Method for generating test set of hardware Trojan horse hidden at chip layout level
By analyzing and modifying the chip layout, a hardware Trojan test set is generated with good hiddenness, which solves the problem of insufficient existing test sets and improves the chip's defense ability and detection difficulty.
Patent Information
- Application Number
- CN202210505611.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-10
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2042-05-10
AI Technical Summary
The existing hardware Trojan test set is not enough to support the further development of detection technology, resulting in insufficient defense capabilities of the chip.
A method for generating a chip layout-level hidden hardware Trojan test set is proposed. By analyzing and modifying the chip layout information, a hardware Trojan test set is generated with a good hidden hardware Trojan test set. This method includes layout information extraction, vulnerability analysis and test set generation, using EDA tools for logical design and physical design, and combining hidden layout algorithms to hide hardware Trojan devices.
It has promoted the development of hardware Trojan detection technology, improved the chip's defense capabilities, and increased the detection difficulty and enhanced the chip's security by hiding hardware Trojan test sets.
Smart Images

Figure CN114996062B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of chip layout-level security, and particularly to a method for generating a test set for hidden hardware trojans at the chip layout level. Background Art
[0002] In 2007, Worcester Polytechnic Institute and IBM Watson Research Center jointly published an article, first proposing the concept of chip hardware trojans (see the literature "Trojan Detection using IC Fingerprinting," D. Agrawal, S. Baktir and D. K arakoyunlu, Proceedings of IEEE Symposium on Security and Privacy (SSP’07), pp. 296-310, 2007). A hardware trojan is a malicious modification or addition to the underlying hardware circuit to achieve the purpose of modifying circuit logic, stealing user information, and destroying circuit functions, with great destructive power (see the literature "Hardware Trojan: Threats and emer ging solutions," R. S. Chakraborty, N. Seetharam and B. Swarup, Proceedings of the 14th IEEE International High Level Design Validation and Test Workshop, pp. 166-171, 2009). Moreover, the insertion method is flexible and the location is hidden, which can seriously affect the chip function and quickly attracted a large number of researchers to the field of hardware trojan detection and design.
[0003] In 2008, Turek et al. from the University of Illinois in the United States inserted shadow logic into the processor, which could secretly enhance the inserter's control over the processing (see the literature "Designing and Implementing Malicious Hardware," S.T. King, J. Tucek, A. Cozzie, et al., Leet, 2008, 8: 1-8). Mark, Bicky, and others from the University of Florida in the United States formulated classification criteria for hardware trojans after detailed discussions and designed the TrustHub standard test set, greatly promoting the progress of hardware trojan detection technology (see the literature "Benchmarking of hardware trojans and maliciously affected circuits," B. Shakya, T. He, H. Salmani, et al., Journal of Hardware and Systems Security, 2017, 1(1): 85-102). With the efforts of researchers, the detection accuracy of hardware trojan detection technology is getting higher and higher, and the existing hardware trojan test sets are increasingly insufficient to support the further development of detection technology. Summary of the Invention
[0004] In view of the results of layout vulnerability analysis, the present invention proposes a method for generating a chip layout-level hidden hardware trojan test set, which promotes the development of trojan detection technology and further enhances the defense ability of the chip.
[0005] A method for generating a chip layout-level hidden hardware trojan test set proposed by the present invention includes the following steps:
[0006] S1) Layout information extraction
[0007] Obtain the register transfer level (RTL) code of a circuit, use electronic design automation (EDA) tools to complete the logical design and physical design of the RTL circuit, obtain the chip layout result, analyze the chip layout result, write an auxiliary script, and obtain the set of chip layout information points N = {n1, n2,..., n l×r}, where the chip layout information point n i corresponds to the i-th chip layout area, i = 1, 2,..., l×r; l and r respectively represent the number of units divided horizontally and vertically in the chip layout; calculate the steady-state information of any chip layout information point n i , that is, the steady-state temperature and the steady-state arrival time Summarize the steady-state information of each chip layout information point into a steady-state feature vector:
[0008]
[0009] Among them, represents splicing the steady-state temperature and the steady-state arrival time to form the steady-state feature vector of chip layout information point n i ; After completing the extraction of the steady-state feature vector for each chip layout information point, the vulnerability analysis of the chip layout can be carried out.
