A functional analysis method and system for logic encryption circuits

通过改进粒子群算法和遗传算法优化种群,解决了现有技术中逻辑加密电路分析的普适性问题,实现了更高效的安全性评估和测试。

CN115952511BActive Publication Date: 2025-07-11XINWEI TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310000890.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-03
Publication Date
2025-07-11
Estimated Expiration
2043-01-03

AI Technical Summary

Technical Problem

The prior art is difficult to effectively analyze SAT-Hard circuits, and the existing circuit key analysis methods lack universality and cannot conduct security assessments for various encryption methods.

Method used

The improved particle swarm algorithm is used to combine genetic algorithms, and the functional analysis of the logical encryption circuit is realized by generating the training data set and initializing the fitness function, and the differentiated input sequence is used to optimize the population.

Benefits of technology

It improves the success rate and accuracy of the security analysis of logic encryption circuits, enhances the safety evaluation ability of circuit design, and simplifies the safety testing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115952511B_ABST
    Figure CN115952511B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of integrated circuits, and particularly relates to a function analysis method and system for logic encryption circuits. The method includes: obtaining the activated encryption circuits and the target encryption circuit on the market; generating a specified number of correct input-output sets according to the activated encryption circuits; using an improved particle swarm algorithm to iteratively optimize the generated initial key; determining whether the accuracy of the global optimal key reaches a preset value. If not, return to the initial stage of the algorithm. If so, output the final key; perform accuracy verification on the final key, randomly generate a specified number of input-output sets again using the activated encryption circuits, calculate the actual accuracy of the final key, and evaluate the security of the encryption circuit based on this accuracy. The present invention can perform function analysis on the target encryption circuit without caring about the specific encryption method of the encryption circuit, and the obtained key has high accuracy, and the analysis method has universality.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of integrated circuits, and particularly relates to a function analysis method and system for logic encryption circuits. Background Art

[0002] To improve economic efficiency, many integrated circuit design manufacturers outsource their designs to third-party foundries for manufacturing. Although this outsourcing can reduce costs and shorten the time to market, the separated design and manufacturing processes result in a lack of effective supervision, which in turn leads to various security vulnerabilities and threats, such as piracy of intellectual property, reverse engineering, counterfeiting, IC overproduction, and hardware Trojan insertion. If an attacker steals the IC design, they can conduct pirated production or insert a hardware Trojan into the IC design, which seriously harms the intellectual property interests of circuit designers. To prevent IC design theft, it is necessary to hide the functions of the IC during the design phase to avoid the above security threats. Since logic encryption can protect potential attackers at any position in the IC supply chain, including untrusted manufacturing plants, testing institutions, end users, etc. Therefore, logic encryption has attracted great interest from researchers. Logic encryption is a key-based hardware obfuscation method, and the additional logic elements inserted are usually called key gates. After adding key gates, for at least one correct key input, the original output of the circuit remains unchanged; for other incorrect key inputs, the circuit will produce incorrect outputs. In this way, only the circuit designer knows the correct key input.

[0003] Evaluating the security of encrypted circuits through an analysis method based on the functional output of the circuit can effectively help circuit designers and users understand the security and security vulnerabilities of the circuit, help users avoid the risk of being attacked, and help designers improve the security of encrypted circuits.

[0004] Currently, research on logic encryption attacks at home and abroad mainly includes structural analysis attacks and circuit function analysis attacks, such as SAT attack research based on modern SAT solvers. However, the SAT method cannot effectively analyze SAT-Hard circuits, and existing circuit key analysis methods often can only analyze one encryption method, lacking universality. Summary of the Invention

[0005] To solve the above technical problems, the present invention proposes a function analysis method and system for logic encryption circuits, including:

[0006] On the one hand, the present invention proposes a function analysis method for logic encryption circuits, including the following steps:

[0007] S1: Obtain the activated encryption circuit and the target encryption circuit in the market, and determine the original input bits, key input bits, and output bits of the target encryption circuit;

