Information flow tracking model generation method for LUT-level netlist

By extracting the logical units in the FPGA netlist, adding information tags, building a new LUT module and processing the truth table, and generating the LUT information flow model, the problem that the existing technology cannot automatically generate an accurate information flow model, and the efficient application of the FPGA-level IFT method is realized.

CN119989999APending Publication Date: 2025-05-13NORTHWESTERN POLYTECHNICAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510049588.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art cannot automatically generate accurate information flow models based on FPGA netlists, resulting in limited application of FPGA-level IFT methods.

Method used

A method for generating information flow tracking model for LUT-level netlists is proposed. By extracting the logical units in the LUT netlist, adding information labels, building a new LUT module, obtaining the truth table, and using the preset truth table analysis algorithm to process the truth table, converting it into a Boolean logical expression, and generating the LUT information flow model.

Benefits of technology

It realizes the automatic generation of accurate information flow models based on FPGA netlists, which reduces the computing and storage overhead of generating and maintaining IFT libraries, and solves the obstacles to the application of FPGA-level IFT methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989999A_ABST
    Figure CN119989999A_ABST
Patent Text Reader

Abstract

The invention discloses an information flow tracking model generation method and a security verification method for an LUT-level netlist, and the method comprises the steps: obtaining all original signals of each logic unit, obtaining a tag signal, building a new LUT module based on the original signals and the tag signal of the LUT module, obtaining a new truth table of the LUT module, and carrying out the truth verification of the new truth table. Converting the truth table of the new LUT module into a Boolean logic expression to obtain an LUT information flow model; processing the original signal and the tag signal of the primitive by using a gate-level information flow tracking algorithm to obtain a primitive information flow model; obtaining an assign statement information flow model based on the tag signal of the assign statement; and obtaining an information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model. The technical problem that an accurate information flow model cannot be automatically generated based on the FPGA netlist in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of information flow analysis, and in particular to a method for generating an information flow tracking model and a security verification method for a LUT-level netlist. Background Art

[0002] Information Flow Tracking (IFT) is an effective method for analyzing the details of information / data flow in a computing system, and can be used for security verification and vulnerability detection of integrated circuit designs. Although there are hardware IFT methods at different levels of abstraction, there is still no method to generate an information flow tracking model based on a LUT netlist. This is due to the huge number of possible LUT configurations, and different LUT configurations correspond to different IFT behaviors. Maintaining a complete IFT library containing all the different configurations of IFT logic has unacceptable time and space complexity. Moreover, there are larger LUTs in newer FPGAs. The high computational and storage overhead required to generate and maintain a complete IFT library for IFT logic construction has long been an obstacle to the development of FPGA-level IFT method applications.

[0003] Existing methods, such as gate-level information flow tracing methods, generate information flow based on gate-level netlists, a hardware description code containing basic logic gates such as AND gates and OR gates; RTL-level information flow tracing methods generate information flow based on RTL-level hardware description codes. Summary of the invention

[0004] The main purpose of this application is to provide an information flow tracking model generation method and a security verification method for a LUT-level netlist, aiming to solve the technical problem in the prior art that it is impossible to automatically generate an accurate information flow model based on an FPGA netlist.

[0005] To achieve the above-mentioned purpose, the present application provides a method for generating an information flow tracking model of a LUT-level netlist, comprising: extracting each logic unit based on the LUT netlist, obtaining all original signals of each of the logic units, adding information labels to all the original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive and an assign statement; constructing a new LUT module based on the original signal of the LUT module and the label signal, obtaining the truth table of the LUT module, processing the truth table of the LUT module based on a preset truth table analysis algorithm to obtain the truth table of the new LUT module, and converting the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model; processing the original signal of the primitive and the label signal using a gate-level information flow tracking algorithm to obtain a primitive information flow model; obtaining an assign statement information flow model based on the label signal of the assign statement; and obtaining an information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

