Hardware trojan detection method and hardware trojan detection apparatus
Patent Information
- Application Number
- CN202180043134.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-06-25
- Filing Date
- 2021-06-23
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2041-06-23
AI Technical Summary
[0005]然而,专利文献1的系统依然为模拟,栅极动作率计算用图案的制作与原来的图案相比,图案数的非常大的降低也存在极限
Smart Images

Figure CN115698993B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method, device, and program for detecting hardware Trojans. Background Technology
[0002] A hardware Trojan horse is primarily composed of a trigger circuit that activates under certain conditions and a payload circuit that outputs abnormal data when activated by the trigger circuit. To make it difficult to detect through logic simulation, hardware Trojan horses are typically designed to perform very little functionality.
[0003] In the case of hardware Trojans implemented through logic simulation, simulation based on test patterns is standard practice. As mentioned above, since hardware Trojans rarely function, all test patterns are required to observe their state, making simulation time-consuming. Furthermore, simulating transition probabilities requires information about all units used by libraries, etc. Therefore, it is difficult for anyone other than the designer to detect hardware Trojans.
[0004] Patent Document 1 discloses a system for calculating the gate action rate using an RTL simulation mechanism, a gate action rate calculation pattern generation mechanism, and a netlist simulation mechanism. According to this system, the number of patterns generated for gate action rate calculation can be significantly reduced compared to the original pattern, and the simulation can be performed in a much shorter time compared to simulation using the original test pattern via netlist simulation.
[0005] However, the system in Patent Document 1 is still analog, and there is a limit to the very large reduction in the number of patterns used to calculate the gate action rate compared to the original pattern.
[0006] Furthermore, Patent Document 2 discloses a netlist for an electronic circuit, an operating rate assigned to the input terminals of each macrocell, a probability that the input terminal is at a high level, and a method for calculating the operating rate using a database of truth tables for that macrocell. Based on the aforementioned operating rates, the probability that the input terminal is at a high level, and the truth table, the operating rate of the output terminal of each macrocell and the probability that the output terminal is at a high level are calculated, and these are propagated from the input stage to the final stage to obtain the operating rate of the macrocell in the netlist.
[0007] The technology disclosed in the aforementioned patent document 2 can determine the operating rate of macrocells, and even when associated with risk avoidance based on heat, it will not trigger the detection of hardware Trojans.
[0008] In addition, Patent Document 3 discloses a method of assigning scores to structural networks that may include Trojan horse networks as reference networks in a known network list, and searching the reference networks for the network list of the object to be inspected, assigning the scores, and detecting hardware Trojan horses based on the scores. Prior art literature Patent documents
[0009] Patent Document 1: Japanese Patent Application Publication No. 2001-350815 Patent Document 2: Japanese Patent Application Publication No. 2005-141538 Patent Document 3: Japanese Patent No. 6566576 Summary of the Invention (The problem the invention aims to solve)
[0010] Embodiments of the present invention, for example, provide a hardware trojan detection method that can appropriately detect hardware trojans in a relatively short time when using IP (Intellectual Property) in SoC (System on a Chip) design, in cases where hardware trojans are inserted. (Technical solution used to solve the problem)
[0011] The hardware Trojan detection method of this embodiment is characterized by comprising: an input / output update step, which performs logical operations on all logical units included in the netlist of the object being inspected, and updates the input / output values of all logical units; and a detection step, which detects hardware Trojans based on the comparison result between the updated input / output values and a threshold. Furthermore, the logical operations performed in logical units are generally operations with only two logical values, such as 1, 0, or true and false. In contrast, in this embodiment, numerical values other than the aforementioned two logical values (decimals such as 0.5 and 0.25, integers such as 5 and 10, etc.) are used to perform logical operations based on logical units. Attached Figure Description
[0012] Figure 1 This is a structural diagram of a computer system that implements the hardware Trojan detection device according to the first embodiment of the present invention. Figure 2 This is a functional block diagram of the hardware Trojan detection device according to the first embodiment of the present invention. Figure 3 This is a diagram illustrating an example of the structure of a netlist used to detect hardware Trojans by the hardware Trojan detection device according to the first embodiment of the present invention. Figure 4 This is a flowchart illustrating the operation of the hardware Trojan detection device according to the first embodiment of the present invention. Figure 5 This is an explanatory diagram of the parameters set in the hardware Trojan detection device according to an embodiment of the present invention. Figure 6 It means to Figure 3 The diagram shown illustrates a structured network with specified parameters. Figure 7 It indicates that it is directed at or against. Figure 3 The diagram shown illustrates a network structure with defined parameters, updated through operations based on logical units. Figure 8 It is a diagram representing the computational expression used to update logic units through operations based on logical expressions. Figure 9 It indicates that it is directed at or against. Figure 7 The diagram shown illustrates the logical units of a structured network with defined parameters, and the updated state diagram based on logical operations. Figure 10 It indicates that it is directed at or against. Figure 9 The diagram shown illustrates the logical units of a structured network with defined parameters, and the updated state diagram based on logical operations. Figure 11 It indicates that it is directed at or against. Figure 10 The diagram shown illustrates the logical units of a structured network with defined parameters, and the updated state diagram based on logical operations. Figure 12 It indicates that it is directed at or against. Figure 11 The diagram shows the state of the second runtime of the network structure with set parameters, where the logical units of the network are updated through logical operations. Figure 13 This is a structural diagram of a computer system that implements the hardware Trojan detection device according to the second embodiment of the present invention. Figure 14 This is a functional block diagram of a hardware Trojan detection device according to the second embodiment of the present invention. Figure 15 This is a diagram showing the transformation table of the first threshold and score used in the hardware Trojan detection device according to the second embodiment of the present invention. Figure 16 This indicates that a waveform with a certain value is output over a long period of time when a Trojan horse network is present. Figure 17 This is a flowchart illustrating the hardware Trojan detection process involved in this second embodiment. Detailed Implementation
[0013] Hereinafter, with reference to the accompanying drawings, the hardware Trojan detection method, hardware Trojan detection device, and hardware Trojan detection program according to embodiments of the present invention will be described. In the drawings, the same reference numerals are used to label the same components, and repeated descriptions are omitted.