[0010] S2) Layout vulnerability analysis
[0011] According to the chip layout and routing principle, the EDA tool uses the logic netlist and standard cell library information to perform chip physical layout design. The EDA tool first arranges the cells in the standard cell library in rows, and in the subsequent routing process, realizes device interconnection through the routing channels on the metal layer; Analyze the blank layout space in the chip layout result obtained in step S1) and the unused routing space after routing is completed. Denote the minimum standard cell area in the current process library as s min , the blank layout space of chip layout area n i is Total number of blank routing channels Then the vulnerability index i that chip layout area n will be inserted by a hardware Trojan horse is calculated as:
[0012]
[0013] Perform the above analysis and calculation for each chip layout information point, and the chip layout vulnerability matrix CV can be obtained:
[0014]
[0015] The matrix CV describes the vulnerability index of each chip layout information point when a hardware Trojan horse is implanted. When is smaller, the chip layout resources are less, it is more difficult to insert a hardware Trojan horse, and the vulnerability of chip layout area n i is higher, but the compact layout resources will also increase the physical field parameters of n i , making it more difficult to detect hardware Trojans.
[0016] After completing the vulnerability analysis of the entire chip layout, the test set generation can be started.
[0017] S3) Test set generation
[0018] Arrange the vulnerability indices of each chip layout information point in the chip layout vulnerability matrix CV in ascending order when a hardware Trojan is implanted, and select the first q chip layout information points corresponding to the vulnerability indices as low-vulnerability points for hardware Trojan implantation, where q ≤ l × r and q is a positive integer;
[0019] These q low-vulnerability points form a set N1 of chip layout information points; Take N1 as the target implantation area. Let the set of hardware Trojan devices be T, and the size of the set T is c3. Implant the set of hardware Trojan devices T into N1 to generate a chip layout-level stealthy hardware Trojan test set.
[0020] The present invention proposes a method for generating a chip layout-level stealthy hardware Trojan test set. Based on the vulnerability analysis of the integrated circuit physical field, a new method for generating a hardware Trojan test set is proposed for the layout-level hardware Trojan attack mode, providing a better test set. By analyzing the chip layout information and modifying the chip layout, the present invention obtains a hardware Trojan test set with better concealment, which can promote the development of hardware Trojan detection technology and enhance the defense ability of the chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 is the overall flowchart of the test set generation method of the present invention;
[0022] Figure 2 is the flowchart of the hardware Trojan layout-level stealth of the present invention;
[0023] Figure 3 is the schematic diagram of the reconstruction result of the layout area N1 of the present invention;
[0024] Figure 4 is the schematic diagram of the area N1 containing only tapfiller of the present invention;
[0025] Figure 5 is the present invention n i is the position correspondence diagram with the N1 area. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] To make the objectives, technical solutions, and advantages of the present invention clearer, the following describes the specific embodiments of the present invention in combination with the embodiments and the drawings, so that those skilled in the art can better understand the present invention. It should be particularly noted that the described embodiments are part of the embodiments of the present invention, not all of the embodiments, and are not intended to limit the scope of the present invention claimed. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0027] The chip layout-level stealthy hardware Trojan test set refers to the chip layout result after the Trojan devices are hidden on the chip layout. Technicians can improve the existing detection means and enhance the chip's defense ability by comparing and analyzing the chip layout without Trojans and the stealthy Trojan chip layout. This invention is mainly based on the existing hardware Trojan side-channel detection method. By performing vulnerability analysis on the completed chip layout and using the stealthy layout algorithm to hide the hardware Trojan devices, the hardware Trojan devices are hidden in positions with lower vulnerability in the chip layout, and then the chip layout is wired to obtain the chip layout-level stealthy hardware Trojan test set.
[0028] Therefore, the main content of the method for generating the chip layout-level stealthy hardware Trojan test set is the design of the Trojan device hiding algorithm. The overall process of a method for generating the chip layout-level stealthy hardware Trojan test set proposed by this invention is as follows Figure 1 as shown.
[0029] Given the register-transfer level (RTL) code of a circuit, the method for performing chip layout-level hardware Trojan stealth and generating a test set has the following specific steps:
[0030] (1) Layout information extraction
[0031] Use electronic design automation (EDA) tools to complete the logical design and physical design of the RTL circuit to obtain the chip layout result. Analyze the chip layout result, write auxiliary scripts, and finally obtain the chip layout information point vector N = {n1, n2,..., n l×r}, where n i (i = 1, 2,..., l×r) corresponds to each chip layout area, as follows Figure 5 shown; l and r respectively represent the number of units divided horizontally and vertically in the chip layout. Calculate the steady-state information of each chip layout information point n i , that is, calculate the steady-state temperature steady-state arrival time Summarize the steady-state information of each chip layout information point into a steady-state feature vector:
[0032]
[0033] where represents concatenating the steady-state temperature and the steady-state arrival time to form the steady-state feature vector of the chip layout information point n i . After completing the steady-state feature vector of each information point n iAfter extracting the steady-state eigenvectors, vulnerability analysis of the chip layout can be carried out.
