Redundancy pruning method for solving multi-valued problem of bit stream mapping unit of FPGA (Field Programmable Gate Array) device

Through the redundant pruning method, the FPGA bitstream file is parsed and module partitioned, which solves the redundancy problem caused by the multi-valued unit problem, improves the accuracy and efficiency of circuit restoration, and provides new technical support for FPGA reverse engineering.

CN120087320AActive Publication Date: 2025-06-03UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510103604.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-06-03
Estimated Expiration
2045-01-22

AI Technical Summary

Technical Problem

During the FPGA design process, the multi-value problem of unit caused by the control bit multiplexing of the device in the bitstream makes it difficult to accurately determine whether the module is actually used, which brings great challenges to the reverse analysis of the FPGA bitstream.

Method used

An efficient redundant pruning method is proposed. By analyzing the FPGA bitstream file, extracting the configuration option set, and dividing it into modules, restoring the circuit model of each site module according to the logical unit configuration resources, establishing a network connection relationship between modules, and finely pruning the redundant modules caused by the multi-value problem of the unit based on the connection between modules, ensuring that only the necessary functional modules are retained.

Benefits of technology

It effectively solves the redundancy caused by the multi-valued unit problem in the FPGA bitstream file parsing process, improves the accuracy and efficiency of circuit restoration, and provides new technical means for FPGA reverse engineering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120087320A_ABST
    Figure CN120087320A_ABST
Patent Text Reader

Abstract

The invention discloses a redundancy trimming method for solving the multi-valued problem of a bit stream mapping unit of an FPGA (Field Programmable Gate Array) device, and relates to the field of hardware security. The method comprises the following steps: firstly, analyzing an FPGA bit stream file, extracting a configuration option set in the FPGA bit stream file, and performing module division on the FPGA bit stream file; secondly, restoring a circuit model of each site module according to the logic unit configuration resources, and establishing a network connection relationship between the modules; thirdly, performing refined trimming on redundant modules caused by the unit multi-valued problem based on the connection condition between the modules; specifically, only necessary functional modules are kept by judging the upstream and downstream connection conditions of the modules and the overall connection relation of the cascade modules. And finally, outputting the trimmed module set and network connection to realize optimized analysis of the FPGA bit stream file. According to the method, redundancy caused by the unit multi-valued problem in the FPGA bit stream file analysis process is effectively solved, the accuracy and efficiency of circuit restoration are improved, and a new technical means is provided for FPGA reverse engineering.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of hardware security, and particularly proposes an efficient redundancy pruning method for the multi-value problem of cells caused by the control bit multiplexing in the bitstream of FPGA designs. Background Art

[0002] Field Programmable Gate Array (FPGA) is widely used in civil and military fields in China due to its high flexibility, high integration, high speed and other characteristics. On the other hand, the security risks faced by FPGAs are becoming increasingly severe, and there is still a lack of effective security protection measures at the user end. Therefore, in order to effectively detect the security risks of FPGAs from the user end, it is first necessary to perform reverse analysis on the FPGA bitstream file, and then perform security analysis on the netlist file generated by the reverse process. However, during the FPGA design process, due to resource reuse and optimization strategies, a multi-value problem of cells (Multi-Value One-Element, MVOE) may occur, that is, one configuration bit corresponds to multiple device states, making it difficult to accurately determine whether a module is actually used. This problem poses a great challenge to the reverse analysis of FPGA bitstreams.

[0003] In 2012, Benz et al. proposed an FPGA reverse toolchain called BIL. By combining the mapping database of FPGA configurable points with the database of FPGA structure information, the bitstream control bits were extracted and reversed. Experiments showed that this tool was effective for the AMD Xilinx Virtex-5 chip, but it could only reverse some circuit modules. In 2014, Cheremisinov proposed an automated bitstream reverse tool DAT for Xilinx FPGAs, but this tool did not cover the reverse of on-chip network resources.