[0014] The hardware Trojan detection device 1 according to the first embodiment of the present invention can be, for example, made by... Figure 1 The system consists of a personal computer, a workstation, and other computer systems. The computer system is controlled by the CPU 10 based on programs and data stored in or read into the main memory 11, performing necessary processing and thus functioning as a hardware Trojan detection device 1.
[0015] External storage interface 13, input interface 14, display interface 15, and network interface 16 are connected to CPU 10 via bus 12. External storage interface 13 is connected to external storage device 23, which stores programs such as hardware Trojan detection programs and necessary data. Input interface 14 is connected to input device 24, such as a keyboard, for inputting instructions or data, and mouse 22, for pointing.
[0016] A display device 25 with an LED, LCD, or similar display screen is connected to the display interface 15. The network interface 16 connects to a network 26, such as the Internet, enabling access to external servers, cloud services, etc. The network 26 is a structure for obtaining necessary data, and can also be a storage medium or input device for data input. Furthermore, this computer system can also have other structures. Figure 1 The structure is just one example.
[0017] Figure 2 This is a functional block diagram of the hardware Trojan detection device 1 according to the first embodiment of the present invention. In the above, the hardware Trojan detection is implemented in the CPU 10 by a hardware Trojan detection program stored in the external storage device 23. Figure 2 The various mechanisms described herein include an input / output update mechanism 31, a parameter setting mechanism 32, and a detection mechanism 33.
[0018] The input / output update mechanism 31 performs logical operations on all logic units included in the netlist of the object being checked, and updates the input / output values of all logic units. Specifically, if the object being checked is a structured net, the input / output update mechanism 31 performs the aforementioned operations on all logic units within the structured net; if the object being checked is a cluster net, the input / output update mechanism 31 performs the aforementioned operations on all logic units within the cluster net; and further, if the object being checked is an LSI as a whole, the input / output update mechanism 31 performs the aforementioned operations on all logic units of that LSI as a whole. In this first embodiment and the second embodiment described later, the input / output update mechanism 31 performs the aforementioned operations on all logic units in the structured netlist included in the netlist of the object being checked, and updates the input / output values of all logic units. The parameter setting mechanism 32 sets the netlist parameters for the inputs and outputs of all logic units as initial values. The object being checked netlist is design data that describes a list of wiring connecting various circuits included in the developed LSI, etc., to each other. The netlist of the inspection target has a hierarchical structure that matches the hierarchy of the circuits constituting the developed LSI, etc., and includes a set net as the top layer and a structure net as the lower layer of the set net. Depending on the scale of the information processing device, there are one or more set nets and structure nets. The structure net consists of a group of circuits connected by wiring between terminals of the connecting circuits (hereinafter referred to as "terminal-to-terminal nets"). Furthermore, logic units are included in the various circuits included in the developed LSI, etc.
[0019] In this embodiment, in the input / output update mechanism 31, the above-mentioned calculations using the set parameters are performed on all the above-mentioned logic units for a predetermined number of runs to update the input and output values.
[0020] The logic unit includes logic circuits and, where necessary, buffers and repeaters other than the logic circuits. During each operation, the input / output update mechanism 31 performs a predetermined number of updates to the buffers and repeaters until the input value is passed to the output of the buffer or repeater, while updating the buffers and repeaters. For example, when performing the above operations on all logic units in the structure network for one operation, the input / output values of the buffers or repeaters are updated in a manner equivalent to updating the buffers or repeaters 10 times.
