Verification system and verification method for parameterized information security module
Through the UVM-based verification system and the clock reset assertion module, combined with the parameters passed in the makefile file, parameterized verification of the information security module of the on-board chip is achieved, solving the problems of poor maintainability of the verification environment and insufficient verification of the clock signal in the prior art, and improving verification efficiency and reliability.
Patent Information
- Application Number
- CN202510342601.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art is difficult to effectively verify the information security module of the on-board chip to ensure the correctness, robustness and reliability of its functions, especially under different parameters and clock conditions.
The clock reset assertion module is created based on UVM verification top-level file, combined with simulated external bus interconnection functions and system proxy components, the parameters of the security algorithm are passed in through the makefile file to realize parameterized verification of information security modules such as SKA, PKI, Hash and TRNG.
It realizes comprehensive verification of the information security module of the on-board chip, covers different parameter scenarios, enhances the maintainability of the verification environment, and improves the verification efficiency, ensuring the correctness and reliability of the information security module under various conditions.
Smart Images

Figure CN120217348A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of chip verification, and relates to a parameterized information security module verification system and a verification method. Background Art
[0002] With the rapid development of intelligent connected vehicle technology, the security issues of in-vehicle chips have gradually attracted wide attention. A large number of electronic control units (ECUs) are integrated inside modern vehicles, which are involved in key functions such as autonomous driving, vehicle communication, and power control. However, due to the complexity of the in-vehicle environment and the continuous evolution of external attack means, in-vehicle chips face security risks such as data leakage, tampering, and forgery. Therefore, adopting hardware-level encryption technology to ensure the security of data during storage, transmission, and calculation has become an important research direction in the current automotive electronics field.
[0003] In the security protection system of in-vehicle chips, a variety of cryptographic algorithms and security mechanisms are usually adopted, including symmetric key algorithms (such as SKA, Symmetric Key Algorithm), public key infrastructure (PKI, Public Key Infrastructure), hash algorithms (Hash), and true / false random number generators (TRNG, True Random Number Generator), etc. These algorithms each undertake different security functions. For example, SKA is used for efficient data encryption, PKI is used for key management and identity authentication, Hash is used for data integrity verification, and TRNG is used to provide a high-quality random number source to ensure the security of cryptographic operations. However, after encapsulating these algorithms together, how to effectively verify the encapsulated information security module to ensure the correctness, robustness, and reliability of its functions is one of the key technical issues for realizing the security protection of in-vehicle chips. Summary of the Invention
[0004] Aiming at the problems existing in the above traditional technologies, the present invention proposes a parameterized information security module verification system and a parameterized information security module verification method, which can effectively verify the information security module of in-vehicle chips to ensure the correctness, robustness, and reliability of its functions.
[0005] To achieve the above object, the embodiments of the present invention adopt the following technical solutions: On the one hand, a parameterized information security module verification system is provided, which includes a clock reset assertion module created based on the uvm verification top-level file, three apb bus interfaces and two ahb bus interfaces, as well as a simulated external bus interconnection function, a system agent component, an environment component, an interrupt function, a virtual memory and a system configuration module derived and instantiated from the base class test case; the system agent component includes three apb bus agents and two ahb bus agents, the environment component includes a TRNG environment component, a HASH environment component, a SKA environment component and a PKI environment component, the apb bus interfaces are respectively connected to the apb bus agents through the algorithm modules to be tested, the ahb bus interfaces are respectively connected to the ahb bus agents through the algorithm modules, and the interrupt function and the virtual memory are respectively connected to the algorithm modules; The simulated external bus interconnection function is used to judge, select and start the bus transmission sequence corresponding to the corresponding security algorithm according to the access address of the security algorithm passed in by the makefle file, the system configuration module is used to randomly generate all the clocks of the algorithm module, and the clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module; After passing in the source address through the makefle file, write the source address random data to the source address in the virtual memory, write the source address and the random target address to the registers of the algorithm module and then start the algorithm dma transfer, and use the reference model of the verification system to calculate the expected algorithm result corresponding to the data in the source address; wait for the dma transfer to complete, then read the algorithm calculation result corresponding to the target address in the virtual memory, and judge whether the algorithm calculation result is consistent with the expected algorithm result. If not, report an error. If so, randomly select the next target address for the verification of the next algorithm module.
