Chip firmware positioning analysis method, system, device and electronic equipment

The chip magnetic field image is analyzed by diamond nitrogen vacancy color center sensor, which solves the stability and reliability problems of the existing chip firmware extraction methods, realizes lossless chip firmware positioning and register positioning, and improves analysis accuracy.

CN114487509BActive Publication Date: 2025-08-12INST OF MICROELECTRONICS CHINESE ACAD OF SCI LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210125483.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-10
Publication Date
2025-08-12
Estimated Expiration
2042-02-10

AI Technical Summary

Technical Problem

The existing chip firmware extraction methods have low stability and reliability, software methods increase the difficulty of analysis and cannot locate vulnerabilities, and hardware methods require dismantling the chip, resulting in high destructiveness and operation is susceptible to errors.

Method used

The diamond nitrogen vacancy color center sensor is used to analyze the depth distribution of the wires in the chip and the flow direction of the configuration information flow through magnetic field image data to realize the lossless positioning of the registers in the chip firmware.

Benefits of technology

It improves the accuracy and reliability of chip firmware positioning analysis, avoids chip damage, and realizes lossless monitoring of integrated circuits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114487509B_ABST
    Figure CN114487509B_ABST
Patent Text Reader

Abstract

The present invention discloses a chip firmware positioning and analysis method, system, device, and electronic device, relating to the field of chip technology. The method includes: traversing all input interfaces, and repeatedly determining the magnetic field image data of the chip firmware under test corresponding to each input interface when it is a target input interface under normal working condition; based on the multiple magnetic field image data, determining the depth distribution data of different wires at the same position in the chip under test; based on the depth distribution data of different wires at the same position in the chip under test, determining the flow direction of the configuration information flow of the chip firmware under test; scanning the chip under test based on a diamond nitrogen vacancy color center sensor, and completing the positioning analysis of the chip firmware under test based on the analysis of the flow direction of the configuration information flow. The method can achieve positioning of registers within the chip under test without damaging the chip under test, thereby improving the accuracy and reliability of the firmware positioning analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of chip technology, and in particular to a chip firmware positioning and analysis method, system, device and electronic equipment. Background Art

[0002] Chips are deployed in countless applications, from industrial systems and automotive control units to end-user devices. As chip performance steadily increases, the complexity of chip tasks also increases. Consequently, chip firmware has become more complex, harboring subtle vulnerabilities. Therefore, extracting and analyzing chip firmware is a crucial step in chip security analysis.

[0003] Currently, firmware extraction primarily involves software and using a programmer to read the firmware. Software methods typically involve accessing the device manufacturer's website or FTP site to obtain publicly available firmware, or following a link to directly download firmware updates and analyzing the device's network traffic to obtain the firmware. Software methods can also utilize software like Binwalk, which can quickly extract firmware images. Current hardware-based firmware extraction methods use a programmer to extract the firmware. This first requires disassembling the chip, identifying the flash memory chip, then soldering the flash memory chip to a programming socket, and then reading the firmware offline.

[0004] However, in the above software method, software delays will increase the difficulty of analysis and testing, any form of randomization will lead to an increase in iteration time, resulting in an increase in acquisition time, and software extraction of firmware can only detect whether there are vulnerabilities in the firmware, but cannot locate the location of the vulnerability. The above-mentioned use of a programmer to read the firmware to disassemble, extract and analyze the firmware is somewhat destructive and cannot locate the firmware information to the physical location of a specific configuration register; and there are many manual operation links, the test results are easily affected by operational errors, and it is difficult to find the cause of the error. The above defects result in low stability and reliability of existing firmware extraction methods. Summary of the Invention

[0005] The object of the present invention is to provide a chip firmware location analysis method, system, device and electronic device to solve the problem of low stability and reliability of existing firmware extraction methods.

[0006] In a first aspect, the present invention provides a chip firmware positioning and analysis method, which is applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces. The method comprises:

[0007] When the chip under test is set to an initial state, controlling the plurality of input interfaces to have one target input interface under test in a normal working state at a time;

[0008] Traversing all the input interfaces, and determining multiple times the magnetic field image data of the firmware of the chip under test corresponding to each input interface being the target input interface under test in a normal working state;

[0009] Determining depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data;

[0010] Determining a flow direction of configuration information flow of the chip under test firmware based on the depth distribution data of different wires at the same position in the chip under test and combining the magnetic field image data of two adjacent times;

[0011] The chip to be tested is scanned based on the diamond nitrogen vacancy color center sensor, and positioning analysis of the firmware of the chip to be tested is completed based on the flow direction of the analysis configuration information flow.