[0021] The detection mechanism 33 detects hardware Trojans based on the comparison result between the updated input / output values and the threshold. In this embodiment, the detection mechanism 33 detects hardware Trojans based on the output value of any logic unit obtained after performing the above-mentioned operation a predetermined number of times.
[0022] In this embodiment, the detection mechanism 33 detects hardware Trojans in the netlist of the object under inspection by comparing a threshold corresponding to the circuit size of the netlist of the object under inspection (i.e., the circuit size threshold) with the input / output value of any logic unit obtained after performing the above operation for a predetermined number of runs. Specifically, in a circuit with approximately 500 inter-terminal nets representing the circuit size of the structural netlist of the object under inspection, when the predetermined number of runs is set to 4 runs, the parameter value becomes approximately 2.8e-8. The parameter can compare the circuit size threshold with an output value of 1e-7 and an input value of 1-(1e-7). That is, if the output value is below 1e-7, it can be determined that a hardware Trojan exists; if the input value is above 1-(1e-7), it can be determined that a hardware Trojan exists.
[0023] The netlist, including the netlist of the object being inspected, is a hierarchical structure corresponding to the hierarchy of circuits in devices such as LSIs, which are typically constructed using netlists. The top layer of this hierarchy is called the set net, and the lower layers of this set net have structure nets. Depending on the size of the device such as the LSI, there are one or more of both the set net and the structure net. The structure net consists of a set of circuits connected by wiring called an inter-terminal net, which is provided between the terminals of the circuit. In this embodiment, the aforementioned operations are performed on all logic units in the structure net, and the input / output values of all logic units are updated.
[0024] An example of a structured network is shown below. Figure 3 The structure includes a suspected Trojan circuit section 41 that may contain hardware Trojans, a non-Trojan circuit section 42 that does not contain hardware Trojans, and a remaining circuit section 43 that is part of the other components.
[0025] The suspected Trojan circuit section 41 includes AND gates C1 to C11 as logic units, and these logic units are connected via terminal lines s1i1 to s1i17, s2i1 to s2i8, s3i1, and s3i2. Three buffers B1 to B3 are connected in series between AND gates C10 and C11.
[0026] The non-Trojan circuit section 42 includes an AND gate C12, a D flip-flop F1, a portion of the multiplexer M, a buffer B4, and also includes inter-terminal networks FB1, FB2, LP1, a non-Trojan network AT1, and the output network OUTPUT of the multiplexer M.
[0027] The remaining circuit section 43 includes three buffers B5 to B7 connected in series, a part of the multiplexer M, and as an inter-terminal network, it has the output line TRG1 connected to the AND gate C11, the network of buffers B5 to B7, the network P1 of the payload of the Trojan horse that reaches one of the inputs of the multiplexer M, and the output network OUTPUT of the multiplexer M.
[0028] For a network structure like the one described above, CPU 10 uses a hardware Trojan detection program stored in external storage device 23, such as... Figure 4 The actions are performed as shown in the flowchart, and therefore the actions are explained based on this flowchart. CPU 10 reads the netlist of the object to be checked (S11). The reading of the netlist of the object to be checked can be performed, for example, from external storage device 23, or it can be performed by accessing external servers, the cloud, etc. via network interface 16 and network 26.
[0029] Next, CPU10 uses the read netlist to set the net parameters of all logic unit inputs and outputs as initial values (S12).
[0030] The parameters used above are determined, for example, as follows. The input and output signals in the logic unit used in the LSI or similar device, which is the subject of this embodiment, are as follows: Figure 5 As shown, having a value of either H or L level is a specific level. Therefore, as... Figure 5 As shown, the H (H) and L (L) levels change, with the proportion of H(L) levels at time T being 0.5. This 0.5 is used as a parameter and set as the initial value in the input / output network of the entire logic unit. The result is as follows. Figure 6 As shown.
[0031] Next, the above-mentioned operations using the set parameters are executed, updating the input and output values of all the above-mentioned logic units (S13). In this case, the operations based on the above operations can start from anywhere, and the order is different. Figure 7 The diagram shows the results of the operations performed on the output side of AND gates C11 and C12. In this case, the above operations are performed via... Figure 8 Use the formula shown.
[0032] exist Figure 9 The diagram shows the results of operations performed downstream from AND gate C11, calculating the outputs of AND gates C9 and C10 respectively. Furthermore, in... Figure 10 The results of operations performed on the respective inputs of AND gate C9 and AND gate C10 are shown in the figure.
[0033] exist Figure 11The example shown illustrates a predetermined number of updates performed on buffers and repeaters until the input value is passed to the output of the buffer or repeater. When performing the above operations on all logic units in the structure network for one runtime, the input / output values of the buffers or repeaters are updated equivalent to 10 of the above operations. As a result, the output 0.0625 of AND gate C10 is passed sequentially in the three buffers B1 to B3. Since the timing of the output of AND gate C10 changes or is uncertain, an update of the input / output values equivalent to 10 of the above operations is performed here.
