Method and device for measuring the concealment of hardware Trojans based on control difficulty analysis

By analyzing the gate-level netlist and combining it with the clock signal status, the control difficulty value of the hardware Trojan is calculated, which solves the problem of low accuracy in hardware Trojan detection and achieves more accurate hardware Trojan detection.

CN118779933BActive Publication Date: 2025-09-30NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410787633.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-18
Publication Date
2025-09-30
Estimated Expiration
2044-06-18

AI Technical Summary

Technical Problem

The existing technology for hardware Trojan detection has the following problems: heavy reliance on test stimuli, low detection accuracy due to the diversity of hardware Trojan forms, and inaccurate measurement of the concealment of clock signal influence.

Method used

A method based on control difficulty analysis is adopted to parse the gate-level netlist, analyze clock signal anomalies, calculate the control difficulty values ​​of combinational logic gates and sequential logic gates, and combine the clock signal status to accurately measure the concealment of hardware Trojans and eliminate the dependence on test stimuli and the influence of clock signals.

Benefits of technology

The accuracy of hardware Trojan detection is improved, the dependence on test stimulus is eliminated, the influence of hardware Trojan morphology and clock signal on stealth measurement is ensured, and more accurate hardware Trojan detection is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118779933B_ABST
    Figure CN118779933B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and device for measuring the concealment of hardware Trojans based on control difficulty analysis. The method comprises the following steps: step S01. parsing the logic gate circuits in the gate-level netlist under test; step S02. determining whether the clock signal is abnormal; step S03. determining the type of each logic gate circuit; if it is a combinational logic gate circuit, calculating the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit according to the type of the logic gate; if it is a sequential logic gate circuit, calculating the control difficulty values ​​C0 and C1 of the sequential logic circuit according to whether the clock signal is abnormal; step S04. calculating the corresponding concealment value based on the C0 and C1 control difficulty values ​​of each logic gate circuit to evaluate the concealment degree of each logic gate circuit. The present invention can eliminate the dependence on test stimuli and suppress the influence of hardware Trojan morphology and clock signals on concealment measurement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of integrated circuit hardware Trojan detection, and in particular to a method and device for measuring the concealment of hardware Trojans based on control difficulty analysis. Background Art

[0002] Measuring the trigger characteristics of hardware Trojans is a crucial step in detecting hardware Trojans in integrated circuits. Existing techniques typically employ quantitative criteria to label signals with low toggle rates or difficult controllability as suspected hardware Trojans. Hardware Trojan functions consist of logic gates, and the same function can exhibit varying gate-level representations. This leads to a diverse range of hardware Trojan forms. Traditional gate-level netlist detection methods, such as functional testing, typically generate trigger stimuli based on the hardware Trojan's circuit structure, calculate the signal's on / off activity probability, and use a threshold to classify the signal as either a normal signal or a hardware Trojan signal. However, these analysis methods based on signal toggle rates and coverage require test stimuli to activate the hardware Trojan, resulting in a heavy reliance on test stimuli. However, test stimuli for the circuit under test are often incomplete. For example, during netlist-level hardware Trojan detection for third-party IP cores, it is often difficult to obtain high-coverage test stimuli. This results in a large number of low-activity signals within the circuit, resulting in low hardware Trojan detection accuracy.

[0003] Traditional digital circuit controllability analysis methods, based on controllability metrics, can eliminate test dependencies. However, the signal concealment metrics based on control difficulty values ​​produce inconsistent results for different Trojan forms. This can be affected by hardware Trojan variations and cannot be eliminated. For example, a Trojan triggered by four signals can consist of either a single four-input AND gate or three two-input AND gates. The control difficulty values ​​for these two configurations are: when control is 0, the result is 2 (CC0=2), and when control is 1, the result is 5 (CC1=5). For CC0=3 and CC1=7, the measurement results differ between the two configurations.

