Register transfer level verification method and register transfer level verification device
By determining the combination of verification nodes and performing equivalence verification in the register transfer stage, the problem of new feature exception drivers in RTL code is solved, the accuracy of exception driver detection is improved, and the normal function of integrated circuits is ensured.
Patent Information
- Application Number
- CN202610467321.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-09
- Publication Date
- 2026-08-25
AI Technical Summary
When new features are inserted into existing register-transfer-level (RTL) code, the accuracy of exception-driven verification is low, making it difficult to ensure the normal operation of integrated circuit functions.
By determining the combination of verification nodes and comparing the signal input and output values of the register transfer stage under test and the reference register transfer stage based on the equivalence verification method, it is possible to detect whether the newly added feature abnormally drives the functional logic.
It improves the accuracy of abnormal driver detection and ensures that new features do not affect the normal function of the register transfer stage.
Smart Images

Figure CN122633478A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of integrated circuit technology, and more specifically, to a method and apparatus for verifying register transfer level. Background Technology
[0002] To meet practical design or testing needs, designers sometimes insert new features, such as debug IDs, into the Register Transfer Level (RTL) code during the design phase. However, the logic complexity of RTL code is high, and these new features can sometimes incorrectly drive the RTL's functional logic, leading to malfunctions. Therefore, after inserting new features into the RTL code, it is necessary to perform exception-driven verification on these new features. However, existing verification methods for these new features have low accuracy. Summary of the Invention
[0003] In view of this, embodiments of the present invention provide a register-transfer level verification method and a register-transfer level verification device to determine the signal input value of the verification node based on the newly added characteristics, and to realize the abnormal drive detection of the newly added characteristics based on equivalence verification, thereby improving the accuracy of abnormal drive detection.
[0004] In a first aspect, embodiments of the present invention provide a register-transfer level verification method, the method comprising: Obtain the register transfer level under test, wherein the register transfer level under test is a reference register transfer level into which new features are inserted, and the new features include debug identifiers; A verification node combination is determined, the verification node combination includes a first verification node and a second verification node, the first verification node is a verification node in the register transfer stage under test, the second verification node is a verification node in the reference register transfer stage, and there is a mapping relationship between the first verification node and the second verification node; Using the second verification node as a benchmark, the first verification node is subjected to equivalence verification according to the new feature to determine the first equivalence verification result of the register transfer stage under test. The first equivalence verification result is used to characterize whether the register transfer stage under test is equivalent to the reference register transfer stage. The abnormal driving state of the newly added feature is determined based on the first equivalence verification result. The abnormal driving state is used to characterize whether the newly added feature drives the functional logic of the register transfer stage under test.
[0005] Optionally, the first verification node includes a first signal input point and a first signal output point, and the second verification node includes a second signal input point and a second signal output point. The first signal input point and the second signal input point are mapped to each other, and the first signal output point and the second signal output point are mapped to each other. The step of using the second verification node as a benchmark and performing equivalence verification on the first verification node based on the newly added features to determine the first equivalence verification result of the register transfer level under test includes: Determine the signal input values of the first signal input point and the second signal input point based on the newly added characteristics; Determine the first signal output value of the first signal output point and the second signal output value of the second signal output point based on the signal input value; A second equivalence verification result is determined based on the first signal output value and the second signal output value. The second equivalence verification result is used to characterize whether the first signal output point and the second signal output point are equivalent. The first equivalence verification result is determined based on the second equivalence verification result.
[0006] Optionally, the first signal input point and the second signal input point are input ports of the corresponding register transfer stage, and the first signal output point and the second signal output point are truncation points or logical equivalent points of the corresponding register transfer stage; or The first signal input point and the second signal input point are truncation points or logical equivalent points of the corresponding register transfer stage, and the first signal output point and the second signal output point are truncation points or logical equivalent points of the corresponding register transfer stage; or The first signal input point and the second signal input point are the cutoff points or logical equivalent points of the corresponding register transfer stage, and the first signal output point and the second signal output point are the output ports of the corresponding register transfer stage.
[0007] Optionally, the first signal input point is adjacent to the first signal output point, and the second signal input point is adjacent to the second signal output point; The step of determining the second equivalence verification result of the first signal output point based on the first signal output value and the second signal output value includes: In response to the first signal output value not being equal to the corresponding second signal output value, the first signal output point corresponding to the first signal output value is determined as the initial signal output point to be measured; The second signal output point corresponding to the second signal output value is determined as the initial reference signal output point; The equivalence of the output value of the signal to be tested of the first verification node downstream of the initial output point of the signal to be tested is verified iteratively based on the reference signal output value of the second verification node downstream of the initial reference signal output point. In response to the fact that the first signal output value and the second signal output value are not equal in the last iteration cycle, the second equivalence verification result is determined to characterize that the initial test signal output point and the initial reference signal output point are not equivalent; The step of iteratively verifying the equivalence of the output value of the signal to be tested of the first verification node downstream of the initial output point of the signal to be tested based on the reference signal output value of the second verification node downstream of the initial reference signal output point includes: The next first verification node of the initial test signal output point is determined as the first target signal output point of the first iteration cycle, and the next second verification node of the initial reference signal output point is determined as the second target signal output point of the first iteration cycle. In each iteration cycle, it is determined whether the test signal output value of the first target signal output point is equal to the reference signal output value of the second target signal output point. In response to the test signal output value not being equal to the reference signal output value, the next first verification node of the first target signal output point is updated to the first target signal output point of the next iteration cycle, and the next second verification node of the second target signal output point is updated to the second target signal output point of the next iteration cycle, until there is no next first verification node and no next second verification node.
[0008] Optionally, determining the second equivalence verification result of the first signal output point based on the first signal output value and the second signal output value includes: In response to the first signal output value being equal to the second signal output value, the second equivalence verification result is determined to characterize the first signal output point as equivalent to the second signal output point.