[0012] Under the condition of adopting the above-mentioned technical scheme, the chip firmware positioning and analysis method provided in the embodiment of the present application can control the existence of a target input interface to be tested in a normal working state at a time among the multiple input interfaces when the chip to be tested is set to an initial state; traverse all the input interfaces, and determine the magnetic field image data of the chip to be tested firmware corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times; determine the depth distribution data of different wires at the same position in the chip to be tested based on the multiple magnetic field image data; based on the depth distribution data of different wires at the same position in the chip to be tested, combine the magnetic field image data of two adjacent times. , determine the flow direction of the configuration information flow of the firmware of the chip to be tested; scan the chip to be tested based on the diamond nitrogen vacancy color center sensor, that is, the transient behavior can be monitored through continuous testing of the magnetic field, and the entire chip to be tested can be scanned at the same time, avoiding the influence of changes in working status at different times on the test results, improving the accuracy of chip firmware monitoring, and completing the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow. Without damaging the chip to be tested, the registers in the chip to be tested can be positioned based on the hardware method, thereby ensuring the integrity of the chip, realizing non-destructive monitoring of the integrated circuit, and improving the accuracy and reliability of firmware positioning analysis.

[0013] In a possible implementation, traversing all the input interfaces and determining the magnetic field image data corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times includes:

[0014] When traversing all the input interfaces and determining multiple times that each input interface is the target input interface to be tested in a normal working state, each position of the chip to be tested is continuously flipped, the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field image data of the sensor's magnetic field changes with the flipping.

[0015] In a possible implementation, determining the depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data includes:

[0016] Based on the plurality of magnetic field image data and in combination with the vector magnetic field image data, the vertical positioning of the register configured in the chip firmware is analyzed to determine the depth distribution data of different wires at the same position in the chip to be tested.

[0017] In one possible implementation, scanning the chip under test based on the diamond nitrogen vacancy color center sensor and completing the positioning analysis of the firmware of the chip under test based on the flow direction of the analysis configuration information flow includes:

[0018] The chip under test is scanned based on the diamond nitrogen vacancy color center sensor, and the configuration information of multiple registers in the chip under test is located and analyzed by the firmware of the chip under test based on the flow direction of the configuration information flow.

[0019] In a second aspect, the present invention further provides a chip firmware positioning and analysis system, the system comprising a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor;

[0020] When the chip to be tested is set to an initial state, control is performed so that there is a target input interface to be tested in a normal working state at a time among the multiple input interfaces; traverse all the input interfaces, and determine the magnetic field image data of the firmware of the chip to be tested corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times; based on the multiple magnetic field image data, determine the depth distribution data of different wires at the same position in the chip to be tested; based on the depth distribution data of different wires at the same position in the chip to be tested, combined with the magnetic field image data of two adjacent times, determine the flow direction of the configuration information flow of the firmware of the chip to be tested; scan the chip to be tested based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow.

[0021] The beneficial effects of the chip firmware positioning and analysis system provided in the second aspect are the same as the beneficial effects of the chip firmware positioning and analysis method described in the first aspect or any possible implementation of the first aspect, and are not repeated here.

[0022] In a third aspect, the present invention provides a chip firmware positioning and analysis device, which is applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces. The device includes:

[0023] a control module, configured to control, when the chip under test is set to an initial state, to ensure that one target input interface under test is in a normal working state at a time among the plurality of input interfaces;

[0024] A first determining module is configured to traverse all the input interfaces and determine, multiple times, the magnetic field image data of the firmware of the chip under test corresponding to each input interface being the target input interface under test in a normal working state;

[0025] A second determining module is configured to determine depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data;

[0026] a third determining module, configured to determine a flow direction of a configuration information flow of the firmware of the chip under test based on the depth distribution data of different wires at the same position in the chip under test and in combination with two adjacent magnetic field image data;

[0027] A positioning analysis module is used to scan the chip to be tested based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the firmware of the chip to be tested based on the flow direction of the analysis configuration information flow.

[0028] In a possible implementation, the first determining module includes:

[0029] The first determination submodule is used to traverse all the input interfaces and determine multiple times that each input interface is the target input interface to be tested in a normal working state. Each position of the chip to be tested is continuously flipped, and the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field image data of the sensor's magnetic field changes with the flipping.

[0030] In a possible implementation, the second determining module includes:

[0031] The second determination submodule is used to analyze the vertical positioning of the registers configured in the chip firmware based on the multiple magnetic field image data and in combination with the vector magnetic field image data, and determine the depth distribution data of different wires at the same position in the chip to be tested.

[0032] In a possible implementation, the positioning analysis module includes:

[0033] The positioning analysis submodule is used to scan the chip under test based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the configuration information of the multiple registers in the chip under test by the firmware of the chip under test based on the flow direction of the configuration information flow.

[0034] The beneficial effects of the chip firmware positioning and analysis device provided in the third aspect are the same as the beneficial effects of the chip firmware positioning and analysis method described in the first aspect or any possible implementation of the first aspect, and are not repeated here.

[0035] In a fourth aspect, the present invention also provides an electronic device comprising: one or more processors; and one or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, enables the device to perform the chip firmware positioning and analysis method described in any possible implementation of the first aspect.