[0008] S2: Use the activated encryption circuit to generate a training dataset, where the dataset includes a specified number of correct input-output pairs, and the correct input-output pairs are all constructed according to the distinguishable input sequence;

[0009] The distinguishable input sequence can distinguish at least two different keys for a group of randomly generated original input vectors at least two different keys and

[0010] S3: Initialize the parameters of the improved particle swarm optimization algorithm according to the original input bits, key input bits, and output bits of the target encryption circuit, and set the fitness of a specific individual in the population on the preset dataset as the fitness function;

[0011] S4: Calculate the fitness of the initialized particle swarm according to the fitness function to obtain the individual extreme value, the group extreme value, and the global extreme value, and let the individual learn from the individual extreme value and the group extreme value according to the learning factor to generate a new population;

[0012] S5: Determine whether a new population needs to be regenerated according to the global extreme value;

[0013] S6: Determine whether the improved particle swarm optimization algorithm has reached the maximum number of iterations. If the maximum number of iterations is reached, the algorithm iteration ends and the global optimal value is obtained. If the termination condition is not reached, repeat S3 - S6;

[0014] S7: After obtaining the optimal value, calculate the actual accuracy of the final key according to the fitness function using the activated encryption circuit, and evaluate the security of the encryption circuit with this accuracy.

[0015] Preferably, using the activated encryption circuit to generate a training dataset includes:

[0016] Set the size of the dataset to P, select the distinguishable input sequences that are twice the size of the dataset from the activated encryption circuit, and sort them according to the distinguishable ability of each distinguishable input sequence, and select the first half of the distinguishable input sequences with higher distinguishable ability as the final dataset.

[0017] Furthermore, the distinguishable ability includes:

[0018]

[0019] where D k represents the distinguishable ability of the k-th distinguishable input sequence, S represents the number of randomly generated keys, s kS represents the number of distinguished random keys among S random keys, and P represents the number of data sets.

[0020] Preferably, the improved particle swarm optimization algorithm includes:

[0021] Using a genetic algorithm guided by the global optimal value to re-optimize the population.

[0022] Preferably, initialize the parameters of the improved particle swarm optimization algorithm according to the original input bit number, key input bit number, and output bit number of the target encryption circuit, including: the number of populations n, the maximum number of iterations G, the learning factors a and b, the judgment generation number t for whether to regenerate the population, and initialize each individual in the population as a binary sequence composed of random 0s and 1s according to the sequences of 0s and 1s formed by the original input bit number, key input bit number, and output bit number.

[0023] Preferably, calculate the fitness of the initialized particle swarm according to the fitness function, including:

[0024]

[0025] Among them, P represents the number of data sets, N represents the number of bits of the logical circuit output vector, HM represents the function for calculating the Hamming distance between vectors, F represents the fitness value of an individual, and the closer the F value is to 1, the better the fitness of the individual, C lock represents the functional function of the encryption circuit, represents the original input of a circuit in the preset data set, represents the key input of the encryption circuit, C oracle represents the activated functional function of the encryption circuit.

[0026] Preferably, learn the individual towards the individual extreme value and the group extreme value according to the learning factors to generate a new population, including:

[0027] Learning towards the individual extreme value:

[0028]

[0029] Learning towards the group extreme value:

[0030]

[0031] Among them, represents the generated new population after learning, Pbest represents the individual extreme value, Genbest represents the group extreme value, a and b respectively represent the first and second probabilities, represents the j-th bit of the particle to be optimized in the i-th iteration.

[0032] Preferably, judge whether to regenerate a new population according to the global extreme value, including:

[0033] Whether the current global extreme value has not been improved for t consecutive iterations. If not, the algorithm enters the genetic algorithm stage and regenerates a new population based on the current population.