[0009] Optionally, the method further includes: In response to the second equivalence verification result indicating that the initial test signal output point and the initial reference signal output point are not equivalent, it is determined that the abnormal driving position of the newly added feature is located between the test signal output point and the corresponding first signal input point.
[0010] Optionally, the first signal input point and the second signal input point are input ports of the corresponding register transfer stage, and the first signal output point and the second signal output point are output ports of the corresponding register transfer stage; The step of determining the second equivalence verification result of the first signal output point based on the first signal output value and the second signal output value includes: In response to the fact that the first signal output value and the second signal output value are not equal, the second equivalence verification result is determined to indicate that the first signal output point and the second signal output point are not equivalent; In response to the first signal output value being equal to the second signal output value, the second equivalence verification result is determined to characterize the first signal output point as equivalent to the second signal output point.
[0011] Optionally, determining the first equivalence verification result based on the second equivalence verification result includes: In response to at least one of the second equivalence verification results indicating that the first signal output point and the second signal output point are not equivalent, it is determined that the first equivalence verification result indicates that the transfer stage of the register under test and the transfer stage of the reference register are not equivalent; In response to each of the second equivalence verification results indicating that the first signal output point and the second signal output point are equivalent, it is determined that the first equivalence verification result indicates that the transfer stage of the register under test is equivalent to the transfer stage of the reference register.
[0012] Optionally, determining the abnormal driving state of the newly added feature based on the first equivalence verification result includes: In response to the first equivalence verification result indicating that the transfer stage of the register under test is not equivalent to the transfer stage of the reference register, the abnormal driving state is determined to indicate that the new feature drives the functional logic; In response to the first equivalence verification result indicating that the transfer stage of the register under test is equivalent to the transfer stage of the reference register, the abnormal driving state is determined to indicate that the new feature does not drive the functional logic.
[0013] Secondly, embodiments of the present invention provide a register-transfer level verification apparatus, the apparatus comprising: An acquisition unit is used to acquire the register transfer stage under test, wherein the register transfer stage under test is a reference register transfer stage with inserted new features, and the new features include a debug identifier. A combination determination unit is used to determine a combination of verification nodes, wherein the combination of verification nodes includes a first verification node and a second verification node, the first verification node is a verification node in the register transfer stage under test, the second verification node is a verification node in the reference register transfer stage, and there is a mapping relationship between the first verification node and the second verification node. The verification unit is used to perform equivalence verification on the first verification node based on the second verification node and the newly added features, and to determine the first equivalence verification result of the register transfer stage under test. The first equivalence verification result is used to characterize whether the register transfer stage under test is equivalent to the reference register transfer stage. The state determination unit is used to determine the abnormal driving state of the newly added feature based on the first equivalence verification result. The abnormal driving state is used to characterize whether the newly added feature drives the functional logic of the register transfer stage under test.
[0014] Thirdly, embodiments of the present invention provide an electronic device, including a memory and a processor, wherein the memory is used to store one or more computer program instructions, wherein the one or more computer program instructions are executed by the processor to implement the method as described in any one of the first aspects.
[0015] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method as described in any one of the first aspects.
[0016] Fifthly, embodiments of the present invention provide a computer program product, the computer program product including a computer program / instruction, which, when executed by a processor, implements the method as described in any one of the first aspects.
[0017] This invention, in its embodiments, obtains the register transfer stage under test (UTP) after inserting a new feature into the reference register transfer stage. It then identifies a verification node combination between the verification node in the UTP and a corresponding verification node in the reference register transfer stage. Using the verification node in the reference register transfer stage as a benchmark, it performs equivalence verification on the verification nodes in the UTP based on the newly added feature. Based on the equivalence verification result, it determines whether the new feature drives the functional logic of the UTP. This invention determines the signal input value of the verification node based on the new feature, thereby enabling abnormal drive detection of the new feature based on equivalence verification, thus improving the accuracy of abnormal drive detection. Attached Figure Description
[0018] The above and other objects, features and advantages of the present invention will become clearer from the following description of embodiments of the invention with reference to the accompanying drawings, in which: Figure 1 This is a flowchart of a register transfer level verification method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the register transfer stage under test and the reference register transfer stage according to an embodiment of the present invention; Figure 3 This is a flowchart of a register transfer level verification method according to an embodiment of the present invention; Figure 4 This is a flowchart of a register transfer level verification method according to an embodiment of the present invention; Figure 5 This is another schematic diagram of the register transfer stage under test and the reference register transfer stage according to an embodiment of the present invention; Figure 6 This is a schematic diagram illustrating the process of determining the second equivalence verification result of the verification node in an embodiment of the present invention; Figure 7 This is a schematic diagram of a register transfer level verification device according to an embodiment of the present invention; Figure 8 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0019] The present application is described below based on embodiments, but it is not limited to these embodiments. In the detailed description of the present application below, certain specific details are described in detail. Those skilled in the art can fully understand the present application without these details. To avoid obscuring the substance of the present application, well-known methods, processes, flows, elements, and circuits are not described in detail.
[0020] Furthermore, those skilled in the art should understand that the accompanying drawings provided herein are for illustrative purposes only and are not necessarily drawn to scale.
[0021] Unless the context explicitly requires it, words such as "including" or "contains" throughout the application should be interpreted as including rather than exclusive or exhaustive; that is, meaning "including but not limited to".
[0022] In the description of this application, it should be understood that the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0023] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0024] Debug flags are dedicated identifiers (or logic units) inserted into RTL designs to quickly locate functional anomalies, signal errors, or version issues during testing, effectively improving debugging and verification efficiency. Therefore, to meet practical design or testing needs, designers sometimes insert new features such as debug flags into the RTL code. In standard RTL designs, to avoid affecting the functionality of integrated circuits, these new features do not drive the functional logic of the RTL. Instead, they are logically isolated from the functional logic of the data path through independent configuration ports, control signals, configuration registers, etc.