[0006] Optionally, the original signal of the LUT module includes multiple input signals and output signals, and the new LUT module includes multiple input signals and output signals, as well as input signal information labels and output signal information labels corresponding one-to-one to the multiple input signals and output signals; the truth table of the LUT module is processed based on the preset truth table analysis algorithm to obtain the truth table of the new LUT module, including: double loop traversal to detect the truth value of any two table items in the LUT module; when the output signals of the two table items are the same, the output signal information label remains unchanged; when the output signals of the two table items are different, 1 is written in the output signal information label; the truth values ​​of the input signals of the two table items of the LUT module are written into the input signals in the two corresponding table items in the new LUT module; if the truth values ​​of the same input signal in the two table items are different, "1" is written in the corresponding input signal information label; otherwise, "-" is written.

[0007] Optionally, the gate-level information flow tracing algorithm is used to process the original signal and the label signal of the primitive to obtain the primitive information flow model, including: using the primitive input signal, primitive output signal, primitive input information label and primitive output information label to construct the input and output logical expressions of each of the primitives, and determining the primitive information flow model based on each of the input and output logical expressions.

[0008] Optionally, the primitive includes an FDRE primitive; constructing the input-output logic expression of the FDRE primitive includes: obtaining an input signal D and a corresponding information tag Dt of a data input port of the FDRE primitive, obtaining an input signal CE and a corresponding information tag CEt of a synchronization enable port, and an information tag Qt of an output signal; constructing the FDRE primitive input-output logic expression based on the input signal D, the information tag Dt, the input signal CE, the information tag CEt and the information tag Q, wherein the FDRE primitive input-output logic expression is:

[0009] Qt<=(Dt|(D&CEt))&(CE|CEt).

[0010] Optionally, obtaining the assign statement information flow model based on the label signal of the assign statement includes: acquiring the original signal of each of the assign statements, and determining the corresponding assign statement label signal based on the original signal; replacing the original signal with the assign statement label signal to obtain the assign statement information flow model of each of the assign statements.

[0011] In addition, to achieve the above objectives, the present application also provides an information flow tracking model generation device for a LUT-level netlist, comprising: extracting each logic unit based on the LUT netlist, obtaining all original signals of each of the logic units, adding information labels to all of the original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive and an assign statement; constructing a new LUT module based on the original signal of the LUT module and the label signal, obtaining the truth table of the LUT module, processing the truth table of the LUT module based on a preset truth table analysis algorithm to obtain the truth table of the new LUT module, and converting the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model; processing the primitive using a gate-level information flow tracking algorithm to obtain a primitive information flow model; obtaining an assign statement information flow model based on the label signal of the assign statement; obtaining an information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

[0012] To achieve the above objectives, the present application also provides a security verification method, including:

[0013] Obtaining each encrypted circuit design file and the field programmable gate array to be tested;

[0014] Performing logic synthesis on the circuit design file to obtain a LUT netlist adapted to the field programmable gate array;

[0015] Execute the information flow tracking model generation method of the LUT level netlist according to any one of claims 1 to 5 on the LUT netlist to obtain the information flow tracking model of the field programmable gate array;

[0016] Security attribute assertions are added to the information flow tracking model, and pollution labels of input signals are set. Formal verification tools are used to complete formal verification of the security attributes of the field programmable gate array.

[0017] Optionally, the method further comprises: if the formal verification of the security attribute fails, using a counterexample provided by a formal verification tool to discover security vulnerabilities in the field programmable gate array hardware design.

[0018] Optionally, the encryption circuit includes at least one of an AES encryption circuit and an RSA encryption circuit.