[0036] The beneficial effects of the electronic device provided in the fourth aspect are the same as the beneficial effects of the chip firmware positioning and analysis method described in the first aspect or any possible implementation of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:

[0038] Figure 1 A schematic diagram of a chip firmware location analysis method provided in an embodiment of the present application is shown;

[0039] Figure 2 A schematic diagram of a process flow of another chip firmware location analysis method provided by an embodiment of the present application is shown;

[0040] Figure 3 A chip firmware configuration flow chart provided in an embodiment of the present application is shown;

[0041] Figure 4 A schematic diagram of the structure of a chip firmware positioning and analysis device provided in an embodiment of the present application is shown;

[0042] Figure 5 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention;

[0043] Figure 6 A schematic diagram of the structure of a chip provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0044] To facilitate a clear description of the technical solutions of the embodiments of the present invention, the words "first" and "second" are used in the embodiments of the present invention to distinguish between identical or similar items with substantially the same functions and effects. For example, the first threshold and the second threshold are merely used to distinguish between different thresholds and do not limit their order. Those skilled in the art will understand that the words "first" and "second" do not limit the quantity or execution order, and the words "first" and "second" do not necessarily mean different.

[0045] It should be noted that, in the present invention, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the present invention should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0046] In the present invention, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can represent: a, b, c, the combination of a and b, the combination of a and c, the combination of b and c, or the combination of a, b and c, where a, b, c can be single or multiple.

[0047] Figure 1 The flowchart of a chip firmware positioning and analysis method provided by an embodiment of the present application is shown, which is applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested arranged on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces, such as Figure 1 As shown, the method for locating and analyzing the firmware of the chip to be tested includes:

[0048] Step 101: When the chip to be tested is set to an initial state, control the plurality of input interfaces to have one target input interface to be tested in a normal working state at a time.

[0049] In this application, an all-optical non-destructive microwave field distribution imaging system, also known as the chip firmware positioning and analysis system in this application, can be used to fabricate a magnetic field sensor using diamond nitrogen vacancy color centers, that is, to fabricate the diamond nitrogen vacancy color center sensor. The magnetic field sensor includes a diamond substrate having a nitrogen vacancy (NV) center surface layer. The diamond can be directly placed on the chip to be tested, with the NV center surface layer in contact with the surface of the chip to be tested. The NV center surface layer can be optically addressed using a continuous laser beam with a certain value. For example, the NV center surface layer can be optically addressed using a 532 nanometer (nm) continuous laser beam. The beam power can be approximately 500 milliwatts (mW) and evenly distributed over the NV center surface layer. The system can also include a flat-top beam shaping element and a cylindrical lens. A flat-top beam shaping element and a cylindrical lens can be used to form a rectangular beam profile so that a sufficiently shallow angle of incidence relative to the top diamond surface can be incident on the diamond substrate surface to illuminate the entire NV center surface layer. The system can use a low-magnification objective to capture NV fluorescence from the surface of the NV center, filter it with a long-pass filter, and then image it on a complementary metal oxide semiconductor (CMOS) camera to create a snapshot. A camera with sufficiently high temporal resolution can be selected to better record magnetic field changes during chip power-up.

[0050] It should be noted that the diamond NV color center can sense the magnetic field strength on the surface of the chip to be tested, provide a resolution of up to nanometers, and has the advantages of stable fluorescence and little interference with the near field. It is an advantageous means of detecting chips based on magnetic fields.

[0051] In this application, the diamond nitrogen vacancy color center sensor can be placed on the surface of the chip to be tested, and the chip to be tested can be connected to the power supply, signal generator and other devices in the chip firmware positioning and analysis system to ensure that the chip to be tested can work normally when the system power is turned on.

[0052] Before the chip to be tested works normally, the chip to be tested is set to an initial state. During the test, the chip state of the chip to be tested is controlled. During each test, there is a target input interface to be tested that is in a normal working state, that is, the target input interface to be tested is assigned a value each time the test is performed, so that during each test run, the chip firmware only executes a small part of the instructions corresponding to the target input interface to be tested.

[0053] When the chip under test is set to an initial state, step 102 is executed after controlling that there is one target input interface under test in a normal working state among the plurality of input interfaces at a time.

[0054] Step 102: traverse all the input interfaces, and determine multiple times the magnetic field image data of the chip firmware to be tested corresponding to each input interface being the target input interface to be tested in a normal working state.

[0055] In the present application, all the input interfaces can be traversed, and when each of the input interfaces is determined to be the target input interface to be tested in a normal working state multiple times, each position of the chip to be tested is continuously flipped, and the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field of the sensor changes with the flipping to obtain magnetic field image data.

[0056] Before each chip firmware execution begins, the system can be reset to an initial state, and the entire chip under test can be traversed through multiple firmware execution processes.

[0057] Specifically, during the process of continuous restart and power-on, each position of the chip under test is constantly flipped, the configuration of the chip firmware changes, and the magnetic field also changes accordingly. The CMOS camera in the system can be used to continuously capture the magnetic field image of the chip under test when it is working normally, that is, to determine the magnetic field image data.

[0058] After traversing all the input interfaces and determining the magnetic field image data of the chip firmware to be tested corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times, step 103 is executed.

[0059] Step 103: Determine depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data.

[0060] In the present application, the current density source is located at different depths of the chip to be tested. By comparing the changes in the playground image data at the same position before and after the firmware is flipped, the vertical positioning of the registers configured by the firmware can be analyzed. Specifically, based on multiple magnetic field image data and combined with vector magnetic field image data, the vertical positioning of the registers configured in the chip firmware can be analyzed to determine the depth distribution data of different wires at the same position in the chip to be tested.