[0006] On the other hand, a parameterized information security module verification method is also provided, which is applied to a parameterized information security module verification system. The verification system includes a clock reset assertion module created based on the uvm verification top-level file, three apb bus interfaces and two ahb bus interfaces, as well as a simulated external bus interconnection function, a system agent component, an environment component, an interrupt function, a virtual memory and a system configuration module derived and instantiated from the base class test case; the system agent component includes three apb bus agents and two ahb bus agents, the environment component includes a TRNG environment component, a HASH environment component, a SKA environment component and a PKI environment component, the apb bus interfaces are respectively connected to the apb bus agents through the algorithm modules to be tested, the ahb bus interfaces are respectively connected to the ahb bus agents through the algorithm modules, and the interrupt function and the virtual memory are respectively connected to the algorithm modules; The simulated external bus interconnection function is used to judge, select and start the corresponding bus sending sequence according to the access address of the security algorithm passed in by the makefile file. The system configuration module is used to randomly generate all the clocks of the algorithm module, and the clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module; The above parameterized information security module verification method includes the following steps: Pass in the source address through the makefile file; Write the source address random data to the source address in the virtual memory; Write the source address and the random target address to the registers of the algorithm module, and start the algorithm dma transfer; Use the reference model of the verification system to calculate the expected algorithm result corresponding to the data in the source address; After waiting for the dma transfer to complete, read the algorithm calculation result corresponding to the target address in the virtual memory, and judge whether the algorithm calculation result is consistent with the expected algorithm result; If not, report an error. If so, randomly select the next target address to verify the next algorithm module.
[0007] One of the above technical solutions has the following advantages and beneficial effects: The above parameterized information security module verification system and verification method build a verification environment for the security algorithm subsystem of the vehicle-mounted chip based on uvm and provide a clock reset assertion module based on clock and reset. By passing in the instantiation parameters of information security modules such as SKA, PKI, Hash, and TRNG through the makefile file, it can not only cover all parameter scenarios, but also greatly enhance the maintainability of the verification environment. And by simulating the external interconnection bus, the register configuration process is simplified, and the verification efficiency of the information security module is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0009] Figure 1 It is a structural block diagram of a parameterized information security module verification system in an embodiment; Figure 2 It is a schematic diagram of the implementation principle of the clock reset assertion module in an embodiment; Figure 3 It is a schematic diagram of the algorithm operation process in an embodiment; Figure 4 Schematic diagram of the construction process of a parameterized information security module verification system in an embodiment; Figure 5 Schematic diagram of the process of a parameterized information security module verification method in an embodiment. Detailed implementation manners
[0010] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the description of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention.
[0011] It should be noted that referring to "embodiment" herein means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present invention. The phrase is shown at various positions in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art can understand that the embodiments described herein can be combined with other embodiments. The term "and / or" used in the description and claims of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0012] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings in the embodiments of the present invention.
[0013] In traditional information security module verification methods, functional simulation and static analysis are usually combined to evaluate the execution process, operation results, and anti-attack capabilities of encryption algorithms. However, this method has the following deficiencies: (1) Lack of systematic parameterized verification: In practical applications, different in-vehicle chips may need to adjust the parameters of the information security module according to the application scenario, such as the type of information security module, key length, random number entropy value, and hash algorithm selection. Traditional verification methods often test with fixed parameters and cannot cover the verification requirements under different configurations in the same test case, resulting in poor environmental maintainability. (2) Insufficient verification of clock signals: Information security modules usually require multiple clock domains to work together inside in-vehicle chips. For example, encryption operations, data access, and key management may use different clocks. If there are timing issues between clock domains, it may lead to abnormal security calculations or even be exploited by attackers. Therefore, only performing functional-level verification cannot guarantee the stability of the system under different clock conditions. (3) Difficulty in discovering problems under boundary conditions: Encryption algorithms usually involve a large number of mathematical operations, and their performance and security may be affected by specific input conditions, such as multiple algorithms working simultaneously, specific data patterns, etc. If these extreme cases are not considered during the verification process, potential security vulnerabilities may not be discovered.