[0004] In 2021, Yu et al. studied the bitstream mapping relationship of the Artix-7 FPGA chip of AMD Xilinx, although only a few components such as 3-bit adders were reverse verified. In 2022, Yao Rui et al. from Nanjing University of Aeronautics and Astronautics proposed a method for analyzing the mapping relationship between FPGA bitstream configuration data and underlying resource units. This method modeled the mapping relationship between FPGA bitstream configuration data and logic units and established a device model parameter library

[14] . In 2023, Zhang et al. proposed a new FPGA bitstream format reverse engineering tool BitFREE, which made the analysis and processing of FPGA bitstream files more efficient.

[0005] In summary, although existing research has been able to reverse engineer multiple AMD Xilinx FPGA chips (such as Spartan-3, Spartan-6, Virtex-2, Virtex-5, and Artix-7) and Microsemi FPGA chips. However, these studies mostly focus on the reverse analysis of partial resources or circuit modules, and often do not cover various configuration situations in large-scale complex designs. There are few verification results for large-scale samples with unit multi-value problems, and the unit multi-value problem has not been effectively solved. Summary of the Invention

[0006] The present invention proposes a redundant pruning method for efficiently solving the unit multi-value problem in FPGA bitstream reverse engineering. This method solves the problem that it is difficult to accurately judge the usage status of circuit modules due to unit multi-values in the prior art. Compared with the prior art, this method does not require reliance on complex algorithms or manual intervention, is applicable to various FPGA reverse engineering scenarios, and researchers can achieve efficient and accurate circuit module restoration and optimization under simple experimental conditions, thus providing effective support for FPGA bitstream file resource analysis and security evaluation.

[0007] The present invention first parses the FPGA bitstream file, extracts the set of configuration options therein, and performs module partitioning on it. Secondly, according to the configuration resources of the logic unit, the circuit model of each site module is restored, and the network connection relationship between the modules is established. Thirdly, based on the connection situation between the modules, the redundant modules caused by the unit multi-value problem are refined and pruned. Specifically, by judging the upstream and downstream connection situations of the modules and the overall connection relationship of the cascaded modules, only the necessary functional modules are ensured to be retained. Finally, the trimmed module set and network connection are output to achieve optimized parsing of the FPGA bitstream file. This method effectively solves the redundancy caused by the unit multi-value problem in the process of parsing the FPGA bitstream file, improves the accuracy and efficiency of circuit restoration, and provides a new technical means for FPGA reverse engineering.

[0008] It can be seen from Figure 1 that the redundant pruning method for solving the unit multi-value problem in FPGA reverse engineering requires the following 7 steps, and each step corresponds to the label in the figure.

[0009] The technical solution of the present invention is a redundant pruning method for solving the unit multi-value problem in FPGA device bitstream mapping. The condition for implementing this method is that a bitstream mapping database of the target FPGA chip has been established. The steps of this method include:

[0010] Step 1: Parse the bitstream file and extract the configuration options;

[0011] Step 2: Perform module partitioning on the set of configuration options P;

[0012] The FPGA chip is divided into several blocks of Tile in the form of a two-dimensional matrix. These blocks are arranged in a grid-like form and are connected by wires; inside each block, there are several logic resource units Site;

[0013] Step 3: Traverse P plp,j , and generate the corresponding circuit module set R;

[0014] Step 4: Construct the network connection between R j ;

[0015] When the circuit module sets R of all Sites j are generated, use the wire resource configuration set P pip , and further restore the network connection relationship between Sites; P pip contains the configurable interconnection point information between Tiles. By recursively searching for P layer by layer outward from the output or input wires of each Site pip and the fixed wire resources, use the depth-first search algorithm to construct the global network connection relationship between Sites, and generate the circuit connection diagram G. The circuit connection diagram G includes the internal connections of the circuit modules R j and the wires between the R j circuit modules. See (11), where N represents the node set, corresponding to all circuit modules r jk , and E represents the connection relationship set, which defines the wire structure between modules;

[0016] G = {Ν, E} (11)

[0017] Step 5: Traverse the marked module r j in R jk ’ and perform redundancy pruning;

[0018] Step 6: Determine whether all circuit module sets R j have been traversed. If so, end; otherwise, continue to execute Step 5;

[0019] Step 7: Finally, obtain the circuit after redundancy processing

[0020] Furthermore, the specific method of Step 1 is as follows:

[0021] Step 1.1: By parsing the bitstream file, extract the flip bit set B, where B = {b 1 , b 2 , …, b N}, and each element b i represents the specific bit of the bitstream file;

[0022] Step 1.2: By searching the FPGA bitstream mapping database, convert B into the set of configuration options P used by the chip, as shown in Equation (1); the set P contains all the activated programmable options in the target FPGA chip, where p i represents the usage of a specific resource;

[0023] P = {p 1 , p 2 ,..., p i ,..., p W}, 1 ≤ i ≤ W (1).