[0061] After the depth distribution data of different wires at the same position in the chip to be tested are determined based on the plurality of magnetic field image data, step 104 is executed.

[0062] Step 104: Based on the depth distribution data of different wires at the same position in the chip under test and in combination with the magnetic field image data of two adjacent times, determine the flow direction of the configuration information flow of the firmware of the chip under test.

[0063] In this application, the high time resolution characteristics of the CMOS camera in the system can be used to compare the two magnetic field image data corresponding to the two adjacent power-on magnetic field images captured, and the flow direction of the chip firmware configuration information flow can be analyzed and determined.

[0064] After determining the flow direction of the configuration information flow of the chip under test firmware based on the depth distribution data of different wires at the same position in the chip under test and combining the two adjacent magnetic field image data, step 105 is executed.

[0065] Step 105: Scan the chip under test based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the firmware of the chip under test based on the flow direction of the analyzed configuration information flow.

[0066] Specifically, the chip to be tested can be scanned based on the diamond nitrogen vacancy color center sensor, and the positioning analysis of the configuration information of multiple registers in the chip to be tested by the firmware of the chip to be tested can be completed based on the analysis of the flow direction of the configuration information flow. This can realize dynamic analysis of the position information of the firmware configuration register, which is conducive to the association analysis of the firmware configuration information with related functional modules.

[0067] In the present application, an all-optical non-destructive microwave field distribution imaging system can be used to make a magnetic field sensor using a diamond nitrogen vacancy color center, that is, to make the diamond nitrogen vacancy color center sensor, scan the chip to be tested set on the sensor, and observe the magnetic field strength. Furthermore, based on the magnetic field strength analysis, the chip firmware analyzes the configuration information of the registers in the chip, and the chip can be retrieved without damaging the integrity of the chip. This synchronous magnetic field method is not affected by reconstruction errors and scanning probe offsets.

[0068] In summary, the chip firmware positioning and analysis method provided in the embodiment of the present application can, when the chip to be tested is set to an initial state, control the presence of a target input interface to be tested in a normal working state at a time among the multiple input interfaces; traverse all the input interfaces, and determine the magnetic field image data of the chip to be tested firmware corresponding to each input interface being the target input interface to be tested in a normal working state multiple times; determine the depth distribution data of different wires at the same position in the chip to be tested based on the multiple magnetic field image data; determine the depth distribution data of different wires at the same position in the chip to be tested based on the depth distribution data of different wires at the same position in the chip to be tested, combined with the magnetic field image data of two adjacent times. The flow direction of the configuration information flow of the firmware of the chip to be tested is analyzed; the chip to be tested is scanned based on the diamond nitrogen vacancy color center sensor, that is, the transient behavior can be monitored through continuous testing of the magnetic field, and the entire chip to be tested can be scanned at the same time, avoiding the influence of changes in working status at different times on the test results, improving the accuracy of chip firmware monitoring, and completing the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow. Without damaging the chip to be tested, the registers in the chip to be tested can be positioned based on the hardware method, thereby ensuring the integrity of the chip, realizing non-destructive monitoring of the integrated circuit, and improving the accuracy and reliability of firmware positioning analysis.

[0069] Figure 2 A flow chart of another chip firmware positioning and analysis method provided in an embodiment of the present application is shown, which is applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces, such as Figure 2 As shown, the chip firmware positioning analysis method includes:

[0070] Step 201: When the chip to be tested is set to an initial state, control one target input interface to be tested in a normal working state at a time among the plurality of input interfaces.

[0071] In this application, an all-optical non-destructive microwave field distribution imaging system, also known as the chip firmware positioning and analysis system in this application, can be used to fabricate a magnetic field sensor using diamond nitrogen vacancy color centers, that is, to fabricate the diamond nitrogen vacancy color center sensor. The magnetic field sensor includes a diamond substrate having a nitrogen vacancy (NV) center surface layer. The diamond can be directly placed on the chip to be tested, with the NV center surface layer in contact with the surface of the chip to be tested. The NV center surface layer can be optically addressed using a continuous laser beam with a certain value. For example, the NV center surface layer can be optically addressed using a 532 nanometer (nm) continuous laser beam. The beam power can be approximately 500 milliwatts (mW) and evenly distributed over the NV center surface layer. The system can also include a flat-top beam shaping element and a cylindrical lens. A flat-top beam shaping element and a cylindrical lens can be used to form a rectangular beam profile so that a sufficiently shallow angle of incidence relative to the top diamond surface can be incident on the diamond substrate surface to illuminate the entire NV center surface layer. The system can use a low-magnification objective to capture NV fluorescence from the surface of the NV center, filter it with a long-pass filter, and then image it on a complementary metal oxide semiconductor (CMOS) camera to create a snapshot. A camera with sufficiently high temporal resolution can be selected to better record magnetic field changes during chip power-up.

[0072] It should be noted that the diamond NV color center can sense the magnetic field strength on the surface of the chip to be tested, provide a resolution of up to nanometers, and has the advantages of stable fluorescence and little interference with the near field. It is an advantageous means of detecting chips based on magnetic fields.