[0025] However, if the RTL design is not standardized, new features may incorrectly drive the functional logic of the RTL, leading to malfunctions in the integrated circuit. To avoid this, it is necessary to verify the abnormal driving of new features. Taking the new feature as a debug flag as an example, existing technologies mainly verify the abnormal driving of debug flags in the following ways: One is manual verification, which is difficult to guarantee the completeness of verification and has low verification efficiency. Another is to use tools to parse all Verilog (a hardware description language) / VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) code, generate the logic hierarchy (including the module to which the logic belongs, the always block to which the code belongs, and the module port to which the signal belongs), and filter out the logic related to the debug flag; if the debug flag logic belongs to a core functional module (or always block), the abnormal driving of the debug flag will be judged as abnormal; if the debug flag logic belongs to an independent debug module (or code block), the abnormal driving of the debug flag will be judged as normal. However, this method is sensitive to the writing of RTL code, is prone to misjudgment, has low accuracy, and cannot cover boundary or extreme scenarios, so its universality is low. One approach involves using tools to locate all load logic that reads or uses debug flag signals, constructing a fan-out tree with these logics as root nodes, and then tracing down the fan-out tree layer by layer to all affected logic units and signals. It checks whether all nodes covered by the fan-out tree only include debug domain logic with debug flags (i.e., logic that does not affect core functional logic without debug flag keywords). Therefore, when the fan-out range of the fan-out tree is limited to the debug domain, the abnormal driver with the debug flag is considered normal; and when the fan-out affects core functional logic outside the debug domain, the abnormal driver with the debug flag is considered abnormal. However, this method is prone to misjudgments, especially misjudging debug flag logic that is actually abnormal but does not affect the core functional domain as normal. The accuracy is low, and in scenarios with complex RTL functional logic, the accuracy and verification efficiency of this method are significantly reduced, resulting in low versatility.
[0026] The embodiments of this invention are mainly described using the newly added feature as a debugging identifier as an example. It should be understood that this embodiment is not limited to this. Existing newly added features that can support the corresponding functions, such as clock gate, or newly added features that can support the corresponding functions as technology develops in the future, are all within the protection scope of this embodiment.
[0027] To address the aforementioned issues, this invention proposes an RTL verification method and an RTL verification device to determine the signal input value of the verification node based on the newly added characteristics, and to realize the abnormal drive detection of the newly added characteristics based on equivalence verification, thereby improving the accuracy of abnormal drive detection.
[0028] The following describes the method through examples. Figure 1 This is a flowchart of the RTL verification method according to an embodiment of the present invention. Figure 1 As shown, the method in this embodiment may include the following steps: Step S100: Obtain the transfer level of the register under test.
[0029] After the RTL is written, the designer can verify it, including static formal verification, such as static lint checks (used to detect syntax and semantic errors, coding style, and potential logical problems in the RTL), CDC (Clock Domain Crossing), code consistency checks, etc., as well as functional verification, such as module-level verification, system-level verification, formal verification, etc. After the RTL passes all the verifications, it is determined as the reference RTL.
[0030] Furthermore, new features can be inserted into the reference RTL to obtain the RTL to be tested. In this embodiment, new features can be inserted in various ways, such as manually by the designer or through tools such as Synopsys SpyGlass Low Power and Cadence Joules RTL Power Solution.
[0031] Step S200: Determine the combination of verification nodes.
[0032] In this step, the verification node determined in the RTL to be tested can be used as the first verification node, and the verification node in the reference RTL that is completely corresponding to the first verification node in terms of function, hierarchical position, signal link and verification target can be used as the second verification node. Then, the mapping relationship between the first verification node and the second verification node is established, and the two verification points are determined as the verification node combination.
[0033] The equivalence verification proves through formal methods that the output signals of the RTL under test and the reference RTL have completely identical timing behavior in any clock cycle under all possible combinations of input signals. Therefore, the first verification node can include the signal input point (i.e., the first signal input point) and the signal output point (i.e., the first signal output point) of the RTL under test. Similarly, the second verification node can include the signal input point (i.e., the second signal input point) and the signal output point (i.e., the second signal output point) of the reference RTL.
[0034] In one optional implementation of this embodiment, the first signal input point can be the input port of the RTL under test, and the first signal output point can be the output port of the RTL under test. Similarly, the second signal input point can be the input port of the reference RTL, and the second signal output point can be the output port of the reference RTL.
[0035] In one optional implementation of this embodiment, the RTL under test and the reference RTL can be truncated symmetrically to determine multiple cut points with mapping relationships. Alternatively, tools such as Conformal, Formality, Questa Formal, and the SEC tool of Formal can be used to automatically identify logical equivalence points in the RTL under test and the reference RTL. That is, both the RTL under test and the reference RTL can be truncated (i.e., both are truncated), or only one RTL can be truncated (i.e., only one is truncated), or neither can be truncated. Therefore, the first signal input point can be the input port of the RTL under test, the first signal output point can be the cut point or logical equivalence point of the RTL under test, and the second signal input point can be the input port of the reference RTL, and the second signal output point can be the cut point or logical equivalence point of the reference RTL. Alternatively, the first signal input point and the first signal output point can be different cutoff points or logical equivalent points of the RTL under test, and the second signal input point and the second signal output point can be different cutoff points or logical equivalent points of the reference RTL. Alternatively, the first signal input point can be a cutoff point or logical equivalent point of the RTL under test, the first signal output point can be an output port of the RTL under test, and the second signal input point can be a cutoff point or logical equivalent point of the reference RTL, and the second signal output point can be an output port of the reference RTL.