[0019] Optionally, the contamination label is an information label in the information flow tracking model; the use of the counterexample provided by the formal verification tool to discover security vulnerabilities in the field programmable gate array hardware design includes: in the MentorGraphics Questa Formal tool, using a first level of a preset value to represent the contamination label of the key signal; using a second level of a preset value to represent other input signals and the security attribute assertion, and the security attribute assertion stipulates that the key cannot flow to outputs other than ciphertext; obtaining a counterexample waveform of the field programmable gate array based on the Mentor Graphics Questa Formal tool; and discovering security vulnerabilities in the field programmable gate array based on the counterexample waveform; wherein the first level is a high level and the second level is a low level.

[0020] The embodiment of the present application proposes a method for generating an information flow tracking model and a security verification method for a LUT-level netlist, which extracts each logic unit based on the LUT netlist, obtains all original signals of each logic unit, and adds information labels to all original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive and an assign statement; constructs a new LUT module based on the original signal and label signal of the LUT module, obtains the truth table of the LUT module, processes the truth table of the LUT module based on a preset truth table analysis algorithm to obtain the truth table of the new LUT module, and converts the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model; uses a gate-level information flow tracking algorithm to process the original signal and label signal of the primitive to obtain a primitive information flow model; obtains an assign statement information flow model based on the label signal of the assign statement; obtains an information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model, thereby solving the technical problem that an accurate information flow model cannot be automatically generated based on an FPGA netlist in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 A flow chart of an embodiment of a method for generating an information flow tracking model for a LUT-level netlist of the present application;

[0022] Figure 2 A schematic diagram of an embodiment of a method for generating an information flow tracking model for a LUT-level netlist of the present application;

[0023] Figure 3 A schematic diagram of adding information labels provided in an embodiment of a method for generating an information flow tracking model for a LUT-level netlist of the present application;

[0024] Figure 4 An example diagram of generating a truth table of a LUT information flow model provided in an embodiment of a method for generating an information flow tracking model of a LUT-level netlist of the present application;

[0025] Figure 5 A specific example of generating an information flow tracking model for a LUT module provided in an embodiment of a method for generating an information flow tracking model for a LUT-level netlist of the present application;

[0026] Figure 6 A specific example of assign statement information flow tracking model generation provided in the first embodiment of the information flow tracking model generation method for LUT-level netlist of the present application;

[0027] Figure 7 An information flow model of a portion of a LUT netlist provided in an embodiment of a method for generating an information flow tracking model for a LUT-level netlist of the present application;

[0028] Figure 8The counter-example waveform in the AES-TJ benchmark test provided by the first embodiment of the information flow tracking model generation method for the LUT-level netlist of the present application;

[0029] Fig. 9 The information flow tracking model generation method for the LUT-level netlist of the present application provides a comparison result with the GLIFT method. DETAILED DESCRIPTION

[0030] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0031] The existing information flow tracing model generation methods can only generate gate-level netlists and RTL-level hardware description codes, but cannot generate LUT-level netlists. Because LUT-level netlists contain special modules such as LUT primitives, the corresponding information flow tracing models cannot be generated by the above two information flow tracing methods.

[0032] In view of the shortcomings of the prior art, this application proposes a method for generating an information flow tracking model for a LUT-level netlist, which solves the challenging problem of how to automatically generate an accurate information flow model for an FPGA netlist. This application further provides a method for verifying FPGA design security, which can capture security property violations to identify FPGA design security vulnerabilities by formally proving information flow security properties on the generated IFT model. This application can effectively implement security assurance and discover security defects in FPGA designs.

[0033] Reference Figure 1 and Figure 2 The information flow tracking model generation method of the LUT-level netlist provided in the first embodiment of the present application can be executed by a processor of a terminal or a server. The method may include:

[0034] S10, extracting each logic unit based on the LUT netlist, obtaining all original signals of each logic unit, and adding information tags to all original signals to obtain tag signals, wherein each logic unit includes a LUT module, a primitive, and an assign statement;

[0035] Among them, the post-synthesis netlist of FPGA usually contains three types of logic units: LUT modules, primitives such as FDRE, and assign statements. LUT modules are used to implement combinational logic functions, primitives such as FDRE are used to implement sequential logic, and assign statements have no logical functions and are only used for signal transmission and connection. Afterwards, corresponding information tags are added to all signals in each logic unit, and new modules are constructed. Figure 3 As shown, taking the LUT2 module as an example, information labels are added to all the signals therein, for example, the label of I0 is I0_t, and a new module is constructed, taking the original signal and the information label as its input and output signals.