[0014] Therefore, the present invention will propose a new parameterized information security module verification technology. Through the parameterized configuration of information security modules such as SKA, PKI, Hash, and TRNG, the same test cases can be reused under different parameter conditions, greatly improving the maintainability of the verification environment; and combined with assertion verification technology to check the correctness of each clock signal to ensure that the information security module can maintain correctness and reliability under various operating conditions. Compared with traditional verification methods, the above solution can achieve more comprehensive security verification, ensure the correctness, robustness, and reliability of its functions, and ensure that the in-vehicle chip can still provide stable and secure encryption capabilities when facing different application requirements and external threats.
[0015] In one embodiment, as Figure 1As shown in the figure, a parameterized information security module verification system is provided, which includes a clock reset assertion module created based on the uvm verification top-level file, three apb bus interfaces and two ahb bus interfaces, as well as a simulated external bus interconnection function, a system agent component, an environment component, an interrupt function, a virtual memory, and a system configuration module derived and instantiated from a base class test case. The system agent component includes three apb bus agents and two ahb bus agents. The environment component includes a TRNG environment component, a HASH environment component, a SKA environment component, and a PKI environment component. The apb bus interfaces are respectively connected to the apb bus agents through the algorithm modules to be tested, the ahb bus interfaces are respectively connected to the ahb bus agents through the algorithm modules, and the interrupt function and the virtual memory are respectively connected to the algorithm modules.
[0016] The simulated external bus interconnection function is used to judge, select and start the bus sending sequence corresponding to the corresponding security algorithm according to the access address of the security algorithm passed in by the makefle file. The system configuration module is used to randomly generate all the clocks of the algorithm module. The clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module. After passing in the source address through the makefle file, random data of the source address is written to the source address in the virtual memory. After writing the source address and the random target address to the registers of the algorithm module, the algorithm dma transfer is started. The expected algorithm result corresponding to the data in the source address is calculated by using the reference model of the verification system; after waiting for the dma transfer to complete, the algorithm calculation result corresponding to the target address in the virtual memory is read, and it is judged whether the algorithm calculation result is consistent with the expected algorithm result. If not, an error is reported. If so, the next target address is randomly selected for verification of the next algorithm module.
[0017] It can be understood that in this embodiment, the security algorithm subsystem verification environment of the vehicle-mounted chip is built by using uvm (Universal Verification Methodology) as Figure 1 shown in the figure. Among them, the uvm verification top-level file is used to initialize the entire verification system and start the test case. Initializing the verification environment components includes, but is not limited to, passing the apb bus interfaces *3 (which can include interface apb0, interface apb1, and interface apb2), the ahb bus interfaces *2 (which can include) to the corresponding proxy components (such as apb bus agents *3, ahb bus agents *2), and initializing the clock reset assertion module, etc. Among them, the algorithm module is the information security module to be verified, which can include SKA, PKI, Hash, and TRNG, etc.
[0018] After creating the AHB / APB sequence function (i.e., simulating the external bus interconnection function) in the base class test case, it is used to simulate the selection of the interconnection bus, that is, to judge, select, and start the bus sending sequence corresponding to the corresponding security algorithm according to the access address (i.e., the source address) of the security algorithm passed in by the makefile. Among them, for the created function of simulating the external bus interconnection, if SKA accesses through the interface apb0, TRNG / PRNG accesses through the interface apb1, HASH accesses through the interface apb2, and PKI accesses through the ahb host in the security algorithm subsystem, at this time, when the access address is in the SKA algorithm module range, the register access is through the apb0 bus, and so on.
[0019] In the base class test case, the creation and instantiation of the virtual memory of the ahb slave (i.e., ahb bus proxy *2) are completed, which is used to simulate the existing storage bodies such as the flash pflash, flash dflash, and data tightly coupled memory dtcm in the vehicle-mounted chip; the creation of the verification environment components is completed, including the system proxy components (such as the APB proxy component apb bus proxy *3 and the AHB proxy component ahb bus proxy *2) and the environment components of each security algorithm (such as the TRNG environment component trng_env, the HASH environment component hash_env, the SKA environment component ska_env, and the PKI environment component pki_env); the creation of the interrupt function is completed, which is used to monitor the interrupts of the algorithm modules corresponding to each security algorithm, etc.; the creation of the virtual mem (memory) read and write access function is completed, which is used to simulate the transfer of the above storage bodies by the security algorithm in the real scenario; the creation of the system configuration (function) module is completed, which is used to randomly generate all the clocks of the security algorithm subsystem. The clock and reset test case is created by inheriting the base class test case. After overloading the clock random function of the base class test case, the clocks corresponding to each algorithm module are constrained to be unequal, and then the reset signals corresponding to each algorithm module are reset in turn.