[0073] In this application, the diamond nitrogen vacancy color center sensor can be placed on the surface of the chip to be tested, and the chip to be tested can be connected to the power supply, signal generator and other devices in the chip firmware positioning and analysis system to ensure that the chip to be tested can work normally when the system power is turned on.

[0074] Before the chip to be tested works normally, the chip to be tested is set to an initial state. During the test, the chip state of the chip to be tested is controlled. During each test, there is a target input interface to be tested that is in a normal working state, that is, the target input interface to be tested is assigned a value each time the test is performed, so that during each test run, the chip firmware only executes a small part of the instructions corresponding to the target input interface to be tested.

[0075] When the chip under test is set to an initial state, step 202 is executed after controlling that there is one target input interface under test in a normal working state among the plurality of input interfaces at a time.

[0076] Step 202: When traversing all the input interfaces and determining that each input interface is the target input interface to be tested in a normal working state for multiple times, each position of the chip to be tested is continuously flipped, the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field of the sensor changes with the flipping to obtain magnetic field image data.

[0077] In the present application, all the input interfaces can be traversed, and when each of the input interfaces is determined to be the target input interface to be tested in a normal working state multiple times, each position of the chip to be tested is continuously flipped, and the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field of the sensor changes with the flipping to obtain magnetic field image data.

[0078] Before each chip firmware execution begins, the system can be reset to an initial state, and the entire chip under test can be traversed through multiple firmware execution processes.

[0079] Specifically, during the process of continuous restart and power-on, each position of the chip under test is constantly flipped, the configuration of the chip firmware changes, and the magnetic field also changes accordingly. The CMOS camera in the system can be used to continuously capture the magnetic field image of the chip under test when it is working normally, that is, to determine the magnetic field image data.

[0080] When traversing all the input interfaces and determining multiple times that each input interface is the target input interface to be tested in a normal working state, each position of the chip to be tested is continuously flipped, the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field of the sensor changes with the magnetic field image data of the flipping, step 203 is executed.

[0081] Step 203: Based on the plurality of magnetic field image data and in combination with the vector magnetic field image data, the vertical positioning of the register configured in the chip firmware is analyzed to determine the depth distribution data of different wires at the same position in the chip to be tested.

[0082] In the present application, the current density source is located at different depths of the chip to be tested. By comparing the changes in the playground image data at the same position before and after the firmware is flipped, the vertical positioning of the registers configured by the firmware can be analyzed. Specifically, based on multiple magnetic field image data and combined with vector magnetic field image data, the vertical positioning of the registers configured in the chip firmware can be analyzed to determine the depth distribution data of different wires at the same position in the chip to be tested.

[0083] After analyzing the vertical positioning of the registers configured in the chip firmware based on the plurality of magnetic field image data and in combination with the vector magnetic field image data to determine the depth distribution data of different wires at the same position in the chip under test, step 204 is executed.

[0084] Step 204: Based on the depth distribution data of different wires at the same position in the chip under test and in combination with the magnetic field image data of two adjacent times, determine the flow direction of the configuration information flow of the firmware of the chip under test.

[0085] In this application, the high time resolution characteristics of the CMOS camera in the system can be used to compare the two magnetic field image data corresponding to the two adjacent power-on magnetic field images captured, and the flow direction of the chip firmware configuration information flow can be analyzed and determined.

[0086] After determining the flow direction of the configuration information flow of the firmware of the chip under test based on the depth distribution data of different wires at the same position in the chip under test and combining the magnetic field image data of two adjacent times, step 205 is executed.

[0087] Step 205: Scan the chip under test based on the diamond nitrogen vacancy color center sensor, and complete positioning analysis of the configuration information of multiple registers in the chip under test by the firmware of the chip under test based on the flow direction of the configuration information flow.

[0088] Specifically, the chip to be tested can be scanned based on the diamond nitrogen vacancy color center sensor, and the positioning analysis of the configuration information of multiple registers in the chip to be tested by the firmware of the chip to be tested can be completed based on the analysis of the flow direction of the configuration information flow. This can realize dynamic analysis of the position information of the firmware configuration register, which is conducive to the association analysis of the firmware configuration information with related functional modules.

[0089] In the present application, an all-optical non-destructive microwave field distribution imaging system can be used to make a magnetic field sensor using a diamond nitrogen vacancy color center, that is, to make the diamond nitrogen vacancy color center sensor, scan the chip to be tested set on the sensor, and observe the magnetic field strength. Furthermore, based on the magnetic field strength analysis, the chip firmware analyzes the configuration information of the registers in the chip, and the chip can be retrieved without damaging the integrity of the chip. This synchronous magnetic field method is not affected by reconstruction errors and scanning probe offsets.

[0090] Figure 3A configuration flow chart of a chip firmware provided by an embodiment of the present application is shown. Taking the chip to be tested as an example, which includes four registers, when testing, the chip firmware execution line 1 can be controlled, and line 2 (register 5 and register 6) is in an inoperative state. The input signal flows from the input end to register 1, and then flows into register 2, register 3 and register 4 in sequence, and finally flows to the output end. Among them, when the signal in register 1 is flipped, the magnetic field intensity changes. At this time, the magnetic field intensity around the other registers does not change. The two magnetic field images at adjacent moments can be compared to locate the position of the register that is flipped. In completing a transmission cycle, the signal flows through 4 registers, and the position of the change in its magnetic field image changes with the direction of signal flow. Thus, the direction of information flow in the firmware configuration process can be analyzed, and the registers configured by the firmware can also be located.