[0034] (2) Layout vulnerability analysis
[0035] According to the principles of chip layout and routing, the EDA tool will use the logic netlist and standard cell library information to perform chip physical layout design. The layout tool (EDA tool) will arrange the cells in the standard cell library (i.e., standard devices) in rows, and then, in the subsequent routing process, interconnect the devices through the routing channels on the metal layer. Here, we analyze the blank layout space after the initial layout of the chip layout (i.e., the chip layout result obtained in step (1), which is also the chip layout result before the Trojan obfuscation) is completed and the unused routing space after routing is completed. Denote the area of the smallest standard cell in the current process library as s min , chip layout area n i (i.e., chip layout information point n i )'s blank layout space is Total number of blank routing channels Then the vulnerability index
[0036]
[0037] Among them, is the vulnerability index at which the chip layout area n i will be inserted with a hardware Trojan. Performing the above analysis on each information point of the entire chip layout, the chip layout vulnerability matrix can be obtained:
[0038]
[0039] Matrix CV describes the vulnerability index of each chip layout information point when a hardware Trojan is implanted, that is, The smaller it is, the fewer chip layout resources, the more difficult it is to insert a Trojan, and the higher the vulnerability of information point n i . However, the compact layout resources will also increase the physical field parameters of n i , making Trojan detection more difficult.
[0040] After completing the vulnerability analysis of the entire chip layout, test set generation can be started.
[0041] (3) Test set generation
[0042] The chip layout-level obfuscated hardware trojan test set refers to the chip layout result after hiding the hardware trojan device on the chip layout. The present invention analyzes the chip layout containing the hardware trojan, changes the layout of the original layout devices through the obfuscation algorithm proposed by the present invention, distributes and hides the trojan devices on the chip layout at low-vulnerability information points, and then completes the physical design process after layout through EDA tools, and finally obtains the chip layout result after obfuscating the hardware trojan, that is, the chip layout-level obfuscated hardware trojan test set.
[0043] Arrange the vulnerability indices of each chip layout information point in the chip layout vulnerability matrix CV in ascending order when implanted with the hardware trojan, select the first q chip layout information points corresponding to the vulnerability indices as low-vulnerability points, and implant the hardware trojan, where q ≤ l × r and q is a positive integer;
[0044] These q low-vulnerability points form a chip layout information point set N1. Take N1 as the target implantation area. Let the hardware trojan device set be T, and the size of the set T is c3. The process of implanting the hardware trojan device set T into N1 is as Figure 2 shown. Figure 2 Complete the following steps:
[0045] The first step: Extract the layout topology
[0046] For the chip layout area N1, use EDA tools to extract the original device set A on N1. The size of the set A is set to c1. The set A includes all devices on the chip layout area N1, specifically divided into logic devices and non-logic device tapfillers. All devices in the present invention can be called standard devices because the devices used in chip design are all taken from the standard cell library. Record the information such as the adjacent devices, coordinates p, and width w of each standard device c in the set A, and thus extract the chip layout topology. After the chip layout topology is extracted, obtain the blank layout space between any two adjacent devices, form an s element with coordinates and width, uniquely corresponding to the blank layout space, and then add it to the set S. The blank layout space between every two adjacent devices is an element in the set S, and thus the set S composed of the blank layout spaces between any two adjacent devices in all cases can be obtained. The size of the set S is c0, as Figure 3 shown. Record the coordinates p and width w of the element s in the set S.
[0047] Among them, tapfiller is a special non-logical device implanted during the process of generating the layout by the EDA tool, which is used to eliminate the latch-up effect of the chip. Specifically, tapfiller applies a bias voltage to the substrate at a fixed pitch to reduce the parasitic resistance of the substrate, so that the triode voltage cannot reach the conduction requirement, thereby cutting off the positive feedback loop of the latch-up effect and eliminating the latch-up effect. Therefore, when changing the layout of the layout, the present invention does not change the coordinate position of the tapfiller device.
[0048] Step 2: Sequential implantation
[0049] Use the sequential implantation algorithm to implant the hardware Trojan device. The specific steps are as follows:
[0050] a) Sort each element in set S and set T in descending order of width to obtain an ordered queue where s j represents the element with the sorting serial number j from large to small in width in the ordered queue Q S and t j′ represents the element with the sorting serial number j′ from large to small in width in the ordered queue Q T where j = 1, 2,..., c0, j′ = 1, 2,..., c3, and then jump to step b).
[0051] b) If Q T is empty, jump to step c); if Q T is not empty but Q S is empty, the sequential implantation method directly ends; when Q T and Q S are both not empty, respectively take the head elements of Q S and Q T , denoted as s0 and t0 respectively, where the width of s0 is and the coordinate is the width of t0 is and the coordinate is If then dequeue s0 and t0, and let update the coordinate of the head element in set T; update the head elements of Q S and Q T , and repeat step b); if then it is determined that there is a hardware Trojan device that is too wide to be implanted, and the sequential implantation method directly ends.