[0036] S20, constructing a new LUT module based on the original signal and the label signal of the LUT module, obtaining the truth table of the LUT module, processing the truth table of the LUT module based on a preset truth table analysis algorithm to obtain the truth table of the new LUT module, and converting the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model;

[0037] Next, generate an information flow model for the LUT module. To generate the information flow model of the LUT module, first use the truth table analysis method to obtain the truth table of the information flow tracking model of the LUT module; then use tools such as YOSYS to convert it into a Boolean logic expression. Finally, add it to the information flow model library.

[0038] This application strictly follows the concept of information flow to accurately model the information flow behavior of LUT. This application considers that there is an information flow if and only if the change of the LUT input signal leads to the change of the output. For any n-input LUT, this application proposes an algorithm that can automatically generate the truth table of its accurate information flow tracking model. The pseudo code of Algorithm 1 is shown below.

[0039]

[0040] Specifically, the original signal of the LUT module includes multiple input signals and output signals, and the new LUT module includes multiple input signals and output signals, and input signal information labels and output signal information labels corresponding to the multiple input signals and output signals one by one;

[0041] The truth table of the LUT module is processed based on a preset truth table analysis algorithm to obtain a new truth table of the LUT module, including:

[0042] Double loop traversal detects the true value of any two entries in the LUT module;

[0043] When the output signals of two table entries are the same, the output signal information label remains unchanged;

[0044] When the output signals of two entries are different, write 1 to the output signal information tag;

[0045] Write the true values ​​of the input signals of the two table entries of the LUT module into the input signals of the two corresponding table entries in the new LUT module;

[0046] If the true value of the same input signal in two table entries is different, write "1" in the corresponding input signal information label;

[0047] Otherwise, write "-".

[0048] In other words, the truth table generation method of the LUT information flow tracking model is specifically as follows: perform a double loop traversal of the LUT truth table to check the output of any two table items. When the outputs of the two selected table items are both '0' or '1', the output remains unchanged, so there is no information flow. When the outputs of the selected table items are "0" and "1" respectively, there is information flow, and two rows of the truth table can be obtained. At this time, write 1 to all O_t items, and write the original signal items into the original signals corresponding to the two table items respectively. If the original signal values ​​in the two table items are different, write "1" to the corresponding label item, otherwise write "-" to represent 0 / 1.

[0049] by Figure 4 Take (a) as an example, Figure 4 Take a two-input LUT module in (a) as an example, traverse Figure 4 In (a), the first and second rows have different output items, so the O_t items in the first and second rows are written as 1 in the truth table of the information flow model. Then the I0 and I1 items are written into the corresponding values ​​of the first and second rows in (a), respectively. Finally, the analysis Figure 4 In (a), the I1 values ​​of the first and second rows are the same. Figure 4 (b) Write “-” into the I1_t item; Figure 4 In (a), the I2 values ​​in the first and second rows are different, and in (b), the I2_t item is written as "1". After processing the analysis to obtain a complete truth table, you can call open source tools such as YOSYS to convert the truth table into a Boolean logic expression.

[0050] The following takes a real 2-input LUT as an example to illustrate the LUT information flow model generation process.

[0051] A 2-input LUT with an initialization vector of 4'hb can generate a 4-item information flow logic function after being processed by the above algorithm 1, which can be expressed as Z_t=(I0_t&(I1|I1_t))|(~I0&I1_t). Each item describes how the taint label of the LUT input signal is propagated to the output, covering all possible information flows, such as Figure 5 As shown, the stain label is the information label.