[0024] Furthermore, the specific method of Step 2 is as follows:

[0025] Step 2.1: Divide the set of configuration options P into two types of resources: programmable interconnect resources PIP and logic cell configuration resources PLP, as shown in Equation (2); use P pip to represent the set of interconnect resource configurations between Tile blocks used by the chip, and P plp to represent the set of logic cell configurations within the Site used by the chip;

[0026] P = P pip ∪ P plp (2)

[0027] Step 2.2: Further divide the sets P pip and P plp ;

[0028] First, take the Tile block as a unit and divide P pip into several Tile subsets P pip,i , as shown in Equation (3); where P pip,i represents the interconnect resource set of the i-th Tile block, satisfying Equation (4), and Tile i (p) represents the Tile to which the configuration option p belongs;

[0029]

[0030] Second, take the Site as a unit and divide P plp into several Site subsets P plp,j , as shown in Equation (5); where P plp,j represents the logic cell configuration set of the j-th Site block, satisfying Equation (6), and Site j (p) represents the Site to which the configuration option p belongs;

[0031]

[0032] Furthermore, the specific method of Step 3 is as follows:

[0033] Traverse each P plp,j , P plp,j corresponds to the configuration options of the j-th Site. According to the configuration options it uses, restore the set R of circuit modules of this Site, as shown in Equation (7); where R j represents the set of circuit modules of the j-th Site, as shown in Equation (8), and r jk represents j the k-th basic circuit module in R

[0034] R = {R 1 , R 2 ,..., R j ,..., R M} 1≤j≤M (7)

[0035] R j = {r j1 , r j2 ,..., r jk ,..., r jT} 1≤k≤T (8)

[0036] Among them, M represents the total number of logic resource modules, and T represents the total number of basic circuit modules;

[0037] During the process of generating the set R of circuit modules j , when the specific state of the device cannot be determined based on the existing information, it is defaulted that the configuration option is in the used state, that is, all possible circuit modules are regarded as active states to ensure the integrity of the circuit function, and at the same time, it is marked as r jk ’, as shown in Equation (9) and Equation (10);

[0038] R' j = {r' jk ∈R j | r' jk is a marking unit} (9)

[0039] R' j = {r' j1 , r' j2 ,..., r' jk ,..., r' jS} 1≤k≤S (10)

[0040] S represents the total number of devices whose specific states cannot be determined based on the existing information.

[0041] Furthermore, the specific method of step 5 is as follows:

[0042] Step 5.1:, for each marked module r j in R jk’, obtain all the path sets E passing through r jk ’, as shown in Equation (12), where e jk represents the l-th path passing through r l ’; jk ’;

[0043] E jk = {e 1 , e 2 ,..., e l ,..., e Q} 1 ≤ l ≤ Q (12)

[0044] where Q represents the total number of paths;

[0045] Step 5.2: Traverse all the paths passing through r jk ’, and determine whether the r l ’ on e jk belongs to the cascade module;

[0046] If it belongs to the cascade module, obtain the cascade module set C on this path, as shown in Equation (13); regard the cascade module set C as a whole; determine whether C has both upstream and downstream connections at the same time. If there are upstream and downstream connections, mark r jk ’ as the reserved module r jk save . If C does not have upstream or downstream connections, no retention process is performed, and continue to traverse the next path of this module;

[0047] C = {r ju , r j(u+1) ,... r jk ,..., r jv} (u ≤ k ≤ v) (13)

[0048] If it does not belong to the cascade module, determine whether the r jk ’ has both upstream and downstream connections at the same time. If there are upstream and downstream connections, mark r jk ’ as the reserved module r jk save . If there are no upstream or downstream connections, no retention process is performed, and continue to traverse the next path of this module;

[0049] Step 5.3: If there is a module r jk save in a path, then retain the module r jk save . If after traversing all the paths of r jk ’, none of the paths are marked, then remove r jk ’; when all the r j in R jkAfter that, a set of modules after redundant pruning is obtained.