[0004] Furthermore, because the control difficulty value is used to measure the concealment of trigger signals, the control difficulty of the clock in different situations is not considered. This can lead to distortion in the measurement of hardware Trojan concealment characteristics, resulting in inaccurate measurement of hardware Trojan trigger characteristics and, consequently, an inaccurate range of hardware Trojan detection. For example, when the clock signal has no control difficulty—for example, when the clock is derived solely from the system clock via a NOT gate or a BUFF gate—the concealment of the trigger output should be solely related to the concealment of the input signal, not the clock signal. However, when measuring the concealment of two flip-flops in series (e.g., FD1 and FD2 in series) based on the control difficulty value, the influence of the clocks is cumulative. For example, if the control difficulty values ​​of flip-flop FD1 are CC0=3 and CC1=3, and the control difficulty values ​​of flip-flop FD2 are CC0=5 and CC1=5, the concealment measurement results for the two flip-flops will be inconsistent. Summary of the Invention

[0005] The technical problem to be solved by the present invention is: In response to the above-mentioned problems in the prior art, a method and device for measuring the concealment of hardware Trojans based on control difficulty analysis are provided, which can accurately measure the concealment of hardware Trojans, eliminate dependence on test stimuli, and suppress the influence of hardware Trojan morphology and clock signals on concealment measurement, thereby helping to improve the detection accuracy of hardware Trojans.

[0006] In order to solve the above technical problems, the technical solution adopted by the present invention is:

[0007] A method for measuring the stealthiness of hardware Trojans based on control difficulty analysis, comprising the following steps:

[0008] Step S01: Analyze the logic gate circuit in the gate-level netlist under test;

[0009] Step S02: Analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test;

[0010] Step S03: Determine the type of each logic gate circuit. If it is a combinational logic gate circuit, calculate the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit according to the different logic gate types. If it is a sequential logic gate circuit, calculate the control difficulty values ​​C0 and C1 of the sequential logic circuit based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​for controlling the primary input to logic 0 and logic 1, respectively.

[0011] Step S04: Calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit to evaluate the concealment degree of each logic gate circuit.

[0012] Furthermore, in step S02, if it is determined that the clock signal only passes through a NOT gate or a cache gate, it is determined to be a clock signal generated by a normal clock tree; otherwise, it is determined to be an abnormal clock signal.

[0013] Furthermore, in step S03, if it is a non-sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the non-sequential logic gate circuit are calculated according to different logic gate types.

[0014] Furthermore, the control difficulty values ​​C0 and C1 of the input and output nodes are used to directly calculate the control difficulty values ​​C0 and C1 of each logic gate unit. If it is an AND gate, C1=C1(a)+C1(b), C0=Min(C0(a), C0(b)), a and b are the two input nodes of the AND gate respectively; if it is an OR gate, C1=Min(C1(a), C1(b)), C0=C0(a)+C0(b), a and b are the two input nodes of the OR gate respectively; if it is a NOT gate, C1=C0(a), C0=C1(a), a is the input node of the NOT gate; if it is a NAND gate, C1=Min(C0(a), C0(b)), C0=C1(a)+C1(b) a and b are the two input nodes of the NAND gate respectively; if it is a NOR gate, C1=C0(a)+C0(b), C0=Min(C1(a),C1(b)), a and b are the two input nodes of the NOR gate respectively; if it is a buffer gate, C1=C1(a); C0=C0(a), a is the input node of the buffer gate; if it is an XOR gate, C1= Min(C0(a)+C1(b),C1(a)+C0(b)), C0= Min(C0(a)+C0(b),C1(a)+C1(b)), a and b are the two input nodes of the XOR gate respectively; if it is an XNOR gate, C1= Min(C0(a)+C0(b),C1(a)+C1(b)), C0= Min(C0(a)+C1(b),C1(a)+C0(b)), a and b are the two input nodes of the XOR gate respectively.

[0015] Furthermore, in step S03, if it is a sequential logic gate circuit, when the clock signal is a normal signal, the control difficulty values ​​C0 and C1 of the clock signal are configured to 0, and the control difficulty values ​​C0 and C1 of the input node are directly used to calculate the C0 and C1 control difficulty values ​​of the sequential logic circuit; when the clock signal is an abnormal signal, the control difficulty values ​​C0 and C1 of the input node and the control difficulty values ​​C0 and C1 of the clock signal are used to calculate the C0 and C1 control difficulty values ​​of the sequential logic circuit respectively.