[0036] Figure 2 This is a schematic diagram of the RTL to be tested and the reference RTL in an embodiment of the present invention. Figure 2As shown, a single-sided truncation method is used to process the RTL under test and the reference RTL, where P2 is the truncation point of the reference RTL and P1 is the logical equivalent point of the RTL under test. In this embodiment, input ports 21 and 22 can be used as the first signal input points of the RTL under test, and output port 23 can be used as the first signal output point of the RTL under test. Simultaneously, input ports 21' and 22' can be used as the second signal input points of the reference RTL, and output port 23' can be used as the second signal output point of the reference RTL. The aforementioned verification nodes are then combined as verification nodes. Alternatively, input port 21 can be used as the first signal input point of the RTL under test, and logical equivalent point P1 can be used as the first signal output point of the RTL under test. Input port 21' is used as the second signal input point of the reference RTL, and cutoff point P2 is used as the second signal output point of the reference RTL. The above verification nodes are then combined as a verification node combination. Then, logic equivalent point P1 and input port 22 are used as the first signal input point of the RTL under test, and output port 23 is used as the first signal output point of the RTL under test. At the same time, cutoff point P2 and input port 22' can be used as the second signal input point of the reference RTL, and output port 23' can be used as the second signal output point of the reference RTL. The above verification nodes are then combined as another verification node combination.
[0037] Step S300: Using the second verification node as a benchmark, perform equivalence verification on the first verification node based on the newly added features, and determine the first equivalence verification result of the register transfer level under test.
[0038] In this embodiment, equivalence verification is used to determine whether the abnormal driver of the newly added feature is abnormal. Therefore, in this step, the equivalence verification of the first verification node of the RTL under test can be performed based on the newly added feature, and the first equivalence verification result of the RTL under test can be determined. Optionally, the equivalence verification method in this embodiment can be sequential equivalence checking (SEC), logical equivalence checking (LEC), etc. Taking sequential equivalence checking as an example, the equivalence verification of the first verification node can be implemented using the SEC tool of the Formal tool.
[0039] Figure 3 This is a flowchart of the RTL verification method according to an embodiment of the present invention. Figure 3 As shown, in an optional implementation of this embodiment, step S300 may include the following steps: Step S310: Determine the signal input values of the first signal input point and the second signal input point based on the newly added characteristics.
[0040] If a new feature drives the functional logic of the RTL under test, the signal output value of the RTL under test will also be affected by the new feature. For example, if the functional logic of the reference RTL is a+b, and the debugging flag logic drives the RTL under test, that is, the functional logic of the RTL under test is modified to a+b+debugging flag, when the signal input values of the RTL under test are a, b, and the debugging flag, the signal output value c_imp of the RTL under test will be a+b+debugging flag. Therefore, this embodiment uses the principle of equivalence verification assuming that the signal input values of the RTL under test and the reference RTL are completely consistent, and determines whether the signal output values of the RTL under test and the reference RTL are still consistent to realize the abnormal driving detection of the new feature.
[0041] In this step, the signal input values of the first signal input point and the second signal input point can be determined based on the newly added characteristics. That is, the signal input values of the first signal input point and the second signal input point are exactly the same, both including the newly added characteristics.
[0042] Before determining the signal input value based on the new feature, a new feature input port can be added to both the reference RTL and the RTL under test. The new feature input port of the reference RTL does not participate in the calculation, so as to ensure that the reference RTL can use the new feature as a signal input value without changing the functional logic of the reference RTL.
[0043] Step S320: Determine the first signal output value of the first signal output point and the second signal output value of the second signal output point based on the signal input value.
[0044] This step calculates the signal output value of the logic path based on the signal input values and functional logic formed by the signal input and output points. The functional logic of the logic path can be determined using RTL (Real-Time Level Translation).
[0045] by Figure 2 Taking the schematic diagram as an example, when the first signal input point is input port 21 and the first signal output point is logic equivalent point P1, the signal output value W of logic equivalent point P1 can be obtained according to the signal input value of input port 21 and the logic function g1 of logic L1.
[0046] If the new feature does not drive the functional logic involved in the logic path, the signal output value of the RTL will not be affected by the new feature. For example, if the functional logic of the reference RTL is a+b, even if the debug flag is included as part of the signal input value of the reference RTL, that is, the signal input value is a, b and the debug flag, the signal output value of the reference RTL will not include the debug flag, that is, the signal output value c_spec=a+b.
[0047] Optionally, in order to perform equivalence verification more accurately, when updating a verification node from a signal output point to a signal input point, the signal input value of the verification node can be verified, and if the verification passes, the signal output value when the verification node is used as a signal output point can be used as the signal input value when the verification node is used as a signal input point.
[0048] Still with Figure 2 Taking the schematic diagram as an example, when the cutoff point P2 is used as the signal output point, the signal output value is Z, and when it is used as the signal input point, the signal input value is Z'. Before using Z' as the signal input value of the cutoff point P2, it is possible to check whether the signal output value Z is equal to the signal output value (which is also the signal input value of the logical equivalent point P1) W. When the signal output value Z is equal to the signal output value W, Z' is assigned the value W. Then, the signal output value of the output port 23' is obtained based on the signal input value of the input port 22' and the signal input value Z'.
[0049] Step S330: Determine the second equivalence verification result of the first signal output point based on the first signal output value and the second signal output value.
[0050] In this step, it can be determined whether the first signal output point and the second signal output point are equivalent based on whether the signal output value of the first signal output point (i.e., the first signal output value) and the signal output value of the second signal output point (i.e., the second signal output value) are equal.
[0051] Still with Figure 2 Taking the schematic diagram as an example, when the second signal input point is input port 21', the second signal output point is cutoff point P2, and the first signal input point is input port 21, and the first signal output point is logical equivalence point P1, the signal input values of input port 21 and input port 21' can be determined according to x, and the equivalence of logical equivalence point P1 and cutoff point P2 can be determined according to whether the signal output value W of logical equivalence point P1 is equal to the signal output value Z of cutoff point P2; when the second signal input point is cutoff point P2 and input port 22', the second signal output point is output port 23', and the first signal input point is logical equivalence point P1 and input port 22, and the first signal output point is output port 23, the signal input values of input port 21 and input port 21' can be determined according to x, the signal input values of input port 22 and input port 22' can be determined according to y, and the equivalence of output port 23 and output port 23' can be determined according to whether the signal output value out_spec of output port 23' is equal to the signal output value out_imp of output port 23.