[0052] S30, using a gate-level information flow tracking algorithm to process the original signal and the label signal of the primitive to obtain a primitive information flow model;

[0053] In an embodiment of the present application, step S30 may specifically include the following execution process:

[0054] S301. Construct input and output logic expressions of each primitive using primitive input signals, primitive output signals, primitive input information labels and primitive output information labels, and determine primitive information flow models based on each input and output logic expression.

[0055] Specifically, the primitive includes an FDRE primitive; constructing an input and output logic expression of the FDRE primitive includes:

[0056] Obtain an input signal D and a corresponding information tag Dt of a data input port of a FDRE primitive, obtain an input signal CE and a corresponding information tag CEt of a synchronization enable port, and an information tag Qt of an output signal;

[0057] The FDRE primitive input and output logic expressions are constructed based on the input signal D, the information tag Dt, the input signal CE, the information tag CEt and the information tag Q, where the FDRE primitive input and output logic expressions are:

[0058] Qt<=(Dt|(D&CEt))&(CE|CEt).

[0059] It should be noted that the process of generating the information flow model of other primitives such as FDRE is different from the process of generating the LUT information flow model. Other primitives such as FDRE have a certain logical structure, and their information flow model can be constructed through the gate-level information flow method. The present application constructs an IFT model library for common FPGA primitives. Specifically, the present application pre-constructs an information flow model library for commonly used FPGA primitives, and directly instantiates its information flow model for each primitive such as FDRE extracted from the netlist. For example, for an FDRE, its information flow model is Qt<=(Dt|(D&CEt))&(CE|CEt), that is, the taint labels of input D and CE are propagated to output Q. The present application performs this mapping process for all FDREs.

[0060] S40, obtaining an assign statement information flow model based on the label signal of the assign statement;

[0061] In an embodiment of the present application, step S40 may specifically include the following execution process:

[0062] S401, obtaining the original signal of each assign statement, and determining the corresponding assign statement label signal based on the original signal;

[0063] S402. Replace the original signal with the assign statement label signal to obtain the assign statement information flow model of each assign statement.

[0064] It is understandable that in the LUT-level netlist, the assign statement only has the function of assigning values ​​and does not participate in logical operations. Therefore, the information flow model construction of the assign statement can continue to replace the original signal with the label signal. For example, to assign a and b to the 2-bit width output c through the assign statement, the original signal can be replaced with the label signal, such as Figure 6shown.

[0065] S50, obtaining an information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

[0066] Based on the LUT and primitive information flow models constructed in the previous steps, this application adopts a constructive method to add taint label signals to each signal at the level of the LUT netlist, and instantiate the corresponding information flow model for each LUT and primitive. For the assign statement, the information flow model can be established by only passing the taint label without additional logic. For example, the information flow model of a part of the LUT netlist is as follows Figure 7 shown.

[0067] In summary, this application adopts a constructive method to add an IFT information tag information to each signal in the LUT netlist. Then, for each LUT and FDRE and other logic units in the netlist, the processor instantiates its corresponding IFT logic unit in the IFT library. For the assign statement, since it does not contain any logical operations, the processor can directly assign and pass the information tag. Through the above steps, a complete LUT netlist information flow model can be constructed.

[0068] Based on the above embodiments, the present application also proposes an information flow tracking model generation device for a LUT-level netlist. The information flow tracking model generation device may include a label generation unit, a first model generation unit, a second model generation unit, a third model generation unit and a total model generation unit, wherein the label generation unit is used to extract each logic unit based on the LUT netlist, obtain all original signals of each logic unit, and add information labels to all original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive and an assign statement; the first model generation unit is used to construct a new LUT module based on the original signal and the label signal of the LUT module , obtain the truth table of the LUT module, process the truth table of the LUT module based on a preset truth table analysis algorithm, obtain the truth table of the new LUT module, and convert the truth table of the new LUT module into a Boolean logic expression to obtain the LUT information flow model; the second model generation unit is used to process the primitive using the gate-level information flow tracing algorithm to obtain the primitive information flow model; the third model generation unit is used to obtain the assign statement information flow model based on the label signal of the assign statement; the total model generation unit is used to obtain the information flow model of the LUT-level netlist based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