[0020] Based on the verification top-level file, a clock reset assertion module based on the clock and reset is also created, which is bound to the algorithm module to be tested and is used to monitor the top-level clock reset and the internal clock behavior of the algorithm module. If top.xxclk ≠ u_dut.xxclk, an error will be reported, where top.xxclk represents the clock randomly generated at the top level for a certain algorithm module, and u_dut.xxclk represents the internal clock of the certain algorithm module to be tested. The implementation principle of the clock reset assertion module is as Figure 2As shown, "test run" indicates the start of the test. The top layer randomly generates different clocks for the nth algorithm module under test. The clock reset assertion module determines whether top.xxclk = u_dut.xxclk. If not, an error is reported. If so, the nth reset is reset to n + 1 (to assert the clock behavior of the next algorithm module). Then, the clock reset assertion module determines whether top.xxclk = u_dut.xxclk. If not, an error is reported. If so, it is determined whether n is greater than or equal to xx (i.e., whether it is already the last algorithm module at present). If not, the step of resetting the nth to n + 1 is returned, and the next test loop continues. If so, it ends.
[0021] Based on the verification top-level file, a makefile file is also created, which is used to link the file lists of each digital module of the security algorithm subsystem and the file list of the verification environment, and can also be used to add compilation macros and coverage collection options. It can be understood that the specific script writing and running implementation process of the makefile file can be understood by referring to the relevant implementation process of the existing makefile file in this field. Therefore, it will not be elaborated in this specification.
[0022] Finally, a multi-algorithm startup test case is created by inheriting the base class test case, and the algorithm running process is executed, such as Figure 3 As shown, it includes the process steps: establish the source address, write the source address random data at this source address in the virtual memory through the virtual memory read and write function; repeat n times, randomly generate the target address, and write the source address and the target address into the algorithm register; configure the register and start the algorithm dma (Direct Memory Access, which is a technology that allows hardware devices to directly transfer data with the memory) transfer; the reference model receives the data at the source address and calculates the expected algorithm result corresponding to the data in this source address; after waiting for the dma transfer to complete, read the algorithm calculation result corresponding to the target address in the virtual memory (returned by the algorithm module calculation), and determine whether the algorithm calculation result corresponding to the target address is consistent with the expected algorithm result. If not, an error is reported. Otherwise, return to the step of repeating n times, randomly generating the target address, and writing the source address and the target address into the algorithm register, and continue the subsequent verification.
[0023] Specifically, first write the source address random data through the virtual memory read and write function, and then configure the SKA, PKI, Hash, and TRNG registers to write the source address, target address, and algorithm type respectively, enable the algorithm module and start the internal dma transfer. Pass the expected algorithm result through the reference model created based on the verification top-level file, and check whether the algorithm calculation result corresponding to the virtual memory target address is consistent with the expected algorithm result.
[0024] The above-mentioned parameterized information security module verification system builds a verification environment for the security algorithm subsystem of in-vehicle chips based on UVM and provides a clock and reset assertion module based on clock and reset. By passing the instantiation parameters of information security modules such as SKA, PKI, Hash, and TRNG through the makefile, it can not only cover all parameter scenarios, but also greatly enhance the maintainability of the verification environment. And by simulating the external interconnection bus, it simplifies the register configuration process and greatly improves the verification efficiency of information security modules.
[0025] In one embodiment, the above verification system further includes a coverage model created based on the verification top-level file. The coverage model is used to collect functional coverage for the clock random range and reset jump; the makefile is also used to add compilation macros and coverage collection options.