[0052] c) According to the updated coordinate information of each element (i.e., device) in set T, output a coordinate update script, and run this script in the EDA tool to update the chip layout, and obtain the chip layout of the hidden hardware Trojan, that is, the generation of the chip layout-level hidden hardware Trojan test set is completed.
[0053] If the sequential implantation method cannot complete the complete layout of the hardware Trojan device set T to obtain the chip layout-level hidden hardware Trojan test set, it is necessary to appropriately change the positions of the devices in the chip layout result obtained in step (1), and then try to implant the hardware Trojan. The specific steps are shown in the third and fourth steps.
[0054] The third step: Effective solution search
[0055] First, the concept of an effective layout position is proposed. The effective layout position of a device on the chip layout refers to the position where the device does not overlap with other devices and cause layout conflicts at the current position, that is, the device can complete the chip layout design process; in addition, the set of coordinate values of each device when all elements in set A and set T are in effective layout positions is called an effective layout solution.
[0056] Using the sequential implantation method, it is impossible to complete the chip layout without changing the positions of the original devices in the original device set A of N1. Therefore, a global search method will be used to search for the layout solution: all the original devices (cells) in set A are removed from the region N1 to which they belong, and only the tapfiller devices are retained. Figure 4 As shown:
[0057] At this time, the layout space margin of the N1 region is divided by the tapfiller device and the N1 edge.
[0058] The purpose of the effective solution search is to determine whether there is at least one layout solution. The process is as follows:
[0059] a) For the region N1 from which all the original devices are removed and only the tapfiller devices are retained, update set S to obtain set S′. Suppose there are c2 elements in the current set S′, and sort the elements in set S′ in descending order of width to obtain an ordered queue where s′ j″ The ordered queue is denoted as Q S′ The element with the sorting serial number j″ in descending order of width in Q, j″ = 1, 2,..., c2. Regard the elements in set A and set T as the devices a to be laid out i′ , i′ = 1, 2..., c1 + c3. Sort each device a to be laid out i′ in descending order of width to obtain an ordered queue
[0060] b) If Q A is empty, jump to step d); if Q A is not empty but Q S′ is empty, it is determined that there is no effective layout solution, and it is necessary to jump to the fifth step to re-divide the chip layout; if Q A 、QS′ If none of them is empty, then respectively take Q A , Q S′ The head elements of the queues, denoted as a0 and s′0 respectively. The width of a0 is The coordinates are The width of s′0 is The coordinates are If Then jump to step c); if It is determined that the current chip layout result divides the chip layout too finely and it is impossible to implant the hardware Trojan device. It is necessary to increase the chip layout division interval and re-analyze the chip layout result to obtain the chip layout information point set, that is, jump to the fifth step to re-divide the chip layout.
[0061] c) Initialize the depth H of the effective solution search algorithm to 1, and jump to step c1).
[0062] c1) Let i″ = 0, where i″ is a variable within the effective solution search algorithm layer and not a global variable. In addition, since the ordered queue Q S′ Will be updated during the progress of the effective solution search algorithm, so the size c2 of the ordered queue Q S′ Is also a variable within the layer, and then jump to step c2).
[0063] c2) If the current Q A Is empty, then jump to step d); otherwise, if i″ > c2, then it is determined that there is no effective solution and jump to the fifth step; if i″ ≤ c2, then select the element s′ S′ In Q i″ And the head element a0 of Q A , where the width of s′ i″ Is The coordinates are And try to implant a0 into s′ i″ . Here, it is discussed in two cases: ① and ②:
[0064] ① If Then a0 dequeues, and let Calculate the width margin of s′ i″ After implanting a0 Update the information of s′ i″ Where Respectively represent the x-component and y-component of the coordinates , and then re-sort the elements in Q S′ In descending order of width, let H = H + 1, the effective solution search algorithm advances one layer, and then jump to step c1).
[0065] ② If Then the effective solution search algorithm retreats one layer, let H = H - 1, and jump to step c2).
[0066] d) When the effective solution search jumps to this step d), it indicates that there is an effective layout solution, and then it can jump to the fourth step to search for the optimal layout solution.
[0067] When there is no effective layout solution, jump to the fifth step.