[0016] Furthermore, when it is a sequential logic circuit and a trigger, if the clock signal clk is a normal signal, C1=C1(D), C0=C0(D), D is the input node of the trigger; if the clock signal clk is an abnormal signal, C1=C1(D)+C0(clk)+C1(clk), C0=C0(D)+C0(clk)+C1(clk), C0(clk) and C1(clk) are the control difficulty values ​​C0 and C1 of the clock signal respectively.

[0017] Furthermore, in step S03, the concealment value Con of each logic gate unit is calculated according to the following formula:

[0018]

[0019] in, Indicates the maximum value of the control difficulty values ​​C0 and C1, Indicates the minimum value of the control difficulty values ​​C0 and C1.

[0020] Furthermore, after step S04, the method further includes classifying the one-dimensional data set formed by the concealment value using a classification algorithm to classify the data set into normal signals and suspicious hardware Trojan signals, and finally obtaining a suspicious hardware Trojan list.

[0021] A device for measuring the concealment of hardware Trojans based on control difficulty analysis, comprising:

[0022] Gate-level netlist parsing module, used to parse the logic gate circuits in the gate-level netlist under test;

[0023] The clock tree analysis module is used to analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test;

[0024] A control difficulty analysis module is used to determine the type of each logic gate circuit. If it is a combinational logic gate circuit, the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit are calculated according to the type of the logic gate. If it is a sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the sequential logic circuit are calculated based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​of controlling the primary input to logic 0 and logic 1, respectively.

[0025] The concealment evaluation module is used to calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit, so as to evaluate the concealment degree of the logic gate circuit.

[0026] A computer device includes a processor and a memory, wherein the memory is used to store a computer program, and the processor is used to execute the computer program to perform the above method.

[0027] Compared with the prior art, the advantages of the present invention are: the present invention performs control difficulty analysis on each logic gate circuit in the gate-level netlist, calculates the control difficulty value of each logic gate circuit according to the type of logic gate circuit and the abnormality of the clock signal, and removes the transmission difficulty of the control difficulty value at each level of logic gate for the combinational logic gate circuit to obtain the control difficulty value; for the sequential logic gate circuit, the control difficulty value of the clock signal is considered when the clock is abnormal, and then the concealment value is calculated based on the control difficulty value, and the concealment degree of the hardware Trojan trigger is measured by the concealment value, thereby solving the problem of measuring the trigger characteristics of the hardware Trojan at the netlist level. It can not only improve the accuracy of the measurement of the trigger characteristics of the hardware Trojan, but also eliminate the dependence of the netlist-level hardware Trojan detection on the test stimulus, and suppress the influence of the hardware Trojan morphology and clock signal on the concealment measurement. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 Schematic diagram of the implementation flow of the method for measuring the concealment of hardware Trojans based on control difficulty analysis in this embodiment.

[0029] Figure 2 This is a schematic diagram of the implementation process of hardware Trojan detection based on the control difficulty analysis hardware Trojan concealment measurement method of this embodiment. DETAILED DESCRIPTION

[0030] Methods based on controllability metrics typically use a controllability calculation method tailored to the type of logic gate, ultimately determining the controllability value for each logic gate. Controllability is the ease with which the logic state of an internal pin can be controlled from the circuit's primary input. The ease with which a pin can be controlled to a logical 1 / 0 from the primary input is called the 1 / 0 controllability of that pin. Controllability values ​​are then categorized, with those with higher controllability values ​​being classified as suspicious hardware malware signals. Table 1 shows the method for calculating controllability values ​​for each logic gate circuit in the controllability metric-based method.

[0031] Table 1: Controllability value calculation method

[0032]

[0033] When measuring controllability using the controllability measurement method described above, the controllability measurement results vary for different Trojan forms. For example, a Trojan triggered by four signals can be constructed from either a single four-input AND gate or three two-input AND gates. If the controllability value of the Trojan input is 1, and the output of the Trojan constructed from a single four-input AND gate is 0, the controllability value is 1 + 1 = 2; if the output is 1, the controllability value is (1 + 1 + 1 + 1) + 1 = 5. This means that when the controllability of the Trojan is 0, the result is 2 (CC0 = 2), and when the controllability is 1, the result is 5 (CC1 = 5). When the output of the Trojan consisting of three two-input AND gates is 0, the controllability value = Min((1+1), (1+1)) + 1 = 3; when the output is 1, the controllability value = ((1+1) + 1) + ((1+1) + 1) + 1 = 7, CC0 = 3, CC1 = 7. That is, the measurement results in the two forms are deviated, resulting in the problem of distorted controllability values.