[0034] In addition, Figure 11 The diagram illustrates the sequential passing of the output 0.0625 of the AND gate C11 through three buffers B5-B7. Regarding the update of the input and output values of the three buffers B5-B7, since the timing of the AND gate C11's output change is uncertain, an update of the input and output values equivalent to 10 times the above operation is performed. In this example, Figure 11 The timing shown updates the input and output of the buffer, but it also happens at other times.
[0035] As described above, when the above operation using the set parameters is performed, and the update of all input and output values of the above logic unit is completed (one cycle of update is completed), it is checked whether the update of the specified number of cycles (four cycles in this case) has been completed (S14). If not, the process returns to step S13 and continues.
[0036] If the process returns to step S13, it becomes the second runtime process. From the above... Figure 11 From the end of the first operating period shown, in Figure 12 In the second runtime process shown, the output of AND gate C11 is updated to 0.001935. Next, the input / output values of the logic units downstream of AND gate C11 are updated, and then the input / output values of the logic units upstream of AND gate C11 are updated. The order of these updates is different in this second runtime. Similarly, the operations described in the first runtime process are performed. Thus, the second runtime process ends, the third runtime process begins and ends, and then the fourth runtime process begins and ends. In step S14, the branch is "Yes," and the process proceeds to step S15.
[0037] In step S15, the CPU10 compares the threshold (output value is 1e-7, input value is 1-(1e-7)) and the input and output values of each logic unit as described above (S15), and determines whether the output value used as the determination condition is below 1e-7 or whether the input value is above 1-(1e-7) (S16).
[0038] If the result is yes in step S16 above, it is determined that a hardware Trojan exists, and output processing such as displaying the subject on the display device 25 is performed (S17). If the result is no in step S16 above, it is determined that a hardware Trojan does not exist, and output processing such as displaying the subject on the display device 25 is performed (S18).
[0039] Next, the hardware Trojan detection method, hardware Trojan detection device, and hardware Trojan detection program according to the second embodiment of the present invention will be described. The embodiments of the hardware Trojan detection method and hardware Trojan detection device according to the second embodiment are also the same as those of the hardware Trojan detection device 1 according to the first embodiment of the present invention. Figure 13 The computer system shown implements hardware Trojan detection device 1A.
[0040] Figure 14 This is a functional block diagram illustrating the hardware Trojan detection device 1A according to the second embodiment of the present invention. In the hardware Trojan detection device 1A according to the second embodiment, the hardware Trojan detection is implemented in the CPU 10 by a hardware Trojan detection program stored in the external storage device 23. Figure 14 The various mechanisms described herein include, specifically, the input / output update mechanism 31 and parameter setting mechanism 32, which are the same as those in the first embodiment. In addition to the input / output update mechanism 31 and parameter setting mechanism 32, it also includes a detection mechanism 33A, a first threshold acquisition mechanism 34, a judgment score threshold acquisition mechanism 35, and a second threshold acquisition mechanism 36.
[0041] The first threshold acquisition mechanism 34 uses a known netlist including a hardware Trojan and a known netlist excluding a hardware Trojan to perform the processing performed by the parameter setting mechanism 32 and the input / output update mechanism 31. Based on the input / output values within the structured netlist obtained after a predetermined number of runs in the input / output update mechanism 31, the first threshold is calculated. The detection mechanism 33A uses the first threshold to detect hardware Trojans.
[0042] In this embodiment, the known netlist and the netlist of the object to be inspected are configured as a collection of netlists comprising at least one set of structural netlists connected by a set of circuits via an inter-terminal netlist. The first threshold acquisition mechanism 34 acquires a first threshold for each structural netlist.
[0043] The decision score threshold acquisition mechanism 35 assigns a predetermined score to each structural network within the known netlist based on the relationship between the maximum and minimum input / output values and a first threshold. It then compares the scores of each structural network with the maximum score assigned to each set of networks in the known netlist, and obtains the decision score threshold based on the minimum score of each set of networks. Here, the set of networks with the maximum score after the decision score threshold acquisition mechanism 35 performs the above processing is called the "maximum score network," and the number of maximum score networks in the known netlist is called the "maximum score network number."
[0044] The detection mechanism 33A assigns a predetermined score to each inspected object's netlist based on its relationship with a first threshold. The maximum score assigned to the structural netlist by summing the scores of each set of netlists in the inspected object's netlist is used to obtain the inspected object's score. The inspected object's score is evaluated based on the judgment score threshold to detect hardware Trojans in the inspected object's netlist.
[0045] The second threshold acquisition mechanism 36 extracts known netlists from multiple known netlists, including hardware Trojans that meet the conditions of having a clock count of more than a predetermined value and a maximum fractional netlist count of less than a maximum fractional netlist count threshold. Using the extracted known netlists, it performs processing based on the parameter setting mechanism 32 and the input / output update mechanism 31. Based on the output value obtained during the above-mentioned operation in the input / output update mechanism 31 after a predetermined number of runs, it calculates the second threshold.