[0026] It can be understood that in this embodiment, a coverage model can also be created based on the verification top-level file. The coverage model is used to collect functional coverage for the clock random range, reset jump, etc., making the verification more accurate and perfect. The creation of the coverage model can be understood by referring to the implementation method of creating a coverage model in the UVM platform. It will not be elaborated in this specification. As Figure 4 shown, it is the construction process of the above-mentioned parameterized information security module verification system, including: creating a verification top-level file, initializing the verification system (platform); connecting interfaces, creating system proxy components; creating base-class test cases, creating bus sending sequence functions; creating assertions and algorithm reference models; adding a coverage module; creating a makefile, adding compilation macros and coverage collection options. It improves the maintainability of the verification environment, simplifies the verification process of information security modules by passing parameters through the makefile, and creates a coverage model for each algorithm function to collect functional verification coverage, making the verification more comprehensive.
[0027] In some embodiments, for example, when the PKI version 2048bit data size is default started, when the system starts, the parameter pki_version = 4096 is passed through the makefile. Since the pki_version macro is used in the test cases, there is no need to make additional changes to the test cases and it can be directly regressed. In the test cases, it is also possible to instantiate and collect the clock division coefficient, reset jump, and algorithm type configuration. The makefile can also be used to pass in the specified number of times to run the test cases to achieve the automatic running of the test cases a specified number of times.
[0028] Each component in the above-mentioned parameterized information security module verification system can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above components can be embedded in a device with data processing capabilities in hardware form or independent thereof, or stored in the memory of the aforementioned device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules. The aforementioned device can be, but is not limited to, various types of chip verification computers existing in the art.
[0029] In one embodiment, a parameterized information security module verification method is provided, which is applied to a parameterized information security module verification system. The verification system includes a clock reset assertion module created based on a uvm verification top-level file, three apb bus interfaces and two ahb bus interfaces, as well as a simulated external bus interconnection function, a system agent component, an environment component, an interrupt function, a virtual memory, and a system configuration module derived and instantiated from a base class test case. The system agent component includes three apb bus agents and two ahb bus agents. The environment component includes a TRNG environment component, a HASH environment component, a SKA environment component, and a PKI environment component. The apb bus interfaces are respectively connected to the apb bus agents through the algorithm modules to be tested, and the ahb bus interfaces are respectively connected to the ahb bus agents through the algorithm modules. The interrupt function and the virtual memory are respectively connected to the algorithm modules. The simulated external bus interconnection function is used to judge, select, and start the bus sending sequence corresponding to the corresponding security algorithm according to the access address of the security algorithm passed in by the makefle file. The system configuration module is used to randomly generate all clocks of the algorithm module. The clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module.
[0030] As Figure 5 shown, the parameterized information security module verification method includes the following steps S10 to S20: S10, passing in the source address through the makefle file; S12, writing source address random data to the source address in the virtual memory; S14, writing the source address and a random target address to the register of the algorithm module, and starting the algorithm dma transfer; S16, using the reference model of the verification system to calculate the expected algorithm result corresponding to the data in the source address; S28, waiting for the dma transfer to complete, then reading the algorithm calculation result corresponding to the target address in the virtual memory, and judging whether the algorithm calculation result is consistent with the expected algorithm result; S20, if not, then report an error, if so, then randomly select the next target address for verification of the next algorithm module.
[0031] The above parametric information security module verification method builds a verification environment for the security algorithm subsystem of in-vehicle chips based on UVM and provides a clock and reset assertion module based on clock and reset. By passing the instantiation parameters of information security modules such as SKA, PKI, Hash, and TRNG through the makefile, it can not only cover all parameter scenarios, but also greatly enhance the maintainability of the verification environment. And by simulating the external interconnect bus, it simplifies the register configuration process and greatly improves the verification efficiency of the information security module.
[0032] In one embodiment, the verification system further includes a coverage model created based on the verification top-level file. The coverage model is used to collect functional coverage for the clock random range and reset jump; the makefile is also used to add compilation macros and coverage collection options.
[0033] In one embodiment, the makefile is also used to pass in the specified number of runs of the test cases.
[0034] For the specific limitations of the parametric information security module verification method, reference can be made to the corresponding limitations of the parametric information security module verification system in the above text, which will not be elaborated here.