[0050] The present invention proposes a redundant pruning method for solving the multi-valued problem of FPGA cells. Aiming to improve the accuracy and efficiency of FPGA circuit structure restoration, for the redundant modules introduced due to the multi-valued cell problem, a method combining hierarchical analysis and global path connectivity judgment is adopted to effectively identify and remove invalid modules. Through the analysis of bitstream configuration options and the network restoration of circuit modules, combined with the redundant pruning algorithm, the functional integrity and logical correctness of the retained modules are ensured. This invention significantly reduces the redundant interference in the circuit restoration process, improves the accuracy of module division and the usability of network connections, and provides reliable technical support for the accurate restoration of complex FPGA circuits. Description of the Drawings

[0051] Figure 1 It is the overall method flow chart of the present invention.

[0052] Figure 2 It is the flow chart of the redundant pruning algorithm of the present invention. Detailed Embodiment

[0053] The present invention conducts experiments on models xc3s200ft256-5, xc3s200aft256-5 of Xilinx Spartan3 series, xc6slx9ftg256-2 of Spartan6 series, xc5vlx50tff1136-1 of Virtex-5 series, and xc7a200tffg1156-3 of Artix-7 series using the method described in the invention content. Circuit samples from the ISCAS’85 standard test set are selected for reverse engineering and redundant pruning algorithms on the above target chips respectively. The time overhead of the entire reverse process is recorded in the following table, and the reverse result is verified by comparing the netlist functions before and after reverse, and the number of circuit modules before and after redundant pruning is also counted. The experimental results show that the present invention can effectively solve the multi-valued cell problem and significantly reduce redundant modules. At the same time, it is verified that the circuit function of the reverse restoration is consistent with the original design, proving that this method optimizes the circuit while ensuring functional integrity, thus verifying its high efficiency and reliability.

[0054] Table 1 Pruning Results of the Embodiment

[0055]