[0046] In this embodiment, for example, a netlist of benchmark tags publicly available on a US site (Trust-HUB) can be used. Ten benchmark tags are selected, with cases including hardware trojans represented as (HT-inserted) and cases not including hardware trojans represented as (HT-free), as shown in Table 1 below.
[0047] [Table 1] b19 HT-free 108,332 EthernetMAC10GE HT-free 103,206 S35932 HT-free 6,423 EthernetMAC10GE-T700 HT-inserted 103,220 RS232-T1000 HT-inserted 311 s15850-T100 HT-inserted 2,456 s38417-T100 HT-inserted 5,819 s38584-T200 HT-inserted 7,580 vga_Icd-T100 HT-inserted 70,162 wb_conmax-T100 HT-inserted 22,197
[0048] The reference markings in Table 1 include more than one set of networks, and each set of networks includes more than one structural network. Within this structural network, it is known that an inter-terminal network, possibly a "suspected Trojan network," can be identified. Structural networks including suspected Trojan networks are included in the reference markings table. Patent Document 3 discloses that a structural network including such a suspected Trojan network is called a comparison network, and nine comparison networks can be identified from the reference markings in Table 1.
[0049] In this embodiment, without identifying the above nine reference nets, the known netlists including hardware Trojans and the known netlists excluding hardware Trojans (the contents of the above reference markers) are used to perform the processing described in the first embodiment by the above parameter setting mechanism 32 and the above input / output update mechanism 31, and the input / output values in the structure net obtained when the above calculation is performed for a predetermined number of runs in the input / output update mechanism 31 are obtained.
[0050] The result of performing the above processing on all structure nets, including known netlists containing hardware Trojans and known netlists excluding hardware Trojans (the contents of the above reference markers), is to obtain a value TO (e.g., 1e-7) that is close to the output value having more than 5 zeros below the decimal point (called the Trojan output threshold) and a value TI (e.g., 1-(1e-7)) that is close to the input value obtained by subtracting TO from 1 (called the Trojan input threshold).
[0051] The first threshold acquisition mechanism 34 calculates the average of the Trojan-containing output thresholds and Trojan-containing input thresholds obtained from all the structure networks, and uses these averages as the first threshold. Furthermore, in cases where a Trojan-containing output threshold with a difference of more than one bit, such as 1e-7 and 1e-6, is obtained, the aforementioned averages are calculated as Trojan-containing output threshold 1 and Trojan-containing output threshold 2, respectively. In this case, if Trojan-containing input threshold 1 and Trojan-containing input threshold 2 are obtained, their averages are also calculated. Moreover, multiple first thresholds are obtained, such as first threshold 1 and first threshold 2.
[0052] The determination threshold acquisition mechanism 35 assigns scores to each input and output value within the structured network. For example... Figure 15 As shown, the score is 2 if it is below the Trojan output threshold of 1, 1 if it is above the Trojan output threshold of 1 but below the Trojan output threshold of 2, and 0 if it is above the Trojan output threshold of 2. Additionally, as... Figure 15 As shown, the value is 2 when the input value is above the Trojan input threshold of 1, 1 when it is below the Trojan input threshold of 1 but above the Trojan input threshold of 2, and 0 when it is below the Trojan input threshold of 2.
[0053] A score is assigned to all input and all output values of the structured net. The maximum score is the sum of the scores assigned to the structured net for each set of nets in the known netlist. Therefore, the maximum score is either the score corresponding to an output value in the structured net that is less than the threshold for a Trojan horse output, or the score corresponding to an input value that is greater than the threshold for a Trojan horse input.
[0054] Next, the maximum score is calculated for all the known netlists. Therefore, in known netlists containing a large number of structural netlists and aggregate netlists with a high probability of containing hardware Trojans, the total score becomes larger. The scores of each netlist obtained in this way are compared, and a decision score threshold is derived based on the minimum score for each netlist. For example, the decision score threshold is obtained by adding 1 to the minimum known netlist score. If the known netlists with the baseline labels in Table 1 are used, then 3 is calculated as the decision score threshold.
[0055] The aforementioned testing mechanism 33A assigns a predetermined score to each structural net of the netlist of the inspected object based on the relationship between the input / output values and a first threshold. In this operation, the first threshold obtained by the first threshold acquisition mechanism 34 is used, and the testing mechanism 33A assigns a predetermined score to each structural net of the netlist of the inspected object based on the relationship between the input / output values and the first threshold. Figure 15 The first threshold and the data from the score transformation table shown are used to assign scores.
[0056] Similar to the scoring assigned by testing agency 33A, all and all output values of the structured network are assigned. The maximum score assigned to the structured network is summed across each set of networks in the known network list. Therefore, the maximum score is the score corresponding to an output value in the structured network of the network list of the inspected object that is less than the Trojan output threshold, or the maximum score is the score corresponding to an input value that is greater than the Trojan input threshold.