[0034] The present invention addresses the problem of measuring the trigger characteristics of hardware Trojans during netlist-level hardware Trojan detection of integrated circuits. By analyzing the control difficulty of signals taking values ​​of 0 and 1, the present invention removes the transmission difficulty of the control difficulty value at each level of logic gates for combinational logic gate circuits. Meanwhile, the control difficulty of clocks under different circumstances is considered. For sequential logic gate circuits, the control difficulty values ​​of logic gates 0 and 1 are statically calculated based on whether the clock is abnormal. A concealment value is then calculated from the control difficulty value, and the concealment degree of the hardware Trojan trigger is measured using the concealment value. This solves the problem of measuring the trigger characteristics of hardware Trojans at the netlist level. Furthermore, the present invention improves the accuracy of the measurement of the trigger characteristics of hardware Trojans, eliminates the dependence of netlist-level hardware Trojan detection on test stimuli, and suppresses the influence of the hardware Trojan morphology and clock signals on the concealment measurement.

[0035] like Figure 1 As shown, the steps of the hardware Trojan concealment measurement method based on control difficulty analysis in this embodiment include:

[0036] Step S01. Gate-level netlist analysis: analyzing the logic gate circuits in the gate-level netlist under test.

[0037] Different process libraries require corresponding calls to different gate-level units. This embodiment targets the data file of the gate-level netlist, first parses the logic gate units corresponding to different process nodes, maps them to basic units such as AND, OR, NOT, and triggers, and parses to obtain multiple logic gate circuits.

[0038] Step S02. Clock tree analysis: Analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test.

[0039] Specifically, starting from the clock signal in the netlist, the clock signal's connections are analyzed. If the clock signal is determined to have passed only through a NOT gate or a BUFF gate, it is considered a normal clock signal generated by the clock tree; otherwise, it is considered an abnormal clock signal. Subsequently, the control difficulty value of the sequential logic gate is calculated using different methods based on the abnormal state of the clock signal. This ensures that the stealth value is consistent with the stealth analysis results, taking into account different clock signal states, and avoids distortion in the measurement of the hardware Trojan's stealth characteristics.

[0040] Step S03. Control difficulty analysis: Determine the type of each logic gate circuit. If it is a combinational logic gate circuit, calculate the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit according to the different logic gate types. If it is a sequential logic gate circuit, calculate the control difficulty values ​​C0 and C1 of the sequential logic circuit based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​of controlling the primary input to logic 0 and logic 1, respectively.

[0041] To quickly and accurately reveal hidden circuits and determine the location of hardware Trojans, this embodiment employs a stealth measurement method to narrow the detection range and facilitate further analysis. When signals (including abnormal clock signals) propagate between gates, the difficulty of controlling the signals to 0 or 1 is solely related to the corresponding inputs. This embodiment first calculates the control difficulty values ​​C0 and C1 based on the input node's control difficulty values ​​C0 and C1, depending on the type of logic gate circuit and whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 represent the difficulty of controlling a particular pin to a logic 0 or 1 from the primary input. These values ​​can be expressed as the minimum number of signal evaluations required to set a node to a logic value of 0 or 1. The control difficulty values ​​C0 and C1 are then used to calculate a stealth value to measure stealth.

[0042] In this embodiment, if it is a non-sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the combinational logic gate circuit are calculated based on the controllable metric method, and then the initial value of the control difficulty value is subtracted to obtain the corresponding control difficulty values ​​C0 and C1.

[0043] Specifically, the initial value of the control difficulty value in the SCOAP (Sandia Controllability / Observability Analysis Program) algorithm is 1. Based on the SCOAP algorithm, this embodiment, for different combinational logic gate circuits, subtracts 1 from the control difficulty values ​​C0 and C1 of each combinational logic gate circuit in the SCOAP algorithm to obtain the corresponding control difficulty values ​​C0 and C1. That is, for combinational logic gates such as AND, OR, and NOT, the control difficulty values ​​C0 and C1 are calculated without adding 1 after each logic gate. This ensures that the same Trojan has consistent concealment values ​​in different forms, eliminating the impact of Trojan form diversity.