[0069] Based on the above embodiments, the present application also provides a security verification method, including:

[0070] S100, obtaining each encrypted circuit design file and the field programmable gate array to be tested;

[0071] S200, performing logic synthesis on the circuit design file to obtain an adapted field programmable gate array LUT netlist;

[0072] S300, executing the above-mentioned method for generating an information flow tracking model of a LUT-level netlist on a LUT netlist to obtain an information flow tracking model of a field programmable gate array;

[0073] S400, adding security attribute assertions to the information flow tracking model, setting pollution labels for input signals, and using formal verification tools to complete formal verification of the security attributes of the field programmable gate array.

[0074] S500. If the formal verification of the security attribute fails, the counterexamples provided by the formal verification tool are used to discover security vulnerabilities in the field programmable gate array hardware design.

[0075] Before step S100, the present application also builds a security verification hardware implementation environment, the implementation environment is:

[0076] Intel i7-13650HX CPU@2.6G (14 cores) processor, 32GB, Windows 11 64-bit operating system. Use a virtual machine to run the Ubuntu 18.04 operating system.

[0077] Among them, step S100 to step S200 include: using the open source tool Yosys to synthesize the hardware design into an FPGA netlist for Xilinx Virtex-7 devices. Specifically, first, the processor can use the Yosys open source tool to synthesize the hardware designs such as AES and RSA into an FPGA netlist for Xilinx Virtex-7 devices. Then the processor can extract three types of logical structures contained in the netlist by analyzing the Verilog code: LUT modules, primitives such as FDRE, and assign statements. Generally speaking, the circuit scale used by encryption hardware ranges from hundreds to thousands of LUTs. For example, the netlist after the AES circuit synthesis contains 1835 LUTs, 274 FDREs, and 264 assign statements. The LUT-level information flow tracking model generation method needs to build an information flow model based on these extracted logical structures.

[0078] By executing step S300, a LUT-level information flow model of the FPGA can be constructed.

[0079] In an optional embodiment, the method of discovering security vulnerabilities in the field programmable gate array hardware design using counterexamples provided by a formal verification tool includes:

[0080] S501, in a Mentor Graphics Questa Formal tool, using a first level of a preset value to represent a contamination label of the key signal;

[0081] S502, using a second level of a preset value to represent other input signals and the security attribute assertion, wherein the security attribute assertion stipulates that the key cannot flow to other outputs except the ciphertext;

[0082] S503, obtain the counterexample waveform of the field programmable gate array based on Mentor Graphics Questa Formal tool;

[0083] S504, discovering a security vulnerability of the field programmable gate array based on the counterexample waveform;

[0084] The first level is a high level, and the second level is a low level.

[0085] Next, the processor performs security vulnerability detection and verification by executing steps S501 to S504. The process is as follows: Figure 8 As shown. This application uses the Mentor Graphics Questa Formal tool to verify the information flow security properties of several open source hardware security benchmarks (AES / RSA) based on the LUT-level information flow tracing model. Taking the AES-TJ circuit as an example, the taint label of the key signal is set to high (taint), and other inputs are set to low (untaint), and it is asserted that all outputs except the ciphertext should be untaint (that is, the key cannot flow to outputs other than the ciphertext). The verification results show that the confidentiality property is violated. By replaying the counter-example waveform, it is found that when the hidden hardware Trojan is triggered, the key value will flow to the illegal capacitance output, exposing the security vulnerability. The counter-example waveform in the AES-TJ benchmark test is shown as follows. Fig. 9 shown.