[0034] Furthermore, when the algorithm enters the genetic algorithm stage and regenerates a new population based on the current population, it includes:

[0035] Using the binary tournament selection method based on elitist retention as the selection operator of the algorithm. Each time, a certain number of individuals are taken out from the current population, and the individual with the best fitness value is selected according to the fitness value of each individual. Repeat this operation until the scale of the new population reaches the scale of the original population to obtain a new population;

[0036] Using the basic single-point crossover as the crossover operator of the algorithm. Select two different individuals with different gene positions in the new population after elitist retention, and randomly select a position with different corresponding gene positions for the two selected individuals to perform crossover to generate two new individuals;

[0037] Perform a mutation operation on the new population after crossover processing. Determine the parameter mutation bit number flip, randomly determine an integer n between 1 and flip, and randomly select n positions of the current individual for inversion to obtain the final new population.

[0038] On the other hand, the present invention proposes a functional analysis system for a logic encryption circuit, including: a circuit calculation module, a data set generation module, an algorithm calculation module, a key output and verification module;

[0039] The circuit calculation module loads the activated encryption circuit and the target encryption circuit, and according to the specified input vector, calculates the corresponding circuit response through calculation, that is, the circuit output vector, population fitness calculation, and accuracy verification of the optimal key;

[0040] The data set generation module generates a specific data set according to preset requirements;

[0041] The algorithm calculation module loads the preset functional analysis algorithm, sets custom parameters, and uses the circuit calculation module to calculate the fitness of the current population in real time to iteratively optimize the key;

[0042] The key output and verification module further verifies the accuracy of the finally generated optimal key.

[0043] Advantages of the present invention: Based on the improved particle swarm optimization algorithm, the present invention realizes a functional analysis method for logic encryption circuits that is more universal than existing key analysis methods, improving the success rate, accuracy, and universality of the logic encryption security analysis process. At the same time, it can effectively help integrated circuit designers understand the security and security vulnerabilities of circuits, help users avoid the risk of being attacked, and help designers improve the security of circuit designs. In addition, a functional analysis system for logic encryption circuits proposed by the present invention integrates a functional analysis method for logic encryption circuits of the present invention, and can perform security tests on logic encryption circuits more simply and quickly. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 Schematic diagram of a functional analysis method for a logic encryption circuit provided in this embodiment;

[0045] Figure 2 Schematic diagram of an individual optimization method provided in this embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0047] A functional analysis method for a logic encryption circuit, as Figure 1 shown, includes:

[0048] S1: Obtain the activated encryption circuit and the target encryption circuit on the market, and determine the original input bits, key input bits, and output bits of the target encryption circuit;

[0049] S2: Use the activated encryption circuit to generate a training data set, where the data set includes a specified number of correct input-output pairs, and the correct input-output pairs are all constructed according to the distinguished input sequences;

[0050] S3: Initialize the algorithm parameters according to the original input bits, key input bits, and output bits of the target encryption circuit, and set the fitness of a specific individual in the population on the preset data set as the fitness function;

[0051] Perform iterative operations using the improved particle swarm optimization algorithm, that is, perform iterative optimization using the binary particle swarm optimization algorithm. To improve the global search ability of the algorithm in the later stage, use the genetic algorithm guided by the global optimal value to re-optimize the population;

[0052] S4: Calculate the fitness of the initialized particle swarm according to the fitness function, obtain the individual extreme value, the swarm extreme value, and the global extreme value, and let the individuals learn from the individual extreme value and the swarm extreme value according to the learning factor to generate a new population;

[0053] S5: Judge whether a new population needs to be regenerated according to the global extreme value;

[0054] S6: Judge whether the improved particle swarm algorithm reaches the maximum number of iterations. If the maximum number of iterations is reached, the algorithm iteration ends and the global optimal value is obtained. If the termination condition is not reached, repeat S3 - S6;

[0055] S7: After obtaining the optimal value, calculate the actual accuracy of the final key using the activated encryption circuit, and evaluate the security of the encryption circuit based on this accuracy.

[0056] The differentiated input sequence includes:

[0057] For a group of randomly generated original input vectors It can distinguish at least two different keys and

[0058] Generating a training data set using the activated encryption circuit includes:

[0059] It is basically impossible to calculate the fitness value of a certain candidate key using all possible input - outputs of the logical encryption circuit. Therefore, consider using a differentiated input sequence with the ability to distinguish different keys to construct a data set, and calculate the fitness value of the individuals in the population based on this. First, set the size P of the data set, then generate twice this number of differentiated input sequences from the activated encryption circuit, and sort them according to the differentiation ability of each differentiated input sequence, and then select the first - half of the differentiated input sequences with higher differentiation ability as the final data set.