[0044] In this embodiment, for a sequential logic gate circuit, when the clock signal is normal, the control difficulty values ​​C0 and C1 of the clock signal are set to 0, and the control difficulty values ​​C0 and C1 of the input node are directly used to calculate the control difficulty values ​​C0 and C1 of the sequential logic circuit. When the clock signal is abnormal, that is, when the clock signal is not obtained from a normal clock tree, the control difficulty values ​​C0 and C1 of the input node and the control difficulty values ​​C0 and C1 of the clock signal are used to calculate the control difficulty values ​​C0 and C1 of the sequential logic circuit, respectively. That is, for a sequential logic gate such as a flip-flop, when the clock signal is obtained from a normal clock tree, the control difficulty value of the clock signal is set to 0. When the clock is abnormal, the control difficulty value of the clock signal needs to be additionally calculated. Finally, the control difficulty value of the input node and the control difficulty value of the clock signal are combined to obtain the final control difficulty value of the logic gate circuit, thereby ensuring that the concealment value is consistent with the concealment analysis result.

[0045] The control difficulty value is calculated differently for different clock conditions. For a trigger controlled by a normal clock, the difficulty of outputting 0 and 1 is determined by the difficulty of inputting 0 and 1. For a trigger controlled by an abnormal clock, the difficulty of outputting 0 and 1 is determined by the difficulty of inputting 0 and 1, and is also affected by the control difficulty of the abnormal clock. Therefore, by calculating the control difficulty value based on the abnormal clock state, a more accurate description of the control difficulty of sequential logic gate circuits can be achieved. Subsequent calculations of the concealment based on this control difficulty value can ensure that it is consistent with the results of signal concealment analysis.

[0046] Specifically, if it is an AND gate, C1= C1(a)+ C1(b), C0=Min(C0(a), C0(b)), a and b are the two input nodes of the AND gate respectively; if it is an OR gate, C1=Min(C1(a), C1(b)), C0=C0(a)+C0(b), a and b are the two input nodes of the OR gate respectively; if it is a NOT gate, C1=C0(a), C0=C1(a), a is the input node of the NOT gate; if it is a NAND gate, C1=Min(C0(a), C0(b)), C0=C1(a)+C1(b) a and b are the two input nodes of the NAND gate respectively; if it is a NOR gate, C1=C0(a)+C0(b), C0=Min(C1(a),C1(b)), a and b are the two input nodes of the NOR gate respectively; if it is a buffer gate, C1=C1(a); C0=C0(a), a is the input node of the buffer gate; if it is an XOR gate, C1= Min(C0(a)+C1(b),C1(a)+C0(b)), C0= Min(C0(a)+C0(b),C1(a)+C1(b)), a and b are the two input nodes of the XOR gate respectively; if it is an XNOR gate, C1= Min(C0(a)+C0(b),C1(a)+C1(b)), C0= Min(C0(a)+C1(b),C1(a)+C0(b)), a and b are the two input nodes of the XOR gate respectively. When it is a sequential logic circuit and a trigger, if the clock signal clk is a normal signal, C1= C1(D), C0= C0(D), D is the input node of the trigger; if the clock signal clk is an abnormal signal, C1= C1(D)+C0(clk)+C1(clk), C0= C0(D)+C0(clk)+C1(clk), C0(clk) and C1(clk) are the control difficulty values ​​C0 and C1 of the clock signal, respectively, that is, the control difficulty values ​​of 0 and 1 of the clock signal clk.

[0047] Table 2 Calculation method of control difficulty value

[0048]

[0049] As shown in Table 2, the calculation control difficulty values ​​for different logic gates are:

[0050] Primary input: The difficulty of setting the primary input signal to 0 and 1 is set to 1.

[0051] AND gate: out = AND(a, b). For out = 1, a = 1 and b = 1 must be satisfied, so C1(out) = C1(a) + C1(b); for out = 0, a = 0 or b = 0 must be satisfied, so C0(out) = Min(C0(a), C0(b)).

[0052] OR gate: out = OR(a, b). For out = 1, either a = 1 or b = 1 must be satisfied, so C1(out) = Min(C1(a), C1(b)). For out = 0, both a = 0 and b = 0 must be satisfied, so C0(out) = C0(a) + C0(b).