[0086] The experiment also found hardware Trojans in AES-T200 / T1000 circuits and timing side channels in RSA circuits. Table 1 shows the comparison results between this application and the existing GLIFT method. The LUTLIFT method of this application reduces the verification time by more than 60% on average when detecting these same security vulnerabilities. These experimental results confirm the effectiveness and efficiency advantages of this application in FPGA design security verification. Table 1 is the comparison results between this application and the existing GLIFT method

[0087] Benchmark Security property LUTLIFT GLIFT AES-T100 The key should not directly flow to output 7s 22s AES-T200 The key should not flow to Capacitance 9s 23s AES-T1000 The key should not flow to Capacitance 3s 22s AES-T1100 The key should not directly flow to output 8s 21s AES-T1200 The key should not flow to Capacitance 7s 23s AES-TJ2 The key should not flow directly to ciphertext 2s 2s 32bit RSA The key should flow to BSY 98s 326s RSA-T100 The key should not flow directly to ciphertext 50s 487s RSA-T200 The ciphertext should not be modified 4s 2s

[0088] In summary, this application uses Mentor Graphics Questa Formal to complete the formal verification of security properties based on the LUT-level information flow tracing model. When the verification passes, it indicates that the security properties are met; when the verification fails, the counterexamples provided by the Questa Formal tool are analyzed to discover security vulnerabilities in the hardware design. This application uses seven benchmarks from Trust-Hub.org and two other self-designed circuits to demonstrate the ability of LUTLIFT in discovering security vulnerabilities that violate confidentiality, integrity, and timing-related security properties. Experimental results show that the method of this application can detect hardware Trojans in the AES-T100 and AES-TJ benchmarks, as well as the timing channels in the RSAIP core. At the same time, the security verification efficiency of this application is better than the existing GLIFT method. The above test cases demonstrate the effectiveness of this application in FPGA design security verification.

[0089] Based on the above embodiments, the present application further proposes a computer-readable storage medium, which includes instructions, which, when executed on a computer, enables the computer to execute the information flow tracking model generation method of the LUT-level netlist provided in any of the above embodiments.

[0090] Based on the above embodiments, the present application also proposes an electronic device, which includes: at least one processor, a memory and an input-output unit; wherein the memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute the information flow tracking model generation method of the LUT-level netlist provided in the above embodiments.

[0091] The above are only preferred embodiments of the present application, and are not intended to limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A method for generating an information flow tracking model of a LUT-level netlist, characterized in that: include: Extracting each logic unit based on the LUT netlist, obtaining all original signals of each logic unit, and adding information labels to all the original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive, and an assign statement; Building a new LUT module based on the original signal of the LUT module and the label signal, obtaining a truth table of the LUT module, processing the truth table of the LUT module based on a preset truth table analysis algorithm to obtain a truth table of the new LUT module, and converting the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model; Processing the original signal of the primitive and the label signal using a gate-level information flow tracking algorithm to obtain a primitive information flow model; Obtaining an assign statement information flow model based on a label signal of the assign statement; An information flow model of a LUT-level netlist is obtained based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

2. The method for generating an information flow tracking model of a LUT-level netlist according to claim 1, characterized in that: The original signal of the LUT module includes multiple input signals and output signals, and the new LUT module includes the multiple input signals and the output signals, and input signal information labels and output signal information labels corresponding to the multiple input signals and the output signals one by one; The processing of the truth table of the LUT module based on a preset truth table analysis algorithm to obtain the truth table of the new LUT module includes: Double loop traversal to detect the true values ​​of any two entries in the LUT module; When the output signals of the two table entries are the same, the output signal information label remains unchanged; When the output signals of the two entries are different, 1 is written into the output signal information tags; Writing the true values ​​of the input signals of the two table entries of the LUT module into the input signals in the two corresponding table entries in the new LUT module; If the true values ​​of the same input signal in the two entries are different, "1" is written in the corresponding input signal information tag; Otherwise, write "-".

