It doesn't mitigate untrusted software, but an interesting approach to tamper resistance can be found in
Infineon SLE78 security controllers (for smart cards, etc). They run dual CPUs out-of-sync and compare results after each instruction.
http://www.infineon.com/cms/en/product/chip-card-and-securit...