[0053] NOT gate: out = NOT(a). For out = 1, a = 0 must be satisfied, so C1(out) = C0(a); for out = 0, a = 1 must be satisfied, so C0(out) = C1(a).

[0054] NAND gate: out = NAND(a, b). For out = 1, either a = 0 or b = 0 must be satisfied, so C1(out) = Min(C0(a), C0(b)); for out = 0, both a = 1 and b = 1 must be satisfied, so C0(out) = C1(a) + C1(b).

[0055] NOR gate: out = NOR(a, b). For out = 1, a = 0 and b = 0 must be satisfied, so C1(out) = C0(a) + C0(b); for out = 0, a = 1 or b = 1 must be satisfied, so C0(out) = Min(C1(a), C1(b)).

[0056] Buffer gate: out = BUFF(a). For out = 1, a = 1 must be satisfied, so C1(out) = C1(a); for out = 0, a = 0 must be satisfied, so C0(out) = C0(a).

[0057] XOR gate: out = XOR(a, b). For out = 1, either (a = 0, b = 1) or (a = 1, b = 0) must be satisfied. Therefore, C1(out) = Min(C0(a) + C1(b), C1(a) + C0(b)). For out = 0, either (a = 0, b = 0) or (a = 1, b = 1) must be satisfied. Therefore, C0(out) = Min(C0(a) + C0(b), C1(a) + C1(b)).

[0058] XNOR gate: out = XNOR(a, b). For out = 1, either (a = 0, b = 0) or (a = 1, b = 1) must be satisfied. Therefore, C1(out) = Min(C0(a) + C0(b), C1(a) + C1(b)). For out = 0, either (a = 0, b = 1) or (a = 1, b = 0) must be satisfied. Therefore, C0(out) = Min(C0(a) + C1(b), C1(a) + C0(b)).

[0059] Flip-flop: out = DFF (D, clk). When the clock clk is normal, out = 1 requires D = 1, so C1(out) = C1(D); out = 0 requires D = 0, so C0(out) = C0(D). When the clock clk is abnormal, out = 1 requires D = 1 and the clock transitions from 0 to 1, so C1(out) = C1(D) + C0(clk) + C1(clk); out = 0 requires D = 0 and the clock transitions from 0 to 1, so C0(out) = C0(D) + C0(clk) + C1(clk).

[0060] Step S04. Concealment analysis: Calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit to evaluate the concealment degree of the logic gate circuit.

[0061] Specifically, the concealment value Con of each logic gate unit can be calculated according to the following formula:

[0062]

[0063] in, Indicates the maximum value of the control difficulty values ​​C0 and C1, Indicates the minimum value of the control difficulty values ​​C0 and C1.

[0064] In the above formula (1), if the concealment value is closer to 1, the concealment of the gate node is poorer. Correspondingly, if the concealment value is larger, the concealment of the gate node is stronger. It is understandable that other methods can also be used to calculate the concealment value Con based on the control difficulty values ​​C0 and C1 according to actual needs. The key is to use the control difficulty values ​​C0 and C1 to measure concealment.

[0065] In this embodiment, the control difficulty values ​​C0 and C1 do not take into account the control difficulty value of the clock signal when the clock signal is normal. However, in an abnormal state, the control difficulty value of the clock signal needs to be added. Therefore, when calculating the concealment value of a timing logic gate such as a trigger, the control difficulty of the abnormal clock signal is additionally considered. In addition, in the concealment calculation process, the concealment value of each gate is determined only by the concealment of its input, so that the concealment value can be consistent with the concealment analysis result.

[0066] For example, a Trojan triggered by four signals has a concealment of 1 (C0 = 1) when the Trojan is composed of a four-input AND gate, and (1+1+1+1) = 4 (C1 = 4) when the output is 0. When the Trojan is composed of three two-input AND gates, the concealment of 0 (Min(1, 1) = 1) (C0 = 1) and the concealment of 1 ((1+1) + (1+1) = 4) (C1 = 4)) is the same in both configurations.