[0057] Next, the maximum score of all sets of the netlist of the object to be inspected is summed to obtain the object score. This object score is compared with the judgment score threshold (3 in the aforementioned example) to detect hardware Trojans in the netlist of the object to be inspected. Specifically, if the object score is higher than or equal to the judgment score threshold (3 in the aforementioned example), it is determined that a hardware Trojan exists, and output processing such as displaying the subject on the display device 25 is performed.
[0058] In this second embodiment, such as Figure 14 As shown, it includes a second threshold acquisition mechanism 36. The second threshold acquisition mechanism 36 extracts from multiple known netlists a known netlist that is intended to include hardware Trojans that meet the conditions of having a clock count that outputs a certain value within a specified time that is above a predetermined value and a maximum score netlist that is below a maximum score netlist threshold.
[0059] In the determination score threshold acquisition mechanism 35, in each structural net in the known netlist, a score with a specified value is assigned according to the relationship between the input and output values and the first threshold, and the maximum score is assigned to the structural net by the total score of all nets in the known netlist.
[0060] Regarding the known netlists with the baseline markers shown in Table 1, the relationship between the maximum score netlist number and the presence of Trojan horse networks was investigated. When including known Trojan horse networks, the maximum score netlist number is relatively small, and the maximum value of the maximum score netlist number (Xnumber) is 5, which is the baseline marker (s38417-T100). Thus, regarding the inclusion / exclusion of known Trojan horse networks, the maximum score netlist number (Xnumber) of multiple known netlists can be investigated, and the largest maximum score netlist number (Xnumber) in the investigation is set as the maximum score netlist number threshold (Tnumber). A condition where the maximum score netlist number is below the maximum score netlist number threshold is a condition for a known netlist including known Trojan horse networks (called the netlist number condition).
[0061] On the other hand, for example, such as Figure 16 As shown, the longest number of clock cycles that outputs a certain value within a 1M clock interval is defined as the maximum constant cycles. The higher this maximum constant cycles, the higher the probability that the maximum score network includes a Trojan network. Since Trojan networks are difficult to operate, in the presence of a Trojan network, the prediction is to continuously output a constant value for a long period of time (called the constant cycles condition).
[0062] Among the reference marks shown in Table 1, Patent Document 3 shows the reference marks of known netlists that satisfy the above-mentioned "constant cycle number condition" and "net number condition" as reference marks (RS232-T1000, s38417-T100 and vga_lcd-T100).
[0063] Thus, the second threshold acquisition mechanism 36 extracts a known netlist that satisfies the above-mentioned "constant cycle number condition" and the above-mentioned "netlist number condition", uses the extracted known netlist to perform the processing performed by the above-mentioned parameter setting mechanism 32 and the above-mentioned input-output update mechanism 31, and calculates the second threshold based on the output value obtained when the above-mentioned operation is performed for a specified number of runs in the input-output update mechanism 31.
[0064] The processing performed by the parameter setting mechanism 32 and the input / output update mechanism 31, and the calculations performed for a predetermined number of runs, yields the same output value processing as described above. The only difference is that the netlist being processed is the netlist of the reference markers (RS232-T1000, s38417-T100, and vga_lcd-T100). Figure 4 Steps S11 to S15 in the flowchart are described, so the description is omitted here.
[0065] In the above-described operation of the input / output update mechanism 31, which has been run a specified number of times, the input and output values within the structure network are obtained. As the output value, a value TO (e.g., 1e-7) with at least five zeros below the decimal point is obtained (called the Trojan output threshold). As the input value, a value TI (e.g., 1-(1e-7)) is obtained (called the Trojan input threshold) that is close to the value TI obtained by subtracting TO from 1.
[0066] The second threshold acquisition mechanism 36 calculates the average value of the Trojan-containing output threshold and Trojan-containing input threshold obtained from all the structural nets, and uses this average value as the second threshold. In this embodiment, since a netlist with three reference labels is used, three second thresholds are generated. Finally, the average value is set as the second threshold, or the threshold with the smallest Trojan-containing output threshold is set as the second threshold, and the threshold with the largest Trojan-containing input threshold is set as the second threshold.
[0067] The aforementioned testing organization 33A uses the aforementioned second threshold to detect hardware Trojans in the netlist of the aforementioned inspected object. The testing process performed by the aforementioned testing organization 33A is as follows: Figure 4 As shown in the flowchart, the threshold used in step S16 becomes the aforementioned second threshold.
[0068] The hardware Trojan detection process involved in this second embodiment, in addition to the input / output update mechanism 31 and the parameter setting mechanism 32, is also represented by the processing steps of the detection mechanism 33A, the first threshold acquisition mechanism 34, the judgment score threshold acquisition mechanism 35, and the second threshold acquisition mechanism 36, as follows: Figure 17 The flowchart is shown.