Claims

1. A redundant pruning method for solving the multi-value problem of bitstream mapping units of FPGA devices. The method is implemented on the premise that a bitstream mapping database of a target FPGA chip has been established. The method comprises the following steps: Step 1: Parse the bitstream file and extract configuration options; Step 2: Divide the configuration option set P into modules; The FPGA chip is divided into several tiles in a two-dimensional matrix form. These tiles are arranged in a grid form, and each tile is connected by wires. Inside the tile, there are several logical resource units, Site. Step 3: Traverse P plp,j , generate the corresponding circuit module set R; Step 4: Build R j Network connections between When the circuit module set R of all sites j After being generated, the connection resource configuration set P is used pip , further restore the network connection relationship between sites; P pip Contains the configurable interconnection point information between tiles, and recursively searches for P layer by layer from the output or input connection of each Site pip and fixed connection resources, using the depth-first search algorithm to build the global network connection relationship between sites and generate a circuit connection graph G, which includes circuit modules R j The internal connection and R j The connections between circuit modules are shown in (11), where N represents the node set corresponding to all circuit modules r jk ,E represents the connection relationship set, which defines the connection structure between modules; G = {N, E} (11) Step 5: Traverse R j The tag module in r jk ', perform redundant pruning; Step 6: Determine whether all circuit module sets R have been traversed j If yes, then end; otherwise, proceed to step 5; Step 7: Finally, we get the circuit after redundancy processing is completed 2. A redundant pruning method for solving the multi-value problem of bit stream mapping unit of FPGA device as claimed in claim 1, characterized in that: The specific method of step 1 is: Step 1.1: Extract the flip bit set B by parsing the bit stream file, where B = {b1, b2, …, b N }, each element b i Indicates the specific bit position of the bit stream file; Step 1.2: By searching the FPGA bitstream mapping database, convert B into the configuration option set P used by the chip, as shown in formula (1); the set P contains all the activated programmable options in the target FPGA chip, where p i Indicates the usage of a specific resource; P={p1,p2,...,p i ,...,p W },1≤i≤W (1)。 3. A redundant pruning method for solving the multi-value problem of bit stream mapping unit of FPGA device as claimed in claim 1, characterized in that: The specific method of step 2 is: Step 2.1: Divide the configuration option set P into two types of resources: programmable wiring resources PIP and logic unit configuration resources PLP, as shown in formula (2); pip Represents the resource configuration set of the tile connections used by the chip, P plp Represents the set of logical unit configurations in the site used by the chip; P=P pip ∪P plp (2) Step 2.2: Set P pip and P plp Further division; First, take Tile blocks as units and transform P pip Divide into several Tile subsets P pip,i , see formula (3); where P pip,i represents the connection resource set of the i-th Tile block, satisfying formula (4), Tile i (p) indicates the Tile to which configuration option p belongs; Secondly, take Site as the unit and set P plp Divide into several Site subsets P plp,j , see formula (5); where P plp,j represents the logical unit configuration set of the jth Site block, satisfying equation (6), Site j (p) indicates the Site to which configuration option p belongs; 4. A redundant pruning method for solving the multi-value problem of bit stream mapping unit of FPGA device as claimed in claim 1, characterized in that: The specific method of step 3 is: Traverse each P plp,j , P plp,j Corresponding to the configuration options of the jth Site, the circuit module set R of the Site is restored according to the configuration options used, as shown in formula (7); where R j represents the circuit module set of the jth Site, see formula (8), r jk Represents R j The kth basic circuit module in; R={R1,R2,...,R j ,...,R M }1≤j≤M (7) R j ={r j1 ,r j2 ,...,r jk ,...,r jT } 1≤k≤T (8) Wherein, M represents the total number of logic resource modules, and T represents the total number of basic circuit modules; In the generated circuit module set R j In the process of , when the specific state of the device cannot be determined based on the existing information, the configuration option is assumed to be in the used state, that is, all possible circuit modules are considered to be activated to ensure the integrity of the circuit function, and are marked as r jk ', see formula (9) and formula (10); R' j ={r' jk ∈R j |r' jk is the marking unit} (9) R' j ={r' j1 ,r' j2 ,...,r' jk ,...,r' jS } 1≤k≤S (10) S represents the total number of devices whose specific status cannot be determined based on the existing information.

5. A redundant pruning method for solving the multi-value problem of bit stream mapping unit of FPGA device as claimed in claim 1, characterized in that: The specific method of step 5 is: Step 5.1: For R j Each tag module r in jk ', get all the jk 'Pathway set E jk , see formula (12), where e l Indicates that after r jk 'The lth path; THE jk ={e1,e2,...,e l ,...,the Q }1≤l≤Q (12) Among them, Q represents the total number of pathways; Step 5.2: Traverse r jk 'All the paths, judge in e l R jk 'Whether it belongs to the cascade module; If it is a cascade module, then obtain the cascade module set C on the path, see formula (13); regard the cascade module set C as a whole; determine whether C has both upstream and downstream connections. If so, mark r jk 'To retain module r jk save ,If C has no upstream or downstream connection, it will not be retained and the traversal of the next path of the module will continue; C={r ju ,r j(u+1) ,...r jk ,...,r jv }(u≤k≤v) (13) If it does not belong to the cascade module, determine the r jk 'Whether there are both upstream and downstream connections, if there are upstream and downstream connections, mark r jk 'To retain module r jk save ,If there is no upstream or downstream connection, no reservation is made and the traversal of the next path of the module continues; Step 5.3: If there is a path with module r jk save , then retain module r jk save , if you traverse r jk 'After all the paths are cleared, all the paths are unmarked, then remove r jk '; When the traversal of R is completed j All r jk 'After that, we get the module set after redundant pruning

Citation Information

Patent Citations

  • Precise reverse engineering method for FPGA (Field Programmable Gate Array) firmware

    CN108733404A

  • Data de-identification based on detection of allowable configurations for data de-identification processes

    CN111417954A

  • Multi-valued APUF-based reconfigurable system

    CN112905506A

  • FPGA chip verification method and system, equipment and storage medium

    CN113705141A

  • Circuit design segmentation method and device

    CN116451624A