[0060] Generating a differentiated input sequence from the activated encryption circuit:

[0061]

[0062] Among them, represents the original input of a logic circuit, represent different random key inputs respectively, and C lock represents the functional function of the encryption circuit.

[0063] The differentiation ability includes:

[0064]

[0065] Among them, D krepresents the discrimination ability of the k-th differentiated input sequence, S represents the number of randomly generated keys, S k represents the number of randomly generated keys distinguished among the S random keys, and P is the preset number of data sets.

[0066] Initialize the algorithm parameters, including: the number of populations n, the maximum number of iterations G, the learning factors a and b, the judgment algebra t for whether to regenerate the population. According to the circuit input, and since the key input and the circuit output are sequences composed of 0 and 1, each individual in the population is initialized as a binary sequence composed of random 0s and 1s.

[0067] Calculate the fitness of the initialized particle swarm according to the fitness function, including:

[0068]

[0069] where P represents the number of data sets, N represents the number of bits of the logic circuit output vector, HM represents the function for calculating the Hamming distance between vectors, F represents the fitness value of an individual, and the closer the F value is to 1, the better the fitness of the individual, C lock represents the functional function of the encryption circuit, represents the original input of a circuit in the preset data set, represents the key input of the encryption circuit, C oracle represents the activated functional function of the encryption circuit.

[0070] Calculate the fitness of the initialized particle swarm according to the fitness function, obtain the individual extreme value, the population extreme value, and the global extreme value. Each particle in the population learns from the individual extreme value and the population extreme value according to the learning factors a and b respectively to generate a new population. As Figure 2 shown, considering the j-th bit of the particle to be optimized, the value of this bit will be replaced by the j-th bit of the individual extreme value with probability a. The learning process of the particle to be optimized for the population extreme value is similar to the above. Figure 2 in which the values of the 3rd and 5th bits of the individual to be optimized will be replaced by the values of the corresponding positions of the individual extreme value;

[0071] The individual extreme value is the individual with the best fitness value in the historical state of the individual, the population extreme value is the individual with the best fitness value in the current iteration process, and the global extreme value is the individual with the best fitness value in all iteration processes;

[0072] Considering the j-th bit of the particle to be optimized, the value of this bit will be replaced by the j-th bit of the individual extreme value with probability a:

[0073]

[0074] After the particle to be optimized has learned its personal best value, it then learns the global best value. Considering the j-th bit of the particle to be optimized, the value of this bit is replaced by the j-th bit of the global best value with probability b, where Genbest represents the global best value and i is the iteration number.

[0075]

[0076] Among them, represents the newly generated population after learning, Pbest represents the personal best value, Genbest represents the global best value, and a and b respectively represent the first and second probabilities. represents the j-th bit of the particle to be optimized in the i-th iteration.

[0077] The above binary-based learning strategy has a simple process and a fast convergence speed, but it is prone to falling into local optimum. Therefore, it is necessary to judge in real time whether a new population needs to be regenerated. The judgment condition is whether the current global optimum has not been improved for t consecutive generations, where the value of t needs to refer to the iteration number G. If so, the algorithm enters the genetic algorithm stage, and a new population is regenerated according to the current population to improve the diversity of the population.

[0078] Whether the current global optimum has not been improved for t consecutive iterations. If not, the algorithm enters the genetic algorithm stage, and a new population is regenerated according to the current population.

[0079]

[0080] Among them, isTrue represents the decision variable for determining whether a new population needs to be regenerated, i is the current iteration number, Gbestm represents the global optimal fitness value of the m-th generation, and it is judged whether a new population needs to be regenerated according to the value of isTrue.