[0035] It should be understood that although Figure 5 the steps in Figure 5 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover
[0036] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), memory bus dynamic random access memory (Rambus DRAM, abbreviated as RDRAM), and interface dynamic random access memory (DRDRAM), etc.
[0037] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0038] The above embodiments only represent several implementation manners of the present invention. The description is relatively specific and detailed, but it cannot be understood as a limitation on the protection scope of the invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, which all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the appended claims.
Claims
1. A parameterized information security module verification system, characterized in that: The invention comprises a clock reset assertion module created based on a UVM verification top-level file, three APB bus interfaces and two AHB bus interfaces, and a simulated external bus interconnection function derived and instantiated based on a base class test case, a system agent component, an environment component, an interrupt function, a virtual memory and a system configuration module; the system agent component comprises three APB bus agents and two AHB bus agents, the environment component comprises a TRNG environment component, a HASH environment component, a SKA environment component and a PKI environment component, the APB bus interface is connected to the APB bus agent through an algorithm module to be tested, the AHB bus interface is connected to the AHB bus agent through the algorithm module, and the interrupt function and the virtual memory are connected to the algorithm module respectively; The simulated external bus interconnection function is used to judge, select and start the bus transmission sequence corresponding to the corresponding security algorithm according to the access address of the security algorithm passed in by the makefile file, the system configuration module is used to randomly generate all clocks of the algorithm module, and the clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module; After the source address is passed in through the makefile file, the source address random data is written into the source address of the virtual memory, the algorithm DMA transfer is started after the source address and the random target address are written into the register of the algorithm module, and the expected algorithm result corresponding to the data in the source address is calculated using the reference model of the verification system; After waiting for the DMA transfer to be completed, read the algorithm calculation result corresponding to the target address in the virtual memory to determine whether the algorithm calculation result is consistent with the expected algorithm result. If not, report an error. If so, randomly select the next target address to verify the next algorithm module.
2. The parameterized information security module verification system according to claim 1, characterized in that: It also includes a coverage model created based on the verification top-level file, and the coverage model is used to collect functional coverage for clock random range and reset jump; the makefile file is also used to add compilation macros and coverage collection options.
3. The parameterized information security module verification system according to claim 1 or 2, characterized in that: The makefile file is also used to pass in the specified number of test case runs.
4. A parameterized information security module verification method, characterized in that: The invention is applied to a parameterized information security module verification system, the verification system comprising a clock reset assertion module created based on a UVM verification top-level file, three APB bus interfaces and two AHB bus interfaces, and a simulated external bus interconnection function derived and instantiated based on a base class test case, a system agent component, an environment component, an interrupt function, a virtual memory and a system configuration module; the system agent component comprises three APB bus agents and two AHB bus agents, the environment component comprises a TRNG environment component, a HASH environment component, a SKA environment component and a PKI environment component, the APB bus interface is connected to the APB bus agent through an algorithm module to be tested, the AHB bus interface is connected to the AHB bus agent through the algorithm module, and the interrupt function and the virtual memory are connected to the algorithm module respectively; The simulated external bus interconnection function is used to judge, select and start the bus transmission sequence corresponding to the corresponding security algorithm according to the access address of the security algorithm passed in by the makefile file, the system configuration module is used to randomly generate all clocks of the algorithm module, and the clock reset assertion module is used to monitor whether the top-level clock is consistent with the internal clock of the algorithm module; The parameterized information security module verification method comprises the steps of: Pass the source address through the makefile file; Write source address random data at the source address of the virtual memory; Write the source address and the random target address into the register of the algorithm module and start the algorithm DMA transfer; Calculating an expected algorithm result corresponding to the data in the source address using a reference model of the verification system; After waiting for the DMA transfer to be completed, read the algorithm calculation result corresponding to the target address in the virtual memory to determine whether the algorithm calculation result is consistent with the expected algorithm result; If not, an error is reported. If so, the next algorithm module is verified at the next random target address.
5. The parameterized information security module verification method according to claim 4, characterized in that: The verification system also includes a coverage model created based on the verification top-level file, and the coverage model is used to collect functional coverage for clock random range and reset jump; the makefile file is also used to add compilation macros and coverage collection options.
6. The parameterized information security module verification method according to claim 4 or 5, characterized in that: The makefile file is also used to pass in the specified number of test case runs.