[0067] This embodiment does not consider the number of logic gates passed through when calculating the control difficulty value of the combinational logic gate circuit, and distinguishes the impact of normal and abnormal clocks on the measurement when calculating the control difficulty value of the sequential logic gate circuit. In an abnormal state, it is necessary to add the control difficulty value of the clock signal, and then use the control difficulty value to calculate the concealment value to evaluate the concealment of the hardware Trojan. This can make the concealment value consistent with the concealment analysis result under the same hardware Trojan function, different hardware Trojan gate-level forms and different clock conditions, and achieve the same measurement result under the same hardware Trojan and different gate-level manifestation forms.

[0068] Further, such as Figure 2 As shown, after step S04, the process also includes classifying the one-dimensional dataset formed by the concealment values ​​using a classification algorithm into normal signals and suspected hardware Trojan signals, ultimately obtaining a list of suspected hardware Trojans. This allows for rapid and accurate hardware Trojan detection. The classification algorithm can be a k-means algorithm, for example. Specifically, the concealment values ​​are passed to the k-means algorithm in the form of a one-dimensional dataset, where k = 2. Ultimately, the signals are classified into two categories: normal signals with smaller concealment values ​​and suspected hardware Trojan signals with larger concealment values, ultimately obtaining a list of suspected hardware Trojans. The specific classification algorithm can be selected based on actual needs.

[0069] The device for measuring the concealment of hardware Trojans based on control difficulty analysis in this embodiment includes:

[0070] Gate-level netlist parsing module, used to parse the logic gate circuits in the gate-level netlist under test;

[0071] The clock tree analysis module is used to analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test;

[0072] The control difficulty analysis module is used to determine the type of each logic gate circuit. If it is a combinational logic gate circuit, the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit are calculated according to the type of the logic gate. If it is a sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the sequential logic circuit are calculated based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​of controlling the logic gate to logic 0 and logic 1 from the primary input, respectively.

[0073] The concealment evaluation module is used to calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit, so as to evaluate the concealment degree of the logic gate circuit.

[0074] The hardware Trojan concealment measurement device based on control difficulty analysis in this embodiment corresponds one-to-one to the above-mentioned hardware Trojan concealment measurement method based on control difficulty analysis, and will not be described in detail here.

[0075] This embodiment further provides a computer device, including a processor and a memory, wherein the memory is used to store a computer program, and the processor is used to execute the computer program to perform the above method.

[0076] It is understandable that the above method of this embodiment can be executed by a single device, such as a computer or server, etc., and can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In the case of a distributed scenario, one of the multiple devices can only execute one or more steps in the above method of this embodiment, and multiple devices interact to complete the above method. The processor can be implemented in the form of a general-purpose CPU, a microprocessor, an application-specific integrated circuit, or one or more integrated circuits, etc., for executing relevant programs to implement the above method of this embodiment. The memory can be implemented in the form of a read-only memory ROM, a random access memory RAM, a static storage device, and a dynamic storage device. The memory can store an operating system and other application programs. When the above method of this embodiment is implemented by software or firmware, the relevant program code is stored in the memory and called and executed by the processor.

[0077] Those skilled in the art will appreciate that the above-mentioned embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0078] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the concept of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A method for measuring the stealth of hardware Trojans based on control difficulty analysis, characterized in that the steps include: Step S01: Analyze the logic gate circuit in the gate-level netlist under test; Step S02: Analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test; Step S03: Determine the type of each logic gate circuit. If it is a combinational logic gate circuit, calculate the control difficulty values ​​C0 and C1 for the combinational logic gate circuit according to the type of logic gate. If it is a sequential logic gate circuit, calculate the control difficulty values ​​C0 and C1 for the sequential logic circuit based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​for controlling the primary input to logic 0 and logic 1, respectively. Step S04: Calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit to evaluate the concealment degree of each logic gate circuit.

2. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to claim 1 is characterized in that: In step S02 , if it is determined that the clock signal only passes through a NOT gate or a cache gate, it is determined to be a clock signal generated by a normal clock tree; otherwise, it is determined to be an abnormal clock signal.

3. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to claim 1 is characterized in that: In step S03, if the circuit is a non-sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the non-sequential logic gate circuit are calculated according to different logic gate types.

4. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to claim 3, characterized in that: Use the control difficulty values ​​C0 and C1 of the input and output nodes to directly calculate the control difficulty values ​​C0 and C1 of each logic gate unit. If it is an AND gate, C1=C1(a)+C1(b), C0=Min(C0(a),C0(b)), a and b are the two input nodes of the AND gate respectively; if it is an OR gate, C1=Min(C1(a),C1(b)), C0=C0(a)+C0(b), a and b are the two input nodes of the OR gate respectively; If it is a NOT gate, C1=C0(a), C0=C1(a), a is the input node of the NOT gate; if it is a NAND gate, C1= Min(C0(a), C0(b)), C0=C1(a)+C1(b), a and b are the two input nodes of the NAND gate respectively; if it is a NOR gate, C1=C0(a)+C0(b), C0=Min(C1(a), C1(b)), a and b are the two input nodes of the NOR gate respectively; if it is a buffer gate, C1=C1(a); C0=C0(a), a is the input node of the buffer gate; if it is an XOR gate, C1= Min(C0(a)+C1(b), C1(a)+C0(b)), C0= Min(C0(a)+C0(b), C1(a)+C1(b)), a and b are the two input nodes of the XOR gate respectively; if it is an XNOR gate, C1= Min(C0(a)+C0(b),C1(a)+C1(b)), C0= Min(C0(a)+C1(b),C1(a)+C0(b)), a and b are the two input nodes of the XNOR gate respectively.

5. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to claim 1 is characterized in that: In step S03, if it is a sequential logic gate circuit, when the clock signal is a normal signal, the control difficulty values ​​C0 and C1 of the clock signal are configured to 0, and the control difficulty values ​​C0 and C1 of the input node are directly used to calculate the C0 and C1 control difficulty values ​​of the sequential logic circuit; when the clock signal is an abnormal signal, the control difficulty values ​​C0 and C1 of the input node and the control difficulty values ​​C0 and C1 of the clock signal are used to calculate the C0 and C1 control difficulty values ​​of the sequential logic circuit respectively.

6. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to claim 5, characterized in that: When it is a sequential logic circuit and a trigger, if the clock signal clk is a normal signal, C1= C1(D), C0= C0(D), D is the input node of the trigger; if the clock signal clk is an abnormal signal, C1= C1(D)+C0(clk)+C1(clk), C0= C0(D)+C0(clk)+C1(clk), C0(clk) and C1(clk) are the control difficulty values ​​C0 and C1 of the clock signal respectively.

7. The method for measuring the concealment of a hardware Trojan based on control difficulty analysis according to any one of claims 1 to 6, characterized in that: In step S03, the concealment value Con of each logic gate unit is calculated according to the following formula: in, Indicates the maximum value of the control difficulty values ​​C0 and C1, Indicates the minimum value of the control difficulty values ​​C0 and C1.

8. The method for measuring the concealment of hardware Trojans based on control difficulty analysis according to any one of claims 1 to 6, characterized in that: After step S04, the process also includes classifying the one-dimensional data set formed by the concealment value using a classification algorithm, into normal signals and suspicious hardware Trojan signals, and finally obtaining a suspicious hardware Trojan list.

9. A device for measuring the concealment of hardware Trojans based on control difficulty analysis, characterized in that: include: Gate-level netlist parsing module, used to parse the logic gate circuits in the gate-level netlist under test; The clock tree analysis module is used to analyze whether the clock signal is abnormal based on the connection relationship of the clock signal in the gate-level netlist under test; A control difficulty analysis module is used to determine the type of each logic gate circuit. If it is a combinational logic gate circuit, the control difficulty values ​​C0 and C1 of the corresponding combinational logic gate circuit are calculated according to the type of the logic gate. If it is a sequential logic gate circuit, the control difficulty values ​​C0 and C1 of the sequential logic circuit are calculated based on whether the clock signal is abnormal. The control difficulty values ​​C0 and C1 are the difficulty values ​​of controlling the primary input to logic 0 and logic 1, respectively. The concealment evaluation module is used to calculate the corresponding concealment value according to the C0 and C1 control difficulty values ​​of each logic gate circuit, so as to evaluate the concealment degree of the logic gate circuit.

10. A computer device comprising a processor and a memory, wherein the memory is used to store a computer program, wherein: The processor is configured to execute the computer program to perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Trojan infection circuit identification method based on chip netlist characteristics

    CN110287735A

  • System chip hardware Trojan horse detection method and system based on differential amplification controllability

    CN111488629A