[0052] In one optional implementation of this embodiment, if the RTL includes both combinational logic and sequential logic (i.e., registers), even if the output signals of the RTL (i.e., the signal output values of the output ports) are completely equivalent, the functions of the internal logic or registers may still be inconsistent. Therefore, in this implementation, the verification node includes not only the input and output ports of the RTL, but also logical equivalence points or cutoff points. That is, the RTL under test and the reference RTL can be processed into multiple logical paths, and the equivalence verification results of each logical path can be verified separately.
[0053] In this optional implementation, if the first signal output value is equal to the second signal output value, then the second equivalence verification result can be determined to indicate that the first signal output point and the second signal output point are equivalent.
[0054] However, in practice, if the cutoff point or logical equivalence point is not positioned appropriately, even if the newly added feature does not drive the functional logic of the RTL under test, equivalence verification may still produce counterexamples. That is, the signal output value of the first signal output point includes the newly added feature and is not equal to the signal output value of the second signal output point. Therefore, alternatively, abnormal driving detection of the newly added feature can be achieved by iteratively updating the verification nodes.
[0055] Figure 4 This is a flowchart of the RTL verification method according to an embodiment of the present invention. Figure 4 As shown, in an optional implementation of this embodiment, step S330 may include the following steps: Step S331: In response to the fact that the first signal output value is not equal to the corresponding second signal output value, the first signal output point corresponding to the first signal output value is determined as the initial test signal output point.
[0056] Optionally, the first signal input point and the first signal output point can be an input port and a logical equivalent point (or cutoff point) adjacent to the input port, or an adjacent logical equivalent point (or cutoff point), or a logical equivalent point (or cutoff point) adjacent to the output port and the output port.
[0057] Figure 5 This is another schematic diagram of the RTL to be tested and the reference RTL in an embodiment of the present invention. Figure 5As shown, the reference RTL and the RTL under test include five sets of verification nodes with a mapping relationship: input port 51 and input port 51', cutoff point P51 and cutoff point P51', cutoff point P52 and cutoff point P52', cutoff point P53 and cutoff point P53', cutoff point P55 and cutoff point P55', and output port 52 and output port 52'. When the first signal input point is input port 51 and the second signal input point is input port 51', the first signal output point is cutoff point P51 and the second signal output point is cutoff point P51'; when the first signal input point is cutoff point P51 and the second signal input point is cutoff point P51', the first signal output point is cutoff point P52 and the second signal output point is cutoff point P52'; when the first signal input point is cutoff point P52 and the second signal input point is cutoff point P52', the first signal output point is cutoff point P53 and the second signal output point is cutoff point P53'; when the first signal input point is cutoff point P53 and the second signal input point is cutoff point P53', the first signal output point is output port 52 and the second signal output point is output port 52'.
[0058] Therefore, in this step, when the first signal output value of any first signal output point is not equal to the signal output value of the corresponding second signal output point, the first signal output point can be determined as the initial signal output point to be tested, so as to carry out further detection in the future.
[0059] Step S332: Determine the second signal output point corresponding to the second signal output value as the initial reference signal output point.
[0060] Similar to step S331, when the first signal output value of any first signal output point is not equal to the signal output value of the corresponding second signal output point, the second signal output point can be determined as the initial reference signal output point.
[0061] Step S333: Perform equivalence verification on the output value of the signal to be tested of the first verification node downstream of the initial output point of the signal to be tested based on the reference signal output value of the second verification node downstream of the initial reference signal output point in an iterative manner.
[0062] In this step, the first signal input point corresponding to the initial test signal output point can still be used as the first signal input point of the RTL under test, and the second signal input point corresponding to the initial reference signal output point can still be used as the second signal input point of the reference RTL. The downstream first verification node of the initial test signal output point is updated to the first target signal output point in an iterative manner, and the downstream second verification node of the initial reference signal output point is updated to the second target signal output point in an iterative manner, so as to perform equivalence verification on the test signal output value of the first target signal output point based on the reference signal output value of the second target signal output point.
[0063] In each iteration cycle, it can be verified whether the output value of the signal under test at the first target signal output point and the output value of the signal under test at the second target signal output point are equal. If they are equal, it means that the counterexample generated at the initial output point of the signal under test is not a valid counterexample. Therefore, it can be determined that the second equivalence verification result of the initial output point of the signal under test indicates that the initial output point of the signal under test is equivalent to the initial reference signal output point. If they are not equal, there is still a possibility that the position of the cutoff point or logical equivalence point is unreasonable. Therefore, the next first verification node of the first target signal output point can be updated to the first target signal output point of the next iteration cycle, and the next second verification node of the second target signal output point can be updated to the second target signal output point of the next iteration cycle, until there are no next first verification node and next second verification node.
[0064] Optionally, when the verification node is not an RTL output port, the verification node update process can be achieved by unmapping the first target signal output point and the second target signal output point in the current iteration cycle. This method prevents the first and second target signal output points in the current iteration cycle from serving as verification nodes; therefore, equivalence verification is still based on adjacent verification nodes. Furthermore, the unmapping process can be automated, for example, using a script. Compared to manual unmapping, automation further improves the verification efficiency of anomaly-driven new features.
[0065] Meanwhile, after demapping the first target signal output point and the second target signal output point in each iteration cycle, the logical paths formed by the demapping first target signal output point and the second target signal output point can be stored as files to avoid repeated verification when re-verifying the RTL under test in the future, thereby further improving the verification efficiency.
[0066] Step S334: In response to the fact that the output value of the signal to be tested is not equal to the output value of the reference signal in the last iteration cycle, the second equivalence verification result is determined to characterize that the initial output point of the signal to be tested is not equivalent to the initial output point of the reference signal.