[0081] When the algorithm enters the genetic algorithm stage and a new population is regenerated according to the current population, it includes:

[0082] For the three operations of the genetic algorithm:

[0083] The binary tournament selection method based on elitist retention is used as the selection operator of the algorithm. Because although the subsequent crossover and mutation operations can increase diversity, they may also destroy the current optimal individual and cause the population to fall into local degradation. Therefore, elitist retention needs to be considered.

[0084] The basic single-point crossover is used as the crossover operator of the algorithm. By the selection process, two different individuals are selected, and it is required that these two individuals have at least two different gene positions. Then a position with different corresponding gene positions is randomly selected for crossover to generate two new individuals.

[0085] Finally, there is the mutation operation. Since the number of key bits of the logic encryption circuit is not fixed. For example, 64-bit or 128-bit keys can be selected. Therefore, the mutation operation needs to consider the actual number of encryption key bits. First, determine the parameter mutation bit number flip (for example, mutate no more than 1 / 10 of the key bits), and its value is determined by the following formula. Then, randomly determine an integer n between 1 and flip. Finally, randomly select n positions of the current individual for inversion.

[0086]

[0087] Among them, flip represents the parameter mutation bit number, and L represents the key input bit number of the encryption circuit. represents rounding up.

[0088] After obtaining the optimal value, calculate the actual accuracy of the final key using the activated encryption circuit according to the fitness function:

[0089]

[0090] Among them, N represents the number of bits of the logic circuit output vector. represents a random original input, P * represents the total number of represents the optimal value finally obtained by S6, HM represents the function for calculating the Hamming distance between vectors, F * represents the final actual accuracy of the key, F * The closer the value is to 1, the better the accuracy of the key. C lock represents the functional function of the encryption circuit, C oracle represents the functional function of the activated encryption circuit.

[0091] A functional analysis system for logic encryption circuits includes: a circuit calculation module, a data set generation module, an algorithm calculation module, a key output and verification module;

[0092] The circuit calculation module loads the activated encryption circuit and the target encryption circuit, and according to the specified input vector, obtains the corresponding circuit response through calculation, that is, the circuit output vector, calculates the population fitness, and verifies the accuracy of the optimal key;

[0093] The data set generation module generates a specific data set according to preset requirements;

[0094] The algorithm calculation module loads the preset functional analysis algorithm, sets custom parameters, and uses the circuit calculation module to calculate the fitness of the current population in real time to iteratively optimize the key;

[0095] The key output and verification module further verifies the accuracy of the finally generated optimal key.

[0096] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art will understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A functional analysis method for logic encryption circuits, characterized in that Including: S1: Obtain the activated encryption circuit and the target encryption circuit in the market, and determine the original input bit number, key input bit number, and output bit number of the target encryption circuit; S2: Use the activated encryption circuit to generate a training data set, where the data set includes a specified number of correct input-output pairs, and the correct input-output pairs are all constructed according to the distinguishing input sequence; The distinguishing input sequence is for a set of randomly generated original input vectors can distinguish at least two different keys and S3: Initialize the parameters of the improved particle swarm optimization algorithm according to the original input bit number, key input bit number, and output bit number of the target encryption circuit, and set the fitness of a specific individual in the population on the preset data set as the fitness function; S4: Calculate the fitness of the initialized particle swarm according to the fitness function to obtain the individual extreme value, population extreme value, and global extreme value, and make the individual learn towards the individual extreme value and population extreme value according to the learning factor to generate a new population; S5: Judge whether a new population needs to be regenerated according to the global extreme value; Judging whether a new population needs to be regenerated according to the global extreme value includes: Whether the current global extreme value has not been improved for t consecutive iterations. If not, the algorithm enters the genetic algorithm stage and regenerates a new population according to the current population; The algorithm enters the genetic algorithm stage and regenerates a new population according to the current population, including: Use the binary tournament selection method based on elitist retention as the selection operator of the algorithm. Each time, a certain number of individuals are taken out from the current population, and the individual with the best fitness is selected according to the fitness value of each individual. Repeat this operation until the size of the new population reaches the size of the original population to obtain a new population; Use the basic single-point crossover as the crossover operator of the algorithm. Select two different individuals with different gene positions in the new population after elitist retention, and randomly select a position with different corresponding gene positions for the selected two individuals to perform crossover to generate two new individuals; Perform a mutation operation on the new population after crossover processing. Determine the parameter mutation bit number flip, randomly determine an integer n between 1 and flip, and randomly select n positions of the current individual for inversion to obtain the final new population; S6: Judge whether the improved particle swarm optimization algorithm has reached the maximum number of iterations. If it reaches the maximum number of iterations, the algorithm iteration ends and the global optimal value is obtained. If the termination condition is not reached, repeat S3 - S6; S7: After obtaining the optimal value, calculate the actual accuracy of the final key according to the fitness function using the activated encryption circuit, and evaluate the security of the encryption circuit with this accuracy.