3. The method for generating an information flow tracking model of a LUT-level netlist according to claim 1, characterized in that: The method of processing the original signal of the primitive and the label signal by using a gate-level information flow tracking algorithm to obtain a primitive information flow model includes: The input and output logic expressions of each primitive are constructed using primitive input signals, primitive output signals, primitive input information labels and primitive output information labels, and the primitive information flow model is determined based on each input and output logic expression.

4. The method for generating an information flow tracking model of a LUT-level netlist according to claim 3, characterized in that: Said primitives include FDRE primitives; Constructing the input-output logic expression of the FDRE primitive, comprising: Obtain an input signal D and a corresponding information tag Dt of a data input port of a FDRE primitive, obtain an input signal CE and a corresponding information tag CEt of a synchronization enable port, and an information tag Qt of an output signal; The FDRE primitive input-output logic expression is constructed based on the input signal D, the information tag Dt, the input signal CE, the information tag CEt and the information tag Q, wherein the FDRE primitive input-output logic expression is: Qt<=(Dt|(D&CEt))&(CE|CEt).

5. The method for generating an information flow tracking model of a LUT-level netlist according to claim 1, characterized in that: The assign statement information flow model is obtained based on the label signal of the assign statement, including: Acquire the original signal of each of the assign statements, and determine the corresponding assign statement label signal based on the original signal; The assign statement label signal is used to replace the original signal to obtain the assign statement information flow model of each assign statement.

6. A device for generating an information flow tracking model of a LUT-level netlist, characterized in that: include: Extracting each logic unit based on the LUT netlist, obtaining all original signals of each logic unit, and adding information labels to all the original signals to obtain label signals, wherein each logic unit includes a LUT module, a primitive, and an assign statement; Building a new LUT module based on the original signal of the LUT module and the label signal, obtaining a truth table of the LUT module, processing the truth table of the LUT module based on a preset truth table analysis algorithm to obtain a truth table of the new LUT module, and converting the truth table of the new LUT module into a Boolean logic expression to obtain a LUT information flow model; Processing the primitive using a gate-level information flow tracing algorithm to obtain a primitive information flow model; Obtaining an assign statement information flow model based on a label signal of the assign statement; An information flow model of a LUT-level netlist is obtained based on the LUT information flow model, the primitive information flow model and the assign statement information flow model.

7. A security verification method, characterized in that: include: Obtaining each encrypted circuit design file and the field programmable gate array to be tested; Performing logic synthesis on the circuit design file to obtain a LUT netlist adapted to the field programmable gate array; Execute the information flow tracking model generation method of the LUT level netlist according to any one of claims 1 to 5 on the LUT netlist to obtain the information flow tracking model of the field programmable gate array; Add security attribute assertions in the information flow tracking model, set pollution labels for input signals, and use formal verification tools to complete formal verification of the security attributes of the field programmable gate array.

8. The security verification method according to claim 7, characterized in that: include: If the formal verification of security properties fails, the counterexamples provided by the formal verification tool are used to discover security vulnerabilities in the field programmable gate array hardware design.

9. The security verification method according to claim 7, characterized in that: The encryption circuit includes at least one of an AES encryption circuit and an RSA encryption circuit.

10. The security verification method according to claim 8, characterized in that: The pollution label is the information label in the information flow tracking model; The counterexamples provided by the formal verification tool are used to discover security vulnerabilities in the field programmable gate array hardware design, including: In the Mentor Graphics Questa Formal tool, a first level of a preset value is used to represent a contamination label of a key signal; Using a second level of a preset value to represent other input signals and the security attribute assertion, the security attribute assertion indicating that the key cannot flow to other outputs except the ciphertext; Obtain counterexample waveforms of field programmable gate arrays based on Mentor Graphics Questa Formal tool; Determining a security vulnerability of the field programmable gate array based on the counterexample waveform; The first level is a high level, and the second level is a low level.