[0067] In the last iteration cycle, the first target signal output point is updated to the output port of the RTL under test, and the second target signal output point is updated to the output port of the reference RTL. If the new feature drives the functional logic between the initial input point of the signal under test and the corresponding first signal input point, then the signal output values of all logic paths, including that logic path, will be affected by the new feature and will not be equal to the signal output value of the second signal output point. Therefore, if the output value of the signal under test and the output value of the reference signal are still not equal in the last iteration cycle, it can be determined that the second equivalence result of the initial output point of the signal under test indicates that the initial output point of the signal under test is not equivalent to the initial output point of the reference signal.
[0068] Figure 6 This is a schematic diagram illustrating the process of determining the second equivalence verification result of the verification node in an embodiment of the present invention. For example... Figure 6 As shown, if the first signal input point is the cutoff point P51, the second signal input point is the cutoff point P51', the first signal output point is the cutoff point P52, and the second signal output point is the cutoff point P52', that is, the logic path in the RTL under test is R51, the logic path in the reference RTL is R51', and the first signal output value of the cutoff point P52 is not equal to the second signal output value of the cutoff point P52', then the cutoff point P52 can be determined as the initial output point of the signal under test, and the cutoff point P52' can be determined as the initial output point of the reference signal. Then, the next first verification node after the initial output point of the signal under test, i.e., the cutoff point P53, can be determined as the first target signal output point of the first iteration cycle. Simultaneously, the next second verification node after the initial reference signal output point, i.e., the cutoff point P53', can be determined as the second target signal output point of the first iteration cycle. This means updating the logic path in the RTL under test to R52 and the logic path in the reference RTL to R52', and determining whether the output value of the signal under test in logic path R52 is equal to the output value of the reference signal in logic path R52'. If they are equal, the second equivalence verification result of the cutoff point P51 can be determined as equivalent to the cutoff point P52 and the cutoff point P52'. If they are not equal, the next first verification node after the first target signal output point, i.e., output port 52, can be determined as the first target signal output point of the second iteration cycle. Simultaneously, the next second verification node after the second target signal output point, i.e., output port 52', can be determined as the second target signal output point of the second iteration cycle. This means updating the logic path in the RTL under test to R53 and the logic path in the reference RTL to R53', and determining whether the output value of the signal under test in logic path R53 is equal to the reference signal output value in logic path R53'. If they are equal, the second equivalence verification result of truncation point P51 can be determined as truncation point P52 and truncation point P52' being equivalent. If they are still not equal, the second equivalence verification result of truncation point P52 can be determined as truncation point P52 and truncation point P52' being inequivalent.
[0069] Optionally, if the first signal output value is not equal to the second signal output value, the verification data can be fed back to the designer or verification personnel for manual verification, so as to determine the second equivalence verification result of the first signal output point manually.
[0070] In another optional implementation of this embodiment, if the RTL only includes combinational logic and does not include sequential logic, the first signal input point and the second signal input point can be the input ports of the corresponding RTL, and the first signal output point and the second signal output point can be the output ports of the corresponding RTL. Therefore, if the first signal output value of the first signal output point is not equal to the second signal output value of the second signal output point, it can be determined that the second equivalence verification result of the first signal output point indicates that the first signal output point and the second signal output point are not equivalent; conversely, it can be determined that the second equivalence verification result of the first signal output point indicates that the first signal output point and the second signal output point are equivalent.
[0071] Step S340: Determine the first equivalence verification result based on the second equivalence verification result.
[0072] In this step, if the second equivalence result of at least one first signal output point indicates that the first signal output point and the corresponding second signal output point are not equivalent, it can be determined that the first equivalence verification result of the RTL under test indicates that the RTL under test and the reference RTL are not equivalent; if the second equivalence result of each first signal output point indicates that the first signal output point and the corresponding second signal output point are equivalent, it can be determined that the first equivalence verification result of the RTL under test indicates that the RTL under test and the reference RTL are equivalent.
[0073] Step S400: Determine the abnormal driving state of the newly added feature based on the first equivalence verification result.
[0074] In this step, if the first equivalence verification result of the RTL under test indicates that the RTL under test is not equivalent to the reference RTL, then the abnormal driving state of the newly added feature indicates that the newly added feature drives the functional logic of the RTL under test; otherwise, the abnormal driving state of the newly added feature indicates that the newly added feature does not drive the functional logic of the RTL under test.
[0075] Furthermore, if the second equivalence verification result of each initial test signal output point is determined using the method described in steps S331 to S334 in this embodiment, and there is at least one second equivalence verification result of the initial test signal output point indicating that the initial test signal output point is not equivalent to the corresponding initial reference signal output point, then it can be determined that the abnormal driving position of the newly added feature is located between the test signal output point and the corresponding first signal input point.
[0076] by Figure 6Taking the diagram shown as an example, if the second equivalence verification result of the cutoff point P52 indicates that the cutoff point P52 and the cutoff point P52' are not equivalent, then it can be determined that the abnormal driving position of the new feature is located between the cutoff point P51 and the cutoff point P52, that is, the functional logic of the new feature driving logic L51.
[0077] This invention eliminates the need for additional verification logic. Anomaly-driven detection of new features can be achieved through the equivalence verification principle, improving accuracy while significantly reducing development costs. Furthermore, by setting adjacent verification nodes in the RTL, including cutoff points or logical equivalence points, as signal input and output points respectively, anomaly-driven detection of new features can comprehensively cover the RTL. When the signal output value of any signal output point in the RTL under test differs from the corresponding signal output value in the reference RTL, each downstream verification node of that signal output point is verified iteratively. This effectively reduces the negative impact of invalid counterexamples on anomaly-driven detection of new features, thus significantly improving the accuracy and completeness of anomaly-driven detection.