[0068] Fourth step: Optimal solution search
[0069] When the EDA tool performs device layout according to the standard cell library, there is a minimum width metric w0, that is, the widths of the layout devices and the chip layout are both integer multiples of w0. Therefore, when there is an effective layout solution, the device layout of the chip layout can be further divided, and with the goal of minimizing layout changes, search for the optimal layout solution. For the original devices in set A, the following are defined:
[0070]
[0071] where p j″′ is the initial coordinate of the original device numbered j″′ in set A, and p′ j″′ is the coordinate of the original device numbered j″′ in set A when the effective solution search is completed, where the completion of the effective solution search means that all the devices to be laid out in sets A and T are implanted into the effective layout positions, ||·||2 is the L2 norm operation, j″′ = 1, 2,..., c1, and dist represents the overall offset degree of all the devices in set A. The process of the optimal solution search is as follows:
[0072] a) Initialize dist A = +∞, and initialize the depth H′ of the optimal layout solution search algorithm to 1, and execute step a1).
[0073] a1) Set i″′ = 0, k = -1, where both i″′ and k are variables within the optimal layout solution search algorithm layer and not global variables, and then jump to step a2). The optimal layout solution search algorithm layer corresponds to the device implantation in Q A . Whenever the implantation of a device is completed, the optimal layout solution search algorithm advances one layer, and the algorithm depth H′ is incremented by 1.
[0074] a2) If the current Q A is empty, jump to step b); otherwise, let i″′ = i″′ + 1. The size of the ordered queue Q S′ is c2. If i″′ > c2: At this time, when H′ = 1, jump to step c); when H′ ≠ 1, the optimal layout solution search algorithm retreats one layer, H′ = H′ - 1, and jumps to a3); if i″′ ≤ c2, take the head element a0 of the current Q A , and select s′ from Q S′ i″′ , where the width of a0 is The coordinate is s′ i″′ The width of The coordinate is Try to implant a0 into s′ i″ ′, and discuss it in three cases: ①, ②, and ③:
[0075] ① If Then a0 dequeues, and let At the same time, s′ i″′ Dequeues, and let H′ = H′ + 1, then jump to step a1).
[0076] ② If Then s′ i″′ Dequeues, and calculate
[0077]
[0078]
[0079] where slack′ represents the width margin in s′ i″′ after implanting a0, and the width margin of s′ i″′ The number of the minimum width metrics w0 included in the width margin slack′, then jump to step a3).
[0080] ③ If If H′ = 1 at this time, then jump to step b); if H′ ≠ 1 at this time, then the optimal layout solution search algorithm retreats one layer, H′ = H′ - 1, and then jumps to step a3).
[0081] a3) Let k = k + 1. If k > c4, then the optimal layout solution search algorithm retreats one layer, H′ = H′ - 1, and then jumps to step a3); if k ≤ c4, then let where k×w0 represents the x - component of the coordinate (k×w0, 0), and 0 represents the y - component of the coordinate (k×w0, 0); create new blank layout space elements s′ (i″′-1) 、s′ (i″′-2) , and initialize the information of s′ (i″′-1) and s′ (i″′-2) as follows:
[0082]
[0083]
[0084] where, s′ (i″′-1) is the remaining blank layout space on the left after implanting a0 into s′ i″′ , s′ (i″′-2)It is to implant a0 into s′ i″′ The remaining blank layout space on the right side after that, respectively represent s′ (i″′-1) and s′ (i″′-2) widths, respectively represent s′ (i″′-1) and s′ (i″′-2) coordinates, respectively represent the x-component and y-component of the coordinate ; Add s′ (i″′-1) and s′ (i″′-2) to the queue Q S′ and reorder Q S′ in decreasing order of width, and let H′ = H′ + 1, then jump to step a1).
[0085] b) When jumping to this step b), all devices in set A and set T are in valid layout positions. It is said that an effective layout solution is obtained at this time. Calculate the dist value of this layout solution. If dist < dist A , then update dist A = dist, record the updated coordinate values of each element in set A and set T in this layout solution, then the optimal solution search algorithm retreats one layer, that is, H′ = H′ - 1, and then jumps to step a3); if dist ≥ dist A , the optimal solution search algorithm directly retreats one layer, that is, H′ = H′ - 1, and then jumps to step a3).
[0086] c) The layout positions of each element in the current set A and set T on the given target implantation area N1 have been searched. The currently recorded layout solution is the optimal layout solution. According to the updated coordinate information values of each element in set A and set T in the currently recorded layout solution, output the coordinate update script, and run this coordinate update script in the EDA tool to update the chip layout, and obtain the chip layout of the hidden hardware Trojan, that is, the generation of the chip layout level hidden hardware Trojan test set is completed.
[0087] Step 5: Re-divide the layout
[0088] When jumping to this step 5, it means that there is no effective layout solution. At this time, the chip layout level hidden hardware Trojan test set cannot be generated. It is necessary to make l = l - 1 and r = r - 1 to increase the chip layout division interval, and then jump to step (1) to re-analyze the chip layout with the updated division fineness until the chip layout level hidden hardware Trojan test set can be generated.