2. The functional analysis method for a logic encryption circuit according to claim 1, characterized in that Using the activated encryption circuit to generate a training data set includes: Set the size of the data set to P, select the distinguishing input sequences that are twice the size of the data set from the activated encryption circuit, and sort them according to the distinguishing ability of each distinguishing input sequence, and select the first half of the distinguishing input sequences with higher distinguishing ability as the final data set.

3. The functional analysis method for a logic encryption circuit according to claim 2, characterized in that The distinguishing ability includes: Among them, D k represents the discrimination ability of the k-th differentiated input sequence, S represents the number of randomly generated keys, and s k represents the number of randomly generated keys distinguished among the S random keys, and P represents the number of data sets.

4. A functional analysis method for a logic encryption circuit according to claim 1, characterized in that The improved particle swarm optimization algorithm includes: Use a genetic algorithm guided by the global optimal value to re-optimize the population.

5. The functional analysis method for a logic encryption circuit according to claim 1, characterized in that Initialize the parameters of the improved particle swarm optimization algorithm according to the number of bits of the original input, key input, and output of the target encryption circuit, including: the number of populations n, the maximum number of iterations G, the learning factors a and b, and the judgment generation number t for whether to regenerate the population. Initialize each individual in the population as a binary sequence composed of random 0s and 1s according to the sequences of 0s and 1s that the number of bits of the original input, key input, and output are all composed of.

6. The functional analysis method for a logic encryption circuit according to claim 1, wherein Calculate the fitness of the initialized particle swarm according to the fitness function, including: Among them, P represents the number of data sets, N represents the number of bits of the output vector of the logic circuit, HM represents the function for calculating the Hamming distance between vectors, F represents the fitness value of an individual, and the closer the F value is to 1, the better the fitness of the individual. C lock represents the functional function of the encryption circuit, represents the original input of a circuit in the preset data set, represents the key input of the encryption circuit, C oracle represents the functional function of the activated encryption circuit.

7. A functional analysis method for a logic encryption circuit according to claim 1, characterized in that Learn the individual to the individual extreme value and the group extreme value according to the learning factor to generate a new population, including: Learn from the individual extreme value: Learn from the group extreme value: Among them, represents the newly generated population after learning, Pbest represents the individual extreme value, Genbest represents the population extreme value, and a and b respectively represent the first and second probabilities. represents the j-th bit of the particle to be optimized in the i-th iteration.

8. A functional analysis system for a logic encryption circuit, which is used to implement a functional analysis method for a logic encryption circuit as described in claims 1-7, characterized in that, Including: Circuit calculation module, dataset generation module, algorithm calculation module, key output and verification module; The circuit calculation module loads the activated encryption circuit and the target encryption circuit, and according to the specified input vector, obtains the corresponding circuit response through calculation, that is, the circuit output vector, calculates the population fitness and verifies the accuracy of the optimal key; The dataset generation module generates a specific dataset according to the preset requirements; The algorithm calculation module loads the preset function analysis algorithm, sets the custom parameters, and uses the circuit calculation module to calculate the fitness of the current population in real time to iteratively optimize the key; The key output and verification module further verifies the accuracy of the finally generated optimal key.