[0078] This invention, in its embodiments, obtains the register transfer stage under test (UTP) after inserting a new feature into the reference register transfer stage. It then identifies a verification node combination between the verification node in the UTP and a corresponding verification node in the reference register transfer stage. Using the verification node in the reference register transfer stage as a benchmark, it performs equivalence verification on the verification nodes in the UTP based on the newly added feature. Based on the equivalence verification result, it determines whether the new feature drives the functional logic of the UTP. This invention determines the signal input value of the verification node based on the new feature, thereby enabling abnormal drive detection of the new feature based on equivalence verification, thus improving the accuracy of abnormal drive detection.
[0079] Figure 7 This is a schematic diagram of a verification device for the register transfer level according to an embodiment of the present invention. Figure 7 As shown, the register transfer level verification device of this embodiment includes an acquisition unit 701, a combination determination unit 702, a verification unit 703, and a status determination unit 704.
[0080] The acquisition unit 701 is used to acquire the register transfer stage under test, which is a reference register transfer stage driving a new feature, and the new feature includes a debug identifier; the combination determination unit 702 is used to determine a verification node combination, which includes a first verification node and a second verification node, where the first verification node is a verification node in the register transfer stage under test, and the second verification node is a verification node in the reference register transfer stage, and there is a mapping relationship between the first verification node and the second verification node; the verification unit 703 is used to perform equivalence verification on the first verification node based on the second verification node and according to the new feature, and determine a first equivalence verification result of the register transfer stage under test, which is used to characterize whether the register transfer stage under test is equivalent to the reference register transfer stage; the state determination unit 704 is used to determine the abnormal driving state of the new feature according to the first equivalence verification result, which is used to characterize whether the new feature drives the functional logic of the register transfer stage under test.
[0081] This invention, in its embodiments, obtains the register transfer stage under test (UTP) after inserting a new feature into the reference register transfer stage. It then identifies a verification node combination between the verification node in the UTP and a corresponding verification node in the reference register transfer stage. Using the verification node in the reference register transfer stage as a benchmark, it performs equivalence verification on the verification nodes in the UTP based on the newly added feature. Based on the equivalence verification result, it determines whether the new feature drives the functional logic of the UTP. This invention determines the signal input value of the verification node based on the new feature, thereby enabling abnormal drive detection of the new feature based on equivalence verification, thus improving the accuracy of abnormal drive detection.
[0082] Figure 8 This is a schematic diagram of an electronic device according to an embodiment of the present invention. In this embodiment, the electronic device 8 includes a server, a terminal, etc. Figure 8 As shown, the electronic device 8 includes at least one processor 801; a memory 802 communicatively connected to at least one processor 801; and a communication component 803 communicatively connected to a scanning device, wherein the communication component 803 receives and transmits data under the control of the processor 801; wherein the memory 802 stores instructions executable by at least one processor 801, the instructions being executed by at least one processor 801 to implement the aforementioned register transfer level verification method.
[0083] Specifically, the electronic device includes: one or more processors 801 and a memory 802. Figure 8Taking a processor 801 as an example, the processor 801 and the memory 802 can be connected via a bus or other means. Figure 8 Taking a bus connection as an example, memory 802, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Processor 801 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions, and modules stored in memory 802, thus implementing the aforementioned register transfer level verification method.
[0084] Memory 802 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and applications required for at least one function; the data storage area may store an option list, etc. Furthermore, memory 802 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some embodiments, memory 802 may optionally include memory remotely located relative to processor 801, and these remote memories can be connected to external devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0085] One or more modules are stored in memory 802, and when executed by one or more processors 801, they perform the register transfer level verification method in any of the above method embodiments.
[0086] The above-mentioned products can perform the methods provided in the embodiments of this application, and have the corresponding functional modules and beneficial effects of performing the methods. For technical details not described in detail in this embodiment, please refer to the methods provided in the embodiments of this application.
[0087] This invention, in its embodiments, obtains the register transfer stage under test (UTP) after inserting a new feature into the reference register transfer stage. It then identifies a verification node combination between the verification node in the UTP and a corresponding verification node in the reference register transfer stage. Using the verification node in the reference register transfer stage as a benchmark, it performs equivalence verification on the verification nodes in the UTP based on the newly added feature. Based on the equivalence verification result, it determines whether the new feature drives the functional logic of the UTP. This invention determines the signal input value of the verification node based on the new feature, thereby enabling abnormal drive detection of the new feature based on equivalence verification, thus improving the accuracy of abnormal drive detection.
[0088] Another embodiment of the present invention relates to a non-volatile storage medium for storing a computer-readable program for use by a computer to execute some or all of the above-described method embodiments.
[0089] That is, those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0090] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A verification method at the register-transfer level, characterized in that, The method includes: Obtain the register transfer level under test, wherein the register transfer level under test is a reference register transfer level into which new features are inserted, and the new features include debug identifiers; A verification node combination is determined, the verification node combination includes a first verification node and a second verification node, the first verification node is a verification node in the register transfer stage under test, the second verification node is a verification node in the reference register transfer stage, and there is a mapping relationship between the first verification node and the second verification node; Using the second verification node as a benchmark, the first verification node is subjected to equivalence verification according to the new feature to determine the first equivalence verification result of the register transfer stage under test. The first equivalence verification result is used to characterize whether the register transfer stage under test is equivalent to the reference register transfer stage. The abnormal driving state of the newly added feature is determined based on the first equivalence verification result. The abnormal driving state is used to characterize whether the newly added feature drives the functional logic of the register transfer stage under test.
2. The method according to claim 1, characterized in that, The first verification node includes a first signal input point and a first signal output point, and the second verification node includes a second signal input point and a second signal output point. The first signal input point and the second signal input point are mapped to each other, and the first signal output point and the second signal output point are also mapped to each other. The step of using the second verification node as a benchmark and performing equivalence verification on the first verification node based on the newly added features to determine the first equivalence verification result of the register transfer level under test includes: Determine the signal input values of the first signal input point and the second signal input point based on the newly added characteristics; Determine the first signal output value of the first signal output point and the second signal output value of the second signal output point based on the signal input value; A second equivalence verification result is determined based on the first signal output value and the second signal output value. The second equivalence verification result is used to characterize whether the first signal output point and the second signal output point are equivalent. The first equivalence verification result is determined based on the second equivalence verification result.