[0089] Embodiment
[0090] Taking the RTL code of the AES series circuits provided by the Trust-Hub website as an example, the experiment of generating the test set is carried out, and the experimental results are shown in Table 1 below.
[0091] Table 1 Comparison of Detection Rates between the Original Layout and the Obfuscated Layout
[0092]
[0093]
[0094] As can be seen from Table 1, before being processed by the method of the present invention, the detection probabilities of the hardware Trojans in the original test set chip layout are all 100%, that is, the original layout strategy cannot hide the hardware Trojans; after the obfuscation process of the present invention, the detection rates of the obfuscated test set all drop significantly to about 50%. From the perspective of probability theory, it can be considered that the current detection means cannot distinguish different types of test samples in the obfuscated test set, and the hardware Trojans are well hidden, and the generation of the obfuscated hardware Trojan test set at the chip layout level is successful.
[0095] The embodiments described above are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
Claims
1. A method for generating a test set for hidden hardware Trojans at the chip layout level, characterized in that, The method includes the following steps: S1) Layout information extraction Obtain the register transfer level (RTL) code of a circuit, use electronic design automation (EDA) tools to complete the logical design and physical design of the RTL circuit, obtain the chip layout result, analyze the chip layout result, write an auxiliary script, and obtain the set of chip layout information points N = {n1, n2,..., n l×r}, where the chip layout information point n i corresponds to the i-th chip layout area, i = 1, 2,..., l × r; l and r respectively represent the number of units divided horizontally and vertically in the chip layout; calculate the steady-state information of any chip layout information point n i , that is, the steady-state temperature and the steady-state arrival time Summarize the steady-state information of each chip layout information point into a steady-state feature vector: Among them, represents the steady-state temperature and the steady-state arrival time are spliced to form the chip layout information point n i of the steady-state eigenvector; after the steady-state eigenvectors of each chip layout information point are extracted, the vulnerability analysis of the chip layout can be carried out; S2) Layout vulnerability analysis According to the principle of chip layout and routing, the EDA tool uses the logic netlist and standard cell library information to perform chip physical layout design. The EDA tool first arranges the cells in the standard cell library in rows, and in the subsequent routing process, realizes device interconnection through the routing channels on the metal layer; analyze the blank layout space in the chip layout result obtained in step S1) and the unused routing space after routing is completed, and record the area of the smallest standard cell in the current process library as s min , the blank layout space of chip layout information point n i is Total number of blank routing channels Then the vulnerability index i that chip layout information point n will be inserted with a hardware Trojan is calculated as: By performing the above analysis and calculation on each chip layout information point, the chip layout vulnerability matrix CV can be obtained: The matrix CV describes the vulnerability index of each chip layout information point when it is implanted with a hardware Trojan. When is smaller, the chip layout resources are fewer, and it is more difficult to insert a hardware Trojan. The vulnerability of the chip layout information point n i is higher. However, the compact layout resources will also increase the physical field parameters of n i , making it more difficult to detect hardware Trojans; After completing the vulnerability analysis of the entire chip layout, the test set generation can be started; S3) Test set generation Arrange the vulnerability indices of each chip layout information point in the chip layout vulnerability matrix CV in ascending order when the hardware Trojan is implanted, and select the first q chip layout information points corresponding to the vulnerability indices as low-vulnerability points for hardware Trojan implantation, where q ≤ l × r and q is a positive integer; The chip layout information point set N1 is composed of these q low-vulnerability points. Taking N1 as the target implantation area, setting the hardware Trojan device set as T, and the size of the set T is c3. The steps of implanting the hardware Trojan device set T into N1 include: S31) Extract layout topology Use an EDA tool to extract the original device set A on N1, set the size of set A to c1, and record the adjacent devices, coordinates p, and width w information of each standard device c in set A. Thus, the chip layout topology is extracted. After the chip layout topology is extracted, the blank layout space between any two adjacent devices is obtained. A unique s element composed of coordinates and width corresponds to this blank layout space, and this s element is added to set S. The size of set S is set to c0, and the coordinates and width of any s element in set S are recorded; S32) Sequential implantation Use the sequential implantation method to implant hardware Trojan devices. The specific steps include: S321) Sort the elements in sets S and T respectively in descending order of width to obtain ordered queues where s j represents the element with the j-th sorting order in the ordered queue Q S in descending order of width, and t j′ represents the element with the j'-th sorting