[0091] In summary, the chip firmware positioning and analysis method provided in the embodiment of the present application can, when the chip to be tested is set to an initial state, control the presence of a target input interface to be tested in a normal working state at a time among the multiple input interfaces; traverse all the input interfaces, and determine the magnetic field image data of the chip to be tested firmware corresponding to each input interface being the target input interface to be tested in a normal working state multiple times; determine the depth distribution data of different wires at the same position in the chip to be tested based on the multiple magnetic field image data; determine the depth distribution data of different wires at the same position in the chip to be tested based on the depth distribution data of different wires at the same position in the chip to be tested, combined with the magnetic field image data of two adjacent times. The flow direction of the configuration information flow of the firmware of the chip to be tested is analyzed; the chip to be tested is scanned based on the diamond nitrogen vacancy color center sensor, that is, the transient behavior can be monitored through continuous testing of the magnetic field, and the entire chip to be tested can be scanned at the same time, avoiding the influence of changes in working status at different times on the test results, improving the accuracy of chip firmware monitoring, and completing the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow. Without damaging the chip to be tested, the registers in the chip to be tested can be positioned based on the hardware method, thereby ensuring the integrity of the chip, realizing non-destructive monitoring of the integrated circuit, and improving the accuracy and reliability of firmware positioning analysis.

[0092] The embodiment of the present application also provides a chip firmware positioning and analysis system, the system comprising a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor;

[0093] When the chip to be tested is set to an initial state, control the presence of a target input interface to be tested in a normal working state at a time among the multiple input interfaces; traverse all the input interfaces, and determine the magnetic field image data of the firmware of the chip to be tested corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times; determine the depth distribution data of different wires at the same position in the chip to be tested based on the multiple magnetic field image data; determine the configuration information flow of the firmware of the chip to be tested based on the depth distribution data of different wires at the same position in the chip to be tested and in combination with the magnetic field image data of two adjacent times. Flow direction; based on the diamond nitrogen vacancy color center sensor, the chip to be tested is scanned, that is, the transient behavior can be monitored through continuous testing of the magnetic field, and the entire chip to be tested can be scanned at the same time, avoiding the influence of changes in working status at different times on the test results, improving the accuracy of chip firmware monitoring, and completing the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow. Without damaging the chip to be tested, the registers in the chip to be tested can be positioned based on the hardware method, thereby ensuring the integrity of the chip, realizing non-destructive monitoring of the integrated circuit, and improving the accuracy and reliability of firmware positioning analysis.

[0094] Figure 4 The schematic diagram of the structure of a chip firmware positioning and analysis device provided by an embodiment of the present application is shown, which is applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested arranged on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces, such as Figure 4 As shown, the chip firmware positioning and analysis device 300 includes:

[0095] The control module 301 is configured to control, when the chip under test is set to an initial state, to have one target input interface under test in a normal working state at a time among the plurality of input interfaces;

[0096] A first determining module 302 is configured to traverse all the input interfaces and determine, multiple times, the magnetic field image data of the chip firmware under test corresponding to each input interface being the target input interface under test in a normal working state;

[0097] A second determining module 303 is configured to determine depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data;

[0098] A third determining module 304 is configured to determine a flow direction of the configuration information flow of the firmware of the chip under test based on the depth distribution data of different wires at the same position in the chip under test and in combination with two adjacent magnetic field image data;

[0099] The positioning analysis module 305 is configured to scan the chip under test based on the diamond nitrogen vacancy color center sensor and perform positioning analysis on the firmware of the chip under test based on the flow direction of the analyzed configuration information flow.

[0100] Optionally, the first determining module includes:

[0101] The first determination submodule is used to traverse all the input interfaces and determine multiple times that each input interface is the target input interface to be tested in a normal working state. Each position of the chip to be tested is continuously flipped, and the configuration parameters of the firmware of the chip to be tested change with the flipping, and the magnetic field image data of the sensor's magnetic field changes with the flipping.

[0102] Optionally, the second determining module includes:

[0103] The second determination submodule is used to analyze the vertical positioning of the registers configured in the chip firmware based on the multiple magnetic field image data and in combination with the vector magnetic field image data, and determine the depth distribution data of different wires at the same position in the chip to be tested.

[0104] Optionally, the positioning analysis module includes:

[0105] The positioning analysis submodule is used to scan the chip under test based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the configuration information of the multiple registers in the chip under test by the firmware of the chip under test based on the flow direction of the configuration information flow.