3. The method according to claim 2, characterized in that, The first signal input point and the second signal input point are input ports of the corresponding register transfer stage, and the first signal output point and the second signal output point are truncation points or logical equivalent points of the corresponding register transfer stage; or The first signal input point and the second signal input point are truncation points or logical equivalent points of the corresponding register transfer stage, and the first signal output point and the second signal output point are truncation points or logical equivalent points of the corresponding register transfer stage; or The first signal input point and the second signal input point are the cutoff points or logical equivalent points of the corresponding register transfer stage, and the first signal output point and the second signal output point are the output ports of the corresponding register transfer stage.
4. The method according to claim 2, characterized in that, The first signal input point is adjacent to the first signal output point, and the second signal input point is adjacent to the second signal output point; The second equivalence verification result for determining the first signal output point based on the first signal output value and the second signal output value includes: In response to the first signal output value not being equal to the corresponding second signal output value, the first signal output point corresponding to the first signal output value is determined as the initial signal output point to be measured; The second signal output point corresponding to the second signal output value is determined as the initial reference signal output point; The equivalence of the output value of the test signal of the first verification node downstream of the initial test signal output point is verified iteratively based on the reference signal output value of the second verification node downstream of the initial reference signal output point. In response to the fact that the output value of the signal under test in the last iteration cycle is not equal to the output value of the reference signal, the second equivalence verification result is determined to characterize that the initial output point of the signal under test is not equivalent to the initial output point of the reference signal. The step of iteratively verifying the equivalence of the output value of the test signal of the first verification node downstream of the initial test signal output point based on the reference signal output value of the second verification node downstream of the initial reference signal output point includes: The next first verification node of the initial test signal output point is determined as the first target signal output point of the first iteration cycle, and the next second verification node of the initial reference signal output point is determined as the second target signal output point of the first iteration cycle. In each iteration cycle, it is determined whether the test signal output value of the first target signal output point is equal to the reference signal output value of the second target signal output point. In response to the test signal output value not being equal to the reference signal output value, the next first verification node of the first target signal output point is updated to the first target signal output point of the next iteration cycle, and the next second verification node of the second target signal output point is updated to the second target signal output point of the next iteration cycle, until there is no next first verification node and no next second verification node.
5. The method according to claim 2, characterized in that, The second equivalence verification result for determining the first signal output point based on the first signal output value and the second signal output value includes: In response to the first signal output value being equal to the second signal output value, the second equivalence verification result is determined to characterize the first signal output point as equivalent to the second signal output point.
6. The method according to claim 4, characterized in that, The method further includes: In response to the second equivalence verification result indicating that the initial test signal output point and the initial reference signal output point are not equivalent, it is determined that the abnormal driving position of the newly added feature is located between the test signal output point and the corresponding first signal input point.
7. The method according to claim 2, characterized in that, The first signal input point and the second signal input point are the input ports of the corresponding register transfer stage, and the first signal output point and the second signal output point are the output ports of the corresponding register transfer stage; The second equivalence verification result for determining the first signal output point based on the first signal output value and the second signal output value includes: In response to the fact that the first signal output value and the second signal output value are not equal, the second equivalence verification result is determined to indicate that the first signal output point and the second signal output point are not equivalent; In response to the first signal output value being equal to the second signal output value, the second equivalence verification result is determined to characterize the first signal output point as equivalent to the second signal output point.
8. The method according to claim 2, characterized in that, Determining the first equivalence verification result based on the second equivalence verification result includes: In response to at least one of the second equivalence verification results indicating that the first signal output point and the second signal output point are not equivalent, it is determined that the first equivalence verification result indicates that the transfer stage of the register under test and the transfer stage of the reference register are not equivalent; In response to each of the second equivalence verification results indicating that the first signal output point and the second signal output point are equivalent, it is determined that the first equivalence verification result indicates that the transfer stage of the register under test is equivalent to the transfer stage of the reference register.
9. The method according to claim 1, characterized in that, The step of determining the abnormal driving state of the newly added feature based on the first equivalence verification result includes: In response to the first equivalence verification result indicating that the transfer stage of the register under test is not equivalent to the transfer stage of the reference register, the abnormal driving state is determined to indicate that the new feature drives the functional logic; In response to the first equivalence verification result indicating that the transfer stage of the register under test is equivalent to the transfer stage of the reference register, the abnormal driving state is determined to indicate that the new feature does not drive the functional logic.
10. A verification device at the register transfer level, characterized in that, The device includes: An acquisition unit is used to acquire the register transfer stage under test, wherein the register transfer stage under test is a reference register transfer stage with inserted new features, and the new features include a debug identifier. A combination determination unit is used to determine a combination of verification nodes, wherein the combination of verification nodes includes a first verification node and a second verification node, the first verification node is a verification node in the register transfer stage under test, the second verification node is a verification node in the reference register transfer stage, and there is a mapping relationship between the first verification node and the second verification node. The verification unit is used to perform equivalence verification on the first verification node based on the second verification node and the newly added features, and to determine the first equivalence verification result of the register transfer stage under test. The first equivalence verification result is used to characterize whether the register transfer stage under test is equivalent to the reference register transfer stage. The state determination unit is used to determine the abnormal driving state of the newly added feature based on the first equivalence verification result. The abnormal driving state is used to characterize whether the newly added feature drives the functional logic of the register transfer stage under test.
11. An electronic device comprising a memory and a processor, characterized in that, The memory is used to store one or more computer program instructions, wherein the one or more computer program instructions are executed by the processor to implement the method as described in any one of claims 1-9.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1-9.
13. A computer program product, characterized in that, The computer program product includes a computer program / instruction that, when executed by a processor, implements the method as described in any one of claims 1-9.