order in the ordered queue Q T in descending order of width, where j = 1, 2,..., c0, j' = 1, 2,..., c3, and then jump to step S322); S322) If Q T is empty, jump to step S323); if Q T is not empty but Q S is empty, the sequential implantation method directly ends; when Q T and Q S are both not empty, respectively take the head elements of Q S and Q T , and denote them as s0 and t0 respectively, where the width of s0 is and the coordinate is the width of t0 is and the coordinate is If , then dequeue s0 and t0, and let update the coordinates of the head element in set T; update the head elements of Q S and Q T , and repeat step S322); if , then it is determined that there is a hardware Trojan device with an excessive width that cannot be implanted, and the sequential implantation method directly ends; S323) According to the updated coordinate information of each element in set T, output a coordinate update script, and run this script in the EDA tool to update the chip layout, obtaining the chip layout with the hidden hardware Trojan, that is, the generation of the chip layout-level hidden hardware Trojan test set is completed; If the sequential implantation method cannot complete the complete layout of the hardware Trojan device set T to obtain the chip layout-level hidden hardware Trojan test set, it is necessary to change the positions of the devices in the chip layout result obtained in step S1), and then try to implant the hardware Trojan. The specific steps are as shown in S33) and S34); S33) Effective solution search First, the concept of an effective layout position is proposed. The effective layout position of a device on the chip layout refers to that the device does not overlap with other devices at the current position and cause layout conflicts, that is, the device can complete the chip layout design process; in addition, the set of coordinate values of each device when all elements in set A and set T are in effective layout positions is called an effective layout solution; When the sequential implantation method cannot complete the chip layout without changing the positions of the original devices in the original device set A on N1, a global search method will be used to search for the layout solution: all the original devices in set A are removed from the area N1 where they belong, and only the tapfiller devices are retained. Among them, the tapfiller device is a special non-logical device implanted during the process of generating the layout by the EDA tool to eliminate the latch-up effect of the chip. Therefore, when changing the layout of the chip layout, the coordinate positions of the tapfiller devices are not changed. At this time, the layout space margin of area N1 is divided by the tapfiller devices and the edge of N1; The purpose of the valid solution search is to determine whether there is at least one valid layout solution, and the process is as follows: S331) For the region N1 where all original devices are removed and only the tapfiller device remains, update the set S to obtain the set S′. Suppose there are c2 elements in the current set S′, and sort the elements in the set S′ in descending order of width to obtain an ordered queue where s′ j″ The ordered queue is denoted as Q S′ The element with the sorting serial number j″ in descending order of width in Q, where j″ = 1, 2,..., c2. Consider the elements in both set A and set T as devices a to be placed i′ , where i′ = 1, 2…, c1 + c3. Sort each device a to be placed i′ in descending order of width to obtain an ordered queue S332) If Q A is empty, then jump to step S334); if Q A is not empty but Q S′ is empty, then it is determined that there is no valid layout solution, and it is necessary to jump to step S35) to re-analyze the chip layout result; if Q A and Q S′ are both not empty, then take the head elements of Q A and Q S′ respectively, and denote them as a0 and s′0. The width of a0 is and the coordinate is The width of s′0 is and the coordinate is If then jump to step S333); if it is determined that the chip layout result currently divides the chip layout too finely and it is impossible to implant the hardware Trojan device. It is necessary to increase the chip layout division interval and re-analyze the chip layout result to obtain the chip layout information point set, that is, jump to step S35). S333) Initialize the depth H of the valid solution search algorithm to 1, and execute step S3331); S3331) Set i″ = 0, where i″ is a variable within the effective solution search algorithm layer and not a global variable. Additionally, since Q will be updated during the progress of the effective solution search algorithm, the size c2 of the ordered queue Q is also a variable within the layer. Then, jump to step S3332); S′ is updated, so the ordered queue Q S′ 's size c2 is also a variable within the layer, and then jump to step S3332); S3332) If the current Q A is empty, jump to step S334); otherwise, if i″ > c2, it is determined that there is no valid solution and jump to step S35); if i″ ≤ c2, select the element s′ S′ in Q i″ and the head element a0 of Q A , where the width of s′ i″ is and the coordinate is and try to implant a0 into s′ i″ . Here, it is discussed in two cases: a) and b): a) If then a0 dequeues, and let calculate s′ i″ the width margin after a0 is implanted update s′ i″ information of where respectively represent the x - component and y - component of the coordinates, and then re - sort each element in Q S′ in descending order of width, let H = H + 1, the effective solution search algorithm advances one layer, and then jumps to step S3331); b) If the effective solution search algorithm goes back one level, sets H = H - 1, and jumps to step S3332); When the valid solution search jumps to this step S334), it indicates that