[0106] The chip firmware positioning and analysis device provided in the embodiment of the present application can control the existence of a target input interface to be tested in a normal working state at a time among the multiple input interfaces when the chip to be tested is set to an initial state; traverse all the input interfaces, and determine the magnetic field image data of the chip to be tested firmware corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times; determine the depth distribution data of different wires at the same position in the chip to be tested based on the multiple magnetic field image data; determine the depth distribution data of different wires at the same position in the chip to be tested based on the depth distribution data of different wires at the same position in the chip to be tested, combined with the magnetic field image data of two adjacent times. The flow direction of the configuration information flow of the chip firmware; based on the diamond nitrogen vacancy color center sensor, the chip to be tested is scanned, that is, the transient behavior can be monitored through continuous testing of the magnetic field, and the entire chip to be tested can be scanned at the same time, avoiding the influence of changes in working status at different times on the test results, improving the accuracy of chip firmware monitoring, and completing the positioning analysis of the firmware of the chip to be tested based on the analysis of the flow direction of the configuration information flow. Without damaging the chip to be tested, the registers in the chip to be tested can be positioned based on the hardware method, thereby ensuring the integrity of the chip, realizing non-destructive monitoring of the integrated circuit, and improving the accuracy and reliability of firmware positioning analysis.

[0107] The present invention provides a chip firmware positioning and analysis device that can achieve the following Figures 1 to 3 To avoid repetition, any of the chip firmware positioning and analysis methods shown will not be described here.

[0108] The electronic device in the embodiments of the present invention may be a device, or a component, integrated circuit, or chip in a terminal. The device may be a mobile electronic device or a non-mobile electronic device. For example, the mobile electronic device may be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a wearable device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc. The non-mobile electronic device may be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine (ATM), or a self-service machine, etc., and the embodiments of the present invention do not specifically limit this.

[0109] The electronic device in the embodiment of the present invention may be a device having an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present invention.

[0110] Figure 5 FIG1 shows a hardware structure diagram of an electronic device provided by an embodiment of the present invention. Figure 5 As shown, the electronic device 400 includes a processor 410 .

[0111] like Figure 5 As shown, the processor 410 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention.

[0112] like Figure 5 As shown, the electronic device 400 may further include a communication line 440. The communication line 440 may include a path for transmitting information between the components.

[0113] Optional, such as Figure 5 As shown, the electronic device may further include a communication interface 420. There may be one or more communication interfaces 420. The communication interface 420 may use any transceiver or other device for communicating with other devices or a communication network.

[0114] Optional, such as Figure 5 As shown, the electronic device may further include a memory 430. The memory 430 is used to store computer-executable instructions for executing the solution of the present invention, and is controlled by the processor to execute the computer-executable instructions stored in the memory, thereby implementing the method provided by the embodiment of the present invention.

[0115] like Figure 5As shown, the memory 430 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 430 can exist independently and be connected to the processor 410 via a communication line 440. The memory 430 can also be integrated with the processor 410.

[0116] Optionally, the computer-executable instructions in the embodiment of the present invention may also be referred to as application program codes, which is not specifically limited in the embodiment of the present invention.

[0117] In a specific implementation, as an embodiment, Figure 5 As shown, the processor 410 may include one or more CPUs, such as Figure 5 CPU0 and CPU1 in.

[0118] In a specific implementation, as an embodiment, Figure 5 As shown, the terminal device may include multiple processors, such as Figure 5 The first processor 4101 and the second processor 4102 in the embodiment of the present invention are shown in FIG. Each of these processors can be a single-core processor or a multi-core processor.

[0119] Figure 6 FIG. 1 is a schematic diagram of the structure of the chip provided by an embodiment of the present invention. Figure 6 As shown, the chip 500 includes one or more (including two) processors 410 .

[0120] Optional, such as Figure 6 As shown, the chip also includes a communication interface 420 and a memory 430. The memory 430 may include a read-only memory and a random access memory, and provides operation instructions and data to the processor. A portion of the memory may also include a non-volatile random access memory (NVRAM).

[0121] In some embodiments, as Figure 6 As shown, the memory 430 stores the following elements, execution modules or data structures, or a subset thereof, or an extended set thereof.

[0122] In the embodiment of the present invention, Figure 6 As shown, corresponding operations are performed by calling an operation instruction stored in a memory (the operation instruction may be stored in an operating system).

[0123] like Figure 6 As shown, the processor 410 controls the processing operations of any one of the terminal devices. The processor 410 may also be referred to as a central processing unit (CPU).

[0124] like Figure 6 As shown, the memory 430 may include a read-only memory and a random access memory, and provides instructions and data to the processor. A portion of the memory 430 may also include NVRAM. For example, in an application, the memory, the communication interface, and the memory are coupled together through a bus system, wherein the bus system may include a power bus, a control bus, and a status signal bus in addition to a data bus. However, for the sake of clarity, the following are not used in the following text: Figure 6 Various buses are labeled as bus system 540 .

[0125] like Figure 6As shown, the methods disclosed in the above embodiments of the present invention can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor may be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The methods, steps, and logic block diagrams disclosed in the embodiments of the present invention can be implemented or executed. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in conjunction with the embodiments of the present invention can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software modules can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. The storage medium is located in a memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0126] On the one hand, a computer-readable storage medium is provided, in which instructions are stored. When the instructions are executed, the functions performed by the terminal device in the above embodiment are implemented.

