduling framework for POSIX systems
abstract
This paper proposes a novel framework providing a declarative interface to access real-time process scheduling services available in an operating system kernel . The main idea is to let applications declare their temporal requirements or characteristics without knowing exactly which underlying scheduling algorithms are offered by the system. The proposed framework can adequately handle such a set of heterogeneous requirements configuring the platform and partitioning the requests among the available multitude of cores, so to exploit the various scheduling disciplines that are available in the kernel, matching application requirements in the best possible way. The framework is realized with a modular architecture in which different plugins handle independently certain real-time scheduling features. The architecture is designed to make its behavior customization easier and enhance the support for other operating systems by introducing and configuring additional plugins.
Gabriele Serra, Gabriele Ara, Pietro Fara, Tommaso Cucinotta
J. Syst. Archit.3
2020 An Architecture for Declarative Real-Time Scheduling on Linux
abstract
This paper proposes a novel framework and programming model for real-time applications supporting a declarative access to real-time CPU scheduling features that are available on an operating system. The core idea is to let applications declare their temporal characteristics and/or requirements on the CPU allocation, where, for example, some of them may require real-time POSIX priorities, whilst others might need resource reservations through SCHED_DEADLINE. The framework can properly handle such a set of heterogeneous requirements configuring an underlying multi-core platform so to exploit the various scheduling disciplines that are available in the kernel, matching applications requirements. The framework is realized as a modular architecture in which different plugins handle independently certain real-time scheduling features within the underlying kernel, easing the customization of its behavior to support other schedulers or operating systems by adding further plugins.
Gabriele Serra, Gabriele Ara, Pietro Fara, Tommaso Cucinotta
ISORC3