there is a valid layout solution, and it can jump to step S34) to perform the optimal layout solution search; S34) Optimal layout solution search When the EDA tool performs device layout according to the standard cell library, there is a minimum width metric w0, that is, the widths of the layout device and the chip layout are both integer multiples of w0. Therefore, when there is a valid layout solution, the device layout of the chip layout can be further divided, aiming at the smallest possible layout change to find the optimal layout solution; for the original devices in set A, the overall offset degree of all devices in set A is defined here as: where p j″′ is the initial coordinate of the original device numbered j″′ in set A, and p′ j″′ is the coordinate of the original device numbered j″′ in set A when the search for the effective solution is completed. The completion of the search for the effective solution means that all the devices to be placed in sets A and T have been implanted into the effective placement positions. ||·||2 represents the L2 norm operation, where j″′ = 1, 2,..., c1. The process of searching for the optimal placement solution includes: S341) Initialize dist A = +∞, initialize the depth H' of the optimal layout solution search algorithm to 1, and execute step S3411); S3411) Set i″′ = 0, k = -1, where both i″′ and k are variables within the optimal layout solution search algorithm layer rather than global variables, and then jump to step S3412). The optimal layout solution search algorithm layer corresponds to the device implantation in Q A For each device implantation completed in S3412) If the current Q A is empty, jump to step S342). Otherwise, let i″′ = i″′ + 1. The size of the ordered queue Q S′ is c2. If i″′ > c2: At this time, when H′ = 1, jump to step S343). When H′ ≠ 1, the optimal layout solution search algorithm retreats one layer, H′ = H′ - 1, and jumps to S3413). If i″′ ≤ c2, take the current Q A queue head element a0, and select s′ S′ from Q i″′ , where the width of a0 is and the coordinate is The width of s′ i″′ is and the coordinate is Try to implant a0 into s′ i″′ , and discuss it in three cases: 1), 2), and 3): 1) If then a0 dequeues, and let At the same time, s′ i″′ dequeues, and let H′ = H′ + 1, then jump to step S3411); 2) If then s' i″′ is dequeued, and calculate where slack′ represents s′ i″′ After being implanted into a0, s′ i″′ the width margin of the width margin in, c4 represents the number of the minimum width measures w0 included in the width margin slack′, and then jumps to step S3413); 3) If If H' = 1 at this time, jump to step S342); if H' ≠ 1 at this time, the optimal layout solution search algorithm retreats one layer, H' = H' - 1, and then jumps to step S3413); S3413) Let k = k + 1. If k > c4, then the optimal layout solution search algorithm retreats one layer, H′ = H′ - 1, and then jumps to step S3413); if k ≤ c4, then let where k×w0 represents the x - component of the coordinate (k×w0, 0), and 0 represents the y - component of the coordinate (k×w0, 0); create new blank layout space elements s′ (i″′-1) and s′ (i″′-2) , and initialize the information of s′ (i″′-1) and s′ (i″′-2) as follows: where s' (i″′-1) is the remaining blank layout space on the left side after implanting a0 into s' i″′ , and s' (i″′-2) is the remaining blank layout space on the right side after implanting a0 into s' i″′ . respectively represent the widths of s' (i″′-1) and s' (i″′-2) ; respectively represent the coordinates of s' (i″′-1) and s' (i″′-2) ; respectively represent the x-component and y-component of the coordinate ; add s' (i″′-1) and s' (i″′-2) to the queue Q S′ , reorder Q S′ in decreasing order of width, and let H' = H' + 1, then jump to step S3411); When jumping to this step S342), all the devices in set A and set T are in the effective layout positions. At this time, an effective layout solution is obtained. Calculate the dist value of this layout solution. If dist < dist A , then update dist A = dist, record the updated coordinate values of each element in set A and set T in this layout solution, and then the optimal solution search algorithm retreats one layer, that is, H' = H' - 1, and then jumps to step S3413); if dist ≥ dist A , the optimal solution search algorithm directly retreats one layer, that is, H' = H' - 1, and then jumps to step S3413); S343) After the layout positions of the elements in the current set A and set T on the given target implantation area N1 are searched, the currently recorded layout solution is the optimal layout solution. According to the updated coordinate information values of the elements in set A and set T in the currently recorded layout solution, output a coordinate update script, and run this coordinate update script in the EDA tool to update the chip layout, and obtain the chip layout of the hidden hardware Trojan, that is, the generation of the chip layout-level hidden hardware Trojan test set is completed; S35) Redivide the chip layout When jumping to this step S35), it indicates that there is no valid layout solution. At this time, the chip layout-level hidden hardware Trojan test set cannot be generated. It is necessary to make l = l - 1 and r = r - 1 to increase the chip layout division interval, and then jump to step S1) to re-analyze the chip layout result to obtain the chip layout information point set until the chip layout-level hidden hardware Trojan test set can be generated.
2. The method for generating a test set for detecting hardware Trojans at the chip layout level according to claim 1, wherein After step S35), it also includes using the RTL code of the AES series circuit provided by the Trust-Hub website as a test set to test the method for generating the chip layout-level hidden hardware Trojan test set.