[0069] First, a process for obtaining a first threshold is performed (S51). In step S51, this process is handled by the input / output update mechanism 31, the parameter setting mechanism 32, and the first threshold acquisition mechanism 34. Next, a process for obtaining a judgment score threshold is performed (S52). In step S52, this process is handled by the judgment score threshold acquisition mechanism 35. Next, a process for detecting hardware Trojans using the judgment score threshold is performed on the inspected netlist (S53). In step S53, this process is handled by the input / output update mechanism 31, the parameter setting mechanism 32, and the detection mechanism 33A.
[0070] Next, a process for obtaining the second threshold is performed (S54). In this step S54, the input / output update mechanism 31, the parameter setting mechanism 32, and the second threshold acquisition mechanism 36 perform the processing. Then, a hardware Trojan detection process using the second threshold is performed on the netlist of the inspection target (S55). In this step S55, the input / output update mechanism 31, the parameter setting mechanism 32, and the detection mechanism 33A perform the processing.
[0071] As described above, in both the first and second embodiments, the network setting parameters of the inputs and outputs of all logic units are used as initial values, and the above-mentioned operations are performed using the set parameters. The basic process is to update the input and output values of all logic units for a predetermined number of runs. It is expected that hardware Trojans can be detected with simple processing without requiring a lot of time.
[0072] Several embodiments of the present invention have been described, but these embodiments are given by way of example and are not intended to limit the scope of the invention. These new embodiments can be implemented in various other ways, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included within the scope or spirit of the invention, and are included within the scope of the invention described in the patent claims and their equivalents.
[0073] The number of known netlists and the number of reference netlists described in the embodiments are not limited to this. The number of known netlists is merely an example. Furthermore, in the embodiments, the score of the reference netlist can be changed. The values of the maximum score threshold and the maximum score netlist threshold can also be changed. The maximum score threshold and the maximum score netlist threshold are merely examples. Additionally, the maximum constant clock count (the longest number of clock cycles that outputs a constant value during a 1MHz clock period) is used, but it is not a limitation. (Label Explanation)
[0074] 1. Hardware Trojan Detection Device According to the First Embodiment Hardware Trojan Detection Device According to Embodiment 1A 11 Main Memory 12 bus 13 External Storage Interface 14 Input Interface 15 Display Interface 16 Network Interfaces 22. Mouse 23 External storage devices 24 Input devices 25 Display devices 26 Network 31 Input / Output Update Mechanism 32 Parameter setting mechanism 33, 33A testing institutions 34 First threshold acquisition mechanism 35. Determine the score threshold acquisition institution 36 Second threshold acquisition mechanism 41 Suspected Trojan Circuit Department 42. Non-Trojan Circuit Section 43. Remaining circuit section.
Claims
1. A method for detecting hardware Trojans, characterized in that, have: The input / output update process performs logical operations on all logical units included in the netlist of the checked object to update the input / output values of all logical units. as well as The detection process involves comparing the updated input / output values with a threshold to detect hardware trojans. In the detection process, hardware Trojans in the netlist of the object under inspection are detected by comparing the threshold corresponding to the circuit size of the netlist of the object under inspection with the input and output values of any logic unit obtained after the operation has been performed for a specified number of times.
2. The hardware Trojan detection method according to claim 1, characterized in that, The hardware Trojan detection method includes a parameter setting step that sets parameters as initial values in the input / output networks of all logic units. In the input / output update process, the logic unit is executed a predetermined number of times, and the operation using the set parameters is performed to update the input and output values. In the detection process, hardware Trojans are detected based on the output value of any logic unit obtained after the operation has been performed a specified number of times.
3. The hardware Trojan detection method according to claim 1 or 2, characterized in that, The logic unit includes logic circuits, and, where necessary, buffers and repeaters in addition to logic circuits. In the input / output update process, during the processing of updating the input and output values in each run, in the case of updating the buffer and repeater, a predetermined number of updates are performed until the input value is passed to the output of the buffer or repeater.
4. The hardware Trojan detection method according to claim 2, characterized in that, The hardware Trojan detection method includes a first threshold acquisition step. In this step, a known netlist including a hardware Trojan and a known netlist excluding a hardware Trojan are used to perform the parameter setting step and the input / output update step. The first threshold is calculated based on the input / output values within the structured net obtained during the calculations in the input / output update step after a predetermined number of runs. In the detection process, the first threshold is used to detect hardware Trojans.