[0127] On the one hand, a chip is provided, which is applied to a terminal device. The chip includes at least one processor and a communication interface. The communication interface is coupled to the at least one processor, and the processor is used to run instructions to implement the functions performed by the chip firmware positioning and analysis method in the above embodiment.

[0128] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer programs or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a terminal, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disc (DVD); or a semiconductor medium, such as a solid-state drive (SSD).

[0129] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art can understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0130] Although the present invention has been described with reference to specific features and embodiments thereof, it will be apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the invention. Accordingly, this specification and drawings are merely illustrative of the invention as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the invention. It will be apparent that various modifications and variations may be made to the present invention by those skilled in the art without departing from the spirit and scope of the invention. Thus, the present invention is intended to include such modifications and variations as fall within the scope of the claims of the present invention and their equivalents.

Claims

1. A chip firmware location analysis method, characterized in that: Applied to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor, the chip to be tested including chip firmware and multiple input interfaces, the method comprising: When the chip under test is set to an initial state, controlling the plurality of input interfaces to have one target input interface under test in a normal working state at a time; Traversing all the input interfaces, and determining the magnetic field image data of the chip firmware corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times; Determining depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data; Determining the flow direction of the chip firmware configuration information flow based on the depth distribution data of different wires at the same position in the chip to be tested and combining the magnetic field image data of two adjacent times; The chip to be tested is scanned based on the diamond nitrogen vacancy color center sensor, and the positioning analysis of the chip firmware is completed based on the flow direction of the analysis configuration information flow.

2. The chip firmware positioning and analysis method according to claim 1, characterized in that: The traversing all the input interfaces and determining the magnetic field image data corresponding to each input interface being the target input interface to be tested in a normal working state for multiple times includes: When traversing all the input interfaces and determining multiple times that each input interface is the target input interface to be tested in a normal working state, each position of the chip to be tested is continuously flipped, the configuration parameters of the chip firmware change with the flipping, and the magnetic field image data of the sensor's magnetic field changes with the flipping.

3. The chip firmware positioning and analysis method according to claim 1, characterized in that: Determining depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data includes: Based on the plurality of magnetic field image data and in combination with the vector magnetic field image data, the vertical positioning of the register configured in the chip firmware is analyzed to determine the depth distribution data of different wires at the same position in the chip to be tested.

4. The chip firmware positioning and analysis method according to claim 1, characterized in that: Scanning the chip to be tested based on the diamond nitrogen vacancy color center sensor and completing the positioning analysis of the chip firmware based on the flow direction of the analysis configuration information flow includes: The chip to be tested is scanned based on the diamond nitrogen vacancy color center sensor, and positioning analysis of the configuration information of multiple registers in the chip to be tested by the chip firmware is completed based on the analysis of the flow direction of the configuration information flow.

5. A chip firmware positioning and analysis device, characterized in that: Applicable to an electronic device including a diamond nitrogen vacancy color center sensor and a chip to be tested disposed on the diamond nitrogen vacancy color center sensor, wherein the chip to be tested includes chip firmware and multiple input interfaces, the device includes: a control module, configured to control, when the chip under test is set to an initial state, to ensure that one target input interface under test is in a normal working state at a time among the plurality of input interfaces; A first determination module is configured to traverse all the input interfaces and determine, multiple times, the magnetic field image data of the chip firmware corresponding to each input interface being the target input interface to be tested in a normal working state; A second determining module is configured to determine depth distribution data of different wires at the same position in the chip to be tested based on the plurality of magnetic field image data; a third determining module, configured to determine a flow direction of the configuration information flow of the chip firmware based on the depth distribution data of different wires at the same position in the chip to be tested and in combination with two adjacent magnetic field image data; A positioning analysis module is used to scan the chip to be tested based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the chip firmware based on the flow direction of the analysis configuration information flow.

6. The chip firmware positioning and analysis device according to claim 5, characterized in that: The first determining module includes: The first determination submodule is used to traverse all the input interfaces and determine multiple times that each input interface is the target input interface to be tested in a normal working state. Each position of the chip to be tested is continuously flipped, and the configuration parameters of the chip firmware change with the flipping, and the magnetic field image data of the sensor's magnetic field changes with the flipping.

7. The chip firmware positioning and analysis device according to claim 5, characterized in that: The second determining module includes: The second determination submodule is used to analyze the vertical positioning of the registers configured in the chip firmware based on the multiple magnetic field image data and in combination with the vector magnetic field image data, and determine the depth distribution data of different wires at the same position in the chip to be tested.

8. The chip firmware positioning and analysis device according to claim 5, characterized in that: The positioning analysis module includes: The positioning analysis submodule is used to scan the chip to be tested based on the diamond nitrogen vacancy color center sensor, and complete the positioning analysis of the configuration information of the chip firmware on multiple registers in the chip to be tested based on the flow direction of the configuration information flow.

9. An electronic device, characterized in that: include: one or more processors; and one or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, enable the chip firmware positioning and analysis method described in any one of claims 1 to 4 to be executed.

Citation Information

Patent Citations

  • Electromagnetic field near-field imaging system and method based on pulsed light detection magnetic resonance

    CN107356820A

  • Test chip, integrated circuit test method and system, and detection equipment

    CN111596199A