5. The hardware Trojan detection method according to claim 4, characterized in that, The known netlist and the netlist of the object under inspection are configured to include at least a set net, which includes one or more structured nets consisting of a group of circuits connected by inter-terminal nets. In the first threshold acquisition process, a first threshold is acquired for each structural network. The hardware Trojan detection method includes a threshold determination step. In this step, a predetermined score is assigned to each structural network within a known netlist based on the relationship between the input / output values and a first threshold. The maximum score assigned to each structural network across all networks in the known netlist is calculated. The scores for each netlist are compared, and the threshold determination is determined based on the minimum score for each netlist. In the detection process, each structural network of the netlist of the object under inspection is assigned a score based on the relationship between the input and output values and a first threshold. The maximum score assigned to the structural networks by the total set of networks in the netlist of the object under inspection is used to obtain the score of the object under inspection. The score of the object under inspection is evaluated based on the judgment score threshold in order to detect hardware Trojans in the netlist of the object under inspection.
6. The hardware Trojan detection method according to claim 2, characterized in that, The hardware Trojan detection method includes a second threshold acquisition step. In this step, a known netlist is extracted from multiple known netlists. This netlist is presumed to include hardware Trojans that meet the conditions of having a clock count of a constant output value above a predetermined value within a specified time and a maximum fractional netlist count below a maximum fractional netlist count threshold. Using the extracted known netlists, the parameter setting step and the input / output update step are performed. The second threshold is calculated based on the output value obtained during the operation in the input / output update step after a specified number of runs. In the detection process, the second threshold is used to detect hardware Trojans in the netlist of the object being inspected.
7. A hardware Trojan detection device, characterized in that, have: The input / output update mechanism performs logical operations on all logical units included in the netlist of the checked object to update the input / output values of all logical units. as well as The detection agency uses the comparison results of the updated input / output values and thresholds to detect hardware Trojans. The detection mechanism performs hardware Trojan detection in the netlist of the object under inspection by comparing a threshold corresponding to the circuit size of the netlist of the object under inspection with the input-output value of any logic unit obtained after the operation has been performed a specified number of times.
8. The hardware Trojan detection device according to claim 7, characterized in that, The hardware Trojan detection device has a parameter setting mechanism that sets parameters as initial values in the input / output network of all logic units. The input / output update mechanism updates the input and output values by performing the operations with the set parameters for all execution cycles of the logic unit. The detection mechanism detects hardware Trojans based on the output value of any logic unit obtained after the operation has been performed a specified number of times.
9. The hardware Trojan detection device according to claim 7 or 8, characterized in that, The logic unit includes logic circuits, and, where necessary, buffers and repeaters in addition to logic circuits. In each run, the input / output update mechanism performs a predetermined number of updates for the input and output values, in the case of updates to buffers and repeaters, until the input value is passed to the output of the buffer or repeater.
10. The hardware Trojan detection device according to claim 8, characterized in that, The hardware Trojan detection device includes a first threshold acquisition mechanism. This first threshold acquisition mechanism uses a known netlist including hardware Trojans and a known netlist excluding hardware Trojans to perform processing by the parameter setting mechanism and the input / output update mechanism. Based on the input / output values within the structured netlist obtained during the calculations performed by the input / output update mechanism for a predetermined number of runs, the first threshold is calculated. The detection agency uses the first threshold to detect hardware Trojans.
11. The hardware Trojan detection device according to claim 10, characterized in that, The known netlist and the netlist of the object under inspection are configured to include at least a set net, which includes one or more structured nets consisting of a group of circuits connected by inter-terminal nets. The first threshold acquisition mechanism acquires a first threshold for each structural network. The hardware Trojan detection device includes a decision score threshold acquisition mechanism. This mechanism assigns a predetermined score to each structural network within a known netlist based on the relationship between the input / output values and a first threshold. It then calculates the maximum score assigned to each structural network across all known netlists, compares the scores of each netlist, and obtains the decision score threshold based on the minimum score for each netlist. The detection mechanism assigns a score to each structural network in the netlist of the object under inspection based on the relationship between the input / output values and a first threshold. The maximum score assigned to the structural networks by the total set of networks in the netlist of the object under inspection is used to obtain the score of the object under inspection. The score of the object under inspection is evaluated based on the judgment score threshold in order to detect hardware Trojans in the netlist of the object under inspection.
12. The hardware Trojan detection device according to claim 8, characterized in that, The hardware Trojan detection device includes a second threshold acquisition mechanism. This mechanism extracts a known netlist from multiple known netlists, including those containing hardware Trojans that meet the conditions of having a clock count above a predetermined value that outputs a constant value within a specified time, and a maximum fractional netlist count below a maximum fractional netlist count threshold. Using the extracted known netlists, the device performs processing by the parameter setting mechanism and the input / output update mechanism, and calculates the second threshold based on the output values obtained during the calculations performed in the input / output update mechanism for a specified number of runs. The detection agency uses the second threshold to detect hardware Trojans in the netlist of the object being inspected.
Citation Information
Patent Citations
Operation rate calculation system
JP2001350815A
Method, apparatus and program for calculating electronic circuit operation rate
JP2005141538A
Activity measurement-based hardware trojan detection method
CN102662144A
Method of detecting hardware trojan, program for detecting hardware trojan, and device for detecting hardware trojan
WO2016080380A1